E-signatures · Glossary
What is eIDAS?
eIDAS is Regulation 910/2014 on electronic identification and trust services for electronic transactions in the internal market. It applies directly in every European Union member state, sets three levels of electronic signature, and regulates the providers of signing, sealing, timestamping and related services.
Most people meet the regulation through a vendor claim about signature levels. It covers considerably more than signatures, and the parts nobody mentions are often the ones that decide a cross border deal.
Nuwan Madhusanka · Co-founder
5 min read · Published
| Service | What it does | Who uses it |
|---|---|---|
| Electronic seal | Binds a document to an organisation rather than a person | Issuers of invoices, statements and certificates |
| Electronic timestamp | Proves data existed at a point in time | Anyone who has to date evidence independently |
| Registered electronic delivery | Evidences sending and receiving a message | Notices where proof of delivery matters |
| Website authentication certificate | Ties a website to the organisation behind it | Sites that must show who operates them |
| Electronic identification schemes | Lets a national identity be used across borders | Public services accepting foreign users |
Why it is a regulation and not a directive
A directive tells member states to achieve a result and leaves the drafting to them, which is what the 1999 electronic signatures directive did, producing twenty eight variations. A regulation applies as written in every member state at the same time. That change is the practical heart of the 2014 reform: a qualified certificate issued in one country has to be recognised in all of them, and a business no longer has to survey national laws before accepting a signature from another member state.
Trust service providers and the lists
The regulation creates a supervised class of provider and a public register of who holds which status. Each member state publishes a trusted list, and the Commission publishes a browser over all of them. That machinery is what makes qualified status checkable rather than assertable: a receiving party can look up the issuer, see which services it was qualified for and from when. Providers that are not qualified may still operate, and their output is perfectly usable, but it carries no presumption and no cross border guarantee.
What the 2024 amendment changed
Regulation 2024/1183 extended the framework rather than replacing it. The headline addition is the European Digital Identity Wallet, a member state issued app for holding identity attributes and using them across services, along with new trust services for electronic attestation of attributes and archiving. The three signature levels survive unchanged. The practical effect over the next few years is on how a signer proves who they are before signing, which is exactly the step most signing processes are weakest at.
Reach beyond the European Union
The regulation binds member states, and the European Economic Area applies it as well. The United Kingdom retained a version in domestic law after leaving, so the vocabulary is shared but the trusted lists and the recognition rules are not identical. Elsewhere the influence is by imitation: several jurisdictions have adopted tiered models with similar language. None of that makes a European qualified signature automatically special in Sydney or Toronto, where the local statute decides.
What this means for a signing service
Ordinary signing here produces a simple electronic signature under this vocabulary, with the identity evidence coming from an emailed link, an access code or an emailed one time code, and the process evidence from an audit trail of eighteen event types. The finished PDF is sealed with a PAdES signature at DocMDP level one so tampering is detectable. Nothing is issued from a qualified trust service, so where a transaction requires a qualified signature or seal, that has to come from a listed provider.
What the regulation deliberately leaves alone
Reading the scope is as useful as reading the articles. It does not require anybody to sign electronically, so a party can still insist on paper as a commercial term. It does not harmonise contract law, so whether an agreement is valid, who had authority and what the words mean remain questions for national law. It does not set data protection rules, which sit in a separate regulation, even though signing collects personal data and the two are often discussed together. It does not govern the internal workings of a private signing platform, only the trust services it defines. And it does not reach beyond the European Union and the European Economic Area, so a European qualified signature carries no special status in Sydney, Toronto or New York unless the local law or the contract says so. Vendors sometimes present eIDAS compliance as a product feature. The regulation regulates providers of trust services and the legal effect of signatures, so for most software the honest claim is compatibility with a level rather than compliance with the regulation. The distinction matters in procurement, because a buyer who asks for an eIDAS compliant product and receives one may still find that the signatures it produces sit at the simple level, which was never what the question meant.
Questions people ask
Does eIDAS apply to contracts between two private companies?
It applies to how their signatures are treated, not to whether they must use one. Freedom of form still governs most commercial contracts, so two companies can agree to sign with a click. The regulation matters when one of them wants the certainty that a qualified signature carries across borders.
Is a qualified signature required to deal with an EU public body?
Sometimes, and it varies by country and by procedure. Public procurement portals and tax filings are the common places where a specific level is prescribed. The requirement will be stated in the relevant national rule or in the portal documentation rather than in the regulation itself.
How is a seal different from a signature?
A signature is an act by a natural person and expresses intent. A seal belongs to a legal person and evidences origin and integrity, which suits invoices, statements and machine issued documents. A qualified seal carries a presumption of integrity and of the origin of the data it is attached to.
Does eIDAS require signatures to be archived?
The 2024 amendment added qualified electronic archiving as a trust service, but the obligation to keep records comes from tax, company and sector law rather than from this regulation. In practice the requirement to reproduce a record later is what drives long term validation choices at signing time.
Is a scanned handwritten signature valid under eIDAS?
It is an electronic signature at the simple level, so it cannot be rejected merely for being electronic. Its weakness is evidential: an image can be copied from any document that carries it, so anyone relying on it is depending entirely on the surrounding process to show who applied it and when.
Where do I read the actual text?
The consolidated regulation is on EUR-Lex under CELEX number 32014R0910, and the 2024 amendment under 32024R1183. Articles 25 and 26 cover the legal effect of signatures and the four requirements for the advanced level, which are the two provisions most often quoted out of context.
Make one with e-signatures
The button opens the generator with this use case already described. Change the wording to match your own.
Send a document for signingRelated questions
- What is the ESIGN Act?The ESIGN Act is the US federal law giving electronic signatures legal effect. Its four conditions, the consumer consent rules, and the documents it excludes.
- What is UETA?UETA is the uniform state act on electronic signatures and records, adopted almost everywhere in the US. What it adds beyond the federal ESIGN Act.
- What is a qualified electronic signature (QES)?A qualified electronic signature is the top eIDAS level: a qualified certificate, a qualified device, and the legal effect of a handwritten signature in the EU.
Written and checked by the OneCraft team. Last checked .