E-signatures · Glossary
What is a qualified electronic signature (QES)?
A qualified electronic signature is the highest of the three levels set by the European eIDAS Regulation. It is an advanced electronic signature created by a qualified signature creation device and backed by a qualified certificate issued by a trust service provider listed on an EU trusted list.
It is the only signature level European law says must be treated the same as a handwritten one across every member state. That guarantee is also why it costs more and takes longer to obtain.
Nuwan Madhusanka · Co-founder
5 min read · Published
| Simple (SES) | Advanced (AES) | Qualified (QES) | |
|---|---|---|---|
| Identity checked | Not required by the definition | Signature must identify the signatory | Verified by a qualified trust service provider |
| Certificate | None needed | Any certificate that meets the four tests | A qualified certificate from a listed provider |
| Where the key lives | Anywhere | Under the signatory's sole control | In a qualified signature creation device |
| Legal effect in the EU | Cannot be denied effect for being electronic | Cannot be denied effect for being electronic | Equivalent to a handwritten signature |
| Recognised across member states | Case by case | Case by case | Yes, in every member state |
What the regulation actually promises
Article 25 does two separate things. It says no electronic signature may be denied legal effect merely for being electronic, which covers every level, and then it gives qualified signatures a specific status: the same legal effect as a handwritten signature, recognised in every member state. That second promise is the reason the level exists. It converts a question of evidence into a question of law, so a party receiving a qualified signature from another country does not have to argue about whether the process behind it was good enough.
Who is allowed to issue one
Only a qualified trust service provider, supervised by a national body and published on that country's trusted list. The lists are machine readable and browsable, which matters in practice: a claim to be qualified is checkable in a minute rather than taken on trust. The provider verifies the applicant's identity to a defined standard, typically in person or through an equivalent remote process, then issues a certificate tied to a device that keeps the private key out of the holder's general purpose computer.
When it is genuinely required
Less often than vendors imply. Ordinary business to business contracts in the European Union do not require a qualified signature. It becomes necessary where national law prescribes a form for a particular act, in a set of public sector dealings, and in regulated areas such as certain notarial, tax and healthcare processes that differ by country. The other common driver is counterparty policy: a large institution may require it as a matter of procurement rather than because a statute says so. Either way the requirement should be traced to a named rule before anyone buys a device.
The cost of the guarantee
Every element that makes the level strong also adds friction. Identity has to be verified before the first signature, not during it, which rules out sending a link to a stranger and having them sign in five minutes. The key sits in hardware or a remote signing service, so the signer needs that device or an account with the provider. Certificates expire and are renewed. For a business signing hundreds of routine agreements, that overhead is the reason most of them stay at the advanced level, with the qualified level reserved for the handful of documents that need it.
What this product does and does not do
It is not a trust service provider and it issues no certificates to signers, so nothing it produces is a qualified electronic signature. Signing here identifies people through an emailed link, an access code or an emailed one time code, and records the result in a chained audit trail. The finished PDF is then sealed with the service's own PAdES certificate at DocMDP level one, which proves the file has not changed since completion. If a transaction genuinely requires a qualified signature, it needs a qualified provider instead.
What obtaining one involves
Procurement runs on a different clock from software. First comes choosing a provider that appears on a member state trusted list for the service required, since being a well known vendor is not the same as being qualified. Then identity verification of each signer, historically in person and now often through a supervised video process or an existing electronic identity scheme, which takes days rather than minutes and has to be repeated for every named individual. Then the signing method: either a physical device holding the key, which means card readers and drivers, or a remote signing service where the provider holds the key in certified hardware and the signer authorises each use. Pricing is usually per certificate with a term, sometimes with a per signature charge on top. Certificates expire, typically after one to three years, so somebody has to own renewals. None of that is difficult, but it is the reason the level is chosen deliberately rather than by default.
Questions people ask
Is a qualified signature needed for a normal commercial contract?
Almost never. Freedom of form applies to most commercial agreements in the European Union, so the parties can agree on how they sign. The level matters when a national rule prescribes a form for that act, or when the counterparty makes it a condition of dealing with them. Check the specific requirement before assuming.
How do I tell whether a certificate is qualified?
Look up the issuer in the trusted list browser published by the European Commission. Every qualified provider appears there with the services it is qualified for and the dates those statuses applied. A reader may also display the status, but the list is the authority, and it is the only way to check historical status for a signature made years ago.
Does the United Kingdom still recognise QES?
The United Kingdom retained a version of the eIDAS rules after leaving the European Union, with its own trusted list arrangements. A signature qualified under European Union rules is not automatically qualified under the retained regime, which is a detail that matters for cross border documents. Take advice for anything where the form is prescribed rather than chosen.
Can a company hold a qualified certificate?
Certificates for electronic signatures are issued to natural persons, because a signature is an act by a human. The comparable instrument for an organisation is a qualified electronic seal, which the regulation defines separately and which carries a presumption of integrity and origin rather than the effect of a handwritten signature.
Is remote signing still qualified?
Yes, where the provider operates a qualified remote signature creation service, meaning the key sits in the provider's certified hardware and is used under the signer's sole control. That model is now the common one, since it removes the smart card reader without dropping the level, provided the provider is listed for that service.
What changed with the 2024 amendment?
The amending regulation introduced the European Digital Identity Wallet and adjusted parts of the trust services framework. The three signature levels and the effect of a qualified signature were not replaced. Wallet based identification is expected to change how signers prove who they are rather than what a qualified signature means.
Make one with e-signatures
The button opens the generator with this use case already described. Change the wording to match your own.
Send a document for signingRelated questions
- What is an advanced electronic signature (AES)?An advanced electronic signature meets four eIDAS tests: uniquely linked, identifies the signatory, sole control, and any later change is detectable.
- What is a simple electronic signature (SES)?A simple electronic signature is the base eIDAS level, with no identity or certificate requirement. Why most business signing is SES and what strengthens it.
- What is eIDAS?eIDAS is the EU regulation covering electronic signatures, seals, timestamps and identity. What it sets out, what the 2024 amendment added, and who it binds.
Written and checked by the OneCraft team. Last checked .