Skip to main content
eIDAS Regulation

What is an electronic signature? The complete eIDAS guide

Signing contracts, issuing authorisations, archiving documents – in many companies today, all of this has long since been done without paper. The legal basis for this is the EU’s eIDAS Regulation, which, since 2016, has provided a uniform framework defining what an electronic signature is, the three levels of electronic signatures, and the legal effect each one has. According to Fortune Business Insights, the European market for digital signatures grew to USD 2.43 billion in 2024 alone — and is set to rise to USD 42.08 billion by 2032 (Fortune Business Insights, Europe Digital Signature Market, 2024).

What is driving this growth? And, above all: which signature level do you actually need for your documents?

This guide answers exactly that — from the definition and the three types to the question of what eIDAS 2.0 and the EUDI wallet will mean for your business from December 2026 onwards.

Over 40,000 customers worldwide who place their trust in us

Contents

Key points at a glance

  • The eIDAS Regulation (EU No 910/2014) defines three levels of electronic signatures: EES, FES and QES — valid in all 27 EU Member States.
  • No EU court may reject an electronic signature solely on the grounds that it is not on paper (Article 25(1) of the eIDAS Regulation).
  • The QES is legally equivalent to a handwritten signature — but is not required for most commercial contracts.
  • Biometric signatures on signotec signature pads meet all four requirements for FES set out in Article 26 of eIDAS and are legally valid in court.
  • By December 2026, all EU Member States must provide an EUDI wallet that enables QES directly from a smartphone (Regulation (EU) 2024/1183, Article 5a).

What is an electronic signature under eIDAS?

The eIDAS Regulation (Regulation (EU) No 910/2014) defines an electronic signature as “data in electronic form which is attached to or logically associated with other electronic data and which the signatory uses to sign” (Article 3(10) of the eIDAS Regulation). In practice, this means that any digital process by which a person confirms the authenticity and integrity of an electronic document can constitute an electronic signature — ranging from simply entering one’s name to a cryptographically secured qualified signature.

Important: Since 1 July 2016, eIDAS has been directly applicable in all 27 EU Member States. A signature issued in Germany is automatically recognised as legally valid in France, Austria, Spain or the Netherlands — without any additional formalities.

Electronic vs. digital signatures — what’s the difference?

In everyday language, both terms are used interchangeably. This is technically inaccurate: ‘electronic signature’ is the legally correct generic term under eIDAS. ‘Digital signature’ refers to the cryptographic process (asymmetric key pair) used to secure FES and QES. A qualified electronic signature is therefore always a digital signature — but not every digital signature meets the standards of a QES.

Basic legal principle: No court may refuse

Article 25(1) of eIDAS stipulates that an electronic signature must not be denied legal effect or admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form or does not meet the requirements for a qualified electronic signature. This is a mandatory EU standard — it applies in every Member State, irrespective of national law.

A legal framework

What are the three levels of signature defined by eIDAS?

The eIDAS Regulation recognises three levels that build on one another. They differ in terms of security level, technical complexity and legal binding effect. Which level you require depends on the document and the applicable formal requirements — not on a general hierarchy of ‘most secure’.

Simple electronic signature (EES)

The EES is the most accessible form. A scanned image of a signature, a typed name at the end of an email, or clicking ‘I agree’ on a web form can all count as an EES. It is suitable for low-risk documents where there are no statutory formal requirements: internal approvals, informal agreements, orders placed in secure systems.

The EES does not usually offer any cryptographic protection. Anyone wishing to challenge it in court has an easier time of it, as the party relying on the signature must prove its authenticity.

Advanced Electronic Signature (AES)

The FES meets four cumulative requirements set out in Article 26 of eIDAS:

  1. It is uniquely linked to the signatory.
  2. It enables the signatory to be identified.
  3. It has been created using data which the signatory can use with a high level of confidence and which is under their sole control.
  4. It is linked to the signed data in such a way that any subsequent alterations are detectable.
Qualified Electronic Signature (QES)

The QES is the highest level. It builds on the FES and adds two further requirements (Article 28 of eIDAS):

  • It must be created using a qualified electronic signature creation device (QSCD).
  • It must be based on a qualified certificate issued by a qualified trust service provider (QTSP) included on an EU trust list.

Important: Article 25(2) of eIDAS stipulates that a QES has the same legal effect as a handwritten signature.

What level of digital signature does your document actually require?

A common misconception in practice: many companies specifically seek out QES solutions because they are regarded as the ‘highest’ level of security — even though the FES is entirely sufficient for the process in question from a legal perspective. If QES is then actually implemented, this results in unnecessary costs and more complex processes, without any real legal added value. The right question is not ‘How secure does it need to be?’, but rather: ‘What formal requirements apply to the document in question?’

Documents for which an electronic signature is not sufficient

The following examples are provided for your guidance. Please note that this list is not exhaustive. 

DocumentSector / AreaReason
Consumer guarantee declarationBanks / LawElectronic form prohibited by law (Section 766, sentence 2 of the German Civil Code (BGB))
Property Purchase AgreementProperty / LawNotarial certification required by law (Section 311b of the German Civil Code (BGB))
Promise of a giftPrivate / LawNotarial certification required by law (Section 518 of the German Civil Code (BGB))
Inheritance contractPrivate / LawNotarial certification required by law (Section 2276 of the German Civil Code (BGB))
Termination and settlement agreements for employment contractsTrade & Industry / HRElectronic form excluded by law (Section 623 of the German Civil Code (BGB))

Documents for which QES is required by law

The following examples are provided for your guidance. Please note that this list is not exhaustive.

DocumentSector / AreaReason
Fixed-term employment contract (in writing in accordance with Section 14 of the TzBfG)Retail & Industry / HRWritten form required by law (Section 14 of the TzBfG)
Interest-bearing consumer loan agreementBanksWritten form required by law (Section 492 of the German Civil Code (BGB))
Tenancy agreement with a fixed term of more than one yearPropertyWritten form required by law (Section 550 of the German Civil Code (BGB))
Employment referencesTrade & Industry / HRWritten or electronic form required by law (Section 109(3) of the Trade Regulation Act (GewO), Section 630(3) of the German Civil Code (BGB), as amended)

Documents for which FES is sufficient

The following examples are provided for your guidance. Please note that this list is not exhaustive.

DocumentSector / AreaReason
Goods Receipt Confirmation / Delivery NoteRetail & IndustryThe recipient signs on the pad upon receipt of goods; the signature is permanently linked to the document and immediately available in the system
Account opening supporting documents, consultation reportBanksMeets documentation requirements. FES with biometrics or two-factor authentication strengthens the chain of evidence
Claim notification / claim reportInsuranceLegally valid signature provided on-site by the surveyor or claims handler
Engagement agreementTax consultancyClear assignment to the client via biometric signature directly at the reception desk
Administrative forms, applicationsGovernment departmentsIn most cases, FES replaces the signature on paper directly at the POS / counter
Patient consent, treatment contractHealthcareBiometric FES ensures proof of personal consent at the place of treatment
Permanent employment contracts, addenda and supporting documents (NachwG)Retail & Industry / HRFES ensures proof and provides long-term evidential value

How does the advanced electronic signature work from a technical point of view?

The FES is the level at which signotec demonstrates its core expertise. There are two technical approaches to meeting the four requirements set out in Article 26: OTP-based FES and biometric FES. Both are legally equivalent — but they are not equivalent from a forensic perspective.

OTP-based FES

Before signing, the signatory receives a one-off code via text message or email. The code confirms the signatory’s identity, is linked to the document and thus establishes a unique association. This method is well suited to remote signatures: the signatory is not physically present, and a simple identity check via a known mobile number is sufficient.

Limitation: If the mobile number used for the text message has been compromised, or if the signatory later denies having provided the signature themselves, the only evidence remaining is the record of the OTP being sent — not any physical characteristic of the signatory.

Biometric FES on signotec signature pads

With biometric FES, the person signs using a stylus on a signotec signature pad — just as usual, but digitally. The pad captures far more than just the visible handwriting, including:

  • The pen’s pressure curve with millisecond resolution
  • The speed and acceleration of the hand movement
  • Points where the stylus is lifted
  • The individual temporal rhythm of the signature

Each of these characteristics is unique to the signatory.

This raw data is cryptographically encrypted and embedded within the document. It is inextricably linked to the exact content of the document — any subsequent alteration to the document invalidates the signature. In the event of legal disputes, the biometric data can be analysed by graphometric experts. This provides a level of evidential strength that an SMS OTP signature cannot structurally achieve.

According to Article 26 of eIDAS, the FES must be ‘created using data that the signatory can use under their sole control with a high level of confidence’. Biometric handwriting data is exclusively linked to the physiological characteristics of the signatory — no other method meets this requirement more directly. (Regulation (EU) No 910/2014, Article 26(c))

What does eIDAS 2.0 say – and what changes will take effect by December 2026?

The revised eIDAS Regulation (EU 2024/1183) came into force on 20 May 2024. It does not alter the three-tier hierarchy of EES, FES and QES — nor does it alter the legal effect of the individual tiers. What it introduces is the European Digital Identity Wallet (EUDI Wallet).

What is the EUDI Wallet?

The EUDI Wallet is a government-issued app in which citizens can store digital proof of identity, qualifications and documents — and use to create QES directly from their smartphone, without the need for a hardware token or smartcard. By December 2026, every EU Member State must offer at least one such wallet (Regulation (EU) 2024/1183, Art. 5a).

From 1 January 2027, public authorities will be obliged to accept the EUDI Wallet as a means of identification. From 31 December 2027, this will also apply to certain private companies in regulated sectors (financial services, telecommunications, healthcare).

Specifically: anyone operating QES processes must, from 2027, accept identity verification via the EUDI wallet as a means of authentication. This significantly simplifies remote QES — but does not alter the signature level logic itself.

In 2024, Regulation (EU) 2024/1183 (eIDAS 2.0) came into force, obliging all 27 EU Member States to provide at least one EUDI wallet by December 2026 that enables QES directly from a smartphone — without the need for a physical security device (eIDAS 2.0, Art. 5a; European Commission, European Digital Identity Wallet, accessed 17 June 2026).

How to implement eIDAS-compliant signatures — the technical requirements

An eIDAS-compliant signature solution must meet three requirements: the correct signature format, long-term validity and data protection compliance of the infrastructure.

Signature formats: PAdES, CAdES, XAdES
The ETSI standards specify the technical structure required for electronic signatures. For PDF documents, PAdES (PDF Advanced Electronic Signatures, ETSI EN 319 132) is the relevant standard. PAdES is integrated into the document container — the document and the signature form a single unit that cannot be separated. For other file formats, CAdES (CMS Advanced Electronic Signatures, for any file type) and XAdES (XML Advanced Electronic Signatures, for XML-based processes) apply.
Long-term validation (LTV)
A frequently overlooked issue: a signature that is valid today must still be verifiable in ten years’ time — even if the certificate used has expired in the meantime. PAdES-LT (Long-Term) and PAdES-LTA (Long-Term with Archive Timestamp) embed all validation information (certificate chain, revocation information, timestamps) directly into the document. For organisations subject to statutory retention periods of 10 years, LTV is not an option, but a requirement.
On-premises vs. cloud signing
Many cloud-based signature solutions store private keys and signature data on servers outside the EU or in shared infrastructures. For organisations in regulated sectors — banks, health insurers, public administration — this may conflict with the GDPR, DORA (Digital Operational Resilience Act) or sector-specific regulatory requirements. On-premises deployment means that all signature data, biometric information and private keys remain on the organisation’s own infrastructure. This is not merely a convenience feature — for many regulated organisations, it is a compliance requirement.

Electronic signatures versus handwritten signatures: Which is more secure?

A common misconception is that, in case of doubt, a handwritten signature is more legally secure. This is not true — at least not across the board. A QES has the same legal effect as a handwritten signature (Article 25(2) of eIDAS). Furthermore, a biometric FES provides evidence that a paper signature is structurally incapable of providing:

CharacteristicHandwritten signatureBiometric FES
Tamper-evident featureNot provided automaticallyCryptographically secured
TimestampNot tamper-proofCryptographically anchored
Proof of identityHandwriting expert requiredGraphometric analysis of biometric data
ArchivabilityPhysical document requiredDigital, can be replicated as often as required
Process efficiencyPrinting, dispatch, scanning, filingFully digital

Get advice now or request a demo

  • Request a personalised demonstration – tailored to your requirements
  • Or speak directly to our team of experts for personalised advice
More than 40.000+ companies
are already using signotec.
FAQ

Frequently asked questions about electronic signatures under eIDAS

Conclusion: The right level — not the highest

Electronic signatures are no longer a niche topic. They form the technical and legal basis for every paperless document process in the EU. Anyone who understands the three levels – EES, FES and QES – who knows when which formal requirements apply, and who uses the biometric FES as a fully-fledged — and in some respects superior — substitute for the handwritten signature, lays the foundation for legally compliant and efficient processes.

The aim is not to use the highest level in every instance. The aim is to choose the right level for each document — and to implement it fully and transparently.

signotec offers hardware and software for the entire spectrum of electronic signatures: from signature pads for on-site biometric FES, through desktop workflows, to QES and remote signatures. Get in touch — we’ll advise you on which solution suits your specific use case.

Sources

• Regulation (EU) No 910/2014 of the European Parliament and of the Council (eIDAS), Official Journal of the EU, 28 August 2014. Articles 3, 25, 26 and 28. https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32014R0910, accessed 17 June 2026.
• Regulation (EU) 2024/1183 of the European Parliament and of the Council (eIDAS 2.0), Official Journal of the EU, 30 April 2024. Art. 5a. https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32024R1183, accessed 17 June 2026.
• Fortune Business Insights, Europe Digital Signature Market Size, Share & Growth, 2024. https://www.fortunebusinessinsights.com/europe-digital-signature-market-107411, accessed 17 June 2026.
• European Commission, European Digital Identity Wallet, 2026. https://digital-strategy.ec.europa.eu/en/policies/eudi-wallet, accessed 17 June 2026.
• Federal Law Gazette, Bureaucracy Relief Act IV (BEG IV), BGBl. 2024. In force since 1 January 2025.
• ETSI, EN 319 132-1: Electronic Signatures and Infrastructures (ESI); XAdES digital signatures, 2016.
• Federal Office for Information Security (BSI), eIDAS Regulation. https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/eIDAS-Verordnung/eidas-verordnung_node.html, accessed 17 June 2026.