eIDAS signature levels: simple, advanced and qualified
eIDAS recognises three levels of electronic signature: simple (SES), advanced (AES) and qualified (QES). Each level builds on the one below, and only the qualified signature is explicitly recognised as the equivalent of a handwritten signature throughout the EU. Here is what each level requires according to the text of the regulation, where the qualified seal and time stamp fit in, and how to choose.
Where the three levels come from
Regulation (EU) No 910/2014, known as eIDAS, defines the three levels in Article 3, points (10) to (12), and lists the requirements for an advanced signature in Article 26. It has applied in every Member State since 1 July 2016. Regulation (EU) 2024/1183, often called eIDAS 2, kept the three definitions unchanged and added Article 26(2), under which the Commission may set reference standards for advanced signatures: a signature that complies with them is presumed to meet the requirements.
Simple electronic signature (SES)
The base definition is broad: "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign". A typed name, a ticked box, a signature drawn on a touchscreen and a click confirmed with a one-time code are all electronic signatures in this sense. The regulation itself does not call them "simple": that is the name commonly given to any electronic signature that does not reach the advanced level.
Its legal effect comes from Article 25(1): it cannot be denied effect or admissibility as evidence just because it is electronic or not qualified. Its weight in a dispute depends on the evidence around it: who received the link, how they confirmed, when, from which device, and whether the document could have changed afterwards.
Advanced electronic signature (AES)
Article 26 sets four requirements. An advanced electronic signature must be:
- uniquely linked to the signatory;
- capable of identifying the signatory;
- created using signature creation data that the signatory can, with a high level of confidence, use under their sole control;
- linked to the signed data so that any subsequent change is detectable.
The regulation does not prescribe a technology. The European Commission notes that public-key infrastructure, with certificates and cryptographic keys, is the most common way to meet these requirements. Online signing platforms usually combine a reliable identification of the signer (for example an identity document check), a signing step under the signer's control (such as a one-time code) and cryptographic protection of the finished document. Some national laws attach extra effects to the advanced level: in Italy, for instance, it satisfies the written form requirement, as our guide to whether electronic signatures are legally binding explains.
Qualified electronic signature (QES)
A qualified electronic signature is an advanced signature that meets two further conditions (Article 3(12)): it is created by a qualified signature creation device, and it is based on a qualified certificate for electronic signatures. That certificate is issued by a qualified trust service provider, one that has been granted qualified status by a national supervisory body and appears in its country's trusted list. The device can be a smart card or a USB token, or a remote device managed by the provider, so that the signer does not need to hold any hardware.
The payoff is legal certainty. Under Article 25(2) a QES has the equivalent legal effect of a handwritten signature, and under Article 24a, inserted by the 2024 amendment, a QES based on a qualified certificate issued in one Member State is recognised as qualified in all the others. Some national rules require it: in Germany, for example, electronic form under § 126a BGB needs a qualified electronic signature.
Seals and time stamps: not signatures, but they matter
Two other eIDAS trust services often travel with a signature and are often confused with it.
- Electronic seal. Created by a legal person, not an individual, to ensure the origin and integrity of data (Article 3(24) and (25)). A qualified electronic seal enjoys a presumption of the integrity of the data and of the correctness of its origin (Article 35(2)).
- Electronic time stamp. Binds data to a particular time, as evidence that the data existed then (Article 3(33)). A qualified time stamp enjoys a presumption of the accuracy of its date and time and of the integrity of the data (Article 41(2)).
A qualified seal applied by a platform protects the document; it does not turn the signer's signature into a qualified one. The two answer different questions: the signature says who agreed, the seal and the time stamp say that the document has not changed since, and when.
Which level for which document?
Everyday agreements with no form requirement
Quotes, order confirmations, NDAs, service agreements, consents and internal approvals: a simple signature backed by a solid audit trail is usually proportionate, and a qualified seal and time stamp on the result make integrity and date much easier to prove.
Higher value, or a counterparty you have never met
When the risk is that someone later says "that was not me", identity is the weak point. An advanced signature with identity document verification is designed to address it.
Documents the law reserves to a qualified signature
Where national law requires a QES, or excludes electronic form altogether, no lower level will do. Check the rules of the country whose law governs the document before you send it.
Common mistakes
- Calling every e-signature a "digital signature". In everyday English the term usually means a certificate-based signature; it is not one of the three eIDAS levels.
- Mistaking the provider's seal for the signer's signature. A qualified seal on the PDF does not make it a QES.
- Keeping the PDF but not the evidence. With simple and advanced signatures, the audit trail is what proves who signed and how.
- Assuming the same rules apply outside the EU. The UK kept the same three definitions in its own version of the regulation, but other countries follow different laws.
The levels in DOCUJET
Every DOCUJET plan provides a simple electronic signature with a record of who signed, when and from where. From the Starter plan upwards, signers can confirm with a one-time code by SMS, and the signed document receives a qualified electronic seal and a qualified time stamp from Namirial, a qualified trust service provider. From the Business plan you can switch on the advanced electronic signature (AES) with identity verification. DOCUJET does not offer the qualified electronic signature. Read what an electronic signature is and how it works for a gentler introduction, and see the pricing page for plans.
Sources: Regulation (EU) No 910/2014 (eIDAS), Articles 3, 25, 26, 35, 41; Regulation (EU) 2024/1183, amending Articles 26 and inserting Article 24a; European Commission, What is eSignature; EU/EEA Trusted List Browser; § 126a BGB; UK version of Regulation 910/2014, Article 3.
Ready to try it?Open a free account: 3 documents a month, forever, with a complete audit trail.Start for free →
