Under the EU eIDAS Regulation (Regulation EU No. 910/2014), electronic signatures are classified into three levels:
Simple Electronic Signature
Advanced Electronic Signature
Qualified Electronic Signature
Each type provides a different level of trust, security, and legal assurance. Understanding the differences helps organizations choose the right signature for each situation.
What Is an Electronic Signature?
An electronic signature is electronic data attached to a document that indicates a person's intent to sign or approve that document.
Electronic signatures can take many forms, from clicking an "Accept" button online to using cryptographic digital certificates issued by trusted authorities.
The Three Types of Electronic Signatures
Simple Electronic Signature (SES)
A Simple Electronic Signature is the most basic type of electronic signature.
Examples:
- Typing your name in an online form
- Clicking an "I agree" button
- Inserting an image of your signature
- Confirming acceptance via email
SES is widely used because it is fast and easy, but it provides limited security. It typically does not include identity verification or strong cryptographic protection.
Commonly used for:
Advanced Electronic Signature (AES)
An Advanced Electronic Signature provides stronger security and verification.
Under eIDAS, AES must meet:
- Must be uniquely linked to the signer
- The signer must be identifiable
- Must be created using data under the sole control of the signer
- Any modification to the document must be detectable
AES uses cryptographic technology and digital certificates to ensure document integrity and signer authenticity. If a signed document is altered after signing, the signature becomes invalid, making tampering easy to detect.
Typically used for:
Qualified Electronic Signature (QES)
A Qualified Electronic Signature is the highest level of electronic signature under eIDAS. It includes all the features of an Advanced Electronic Signature but adds two critical elements:
Qualified digital certificate
Issued by a Qualified Trust Service Provider (QTSP)
Qualified Device (QSCD)
Qualified Signature Creation Device
QES is legally equivalent to a handwritten signature throughout the European Union.
Typical use cases:
SES vs AES vs QES – Key Differences
| Feature | SES | AES | QES |
|---|---|---|---|
| Identity verification | Not required | Possible but not guaranteed | Strong verification required |
| Cryptographic protection | No | Yes | Yes |
| Authentication | Not guaranteed | Often includes MFA | Multi-factor authentication required |
| Tamper detection | Limited | Yes | Yes |
| Legal strength | Context dependent | Strong evidential value | Equivalent to handwritten signature |
How Digital Signatures Work
Advanced and qualified electronic signatures rely on Public Key Infrastructure (PKI) technology, which uses two cryptographic keys:
Private key
Used by the signer to create the signature
Public key
Used to verify the signature
When a document is signed digitally:
A unique digital fingerprint of the document (hash) is generated
The hash is encrypted with the signer's private key
The encrypted signature is attached to the document
Even a small change in the document will invalidate the signature.
Digital Certificates and Trust Service Providers
Digital signatures rely on digital certificates to verify the identity of the signer. A digital certificate links a person's identity to their cryptographic keys and is issued by a trusted organization called a Trust Service Provider.
For Qualified Electronic Signatures, certificates must be issued by Qualified Trust Service Providers (QTSPs) that comply with the eIDAS regulation. These providers are listed in the official EU Trusted List.
Electronic Timestamps for Additional Security
A timestamp proves that a document existed at a specific time and has not been altered since that moment. The timestamp is cryptographically linked to the document, providing additional proof of integrity and chronology.
Qualified timestamps are recognized across all EU Member States.
Which Electronic Signature Should You Use?
The appropriate signature type depends on the risk level and legal requirements of the document.
Suitable for simple approvals or low-risk agreements
Stronger authentication and document protection
Highest level of legal assurance and identity verification
Digital Signing with Simplifi
Simplifi combines qualified trust services with modern document workflows, enabling organizations to sign documents securely and efficiently.
Execute legally binding documents faster, safer, and fully compliant with eIDAS.
