Skip to content
KEDBYTE
How Identity Works
Chapter
33

What a Signature Means in Law

Part III · The Certificate and the Signature|13,985 words|about 61 min read|Volume 3
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

33.0 What this chapter gives you#

  1. You will be able to name the three legal tiers of electronic signature under European law, state the exact test each one has to pass, and say which of them the product you are building actually produces.
  2. You will be able to explain why a qualified electronic signature is the only one the law itself calls equal to a signature written by hand, and what that equality does and does not win you in a courtroom.
  3. You will be able to read the four conditions in Article 26 of Regulation 910/2014 and test a real product against them one by one, instead of accepting a vendor’s claim that a signature is “advanced”.
  4. You will be able to describe what a qualified signature creation device must guarantee, how it is certified, and why a server in a data centre can be one while a browser plug-in cannot.
  5. You will be able to find a named company on a national trusted list, follow the chain from that list back to the European list of lists, and say precisely what being on the list buys the company.
  6. You will be able to contrast the European tiered approach with the deliberately untiered approach of the United States, and explain why the same signature can be strong evidence in Berlin and weak evidence in California for reasons that have nothing to do with cryptography.
  7. You will be able to state what India’s Information Technology Act 2000 requires in sections 3 and 3A, name the authority that licenses the companies that issue signing certificates there, and say what changed in the exclusion list in September 2022.
  8. You will be able to say who has to prove what, under each of the four regimes in this chapter, when the other side says “that is not my signature”.
  9. You will be able to list, by jurisdiction and with the statute reference, the common documents that still cannot be signed electronically at all, and explain why that list is shrinking unevenly.
  10. You will be able to lay out the eIDAS 2.0 timeline with real dates, and say what obligation lands on which party on each of them.

A signature is not a thing. It is a claim about a person, made in a form that a court will accept as coming from that person. The paper version of that claim has had four hundred years of argument poured into it, and the argument produced rules that most people never see: rules about what counts as a signature, rules about who must prove it is genuine, rules about the handful of documents where nothing but ink on paper will do. The electronic version inherits all of that argument, and adds a new one, because the electronic version comes in tiers.

That is the whole point of this chapter. In the European Union, and in every country that copied its model, there are three legally distinct kinds of electronic signature. They are not three quality settings on the same dial. They are three different legal objects with three different tests, three different costs, three different consequences when somebody denies signing, and only one of them is declared by statute to be the equal of a signature written by hand. Most software, including most software sold on the strength of the word “compliant”, produces the weakest of the three. That is not always wrong. It is very often not understood.

The previous chapter, chapter 32, “The Digital Signature”, established the narrow true thing: a verified digital signature proves that a specific private key was applied to specific bytes, and everything else is inference. This chapter is about what a legal system does with that inference, which turns out to depend far more on paperwork, audits and registers than on mathematics. The chapter after this one, chapter 34, “Time, and Signatures That Must Outlive Their Keys”, deals with keeping a signature checkable for decades; we will touch that here in one line and leave it there.

We will build the argument on one document and carry it all the way through. It is a supply agreement between an Indian company and a German company, dated 12 March 2026, worth INR 42,00,000. We will sign it three ways, put it in front of three courts, and see exactly what each court is told, what each court presumes, and who has to stand up first and prove something.

The plain version#

Three counters in the same office#

Picture the registry office of a district town. It is one building, with one queue at the door, and inside there are three counters. All three of them will put your name on a document. They are not the same.

At the first counter there is a stack of forms and a pen on a string. You write your name in the box and hand the form in. Nobody looks up. Nobody asks who you are. The clerk stamps a date on it and files it. This costs nothing and takes a minute. If, two years later, somebody produces that form and you say “I never wrote that”, the argument is entirely open. Your handwriting is one piece of evidence. So is the fact that the form was posted from your street. So is the fact that you turned up at the town hall that morning, if anyone can show it. All of it is evidence, none of it settles anything, and a judge will weigh whatever the two sides can bring.

At the second counter there is a clerk who works for the office. Before she lets you sign, she asks for your identity card, looks at your face, writes the card number in a register beside your name, and watches you sign. She puts the register entry and the document together in one envelope and seals it. This takes twenty minutes and costs a small fee. Two years later, if you say “I never signed that”, the other side does not merely have your handwriting. It has a named clerk, a register entry, a card number, and a sealed envelope showing the document has not been swapped. You can still fight. It is a much harder fight.

At the third counter there is an officer appointed by the government. Her office is inspected every two years by inspectors who do not work for her. The list of offices allowed to run a third counter is published by the state and anybody can look at it. She checks your identity against the state register, not against the card you brought. She hands you a pen that belongs to the office, and the pen is the point: it is kept in a locked drawer, it never leaves the counter, and it is built so that only the person it was issued to can make it write. When you have signed, she stamps the document with the office seal and records it in a numbered book. This takes an appointment, a longer wait and a real fee. Two years later, if you say “I never signed that”, the law does not start from a blank sheet. The law starts from the position that you did sign, and it is you who must produce facts strong enough to shake it.

That third counter is the whole difference. Not the ink. Not the pen. The fact that somebody who is independently inspected checked you against a register, that the pen was under your control alone, and that the state published a list saying this office was allowed to do it.

What each counter costs and what it buys#

Everything in this chapter follows from a single trade. The more work is done before the signature, the less work has to be done after it, and the less of that after-work falls on the side trying to rely on the document.

At the first counter, all the work happens after. Somebody has to gather records, call witnesses, produce delivery logs and convince a judge. At the third counter, most of the work happened before, in front of a clerk, in a register, under an inspection regime, and the judge starts from the answer.

The second counter sits between them, and it is where most of the real world lives, because it is where the ratio of cost to benefit is best for ordinary business. It is also the counter that is easiest to fake the appearance of. Anyone can print a form that says “identity verified”. Whether an identity was actually verified, by whom, against what, and whether the pen was really under your sole control, is a question about the office and not about the piece of paper it hands you.

Here is the trade written out.

Counter Work done before Work done after
First None All of it, by the claimant
Second Identity checked once Some, by the claimant
Third Checked, sealed, listed Some, by the denier

Read the right-hand column twice. At the third counter the direction of the work reverses. That reversal is worth more than every cryptographic property in the previous chapter put together, and it is bought with paperwork.

A worked example: the disputed order#

Take a real shape of argument. On 12 March 2026 an Indian supplier and a German buyer agree a supply contract worth INR 42,00,000, payable in three instalments. The document is eleven pages. It is signed electronically by one named person on each side. Delivery starts. In August the buyer refuses the second instalment and says the agreed price was lower, and that the version the supplier is waving about is not the version anybody signed.

Now count what each side has to do, under each counter.

If the signature came from the first counter, the supplier has to prove everything: that the person named actually applied the mark, that the eleven pages in its hand are the eleven pages that were marked, and that the person had authority. It will do this with server logs, emails, a record of the click, an internet address, and a witness from its own sales team. All of that is admissible. None of it is conclusive. The case turns on whose story the judge finds more believable, and it costs both sides months.

If the signature came from the second counter, the supplier can also show that an independent company checked the signer’s passport before issuing him the means of signing, and that the eleven pages cannot have changed since, because any change would show. The buyer’s story now has to explain away an identity check by a company with no interest in the outcome. It is still an open argument, but it is a narrower one.

If the signature came from the third counter, the supplier does something much shorter. It shows that the signing device was one certified by a national body, that the company that issued the signer’s credentials was on the published state list on 12 March 2026, and that the check comes out clean. The German court’s starting position flips: the declaration is taken to be the signer’s own, and the buyer must bring facts that raise serious doubt about that. Not arguments. Facts.

Same document, same eleven pages, same date. Three different lawsuits.

What the three counters are actually called#

Now the names, in plain words, because from here on the rest of the world uses them.

The first counter produces what European law calls a simple electronic signature: any data in electronic form attached to other data and used by the signer to sign. A typed name, a scanned image of a signature, a tick in a box, a finger drawing on a phone screen. The law’s only promise about it is that it cannot be thrown out of court just for being electronic.

The second counter produces an advanced electronic signature: one that is tied to a single signer, can identify that signer, is made with something the signer alone controls, and is linked to the document so that any later change shows up.

The third counter produces a qualified electronic signature: an advanced one, made with a certified device, using credentials from a company that the state has inspected and put on a published list. This is the only one that the statute itself declares to be equal to a signature written by hand.

One more plain fact before we take the analogy apart. Three counters exist in Europe, in the United Kingdom, in Switzerland, in India in a different shape, and in a growing number of other places. They do not exist in the United States at all. American law made a deliberate decision in the year 2000 to have exactly one counter, to write no technology into the statute, and to leave every question of quality to the judge and the evidence. Which approach is better is a real disagreement between serious people, and we will give both sides properly later in this chapter.

Where the plain version stops being true#

The counters are not a ladder that every country climbs#

The picture of three counters in one office suggests a universal building. There is no universal building. The three-counter model is European law, written into Regulation (EU) No 910/2014, and copied by choice into other legal systems. It is not a description of how signatures work everywhere.

The honest version: the United States has one counter and no tiers at all. Under the federal ESIGN Act of 2000 and the state-level Uniform Electronic Transactions Act, an electronic signature is an electronic sound, symbol or process attached to a record and executed with intent to sign, and that is the end of the definition. There is no advanced tier to climb to and no qualified tier above it. Everything that Europe front-loads into certification, the United States leaves to the ordinary law of evidence, decided case by case. A tick in a box and a smart-card signature are the same legal object there, and differ only in how convincing they are on the day.

India built something in between and did it earlier than Europe’s current law: a licensing regime for certificate issuers dating from 2000, one legally privileged technique, and later a second tier layered on top. The United Kingdom inherited the European model in 2016, kept it after leaving the European Union, and then let it drift.

“Equal to a handwritten signature” is a smaller sentence than it looks#

The plain version says the third counter’s product is equal to a signature written by hand. That is exactly what Article 25(2) of the Regulation says. It is also much less than most engineers hear in it.

The honest version: equality with a handwritten signature does not mean the document is valid, that the terms are enforceable, that the signer had authority to bind the company, or that the signer read anything. It means one narrow thing: wherever the law requires “a signature”, this satisfies it, and nobody may say the requirement was unmet because the signature was electronic. Every other objection survives untouched. A handwritten signature obtained by fraud is void; so is a qualified one. A handwritten signature by a person with no authority does not bind the company; neither does a qualified one. The tier decides one question only, and it is the question of the mark, not the question of the deal.

The office does not check you every time you sign#

In the analogy, the clerk at the second and third counters looks at your face each time. Real systems do not work that way, and the gap matters.

The honest version: identity is checked once, when your credentials are issued, and that check is then relied on for every signature until the credentials expire or are revoked. A qualified certificate is typically valid for one to three years. Everything that happens in between rests on the assumption that whatever protects the signing key, a card and a code, a phone and a fingerprint, is still in the right hands. This is why the rules about the signing device are so heavy, and it is also why remote signing, where the key lives on a company’s server rather than in your pocket, needed a separate set of rules before it could count as qualified at all.

Form requirements are a separate law and they survive#

The three counters suggest that if you climb high enough, anything can be signed electronically. That is not so, and the Regulation says so in its own text.

The honest version: Article 2(3) of Regulation 910/2014 states that the Regulation does not affect national or Union law related to the conclusion and validity of contracts or other legal or procedural obligations relating to form. Signature law and form law are two different bodies of rule sitting side by side. Signature law says what counts as a signature. Form law says whether this kind of document needs a signature at all, needs a witness, needs a notary, needs to be recorded in a public register, or needs to be on paper and nothing else. A qualified electronic signature satisfies signature law completely and does nothing whatever to form law. In Germany a contract of suretyship given by a private person requires the written form and the electronic form is expressly excluded, and a qualified signature cannot cure that. In India, until September 2022, a contract for the sale of immovable property sat outside the Information Technology Act altogether.

The published list is a national list, not a world list#

The plain version says the state publishes a list of offices allowed to run a third counter. True, but each state publishes its own.

The honest version: trusted lists are national. The European Union stitches them together with a list of lists, and the Regulation makes every member state recognize every other member state’s qualified signatures, so within the Union the effect is one list. Outside it, there is no automatic bridge. Since the end of the Brexit transition period on 31 December 2020, the United Kingdom recognizes European Union qualified trust services, but the European Union does not recognize United Kingdom ones, because recognition of a third country requires an agreement and, as of August 2026, there is none. A British qualified signature is a qualified signature in London and an ordinary advanced signature in Lisbon. Nothing about the signature changed; the list it appears on did.

The tier is a property of the moment of signing, not of the file#

The analogy makes the tier feel like a stamp on the document. It is not.

The honest version: whether a signature is qualified is a statement about conditions that held at one instant: the certificate was qualified then, the issuer was on the list then, the device was certified then, and the four advanced-signature conditions were met then. Article 32 of the Regulation spells out the checks in exactly those terms, and several of them are expressed as “at the time of signing”. A certificate that expires next year does not make last year’s signature retroactively simple. Equally, a file that looks qualified today may fail validation tomorrow because the evidence needed to prove those past conditions has gone missing. Preserving that evidence is the subject of chapter 34, “Time, and Signatures That Must Outlive Their Keys”, and we leave it there.

Most software is at the first counter and says otherwise#

The last and most practical place the plain version misleads. It suggests that if you have bought a product with a legal-sounding name, you are somewhere up the ladder.

The honest version: as of August 2026 the default flow in the mass-market electronic signature platforms produces a simple electronic signature with a detailed audit trail attached. The audit trail is genuinely useful evidence. It is not a tier. A platform that generates one server-held key for itself, signs on the customer’s behalf, and records the signer’s name, address and click time in a report has not met the sole-control condition of an advanced signature, because the signer never controlled any signing data. Advanced and qualified signing are usually available from the same vendors as separately priced products that require an identity check on the signer. Whether your own deployment uses them is a question you can answer in an afternoon, and most teams have never asked it.

The technical version#

Regulation 910/2014 and the three definitions, exactly#

The instrument is Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. It was published in the Official Journal on 28 August 2014, entered into force on the twentieth day after publication, and applied from 1 July 2016. Everybody calls it eIDAS. It is a regulation and not a directive, which is the first technical fact that matters: it took effect in every member state directly, without national transposition, so the definitions below are the same words in twenty-seven countries.

The three tiers are defined in Article 3. They are nested; each is the one below it with something added.

An electronic signature, defined in Article 3(10), is “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign”. Nothing in that sentence requires cryptography, a certificate, or any check on anybody. A typed name qualifies. This tier is usually written SES, for simple electronic signature, though the Regulation itself never uses the word “simple”.

An advanced electronic signature, Article 3(11), is an electronic signature which meets the requirements set out in Article 26. Written AES.

A qualified electronic signature, Article 3(12), is “an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures”. Written QES. Two extra components, both defined elsewhere in the Regulation, both requiring an external body to have done work.

Article 25 states the legal effects, and it is short enough to hold in your head. Paragraph 1: an electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures. Paragraph 2: a qualified electronic signature shall have the equivalent legal effect of a handwritten signature. Paragraph 3: a qualified electronic signature based on a qualified certificate issued in one member state shall be recognized as a qualified electronic signature in all other member states.

Notice what Article 25 does not say. It says nothing about the advanced tier. An advanced electronic signature gets exactly the same statutory promise as a typed name: it cannot be rejected for being electronic. Every advantage the advanced tier has over the simple tier is evidential rather than statutory, and it is delivered by national procedural law, by the facts of the case, and by what the parties can show. That is a surprise to most engineers, who assume the middle tier carries some middle amount of legal privilege written into the Regulation. It does not. In the Regulation the ladder has two rungs of legal effect and three rungs of technical requirement.

Tier Regulation text Legal effect given
SES Article 3(10) Not deniable for e-form
AES Articles 3(11), 26 The same, and no more
QES Articles 3(12), 25(2) Equals a handwritten sig

One further article shapes the market more than its length suggests. Article 27 governs electronic signatures in public services. If a member state requires an advanced signature to use an online public-sector service, it must recognize advanced signatures, advanced signatures based on a qualified certificate, and qualified signatures, in at least the formats defined by implementing act. Article 27(3) forbids member states from demanding anything above qualified for cross-border use. That is the ceiling: no public body in the Union may invent a fourth tier and insist on it.

Article 26: the four conditions, tested against a real product#

Article 26 is four lines and it is the most useful test in this chapter, because it is the one you can run against a system you are actually responsible for. An advanced electronic signature shall meet the following requirements:

  1. it is uniquely linked to the signatory;
  2. it is capable of identifying the signatory;
  3. it is created using electronic signature creation data that the signatory can, with a high level of confidence, use under his sole control; and
  4. it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable.

Take a common architecture and hold it against those four. A software product signs documents on behalf of its customers using one private key held in the product’s own hardware security module. When a signer clicks “Agree”, the platform records the name, the electronic mail address, the internet address, a timestamp and a one-time code sent to a telephone, then signs the resulting package with the platform key and issues a PDF with an audit page appended.

Condition (a) fails: the signature is uniquely linked to the platform, not to the signer, because the same key signs for everyone. Condition (b) is at best indirect: the certificate identifies the platform; the signer is identified only by the contents of the audit page, which the platform itself wrote. Condition (c) fails outright: the signer never held or controlled any signature creation data. Condition (d) passes: the document cannot be changed without detection. One out of four. This is a simple electronic signature with good evidence attached, and it should be described that way in your own documentation, whatever the invoice from the vendor says.

Now change one thing. The platform, instead of signing with its own key, asks a trust service provider to generate a key pair for the individual signer after that provider has checked the signer’s passport by video, and the private key is held in a module that only releases it on a signal derived from something the signer knows or holds. Now (a) and (b) pass, (c) passes if and only if the release mechanism really is under the signer’s sole control, and (d) still passes. That is an advanced electronic signature, and the whole weight of the claim now rests on the word “sole” in condition (c).

That word is where the standards live. Sole control over a key held on a server is not obviously possible at all, and the European standards bodies took years to define a system where it is: ETSI EN 419 241-1 sets the general requirements for trustworthy systems supporting server signing, and ETSI EN 419 241-2 is the protection profile for a qualified signature creation device for server signing. If you are running remote signing and cannot name the mechanism that gives one human sole control of one key, you do not have an advanced signature, you have a shared key with an access-control list.

The qualified certificate: Annex I, Article 28, and the statements inside#

A qualified certificate for electronic signatures is defined by two things: who issued it and what it contains. Article 28(1) requires it to meet Annex I. Article 28(2) forbids member states from adding mandatory requirements beyond Annex I, which is what stops twenty-seven national dialects from appearing. Article 28(4) says that once a qualified certificate is revoked after initial activation it loses validity from the moment of revocation and its status shall not in any circumstances be reverted. Article 28(5) allows member states to permit temporary suspension, with the suspension period clearly indicated in the certificate database.

Annex I lists nine required elements. In summary, a qualified certificate for electronic signature must contain an indication, in a form suitable for automated processing, that it was issued as a qualified certificate for electronic signature; a set of data unambiguously representing the issuing qualified trust service provider; at least the name of the signatory or a pseudonym, with any pseudonym clearly indicated; the signature validation data corresponding to the signature creation data; the beginning and end of the validity period; a certificate identity code unique to the provider; the advanced signature or seal of the issuing provider; the location where the certificate supporting that signature or seal is available free of charge; and the location of the services that can be used to enquire about the validity status of the certificate.

The first of those is worth expanding, because it is the machine-readable marker that tells a validator it is holding a qualified certificate rather than an ordinary one. It is carried in an X.509 extension called QCStatements, profiled in ETSI EN 319 412-5, version 2.3.1 of April 2020. The statements are object identifiers under the arc 0.4.0.1862.1.

QCStatements extension, values under 0.4.0.1862.1

  0.4.0.1862.1.1   QcCompliance
                   "this is an EU qualified certificate"
  0.4.0.1862.1.2   QcLimitValue     transaction value limit
  0.4.0.1862.1.3   QcRetentionPeriod
  0.4.0.1862.1.4   QcSSCD
                   "the key is in a qualified device"
  0.4.0.1862.1.5   QcPDS            disclosure statement URLs
  0.4.0.1862.1.6   QcType           what kind of qualified cert

QcType values
  0.4.0.1862.1.6.1  esign   signature by a natural person
  0.4.0.1862.1.6.2  eseal   seal by a legal person
  0.4.0.1862.1.6.3  web     website authentication

Two of those decide the tier. QcCompliance, 0.4.0.1862.1.1, is the assertion that the certificate is a qualified certificate. QcSSCD, 0.4.0.1862.1.4, is the assertion that the corresponding private key sits in a qualified signature creation device. A signature made with a certificate carrying QcCompliance and QcType esign but not QcSSCD is not qualified; it is an advanced signature based on a qualified certificate, which is a real and distinct thing named in Article 27 and worth less than a qualified signature. This single missing object identifier is the most common reason that a signature a company believes is qualified turns out not to be.

The policy rules that a provider must follow to issue these certificates are in ETSI EN 319 411-2, which builds on the general trust service provider policy requirements in ETSI EN 319 401. Those are standards, in the strict sense used in this book: documents you can buy and read, against which an auditor can test a provider. Compliance with them is not itself the law; the law is the Regulation, and the standards are the agreed way of showing you met it.

The qualified signature creation device and what it must guarantee#

Annex II is the shortest important text in European signature law. A qualified electronic signature creation device, universally abbreviated QSCD, must ensure by appropriate technical and procedural means at least that the confidentiality of the signature creation data used for signature creation is reasonably assured; that the signature creation data used for signature creation can practically occur only once; that the signature creation data cannot, with reasonable assurance, be derived, and that the signature is reliably protected against forgery using currently available technology; and that the signature creation data can be reliably protected by the legitimate signatory against use by others.

Annex II point 2 adds a requirement that is about the human being rather than the key: qualified signature creation devices shall not alter the data to be signed or prevent such data from being presented to the signatory prior to signing. That is the legal form of the problem chapter 32 called “what you see is not what you sign”. Annex II point 3 restricts who may hold your key for you: generating or managing electronic signature creation data on behalf of the signatory may only be done by a qualified trust service provider. Annex II point 4 permits such a provider to duplicate the signature creation data for back-up purposes only, provided the duplicates carry the same security level and their number does not exceed the minimum needed for continuity of service.

Those four points, read together, are what makes remote qualified signing legal at all, and they draw a hard line around it. Your key may live on somebody else’s server, but only if that somebody is a qualified provider, only if the copies are backups and not conveniences, and only if you retain sole control.

Article 29 makes Annex II binding. Article 30 sets out certification: conformity with Annex II shall be certified by appropriate public or private bodies designated by member states, and the certification must be based either on a security evaluation process carried out under a standard from a Commission list, or on another process using comparable security levels which the designated body has notified to the Commission, usable only where the listed standards do not cover the case or an evaluation is in progress. Article 31 requires member states to notify the Commission of every certification within one month, and every cancellation within one month, and requires the Commission to publish and maintain the list of certified devices.

The Commission list of evaluation standards is Commission Implementing Decision (EU) 2016/650 of 25 April 2016, published in the Official Journal on 26 April 2016, laying down standards for the security assessment of qualified signature and seal creation devices under Articles 30(3) and 39(2) of the Regulation. It repealed the older Decision 2003/511/EC. Its annex points at the Common Criteria family, ISO/IEC 15408-1:2009, 15408-2:2008 and 15408-3:2008 with the evaluation methodology ISO/IEC 18045:2008, and at the European protection profiles for secure signature creation devices in the EN 419211 series.

Standard Covers
EN 419211-1:2014 Overview
EN 419211-2:2013 Device with key generation
EN 419211-3:2013 Device with key import
EN 419211-5:2013 Signature creation application

The practical shape of this for an engineer is simple to state and expensive to satisfy. A QSCD is a smart card, a USB token, a SIM, or a hardware security module in a data centre that has been through a Common Criteria evaluation against one of those protection profiles, by a laboratory, under a national scheme, with the result notified to the Commission by a designated body. It is not a software key store. It is not a key in a cloud key management service unless that specific configuration has been certified. It is not a passkey in a phone’s secure element, however good that element is, unless somebody paid for the evaluation and the member state notified it.

Qualified trust service providers, supervision and the trusted list#

A trust service provider under Article 3(19) is a natural or legal person who provides one or more trust services either as qualified or non-qualified. A qualified trust service provider, Article 3(20), is one who provides one or more qualified trust services and has been granted the qualified status by the supervisory body. That last clause is doing all the work: qualified status is granted, by a named national body, and it can be taken away.

The route in is Article 21. A provider intending to start a qualified service submits a notification to the supervisory body together with a conformity assessment report issued by a conformity assessment body, and the supervisory body verifies compliance and, if satisfied, grants qualified status and has the provider and the services entered on the trusted list not later than three months after notification. Once running, Article 20(1) requires the provider to be audited at its own expense at least every 24 months by a conformity assessment body, and to submit the resulting report to the supervisory body. Article 19(2) requires notification of any breach of security or loss of integrity with a significant impact within 24 hours of becoming aware of it.

Article 22 requires each member state to establish, publish and maintain trusted lists, including information relating to the qualified trust service providers for which it is responsible together with information about the qualified services they provide, in a secured manner, electronically signed or sealed, and in a form suitable for automated processing. The technical format is set by Commission Implementing Decision (EU) 2015/1505 of 8 September 2015, which points at the ETSI specification TS 119 612.

The lists have what lawyers call constitutive effect. A provider is not qualified because it is good, or because it says it is; it is qualified because it appears, as qualified, on a trusted list. If the entry is not there on the day you signed, you did not make a qualified signature that day, whatever the software displayed.

Above the national lists sits one more file. The Commission publishes a list of the lists, universally called the LOTL, which carries the location and the signing certificates of each national list. A validator that wants to answer “was this issuer qualified on 12 March 2026” walks that chain downwards.

      European Commission
    List of Trusted Lists (LOTL)
    signed, published centrally
                |
    +-----------+-----------+-----------+
    |           |           |           |
  DE list     NL list     IE list    ... 27
  signed by   signed by   signed by
  DE scheme   NL scheme   IE scheme
    |
  Trust service provider entry
    ServiceTypeIdentifier: CA/QC
    ServiceStatus: granted
    StatusStartingTime: a date
    X.509 certificate of the CA
    |
  Qualified certificate for the signer
    QcCompliance + QcSSCD + QcType esign
    |
  The signature on the document

An entry inside a national list is XML, and the two fields that decide everything are the service type and the status.

<TSPService>
 <ServiceInformation>
  <ServiceTypeIdentifier>
   http://uri.etsi.org/TrstSvc/Svctype/CA/QC
  </ServiceTypeIdentifier>
  <ServiceStatus>
   http://uri.etsi.org/TrstSvc/TrustedList/
   Svcstatus/granted
  </ServiceStatus>
  <StatusStartingTime>
   2019-11-04T00:00:00Z
  </StatusStartingTime>
 </ServiceInformation>
</TSPService>

Note the StatusStartingTime. Status is a history, not a flag. A list records when a service became granted, and, if it happened, when it was withdrawn, which is exactly what a validator needs in order to answer a question about a signature made two years ago.

To make this concrete, take one country’s list as it stood when this chapter was written. The Netherlands trusted list, read in August 2026, carried nine providers with active entries, among them CIBG, Cleverbase ID B.V., DigiCert Europe Netherlands B.V., Digidentity B.V., KPN B.V. and two Dutch ministries, along with several historical entries whose services are no longer active, including DigiNotar B.V., the certificate authority that collapsed in 2011 after an intrusion and whose entry is now a tombstone in the file. The European list of lists itself carried an issue date of 3 August 2026. Those numbers move; the shape does not.

Two limits are worth stating plainly. First, being on a trusted list is a statement about a company and a service, not about any individual signature. Second, the Regulation places no obligation on browser vendors or document readers to consult trusted lists at all, so whether a piece of software shows you a green tick has nothing necessarily to do with the legal tier of what you are looking at.

Validation under Article 32, and the report a court is handed#

Article 32(1) lists what the process of validating a qualified electronic signature must confirm. The certificate that supported the signature was, at the time of signing, a qualified certificate complying with Annex I; it was issued by a qualified trust service provider and was valid at the time of signing; the signature validation data corresponds to the data provided to the relying party; the unique set of data representing the signatory in the certificate is correctly provided to the relying party; the use of a pseudonym is clearly indicated if one was used; the signature was created by a qualified electronic signature creation device; the integrity of the signed data has not been compromised; and the requirements in Article 26 were met at the time of signing.

Article 32(2) adds a requirement about the tool rather than the signature: the system used for validating must give the relying party the correct result of the validation process and allow the relying party to detect any security relevant issues. Article 33 defines a qualified validation service, which may be provided only by a qualified trust service provider and which must return results in an automated, reliable and efficient manner bearing the provider’s own advanced signature or seal. Article 34 defines a qualified preservation service for keeping the trustworthiness of a qualified signature beyond the technological validity period, which is the subject of chapter 34.

The report produced by a validator follows the procedures in the ETSI standard EN 319 102-1, whose three top-level results are what an expert witness will actually put in front of a court.

Validation report, worked example
  Document : supply-agreement-2026-03-12.pdf
  Signature: PAdES, detached CMS in /Contents
  Digest   : SHA-256
  Claimed signing time: 2026-03-12T09:14:07Z

  Main indication      : TOTAL-PASSED
  Signing certificate  : qualified (QcCompliance)
  QSCD asserted        : yes (QcSSCD)
  Issuer on trusted list at signing time: yes
  Revocation at signing time : good (OCSP)
  Article 26 conditions      : met
  Conclusion : qualified electronic signature

Change one line of that report and the legal conclusion changes with it. Drop QcSSCD and the conclusion becomes “advanced electronic signature based on a qualified certificate”. Drop QcCompliance as well and it becomes “advanced electronic signature”, assuming sole control can be shown. Fail the trusted list check at signing time and it becomes, at best, an advanced signature whatever the certificate claims about itself, because the qualified status of the issuer is a fact about the list and not a fact about the certificate.

A validator may also return TOTAL-FAILED, which means the signature is broken or the document changed, or INDETERMINATE, which means the validator could not obtain enough material to decide, usually because revocation information or a trusted timestamp is missing. INDETERMINATE is the most misread result in the field: it is not a failure, and it is not a pass. It is the tool saying that the question has not been answered, and a court that is handed an INDETERMINATE report is back to weighing ordinary evidence.

Burden of proof: who must prove what, under each regime#

This is where the tiers stop being a technical hierarchy and start being money. Three separate burden questions get confused with each other, and they need separating before any of them can be answered.

The first is the burden on the person relying on the document: must they prove the signature is genuine, or is it taken as genuine until challenged? The second is the burden on the trust service provider if its own failure caused a loss. The third is the burden on the party who wants to have the document admitted as evidence at all, which is a question of procedure and differs by court more than by country.

On the second question the Regulation is explicit and symmetrical, and it is one of the clearest incentives in the whole instrument. Article 13 provides that trust service providers are liable for damage caused intentionally or negligently to any person due to a failure to comply with the obligations under the Regulation, and then splits the proof. The burden of proving intention or negligence of a non-qualified trust service provider lies with the person claiming the damage. The intention or negligence of a qualified trust service provider is presumed unless that provider proves that the damage occurred without its intention or negligence. Article 13(2) allows a provider to limit liability where it has properly informed customers in advance of the limitations, and Article 13(3) says the whole thing is applied according to national rules on liability.

On the first question the Regulation is deliberately quiet, and national procedural law fills the gap. Germany is the cleanest illustration because it wrote the rule down. Section 371a(1) of the Zivilprozessordnung, the German code of civil procedure, provides that the rules on the evidential value of private documents apply correspondingly to private electronic documents bearing a qualified electronic signature, and then continues: the appearance of authenticity of a declaration in electronic form, arising from verification of the qualified electronic signature under Article 32 of Regulation (EU) No 910/2014, can only be shaken by facts which give rise to serious doubt that the declaration was made by the responsible person.

Read that carefully, because it is the practical content of Article 25(2) in one national system. It does not say the signature is conclusive. It says the appearance of authenticity can be displaced only by facts raising serious doubt. Denial is not enough. Speculation is not enough. The party denying the signature must bring facts. For an advanced or simple signature, German procedure applies the ordinary rule of free evaluation of evidence, and the judge weighs everything without any starting presumption.

Regime Denier’s position on QES On SES or AES
Germany, ZPO 371a Must show serious doubt Free evaluation
EU, Article 13 QTSP must disprove fault Claimant proves fault
US, UETA s.9 No tiers; attribution proved Same test
India, BSA s.86 Secure signature presumed No presumption

The United States: one counter, on purpose#

American federal law on this subject is the Electronic Signatures in Global and National Commerce Act, Public Law 106-229, enacted 30 June 2000 and generally effective 1 October 2000, codified at 15 U.S.C. 7001 and following, with the record retention provisions effective 1 March 2001. The operative sentence in section 7001(a) is that with respect to any transaction in or affecting interstate or foreign commerce, a signature, contract or other record relating to such transaction may not be denied legal effect, validity or enforceability solely because it is in electronic form.

Beside it sits the Uniform Electronic Transactions Act, drafted by the Uniform Law Commission in 1999 and enacted state by state. UETA section 7 carries the same non-discrimination rule. UETA section 2 defines an electronic signature as an electronic sound, symbol or process attached to or logically associated with a record and executed or adopted by a person with the intent to sign the record. That definition contains no cryptography, no certificate, no device, and no tier.

The adoption position, as of August 2026, is that UETA is in force in 49 states, the District of Columbia, Puerto Rico and the United States Virgin Islands. Washington enacted it in 2020 and Illinois in 2021, leaving New York as the only state that has not, governed instead by its own Electronic Signatures and Records Act, article III of the State Technology Law, sections 301 to 309. The New York City Bar Association has repeatedly urged the state legislature to align that act with UETA, most recently in a committee report carried on its site in 2026.

ESIGN section 7003 carves out categories rather than technologies. Section 7001 does not apply to a statute, regulation or other rule of law governing the creation and execution of wills, codicils or testamentary trusts; to a state law governing adoption, divorce or other matters of family law; or to the Uniform Commercial Code other than sections 1-107 and 1-206 and Articles 2 and 2A. Section 7003(b) further excludes court orders, notices and official court documents; notices of cancellation of utility services; notices of default, acceleration, repossession, foreclosure or eviction under a credit agreement or a rental agreement for a primary residence; cancellation of health or life insurance benefits; product recall notices; and any document required to accompany the transport or handling of hazardous materials, pesticides or other toxic or dangerous materials.

Because there are no tiers, everything the European system decides in advance gets decided in the courtroom, under the ordinary law of evidence, and it is decided against whoever is trying to rely on the signature. UETA section 9 states the attribution rule: an electronic signature is attributable to a person if it was the act of the person, which may be shown in any manner, including a showing of the efficacy of any security procedure applied.

That sentence has real teeth, and one case shows them well. In Ruiz v. Moss Bros. Auto Group, decided by the California Court of Appeal, Fourth Appellate District, on 23 December 2014, an employer sought to compel arbitration on the strength of an electronically signed agreement. The employee said he did not recall signing it. The employer’s manager stated that he had. Under California Civil Code section 1633.9(a), the state’s enactment of UETA section 9, the court held that the employer had not carried its burden: it never explained how the electronic signature was created, how the system attributed it to that employee, or how the manager knew. A timestamp and a printed name were not enough. The petition failed.

The lesson generalizes past California. In a technology-neutral system the security procedure is not a legal tier but it is the evidence, and a party that cannot describe its own signing system in detail loses cases it should have won. Where Europe makes you buy the evidence in advance from an audited provider, the United States makes you build and document it yourself and produce it later, under oath. Experts genuinely disagree about which is better. The European side argues that predictable evidence lowers the cost of cross-border trade and protects the weaker party; the American side argues that tiers freeze one generation’s technology into law and hand a licensed industry a rent, and points out that the American market for electronic signature adopted faster and more widely under the neutral rule. Both observations are true at once.

India: sections 3 and 3A, the Controller, and eSign#

India legislated early. The Information Technology Act 2000 is Act 21 of 2000, enacted on 9 June 2000 and brought into force on 17 October 2000 by notification G.S.R. 788(E). It was substantially rewritten by the Information Technology (Amendment) Act 2008, which is Act 10 of 2009 and came into force on 27 October 2009. The signature provisions sit in two sections that do different jobs and are constantly confused with one another.

Section 3 is the original, technology-specific provision. Section 3(1): any subscriber may authenticate an electronic record by affixing his digital signature. Section 3(2): the authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record. That is a statute naming public-key cryptography and hashing in its own text, in the year 2000, which almost no other legislature did.

Section 3A was inserted in 2009 to loosen that. Section 3A(1): notwithstanding anything contained in section 3, a subscriber may authenticate any electronic record by such electronic signature or electronic authentication technique which is considered reliable, and may be specified in the Second Schedule. Section 3A(2) sets out when a technique is considered reliable: the signature creation data or authentication data are, within the context in which they are used, linked to the signatory and to no other person; those data were, at the time of signing, under the control of the signatory and of no other person; any alteration to the electronic signature made after affixing is detectable; any alteration to the information made after its authentication is detectable; and it fulfils such other conditions as may be prescribed.

Read section 3A(2) beside Article 26 of eIDAS. They are close cousins: unique linkage, sole control, detectability of change. India’s list is the one from the UNCITRAL Model Law on Electronic Signatures of 2001, and Europe’s derives from the 1999 Electronic Signatures Directive; both descend from the same international drafting effort.

The crucial Indian difference is section 3A(1)(b). A technique is usable only if it “may be specified in the Second Schedule”. The Second Schedule is a closed list, amendable by the central government by notification, and for most of the Act’s life it was empty. It now contains two entries. The first, “e-authentication technique using Aadhaar or other e-KYC services”, was inserted by G.S.R. 61(E) of 27 January 2015 and widened beyond Aadhaar by S.O. 1119(E) of 1 March 2019. The second, covering an e-authentication technique and procedure for creating and accessing a subscriber’s signature key facilitated by a trusted third party, was inserted by S.O. 3472(E) of 29 September 2020.

The consequence is worth stating flatly, because it is the opposite of the American position. In India, a signing technique that is not in section 3 and not in the Second Schedule is not an electronic signature under the Act at all. A typed name or a drawn squiggle is evidence of agreement, and a contract concluded that way is not unenforceable merely for being electronic, because section 10A protects contract formation by electronic means. But it does not satisfy a statutory requirement for a signature under section 5, which recognizes electronic signatures where the record is authenticated by means of an electronic signature affixed in the manner prescribed by the central government.

The institutional machinery is the Controller of Certifying Authorities, appointed under section 17 by the central government. The Controller licenses Certifying Authorities, which issue the certificates used for digital signatures under section 3, and section 35 governs applications for certificates, with a statutory fee ceiling of INR 25,000. As of August 2026, the Controller’s published list carried 23 licensed Certifying Authorities, including Safescrypt, IDRBT, (n)Code Solutions, e-Mudhra, CDAC, Capricorn, Protean, CSC and, unusually, the Indian Army, the Indian Navy, the Indian Air Force and Assam Rifles.

Section 15 defines a secure electronic signature, and this is the tier boundary in Indian law. An electronic signature is deemed secure if, at the time of affixing, the signature creation data was under the exclusive control of the signatory and of no other person, and was stored and affixed in the prescribed exclusive manner. Everything evidential turns on that word.

The eSign service is India’s answer to the same problem remote signing answers in Europe, and its design is worth studying. An Application Service Provider integrates an interface offered by a licensed Certifying Authority. The signer is identified by an electronic know-your-customer check, most often against Aadhaar. The Certifying Authority then generates a key pair for that signer inside a hardware security module, issues a very short-lived Digital Signature Certificate, uses the key once, and destroys it. The Controller’s own description of the benefits is that the private keys are created on a hardware security module and destroyed immediately after one time use, with short validity certificates and no concerns about key storage. It is a per-signature key, born and killed inside an audited device, which is a genuinely different architecture from the European model of a long-lived credential held by the signer.

Evidence law changed underneath all of this on 1 July 2024, when the Bharatiya Sakshya Adhiniyam 2023, Act 47 of 2023, which received assent on 25 December 2023, replaced the Indian Evidence Act 1872. The relevant provisions carried across with new numbers. Section 63 governs the admissibility of electronic records and carries the certificate requirement that practitioners knew as section 65B. Section 66 provides that except in the case of a secure electronic signature, if the electronic signature of a subscriber is alleged to have been affixed to an electronic record, the fact that it is that subscriber’s signature must be proved. Section 73 lets the court direct production of the Digital Signature Certificate and application of the public key in order to verify a digital signature. Section 85 presumes that an electronic record purporting to be an agreement containing the electronic or digital signature of the parties was so concluded. Section 86 carries the presumptions about secure electronic records and secure electronic signatures. Section 93 allows a court to presume, for an electronic record five years old produced from proper custody, that the electronic signature was affixed by the person it purports to be.

Section 66 is the burden rule in one sentence. Secure electronic signature: no proof needed to start. Anything else: prove it.

The United Kingdom: section 7, retained law, and the case law#

The United Kingdom has two overlapping layers and a habit of common-law pragmatism that makes the tiers matter less than they do across the Channel.

The base layer is the Electronic Communications Act 2000. Section 7 provides that in any legal proceedings an electronic signature incorporated into or logically associated with a particular electronic communication or particular electronic data, and the certification by any person of such a signature, shall each be admissible in evidence in relation to any question as to the authenticity or the integrity of the communication or data. Section 7(2)(b) and section 7(3) were amended on 22 July 2016 by the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016, which is the instrument that plugged eIDAS into United Kingdom law. Section 8 of the Act gives ministers a power to modify other legislation to authorize or facilitate electronic form, which is how a long list of specific statutory paper requirements has been unpicked one at a time.

Note what section 7 does and does not do. It makes electronic signatures admissible. It does not tell a court what weight to give them, and it creates no tiers at all. That is the ordinary common-law position: admissibility is cheap, weight is everything.

The second layer is retained European law. On leaving the European Union the United Kingdom kept Regulation 910/2014 in domestic law, amended by the Electronic Identification and Trust Services for Electronic Transactions (Amendment etc.) (EU Exit) Regulations 2019. The three tiers therefore still exist in the United Kingdom, with the same definitions. Article 22 as amended reads differently from the European version: the Secretary of State must make arrangements for the maintenance and publication of a trusted list containing information relating to qualified trust service providers and the qualified trust services they provide, and must provide for a body responsible for maintaining and publishing it. The Information Commissioner’s Office is the supervisory body for United Kingdom trust service providers, with power to grant and revoke qualified status, carry out audits and take enforcement action; its guidance was last updated on 12 February 2026 and still describes the regime as in force. Recognition runs one way: European Union qualified trust services are recognized in the United Kingdom, but there is no reciprocal arrangement, so a United Kingdom qualified signature is not automatically qualified in the European Union.

In practice, English courts got where they were going without tiers. In J Pereira Fernandes SA v Mehta, decided in the High Court on 7 April 2006, an electronic mail address inserted automatically into the header was held not to be a signature for the purposes of section 4 of the Statute of Frauds 1677, because nobody had chosen to put it there, though the court indicated that a typed name would have sufficed. In Golden Ocean Group Ltd v Salgaocar Mining Industries PVT Ltd, in the Court of Appeal in 2012, a contract of guarantee was held to have been concluded in writing across a chain of electronic mail messages. In Neocleous v Rees, decided in the High Court on 20 September 2019, an automatically generated footer at the end of a solicitor’s electronic mail, containing his name and contact details, was held to be a signature satisfying section 2 of the Law of Property (Miscellaneous Provisions) Act 1989 for a contract dealing with land, because the sender had set the software to add it and knew it would be added. In Hudson v Hathway, in the Court of Appeal in 2022, a name typed at the foot of an electronic mail was held to be a signature for the purposes of section 53(1)(c) of the Law of Property Act 1925.

The Law Commission examined the whole question and reported on 4 September 2019 in Electronic Execution of Documents. Its central conclusion was that an electronic signature is capable in law of executing a document, including a deed, provided the signer intends to authenticate it and any execution formalities are satisfied; and that a deed must still be signed in the physical presence of a witness who attests it, even where both are signing electronically. The government responded in March 2020, accepting the legal conclusions and undertaking to convene an Industry Working Group, which published an interim report on 1 February 2022 and a final report in February 2023 addressing cross-border transactions, fraud and possible approaches to video witnessing.

The United Kingdom is therefore the clearest case of the point this chapter keeps making: the three tiers exist there in statute, and they are almost never the decisive question in an English contract dispute, because the common law asks whether the mark was made with the intention of authenticating and then weighs the evidence.

Where a wet signature is still required#

Every regime keeps a list of documents that electronic signature law does not reach. The lists are shrinking, unevenly, and each entry has its own history.

Jurisdiction Still needs paper or notary
US, 15 U.S.C. 7003 Wills and testamentary trusts
US, 15 U.S.C. 7003 Most of the UCC; family law
Germany, BGB 623 Termination of employment
Germany, BGB 766 Private suretyship
Germany, BGB 2247 Handwritten will
India, First Schedule Trusts, wills, instruments
England and Wales Deeds need a present witness

The German entries repay a closer look because they show the mechanism. BGB section 126 sets out the written form. BGB section 126a sets out the electronic form: if the legally prescribed written form is to be replaced by the electronic form, the issuer of the declaration must add their name and provide the electronic document with their qualified electronic signature, and for a contract each party must sign an identical document that way. So the German legislature already made a general rule that a qualified signature substitutes for writing. Then individual provisions switch that rule off. BGB section 623 requires the written form for notice of termination of an employment relationship and for a termination agreement, and excludes the electronic form expressly, so a qualified signature does not save a dismissal sent by electronic means. BGB section 766 requires the surety’s declaration to be given in writing and states that giving it in electronic form is excluded. BGB section 2247 lets a testator make a will by a declaration written and signed in their own hand, which no electronic mechanism can satisfy.

India’s First Schedule works the same way, as a list attached to section 1(4) saying the Act does not apply to what is listed. It covers a negotiable instrument other than a cheque, as defined in section 13 of the Negotiable Instruments Act 1881, with an exception now carved out for demand promissory notes and bills of exchange issued in favour of or endorsed by entities regulated by the Reserve Bank of India; a power-of-attorney as defined in section 1A of the Powers-of-Attorney Act 1882, with a similar carve-out; a trust as defined in section 3 of the Indian Trusts Act 1882; and a will as defined in clause (h) of section 2 of the Indian Succession Act 1925, including any other testamentary disposition by whatever name called.

The fifth entry used to be any contract for the sale or conveyance of immovable property or any interest in such property. It was omitted by notification S.O. 4720(E) dated 26 September 2022. That single deletion moved Indian property contracts from outside the Act to inside it, and it is the best available example of how these lists shrink: not by grand reform, but by one notification at a time, usually because a sector lobbied and a ministry agreed.

Two general observations. First, the pattern across all four regimes is that the survivors are documents where the law wants a moment of solemnity, a witness, or a public register: wills, guarantees given by individuals, dismissals, land, court process, powers over other people’s affairs. Second, these exclusions are about form law, not signature law, so the highest tier in the world does not help. A qualified electronic signature on a German dismissal notice is a perfectly valid qualified electronic signature on a void document.

eIDAS 2.0: what changes, and when#

The amending instrument is Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. It entered into force on 20 May 2024. It does not replace eIDAS; it amends it, so the article numbers in the rest of this chapter survive and new ones are inserted around them.

Three things in it matter for signatures.

The first is the European Digital Identity Wallet. Article 5a(1) requires each member state to provide at least one wallet within 24 months of the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6). Those implementing acts were adopted on 28 November 2024 and published on 4 December 2024; among them is Commission Implementing Regulation (EU) 2024/2981 on the certification of European Digital Identity Wallets. They entered into force on 24 December 2024. The wallet deadline is therefore 24 December 2026, four months after this chapter was written.

The second is free qualified signing. The wallet must let the user sign by means of qualified electronic signatures, and the Regulation requires that capability to be available free of charge to natural persons, while allowing member states to take proportionate measures to confine free use to non-professional purposes. If it works as drafted, this is the largest change to the economics of qualified signing since 2016: the tier that was expensive because somebody had to check your passport becomes free for individuals, because the state already checked it when it issued the wallet.

The third is that wallets become an identity-proofing method for certificates. Article 24(1a), as amended, lists the methods a qualified trust service provider may use to verify the identity of the person receiving a qualified certificate: by means of the European Digital Identity Wallet or a notified electronic identification means meeting assurance level high; by means of a certificate of a qualified electronic signature or seal issued in compliance with those methods; by other identification methods ensuring identification with a high level of confidence, whose conformity is confirmed by a conformity assessment body; or through the physical presence of the person or an authorized representative. Article 24(1c) required the Commission to establish reference standards for that verification by 21 May 2025.

Date What happens
11 April 2024 Regulation 2024/1183 adopted
20 May 2024 eIDAS 2.0 enters into force
28 Nov 2024 First implementing acts
24 Dec 2024 Those acts enter into force
21 May 2025 Article 24(1c) standards due
24 Dec 2026 Member states offer a wallet
24 Dec 2027 Big relying parties accept

The last row needs its exact scope. Article 5f provides that where private relying parties providing services, other than micro and small enterprises, are required by Union or national law to use strong user authentication for online identification, or where such authentication is required by contractual obligation, including in transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, those relying parties shall, no later than 36 months from the entry into force of the implementing acts, and only upon the voluntary request of the user, also accept wallets.

As of August 2026 the position on the ground is uneven, and it is worth recording honestly because the difference between a regulation’s dates and a market’s dates is one of the recurring lessons of this book. Denmark launched its wallet, AltID, in production on 3 June 2026. Several member states are upgrading existing national identity applications, among them Austria, Belgium, Greece, Luxembourg, Poland and Slovakia. Germany’s state wallet is scheduled for early 2027, after the December 2026 deadline; France has planned public testing in the second half of 2026. Expect a handful of wallets on the deadline and a wave through 2027. That is a forecast, clearly marked as one, and not a fact.

The worked example, carried through three courts#

Return to the supply agreement. To keep every number in this section checkable by hand, take the operative line of the document to be exactly these 107 bytes, ending with a single newline.

Supply Agreement 2026-03-12: KedByte Technologies
Private Limited and Rheinmark GmbH. Value INR 42,00,000.

SHA-256 of those 107 bytes:
  bb60adb07c9faf98bf5cee3c1cf1abc0
  301d8adeff8134595d7ad9cd68fa4622

That fingerprint is what actually gets signed, in every tier, by every method described in this chapter. It is identical whether the signature is a tick in a box wrapped by a platform key or a qualified signature made on a certified card in Munich. The cryptography does not change between the tiers at all. Everything that changes is the paperwork around the key, and the paperwork is what the court is being asked about.

Now three courts, one dispute, the buyer denying the price term.

Before a German court, with a qualified signature from a provider on the German trusted list, the supplier files a validation report showing TOTAL-PASSED, QcCompliance and QcSSCD present, and the issuer granted on the list on 12 March 2026. Section 371a(1) of the Zivilprozessordnung then applies the rules on the evidential value of private documents, and the buyer must produce facts giving rise to serious doubt that the declaration came from the responsible person. A bare denial fails. If instead the signature were advanced, the same report proves integrity and identity to the same technical standard, but the court is in free evaluation of evidence and the buyer’s denial is simply one more thing in the scales.

Before an Indian court, the question is section 15 of the Information Technology Act. If the signature was made with a Digital Signature Certificate from a licensed Certifying Authority with the key under the signatory’s exclusive control, it is a secure electronic signature, and section 66 of the Bharatiya Sakshya Adhiniyam means the supplier does not have to prove that the signature is the subscriber’s. If it was an ordinary platform tick, section 66 puts that proof squarely on the supplier, and section 63 sets out the certificate that must accompany the electronic record before it is admitted at all.

Before a United States court, if the contract had been signed by the German buyer’s American affiliate, none of the above exists. The signature is admissible under 15 U.S.C. 7001(a) whatever it is. Attribution is proved under the state’s enactment of UETA section 9, in any manner, including by showing the efficacy of the security procedure. The supplier wins or loses on whether it can put a witness in the box who can explain how its own signing system works, which is precisely what the employer in Ruiz v. Moss Bros. Auto Group could not do.

One document, one fingerprint, three completely different pieces of litigation. That is the thesis of this chapter, in one worked example.

Which leaves the practical question: how do you choose a tier without lying to yourself about which one you have built. A short procedure, in the order that keeps teams out of trouble.

  1. Ask what happens if the signer denies it. If the answer is “we lose a few hundred rupees”, stop; a simple signature with a good audit trail is the right engineering answer and you should say so in writing.
  2. Ask whether any statute requires a signature for this document, and then ask separately whether any statute requires a form: writing, a witness, a notary, a register. Those are two different questions with two different answers and the second one is not solved by any tier.
  3. If you claim advanced, name the mechanism that gives one human sole control of one key, and name the standard it is certified against. If you cannot, you are at the simple tier.
  4. If you claim qualified, name the provider, the country whose trusted list carries it, and the certified device. Check the entry was granted on the day of signing, not today.
  5. Write the tier down in the system’s own documentation, in the words the Regulation uses, so that the next engineer inherits a fact rather than a marketing phrase.

33.98 Common wrong ideas#

Wrong: An advanced electronic signature has stronger legal effect than a simple one under eIDAS. Right: Article 25 gives statutory legal effect to only two things: no signature may be denied effect for being electronic, and a qualified signature equals a handwritten one. The advanced tier has stricter technical requirements but the same statutory effect as the simple tier, and its whole advantage is evidential, delivered by national procedural law and by what the parties can show in court.

Wrong: A qualified electronic signature makes a document legally valid. Right: It satisfies a requirement for a signature and nothing else. Article 2(3) of Regulation 910/2014 states that the Regulation does not affect national or Union law on the conclusion and validity of contracts or other obligations relating to form, so a qualified signature on a German dismissal notice, which BGB section 623 requires to be in written form with electronic form excluded, is a valid signature on a void document.

Wrong: If the certificate says “qualified”, the signature is qualified. Right: Qualified status has three independent components: the certificate must meet Annex I and carry the QcCompliance statement, the key must be in a qualified signature creation device, usually asserted by the QcSSCD statement, and the issuer must have been listed as granted on a national trusted list at the moment of signing. A certificate with QcCompliance but no QcSSCD produces an advanced signature based on a qualified certificate, which is a different and lesser thing.

Wrong: Trusted lists are a convenience for software, like a root store. Right: They are constitutive. Under eIDAS a provider is qualified because it appears as qualified on a member state’s trusted list, not because it meets the requirements in the abstract, so the list is the legal fact and the audit is only the reason for it.

Wrong: The United States has an equivalent of the qualified tier that Americans just call something else. Right: It has no tiers at all. ESIGN and UETA are deliberately technology-neutral, defining an electronic signature as a sound, symbol or process executed with intent to sign, and leaving every question of reliability to the ordinary law of evidence, decided case by case against whoever relies on the document.

Wrong: India recognizes any reliable electronic signature, like the UNCITRAL model. Right: Section 3A of the Information Technology Act 2000 requires the technique to be both reliable and specified in the Second Schedule, which is a closed list containing two entries as of August 2026, added by G.S.R. 61(E) of 27 January 2015, widened by S.O. 1119(E) of 1 March 2019, and extended by S.O. 3472(E) of 29 September 2020.

Wrong: After Brexit a United Kingdom qualified signature still works everywhere in Europe. Right: The United Kingdom retained eIDAS and recognizes European Union qualified trust services, but there is no reciprocal recognition, so as of August 2026 a signature qualified under the United Kingdom regime is treated in the European Union as an ordinary advanced signature.

Wrong: The tier is a property of the file, so you can check it at any time. Right: It is a statement about conditions at the moment of signing, which is why Article 32 repeatedly says “at the time of signing”, and why the evidence needed to prove those conditions has to be captured and preserved before it disappears, which is the subject of chapter 34, “Time, and Signatures That Must Outlive Their Keys”.

Wrong: eIDAS 2.0 replaces the three tiers with the wallet. Right: Regulation (EU) 2024/1183 amends Regulation 910/2014 rather than replacing it; the three tiers, Annex I, Annex II and the trusted lists all survive, and the wallet is added as a new way to hold credentials, to be identified for a certificate under the amended Article 24(1a), and to make qualified signatures free of charge for natural persons.

33.99 Chapter summary in 20 lines#

  1. Regulation (EU) No 910/2014, adopted 23 July 2014 and applicable from 1 July 2016, defines three legally distinct tiers of electronic signature that are not interchangeable.
  2. A simple electronic signature is any data in electronic form attached to other data and used by the signatory to sign, and it may not be denied legal effect merely for being electronic.
  3. An advanced electronic signature must satisfy the four conditions of Article 26: unique linkage, capability of identifying the signatory, creation under sole control, and detectability of later change.
  4. A qualified electronic signature is an advanced signature made with a qualified signature creation device on the basis of a qualified certificate, and it alone is declared by Article 25(2) to have the equivalent legal effect of a handwritten signature.
  5. The advanced tier carries no extra statutory legal effect over the simple tier; its advantage is entirely evidential and is delivered by national procedural law.
  6. A qualified certificate must meet the nine elements of Annex I and is marked machine-readably by the QCStatements extension profiled in ETSI EN 319 412-5, with QcCompliance at 0.4.0.1862.1.1 and QcSSCD at 0.4.0.1862.1.4.
  7. A qualified signature creation device must ensure confidentiality and single occurrence of the signature creation data, resistance to derivation and forgery, and protection by the signatory against use by others, and must not alter or hide the data to be signed.
  8. Only a qualified trust service provider may generate or manage signature creation data on a signatory’s behalf, which is the legal basis of remote qualified signing.
  9. Devices are certified by bodies designated by member states, under the standards listed in Commission Implementing Decision (EU) 2016/650 of 25 April 2016, and the Commission publishes the resulting list.
  10. Qualified status is granted by a national supervisory body, requires an audit at least every 24 months, and takes effect by the provider’s entry on a national trusted list, which is constitutive rather than merely informative.
  11. Article 13 reverses the burden of proving fault against qualified trust service providers, while a claimant must prove fault against a non-qualified one.
  12. Section 371a of the German Zivilprozessordnung shows what Article 25(2) means in practice: the appearance of authenticity from a qualified signature can be displaced only by facts giving rise to serious doubt.
  13. The United States chose the opposite approach in 2000, with ESIGN at 15 U.S.C. 7001 and the Uniform Electronic Transactions Act, defining one technology-neutral signature and leaving reliability to the law of evidence.
  14. UETA is in force in 49 states and several territories as of August 2026, with New York the sole holdout under its own Electronic Signatures and Records Act.
  15. Ruiz v. Moss Bros. Auto Group, decided 23 December 2014, shows the American cost of no tiers: a party that cannot explain its own signing system fails to attribute the signature and loses.
  16. India’s Information Technology Act 2000 recognizes digital signatures under section 3 and, since the 2008 amendment in force from 27 October 2009, other techniques under section 3A only if they are both reliable and listed in the Second Schedule.
  17. India’s Controller of Certifying Authorities, appointed under section 17, licensed 23 Certifying Authorities as of August 2026, and the eSign service issues a short-lived certificate whose key is created in a hardware security module and destroyed after a single use.
  18. The United Kingdom keeps both the admissibility rule in section 7 of the Electronic Communications Act 2000 and the retained eIDAS tiers, but its courts decide most disputes on intention to authenticate, as in Neocleous v Rees in 2019.
  19. Every regime keeps a shrinking list of documents that electronic signatures cannot reach, and India’s removal of immovable property contracts from the First Schedule by notification S.O. 4720(E) of 26 September 2022 is a good example of how that shrinking happens.
  20. Regulation (EU) 2024/1183 entered into force on 20 May 2024 and, through implementing acts in force from 24 December 2024, requires every member state to offer a European Digital Identity Wallet by 24 December 2026 and large private relying parties in listed sectors to accept it by 24 December 2027.

Chapter sources: Regulation (EU) No 910/2014 of 23 July 2014, Official Journal L 257 of 28 August 2014, in particular Articles 2(3), 3(10) to 3(23), 13, 19 to 22, 24, 25 to 34, Annex I and Annex II; Regulation (EU) 2024/1183 of 11 April 2024, in force 20 May 2024, in particular Articles 5a, 5f and the amended Article 24; Commission Implementing Regulation (EU) 2024/2981 of 28 November 2024 on the certification of European Digital Identity Wallets, in force 24 December 2024; Commission Implementing Decision (EU) 2015/1505 of 8 September 2015 on trusted list specifications; Commission Implementing Decision (EU) 2016/650 of 25 April 2016 on standards for the security assessment of qualified signature and seal creation devices, listing ISO/IEC 15408 parts 1 to 3, ISO/IEC 18045 and the EN 419211 series; ETSI EN 319 412-5 version 2.3.1 of April 2020 for QCStatements; ETSI EN 319 401, EN 319 411-2, EN 319 102-1, EN 419 241-1 and EN 419 241-2, and TS 119 612 for trusted lists; the European list of trusted lists as issued on 3 August 2026 and the Netherlands trusted list as read in August 2026; the Electronic Signatures in Global and National Commerce Act, Public Law 106-229 of 30 June 2000, codified at 15 U.S.C. 7001 and 7003; the Uniform Electronic Transactions Act 1999, sections 2, 7 and 9, and New York State Technology Law article III sections 301 to 309; Ruiz v. Moss Bros. Auto Group, California Court of Appeal, Fourth Appellate District, 23 December 2014, applying California Civil Code section 1633.9(a); the Information Technology Act 2000, Act 21 of 2000, enacted 9 June 2000 and in force from 17 October 2000 by G.S.R. 788(E), as amended by Act 10 of 2009 in force from 27 October 2009, sections 3, 3A, 5, 10A, 15, 17 and 35 with the First and Second Schedules, and notifications G.S.R. 61(E) of 27 January 2015, S.O. 1119(E) of 1 March 2019, S.O. 3472(E) of 29 September 2020 and S.O. 4720(E) of 26 September 2022; the Bharatiya Sakshya Adhiniyam 2023, Act 47 of 2023, assented 25 December 2023 and in force from 1 July 2024, sections 63, 66, 73, 85, 86 and 93; the Controller of Certifying Authorities’ published list of licensed Certifying Authorities and its description of the eSign service, read in August 2026; the Electronic Communications Act 2000 section 7 as amended on 22 July 2016, the Electronic Identification and Trust Services for Electronic Transactions (Amendment etc.) (EU Exit) Regulations 2019, and Information Commissioner’s Office guidance on the UK eIDAS Regulation updated 12 February 2026; J Pereira Fernandes SA v Mehta of 7 April 2006, Golden Ocean Group Ltd v Salgaocar Mining Industries PVT Ltd of 2012, Neocleous v Rees of 20 September 2019 and Hudson v Hathway of 2022; the Law Commission report Electronic Execution of Documents of 4 September 2019, the Government response of March 2020, and the Industry Working Group interim report of 1 February 2022 and final report of February 2023; and the German Bürgerliches Gesetzbuch sections 126, 126a, 127, 623, 766 and 2247 and Zivilprozessordnung section 371a.