5 Step eIDAS Checklist: Map Signature Levels to Controls
Map eIDAS signature levels to precise controls and verification checks. Use the five step checklist to operationalize compliance.

eIDAS defines three signature levels, simple (SES), advanced (AES), and qualified (QES), and does not force any organization into one technology. A qualified electronic signature carries the same legal weight as a handwritten one. What matters for compliance is matching your identity assurance, certificate and device controls, and tamper-evident validation to the actual legal risk of the document you’re signing, backed by texts like Regulation (EU) No 910/2014 and platforms built with eIDAS in mind.
TL;DR:
- Most routine documents can be signed electronically using AES, which offers cryptographic tamper detection and signer control, but QES is necessary for high-stakes or statutory transactions.
- Recognition of notified eID schemes and certificates is automatic across the EU, but compliance depends on matching identity assurance, device controls, and legal risk for each document type.
- eIDAS specifies three formats for signatures—XAdES, CAdES, and PAdES—and validation must include certificate validity, document integrity, and adherence to recognized standards.
- Verified qualified trust service providers can issue certificates that are valid across all EU Member States, but signers must ensure the certificate was active and the signature device proper at signing time.
- Building an eIDAS-compliant process involves matching risk levels to signature types, verifying signer identity, and maintaining long-term validation records, with legal counsel recommended for high-risk or statutory documents.
Table of Contents
- What Does eIDAS Say About Electronic Signature Validity?
- What Are the Three eIDAS Signature Levels?
- What Technical Standards Does eIDAS Reference?
- Who Are Qualified Trust Service Providers and What Do They Verify?
- How Do You Build an eIDAS-Compliant Signing Process?
- Can a Signing Platform Actually Operationalize eIDAS?
- Get Your Signing Workflow eIDAS-Ready With Beesign
- Sources
- FAQ
What Does eIDAS Say About Electronic Signature Validity?
Regulation (EU) No 910/2014, commonly called eIDAS, sets a single legal framework for electronic identification and trust services across every EU Member State, applying directly without each country needing to pass its own version. Its core rule is simple to state and easy to underestimate: a signature in electronic form cannot be denied legal effect or admissibility in court solely because it’s electronic. That protection applies to all three signature types, SES, AES, and QES.
Qualified electronic signatures get a stronger guarantee. Under the eIDAS Regulation, a QES has the equivalent legal effect of a handwritten signature when it meets the Regulation’s technical requirements. That equivalence is automatic across the EU. Nothing in eIDAS, though, stops a Member State from layering on its own rules, certain contracts (real estate transfers, some family law matters) still require notarization or wet-ink signatures regardless of what eIDAS permits.
The Regulation is also technology-neutral by design. It sets outcomes, not vendors or algorithms, and requires:
- Recognition of notified eID schemes at matching assurance levels (low, substantial, high) across borders
- Non-discrimination against electronic form for admissibility purposes
- Special legal status for QES equivalent to wet-ink signing
- Room for national law to impose stricter requirements for specific transaction types
That last point trips up more compliance teams than any other part of eIDAS. The Regulation guarantees a floor, it never guarantees that electronic will satisfy every legal formality in every jurisdiction.
What Are the Three eIDAS Signature Levels?
Matching the right signature level to the right document is the single most consequential decision in an eIDAS compliance program, and it comes down to three tiers with distinct technical requirements.
Simple electronic signature (SES) covers almost anything that shows intent to sign electronically, a typed name, a scanned signature image, or a checked “I agree” box. SES is admissible under eIDAS’s non-discrimination rule, but it carries the thinnest evidentiary weight. If a signer later disputes it, you’re relying on circumstantial proof of intent rather than built-in cryptographic assurance.
Advanced electronic signature (AES) must satisfy three specific properties: it’s uniquely linked to the signer, it’s created under the signer’s sole control, and any later change to the signed document is detectable. Organizations typically meet these requirements through identity-verified accounts, unique signing credentials, and cryptographic hashing that flags tampering. This is the level most business contracts, HR documents, and vendor agreements actually need.
Qualified electronic signature (QES) takes AES and adds two more requirements: a qualified certificate issued by a qualified trust service provider, and a qualified signature creation device that keeps the signer’s private key protected. Per the Regulation itself, QES is the only tier with legal equivalence to a handwritten signature written into the text.
- Low-risk internal approvals or informal agreements: SES is usually adequate.
- Standard commercial contracts, NDAs, employment offers: AES fits, and Beesign’s breakdown of eIDAS signature levels walks through the control mapping in more detail.
- High-stakes transactions with strict statutory requirements, some loan agreements, regulated financial instruments: QES is the safer, sometimes mandatory, choice.
Pro Tip: Don’t default to QES for everything. It adds cost, friction, and certificate management overhead that most routine business documents don’t need. Reserve it for the transactions where the legal exposure justifies it.
What Technical Standards Does eIDAS Reference?
Compliance auditors and IT teams need to know the actual file formats and validation elements eIDAS points to, not just the legal categories.
Three signature formats dominate: XAdES (XML Advanced Electronic Signatures) for structured data exchanges, CAdES (CMS Advanced Electronic Signatures) for binary document signing, and PAdES (PDF Advanced Electronic Signatures) for signing PDFs directly, the format most contract platforms use because it embeds the signature inside the document itself.

Annex I of the Regulation specifies what a qualified certificate must contain: signer identity, issuer details, validity period, and a unique identifier. Annex II sets requirements for qualified signature creation devices, covering how they protect the signer’s private key and prevent unauthorized use, detail confirmed in the Regulation’s annexes. Implementing Regulation (EU) 2026/248 updates format and validation expectations further, giving Member States defined transition timelines for supporting current signature formats.
Whatever format is in play, valid AES or QES validation checks for the same things:
- Certificate validity and revocation status at the exact moment of signing
- Integrity of the document since signing, confirmed through cryptographic timestamps
- The signature container format matches a recognized standard (XAdES, CAdES, or PAdES)
- Validation metadata that a relying party or auditor can independently verify later
eIDAS never mandates a specific algorithm or vendor. What it mandates is that the outcome, verifiable identity, tamper evidence, and long-term validation, holds up regardless of which technology delivers it. One useful way to frame it: eIDAS treats compliance as an outcomes standard, not a checklist of specific software features, so audits should focus on what the signature proves rather than what tool produced it.
Who Are Qualified Trust Service Providers and What Do They Verify?
A qualified trust service provider (QTSP) is an organization formally notified by an EU Member State and listed on that state’s official trusted list, the entity responsible for issuing qualified certificates and, in many cases, operating the qualified signature creation devices behind QES. Mutual recognition means a QTSP certificate issued in one Member State is valid across all 27, provided the assurance level requirements line up, per the framework laid out in the eIDAS Regulation.
A qualified certificate itself must state the signer’s verified identity, the issuing QTSP, the certificate’s validity window, and a location where relying parties can check its status in real time.
Before relying on any signed document for a high-stakes matter, verify these points:
- The QTSP was notified and active on the relevant Member State’s trusted list at signing time
- The certificate was valid, not expired or revoked, at the moment of signature
- The signature creation device used is indicated where the certificate requires it
- The document’s cryptographic integrity is intact from signing to the point you’re checking it
EU trusted lists and QTSP registries are public, and validation tools can check certificate and provider status directly rather than taking a signed PDF’s word for it.
How Do You Build an eIDAS-Compliant Signing Process?
Start by mapping risk before you map technology. Low-risk internal documents can run on SES. Commercial contracts generally call for AES, with identity-verified signer accounts and tamper-evident audit trails as the baseline controls. High-risk, statute-heavy transactions should default to QES, and Beesign’s guide on eIDAS-compliant electronic signatures breaks down how that mapping typically plays out in practice.
From there, work through this sequence:
- Verify signer identity through a method proportional to the document’s risk level.
- Choose your certificate source, self-managed for AES, a QTSP for QES.
- Confirm key management or QES device handling meets the qualified device requirements.
- Generate tamper-evident audit trails with cryptographic timestamps at signing.
- Retain signed records with long-term validation support so they’re checkable years later.
Handle consent disclosures, hardware and software compatibility for future access, and certificate revocation scenarios before they become a problem, not after a dispute lands on your desk.
Pro Tip: If a transaction touches statutory writing requirements or notarization rules in a specific jurisdiction, loop in legal counsel before you finalize the signature level. No platform decision overrides a national law requiring a wet-ink signature.
Can a Signing Platform Actually Operationalize eIDAS?
Compliance frameworks are only as good as the systems enforcing them day to day. A platform built around identity verification, tamper-evident audit trails, and bring-your-own-cloud storage turns the eIDAS checklist into something your team runs consistently instead of reconstructing for every audit. Beesign’s approach to identity verification and audit logging exists for exactly that reason: centralized validation beats ad hoc proof-gathering every time. Start with your highest-risk workflows first, and bring in legal counsel wherever QES-level certainty is genuinely required.
— Mustafa Abusharkh
Get Your Signing Workflow eIDAS-Ready With Beesign
This platform is designed for organizations that need identity-verified signing, tamper-evident audit trails, and control over where their data lives, all without juggling separate tools for each requirement.

That combination matters most for AES-level agreements, where sole control and tamper detection aren’t optional extras, they’re the legal foundation of the e-signature. Beesign’s electronic signature platform pairs identity checks with automatic audit trails, and its white-label and BYOC options let regulated organizations keep signed records inside their own infrastructure instead of a third-party black box. Teams that need automated document routing can also use an API to build compliance checks directly into existing workflows.
The Individual plan starts at $9.99 per month, and Enterprise pricing with custom integrations is available on request. If your organization handles contracts where QES is the safer call, talk to legal first, then start a trial to see how the rest of the workflow, identity verification, audit trails, retention, fits together before you commit.
Sources
- Regulation (EU) No 910/2014 (eIDAS) — EUR-Lex
- 15 U.S.C. §7001 — ESIGN Act (US Government Publishing Office)
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
What Are the Requirements for a Valid Electronic Signature Under eIDAS?
A valid electronic signature under eIDAS needs a clear indication of intent to sign, and if it’s an AES, it must be uniquely linked to the signer, created under their sole control, and capable of detecting any later change to the document. QES adds a qualified certificate and a qualified signature creation device on top of those AES requirements, as defined in the eIDAS Regulation.
What Counts as an Acceptable Electronic Signature?
Almost any method showing clear intent to sign counts as acceptable under eIDAS, including a typed name, a checkbox, or a scanned signature image at the SES level. The right choice depends on the transaction’s legal risk: routine business documents typically work fine with AES, while statutory or high-value transactions often call for QES.
What Is the Difference Between AES and QES?
AES requires a unique signer link, sole control, and tamper detection, met through identity-verified accounts and cryptographic hashing. QES requires all of that plus a qualified certificate from a qualified trust service provider and a qualified signature creation device, and only QES carries automatic legal equivalence to a handwritten signature.
Does eIDAS Apply Outside the European Union?
eIDAS governs electronic signatures and trust services within the EU, but organizations signing documents that touch U.S. commerce should also check requirements under the ESIGN Act, which similarly bars denying legal effect to electronic signatures but adds its own consumer-consent and record-access rules.
Does Beesign Support eIDAS Signature Levels?
Beesign’s platform supports identity verification and tamper-evident audit trails that map to AES-level requirements, along with BYOC storage for organizations that need to keep signed records within their own infrastructure. Current pricing and plan details are available on Beesign’s pricing page.
Recommended
Ready to transform your workflow?
Start using BeeSign today and experience the future of document signing