Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover key requirements, synergies with eIDAS, and best practices to adopt.
Updated on
Electronic signature (or e-signature) allows you to sign documents digitally with the same legal value as a manuscript signature. This guide explains how it works, the three levels defined by eIDAS regulation, its legal validity in France and Europe, and how to implement electronic signature in your organisation.

A electronic signature is a set of data in electronic form, which are attached or logically associated with other data in electronic form and which the signer uses to sign. This definition, taken from the eIDAS regulation (regulation (EU) No. 910/2014), covers a wide spectrum of technical mechanisms, from the simplest (checking a box, typing your name) to the most sophisticated (qualified cryptographic certificate).
In French law, article 1367 of the Civil Code provides that "the signature necessary for the perfection of a legal act identifies the person who affixes it" and that, when it is electronic, it "consists in the use of a reliable identification process guaranteeing its link with the act to which it attaches". The reliability of the process is presumed for signatures qualified under eIDAS.
In practice, an electronic signature fulfils three functions: it identifies the signatory, it expresses their consent to the contents of the document, and it guarantees the integrity of the document (any modification after signing is detectable).
The terms are often confused. Electronic signature is the legal concept (what commits the signer). Digital signature is the underlying cryptographic technique (document hash, asymmetric encryption with private key) which can be used to implement an advanced or qualified electronic signature. Every digital signature is an electronic signature, but the reverse is not true.
The mechanism rests on two pillars: the authentication of the signer and the integrity of the document.
To authenticate the signatory, one or more identification factors are used: trusted email address (single-use link), OTP code received by SMS, personal cryptographic certificate, etc. To guarantee integrity, a hash (fingerprint) of the document is calculated at the time of signing. If the document is modified afterwards, the hash no longer matches — the signature is then invalidated.
In solutions like Certyneo, the process relies on PDF processing libraries that integrate these cryptographic metadata directly into the file. A timestamped audit trail (log of actions) completes the system by recording each step: sending, opening, OTP validated, signature, etc.
From a technical perspective, several security mechanisms strengthen the inviolability of the process: qualified timestamping (RFC 3161) applies certified time-proof to each signature; TLS 1.3 encryption protects data in transit; geolocation and the signatory's IP address are recorded for traceability; finally, in certain flows (AES/QES), behavioural biometric data (typing speed, pressure) complement the identity fingerprint.
The concept of non-repudiation is central: thanks to the timestamped and cryptographically signed audit trail, it is technically impossible for a signatory to deny having signed a document without falsifying the chain of evidence. With respect to archiving, French regulations (Decree 2016-1673) require retention for 10 years for most commercial acts — Certyneo ensures this archiving with probative value in sovereign hosting (EU).
The eIDAS regulation defines a hierarchy of three levels. The higher the level, the stronger the identification requirements and the more robust the legal presumption.
Simple electronic signature
Examples
Web form, checkbox, name typed on keyboard
Typical use cases
Quotations, internal orders, low-risk documents
Certyneo
Available on all Certyneo plans
Advanced electronic signature
Examples
SMS OTP + email, strong signer authentication
Typical use cases
Employment contracts, NDAs, significant commercial contracts
Certyneo
Standard and Business plans — Dual-channel OTP (email + SMS)
Qualified Electronic Signature
Examples
QTSP certificate + secure creation device
Typical use cases
Notarised deeds, very high-value contracts, public procurement
Certyneo
Via QTSP partner on request — native integration in roadmap
| Criterion | SES Simple | AES — Advanced | QES — Qualified |
|---|---|---|---|
| Signer identification | Email only | OTP SMS + email | QTSP + QSCD Certificate |
| Document Integrity | Basic | Cryptographic (hash) | Cryptographic (hash) |
| Qualified Certificate Required | No | No | Yes (eIDAS provider) |
| Presumption of Equivalence to Handwritten Signature | No | Partial | Full (art. 25 eIDAS) |
| Reversal of Burden of Proof | No | No | Yes (in favour of the signatory) |
| Typical Use Cases | Quotations, orders | HR contracts, NDAs, employment agreements | Notarised deeds, public procurement |
| Certyneo Availability | All plans | Standard and Business | Via partner QTSP |
Key legal point — reversal of burden of proof: For QES only, article 25 of eIDAS regulation establishes a legal presumption of equivalence with manuscript signature. In case of dispute, it is for the challenger to prove that the signature is invalid — not for the signer to prove its validity. This reversal is a considerable advantage in contractual disputes.
In France, electronic signature has been recognised since law No. 2000-230 of 13 March 2000, which amended the Civil Code to establish electronic writing and electronic signature as equivalent to their paper counterparts. Article 1366 specifies that electronic writing "has the same probative force as writing on paper support".
At European level, eIDAS regulation (EU) No. 910/2014 creates a unified legal framework for electronic signatures. Its article 25 establishes the principle of non-discrimination: "an electronic signature cannot be denied legal effects and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form". Qualified signatures (QES) also benefit from a legal presumption equivalent to a manuscript signature in the 27 member states.
For standard documents (commercial contracts, employment contracts, quotes, NDAs, mandates), an advanced signature (AES) offers an excellent balance between ease of use and legal security. Qualified signature (QES) is reserved for high-value documents or situations where sector-specific regulations explicitly require it.
To ensure a service provider's compliance, ANSSI publishes the French trust list (TSL — Trust Service List) of qualified providers authorised to issue QES certificates. At the European level, each Member State publishes its own TSL, all accessible via the official European Commission portal (eidas.ec.europa.eu). Certyneo is ISO 27001 certified and hosts its data in the EU (Germany).
Beyond legality, electronic signature fundamentally transforms contractual and administrative processes.
Un contrat qui prenait 5 jours (impression, envoi postal, retour) se finalise en quelques heures. Les rappels automatiques éliminent les relances manuelles.
L'audit trail horodaté, le chiffrement TLS 1.3 et l'OTP double canal offrent un niveau de preuve supérieur au papier contre la falsification ou le déni.
eIDAS compliance and article 1367 of the French Civil Code. Signed documents have the same probative force as a manuscript signature and are admissible before French courts.
Élimination des coûts d'impression, d'envoi, d'archivage physique et de gestion manuelle. Le ROI est généralement atteint en moins de 3 mois.
Every step of the document's lifecycle is recorded. You know exactly who opened, read and signed, and at what time, from which IP address.
Data hosted in Germany (EU) (European Union), documented retention period, right of access and deletion. GDPR compliance is included natively.
Nearly all contracts and legal documents can be electronically signed. Few exceptions remain (notarial deeds, handwritten wills) but they account for less than 5% of common commercial documents.
Even if legally recognised, an electronic signature can be challenged if poorly implemented. Here are the most frequent pitfalls observed in business.
Signing an employment contract or deed of transfer with SES (simple click) exposes the employer to a risk of challenge. Rule: any contract worth > €1,500 or with significant HR consequences must use at minimum AES with SMS OTP.
The signed document is only part of the proof. The audit trail — which documents each step (send, open, OTP validated, time, IP) — is the cornerstone in case of dispute. Without it, it is impossible to reconstruct the chain of events before a judge.
Biometric and identification data of signatories are sensitive personal data. Your service provider must host data in the European Union and have a DPA (Data Processing Agreement) compliant with GDPR. Beware of US-based solutions without EU hosting.
Scanning your manuscript signature and inserting it into a PDF has no legal value under eIDAS regulation. A true electronic signature is based on cryptographic mechanisms for integrity and authentication — not on an image.
Decree 2016-1673 requires preserving signature evidence for the entire legal lifetime of the contract (10 years for commercial documents, 5 years for employment contracts). Your solution must guarantee archiving with probative value, not just standard cloud storage.
With Certyneo, you can send your first document to sign in less than 5 minutes.
Sign up on Certyneo in seconds with your email or via Google/Microsoft. No credit card required to get started.
Import your PDF or Word file. Certyneo automatically converts Word files to PDF optimised for signing.
Enter the name and email of each signatory. Set the signing order if necessary and position the signature fields in the document.
A secure email is sent to each signatory with a unique link. For advanced signature, the signatory also receives an OTP via SMS.
From your dashboard, track the status of each envelope: sent, opened, signed or rejected. Automatic reminders follow up with inactive signatories.
Once all signatories have signed, the final PDF (with integrated audit footer) is automatically archived for 10 years and accessible at any time.
An electronic signature is a technical process for identifying the author of a digital document and guaranteeing the integrity of that document. It is the legal equivalent of a manuscript signature under eIDAS regulation (EU) No. 910/2014 and article 1367 of the French Civil Code.
Yes. Electronic signature is legally recognised in France since the law of 13 March 2000 (article 1367 of the Civil Code) and throughout the European Union thanks to eIDAS regulation. It has the same legal value as a manuscript signature as long as the conditions for identification of the signer and integrity of the document are met.
eIDAS defines three levels. Simple signature (SES) corresponds to the basic level: click, check a box or type your name. Advanced signature (AES) requires identification of the signer (OTP SMS/email, for example) and a unique link with the document. Qualified signature (QES) additionally requires a certificate issued by a qualified trust service provider (QTSP) and a secure signature creation device — it offers the strongest legal presumption.
Almost all contractual and commercial documents can be signed electronically: employment contracts, quotations and purchase orders, NDAs, service contracts, amendments, mandates, agreements, transfer deeds. Certain authentic acts (notarial deeds, civil status acts) require specific conditions.
With Certyneo, the sender uploads their PDF document, adds the signatories and defines the fields. Each signatory receives a secure link by email. For advanced signature (AES), a dual OTP email + SMS (our SMS OTP provider) authenticates the signatory. The final PDF incorporates a timestamped audit footer and is archived for 10 years.
Yes. eIDAS is directly applicable in the 27 member states of the European Union. A qualified signature issued in one member country is recognised in all other member states. Simple and advanced signatures also have probative value but may be subject to assessment by the court.
Certyneo offers a free plan (5 envelopes/month), a Personal plan at €9/month, a Standard plan at €19/month and a Business plan at €39/month (Business) or €99/month (Business Pro). Advanced eIDAS signature (AES) is available from the Personal plan (€9/month).
The audit trail is a timestamped log of all actions performed on an envelope: send, open, view, sign, reject, expire. It provides evidence of the chronology of events and strengthens the evidential value of the signed document in case of dispute.
Yes, an eIDAS-compliant electronic signature is technically safer than a manuscript signature. It combines: (1) signer identification via OTP SMS or certificate, (2) cryptographic fingerprint (SHA-256 hash) of the document — any post-signature modification immediately invalidates the signature, (3) qualified time-stamping certifying the exact time, (4) signed and encrypted audit trail preserving complete history. None of these protections exist for a paper signature.
The duration depends on the nature of the document: 10 years for commercial contracts (art. L.110-4 French Commercial Code), 5 years for employment contracts, 30 years for property matters. Decree 2016-1673 requires archiving to be carried out under conditions guaranteeing document integrity and readability. Certyneo ensures such archiving with evidential value, hosted in the European Union.
Non-repudiation is the legal and technical property that prevents a signer from denying having affixed their signature. It is guaranteed by the combination of: the time-stamped audit trail and cryptographically signed, the OTP sent to the signer''s phone number (proof of possession), and the unique fingerprint of the document. In case of judicial dispute, non-repudiation constitutes a strong presumption in favour of the signature beneficiary.
For a reliable and compliant solution, verify: eIDAS qualification (ANSSI trust list for QES), ISO 27001 certification (information security), GDPR compliance with hosting in the EU, HDS compliance if you process health data, and ideally ANSSI's SecNumCloud qualification for cloud-hosted solutions. Certyneo hosts all its data in Germany (EU).
Certyneo Legal Team
Electronic signature and contract law experts
This guide is written and maintained by Certyneo's legal and technical team, specialising in electronic contract law, eIDAS compliance and data protection (GDPR). Each article is reviewed quarterly to reflect the latest regulatory developments.
Last review :
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover key requirements, synergies with eIDAS, and best practices to adopt.
Electronic signature is revolutionising medical document workflows, but imposes strict requirements for patient data protection. Discover how to reconcile efficiency and HIPAA compliance.
Does a contract signed electronically really hold up in a French court? Complete breakdown of the evidentiary value of electronic signature in litigation situations.
Electronic signature in B2C contracts raises specific questions about legal validity and customer consent collection. Here is everything you need to know for 2026.
Since 2020, electronic signature has been mandatory in public procurement above certain thresholds. Discover the rules, required levels, and how to bring your administration into compliance.
Territorial authorities are accelerating their digitisation. Discover how electronic signature secures your contracts, reduces delays and complies with the European legal framework.
We use cookies to improve your experience on our site. Cookies strictly necessary for the service to function are always active. Learn more