Back to glossary

Advanced Electronic Signature

An advanced electronic signature is an electronic signature that meets four specific requirements under Article 26 of the European Union’s eIDAS Regulation.

Updated
Advanced Electronic Signature glossary signal map Prompt Answer Citation Signal

An advanced electronic signature is an electronic signature that meets four specific requirements under Article 26 of the European Union’s eIDAS Regulation.

Often abbreviated as AES, it provides a higher level of assurance about who signed a document, whether the signer controlled the signing process, and whether the signed data was changed afterward. It sits between a basic electronic signature and a qualified electronic signature within the eIDAS framework.

AES is a legal standard, not the name of a particular technology, certificate, button, or software feature. A signing process qualifies based on whether it satisfies the eIDAS requirements in practice, not simply because a provider describes its product as “advanced.”

The four requirements for an advanced electronic signature

Article 26 of eIDAS states that an advanced electronic signature must satisfy all four of the following requirements.

  1. It must be uniquely linked to the signer.
    The signature must have a connection to one particular natural person. The evidence should make it possible to distinguish that signer from other users.

  2. It must be capable of identifying the signer.
    The signing process must contain information or evidence that can be used to establish the signer’s identity. The appropriate method depends on the transaction and the level of identity assurance required.

  3. It must be created using signature creation data under the signer’s sole control.
    The signer must be able to use the relevant credentials, keys, or other signature creation data with a high level of confidence and without another person being able to sign freely on the signer’s behalf. Passwords, security tokens, mobile devices, biometrics, or multi-factor authentication may support this requirement, depending on how they are implemented.

  4. It must be linked to the signed data so later changes are detectable.
    If the document or associated data is altered after signing, the verification process must reveal that change. Cryptographic hashes and digital signatures are commonly used to provide this form of document integrity.

These requirements work together. Strong identity verification alone is not enough if later document changes cannot be detected. Similarly, a tamper-evident document does not establish an AES if the signature cannot be linked to and controlled by the signer.

How advanced electronic signatures are implemented

eIDAS is technology-neutral. It defines the result a signing process must achieve without requiring every AES to use one particular format or technical system.

A common implementation uses a certificate-based digital signature. The platform verifies the signer, gives the signer controlled access to a private signing key, and uses that key to sign a cryptographic hash of the document. Verification can then confirm both the signature and whether the document has changed.

Remote signing can also support AES. The signing key may be held in a managed system instead of on the signer’s computer, provided the process gives the signer sole control with a high level of confidence. Exclusive authentication, explicit approval for each signature, protected credentials, and reliable security controls may all be relevant.

Other workflows may combine:

  • Identity verification or account enrollment
  • A private signing link
  • One-time codes or multi-factor authentication
  • A clear action confirming the signer’s intent
  • Cryptographic protection of the completed document
  • Records connecting authentication and signing events

These features can support the Article 26 requirements, but no individual feature automatically creates an AES. An email link, SMS code, audit log, or ID check must be evaluated as part of the complete process. Effective signer authentication is important, but authentication and signing are not the same function.

Simple, advanced, and qualified signatures compared

“Simple electronic signature” is a common industry term, not a separately defined signature category in eIDAS. It usually refers to an electronic signature that meets the regulation’s broad definition but not necessarily the additional AES requirements.

Signature level Main characteristics Legal position under eIDAS
Simple electronic signature May include a typed name, checked box, scanned signature, or click to accept Cannot be denied legal effect or admissibility solely because it is electronic or not qualified
Advanced electronic signature Meets all four Article 26 requirements for signer linkage, identification, control, and change detection Provides stronger evidence, but does not automatically receive handwritten-signature equivalence
Qualified electronic signature An AES created using a qualified signature creation device and based on a qualified certificate Has the equivalent legal effect of a handwritten signature and receives EU-wide recognition as a QES

Every qualified electronic signature is advanced, but not every advanced electronic signature is qualified. A qualified electronic signature must meet additional regulated requirements involving qualified certificates, qualified trust service providers, and qualified signature creation devices.

An AES does not require a qualified certificate or qualified trust service provider merely because it is advanced.

What AES means as legal evidence

Under Article 25 of eIDAS, an electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic or because it does not meet the requirements for a qualified electronic signature. This rule applies to electronic signatures generally, including AES.

However, eIDAS does not give every AES the automatic handwritten-signature equivalence granted to a QES. If a signature is disputed, the party relying on it may need to demonstrate how the process satisfied Article 26 and how the available evidence connects the signer to the document.

An AES can provide persuasive evidence of identity, control, intent, and document integrity, but it does not prove every element of a valid transaction. It does not automatically establish that:

  • The signer had legal capacity or authority
  • Consent was informed and freely given
  • The agreement’s terms were lawful
  • A document met every applicable formality
  • The signer’s credentials were never compromised
  • A particular signature method was accepted for that transaction

Contract validity and signature formalities can depend on EU law, the national law of a Member State, the type of document, and the facts surrounding the transaction. Some agreements may be valid with a simple signature or without a signature, while specific documents may require a QES, notarization, or another prescribed form.

This entry provides general educational information and is not legal advice.

Where an AES claim succeeds or fails

A signing process that verifies a person’s identity, requires exclusive multi-factor authentication, applies an identity-linked digital signature, and detects later document changes may be designed to produce an AES.

By contrast, typing a name into a document after opening a shared email link is an electronic signature, but it is not automatically advanced. The surrounding system would still need to satisfy all four Article 26 requirements.

A captured handwritten signature on a touchscreen may contribute behavioral or biometric evidence. Its visual appearance does not determine its legal level. The complete process must still establish signer linkage, identification, control, and change detection.

An electronic seal is also not an AES. Under eIDAS, signatures are created by natural persons, while electronic seals are used to support the origin and integrity of data associated with a legal person, such as a company or public authority.

FAQ

Is an advanced electronic signature the same as a digital signature?

No. AES is a legal standard under eIDAS, while a digital signature is a cryptographic technique. Digital signatures are often used to implement AES, but the technology must operate within a process that meets all four legal requirements.

Does an AES require a qualified digital certificate?

No. A certificate may help link a signing key to a signer, but AES does not automatically require a qualified certificate. Qualified certificates are part of the additional requirements for qualified electronic signatures.

Is an advanced electronic signature legally binding?

It can support a legally binding agreement, but AES status alone does not make every agreement valid or enforceable. Applicable law, consent, capacity, authority, document type, and other formalities still matter.

Can a typed signature qualify as an AES?

The typed name alone is unlikely to demonstrate all four requirements. A broader signing system might use a typed signature as the visible mark while separately providing the identification, signer control, and integrity protections required for AES.