Skip to content

Practice

E-signatures under eIDAS: three levels, and when the difference matters

Most documents do not need the strongest form of electronic signature. Knowing which ones do is the whole skill.

Dainius Alekna

Legal Engineer

·8 min read

Electronic signature questions arrive in legal teams in a predictable shape. Someone in the business wants to sign something quickly, someone in legal is uneasy, and nobody can articulate precisely what the unease is about. The conversation then collapses into a binary — is this allowed or not — when the real question is which of several available instruments is proportionate.

The EU framework, commonly referred to as eIDAS, sets out a tiered structure rather than a single rule. Understanding the tiers is what turns this from a recurring argument into a policy.

Three levels, in increasing order of ceremony

The simple electronic signature is the broad category: essentially any data in electronic form attached to or logically associated with other data, used by the signatory to sign. A typed name at the foot of an email, a scanned image of a signature, a click on an "I agree" button. It is a signature, and the framework is explicit that it cannot be denied legal effect purely because it is electronic. What it lacks is any inherent evidential strength — if the signatory later denies signing, you are proving the point with whatever surrounding evidence you happen to have.

The advanced electronic signature adds requirements about the link between signature and signatory: it must be uniquely linked to and capable of identifying the signatory, created using means under the signatory's sole control, and linked to the signed data so that any subsequent change is detectable. In practice this is what mainstream signing platforms produce — cryptographic binding plus an audit trail covering identity checks, timestamps and the document hash. The evidential position is materially stronger.

The qualified electronic signature is the advanced signature created by a qualified signature creation device and based on a qualified certificate issued by a trust service provider on the EU trusted list. Its distinguishing feature is legal rather than technical: it has the equivalent legal effect of a handwritten signature, and it must be recognised across member states. This is the level associated with national eID schemes and qualified certificates issued to individuals.

Deciding what to use

The useful framing is not "how secure do we want to be" but "who might dispute this, and what would we need to show".

Three questions get most teams to an answer:

  1. Does a specific rule prescribe a form? Certain transactions — commonly those involving real property, succession, family matters, some corporate acts and certain guarantees — carry formality requirements set by national law, which may demand notarisation or a specific signature level. This is jurisdiction-specific and it is the first thing to check, not the last.
  2. What is the realistic dispute scenario? A recurring low-value supplier order signed by a known counterparty carries a different risk profile from a one-off settlement with a party who has already proved difficult. Match the ceremony to the likelihood and cost of someone denying it.
  3. Who needs to be persuaded? Sometimes the constraint is not legal validity but an institution — a registry, a bank, a counterparty's own policy — that will only accept a particular form. Validity and acceptability are different problems and the second is often the binding one.

What to retain

Whichever level is used, the evidential value depends almost entirely on what you keep. A signed PDF sitting in a folder, detached from its audit trail, is much weaker than the signing platform's record suggests.

A sensible retention set: the signed document in its final form; the platform's completion certificate or audit trail, including timestamps, IP or device information and the identity verification method used; the document hash; and the record of what the signatory was actually shown at the point of signing. The last one is frequently overlooked and frequently decisive — a dispute about whether someone agreed to a term often turns on whether the term was visible on the screen where they clicked.

Store all of it with the matter, not in the signing platform alone. Platform subscriptions lapse, exports get forgotten, and the audit trail matters most several years after anyone is still paying for the tool that produced it.

Building it into a policy

Firms that handle this well convert the analysis into a short internal matrix. Document type down one axis, permitted signature level and required retention across the other, with an escalation route for anything not listed. Two pages, approved once, saves the same argument recurring monthly.

The matrix should also record the exceptions where wet ink or notarisation remains necessary — partly to prevent an expensive mistake, and partly because being able to say precisely which categories are excluded is what gives the business confidence in everything that is not.

The final piece is a review date. National implementations and institutional practice shift, and a signature policy written three years ago and never revisited is a policy nobody trusts.


This article is general commentary on how legal teams approach electronic signature decisions. It is not legal advice, does not address any specific national implementation, and should not be relied on for a particular transaction.

eIDASE-signatureEU lawProcess

A note on this article. Lexoria is a fictional company and this post is original editorial content written for a demonstration website. It is general commentary, not legal advice, and no lawyer–client relationship arises from reading it.

More from the blog

Operations

What document automation actually returns

The business case for automating drafting is usually built on the wrong number. Here is the arithmetic that survives contact with a real firm.

·7 min read

Book a demo

See Lexoria against your own matters.

A 40-minute walkthrough with someone who has actually practised. We will use your matter types, not a canned demo file.

No card required EU-hosted DPA available on request