Multi-Company Setups and Advisors: Multiple Tax IDs in One Invoicing Software
A director who owns three companies. An accounting firm (gestoría) issuing invoices for forty clients. A group with a holding and two operating subsidiaries. Since Spain's Royal Decree 1007/2023 came into force — companies from 1 January 2026, self-employed workers from 1 July 2026 — they all face the same question: every taxpayer must invoice through a compliant SIF (certified invoicing system), and running several tax IDs (NIFs) in one tool has its own rules. Getting it wrong is not cosmetic: it affects the record chain, the invoice series, and who is liable when something breaks.
Each tax ID gets its own chain
The core principle: the SHA-256 hash chain of billing records is maintained per taxpayer. Company A's chain starts with its first record and grows only with A's invoices; Company B's chain is fully independent. There is no such thing as "the software's chain" — there is one chain per issuer.
In practice, serious multi-company software must guarantee that:
- Each NIF has its own records, its own chain and its own event log, never mixed.
- Each NIF defines its own invoice series. Series FA-2026 of Company A has nothing to do with FA-2026 of Company B, even if the names match.
- If one NIF operates in VeriFactu mode (continuous real-time transmission to the AEAT) and another in non-VeriFactu mode (locally stored, signed records plus event log), the system supports both side by side — the mode is chosen per taxpayer, not per installation.
Strict data isolation
Sharing an application must never mean sharing data. A user working for Company A should not see — let alone edit — clients, invoices or drafts belonging to Company B without explicit permission. For advisory firms this is critical: their clients are often competitors of each other, and cross-leaking price lists or customer bases is a genuine confidentiality incident.
The practical rule: permissions per company and per role. The group administrator sees everything; a subsidiary's bookkeeper sees only that subsidiary; a billing clerk can issue invoices in their company and nothing more — no access to series configuration or certificates.
Advisors invoicing on behalf of clients
The fact that the gestoría operates the software changes nothing legally: the invoice is issued by the taxpayer (the client), in their name and under their NIF, even if the advisor physically clicks the button. That means:
- The billing records belong to the client and are generated under the client's NIF and chain.
- Liability towards the AEAT sits with the taxpayer, not the advisory firm. If the software used is non-compliant, the fine of up to €50,000 per financial year (Article 201 bis of the General Tax Law) targets the issuer. The advisor may face contractual liability towards the client, but the tax liability does not transfer.
- Put it in writing (engagement letter): who configures the series, who safeguards the records, and what happens if the client switches advisors. Records and their chain must be exportable and continuable, never held hostage.
What to ask your software before adding a second company
Before onboarding another NIF, check these five points:
1. Does it maintain an independent hash chain per NIF? A vague answer is a red flag. 2. Are invoice series scoped to each company, with the system preventing collisions and gaps? 3. Can I choose VeriFactu or non-VeriFactu per company, and switch modes in an orderly way? 4. Do permissions isolate data per company, with differentiated roles and a trail of who did what? (The event log also captures relevant accesses and operations.) 5. Can I export one NIF's complete records if that company moves to another tool or another advisor?
One calendar reminder to close: do not confuse any of this with Spain's mandatory B2B e-invoicing under the "Crea y Crece" law. That is a separate obligation, still pending rollout with a 2027 horizon (large companies first, everyone else a year later). What is already enforceable today, for every NIF you manage, is that each one invoices from a compliant SIF — chain intact, data properly walled off.
Want to sort it out today?
InvoSeal complies with RD 1007/2023 in VeriFactu and Non-VeriFactu mode from day one. Statement of Responsibility published.
Try InvoSeal →