eIDAS Signature Levels: SES, AES, and QES Explained
Understand eIDAS signature levels: explore how simple, advanced, and qualified signatures differ and which one is best for your needs.

eIDAS defines three levels of electronic signature: simple (SES), advanced (AES), and qualified (QES). Each level builds on the last, and the legal strength runs QES > AES > SES, with QES carrying a presumption of validity that puts it on equal footing with a handwritten signature. A basic click-to-agree checkbox is SES. A signature tied to a verified identity and locked to that signer’s control is AES. A signature backed by a qualified certificate and a certified device is QES.
For most day-to-day business, AES is the right call. It gives you identity assurance, a tamper-evident audit trail, and enough legal weight to hold up in a contract dispute. Reserve QES for situations where a regulation names it specifically, or where the transaction is high value enough that you want the burden of proof to sit with the person challenging the signature, not with you.
- SES: a typed name, a scanned signature, or a click-to-sign box, with minimal identity verification.
- AES: uniquely linked to the signer, created under their sole control, and any later change to the document is detectable.
- QES: everything AES requires, plus a qualified certificate issued by an accredited provider and a certified signing device.
TL;DR:
- Most commercial transactions are best suited to advanced signatures due to their balance of identity assurance and proof detection without the higher costs of QES.
- Qualified electronic signatures offer a presumption of validity comparable to handwritten signatures but require verified identity through face-to-face, eID, or supervised video KYC.
- Cross-border recognition of QES is automatic across the EU, while AES remains enforceable but lacks universal recognition, with SES recognition depending on local laws.
- Moving from AES to QES involves increased cost, hardware or cloud-based certificate needs, and user friction, which should be carefully managed based on transaction risk.
- Hybrid workflows routing most contracts through AES and only high-risk or regulated deals through QES can optimize legal certainty and operational efficiency.
Table of Contents
- What Are eIDAS Signature Levels and Their Legal Basis?
- How Do the Legal and Technical Requirements Compare?
- When Should You Use Each Signature Level?
- What Should You Budget for When Implementing eIDAS Signatures?
- How Beesign Supports AES and QES Workflows
- How Do eIDAS Levels Compare to Other Digital Signature Standards
- What Security Risks Come With Each Signature Level
- What Does a QTSP Do and How Does Accreditation Work
- What Challenges Come Up When Deploying eIDAS Signature Levels
- What’s Next for eIDAS Signature Regulations
- Key Takeaways
- Sources
What Are eIDAS Signature Levels and Their Legal Basis?
The European Commission’s eIDAS guidance sets out SES, AES, and QES as a tiered structure, and understanding the legal basis for each one matters more than memorizing the acronyms.
Simple Electronic Signature (SES) covers almost anything that shows intent to sign electronically: a typed name at the bottom of an email, a scanned image of a wet signature, or a checkbox on a web form. eIDAS does not require any identity verification for SES, which is exactly why it carries the least evidential weight. If a signer disputes an SES contract, you may need supporting evidence (emails, IP logs, timestamps) to prove they actually agreed to it.
Advanced Electronic Signature (AES) has to meet four specific criteria under Article 26 of the regulation:
- It is uniquely linked to the signer.
- It is capable of identifying the signer.
- It is created using signature data the signer keeps under their sole control.
- It is linked to the signed document so that any later change is detectable.
Most e-signature platforms achieve this through a combination of email or SMS verification, unique cryptographic keys generated per signer, and a hash-based seal on the final document. You don’t need government-issued ID for AES in most cases, though stronger identity proofing (a scanned ID plus a selfie match, for instance) makes the resulting signature harder to challenge later.
Qualified Electronic Signature (QES) takes AES and adds two hard requirements: the signature must be created with a Qualified Signature Creation Device (QSCD), and it must rest on a qualified certificate issued by a Qualified Trust Service Provider (QTSP). That combination is what gives QES its unique status.
Pro Tip: A QES carries a legal presumption of equivalence to a handwritten signature under Article 25 of eIDAS, meaning the burden shifts to whoever disputes it, rather than to the person relying on the signature, according to Certyneo’s breakdown of the three levels.
That presumption is the single biggest reason organizations pursue QES for anything with real legal exposure. AES and SES both remain enforceable in most jurisdictions, but if a signature is ever challenged in court, you’re the one who has to prove it’s authentic. Learn more about how these levels affect enforceability.
How Do the Legal and Technical Requirements Compare?
The gap between AES and QES isn’t cosmetic. It changes who has to prove what, what hardware or service you need, and how the signature is recognized once it crosses a border.
| Factor | SES | AES | QES |
|---|---|---|---|
| Legal presumption | None | None (enforceable but must be proven) | Presumption of validity, equivalent to handwritten signature |
| Burden of proof | On the relying party | On the relying party | Shifts to the party disputing it |
| Certificate required | No | Optional, not qualified | Yes, qualified certificate from a QTSP |
| Signing device | Any device | Standard PKI or hosted keys | Certified QSCD (hardware or certified cloud) |
| Identity verification | Minimal or none | Email/SMS, sometimes ID + biometric match | Face-to-face, eID, or supervised video KYC |
| Cross-border recognition | Not guaranteed | Recognized but not automatically equivalent | Automatically recognized across all EU member states |
Signicat’s comparison of advanced and qualified signatures puts it plainly: in a dispute, QES benefits from the presumption while AES and SES don’t, which changes how a court weighs the evidence from day one.
Identity assurance is where the practical differences show up first. AES platforms typically verify identity through email confirmation, SMS one-time codes, or a document-plus-selfie check. QES requires something stronger, usually a face-to-face appointment, a recognized eID scheme, or a supervised video KYC session run by the QTSP itself.
- QES issued by any EU-recognized QTSP is valid across all EU member states, per Certyneo’s eIDAS guide, which matters if you’re signing cross-border contracts.
- AES has no automatic cross-border equivalence guarantee, though most EU courts accept it when the technical criteria are documented.
- SES cross-border recognition depends entirely on the receiving country’s own evidentiary rules.
When Should You Use Each Signature Level?
Match the signature level to the risk, not to what feels most secure. Over-engineering a low-stakes approval with QES wastes time and money; under-securing a high-value contract with SES invites a dispute you can’t easily win.
- SES fits internal approvals, consumer terms-of-service clicks, and other low-risk agreements where a dispute is unlikely and the cost of being wrong is small.
- AES fits employment contracts, NDAs, vendor agreements, and most commercial contracts where you want a real audit trail and verified identity but don’t face a specific legal mandate for QES.
- QES fits public procurement submissions, regulated financial transactions, notarized real estate transfers, and any cross-border contract where you need guaranteed equivalence to a wet signature.
YouTrust’s guidance on high-value contracts recommends AES as the default for commercial workflows and QES only where the law names it or the deal size justifies the extra friction.
Pro Tip: *Run a hybrid model. Use AES for your high-volume, everyday contracts, and route only the transactions that trigger a legal or regulatory requirement through QES.
What Should You Budget for When Implementing eIDAS Signatures?
Cost and friction rise sharply once you move from AES to QES, and knowing where that jump happens lets you plan a realistic pilot instead of guessing at a company-wide rollout.
- Map your cost drivers first. AES typically runs on a per-signature or per-seat SaaS fee with no extra hardware. QES adds qualified certificate costs and QSCD fees, whether that’s a hardware token or a certified cloud service, which is why Certyneo notes that QES implementation carries higher cost and complexity than AES.
- Weigh the user experience trade-off. AES flows can complete in under a minute with email verification. QES often requires a video KYC session or a hardware token, which adds real friction, especially for signers who aren’t tech-savvy.
- Choose your QSCD deployment model. You can run a local hardware HSM, use a certified cloud QSCD, or bring your own cloud (BYOC) infrastructure to keep signing keys inside your own environment for compliance reasons.
- Plan for integration and long-term validation. Your API needs to capture a complete audit trail, and your archiving strategy needs to support long-term validation (LTV) so signatures remain verifiable years after signing.
BeeSign’s identity verification guide walks through how video KYC and document-matching options affect both cost and completion rates, which is worth reviewing before you commit to a specific identity verification vendor.
How Beesign Supports AES and QES Workflows
Beesign is built around the identity and audit requirements both AES and QES demand, not just basic click-to-sign. Government ID capture and biometric face matching give you the identity proofing layer AES needs and the documentation trail QES processes require. Every document carries a complete audit trail with blockchain timestamp proof, which satisfies the “detectability of changes” criterion under Article 26.
- White-label and bring-your-own-cloud (BYOC) deployment keep signing infrastructure inside your own environment, which matters for regulated industries with strict data residency rules.
- A developer REST API automates identity checks, document routing, and certificate handling across high-volume AES workflows.
- Identity verification tools map directly to the stronger proofing that QES eventually requires if you scale up from AES.
A signature platform that can’t show you exactly who signed, when, and whether the document changed afterward isn’t giving you AES. It’s giving you SES with better branding.
How Do eIDAS Levels Compare to Other Digital Signature Standards
eIDAS isn’t the only framework governing electronic signatures, and if you operate across the Atlantic, you’re dealing with a different legal structure entirely. In the United States, the ESIGN Act and UETA (adopted by nearly every state) take a more permissive, intent-based approach. Neither law creates tiered signature levels the way eIDAS does. Instead, both ask a simpler question: did the signer intend to sign, and can you prove it?
That difference matters practically. A signature that qualifies as AES under eIDAS would almost certainly satisfy ESIGN and UETA requirements too, since US law doesn’t demand a qualified certificate or a QSCD for validity. But the reverse isn’t automatically true. A signature valid under UETA might not clear the AES bar in the EU if it lacks the sole-control and change-detection elements Article 26 requires.
For companies operating in both markets, the practical move is to build workflows that satisfy the stricter standard, generally AES or QES, since that approach tends to clear the lower US bar as well. A best UETA compliant esign or best eIDAS compliant esign platform, in practice, is usually the same platform: one that captures strong identity evidence and a tamper-evident audit trail regardless of which regulation ultimately governs the dispute. That’s a meaningfully different posture than treating US and EU compliance as two separate projects.
What Security Risks Come With Each Signature Level
Security risk scales inversely with the legal protection each level provides, and that relationship is worth sitting with before you pick a level based on convenience alone.
SES carries the highest practical risk because it offers almost no built-in identity verification. A typed name or a checkbox click can be repudiated relatively easily, and if your only defense is a server log or an email thread, you’re reconstructing evidence after the fact rather than relying on the signature itself.
AES closes much of that gap. The sole-control requirement means the signing key or credential is tied to one person, and the tamper-evident seal means any post-signing edit breaks the signature’s validity, alerting both parties immediately. The main residual risk with AES sits in identity proofing quality. An AES signature verified only by email confirmation is weaker than one verified with a document-and-selfie check, even though both technically qualify as AES.
QES minimizes signer-side risk almost entirely by shifting identity verification to an accredited third party and locking signing keys inside a certified device. The remaining risk shifts to the QTSP itself: if a qualified certificate authority is compromised, the fallout affects every signature it issued. That’s rare, but it’s the reason regulators require QTSPs to meet strict accreditation standards rather than letting any vendor self-certify.

What Does a QTSP Do and How Does Accreditation Work
A Qualified Trust Service Provider is the accredited entity that makes QES possible. Without a QTSP, there’s no qualified certificate, and without a qualified certificate, a signature can’t legally be called QES no matter how strong its underlying technology is.
QTSPs undergo a formal accreditation process supervised by a national supervisory body in an EU member state. That process includes an independent conformity assessment against eIDAS technical standards, background checks on the organization’s security practices, and ongoing audits to keep the accreditation active. Once accredited, a QTSP is listed on the EU’s Trusted List, a public registry that lets any relying party verify a given provider is legitimately authorized to issue qualified certificates.
The QTSP’s job doesn’t end at issuance. It verifies signer identity (often through face-to-face appointment, eID, or supervised video KYC), issues and manages the qualified certificate’s lifecycle, and in many cases provides or certifies the QSCD used to create the signature. Some QTSPs offer certified cloud-based QSCDs, which lets organizations avoid distributing physical hardware tokens to every signer while still meeting the device requirement.
Because QTSP accreditation is nationally supervised but mutually recognized across the EU, a qualified certificate issued in one member state carries the same legal weight in every other member state, which is the backbone of the cross-border recognition that makes QES useful for international contracts.
What Challenges Come Up When Deploying eIDAS Signature Levels
The most common deployment mistake is applying QES everywhere out of caution, then watching signing completion rates drop because signers abandon a video KYC session or can’t locate a hardware token. Friction is the single biggest practical obstacle to QES adoption, and it’s almost always underestimated during planning.
Identity verification mismatches cause a second wave of problems. Teams sometimes assume any ID check counts as sufficient AES proofing, then discover during a dispute that their verification method was too weak to support the “identifying the signer” criterion under Article 26. Document that decision at the point of implementation, not after a challenge arises.
Cross-border deployments introduce a third layer of complexity: a QTSP accredited in one country is automatically recognized elsewhere in the EU, but signers in non-EU jurisdictions may not have access to the eID schemes or in-person verification options a QTSP typically requires, forcing teams to build fallback verification paths.
Integration friction is common too. Legacy document management systems weren’t built with long-term validation (LTV) in mind, and archiving a QES signature so it remains verifiable a decade later requires re-timestamping infrastructure many organizations don’t have until they’re forced to build it. Public-sector procurement, which frequently mandates digital certificates for submissions, is a useful reference point for how technology-driven certificate workflows get handled at scale, as seen in how GSA structured its shift toward digital certificate use in federal procurement.

What’s Next for eIDAS Signature Regulations
eIDAS 2.0 is pushing the regulation toward the European Digital Identity Wallet, a framework that will let citizens and businesses hold verified credentials, including qualified certificates, directly on a mobile device rather than obtaining them through a separate QTSP appointment each time. That shift is likely to lower the friction that currently keeps QES adoption below AES, since wallet-based identity could make qualified signing nearly as fast as advanced signing.
Expect QTSP accreditation standards to tighten further as regulators respond to the growing sophistication of identity fraud, particularly around remote video KYC processes that became common after the increase in remote signing. Cloud-based QSCDs will likely keep gaining ground over hardware tokens, since certified cloud services remove the logistical burden of distributing physical devices to distributed workforces.
The interoperability push between eIDAS and non-EU frameworks, including UETA and ESIGN in the US, is also likely to continue, driven by multinational companies that need one signing workflow to satisfy multiple jurisdictions rather than maintaining parallel compliance programs. None of this changes the core three-tier structure of SES, AES, and QES in the near term, but it will change how quickly and cheaply organizations can reach the higher tiers.
A Practical View on Choosing a Signature Level
Most enterprises overthink this decision by treating it as one choice instead of two. The smarter approach is a hybrid: default to AES for the bulk of commercial signing, and carve out a short list of document types (real estate, regulated finance, public procurement) that get routed to QES because law or risk demands it. Before committing budget to either tier, run a regulatory check against your specific sector and pilot the identity verification flow with real signers. Friction and cost look very different on paper than they do once actual users hit the video KYC step or fumble with a hardware token.
— Mustafa Abusharkh
Get Compliant AES and QES Workflows Running With Beesign
Beesign gives you a direct path from AES to QES without stitching together separate vendors for identity checks, certificate handling, and document storage. Government ID capture and biometric face matching cover the identity proofing layer both levels need, while bring-your-own-cloud deployment keeps signing data inside your own infrastructure for teams that can’t compromise on data residency.

If you’re closing commercial deals and need AES-level signing built into your sales workflow, the Sales & Business solution is built for exactly that. Regulated teams that need signing to run entirely under their own domain and branding, with certified QSCD deployment options, should look at the White Label and BYOC offering. Start a free trial and test your actual documents against both AES and QES workflows before committing to a rollout.
Key Takeaways
Choosing the right eIDAS signature level comes down to matching legal risk to technical requirements, with AES covering most commercial needs and QES reserved for regulated or high-stakes transactions.
| Point | Details |
|---|---|
| Three levels, rising legal weight | SES, AES, and QES form a hierarchy where QES alone carries a presumption of validity equivalent to a handwritten signature. |
| AES fits most contracts | Employment agreements, NDAs, and commercial deals rarely need more than AES’s identity linkage and tamper-evident seal. |
| QES shifts the burden of proof | In a dispute, QES puts the burden on the challenger; AES and SES leave it with the relying party. |
| QTSP accreditation backs QES | Qualified certificates only carry legal weight when issued by an EU-accredited QTSP listed on the Trusted List. |
| Beesign supports both tiers | Beesign’s identity verification, audit trails, and BYOC deployment map directly to AES requirements and scale toward QES workflows. |
Sources
- What is eSignature - European Commission
- Advanced vs qualified electronic signatures: what is the difference? - Signicat
Recommended
Ready to transform your workflow?
Start using BeeSign today and experience the future of document signing