CAdES & .p7m signature verification
Validate CAdES digital signatures inside your .p7m and .p7s files. Upload a signed CMS file and Chaindoc checks the message-digest integrity, certificate chain, embedded timestamps, and eIDAS compliance with the EU DSS library.
Verify CAdES Signature
Upload a signed .p7m or .p7s file to validate its CAdES (CMS / PKCS#7) digital signatures using EU DSS verification standards.
What the CAdES check includes
- Free CAdES & eIDAS signature validation
- Certificate chain and revocation checks
- Detailed report ready in seconds
- Your file is never stored
The .p7m or .p7s you upload is never stored. The verification report is kept privately for 7 days and then deleted; after that your account holds only a minimal record: result, signature count, date.
What CAdES verification checks
CAdES (CMS Advanced Electronic Signatures) is defined by ETSI EN 319 122 and built on the Cryptographic Message Syntax (RFC 5652), the format that grew out of PKCS#7. Chaindoc runs your file through the EU Digital Signature Service (DSS) library to check it against these rules.
Re-runs the SignedData hash against the content to confirm nothing changed after signing. For a .p7m that means the file wrapped inside is byte-for-byte what the signer approved. The same CAdES signature can also travel zipped inside an ASiC container.
Traces the signer's certificate back to a trusted root and checks whether it was revoked, using CRL and OCSP responders. See how trust is established under eIDAS across all signature formats.
Reads any CAdES timestamps baked into the signature, so a .p7m signed years ago still checks out even after the certificate expires.
Confirms whether the signature meets eIDAS rules and the ETSI EN 319 122 profile for advanced and qualified electronic signatures.
From verifying to signing your own
Chaindoc is electronic signature software with proof built in: send agreements for signature, anchor every step to a blockchain audit trail, and hand auditors a verification report instead of a promise.
Supported CAdES profiles
Chaindoc validates the four CAdES baseline profiles from ETSI EN 319 122. Each one adds another layer of assurance on top of the one below it.
CAdES-BASELINE-B
The baseline. The minimum an advanced electronic signature needs under eIDAS.
CAdES-BASELINE-T
Adds a trusted timestamp proving the file was signed before a specific moment. Useful when a submission deadline is on the line.
CAdES-BASELINE-LT
Packs the certificates and revocation data into the signature, so it stays verifiable even after the issuing CA goes dark.
CAdES-BASELINE-LTA
Adds an archive timestamp for long-term storage. The signature keeps validating for years as old algorithms are retired. See pricing for archival options.
Common questions about CAdES signature verification
What CAdES is, how the check runs, and what the result means. More on our support page.
CAdES stands for CMS Advanced Electronic Signatures, an ETSI standard (EN 319 122) built on the Cryptographic Message Syntax (RFC 5652), the modern successor to PKCS#7. It's a binary signature container, usually a .p7m file. Italy's legal digital signature leans on it heavily, so you'll often see a document.pdf.p7m bundle where the original file sits wrapped inside the signature.
Same cryptography, three different wrappers. PAdES lives inside a PDF, XAdES wraps XML, and CAdES uses the binary CMS format from the PKCS#7 world. If you're checking a signed PDF, use the PDF signature verification tool; for signed XML and e-invoices, reach for XAdES verification instead. CAdES is the format you want when the signed thing isn't a formatted document at all, like an email attachment or an arbitrary file, so it shows up wherever a raw byte stream needs a legally binding signature. And if a CAdES signature is zipped together with the file it signed, that package is an ASiC container; check those with ASiC verification.
A .p7m is enveloping: the signed content is packed inside the signature, so the file is self-contained and this page can check it on its own. A .p7s is usually detached, holding the signature only while the original file lives somewhere else. Upload a lone detached .p7s and the report may come back indeterminate, because the data it signed is missing. To validate a detached signature, add the original file alongside it in the form above — selecting a .p7s file reveals a second field for the signed document.
Yes. Italian firma digitale files, the .p7m buste crittografiche you get from PA portals and PEC email, are CAdES signatures and this tool reads them. Signed S/MIME email attachments work too, as long as the signature is self-contained rather than detached from its message.
A few usual suspects: the content changed after signing so the message digest no longer matches, the signing certificate expired or was revoked, or the chain doesn't reach a trusted root. One that's specific to CAdES is uploading a detached .p7s without its original file. The report names the exact check that failed, so you're not left guessing. Running an internal PKI and need custom trust anchors? Check pricing.
CMS signatures and document verification guides
How CAdES, PKCS#7, and certificate validation keep signed files tamper-proof and eIDAS-ready.



