Back to glossary

Qualified Electronic Signature

A qualified electronic signature (QES) is an advanced electronic signature that is based on a qualified certificate for electronic signatures and created using a qualified electronic signature creation device, as defined by eIDAS .

Updated
Qualified Electronic Signature glossary signal map Prompt Answer Citation Signal

A qualified electronic signature (QES) is an eIDAS Regulation.">advanced electronic signature that is based on a qualified certificate for electronic signatures and created using a qualified electronic signature creation device, as defined by eIDAS.

It is the highest electronic signature level recognized under the European Union’s eIDAS framework, Regulation (EU) No 910/2014, as amended by the European Digital Identity Framework. A QES has the equivalent legal effect of a handwritten signature across EU Member States.

That status depends on specific legal and technical requirements. A signature does not become qualified simply because it uses encryption, includes identity checks, or appears as valid in a PDF viewer.

What makes an electronic signature qualified under eIDAS

Every QES must first meet the requirements of an advanced electronic signature. It must be:

  • Uniquely linked to the signer
  • Capable of identifying the signer
  • Created using signature creation data that the signer can use under their sole control, with a high level of confidence
  • Linked to the signed data so that subsequent changes are detectable

Two additional elements give the signature qualified status:

  1. It must be based on a qualified certificate for electronic signatures.
  2. It must be created using a qualified electronic signature creation device, or QSCD.

All three layers matter. For example, an advanced signature supported by a qualified certificate is not a QES if the private key was not protected and used through a QSCD. This intermediate form is sometimes described as an advanced electronic signature based on a qualified certificate.

The qualified certificate and qualified trust service provider

A qualified certificate is a specialized digital certificate that connects the signature validation data, usually a public key, to an identified natural person. It must contain the information required by eIDAS and be issued by a qualified trust service provider.

A qualified trust service provider, or QTSP, is a provider that has received qualified status from the appropriate national supervisory body. EU Member States publish trusted lists showing QTSPs, their qualified services, and the status history of those services.

Qualification applies to specific services. A provider appearing on a trusted list may offer both qualified and nonqualified services, so checking the provider’s name alone is insufficient. The certificate issuance service used for the signature must itself have qualified status.

Before issuing a qualified certificate, the QTSP must verify the signer’s identity through an identification method permitted by the eIDAS framework. The certificate identifies a natural person by name or, where permitted and clearly indicated, by a pseudonym.

How a QSCD protects the signing key

A qualified electronic signature creation device is the approved environment used to create the signature. Its purpose is to protect the signature creation data, typically the signer’s private cryptographic key, against copying, unauthorized use, and forgery.

A QSCD may be:

  • A physical device, such as a smart card, secure token, or supported electronic identity card
  • A remote system operated through a qualified service, where protected signing keys are managed in secure infrastructure

Remote signing does not remove the QSCD requirement. The system must still meet eIDAS requirements and preserve the signer’s control over each signing action, commonly through strong authentication and explicit approval.

Legal effect and recognition across the EU

Under Article 25 of eIDAS, a QES has the equivalent legal effect of a handwritten signature. A QES based on a qualified certificate issued in one EU Member State must also be recognized as a QES in every other Member State.

This enables cross-border use. For example, a person in one Member State may use a QES on a document submitted to a business or public authority in another Member State, subject to applicable procedural and technical requirements.

The rule does not mean a QES automatically makes every document valid or enforceable. National and sector-specific laws may still determine:

  • Whether the signer had legal capacity or authority
  • Whether the parties gave valid consent
  • Whether the document’s terms are lawful
  • Whether witnesses, notarization, registration, or another formality is required
  • Whether the particular transaction accepts electronic execution

The cross-border recognition rule also does not automatically extend beyond the EU. Recognition in a non-EU country depends on that country’s laws and any applicable agreements.

How qualified status is verified

QES validation involves more than checking whether a visible signature mark appears on the document. A validation system examines the cryptographic signature and the trust information supporting it.

A proper validation process generally checks that:

  • The signed data has not changed since signing
  • The signature is cryptographically valid
  • The certificate was qualified and valid at the time of signing
  • The certificate was issued through a qualified service listed by an EU Member State
  • The certificate’s identity information corresponds to the signer
  • The signature was created using a QSCD
  • The signature met the advanced signature requirements when created

A certificate expiring after signing does not necessarily invalidate a signature that was valid when created. Reliable timestamps, revocation information, and preserved validation evidence can help establish its historical validity.

A software message stating that a signature is valid may confirm only its mathematical integrity. It does not necessarily confirm qualified status unless the software also evaluates the qualified certificate, QSCD status, and relevant EU trusted-list data.

QES compared with other electronic signatures

Signature level Main requirements Qualified certificate and QSCD eIDAS legal treatment
Ordinary or simple electronic signature Electronic data used by a person to sign Not required Cannot be denied legal effect or admissibility solely because it is electronic or not qualified
Advanced electronic signature, AES or AdES Identifies and is uniquely linked to the signer, remains under the signer’s control, and makes later changes detectable Not required Receives no automatic handwritten-signature equivalence under eIDAS
Qualified electronic signature Meets all advanced signature requirements Both are required Has the equivalent legal effect of a handwritten signature across EU Member States

An ordinary electronic signature can still be legally effective. QES is not required for every transaction, and choosing a signature level should reflect the document, governing law, risk, and evidentiary needs.

A QES commonly uses a cryptographic digital signature, but the terms are not interchangeable. “Digital signature” describes the cryptographic technique. “Qualified electronic signature” describes a regulated legal category that also requires a qualified certificate, a QSCD, and qualified trust infrastructure.

Practical boundaries

A QES can be appropriate where a handwritten-signature equivalent is required or where parties want the strongest standardized eIDAS signature level. Potential contexts include regulated submissions, employment documents, commercial agreements, and cross-border administrative processes.

However, qualified status does not prove that the signer understood the document, signed voluntarily, or possessed authority to bind an organization. It also does not replace notarization where notarization is legally required. Questions about whether a particular electronic signature is legally binding depend on the full transaction, not the signature label alone. See Are Electronic Signatures Legally Binding? for a broader explanation.

FAQ

Is a qualified electronic signature the same as a handwritten signature?

Under eIDAS, a QES has the equivalent legal effect of a handwritten signature. Other requirements affecting the document or transaction may still apply.

Does every digital signature qualify as a QES?

No. A digital signature is not qualified unless it meets the advanced signature requirements, uses a qualified certificate, and is created with a QSCD.

Can a company create a qualified electronic signature?

An electronic signature belongs to a natural person. An authorized representative can use a QES when signing for a company. A legal entity may instead use a qualified electronic seal to support document origin and integrity.

Is a QES required for every EU contract?

No. Many agreements can use ordinary or advanced electronic signatures. The required level depends on applicable law, the transaction, and any agreed or procedural requirements.

Does a QES make a contract automatically enforceable?

No. A QES provides a recognized signature method, but it does not resolve questions about consent, capacity, authority, legality, or additional formalities. This entry provides general educational information, not legal advice.