Skip to main content
Certyneo
Regulation (EU) No 910/2014 · Updated 2026

eIDAS Regulation: understand everything about electronic signature in Europe

Last updated

eIDAS regulation is the founding text of electronic signature in Europe. It defines three levels of signature (simple, advanced, qualified), establishes the legal value of electronic documents and governs trust service providers. This guide explains everything you need to know to be compliant in 2026.

eIDAS Regulation — European flag and institutions

What is eIDAS and why was it created?

Before eIDAS, each EU member state had its own regulations on electronic signatures, creating legal fragmentation that hindered cross-border transactions. An electronic signature valid in France was not necessarily recognised in Germany or Spain.

The Regulation (EU) No 910/2014, known as eIDAS (Electronic IDentification, Authentication and trust Services), was adopted on 23 July 2014 and entered into force on 1 July 2016. As a regulation (not a directive), it applies directly and uniformly in all 27 member states, without requiring national transposition.

eIDAS pursues three main objectives: creating a single digital market in Europe through mutual recognition of electronic identities, guaranteeing legal certainty for cross-border electronic transactions, and establishing a framework of trust for digital services through qualified trust service providers (QTSP — Qualified Trust Service Provider).

The 3 levels of signature defined by eIDAS

eIDAS establishes a pyramid of three levels of electronic signature, each with its own technical requirements and probative value.

Level 1SESArticle 3(10) eIDAS

Simple Electronic Signature

Available on Certyneo

eIDAS requirements

  • Data in electronic form linked to other data
  • Used to sign (no specific technical requirements)
  • Can be a simple click, a ticked box, or a typed name

Usage examples

  • Acceptance of terms and conditions
  • Online form
  • Confirmation email

Legal value

Basic contractual value, no legal presumption

Level 2AESArticle 26 eIDAS

Advanced Electronic Signature

Available on Certyneo

eIDAS requirements

  • Uniquely linked to the signatory
  • Allows identification of the signatory
  • Created using data under the sole control of the signatory
  • Any subsequent modification of the document is detectable

Usage examples

  • Employment Contracts
  • NDAs
  • Commercial Contracts
  • Powers of Attorney

Legal value

Strong evidential value — recommended for important contracts

Level 3QESArticle 25(2) + Annex I eIDAS

Qualified Electronic Signature

Available on Certyneo

eIDAS requirements

  • Meets all requirements of AES
  • Created by a Qualified Signature Creation Device (QSCD)
  • Based on a qualified certificate issued by a QTSP (EU trust list)

Usage examples

  • Digital authentic deeds
  • High-value public procurement
  • Regulated deeds

Legal value

Legal presumption equivalent to manuscript signature (art. 25 eIDAS)

eIDAS 2.0: What's New in 2024

The eIDAS regulation has been revised by Regulation (EU) 2024/1183, published in the EU Official Journal on 30 April 2024 and entered into force on 20 May 2024. This revision modernises the initial framework to address contemporary digital challenges: digital identity for citizens, sovereign cloud, and resilience of trust service providers.

The flagship measure of eIDAS 2.0 is the European digital identity wallet (EUDIW). By the end of 2026, each member state must offer its citizens and residents an application to store and present certified identity credentials — the digital equivalent of an ID card, driving licence, diplomas. This development will have a direct impact on qualified signature processes.

Digital Identity Wallet (EUDIW)

eIDAS 2.0 introduces the European Digital Identity Wallet: each European citizen will be able to store certified identity credentials (identity card, driving licence, diplomas) in a mobile application interoperable across the entire EU.

Strengthened QTSP Requirements

Requirements applicable to qualified trust service providers (QTSP) are reinforced, particularly regarding cybersecurity, audits, and service continuity.

New Trust Services

eIDAS 2.0 adds new qualified services: qualified electronic archiving, qualified attribute data management, and qualified electronic registry (certified blockchain).

Enhanced Interoperability

Better mutual recognition of digital identities between Member States. Qualified signatures issued in any EU country are recognised everywhere.

How to Be eIDAS Compliant in Practice?

eIDAS compliance is not just about choosing a signature level. It involves reflection on the entire process: risk identification, tool selection, proof retention and document governance.

Here is a practical checklist for businesses wishing to secure their electronic signature processes in compliance with eIDAS:

Identify the appropriate signature level for each type of document
Use a solution whose provider hosts data within the EU
Preserve the timestamped audit trail with each signed document
Ensure that the signatory is identified appropriately for the chosen level
Have a documented retention policy (duration, access, deletion)
Verify that the provider has a Data Processing Agreement (DPA) compliant with GDPR
For AES: implement an OTP mechanism or strong authentication
For QES: engage a QTSP listed on a national trust list

Certyneo's eIDAS Compliance Approach

Certyneo natively implements the three levels of the eIDAS regulation: SES (Simple Electronic Signature), AES (Advanced Electronic Signature) and QES (Qualified Electronic Signature). Advanced signature is based on dual-factor authentication: a single-use link sent by email and an OTP code sent by SMS via our OTP SMS provider, in accordance with the four criteria of article 26 of eIDAS. Qualified signature (QES) is delivered per act at €14.90/signature on all plans, including Free, via a qualified provider (QTSP) listed on the European trust list — legal equivalent of a handwritten signature throughout the EU under article 25(2) of eIDAS.

Each envelope generates a complete audit trail: timestamping of each action (sending, link opening, OTP validation, signature application, potential refusal), signatory's IP address, browser user-agent. This audit trail is embedded at the bottom of each page of the final PDF (audit footer) and retained for 10 years.

Data is hosted (EU) (IONOS infrastructure), within the European Union, in compliance with digital sovereignty requirements and GDPR. Visit our security and compliance page for all technical details.

Frequently Asked Questions about eIDAS

What is the eIDAS regulation?

eIDAS (Electronic Identification, Authentication and Trust Services) is the European regulation (EU) No 910/2014 which establishes a common legal framework for electronic signatures, electronic seals, timestamps, electronic registered delivery services, and website authentication services across the European Union. It entered into force on 1 July 2016 and applies directly in all 27 Member States.

What is the difference between eIDAS and eIDAS 2.0?

eIDAS 2.0 (regulation (EU) 2024/1183, which came into force on 20 May 2024) modernises eIDAS 1.0 by introducing notably the European digital identity wallet (EUDIW — European Digital Identity Wallet), which will allow European citizens to store certified digital identity credentials. For businesses, eIDAS 2.0 strengthens the requirements of qualified trust service providers (QTSP) and improves cross-border interoperability.

Does a simple electronic signature have legal value under eIDAS?

Yes. Article 25 of eIDAS explicitly prohibits refusing legal effects to an electronic signature solely on the grounds that it is in electronic form. A simple signature (SES) therefore has legal value, but it does not benefit from the legal presumption reserved for qualified signatures (QES). In case of dispute, it is for the party relying on the signature to prove its authenticity.

How do I know which eIDAS level to choose for my contracts?

The general rule is to calibrate the level to the legal and commercial risk of the document. For low-stakes standard documents (quotes, internal orders), simple signature is sufficient. For important commercial contracts, employment contracts, NDAs or mandates, advanced signature (AES) is recommended. Qualified signature (QES) is reserved for situations where the law explicitly requires it (certain administrative documents, large-scale public procurement) or when the risk of dispute is maximal.

How is Certyneo compliant with eIDAS?

Certyneo natively implements all three eIDAS levels: simple signature (SES), advanced signature (AES) with SMS OTP, and qualified signature (QES) at €14.90 per signature on every plan, including Free, via a qualified QTSP from the EU trust list. Every envelope generates a timestamped audit trail embedded in the final PDF. Data is hosted in the European Union, in line with digital sovereignty requirements.

Does eIDAS apply to businesses outside the European Union?

eIDAS applies to trust services provided in the EU. A company established outside the EU wishing its signatures to be recognised in the EU must use an eIDAS-compliant solution or a qualified trust service provider (QTSP) recognised in the trust list of a member state. For international B2B exchanges, mutual recognition agreements exist with certain third countries.

An eIDAS-compliant solution, starting today

Certyneo implements SES and AES signatures in accordance with the eIDAS regulation. Hosting (EU), timestamped audit trail and GDPR included.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.