When a validation tells you your invoice is valid, the next sensible question is: who says so, and against what did they measure it? Here the answer is Mustang — an open-source Java library from mustangproject, released under the Apache 2.0 licence and maintained on GitHub under the ZUGFeRD organisation.
It has become the de facto reference implementation around ZUGFeRD and Factur-X, and it handles XRechnung and Order-X as well. The same validation your file goes through here runs inside many tools across the industry.
What Mustang actually checks
The validator runs exactly the three layers described in How validation works — in sequence and with different tools:
| Layer | What is checked | With what |
|---|---|---|
| Container | valid PDF/A-3: embedded fonts, colour profiles, XMP metadata, a properly declared XML attachment | veraPDF |
| Schema | the embedded CII XML against its XSD: well-formedness, elements in place, correct data types | XML schema validation |
| Business rules | the EN 16931 rules including national flavours: totals, tax categories, mandatory details | Schematron |
The order is not cosmetic. If the container is broken there may be no reliable XML to examine at all — a finding from the third layer then describes a file nobody could read in the first place. Which is why you read the report top to bottom.
The validator’s version is not the format’s version
This is the most common confusion around Mustang, and it turns up regularly in sales material. Two numbering series with nothing to do with each other:
- Mustang is developed in the 2.x line. The library is currently 2.26.0, released 25 August 2026 — it supports ZUGFeRD 2.5.0, ZUGFeRD 1, Factur-X 1 and CII XRechnung 3.0.2. The matching Mustangserver 1.8.3 of 29 August 2026 validates against Schematron EN 16931 v1.3.16 and the corrected ZUGFeRD 2.5.2.
- ZUGFeRD and Factur-X are numbered separately and updated roughly every six months — currently 2.5.2 and 1.09.2 respectively, in force since 1 September 2026.
There is no Mustang version 3.x. Anyone quoting “Mustang 3” to you is confusing the tool’s number with a format’s — or has copied from somebody who did. On this site Mustang runs in the 2.x line.
Why this tool in particular
A validator is a matter of trust: it tells you whether a document is valid, and you cannot recompute that yourself. Three things argue for Mustang:
- It is open source. Which rules it applies can be read — it is not a black box producing a verdict.
- It uses the official rule sets, not reimplementations. The EN 16931 Schematron files come from where they are published.
- It is maintained in step with the formats. When a new ZUGFeRD edition appears, the adaptation follows — that is the difference between a tool and a snapshot of the state of things two years ago.
There is a practical point on top: because the same library runs in many places, there is a good chance your recipient validates against the same rule set you do. A green result here then means something.
What passing validation does not mean
This boundary tends to get skipped in marketing copy, and it is why a formally flawless invoice can still come back:
- Conformance is not correctness. A file can pass every rule and still carry the wrong price, the wrong date or the wrong customer. The validator can do arithmetic; it cannot know what is right.
- Valid is not accepted. A recipient may additionally require an order number, a particular reference or a particular profile — those are their rules, not the standard’s.
- Notices are not errors. A report separates fatal findings from remarks; the latter often come from a national flavour that does not apply to your document at all. Trying to drive them to zero is the most common way to lose an afternoon to a file that was valid long ago.
How to read the report
Every finding names two things: a rule code and a location in the XML. The location tells you where; the code tells you why. The code families and the errors that really occur in actual documents are in EN 16931 business rules.
The right next step is almost never the file but the system that produced it: the missing VAT identifier belongs in the company profile, the rounding setting in the invoicing software. Patching the XML by hand produces a document whose visible page no longer matches its data — see Validate an invoice.
Running Mustang yourself
Mustang exists as a standalone command-line tool and as a library to embed. Anyone building their own integration or validating files in bulk is well served by it — it is the same validation, just without a user interface.
If you would rather not run it yourself: the same validation runs here in the browser, without signing up, with a readable report instead of console output. Your file is used only for the check; we keep no copy.
Frequently asked questions
Do I need Java installed to validate my invoice?
No. That only applies if you want to run Mustang yourself. For a single file, uploading it here is enough.
Does Mustang validate XRechnung too?
Yes, plain XML files included. On an XML upload the container layer drops out — there is no PDF to check — and the rest runs as usual.
What is veraPDF?
The open-source PDF/A checker Mustang uses for the container layer. It answers whether the file is a valid PDF/A-3 — not whether the invoice inside it is right.
Why does validation report a rule my recipient does not apply?
Because national flavours bring their own rules and the report names them as soon as the profile provides for them. What matters is the severity: fatal means invalid, a notice means unusual but permitted.
Does the result change when a new format version appears?
It can. A corrigendum such as ZUGFeRD 2.5.2 clears up inconsistencies in validation rules — a file that produced a message before may be clean afterwards, or the other way round. Which is why it makes sense to validate before sending rather than once at the outset.
Can I rely on a green result?
On what it states: the file conforms to the standard and to the profile it declares. Whether the invoice is correct in substance and whether your recipient accepts it are two further questions — see above.
In short
- Mustang is open source (Apache 2.0) and the de facto reference in the ZUGFeRD world.
- Three layers, three tools: veraPDF for the container, XSD for the schema, Schematron for the business rules.
- The validator’s number is not the format’s. Library 2.26.0 (25 Aug 2026), formats 2.5.2 / 1.09.2. A version 3.x of Mustang does not exist.
- Passing means standard-conformant, not correct and not accepted.
- The report names the code and the location — the cause gets fixed in the producing system, not in the XML.
Want to try the same validation without installing anything? Upload a file without signing up — or create a free account if you want to keep a history.
