Skip to main content

Mexico SUA Payroll System

What it is: SUA is the IMSS-issued software that Mexican employers use to self-determine what they owe in social security, retirement and housing contributions each period, and to generate the file that produces the payment reference. It is the calculation engine at the centre of Mexican payroll compliance – and, unusually for a modern statutory system, it is a locally installed desktop application rather than a web portal.

Full name: Sistema Único de Autodeterminación

Also known as: IMSS SUA, the SUA system, autodeterminación de cuotas

The principle behind it: self-determination

Mexican social security operates on autodeterminación. The authority does not assess the employer and issue a bill; the employer calculates its own liability, declares it, and pays. IMSS then verifies, and discrepancies become assessments, surcharges and fines after the fact.

SUA exists to make that self-calculation tractable. It takes the employer’s workforce data – affiliation movements, salaries, absences, housing credits – and derives the contributions due across every branch of the obligatory regime, plus retirement and housing, plus any surcharges for late payment.

It is mandatory for employers with five or more workers. Smaller employers may use it voluntarily, and in practice most do, because the calculation logic is difficult to reproduce reliably by hand.

What SUA calculates

A single SUA run covers three distinct streams of liability:

  • IMSS contributions across the branches of the obligatory regime – occupational risk, sickness and maternity, disability and life, retirement, and daycare and social benefits – split between the employer share and the employee share that the employer withholds and remits.
  • RCV – retirement, old-age severance and old age – which feeds the employee’s individual pension account.
  • INFONAVIT – the 5% housing fund contribution, plus the amortisation of any housing credit the employee holds, which the employer deducts from wages and remits on the employee’s behalf.

It also calculates surcharges (recargos) and inflation updating (actualización) for late or extemporaneous payments, and can compute administrative fines where a payment demand has already been notified. Its output is a payment file and, ultimately, a capture line (línea de captura) for settlement through the banking system.

Where SUA sits in the wider stack

SUA does not work alone, and confusing the three systems is one of the most common sources of error in internationally managed Mexican payroll.

IDSE (IMSS Desde Su Empresa) is the online channel for affiliation movements – hires, terminations and salary changes. It is where the employment relationship is registered.

SUA is the calculation engine. It consumes the movement and salary data and produces the amount owed.

SIPARE (Sistema de Pago Referenciado) is the payment channel. The SUA file is uploaded there to obtain the payment reference used to settle at the bank.

EMA and EBA – the monthly and bimonthly advance statements IMSS produces from its own records – are the reconciliation counterpart. They represent the authority’s version of what the employer owes. Comparing them against SUA’s output before paying is the control that catches divergences while they are still cheap to fix, and it is the step most often skipped.

The data feeding all of this comes back to one figure: the salario base de cotización (SBC). Which pay elements integrate into the SBC, and which are excluded, determines every contribution amount downstream. SBC integration errors are the single most expensive category of mistake in Mexican payroll, because they compound silently across every employee and every period until an IMSS review surfaces them.

The payment calendar

Monthly IMSS contributions are due by the 17th of the month following the period, paid in arrears under Article 39 of the Social Security Law.

RCV and INFONAVIT are settled bimonthly, due by the 17th of the month following the close of each two-month period – in practice January, March, May, July, September and November.

Where the 17th falls on a non-business day, the deadline moves to the next business day.

Affiliation movements run on their own clock: hires, terminations and salary changes must be reported through IDSE within five business days, with registration of a new worker required before they begin work, or at the latest on the same day. An unregistered worker who has an accident leaves the employer carrying the full medical and benefit cost.

Version management: the part that breaks

Because SUA is installed software rather than a hosted service, staying current is an active obligation, and the government updates it whenever the underlying rules change.

The current release is version 3.7.1, published on 2 March 2026, which layers adjustments derived from the 2026 tax miscellany onto the structural changes introduced in 3.7.0. Its additions include INFONAVIT notification fees and a document type covering joint-and-several liability where the employer makes late payments or pays contribution differences.

The recent release history illustrates the cadence: version 3.6.6, in mid-2025, added configuration for digital platform companies; version 3.6.7, in August 2025, adapted the system to the reform of Article 29 of the INFONAVIT Law.

Two operational details matter for anyone setting up a new environment. New installations must apply the base version 3.5.3 first and then the current updater – the current release is not a standalone installer. And because SUA holds a local database, an installation carries an employer’s entire contribution history, which makes backup before every update a genuine requirement rather than a formality.

Separately, IMSS has been consolidating authentication for affiliation procedures onto the SAT’s e.firma, completing a transition first contemplated in 2013. Employers still authenticating with the older IMSS digital certificate should confirm their position against the current transition deadlines.

What late or incorrect payment costs

Non-compliance is expensive in layers rather than in a single penalty.

Surcharges and updating accrue automatically on unpaid amounts from the day after the deadline, with monthly surcharge rates published for each year and inflation updating applied on top.

Administrative fines are set in UMAs and run from roughly 20 to 350 UMAs per infraction, which in 2026 terms translates into thousands to tens of thousands of pesos per worker or per event depending on the breach.

Escalation for repeated omission, where IMSS may impose fines in the range of 40% to 100% of the amount omitted.

Enforcement through the administrative execution procedure, which can extend to seizure of bank accounts, and blocking of the employer’s IDSE movements until the position is regularised – meaning the company cannot register new hires.

There is also a consequence that falls on employees rather than the employer, and it generates disputes: incorrect contribution reporting damages a worker’s INFONAVIT credit eligibility and their accumulated weeks of contribution toward pension entitlement.

FAQs

Is SUA compulsory?

For employers with five or more workers, yes. Below that threshold its use is optional, though smaller employers generally use it anyway because the calculation – particularly surcharges, credit amortisations and mid-period movements – is impractical to reproduce manually.

Does SUA replace IDSE or SIPARE?

No. The three are sequential parts of one workflow. Movements are filed in IDSE, contributions are calculated in SUA, and payment is made through SIPARE. A company that has SUA configured correctly but is not filing movements on time will still calculate the wrong number, because SUA can only work with the workforce data it has been given.

Why does IMSS send an EMA if we calculate our own contributions?

Because self-determination and verification coexist. The EMA and EBA are IMSS’s calculation from its own records, issued so employers can reconcile before paying. Divergence between the two usually means a movement was filed late, filed incorrectly, or not filed at all – and the divergence is far cheaper to investigate before payment than after an audit.

What determines the contribution amount?

The salario base de cotización. Which components of remuneration integrate into it – and which are excluded under the Social Security Law – governs every figure SUA produces. Bonuses, allowances, savings fund arrangements and benefits in kind each have specific treatment, and misclassification propagates into every branch simultaneously.

How often does SUA need updating?

Whenever IMSS publishes a new version, which in recent years has been multiple times a year. Using a superseded version can produce rejected payment files or incorrect calculations, so the release announcement needs to sit in the payroll compliance calendar rather than arriving as a support ticket.

Can SUA be integrated with payroll software?

Yes, and most organisations of any size do, feeding movement and salary data into SUA rather than capturing it twice. The integration reduces manual keying errors but does not remove the reconciliation obligation – the SUA output still needs checking against the IMSS statements.

What happens if we discover an underpayment ourselves?

Voluntary regularisation is materially cheaper than waiting for a payment demand. SUA calculates the updating and surcharges from the payment date selected; once a formal demand has been notified, the fine calculation enters the picture as well.

Does a foreign company need a Mexican entity to use SUA?

It needs an employer registration number (registro patronal) with IMSS, which presupposes a Mexican legal presence and tax registration. Companies without a local entity meet these obligations through an employer of record.

Why Mexico resists standard payroll localisation

Three features make SUA harder to absorb into a global payroll model than its function suggests.

  • It is installed, not hosted. The statutory calculation lives in a local database on a specific machine, with its own backup, access control and version state. That sits awkwardly inside a cloud payroll architecture, and it makes continuity planning a real question rather than a theoretical one.
  • It is versioned unpredictably. Releases follow regulatory change, not a published annual calendar, and a missed update produces rejected files rather than a warning.
  • It is one of three systems that must agree. Movements in IDSE, the calculation in SUA, and the authority’s own EMA and EBA statements all have to reconcile before payment. A provider that runs SUA but does not reconcile against the IMSS emission is performing the calculation without the control that makes it reliable.

Mercans runs Mexican payroll through its own local entity, covering IMSS and INFONAVIT determination, IDSE movement filing and SIPARE settlement as one managed process: https://mercans.com/employer-of-record-payroll-peo/mexico/

For the wider Mexican employment, payroll and benefits framework, see the Mercans country payroll guides: https://mercans.com/country/