Multi-Company Setups and Advisors: Multiple Tax IDs in One Invoicing Software

A director who owns three companies. An accounting firm (gestoría) issuing invoices for forty clients. A group with a holding and two operating subsidiaries. Since Spain's Royal Decree 1007/2023 came into force — companies from 1 January 2026, self-employed workers from 1 July 2026 — they all face the same question: every taxpayer must invoice through a compliant SIF (certified invoicing system), and running several tax IDs (NIFs) in one tool has its own rules. Getting it wrong is not cosmetic: it affects the record chain, the invoice series, and who is liable when something breaks.

Each tax ID gets its own chain

The core principle: the SHA-256 hash chain of billing records is maintained per taxpayer. Company A's chain starts with its first record and grows only with A's invoices; Company B's chain is fully independent. There is no such thing as "the software's chain" — there is one chain per issuer.

In practice, serious multi-company software must guarantee that:

Strict data isolation

Sharing an application must never mean sharing data. A user working for Company A should not see — let alone edit — clients, invoices or drafts belonging to Company B without explicit permission. For advisory firms this is critical: their clients are often competitors of each other, and cross-leaking price lists or customer bases is a genuine confidentiality incident.

The practical rule: permissions per company and per role. The group administrator sees everything; a subsidiary's bookkeeper sees only that subsidiary; a billing clerk can issue invoices in their company and nothing more — no access to series configuration or certificates.

Advisors invoicing on behalf of clients

The fact that the gestoría operates the software changes nothing legally: the invoice is issued by the taxpayer (the client), in their name and under their NIF, even if the advisor physically clicks the button. That means:

What to ask your software before adding a second company

Before onboarding another NIF, check these five points:

1. Does it maintain an independent hash chain per NIF? A vague answer is a red flag. 2. Are invoice series scoped to each company, with the system preventing collisions and gaps? 3. Can I choose VeriFactu or non-VeriFactu per company, and switch modes in an orderly way? 4. Do permissions isolate data per company, with differentiated roles and a trail of who did what? (The event log also captures relevant accesses and operations.) 5. Can I export one NIF's complete records if that company moves to another tool or another advisor?

One calendar reminder to close: do not confuse any of this with Spain's mandatory B2B e-invoicing under the "Crea y Crece" law. That is a separate obligation, still pending rollout with a 2027 horizon (large companies first, everyone else a year later). What is already enforceable today, for every NIF you manage, is that each one invoices from a compliant SIF — chain intact, data properly walled off.

Want to sort it out today?

InvoSeal complies with RD 1007/2023 in VeriFactu and Non-VeriFactu mode from day one. Statement of Responsibility published.

Try InvoSeal →
← Back to blog