Skip to main content
Certyneo

QES, AES, and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026

The eIDAS regulation distinguishes three levels of electronic signature with vastly different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Certyneo Editorial Team14 min read
black smartphone

The eIDAS regulation (No. 910/2014) is the cornerstone of European electronic signature law. Since its entry into force, it has structured three levels of signature — SES, AES, and QES — whose technical requirements and evidential value differ radically. In 2026, with the progressive entry into force of eIDAS 2.0 (EU Regulation 2024/1183), these distinctions become increasingly important for any organisation wishing to digitise its legal documents in full compliance. This article decodes the fundamental differences between these three levels, the obligations they entail, and the criteria to consider when choosing the right format depending on the nature of your documents.

SES: Simple Electronic Signature, Flexible but Limited

Definition and Technical Characteristics

The Simple Electronic Signature (SES) is defined in Article 3(10) of the eIDAS regulation as "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign". This definition is deliberately broad: a simple click on "I Accept", a signature drawn by finger on a tablet, or even a ticked checkbox in an online form fall into this category.

The SES requires no prior verification of the signatory's identity, nor any cryptographic certificate. Its robustness relies solely on the contractual context and peripheral evidence (IP address, server timestamp, confirmation email). The electronic signature glossary lists all the technical terms associated with these mechanisms.

The SES benefits from the principle of non-discrimination laid down in Article 25(1) eIDAS: it cannot be rejected as evidence solely on the grounds that it is electronic. However, it carries no presumption of reliability. In the event of a dispute, the burden of proof falls entirely on the party invoking it. The legal value of electronic signature therefore depends heavily on the level chosen.

The SES is suitable for low-risk documents: acceptance of terms and conditions, internal forms, low-value online orders, or satisfaction surveys. It is unsuitable for any document likely to be contested in court.

AES: Advanced Signature, the Balance Between Security and Practicality

The Four Cumulative Criteria of Article 26 eIDAS

The Advanced Electronic Signature (AES) is defined in Article 3(11) eIDAS and must satisfy four conditions listed in Article 26:

  1. Be linked to the signatory in a unique manner: a unique identifier links the signature to a determined natural person.
  2. Allow the signatory to be identified: identity verification is performed (email, telephone number, identity document depending on the service provider).
  3. Have been created using data that the signatory can use with a high level of confidence under their sole control: typically a one-time password (OTP) sent to their phone or a software certificate.
  4. Be linked to the signed data in such a way that any subsequent modification is detectable: the signature is based on a cryptographic hash of the document.

Technologies Used and Assurance Levels

In practice, AES is implemented through digital certificates at a substantial assurance level (within the meaning of eIDAS), multi-factor authentication mechanisms, or documentary identity solutions (identity document scanning, biometric comparison). Qualified trust service providers such as Certyneo offer AES signature workflows incorporating remote identity verification, compliant with ANSSI benchmarks and ETSI EN 319 401 standards.

AES offers an excellent compromise between security and user experience fluidity. It is recommended for standard commercial contracts, HR documents, partnership agreements, or service provision contracts. Consult our comprehensive guide to electronic signature in business to deepen your understanding of uses in a professional context.

Limitations of AES for Certain Documents

AES remains insufficient for authentic documents or those for which the law expressly requires a qualified signature. In France, Article 1367 of the Civil Code reserves the presumption of maximum reliability exclusively to qualified signatures within the meaning of eIDAS. AES may be rejected by a judge if the opposing party demonstrates an insufficiency in the identity verification process.

Regulatory Definition and Technical Requirements

The Qualified Electronic Signature (QES) is defined in Article 3(12) eIDAS as an advanced signature created by a qualified signature creation device (QSCD) and based on a qualified electronic signature certificate. These two components are inseparable.

The qualified certificate is issued by a qualified trust service provider (QTSP) registered on the national trusted list (Trusted List) published by each Member State. In France, this list is administered by ANSSI. The QTSP must have been audited and accredited in accordance with the requirements of Annex I of the eIDAS regulation and ETSI EN 319 411-2 standards.

The QSCD (qualified signature creation device) is a secure hardware or software support — typically a smart card, a cryptographic USB token, or a remote Hardware Security Module (HSM) — ensuring that the signatory's private key cannot be extracted or copied. The QSCD requirements are detailed in Annex II of the eIDAS regulation.

The Irrefutable Legal Presumption of Article 25(2)

Article 25(2) of the eIDAS regulation confers on QES a legal effect equivalent to a handwritten signature in all Member States of the European Union. This presumption is automatic: unlike AES, the party producing a QES does not have to demonstrate the reliability of the process. It is up to the opponent to rebut this presumption, which is in practice very difficult once the QTSP and QSCD are properly qualified.

In France, Article 1367 paragraph 2 of the Civil Code transposes this requirement into domestic law: the reliability of the electronic signature process is presumed until proven otherwise when a qualified eIDAS electronic signature is used. This presumption also covers the integrity of the signed document.

Process for Obtaining a Qualified Certificate

Obtaining a qualified certificate requires face-to-face identity verification or an equivalent remote process with the same level of assurance (for example, video identification compliant with ISO/IEC 18013 or the specifications of Implementing Regulation 2015/1502). The process involves:

  • Collection of official identity documents
  • Verification of their authenticity (detection of forgery)
  • Biometric recording of the signatory
  • Certificate issuance by the QTSP after validation

This level of requirement explains why QES is reserved for high-risk documents: private deeds with significant financial stakes, electronic notarial documents, public procurement, sensitive medical documents, or where sectoral regulations explicitly require it. To compare available market solutions, our comparison of electronic signature solutions will guide you in your choice.

Comparative Table and Selection Criteria in 2026

Summary of Structuring Differences

Three axes allow for quick distinction of the three levels:

Identity verification: none for SES, documentary or OTP for AES, face-to-face or equivalent for QES. Cryptographic support: non-existent for SES, software certificate for AES, certified QSCD for QES. Legal presumption: absent for SES, partial for AES, total and automatic for QES.

In terms of user friction, the equation is reversed: SES is nearly transparent, AES requires a few minutes of verification, QES requires a prior registration process that can take from a few minutes (video identification) to a few days.

Impact of eIDAS 2.0 on These Distinctions in 2026

The eIDAS 2.0 regulation (EU 2024/1183), whose implementing acts have been progressively published since 2024, strengthens several key points. It introduces the European Digital Identity Wallet (EUDI Wallet), which will eventually allow European citizens to store their qualified certificate directly in their smartphone, significantly reducing the friction associated with QES. It also clarifies the requirements applicable to QTSPs and strengthens the governance of national trusted lists.

Furthermore, eIDAS 2.0 extends the scope of mutual recognition of qualified signatures between Member States, which is particularly significant for businesses operating in multiple EU countries. The comprehensive guide to eIDAS 2.0 regulation details all these regulatory developments. Finally, the question of qualified electronic time-stamping — complementary to QES to preserve the evidential value of documents over time — also deserves attention when designing your document architecture.

The hierarchy of electronic signatures rests on a dense body of regulation, articulating European law and French domestic law.

eIDAS Regulation No. 910/2014: this foundational text defines the three levels of signature in Articles 3(10), 3(11), and 3(12). Article 25 establishes the principle of non-discrimination (§1) and the presumption of handwritten equivalence for QES (§2). Article 26 lists the four cumulative conditions for an advanced signature. Annexes I and II specify the requirements applicable to qualified certificates and qualified signature creation devices (QSCD) respectively.

eIDAS 2.0 Regulation — EU 2024/1183: entered into force on 20 May 2024, it substantially amends the 2014 regulation, in particular through the introduction of the European Digital Identity Wallet (EUDI Wallet), the extension of qualified trust services, and the strengthening of QTSP governance. Implementing acts continue to be published in 2026.

French Civil Code, Articles 1366 and 1367: Article 1366 recognises an electronic document as evidence in the same way as a paper document, provided that the person from whom it originates can be duly identified and that it has been drawn up and preserved under conditions designed to guarantee its integrity. Article 1367 paragraph 2 establishes the presumption of reliability for eIDAS qualified signature, in direct transposition of Article 25(2) of the regulation.

Decree No. 2017-1416 of 28 September 2017: specifies in French law the conditions for benefiting from the presumption of reliability, explicitly referring to the requirements of the eIDAS regulation for qualified signatures.

ETSI Standards: ETSI EN 319 102-1 standards (signature creation and validation procedures), ETSI EN 319 132 (XAdES format), ETSI EN 319 122 (CAdES format), and ETSI EN 319 142 (PAdES format) technically govern the creation of compliant electronic signatures. Qualified service providers must implement these formats to guarantee European interoperability.

GDPR — EU Regulation 2016/679: the collection of biometric data in the context of identity verification for the issuance of qualified certificates constitutes processing of sensitive personal data within the meaning of Article 9. The QTSP must have an explicit legal basis, inform individuals, and implement appropriate technical safeguards. A Data Protection Impact Assessment (DPIA) is generally required.

NIS2 Directive — EU 2022/2555: applicable to essential service operators and digital service providers, it imposes strengthened cybersecurity requirements that apply indirectly to QTSPs operating critical electronic signature infrastructures.

Organisations that deploy electronic signature solutions without respecting the level required by the legal nature of the act face the risk of nullity or unenforceability of signed documents, as well as litigation risks that can result in significant financial losses.

Use Cases: Choosing the Right Level Based on Context

Case 1 — Industrial SME Managing Hundreds of Supplier Orders

An industrial SME handling approximately 400 purchase orders and supplier contracts per year has deployed AES for all its standard commercial documents. The signature workflow is based on verification through a secure email link and SMS OTP, with the generation of a time-stamped audit report for each document. The average time to signature has fallen from 4.5 days (registered mail) to less than 3 hours. The rate of contractual disputes has remained zero over 18 months of operation, with the audit trail providing sufficient evidence in the event of commercial disagreement. The reduction in printing, postage, and document management costs reached approximately 60% according to internal estimates, consistent with ranges published by European industry studies (Billentis Report, 2025).

Case 2 — Business Law Firm Specialised in Corporate Law

A business law firm of approximately fifteen staff members has implemented a two-tier infrastructure: AES signature for internal correspondence, representation mandates, and fee agreements; QES signature for high-stakes private deeds (sale of equity interests, settlement agreements, financial guarantees). Obtaining qualified certificates for the partners was achieved through a video identification session compliant with eIDAS, without physical travel, in less than 20 minutes per person. The legal presumption attached to QES allows the firm to present its documents before any European court without having to demonstrate the reliability of the process, significantly reducing procedural risk.

Case 3 — Hospital Group Digitising HR and Medical Documents

A hospital group of approximately 1,200 beds has chosen a differentiated approach depending on the nature of the documents. Employment contracts, amendments, and job descriptions are signed in AES, allowing the 800 staff members concerned to sign from their smartphones without heavy infrastructure. For specific medical agreements and documents requiring strong authentication mandated by healthcare regulations (HDS), QES is deployed for designated practitioner signatories. This hybrid model reduces by 75% the time to assemble HR files during recruitment, a gain that is particularly critical during periods of tension on medical resources. It also ensures compliance with CNIL obligations relating to health data processing.

Frequently Asked Questions

What is the main difference between QES and AES in eIDAS?

The fundamental difference lies in two elements: the certificate and the signature device. QES is mandatory based on a qualified certificate issued by an accredited service provider (QTSP) and on a qualified signature creation device (QSCD) that is materially secure. AES may use a software certificate and less stringent identity verification. Direct consequence: QES benefits from a legal presumption of equivalence to a handwritten signature throughout the European Union, which AES does not automatically guarantee.

In what cases is it mandatory to use a QES signature?

No European text mandates QES in general, but several sectoral or national regulations require it implicitly or explicitly. This is the case for certain electronic authentic documents, specific public procurement, electronic notarial documents, or in regulated sectors such as banking (DSP2, enhanced KYC) or health. The general rule is as follows: the higher the legal or financial stake of the document, the more using QES is recommended to eliminate any risk of challenge.

Yes, SES signature is legally admissible in France under the principle of non-discrimination set out in Article 25(1) of the eIDAS regulation and Article 1366 of the Civil Code. It cannot be rejected as evidence solely on the grounds that it is electronic. However, it benefits from no presumption of reliability: in the event of a dispute, the party invoking it must demonstrate its robustness by other means (logs, IP address, audit trail). Its use should therefore be reserved for low-risk documents.

Is a qualified certificate obtained in France recognised throughout the European Union?

Yes. Article 25(2) of the eIDAS regulation and the mechanism for mutual recognition of national trusted lists (Trusted Lists) guarantee that a qualified certificate issued by a QTSP accredited in France is recognised in all Member States of the European Union with the same legal effect. eIDAS 2.0 (EU 2024/1183) further strengthens this principle by extending recognition to new qualified trust services introduced by the revised regulation.

How do you verify that a signature service provider is properly qualified under eIDAS?

Each Member State publishes and maintains an official trusted list (Trusted List) listing all qualified trust service providers (QTSPs) accredited in its territory. In France, this list is published and updated by ANSSI on its official website. The European Commission aggregates all national lists on the EU Trusted List Browser portal (tlbrowser.tsl.europa.eu). Check that a service provider is listed there before entrusting it with the issuance of qualified certificates or the creation of QES signatures.

Conclusion

The three levels of electronic signature defined by the eIDAS regulation — SES, AES, and QES — respond to fundamentally different legal and operational needs. SES is suitable for low-stakes documents, AES covers the majority of standard professional contracts with an excellent balance between security and fluidity, whilst QES is essential for documents with strong legal value thanks to its legal presumption of handwritten equivalence throughout the European Union. In 2026, with the progressive entry into force of eIDAS 2.0, mastering these distinctions is more strategic than ever for any organisation digitising its document processes.

Certyneo enables you to deploy all three levels of signature according to your actual needs, with a unified interface compliant with eIDAS and ANSSI requirements. Discover our offerings or estimate your gains straight away using our electronic signature ROI calculator, or contact our team for a personalised audit of your document flows.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Dive deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.