QES, AES, and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026
The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.
Writer — Certyneo · About Certyneo

The eIDAS regulation (No. 910/2014) forms the cornerstone of European electronic signature law. Since its entry into force, it has structured three levels of signature — SES, AES, and QES — whose technical requirements and evidentiary value differ radically. In 2026, with the progressive implementation of eIDAS 2.0 (EU Regulation 2024/1183), these distinctions become increasingly important for any organization seeking to digitize its legal documents in full compliance. This article decrypts the fundamental differences between these three levels, the obligations they entail, and the criteria to consider when choosing the right format based on the nature of your documents.
SES: Simple Electronic Signature, Flexible but Limited
Definition and Technical Characteristics
Simple Electronic Signature (SES) is defined in Article 3(10) of the eIDAS regulation as "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign". This definition is intentionally broad: a simple click on "I accept," a signature drawn with a finger on a tablet, or even a checked box in an online form fall into this category.
SES requires no prior verification of the signatory's identity, nor any cryptographic certificate. Its reliability rests solely on the contractual context and peripheral evidence (IP address, server timestamp, confirmation email). The electronic signature glossary lists all technical terms associated with these mechanisms.
Legal Value and Accepted Use Cases
SES benefits from the non-discrimination principle set out in Article 25(1) eIDAS: it cannot be rejected as evidence solely because it is electronic. However, it carries no presumption of reliability. In case of dispute, the burden of proof rests entirely on the party invoking it. The legal value of electronic signature thus depends heavily on the level chosen.
SES is suitable for low-risk documents: acceptance of terms and conditions, internal forms, low-value online orders, or satisfaction surveys. It is unsuitable for any document likely to be contested in court.
AES: Advanced Electronic Signature, the Balance Between Security and Practicality
The Four Cumulative Criteria of Article 26 eIDAS
Advanced Electronic Signature (AES) is defined in Article 3(11) eIDAS and must satisfy four conditions enumerated in Article 26:
- Be linked to the signatory in a unique manner: a unique identifier connects the signature to a specific natural person.
- Enable identification of the signatory: identity verification is performed (email, phone number, identification document according to the provider).
- Have been created from data that the signatory can use with a high level of confidence under their exclusive control: typically a one-time password (OTP) sent to their phone or a software certificate.
- Be linked to the signed data in such a way that any subsequent modification is detectable: the signature is based on a cryptographic hash of the document.
Technologies Used and Assurance Levels
In practice, AES is implemented through digital certificates at a substantial level (within the meaning of the eIDAS regulation), multi-factor authentication mechanisms, or document-based identity solutions (identity document scanning, biometric comparison). Qualified trust service providers such as Certyneo offer AES signature workflows incorporating remote identity verification, compliant with ANSSI referentials and ETSI EN 319 401 standards.
AES offers an excellent compromise between security and user experience fluidity. It is recommended for standard commercial contracts, HR documents, partnership agreements, or service contracts. Consult our comprehensive guide to electronic signature in business to learn more about uses in a professional context.
AES Limitations with Certain Documents
AES remains insufficient for authentic documents or those for which the law expressly requires qualified signature. In France, Article 1367 of the Civil Code reserves maximum reliability presumption solely to signatures qualified within the meaning of eIDAS. AES can be rejected by a judge if the opposing party demonstrates insufficiency in the identity verification process.
QES: Qualified Electronic Signature, Legal Equivalent of Handwritten Signature
Regulatory Definition and Technical Requirements
Qualified Electronic Signature (QES) is defined in Article 3(12) eIDAS as an advanced signature created by a qualified signature creation device (QSCD) and based on a qualified certificate for electronic signatures. These two components are inseparable.
The qualified certificate is issued by a qualified trust service provider (QTSP) registered on the national trust list (Trusted List) published by each member state. In France, this list is administered by the ANSSI. The QTSP must have been audited and accredited according to the requirements of Annex I of the eIDAS regulation and ETSI EN 319 411-2 standards.
The QSCD (qualified signature creation device) is a secure hardware or software support — typically a smart card, cryptographic USB token, or remote Hardware Security Module (HSM) — guaranteeing that the signatory's private key cannot be extracted or copied. QSCD requirements are specified in Annex II of the eIDAS regulation.
The Irrebuttable Legal Presumption of Article 25(2)
Article 25(2) of the eIDAS regulation gives QES a legal effect equivalent to handwritten signature in all European Union member states. This presumption is automatic: unlike AES, the party producing a QES is not required to demonstrate the reliability of the process. It is up to the adversary to rebut this presumption, which is in practice very difficult once the QTSP and QSCD are duly qualified.
In France, Article 1367 paragraph 2 of the Civil Code transposes this requirement into domestic law: the reliability of the electronic signature process is presumed until proven otherwise when qualified electronic signature eIDAS is used. This presumption also covers the integrity of the signed document.
Process for Obtaining a Qualified Certificate
Obtaining a qualified certificate requires face-to-face identity verification or remote equivalent with the same assurance level (for example, video identification compliant with EN ISO/IEC 18013 standard or specifications of implementing regulation 2015/1502). The process involves:
- Collection of official identity documents
- Verification of their authenticity (forgery detection)
- Biometric registration of the signatory
- Certificate issuance by the QTSP following validation
This level of requirement explains why QES is reserved for high-risk documents: under-hand deeds with high financial stakes, electronic notarial documents, public procurement, sensitive medical documents, or where sectoral regulation explicitly requires it. To compare available solutions on the market, our comparison of electronic signature solutions will guide you in your choice.
Comparative Table and Selection Criteria in 2026
Summary of Structural Differences
Three axes allow for quick distinction between the three levels:
Identity verification: none for SES, documentary or OTP for AES, face-to-face or equivalent for QES. Cryptographic support: non-existent for SES, software certificate for AES, certified QSCD for QES. Legal presumption: absent for SES, partial for AES, total and automatic for QES.
In terms of user friction, the equation is reversed: SES is quasi-transparent, AES requires a few minutes of verification, QES requires a prior registration process that can take from a few minutes (video identification) to several days.
Impact of eIDAS 2.0 on These Distinctions in 2026
Regulation eIDAS 2.0 (EU 2024/1183), whose implementing acts have been progressively published since 2024, reinforces several key points. It introduces the European Digital Identity Wallet (EUDI Wallet), which will eventually allow European citizens to store their qualified certificate directly on their smartphone, significantly reducing friction associated with QES. It also clarifies requirements applicable to QTSPs and strengthens the governance of national trust lists.
Furthermore, eIDAS 2.0 extends the scope of mutual recognition of qualified signatures between member states, which is particularly important for businesses operating in multiple EU countries. The comprehensive guide to eIDAS 2.0 regulation details all these regulatory developments. Finally, the issue of qualified electronic timestamp — complementary to QES to preserve the evidentiary value of documents over time — also deserves attention when designing your documentary architecture.
Legal Framework Applicable to SES, AES, and QES Signatures
The hierarchy of electronic signatures rests on a dense regulatory framework, articulating European law and French domestic law.
Regulation eIDAS No. 910/2014: this foundational text defines the three levels of signature in Articles 3(10), 3(11), and 3(12). Article 25 establishes the non-discrimination principle (§1) and the presumption of handwritten equivalence for QES (§2). Article 26 enumerates the four cumulative conditions for advanced signature. Annexes I and II specify respectively the requirements applicable to qualified certificates and qualified signature creation devices (QSCD).
Regulation eIDAS 2.0 — EU 2024/1183: entered into force on May 20, 2024, it substantially amends the 2014 regulation, notably by introducing the European Digital Identity Wallet (EUDI Wallet), expanding qualified trust services, and strengthening QTSP governance. Implementing acts continue to be published in 2026.
French Civil Code, Articles 1366 and 1367: Article 1366 recognizes the electronic document as evidence on equal footing with paper documents, provided that the person from whom it originates can be duly identified and it is established and maintained in conditions ensuring its integrity. Article 1367 paragraph 2 establishes the presumption of reliability for qualified electronic signature eIDAS, in direct transposition of Article 25(2) of the regulation.
Decree No. 2017-1416 of September 28, 2017: specifies in French law the conditions for benefiting from the presumption of reliability, explicitly referring to eIDAS regulation requirements for qualified signatures.
ETSI Standards: ETSI standards EN 319 102-1 (signature creation and validation procedures), ETSI EN 319 132 (XAdES format), ETSI EN 319 122 (CAdES format), and ETSI EN 319 142 (PAdES format) technically govern the creation of compliant electronic signatures. Qualified providers must implement these formats to ensure European interoperability.
GDPR — Regulation EU 2016/679: the collection of biometric data in the context of identity verification for qualified certificate issuance constitutes processing of sensitive data within the meaning of Article 9. The QTSP must have an explicit legal basis, inform individuals, and implement appropriate technical safeguards. An impact assessment (DPIA) is generally required.
NIS2 Directive — EU 2022/2555: applicable to essential service operators and digital service providers, it imposes strengthened cybersecurity requirements that indirectly apply to QTSPs operating critical electronic signature infrastructures.
Organizations that deploy electronic signature solutions without respecting the level required by the legal nature of the document are exposed to nullity or inopposability of signed documents, as well as litigation risks that can lead to significant financial losses.
Use Scenarios: Choosing the Right Level According to Context
Case 1 — Industrial SME Managing Hundreds of Supplier Purchase Orders
An industrial SME processing approximately 400 purchase orders and supplier contracts annually deployed AES for all standard commercial documents. The signature workflow relies on verification through a secure email link and SMS OTP, with generation of a timestamped audit report for each document. Average signing time fell from 4.5 days (registered mail) to less than 3 hours. The contractual dispute rate remained zero over 18 months of operation, with the audit trail providing sufficient evidence in case of commercial disagreement. Reduction in printing, postage, and document management costs reached approximately 60% according to internal estimates, consistent with ranges published by European sector studies (Billentis Report, 2025).
Case 2 — Business Law Firm Specialized in Corporate Law
A business law firm with approximately fifteen attorneys implemented a two-tier infrastructure: AES signature for internal correspondence, representation mandates, and fee agreements; QES signature for high-stakes under-hand deeds (share transfers, settlement protocols, financial guarantees). Obtaining qualified certificates for partners was accomplished through a video identification session compliant with eIDAS, without physical travel, in less than 20 minutes per person. The legal presumption attached to QES allows the firm to present its documents before any European court without having to demonstrate the reliability of the process, significantly reducing procedural risk.
Case 3 — Hospital Group Digitizing HR and Medical Documents
A hospital group of approximately 1,200 beds chose a differentiated approach based on document nature. Employment contracts, amendments, and job descriptions are signed in AES, allowing approximately 800 staff members to sign from their smartphone without heavy infrastructure. For specific medical agreements and documents requiring strong authentication mandated by healthcare regulations (HDS), QES is deployed for designated physician signatories. This hybrid model reduces HR file preparation time by 75% during recruitment, a gain particularly critical during periods of healthcare resource tension. It also ensures compliance with CNIL obligations regarding health data processing.
Frequently Asked Questions
What Is the Main Difference Between QES and AES in eIDAS?
The fundamental difference lies in two elements: the certificate and the signature device. QES necessarily rests on a qualified certificate issued by an accredited provider (QTSP) and on a qualified signature creation device (QSCD) that is materially secure. AES can use a software certificate and less strict identity verification. Direct consequence: QES benefits from a legal presumption of equivalence to handwritten signature throughout the European Union, which AES does not automatically guarantee.
In What Cases Is It Mandatory to Use a QES Signature?
No European text imposes QES in general, but several sectoral or national regulations require it implicitly or explicitly. This applies to certain electronic authentic documents, specific public procurement, digitized notarial documents, or in regulated sectors such as banking (DSP2, enhanced KYC) or healthcare. The general rule is as follows: the higher the legal or financial stakes of the document, the more recommended QES use is to eliminate any risk of challenge.
Does Simple Electronic Signature Have Legal Value in France in 2026?
Yes, SES is legally admissible in France under the non-discrimination principle set out in Article 25(1) of the eIDAS regulation and Article 1366 of the Civil Code. It cannot be rejected as evidence solely because it is electronic. However, it benefits from no presumption of reliability: in case of challenge, the party invoking it must demonstrate its robustness by other means (logs, IP address, audit trail). Its use should therefore be reserved for low-risk documents.
Is a Qualified Certificate Obtained in France Recognized Throughout the European Union?
Yes. Article 25(2) of the eIDAS regulation and the mechanism for mutual recognition of national trust lists (Trusted Lists) ensure that a qualified certificate issued by an accredited QTSP in France is recognized in all European Union member states with the same legal effect. eIDAS 2.0 (EU 2024/1183) further strengthens this principle by extending recognition to new qualified trust services introduced by the revised regulation.
How Can I Verify That a Signature Provider Is Properly Qualified Under eIDAS?
Each member state publishes and maintains an official trust list (Trusted List) listing all qualified trust service providers (QTSP) accredited in its territory. In France, this list is published and updated by ANSSI on its official website. The European Commission aggregates all national lists on the EU Trusted List Browser portal (tlbrowser.tsl.europa.eu). Verify that a provider is listed there before entrusting them with issuing qualified certificates or creating QES signatures.
Conclusion
The three levels of electronic signature defined by eIDAS regulation — SES, AES, and QES — meet fundamentally different legal and operational needs. SES suits low-stakes documents, AES covers the majority of standard professional contracts with an excellent balance between security and fluidity, while QES is necessary for documents with high legal value thanks to its legal presumption of handwritten equivalence throughout the European Union. In 2026, with the progressive implementation of eIDAS 2.0, mastering these distinctions is more strategically important than ever for any organization digitizing its documentary processes.
Certyneo allows you to deploy all three signature levels according to your actual needs, with a unified interface compliant with eIDAS and ANSSI requirements. Discover our offerings or estimate your gains right now using our electronic signature ROI calculator, or contact our team for personalized audit of your documentary workflows.
Try Certyneo for Free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Dive Deeper
Reference articles on this topic.
Dive Deeper
Our comprehensive guides to master electronic signatures.
Recommended Articles
Deepen your knowledge with these related articles.

Healthcare Data Protection and GDPR Compliance for Professionals
Healthcare data is the most sensitive personal data under GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.

VAT 2026: Calculation, Declaration and New Obligations for Businesses
The VAT reform of 2026 transforms calculation and declaration rules for millions of French businesses. Master the new obligations before they apply to you.

EIRL vs SARL: Complete Comparison of Legal Business Structures in 2026
Choosing between EIRL and SARL is a strategic decision that affects your personal assets, tax situation, and professional future. Discover the complete comparison for 2026.