Sign a SOW Electronically: eIDAS 2026 Legal Value
An electronically unsigned Statement of Work exposes your company to costly litigation. Discover how to sign your SOWs with full legal value under eIDAS.
Updated on
The eIDAS regulation is the founding text for electronic signature in Europe. It defines three signature levels (simple, advanced, qualified), establishes the legal value of electronic documents and governs trust service providers. This guide explains everything you need to know to be compliant in 2026.

Before eIDAS, each EU Member State had its own regulation on electronic signatures, creating legal fragmentation that hampered cross-border exchanges. An electronic signature valid in France was not necessarily recognised in Germany or Spain.
The Regulation (EU) No 910/2014, known as eIDAS (Electronic IDentification, Authentication and trust Services), was adopted on 23 July 2014 and came into force on 1 July 2016. As a regulation (rather than a directive), it applies directly and uniformly in all 27 member states, without requiring national transposition.
eIDAS pursues three main objectives: creating a single digital market in Europe through mutual recognition of electronic identities, guaranteeing the legal certainty of cross-border electronic transactions, and establishing a framework of trust for digital services via qualified trust service providers (QTSP — Qualified Trust Service Provider).
eIDAS establishes a pyramid of three electronic signature levels, each with its own technical requirements and probative value.
eIDAS Requirements
Usage examples
Legal value
Basic contractual value, no legal presumption
eIDAS Requirements
Usage examples
Legal value
Strong probative value — recommended for important contracts
eIDAS Requirements
Usage examples
Legal value
Legal presumption equivalent to handwritten signature (art. 25 eIDAS)
The eIDAS regulation was revised by regulation (EU) 2024/1183, published in the EU Official Journal on 30 April 2024 and entered into force on 20 May 2024. This revision modernises the initial framework to address contemporary digital challenges: digital identity for citizens, sovereign cloud, resilience of trust service providers.
The flagship measure of eIDAS 2.0 is the European Digital Identity Wallet (EUDIW). By the end of 2026, each Member State must offer its citizens and residents an application to store and present certified identity attestations — digital equivalent of an identity card, driving licence, diplomas. This development will have a direct impact on qualified signature processes.
eIDAS 2.0 introduces the European Digital Identity Wallet: each European citizen will be able to store their certified identity credentials (identity card, driving licence, diplomas) in a mobile application interoperable across the EU.
Requirements applicable to qualified trust service providers (QTSP) are strengthened, particularly in cybersecurity, audits, and service continuity.
eIDAS 2.0 adds new qualified services: qualified electronic archiving, qualified attribution data management, qualified electronic register (certified blockchain).
Better mutual recognition of digital identities between Member States. Qualified signatures issued in any EU country are recognised everywhere.
eIDAS compliance does not come down to choosing a signature level. It involves reflection on the entire process: risk identification, tool selection, evidence preservation and document governance.
Here is a practical checklist for companies wishing to secure their electronic signature processes in compliance with eIDAS:
Certyneo implements the SES (Simple Electronic Signature) and AES (Advanced Electronic Signature) levels of the eIDAS regulation. Advanced signature is based on two-factor authentication: a single-use link sent by email and an OTP code sent by SMS via our SMS OTP provider. This mechanism meets the four criteria of article 26 of eIDAS for advanced signature.
Each envelope generates a complete audit trail: timestamping of each action (sending, link opening, OTP validation, signature placement, possible refusal), signatory's IP address, browser user-agent. This audit trail is integrated at the bottom of each page of the final PDF (audit footer) and retained for 10 years.
Data is hosted in Germany (EU) (IONOS infrastructure), within the European Union, in accordance with digital sovereignty requirements and GDPR. See our security and compliance page for all technical details.
eIDAS (Electronic Identification, Authentication and Trust Services) is the European regulation (EU) No 910/2014 that establishes a common legal framework for electronic signatures, electronic seals, timestamps, electronic registered delivery services and website authentication services in the European Union. It entered into force on 1 July 2016 and applies directly in all 27 Member States.
eIDAS 2.0 (regulation (EU) 2024/1183, which entered into force on 20 May 2024) modernises eIDAS 1.0 by introducing notably the European Digital Identity Wallet (EUDIW — European Digital Identity Wallet), which will enable European citizens to store certified digital identity attestations. For businesses, eIDAS 2.0 strengthens the requirements of qualified trust service providers (QTSP) and improves cross-border interoperability.
Yes. Article 25 of eIDAS explicitly prohibits refusing legal effects to an electronic signature solely on the grounds that it is in electronic form. A simple signature (SES) therefore has legal value, but it does not benefit from the legal presumption reserved for qualified signatures (QES). In the event of a dispute, it is up to the party relying on the signature to prove its authenticity.
The general rule is to calibrate the level to the legal and commercial risk of the document. For standard, low-stakes documents (quotations, internal orders), simple signature is sufficient. For important commercial contracts, employment contracts, NDA or mandates, advanced signature (AES) is recommended. Qualified signature (QES) is reserved for situations where the law explicitly requires it (certain administrative acts, large public procurement) or when the risk of dispute is maximal.
Certyneo implements simple signature (SES) and advanced signature (AES) in accordance with eIDAS. Advanced signature is based on dual email + SMS OTP (our SMS OTP provider) which links the signer to their act. Each envelope generates a timestamped audit trail embedded in the final PDF. Data is hosted in Germany (EU), in accordance with digital sovereignty requirements.
eIDAS applies to trust services provided in the EU. A business established outside the EU wishing its signatures to be recognised in the EU must use an eIDAS-compliant solution or a qualified trust service provider (QTSP) recognised in the trust list of a Member State. For international B2B exchanges, mutual recognition agreements exist with certain third countries.
An electronically unsigned Statement of Work exposes your company to costly litigation. Discover how to sign your SOWs with full legal value under eIDAS.

eIDAS 2 regulation redefines digital identity rules in Europe for 2026. Discover what changes for businesses and how to anticipate compliance.
What is the eIDAS regulation, what does it change, what are its 3 signature levels and why it concerns every European business.
Advanced Electronic Signature (AES), Simple (SES) or Qualified (QES): the eIDAS regulation defines three levels. Comparison, legal value and recommended choice according to the document.
The eIDAS 2 regulation imposes new requirements on trust service providers. Discover the complete certification pathway to remain compliant in 2026.
The European EUDI Wallet is profoundly transforming the use of electronic signatures and authentication in business. Everything you need to understand to anticipate regulatory changes in 2026.
We use cookies to improve your experience on our site. Cookies strictly necessary for the service to function are always active. Learn more