Skip to main content
Certyneo

QES, AES and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026

The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Certyneo Editorial Team14 min read
black smartphone

The eIDAS regulation (No. 910/2014) is the cornerstone of European electronic signature law. Since its entry into force, it has structured three levels of signature — SES, AES and QES — whose technical requirements and probative value differ radically. In 2026, with the progressive entry into force of the eIDAS 2.0 regulation (EU Regulation 2024/1183), these distinctions become even more important for any organisation wishing to dematerialise its legal documents in full compliance. This article decrypts the fundamental differences between these three levels, the obligations they entail and the criteria to consider when choosing the right format according to the nature of your documents.

SES: Simple Electronic Signature, Flexible but Limited

Definition and Technical Characteristics

The Simple Electronic Signature (SES) is defined in Article 3(10) of the eIDAS regulation as "data in electronic form which are attached to or logically associated with other data in electronic form and which the signatory uses to sign". This definition is intentionally broad: a simple click on "I accept", a signature drawn by finger on a tablet, or even a ticked box in an online form all fall into this category.

SES requires no prior verification of the signatory's identity, nor any cryptographic certificate. Its robustness depends solely on the contractual context and peripheral evidence (IP address, server timestamp, confirmation email). The electronic signature glossary lists all the technical terms associated with these mechanisms.

SES benefits from the non-discrimination principle laid down in Article 25(1) eIDAS: it cannot be rejected as evidence solely on the grounds that it is electronic. However, it carries no presumption of reliability. In case of dispute, the burden of proof rests entirely on the party relying on it. The legal value of electronic signature therefore depends heavily on the level chosen.

SES is suitable for low-risk documents: acceptance of terms and conditions, internal forms, low-value online orders, or satisfaction surveys. It is unsuitable for any document likely to be contested in court.

AES: Advanced Electronic Signature, the Balance between Security and Practicality

The Four Cumulative Criteria of Article 26 eIDAS

Advanced Electronic Signature (AES) is defined in Article 3(11) eIDAS and must satisfy four conditions listed in Article 26:

  1. Be linked to the signatory in a unique manner: a unique identifier links the signature to a determined natural person.
  2. Enable identification of the signatory: identity verification is performed (email, telephone number, identity document depending on the provider).
  3. Have been created using data that the signatory can use with a high level of confidence under their sole control: typically a one-time password (OTP) sent to their telephone or a software certificate.
  4. Be linked to the signed data in such a manner that any subsequent modification is detectable: the signature is based on a cryptographic hash of the document.

Technologies Used and Assurance Levels

In practice, AES is implemented via digital certificates of substantial level (within the meaning of the eIDAS regulation), multi-factor authentication mechanisms, or documentary identity solutions (identity document scan, biometric comparison). Qualified trust service providers such as Certyneo offer AES signature workflows incorporating remote identity verification, compliant with ANSSI frameworks and ETSI EN 319 401 standards.

AES offers an excellent compromise between security and user experience fluidity. It is recommended for standard commercial contracts, HR documentation, partnership agreements or service contracts. Consult our comprehensive guide to electronic signature in business to deepen your understanding of professional applications.

Limitations of AES for Certain Documents

AES remains insufficient for authentic deeds or those for which the law expressly requires qualified signature. In France, Article 1367 of the Civil Code reserves the presumption of maximum reliability solely to qualified signatures within the eIDAS meaning. AES may be set aside by a judge if the opposing party demonstrates an insufficiency in the identity verification process.

Regulatory Definition and Technical Requirements

Qualified Electronic Signature (QES) is defined in Article 3(12) eIDAS as an advanced signature created by a Qualified Signature Creation Device (QSCD) and based on a qualified electronic signature certificate. These two components are inseparable.

The qualified certificate is issued by a Qualified Trust Service Provider (QTSP) listed on the national Trust List published by each Member State. In France, this list is administered by ANSSI. The QTSP must have been audited and accredited in accordance with the requirements of Annex I of the eIDAS regulation and ETSI EN 319 411-2 standards.

The QSCD (Qualified Signature Creation Device) is a secure hardware or software medium — typically a smart card, cryptographic USB token or remote Hardware Security Module (HSM) — guaranteeing that the signatory's private key cannot be extracted or copied. QSCD requirements are detailed in Annex II of the eIDAS regulation.

The Irrefutable Legal Presumption of Article 25(2)

Article 25(2) of the eIDAS regulation grants QES a legal effect equivalent to handwritten signature in all European Union Member States. This presumption is automatic: unlike AES, the party presenting a QES does not have to demonstrate the reliability of the process. It is for the opposing party to rebut this presumption, which is in practice very difficult once the QTSP and QSCD are duly qualified.

In France, Article 1367 paragraph 2 of the Civil Code transposes this requirement into domestic law: the reliability of the electronic signature process is presumed until proved otherwise when a qualified eIDAS electronic signature is used. This presumption also covers the integrity of the signed document.

Process for Obtaining a Qualified Certificate

Obtaining a qualified certificate requires face-to-face identity verification or its remote equivalent with the same level of assurance (for example, video identification compliant with EN ISO/IEC 18013 standard or with specifications in Implementing Regulation 2015/1502). The process involves:

  • Collection of official identity documents
  • Verification of their authenticity (detection of forgery)
  • Biometric recording of the signatory
  • Issuance of the certificate by the QTSP after validation

This level of requirement explains why QES is reserved for high-risk documents: private written deeds with significant financial stakes, electronic notarial documents, public procurement, sensitive medical documents, or where sectoral regulation explicitly requires it. To compare available solutions on the market, our comparison of electronic signature solutions will guide you in your choice.

Comparative Table and Selection Criteria in 2026

Summary of Structuring Differences

Three axes allow quick distinction between the three levels:

Identity verification: none for SES, documentary or OTP for AES, face-to-face or equivalent for QES. Cryptographic support: non-existent for SES, software certificate for AES, certified QSCD for QES. Legal presumption: absent for SES, partial for AES, total and automatic for QES.

In terms of user friction, the equation is reversed: SES is quasi-transparent, AES requires a few minutes of verification, QES requires a prior registration process that can take from a few minutes (video identification) to several days.

Impact of eIDAS 2.0 on these Distinctions in 2026

The eIDAS 2.0 regulation (EU 2024/1183), whose implementing acts have been progressively published since 2024, strengthens several key points. It introduces the European Digital Identity Wallet (EUDI Wallet), which will eventually allow European citizens to store their qualified certificate directly on their smartphone, significantly reducing the friction associated with QES. It also clarifies the requirements applicable to QTSPs and strengthens the governance of national trust lists.

Furthermore, eIDAS 2.0 extends the scope of mutual recognition of qualified signatures between Member States, which is particularly significant for businesses operating in multiple EU countries. The comprehensive guide to eIDAS 2.0 regulation details all these regulatory developments. Finally, the question of qualified electronic time stamping — complementary to QES to maintain the probative value of documents over time — also deserves attention when designing your documentary architecture.

The hierarchy of electronic signatures rests on a dense regulatory framework, articulating European law and French domestic law.

eIDAS Regulation No. 910/2014: this foundational text defines the three levels of signature in Articles 3(10), 3(11) and 3(12). Article 25 establishes the principle of non-discrimination (§1) and the presumption of equivalence to handwritten signature for QES (§2). Article 26 lists the four cumulative conditions for advanced signature. Annexes I and II respectively detail the requirements applicable to qualified certificates and Qualified Signature Creation Devices (QSCD).

eIDAS 2.0 Regulation — EU 2024/1183: entering into force on 20 May 2024, it substantially amends the 2014 regulation, notably through the introduction of the European Digital Identity Wallet (EUDI Wallet), the extension of qualified trust services and the strengthening of QTSP governance. Implementing acts continue to be published in 2026.

French Civil Code, Articles 1366 and 1367: Article 1366 recognises electronic writing as evidence on the same basis as paper writing, provided that the person from whom it emanates can be duly identified and that it is established and kept under conditions capable of guaranteeing its integrity. Article 1367 paragraph 2 presumes reliability for qualified eIDAS signature, in direct transposition of Article 25(2) of the regulation.

Decree No. 2017-1416 of 28 September 2017: specifies in French law the conditions allowing benefit from the presumption of reliability, explicitly referring to eIDAS regulation requirements for qualified signatures.

ETSI Standards: ETSI EN 319 102-1 standards (signature creation and validation procedures), ETSI EN 319 132 (XAdES format), ETSI EN 319 122 (CAdES format) and ETSI EN 319 142 (PAdES format) technically frame the creation of compliant electronic signatures. Qualified providers must implement these formats to guarantee European interoperability.

GDPR — EU Regulation 2016/679: the collection of biometric data in the context of identity verification for the issuance of qualified certificates constitutes processing of sensitive data within the meaning of Article 9. The QTSP must have an explicit legal basis, inform individuals and implement appropriate technical safeguards. An impact assessment (DPIA) is generally required.

NIS2 Directive — EU 2022/2555: applicable to essential service operators and digital service providers, it imposes strengthened cybersecurity requirements that indirectly apply to QTSPs operating critical electronic signature infrastructures.

Organisations that deploy electronic signature solutions without respecting the level required by the legal nature of the deed expose themselves to nullity or unenforceability of signed documents, as well as contentious risks that can lead to significant financial harm.

Use Cases: Choosing the Right Level According to Context

Case 1 — Industrial SME Managing Hundreds of Supplier Orders

An industrial SME processing approximately 400 purchase orders and supplier contracts per year has deployed AES for all its standard commercial documents. The signature workflow relies on verification via secure email link and SMS one-time password, with generation of a time-stamped audit report for each deed. The average signature time has fallen from 4.5 days (registered mail) to less than 3 hours. The rate of contractual dispute remained zero over 18 months of operation, with the audit trail providing sufficient evidence in case of commercial disagreement. The reduction in printing, postage and document management costs reaches approximately 60% according to internal estimates, consistent with ranges published by European sectorial studies (Billentis Report, 2025).

Case 2 — Business Law Firm

A business law firm with about fifteen practitioners has implemented a two-tier infrastructure: AES signature for internal correspondence, representation mandates and fee agreements; QES signature for high-stakes private written deeds (sale of equity interests, settlement protocols, financial guarantees). Obtaining qualified certificates for the partners was achieved via a video identification session compliant with eIDAS, without physical travel, in less than 20 minutes per person. The legal presumption attached to QES allows the firm to present its deeds before any European court without having to demonstrate the reliability of the process, reducing procedural risk significantly.

Case 3 — Hospital Group Dematerialising HR and Medical Deeds

A hospital group of approximately 1,200 beds has chosen a differentiated approach depending on the nature of documents. Employment contracts, amendments and job descriptions are signed in AES, allowing the approximately 800 staff members concerned to sign from their smartphone without heavy infrastructure. For specific medical conventions and documents requiring strong authentication imposed by healthcare regulation (HDS), QES is deployed for designated practitioner signatories. This hybrid model reduces by 75% the time to constitute HR files during recruitment, a particularly critical gain during periods of medical resource shortage. It also ensures compliance with CNIL obligations relating to health data processing.

Frequently Asked Questions

What is the Main Difference between QES and AES under eIDAS?

The fundamental difference lies in two elements: the certificate and the signature device. QES necessarily relies on a qualified certificate issued by an accredited provider (QTSP) and on a Qualified Signature Creation Device (QSCD) with material security features. AES can use a software certificate and less strict identity verification. Direct consequence: QES benefits from a legal presumption of equivalence to handwritten signature throughout the European Union, which AES does not automatically guarantee.

In What Cases is it Mandatory to Use a QES Signature?

No European text imposes QES generally, but several sectoral or national regulations require it implicitly or explicitly. This is the case for certain electronic authentic deeds, specific public procurement, dematerialised notarial deeds, or in regulated sectors such as banking (PSD2, enhanced KYC) or healthcare. The general rule is as follows: the higher the legal or financial stakes of the deed, the more QES use is recommended to rule out any risk of dispute.

Yes, SES signature is legally admissible in France by virtue of the non-discrimination principle laid down in Article 25(1) of the eIDAS regulation and Article 1366 of the Civil Code. It cannot be dismissed as evidence solely on the grounds that it is electronic. However, it benefits from no presumption of reliability: in case of dispute, the party relying on it must demonstrate its robustness by other means (logs, IP address, audit trail). Its use must therefore be reserved for low-risk documents.

Is a Qualified Certificate Obtained in France Recognised Throughout the European Union?

Yes. Article 25(2) of the eIDAS regulation and the mutual recognition mechanism of national trust lists guarantee that a qualified certificate issued by a QTSP accredited in France is recognised in all European Union Member States with the same legal effect. eIDAS 2.0 (EU 2024/1183) further strengthens this principle by extending recognition to new qualified trust services introduced by the revised regulation.

How Can I Verify That a Signature Provider is Genuinely eIDAS Qualified?

Each Member State publishes and maintains an official Trust List which lists all Qualified Trust Service Providers (QTSP) accredited on its territory. In France, this list is published and updated by ANSSI on its official website. The European Commission aggregates all national lists on the EU Trusted List Browser portal (tlbrowser.tsl.europa.eu). Verify that a provider is listed there before entrusting it with the issuance of qualified certificates or the creation of QES signatures.

Conclusion

The three levels of electronic signature defined by the eIDAS regulation — SES, AES and QES — respond to fundamentally different legal and operational needs. SES is suitable for low-stakes documents, AES covers the majority of standard professional contracts with an excellent balance between security and fluidity, whilst QES is essential for documents of high legal value thanks to its legal presumption of equivalence to handwritten signature throughout the European Union. In 2026, with the progressive entry into force of eIDAS 2.0, mastering these distinctions is more strategic than ever for any organisation dematerialising its documentary processes.

Certyneo enables you to deploy all three levels of signature according to your actual needs, with a unified interface compliant with eIDAS and ANSSI requirements. Discover our offers or estimate your gains right now using our electronic signature ROI calculator, or contact our team for a personalised audit of your documentary workflows.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Go deeper into this topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.