Go to main content
Certyneo

Advanced vs Qualified Electronic Signature: Key Differences

AES vs QES under eIDAS: understand the legal differences, technical requirements, and exactly when each signature type is required for compliance.

Rédaction Certyneo12 min read

Rédaction Certyneo

Writer — Certyneo · About Certyneo

Person pointing at a marriage certificate on a wooden table.

Introduction

Electronic signatures are no longer a convenience — they are a legal necessity for businesses operating across borders. Yet many legal, compliance, and operations teams still conflate two fundamentally different tiers: the advanced electronic signature (AES) and the qualified electronic signature (QES). Choosing the wrong type can invalidate a contract, trigger a regulatory penalty, or create costly litigation. This guide cuts through the confusion, explaining the technical definitions, the legal weight, the applicable standards under eIDAS Regulation 910/2014, and the precise scenarios where each signature type belongs.

---

What eIDAS Says: The Three-Tier Signature Framework

The EU's eIDAS Regulation (EU No 910/2014) establishes a three-tier hierarchy for electronic signatures, each carrying progressively stronger legal presumptions and technical requirements.

Simple Electronic Signature (SES)

A simple electronic signature is any data in electronic form that is attached to or logically associated with other data and used by the signatory to sign. A typed name at the bottom of an email qualifies. It carries the least legal weight and is appropriate only for low-risk, informal agreements. There is no mandatory identity verification and no cryptographic binding.

Advanced Electronic Signature (AES)

Under Article 26 of eIDAS, an advanced electronic signature must meet four requirements:

  1. It is uniquely linked to the signatory.
  2. It is capable of identifying the signatory.
  3. It is created using signature-creation data that the signatory can, with a high level of confidence, use under their sole control.
  4. It is linked to the signed data in such a way that any subsequent change is detectable.

In practice, AES is typically delivered via PKI-based digital certificates issued by a trusted certificate authority, combined with multi-factor authentication (MFA). The signatory does not need to hold a hardware token; a software-based certificate issued after strong remote identity proofing is sufficient. For a deeper look at how this standard is implemented, see our glossary entry on AES.

Qualified Electronic Signature (QES)

QES sits at the apex of the eIDAS hierarchy. Article 25(2) states that a QES has the equivalent legal effect of a handwritten signature across all EU member states. To qualify, a QES must:

  • Be an advanced electronic signature (meeting all four Article 26 requirements).
  • Be based on a qualified certificate for electronic signatures issued by a Trust Service Provider (TSP) on the EU Trusted List.
  • Be created by a qualified electronic signature creation device (QESCD) — typically a hardware security module (HSM) or a physical smart card/USB token that meets the requirements of Annex II of eIDAS.

The identity verification for a QES certificate must be conducted face-to-face or via an approved video-identification process. This is an irreducible requirement. For a full technical breakdown, see our QES glossary page.

---

Advanced vs Qualified Electronic Signature: A Side-by-Side Comparison

Understanding the advanced vs qualified electronic signature eIDAS difference when to use each comes down to four axes: legal presumption, identity proofing, technical device, and friction.

| Criterion | AES | QES | |---|---|---| | Legal presumption of validity | Rebuttable — must prove authenticity if challenged | Non-rebuttable across EU (Art. 25 eIDAS) | | Cross-border EU recognition | Recognised but not automatically equivalent to handwritten | Legally equivalent to handwritten signature EU-wide | | Admissibility in court | Admissible; weight determined by judge | Presumed valid; burden of proof shifts to challenger |

Outside the EU, recognition depends on local law. In the United States, the ESIGN Act (15 U.S.C. §7001) and the Uniform Electronic Transactions Act (UETA) both adopt a technology-neutral, intent-based approach: any electronic signature — including AES or QES — can be enforceable provided intent to sign is demonstrable. There is no US equivalent of QES's automatic legal equivalence. In Australia, the Electronic Transactions Act 1999 similarly focuses on consent and reliability rather than a tiered certification hierarchy.

Identity Proofing Requirements

AES requires strong identity proofing — typically government-issued ID verification combined with biometric liveness checks or MFA — but allows remote identity proofing via approved methods. QES requires in-person or video-based identity verification that meets the eIDAS-approved scheme, conducted by a qualified TSP. This additional friction is the single biggest operational distinction.

Technical Device Requirements

AES signatures can be applied using server-side HSMs managed by the TSP on behalf of the signer — a model known as remote signing. QES requires a QESCD, which may be a physical token issued to the individual or, increasingly, a cloud-based QESCD operated by the TSP under the CEN EN 419 241-2 standard for remote QES. Both options are valid but the cloud QESCD still requires the qualified certificate and TSP involvement.

When to Use AES vs QES

This is where the advanced vs qualified electronic signature eIDAS difference when to use question becomes most practical.

Use AES for:

  • Commercial contracts, NDAs, and service agreements between businesses.
  • HR documents: offer letters, employment contracts (in most jurisdictions), policy acknowledgments.
  • B2C agreements where high-volume signing is required and the risk of dispute is moderate.
  • Cross-border transactions where eIDAS QES is not mandated but stronger than SES is needed.
  • Regulated sectors in the US: FDA 21 CFR Part 11 for electronic records in clinical trials accepts AES-level controls (audit trail, access control, and unique user identification) as compliant.

Use QES for:

  • Notarial acts and deeds where local law requires the equivalent of a handwritten signature.
  • Real estate transactions in EU jurisdictions (e.g., German land register filings under §126a BGB).
  • Financial services: MiFID II suitability reports, certain insurance contracts, and consumer credit agreements under EU Directive 2008/48/EC.
  • Healthcare: clinical trial informed consent under EU CTR 536/2014.
  • Cross-border EU public procurement where contracting authorities specify QES.
  • Any context where you want the non-repudiation presumption to be legally unchallengeable.

Our complete guide to electronic signatures provides jurisdiction-specific document lists to help you map signature type to document category.

---

Technical Standards Underpinning Both Signature Types

ETSI and CEN Standards

Both AES and QES are governed by technical standards published by ETSI (European Telecommunications Standards Institute) and CEN:

  • ETSI EN 319 132: XAdES (XML Advanced Electronic Signatures) — baseline and extended formats for AES and QES.
  • ETSI EN 319 122: CAdES (CMS Advanced Electronic Signatures).
  • ETSI EN 319 132 / 319 162: PAdES (PDF Advanced Electronic Signatures) — the most common format for B2B document workflows.
  • ETSI TS 119 431: Policy and security requirements for TSPs providing remote signing services.
  • CEN EN 419 241-2: Trustworthy Systems Supporting Server Signing — the standard enabling cloud-based QES creation devices.

When evaluating a signature provider, confirming ETSI-compliant output formats is essential for long-term verifiability. Signatures produced in LT (Long-Term) or LTA (Long-Term Archive) levels embed the full validation chain, ensuring the signature remains verifiable after certificates expire — a critical requirement for contracts lasting 10 or 20 years.

Interoperability Under eIDAS 2.0

The revised eIDAS framework (eIDAS 2.0, EU Regulation 2024/1183) introduces the European Digital Identity Wallet (EUDI Wallet), which will allow EU citizens to issue QES-level signatures directly from their national digital identity. This will dramatically reduce the friction of QES issuance, potentially making QES viable for consumer-facing workflows by 2026–2027. Businesses planning their signature infrastructure should account for EUDI Wallet compatibility when selecting a provider.

---

Cost, Friction, and Operational Tradeoffs

The practical decision between AES and QES is often a function of cost and user experience rather than pure legal analysis.

AES onboarding — remote identity proofing, certificate issuance, and signing — typically takes 2–5 minutes per signatory and can be embedded invisibly in a document workflow. Costs for AES at volume range from $0.50 to $3.00 per envelope depending on provider and volume tier.

QES onboarding, even with video-identification, typically requires 10–20 minutes per signatory for the first certificate issuance. Some TSPs charge €5–€20 per QES transaction, and for high-volume use cases, this cost compounds quickly. Where QES is legally mandated, this cost is unavoidable. Where it is not, AES delivers equivalent enforceability for most commercial purposes at a fraction of the friction.

For organisations operating at scale, comparing provider pricing models is critical — see Certyneo's pricing tiers for a transparent breakdown of AES and QES transaction costs.

For teams evaluating providers, our Certyneo vs DocuSign comparison covers how each platform handles the AES/QES distinction in practice, including trust list coverage and ETSI format support.

If you are ready to deploy a compliant electronic signature workflow, explore the full Certyneo electronic signature platform to understand how AES and QES are implemented end-to-end.

The primary legislative foundation for electronic signatures across the EU is eIDAS Regulation (EU) No 910/2014, which directly applies in all EU member states without the need for national implementing legislation. Articles 25–34 govern electronic signatures, seals, and time stamps. Critically, Article 25(1) prohibits member states from denying legal effect to an electronic signature solely on the grounds that it is in electronic form — establishing a floor of acceptability for even simple electronic signatures. Article 25(2) guarantees that a QES has the equivalent legal effect of a handwritten signature.

For organisations operating in the United States, the federal ESIGN Act (15 U.S.C. §7001 et seq.) and the Uniform Electronic Transactions Act (UETA), adopted in 49 US states, govern enforceability. Both statutes are technology-neutral: they do not mandate AES or QES. However, regulated sectors impose overlay requirements. Under FDA 21 CFR Part 11, electronic records and signatures in clinical and pharmaceutical contexts must meet controls including unique user authentication, audit trails, and system validation — requirements that AES-level controls typically satisfy. Under HIPAA (45 CFR Parts 160 and 164), covered entities must implement access controls and audit logs for electronic protected health information (ePHI); AES-level digital signatures provide the non-repudiation and integrity evidence HIPAA auditors expect.

In the UK, following Brexit, the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (UK eIDAS) remains in force and mirrors the EU framework, maintaining the three-tier hierarchy and the legal equivalence of QES to handwritten signatures. The Law Commission's 2019 report on electronic execution of documents confirmed that electronic signatures are valid for most contracts under English law, provided intent to sign is clear.

In Australia, the Electronic Transactions Act 1999 (Cth) and state equivalents permit electronic signatures for most transactions. High-value property deeds in some states still require wet-ink or specific witnessed electronic execution.

In India, the Information Technology Act 2000, as amended, recognises digital signatures based on PKI certificates issued by licensed certifying authorities — functionally analogous to AES — as legally valid. Aadhaar-based e-signatures use government-issued biometric credentials, creating a de facto QES-equivalent for many regulatory filings.

In South Africa, the Electronic Communications and Transactions Act 25 of 2002 (ECTA) distinguishes between ordinary electronic signatures and advanced electronic signatures (AES), the latter being required for specific regulated documents including deeds of sale for immovable property.

Compliance risk arises when organisations apply a lower-tier signature to a document class that legally requires a higher tier. In such cases, the document may be void, unenforceable, or subject to administrative sanction. Organisations should conduct a document-risk classification exercise before selecting a signature tier.

Use Cases

A mid-size UK financial services firm processing MiFID II suitability reports

A 200-person investment advisory firm operating across the UK and EU was issuing suitability reports and discretionary management agreements using simple electronic signatures — typed names appended to PDF emails. Following an FCA supervisory review, the firm was advised that under MiFID II Article 25 obligations, suitability documentation needed to demonstrate stronger non-repudiation. The firm migrated to AES for standard client correspondence and QES for discretionary portfolio management agreements. By integrating the signing workflow into their CRM, turnaround time on client-agreement execution dropped from an average of 4.2 days (wet-ink post) to 6 hours. Compliance audit preparation time fell by an estimated 35%, as the ETSI-compliant LTA-format signatures provided instant, court-ready audit trails without manual document retrieval.

A multi-state US healthcare network managing clinical trial consent

A hospital network operating in seven US states was enrolling participants in a Phase II clinical trial. Under FDA 21 CFR Part 11 and the ICH E6(R2) Good Clinical Practice guideline, informed consent documentation required electronic signatures with full audit trails, system validation, and participant identity verification. The network implemented AES with biometric liveness verification for the majority of participants completing remote consent. For participants requiring a legal representative's signature on a notarised consent document in states requiring notarial equivalency, QES-level certification was applied. The combined workflow reduced consent document processing time by 42% versus paper-based methods and eliminated courier costs estimated at $180,000 annually across trial sites.

A 50-person cross-border fintech startup handling SME lending agreements

A fintech lender operating across Ireland, the Netherlands, and Germany was issuing loan agreements to SME borrowers. German consumer credit law (§492 BGB) requires the written form for certain loan agreements, which under §126a BGB can be satisfied by QES but not by AES or SES. For German borrowers, the startup implemented a QES workflow using video-identification via a qualified TSP. For Irish and Dutch borrowers, where AES was legally sufficient for the same loan product, AES was deployed, reducing per-transaction signing cost by approximately 60% and onboarding time from 18 minutes to under 4 minutes. The tiered approach — AES where legally sufficient, QES where mandated — resulted in a blended per-signature cost reduction of 38% compared to a uniform QES strategy.

Conclusion

The advanced vs qualified electronic signature distinction is not merely technical — it determines legal enforceability, regulatory compliance, and operational cost across every jurisdiction you operate in. AES delivers strong, PKI-backed authentication with remote identity proofing and is legally sufficient for the vast majority of commercial and regulated-sector use cases globally. QES adds the irreducible legal presumption of a handwritten signature across the EU, but at greater cost and user friction, and is mandatory only for specific document categories defined by national or sectoral law.

The right answer is almost never one or the other universally — it is a tiered strategy that maps document risk to signature type, jurisdiction by jurisdiction. Certyneo supports both AES and QES natively, with ETSI-compliant output formats and coverage across EU Trusted List providers.

Ready to build a compliant, cost-efficient signature workflow? Talk to the Certyneo team or start your free trial today.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 free envelopes per month, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.