How should a mid-market DTC brand collect exemption certificates at checkout and in B2B order flow?

A mid-market ecommerce brand collects exemption certificates across four order flows: DTC checkout, Shopify Plus B2B, wholesale ERP entry, and wholesale platform orders. Each surface creates certificate obligations on different timing. Manual email collection holds at fewer than 100 exchanges per month. Above that breakpoint, the workflow needs state-specific form validation, expiration tracking, and each certificate linked directly to the transactions it covers.

Last updated: Aug 11, 2026 Sales Tax at Scale Team

Key takeaways

  • DTC checkout offers three collection patterns: account-tagged (cert at account open, exempt flag applied to subsequent orders), prompt-on-checkout (cert required before order processes), and post-purchase (tax collected at checkout, cert and refund processed after). Each trades cart abandonment risk against operational load differently.
  • Shopify Plus B2B applies a tax-exempt flag at the company account level but does not validate certificates against state-specific field requirements. The exempt flag carries into connected ERP systems without the underlying certificate evidence chain an auditor will request.
  • NetSuite and QuickBooks Online store certificates as attachments on the customer record but do not validate field completeness against state-specific requirements. The ERP's exempt flag does not guarantee the stored certificate is audit-ready.
  • Wholesale platforms like Faire collect and remit sales tax as marketplace facilitators for on-platform orders. The brand still owns the certificate pool for every direct retailer relationship conducted off-platform, even when that retailer also buys through the platform.
  • At roughly 100 to 200 cert exchanges per month, a folder-and-email workflow breaks. Collection falls behind order flow, expiration tracking becomes unreliable, and month-end reconciliation turns into a cert-collection sprint.
  • Retroactive certificate recovery is an operational pattern, not an exception. Collect the missing cert from the buyer, process the tax refund where applicable, and update the transaction linkage in the audit trail. Batch this at month-end rather than chasing each gap transaction-by-transaction.

How to structure DTC checkout certificate collection: three patterns and their trade-offs

Three patterns exist for handling exemption certificate collection at DTC checkout. Each solves the same problem at a different intervention point: when the brand collects the certificate relative to when the order ships.

Pattern 1: Account-tagged

The buyer is flagged as exempt on the customer record before checkout begins. The brand collected a valid certificate at the start of the buyer relationship, validated it against the applicable state's form requirements, and marked the account exempt. Every subsequent order is automatically flagged; no certificate is requested again unless a triggering event requires reissuance: permit expiration, entity change, or a new ship-to state. Tax is not applied at checkout and no friction hits the cart. The audit burden sits entirely on whether the original certificate is valid, still current, and linked to each subsequent order.

Pattern 2: Prompt-on-checkout

The checkout flow detects an exemption claim and requests a certificate upload before the order completes. The transaction does not process until a document is on file. This closes the gap where an uncertificated order ships on exempt status, but the cost is real: higher cart abandonment among buyers who do not have a document ready at purchase and a validation step that requires near-real-time processing before the order queue moves.

Pattern 3: Post-purchase

The order ships with sales tax applied at the applicable state and local rates. The brand then contacts the buyer, collects a certificate, validates it, and processes a tax refund. The audit trail requires three linked records: the original taxed transaction, the certificate, and the refund. This pattern eliminates checkout friction entirely at the cost of higher operational load per transaction and suits irregular or first-time exempt buyers where blocking checkout is worse than running a refund process.

The trade-off across all three patterns:

Pattern
Cart abandonment risk
Operational load per transaction
Cert-to-order linkage burden
Account-tagged
None
Low (one-time cert collection at account open)
Blanket cert covers all subsequent orders; linkage requires transaction log
Prompt-on-checkout
Moderate to high
Medium (near-real-time validation)
Cert collected before order processes
Post-purchase
None
High (cert request, validation, and refund per transaction)
Three-record trail per transaction

For brands with 20 to 40 recurring wholesale accounts, account-tagged with cert collection at account creation is the operational baseline. For irregular or first-time exempt buyers, post-purchase avoids blocking checkout while still building the audit trail.

The Shopify Plus B2B portal workflow and the validation gap it leaves

Shopify Plus B2B introduces dedicated B2B order flows through company profiles, which carry a tax-exempt flag that suppresses tax collection at checkout when set. The flag is applied at the company or location level in the Shopify admin. When a buyer places an order under an exempt company, Shopify does not collect tax.

The operational gap is not in the order flow. It is in what the order flow does not manage: the certificate documentation.

Shopify Plus B2B does not validate whether the brand holds a valid certificate from that buyer for the states where orders are shipping. It does not check whether the certificate covers the specific ship-to state on a given order. It does not verify required fields for the applicable jurisdiction. It does not track expiration. The platform manages the exempt flag; everything behind the flag is the brand's responsibility.

At audit, the Shopify Plus B2B order history shows exempt transactions. The state reviewer's first request is the certificates that authorized those exemptions, mapped to each transaction and each ship-to state. The certificate pool must provide that mapping. Shopify Plus B2B does not.

The flag also passes downstream. When Shopify Plus connects to NetSuite or QuickBooks Online, the order's exempt status carries over. The ERP records an exempt transaction. The gap between what the system records and what an audit requires is where certificate exposure accumulates: the system records that a transaction was exempt; the audit requires proof the exemption was valid in the ship-to state, on the transaction date, against the applicable state's field requirements.

TaxCloud's native Shopify and Shopify Plus integration connects the exempt-customer flag to certificate collection within the same workflow. A new B2B company account triggers a certificate collection request against the applicable states' form requirements before the first exempt order processes. Each subsequent order links to the valid cert on file, producing a cert pool that matches the order history Shopify Plus generates rather than a separate trail reconstructed at audit time.

NetSuite and QuickBooks Online wholesale order entry: why the ERP is not the validation layer

In NetSuite and QuickBooks Online, exemption handling operates at the customer record level. The operations team marks a customer as exempt, assigns a reason code, and the system applies that status to every subsequent transaction. Most implementations also store the certificate as a file attachment on the customer record or in a dedicated certificates module.

The problem is not storage. The problem is validation.

NetSuite's tax configuration and QuickBooks Online's basic exemption handling check whether an exemption reason code is present on a transaction, not whether the stored certificate satisfies the ship-to state's specific field requirements. A customer record marked exempt with a PDF attachment does not confirm that the document is a valid California CDTFA-230, or that the buyer's permit number is current, or that the certificate covers orders shipped to Texas as well as orders shipped to California.

This gap becomes material when the wholesale channel spans multiple states. A $40M brand with wholesale accounts shipping into 25 states has state-specific form requirements in each. California requires the CDTFA-230 under CDTFA Reg. 1668.[3] Texas blanket resale certificates under 34 TAC §3.287 require a specific use description.[4] Florida's Annual Resale Certificate (DR-13) expires December 31 of each year under Fla. Stat. §212.07, requiring reissuance from every account with Florida-destined orders each January.[5] New York's ST-120 applies to taxable goods shipped into the state per Publication 750.[6]

The ERP exempt flag for a given customer is the same regardless of which state an order ships to. The certificate requirement varies by state. A blanket flag does not replace state-specific documentation.

The ERP is the order-management layer. It is not the certificate-management layer. Brands that treat it as the latter discover the gap when an auditor requests state-specific certificates for the exempt transactions in the ERP history and the attachment folder holds a generic PDF that covers none of the required state formats. Connecting the ERP's exempt flag to a validation layer that checks state-specific field requirements and tracks expiration is the structural fix.

Wholesale platforms (Faire, NuOrder) and the platform-vs-direct certificate distinction

Faire operates as a marketplace facilitator under statutes enacted across most states following the South Dakota v. Wayfair framework.[7] When a retailer places an order through Faire, Faire collects and remits sales tax where it holds marketplace facilitator obligations. The brand does not collect tax on those transactions and carries no certificate obligation for them; the tax obligation sits with the platform.

NuOrder operates under the same framework for many transactions. The specific states and transaction types where a given platform holds marketplace facilitator status vary by platform and state. Brands should confirm coverage for each state rather than assuming platform-wide coverage.

The audit exposure is not from on-platform transactions. It is from the same retailer accounts placing orders directly off-platform.

A retailer that sources core wholesale inventory through Faire and places direct purchase orders through a Shopify Plus B2B portal or against a NetSuite customer record is two separate things from a certificate perspective. The Faire transactions may be fully handled by the marketplace facilitator. The direct purchase orders require a valid certificate from the brand, collected and validated against the ship-to state's requirements.

At audit, the examiner separates the transaction population by source. Faire-originated transactions generate a different evidence chain than direct-channel transactions. A brand that never collected certificates from a retailer account because that retailer also buys through Faire has a gap in its cert pool for every direct transaction in the audit period. Each order surface carries its own certificate obligation. Platform-facilitated transactions are the platform's problem; every off-platform transaction is the brand's, regardless of who placed the order.

The volume breakpoint: what breaks at 100 to 200 cert exchanges per month

A manual certificate workflow operates through email requests, PDF attachments, and a shared folder. One person can manage it when the brand processes fewer than 100 cert exchanges per month, covering roughly 20 to 40 active wholesale accounts generating regular orders.

The workflow breaks in a predictable sequence above 100 to 200 cert exchanges per month:

  1. Collection lag. Certificate requests go out with order confirmations but are not tracked independently. Orders ship on exempt status before the cert arrives. The gap between "assumed exempt" and "cert on file" widens across multiple accounts simultaneously.
  2. Expiration drift. Florida's DR-13 expires every December 31.[5] New York certificates are generally valid for three years per Publication 750.[6] Texas blanket certificates have no stated expiration under 34 TAC §3.287 but require reissuance when the buyer's permit changes.[4] Without a tracking system, renewals slip past unnoticed until an auditor flags the lapsed cert.
  3. Close slippage. Month-end closes require a reconciled cert pool to support the exempt transaction count. When certs are missing for a material portion of exempt transactions, the close becomes a cert-collection sprint.
  4. Audit readiness gap. State notice response windows are typically 30 to 90 days. Reconstructing a cert pool from email archives under that deadline is structurally incomplete.

What replaces a manual workflow at this volume is a structured certificate management system with four components:

  • State-specific form validation. The system requests the correct form for each ship-to state: CDTFA-230 for California,[3] DR-13 for Florida,[5] 01-339 for Texas.[4] The SSTGB Form F0003 covers the 23 full member states plus Tennessee as associate member for resale and most exempt-use purposes.[1]
  • Expiration tracking. Each certificate carries an expiration date or renewal trigger, surfaced as an automated reminder before it lapses.
  • Transaction linkage. Each certificate connects to the transactions it covers at collection time, not at audit.
  • Automated renewal prompts. The system generates renewal requests before expiration rather than waiting for a collection event to reveal a lapsed cert.

TaxCloud maintains the state-specific form acceptance logic and expiration schedules in the collection layer. A new wholesale account in California triggers a CDTFA-230 request. A Florida account's DR-13 generates a renewal prompt each December before the cert expires. The brand manages account relationships; the compliance layer manages the certificate rules behind each state.

Retroactive certificate collection: recovering certs from buyers who ordered without one

Not every exempt transaction arrives with a certificate on file. A wholesale account's cert has expired. A B2B buyer places a first Shopify Plus order before collection is configured. An ERP exempt flag fires without triggering a cert request. In each case, the transaction closes as exempt with no current documentation.

The retroactive collection workflow runs through five steps.

Step 1: Identify the gap

At month-end, compare exempt transactions against the cert pool. Flag every exempt transaction where no current, valid certificate covers the transaction date, the ship-to state, and the buyer's entity.

Step 2: Contact the buyer with a state-specific request

Name the ship-to state, the applicable form, the transaction dates, and a response deadline. "California CDTFA-230 required for your orders shipped to California between January 1 and March 31" produces the correct document more reliably than a generic request.

Step 3: Validate the returned certificate

Check it against the applicable state's field requirements before recording it as coverage. A deficient retroactive certificate does not resolve the gap.

Step 4: Process the tax refund where applicable

For post-purchase transactions where tax was collected at checkout, a valid retroactive certificate supports a refund to the buyer. Document the original transaction, the certificate, and the refund processing date in a linked trail.

Step 5: Update the transaction linkage

Connect the retroactive certificate to the specific transactions it retroactively covers. A cert added to the general pool without a transaction linkage cannot be matched to the transactions an auditor reviews.

At scale, batch-processing this reconciliation at month-end is more manageable than chasing each gap individually. A monthly review against the cert pool takes a defined block of time; transaction-by-transaction correction becomes an ongoing interruption.

In SST member states, the SSTGB Form F0003 retroactive cure provision allows a retroactively obtained certificate to resolve an audit gap when the buyer is still registered and the transaction was genuinely exempt.[1] This cure is not available in California, New York, Texas, or Florida: a missing CDTFA-230 cannot be resolved by substituting an MTC Uniform Resale Certificate.[2][3] The required form must have been the required form at the time of collection.

When a state reviewer requests it, every exempt transaction in the Shopify and Shopify Plus order history maps to a current, valid certificate, because TaxCloud tied collection, validation, and expiration tracking to the order flow from the start.

Sources

  • Streamlined Sales Tax Governing Board

    SSTGB Form F0003, the Streamlined Sales and Use Tax Agreement Certificate of Exemption

    Source link
  • Multistate Tax Commission

    Uniform Sales and Use Tax Resale Certificate, Multijurisdiction

    Source link
  • California Department of Tax and Fee Administration

    Regulation 1668 on sales for resale

    Source link
  • Texas Comptroller of Public Accounts

    34 TAC §3.287 on exemption certificates

    Source link
  • Florida Department of Revenue

    Annual Resale Certificate for Sales Tax (DR-13) under Fla. Stat. §212.07

    Source link
  • New York State Department of Taxation and Finance

    Publication 750, a guide to sales tax in New York State, covering the ST-120

    Source link
  • Streamlined Sales Tax Governing Board

    Marketplace Facilitator State Guidance

    Source link

FAQ

Common questions

How does collecting exemption certificates at Shopify Plus B2B checkout differ from collecting them at DTC checkout?

Shopify Plus B2B applies a tax-exempt flag at the company account level, suppressing tax collection without requesting a certificate during the order flow. DTC checkout collection happens through one of three patterns: account-tagged, prompt-on-checkout, or post-purchase. The underlying gap is the same across both surfaces: Shopify manages the exempt flag, not the certificate documentation. A current, valid certificate for each ship-to state is required regardless of which order surface generated the transaction.

What happens to our certificate obligations when we sell through Faire or another wholesale marketplace?

When a wholesale platform operates as a marketplace facilitator, it collects and remits sales tax on transactions processed through the platform. The brand does not carry a certificate collection obligation for those platform-facilitated transactions. The obligation attaches to every direct purchase order the same retailer places off-platform, through Shopify Plus B2B, NetSuite, or direct order entry. At audit, platform-facilitated and direct transactions are reviewed separately. Assuming platform coverage extends to direct relationships is the common exposure pattern.

At what volume does a manual certificate collection workflow stop working?

A manual workflow holds at fewer than 100 cert exchanges per month, covering roughly 20 to 40 active wholesale accounts. Above 100 to 200 exchanges per month, collection lag widens, expiration tracking becomes unreliable, and month-end reconciliation turns into a sprint. The breakpoint is usually visible before it causes audit exposure: the close starts requiring manual cert cleanup to match exempt transactions against current documentation.

How do we recover exemption certificates for exempt orders that already shipped without one?

At month-end, compare exempt transactions against the cert pool and flag every gap. Send state-specific certificate requests naming the correct form for each ship-to state and the transaction dates at issue. Validate the returned certificate before recording it as coverage. In SST member states, the SSTGB Form F0003 retroactive cure provision allows a retroactively obtained certificate to resolve an audit gap when the buyer is still registered.[1] Non-SST states requiring state-specific forms do not offer this cure.

Does the tax-exempt flag in NetSuite or QuickBooks Online provide audit protection on its own?

No. The exempt flag records that a transaction was treated as exempt; it does not confirm that a valid certificate exists, that the stored document covers the specific ship-to state, that all required fields are present, or that the certificate has not expired. An auditor reviewing exempt transactions in the ERP will request the underlying certificates. The flag identifies where to look; the certificate pool is what needs to hold up against state-specific form requirements and field-level validation.