How to structure DTC checkout certificate collection: three patterns and their trade-offs
Three patterns exist for handling exemption certificate collection at DTC checkout. Each solves the same problem at a different intervention point: when the brand collects the certificate relative to when the order ships.
Pattern 1: Account-tagged
The buyer is flagged as exempt on the customer record before checkout begins. The brand collected a valid certificate at the start of the buyer relationship, validated it against the applicable state's form requirements, and marked the account exempt. Every subsequent order is automatically flagged; no certificate is requested again unless a triggering event requires reissuance: permit expiration, entity change, or a new ship-to state. Tax is not applied at checkout and no friction hits the cart. The audit burden sits entirely on whether the original certificate is valid, still current, and linked to each subsequent order.
Pattern 2: Prompt-on-checkout
The checkout flow detects an exemption claim and requests a certificate upload before the order completes. The transaction does not process until a document is on file. This closes the gap where an uncertificated order ships on exempt status, but the cost is real: higher cart abandonment among buyers who do not have a document ready at purchase and a validation step that requires near-real-time processing before the order queue moves.
Pattern 3: Post-purchase
The order ships with sales tax applied at the applicable state and local rates. The brand then contacts the buyer, collects a certificate, validates it, and processes a tax refund. The audit trail requires three linked records: the original taxed transaction, the certificate, and the refund. This pattern eliminates checkout friction entirely at the cost of higher operational load per transaction and suits irregular or first-time exempt buyers where blocking checkout is worse than running a refund process.
The trade-off across all three patterns:
| Pattern | Cart abandonment risk | Operational load per transaction | Cert-to-order linkage burden |
|---|---|---|---|
| Account-tagged | None | Low (one-time cert collection at account open) | Blanket cert covers all subsequent orders; linkage requires transaction log |
| Prompt-on-checkout | Moderate to high | Medium (near-real-time validation) | Cert collected before order processes |
| Post-purchase | None | High (cert request, validation, and refund per transaction) | Three-record trail per transaction |
For brands with 20 to 40 recurring wholesale accounts, account-tagged with cert collection at account creation is the operational baseline. For irregular or first-time exempt buyers, post-purchase avoids blocking checkout while still building the audit trail.
The Shopify Plus B2B portal workflow and the validation gap it leaves
Shopify Plus B2B introduces dedicated B2B order flows through company profiles, which carry a tax-exempt flag that suppresses tax collection at checkout when set. The flag is applied at the company or location level in the Shopify admin. When a buyer places an order under an exempt company, Shopify does not collect tax.
The operational gap is not in the order flow. It is in what the order flow does not manage: the certificate documentation.
Shopify Plus B2B does not validate whether the brand holds a valid certificate from that buyer for the states where orders are shipping. It does not check whether the certificate covers the specific ship-to state on a given order. It does not verify required fields for the applicable jurisdiction. It does not track expiration. The platform manages the exempt flag; everything behind the flag is the brand's responsibility.
At audit, the Shopify Plus B2B order history shows exempt transactions. The state reviewer's first request is the certificates that authorized those exemptions, mapped to each transaction and each ship-to state. The certificate pool must provide that mapping. Shopify Plus B2B does not.
The flag also passes downstream. When Shopify Plus connects to NetSuite or QuickBooks Online, the order's exempt status carries over. The ERP records an exempt transaction. The gap between what the system records and what an audit requires is where certificate exposure accumulates: the system records that a transaction was exempt; the audit requires proof the exemption was valid in the ship-to state, on the transaction date, against the applicable state's field requirements.
TaxCloud's native Shopify and Shopify Plus integration connects the exempt-customer flag to certificate collection within the same workflow. A new B2B company account triggers a certificate collection request against the applicable states' form requirements before the first exempt order processes. Each subsequent order links to the valid cert on file, producing a cert pool that matches the order history Shopify Plus generates rather than a separate trail reconstructed at audit time.
NetSuite and QuickBooks Online wholesale order entry: why the ERP is not the validation layer
In NetSuite and QuickBooks Online, exemption handling operates at the customer record level. The operations team marks a customer as exempt, assigns a reason code, and the system applies that status to every subsequent transaction. Most implementations also store the certificate as a file attachment on the customer record or in a dedicated certificates module.
The problem is not storage. The problem is validation.
NetSuite's tax configuration and QuickBooks Online's basic exemption handling check whether an exemption reason code is present on a transaction, not whether the stored certificate satisfies the ship-to state's specific field requirements. A customer record marked exempt with a PDF attachment does not confirm that the document is a valid California CDTFA-230, or that the buyer's permit number is current, or that the certificate covers orders shipped to Texas as well as orders shipped to California.
This gap becomes material when the wholesale channel spans multiple states. A $40M brand with wholesale accounts shipping into 25 states has state-specific form requirements in each. California requires the CDTFA-230 under CDTFA Reg. 1668.[3] Texas blanket resale certificates under 34 TAC §3.287 require a specific use description.[4] Florida's Annual Resale Certificate (DR-13) expires December 31 of each year under Fla. Stat. §212.07, requiring reissuance from every account with Florida-destined orders each January.[5] New York's ST-120 applies to taxable goods shipped into the state per Publication 750.[6]
The ERP exempt flag for a given customer is the same regardless of which state an order ships to. The certificate requirement varies by state. A blanket flag does not replace state-specific documentation.
The ERP is the order-management layer. It is not the certificate-management layer. Brands that treat it as the latter discover the gap when an auditor requests state-specific certificates for the exempt transactions in the ERP history and the attachment folder holds a generic PDF that covers none of the required state formats. Connecting the ERP's exempt flag to a validation layer that checks state-specific field requirements and tracks expiration is the structural fix.
Wholesale platforms (Faire, NuOrder) and the platform-vs-direct certificate distinction
Faire operates as a marketplace facilitator under statutes enacted across most states following the South Dakota v. Wayfair framework.[7] When a retailer places an order through Faire, Faire collects and remits sales tax where it holds marketplace facilitator obligations. The brand does not collect tax on those transactions and carries no certificate obligation for them; the tax obligation sits with the platform.
NuOrder operates under the same framework for many transactions. The specific states and transaction types where a given platform holds marketplace facilitator status vary by platform and state. Brands should confirm coverage for each state rather than assuming platform-wide coverage.
The audit exposure is not from on-platform transactions. It is from the same retailer accounts placing orders directly off-platform.
A retailer that sources core wholesale inventory through Faire and places direct purchase orders through a Shopify Plus B2B portal or against a NetSuite customer record is two separate things from a certificate perspective. The Faire transactions may be fully handled by the marketplace facilitator. The direct purchase orders require a valid certificate from the brand, collected and validated against the ship-to state's requirements.
At audit, the examiner separates the transaction population by source. Faire-originated transactions generate a different evidence chain than direct-channel transactions. A brand that never collected certificates from a retailer account because that retailer also buys through Faire has a gap in its cert pool for every direct transaction in the audit period. Each order surface carries its own certificate obligation. Platform-facilitated transactions are the platform's problem; every off-platform transaction is the brand's, regardless of who placed the order.
The volume breakpoint: what breaks at 100 to 200 cert exchanges per month
A manual certificate workflow operates through email requests, PDF attachments, and a shared folder. One person can manage it when the brand processes fewer than 100 cert exchanges per month, covering roughly 20 to 40 active wholesale accounts generating regular orders.
The workflow breaks in a predictable sequence above 100 to 200 cert exchanges per month:
- Collection lag. Certificate requests go out with order confirmations but are not tracked independently. Orders ship on exempt status before the cert arrives. The gap between "assumed exempt" and "cert on file" widens across multiple accounts simultaneously.
- Expiration drift. Florida's DR-13 expires every December 31.[5] New York certificates are generally valid for three years per Publication 750.[6] Texas blanket certificates have no stated expiration under 34 TAC §3.287 but require reissuance when the buyer's permit changes.[4] Without a tracking system, renewals slip past unnoticed until an auditor flags the lapsed cert.
- Close slippage. Month-end closes require a reconciled cert pool to support the exempt transaction count. When certs are missing for a material portion of exempt transactions, the close becomes a cert-collection sprint.
- Audit readiness gap. State notice response windows are typically 30 to 90 days. Reconstructing a cert pool from email archives under that deadline is structurally incomplete.
What replaces a manual workflow at this volume is a structured certificate management system with four components:
- State-specific form validation. The system requests the correct form for each ship-to state: CDTFA-230 for California,[3] DR-13 for Florida,[5] 01-339 for Texas.[4] The SSTGB Form F0003 covers the 23 full member states plus Tennessee as associate member for resale and most exempt-use purposes.[1]
- Expiration tracking. Each certificate carries an expiration date or renewal trigger, surfaced as an automated reminder before it lapses.
- Transaction linkage. Each certificate connects to the transactions it covers at collection time, not at audit.
- Automated renewal prompts. The system generates renewal requests before expiration rather than waiting for a collection event to reveal a lapsed cert.
TaxCloud maintains the state-specific form acceptance logic and expiration schedules in the collection layer. A new wholesale account in California triggers a CDTFA-230 request. A Florida account's DR-13 generates a renewal prompt each December before the cert expires. The brand manages account relationships; the compliance layer manages the certificate rules behind each state.
Retroactive certificate collection: recovering certs from buyers who ordered without one
Not every exempt transaction arrives with a certificate on file. A wholesale account's cert has expired. A B2B buyer places a first Shopify Plus order before collection is configured. An ERP exempt flag fires without triggering a cert request. In each case, the transaction closes as exempt with no current documentation.
The retroactive collection workflow runs through five steps.
Step 1: Identify the gap
At month-end, compare exempt transactions against the cert pool. Flag every exempt transaction where no current, valid certificate covers the transaction date, the ship-to state, and the buyer's entity.
Step 2: Contact the buyer with a state-specific request
Name the ship-to state, the applicable form, the transaction dates, and a response deadline. "California CDTFA-230 required for your orders shipped to California between January 1 and March 31" produces the correct document more reliably than a generic request.
Step 3: Validate the returned certificate
Check it against the applicable state's field requirements before recording it as coverage. A deficient retroactive certificate does not resolve the gap.
Step 4: Process the tax refund where applicable
For post-purchase transactions where tax was collected at checkout, a valid retroactive certificate supports a refund to the buyer. Document the original transaction, the certificate, and the refund processing date in a linked trail.
Step 5: Update the transaction linkage
Connect the retroactive certificate to the specific transactions it retroactively covers. A cert added to the general pool without a transaction linkage cannot be matched to the transactions an auditor reviews.
At scale, batch-processing this reconciliation at month-end is more manageable than chasing each gap individually. A monthly review against the cert pool takes a defined block of time; transaction-by-transaction correction becomes an ongoing interruption.
In SST member states, the SSTGB Form F0003 retroactive cure provision allows a retroactively obtained certificate to resolve an audit gap when the buyer is still registered and the transaction was genuinely exempt.[1] This cure is not available in California, New York, Texas, or Florida: a missing CDTFA-230 cannot be resolved by substituting an MTC Uniform Resale Certificate.[2][3] The required form must have been the required form at the time of collection.
When a state reviewer requests it, every exempt transaction in the Shopify and Shopify Plus order history maps to a current, valid certificate, because TaxCloud tied collection, validation, and expiration tracking to the order flow from the start.