Chaindoc
Articles

Qualified Electronic Signature: The Complete 2026 Guide

A qualified electronic signature carries the same legal weight as a handwritten one under EU law. Learn how QES works, when you need it, and how to verify one.

Qualified Electronic Signature: The Complete 2026 Guide

What a qualified electronic signature is

A qualified electronic signature (QES) is an advanced electronic signature created with a qualified signature creation device and backed by a qualified certificate issued by an accredited trust service provider. That's the formal definition straight out of EU law, and every word in it does work. "Advanced" means the signature is uniquely tied to you and tamper-evident. "Qualified device" means your private signing key lives somewhere genuinely hard to extract, not just a password-protected file. "Qualified certificate" means a vetted third party checked your identity before issuing it, and published that check so anyone can verify it later.

Here's the part most explainers skip: QES isn't a brand or a product. It's a legal status. Any signature meeting the technical bar set by Regulation (EU) 910/2014, commonly called eIDAS, qualifies. Dozens of providers across Europe issue QES-compliant certificates, and the EU maintains a public list of every one.

Why should you care? QES is the only electronic signature format EU law says a court must treat exactly like a handwritten one. Not "similar to." Equivalent. That single fact is why banks, notaries, and government agencies build entire workflows around it, and why it's worth understanding even if your business only occasionally touches EU paperwork.

If you've read our plain-English guide to eIDAS 2.0, you already know the three-tier signature system (SES, AES, QES) didn't change under the newer regulation. This guide focuses just on QES: what it is, how it differs from the tiers below it, and when you actually need one.

A qualified electronic signature is the only e-signature type EU law explicitly equates with a wet-ink signature. Everything else on this page explains what that costs you in process, and what it buys you in legal certainty.

QES vs AdES vs SES: what actually separates them

Every EU e-signature falls into one of three tiers, and the differences aren't cosmetic. They're about how much identity proof and tamper evidence sit behind the click, the same cryptographic gap that separates a digital signature vs electronic signature. Simple Electronic Signature (SES) is the lowest bar: a typed name, a checkbox, a scanned wet-ink signature pasted onto a PDF. It's legally valid (Article 25(1) says no signature can be denied legal effect solely for being electronic), but if a dispute lands in court, an SES gives a judge the least to work with.

Advanced Electronic Signature (AdES) raises the bar. It must be uniquely linked to the signer, capable of identifying them, created using data under their sole control, and able to detect any change made after signing. Most mainstream e-signature platforms, Chaindoc included, deliver AdES-level signing by default: identity verification before document access, a cryptographic hash generated at signing, and a tamper-evident audit trail.

QES adds two things AdES doesn't have: a qualified certificate from an accredited trust service provider, and a qualified signature creation device holding the private key. That combination earns QES its handwritten-equivalence status.

FeatureSESAdESQES

Identity proofing

None required

Verified by the platform

Verified by an accredited QTSP

Tamper evidence

Not guaranteed

Cryptographic hash, tamper-evident

Cryptographic hash, tamper-evident

Signing key control

N/A

Sole control of signer

Sole control, stored on qualified device (QSCD)

Legal weight in the EU

Valid but lowest evidentiary weight

Valid, strong evidentiary weight

Equivalent to a handwritten signature (Art 25(2))

Typical use case

Internal approvals, low-stakes agreements

Most commercial contracts, NDAs, vendor agreements

Notarial-form contracts, certain regulated filings, consumer credit

Honestly, for the overwhelming majority of B2B contracts, AdES is plenty. It's not a compromise tier, it's the tier most businesses should default to unless a specific statute or counterparty demands more.

The legal effect: Article 25(2) explained

This is the clause that makes QES worth the extra process. Article 25(2) of Regulation 910/2014 states that a qualified electronic signature "shall have the equivalent legal effect of a handwritten signature." Not comparable. Not admissible. Equivalent. That wording matters in a courtroom, because a judge doesn't need to separately assess the evidentiary weight of a QES the way they might for an AdES or SES; the law already made that determination.

There's a second, quieter benefit built into the same regulation: cross-border recognition. A QES issued by a trust service provider in Poland has to be recognized by a court or business in Portugal, no separate legal opinion required. That's not automatically true for AdES, where recognition can depend more on the specific facts and the receiving country's evidentiary rules.

None of this means AdES is legally weak. Article 25(1) protects every electronic signature, including SES, from being denied legal effect merely for being electronic. QES just removes the argument entirely. If a counterparty's lawyer wants to contest a signature's validity, QES gives them nothing to work with on that front, they'd have to attack the underlying facts of the agreement instead.

Worth noting: eIDAS 2.0 (Regulation 2024/1183) left Article 25 completely untouched. It adds a digital identity wallet layer on top of the existing signature tiers; it doesn't redefine what QES, AdES, or SES mean. See our eIDAS 2.0 guide for the full picture on what did change.

How to get a qualified electronic signature

Getting a QES is a four-step process, and the order matters because each step depends on the one before it.

  1. 1
    Identity proofing by a QTSP. A Qualified Trust Service Provider verifies who you are, historically through a face-to-face appointment, more commonly today through video-identification or, increasingly, an EUDI Wallet credential. This is the step that can't be shortcut. The whole legal weight of QES rests on a third party actually confirming your identity.
  2. 2
    Key pair generation in a QSCD. Once identity is confirmed, a cryptographic key pair gets created, and the private half lives inside a Qualified Signature Creation Device: a certified smart card, a USB token, or a certified server-side (remote) QSCD run by the QTSP itself. You never get to export or copy that private key. That's the point.
  3. 3
    The QTSP issues a qualified certificate. According to Annex I of Regulation 910/2014, this certificate must bind your verified identity to your public key and identify the issuing QTSP by name.
  4. 4
    Certificate status gets published. Every qualified certificate's validity status is published through OCSP or a certificate revocation list, so anyone verifying a signature later can confirm the certificate was valid at signing time, not just that it existed. Renewal cycles typically run 1 to 3 years, depending on the provider.

Remote QES has made this dramatically less painful than it used to be. Instead of visiting a notary or trust center in person, you complete video-identification or wallet-based authentication once, and a server-side QSCD handles the signing itself, authorized through an app confirmation or one-time code each time you sign. You still get the same legal weight; you just don't need a physical token rattling around in a drawer.

Cost varies by QTSP and volume: individual qualified certificates commonly run from roughly €20 to over €100 per year for a single user, and business-tier bulk pricing can bring the per-seat cost well under €10 at higher volumes. There's no single published EU-wide rate, so check current price lists directly with a QTSP on the Trusted List rather than budgeting off a fixed figure.

Chaindoc's signing workflow currently delivers AdES-level signing (identity verification, cryptographic hashing, blockchain-anchored audit trail) as the default for every document. If your specific contract or jurisdiction requires full QES, you'd pair that workflow with a QTSP-issued qualified certificate; the audit-trail architecture underneath doesn't change, the certificate layer on top does.

Professional completing remote identity verification for a qualified electronic signature certificate via video call

Remote QES issuance: identity proofing now happens through video-identification instead of an in-person notary visit.

When QES is actually required

Here's where a lot of guides get sloppy, so let's be precise: there is no single EU-wide list of "contracts that require QES." Whether a specific agreement needs QES, AdES, or SES is decided by national law and, sometimes, by what the counterparty's internal policy demands. eIDAS sets the technical definitions and cross-border recognition rules; it doesn't mandate QES for particular contract types across all 27 member states uniformly.

That said, a few patterns show up consistently in civil-law countries with formal "written form" requirements. Germany is the clearest example: Section 126a of the German Civil Code (BGB) allows electronic form to replace the statutory written-form requirement, but only if the signature used is a QES. Certain consumer credit agreements, employment-related notices, and notarial-adjacent filings across EU member states lean on similar QES-or-nothing rules.

For everything outside those specific statutory carve-outs, most commercial contracts, NDAs, vendor agreements, service contracts, AdES is legally sufficient and considerably less friction for everyone involved. QES exists for cases where the law explicitly demands handwritten-equivalence, not as a default upgrade you should reach for out of caution.

Don't treat this section as a checklist. National statutes decide QES requirements on a country-by-country, contract-by-contract basis, and they change. If a specific deal genuinely depends on getting the signature format right, get a local legal opinion for that jurisdiction rather than relying on any general guide, including this one.

Not Sure Which Signature Tier Your Contract Needs?

Chaindoc delivers AdES-level signing by default on every document, with a blockchain-anchored audit trail and identity verification built in, no separate certificate purchase required for the majority of commercial agreements.

QES under eIDAS 2.0: what changes and what doesn't

Short version: QES itself doesn't change under eIDAS 2.0. The four-step issuance process above, the Article 25(2) legal effect, the QTSP/QSCD architecture, none of that moved. What eIDAS 2.0 (Regulation 2024/1183) adds is a new way to complete step one: identity proofing through an EUDI Wallet credential instead of a standalone video-identification session or in-person appointment.

In practice, this points toward a future where you authenticate once through your wallet and reuse that verified identity across multiple QES issuance requests, rather than re-proving your identity from scratch every time. That's a genuine efficiency gain, but as of mid-2026 it's still an emerging path, not the universal default. Implementing Acts and ETSI standards governing wallet-bound QES issuance are still finalizing through 2026, so treat "wallet-issued QES" as the direction of travel, not something every QTSP already supports.

If you want the full regulatory picture, including the wallet rollout timeline and which sectors must accept it by when, our eIDAS 2.0 guide covers that ground in detail. This article stays focused on what QES itself requires today.

QES outside the EU

QES is an EU legal construct, so its handwritten-equivalence guarantee under Article 25(2) is an EU-law statement, not a global one. That doesn't mean a QES-signed document becomes worthless the moment it crosses a border, but the legal certainty changes shape.

Within the EU, cross-border recognition is automatic: a QES issued in one member state has to be accepted in every other. Outside the EU, recognition depends on the receiving country's own law and, often, on bilateral agreements. Countries with close regulatory ties to the EU tend to extend similar recognition; others don't formally recognize the QES designation, though the underlying signature typically still counts as valid, tamper-evident electronic evidence under their own general electronic-signature laws.

The US works on a genuinely different model. The ESIGN Act and state-level UETA adoption don't create a tiered system like SES/AdES/QES; they broadly validate any electronic signature backed by clear intent to sign, regardless of the technology used. There's no US legal concept that maps one-to-one onto "qualified electronic signature." A signature that would qualify as QES in the EU is, under US law, simply a valid electronic signature. That's worth knowing if you're a US business wondering whether you need EU-style QES domestically: you generally don't, ESIGN and UETA already give you strong enforceability without it.

For businesses actually operating cross-border, the practical move is matching signature format to where enforcement is most likely to happen, not defaulting to QES everywhere out of caution.

Verifying a qualified signature

A QES is only as useful as your ability to prove it's genuine later, which is where verification comes in. Every qualified certificate's status gets published by its issuing QTSP, so verification means checking three things: the cryptographic hash matches the document exactly as signed, the certificate was valid (not expired or revoked) at signing time, and the certificate traces back to an accredited QTSP on the EU Trusted List.

That last part is easy to overlook. The Trusted List browser, maintained by the European Commission, lets anyone look up which providers are accredited in which member state. If a signature claims QES status but its issuer doesn't appear on the list, that's a red flag worth investigating before you rely on the document.

You don't need specialized software to check this yourself. Chaindoc's free signature verification tool checks a file's cryptographic integrity, certificate chain, and EU Trusted List status in seconds, whether it's PAdES, XAdES, CAdES, or ASiC. For the fuller compliance picture across eIDAS, GDPR, and NIST frameworks together, our digital signature compliance guide walks through how verification fits into a broader audit posture.

Getting the signature tier right matters less than most people assume, and verifying it properly matters more. A QES that nobody bothers to verify carries the same practical risk as an unverified SES: technically compliant, practically unprovable if it's ever challenged.

Tags

#qes#eidas#compliance#digital-signing
FAQ

Frequently Asked Questions

Answers to popular questions about Chaindoc and secure document workflows.