E-signatures · Glossary

What is eIDAS?

eIDAS is Regulation 910/2014 on electronic identification and trust services for electronic transactions in the internal market. It applies directly in every European Union member state, sets three levels of electronic signature, and regulates the providers of signing, sealing, timestamping and related services.

Most people meet the regulation through a vendor claim about signature levels. It covers considerably more than signatures, and the parts nobody mentions are often the ones that decide a cross border deal.

· Co-founder

5 min read · Published

The trust services the regulation covers, besides signatures
ServiceWhat it doesWho uses it
Electronic sealBinds a document to an organisation rather than a personIssuers of invoices, statements and certificates
Electronic timestampProves data existed at a point in timeAnyone who has to date evidence independently
Registered electronic deliveryEvidences sending and receiving a messageNotices where proof of delivery matters
Website authentication certificateTies a website to the organisation behind itSites that must show who operates them
Electronic identification schemesLets a national identity be used across bordersPublic services accepting foreign users

Why it is a regulation and not a directive

A directive tells member states to achieve a result and leaves the drafting to them, which is what the 1999 electronic signatures directive did, producing twenty eight variations. A regulation applies as written in every member state at the same time. That change is the practical heart of the 2014 reform: a qualified certificate issued in one country has to be recognised in all of them, and a business no longer has to survey national laws before accepting a signature from another member state.

Trust service providers and the lists

The regulation creates a supervised class of provider and a public register of who holds which status. Each member state publishes a trusted list, and the Commission publishes a browser over all of them. That machinery is what makes qualified status checkable rather than assertable: a receiving party can look up the issuer, see which services it was qualified for and from when. Providers that are not qualified may still operate, and their output is perfectly usable, but it carries no presumption and no cross border guarantee.

What the 2024 amendment changed

Regulation 2024/1183 extended the framework rather than replacing it. The headline addition is the European Digital Identity Wallet, a member state issued app for holding identity attributes and using them across services, along with new trust services for electronic attestation of attributes and archiving. The three signature levels survive unchanged. The practical effect over the next few years is on how a signer proves who they are before signing, which is exactly the step most signing processes are weakest at.

Reach beyond the European Union

The regulation binds member states, and the European Economic Area applies it as well. The United Kingdom retained a version in domestic law after leaving, so the vocabulary is shared but the trusted lists and the recognition rules are not identical. Elsewhere the influence is by imitation: several jurisdictions have adopted tiered models with similar language. None of that makes a European qualified signature automatically special in Sydney or Toronto, where the local statute decides.

What this means for a signing service

Ordinary signing here produces a simple electronic signature under this vocabulary, with the identity evidence coming from an emailed link, an access code or an emailed one time code, and the process evidence from an audit trail of eighteen event types. The finished PDF is sealed with a PAdES signature at DocMDP level one so tampering is detectable. Nothing is issued from a qualified trust service, so where a transaction requires a qualified signature or seal, that has to come from a listed provider.

What the regulation deliberately leaves alone

Reading the scope is as useful as reading the articles. It does not require anybody to sign electronically, so a party can still insist on paper as a commercial term. It does not harmonise contract law, so whether an agreement is valid, who had authority and what the words mean remain questions for national law. It does not set data protection rules, which sit in a separate regulation, even though signing collects personal data and the two are often discussed together. It does not govern the internal workings of a private signing platform, only the trust services it defines. And it does not reach beyond the European Union and the European Economic Area, so a European qualified signature carries no special status in Sydney, Toronto or New York unless the local law or the contract says so. Vendors sometimes present eIDAS compliance as a product feature. The regulation regulates providers of trust services and the legal effect of signatures, so for most software the honest claim is compatibility with a level rather than compliance with the regulation. The distinction matters in procurement, because a buyer who asks for an eIDAS compliant product and receives one may still find that the signatures it produces sit at the simple level, which was never what the question meant.

Questions people ask

Does eIDAS apply to contracts between two private companies?

It applies to how their signatures are treated, not to whether they must use one. Freedom of form still governs most commercial contracts, so two companies can agree to sign with a click. The regulation matters when one of them wants the certainty that a qualified signature carries across borders.

Is a qualified signature required to deal with an EU public body?

Sometimes, and it varies by country and by procedure. Public procurement portals and tax filings are the common places where a specific level is prescribed. The requirement will be stated in the relevant national rule or in the portal documentation rather than in the regulation itself.

How is a seal different from a signature?

A signature is an act by a natural person and expresses intent. A seal belongs to a legal person and evidences origin and integrity, which suits invoices, statements and machine issued documents. A qualified seal carries a presumption of integrity and of the origin of the data it is attached to.

Does eIDAS require signatures to be archived?

The 2024 amendment added qualified electronic archiving as a trust service, but the obligation to keep records comes from tax, company and sector law rather than from this regulation. In practice the requirement to reproduce a record later is what drives long term validation choices at signing time.

Is a scanned handwritten signature valid under eIDAS?

It is an electronic signature at the simple level, so it cannot be rejected merely for being electronic. Its weakness is evidential: an image can be copied from any document that carries it, so anyone relying on it is depending entirely on the surrounding process to show who applied it and when.

Where do I read the actual text?

The consolidated regulation is on EUR-Lex under CELEX number 32014R0910, and the 2024 amendment under 32024R1183. Articles 25 and 26 cover the legal effect of signatures and the four requirements for the advanced level, which are the two provisions most often quoted out of context.

Make one with e-signatures

The button opens the generator with this use case already described. Change the wording to match your own.

Send a document for signing

Related questions

Sources

Written and checked by the OneCraft team. Last checked .