Go to main content
Certyneo

QES, AES and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026

The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Certyneo Legal Team14 min read

Certyneo Legal Team

Writer — Certyneo · About Certyneo

black smartphone

The eIDAS regulation (No. 910/2014) forms the cornerstone of European electronic signature law. Since its entry into force, it has structured three levels of signature — SES, AES and QES — whose technical requirements and probative value differ radically. In 2026, with the progressive entry into force of eIDAS 2.0 regulation (EU Regulation 2024/1183), these distinctions become increasingly important for any organization seeking to digitize its legal documents in full compliance. This article deciphers the fundamental differences between these three levels, the obligations they imply and the criteria to consider when choosing the right format based on the nature of your documents.

SES: the simple electronic signature, flexible but limited

Definition and technical characteristics

The simple electronic signature (SES, or Simple Electronic Signature) is defined in Article 3(10) of the eIDAS regulation as "data in electronic form which is attached to or logically associated with other electronic data and which is used by the signatory to sign". This definition is intentionally broad: a simple click on "I agree", a signature drawn by finger on a tablet, or even a checked box in an online form fall into this category.

SES requires no prior verification of the signatory's identity, nor any cryptographic certificate. Its robustness rests solely on contractual context and peripheral evidence (IP address, server timestamp, confirmation email). The electronic signature glossary lists all the technical terms associated with these mechanisms.

SES benefits from the non-discrimination principle laid down in Article 25(1) eIDAS: it cannot be rejected as evidence solely on the ground that it is electronic. However, it carries no presumption of reliability. In case of dispute, the burden of proof rests entirely with the party invoking it. The legal value of electronic signature therefore depends strongly on the level chosen.

SES is suitable for low-risk acts: acceptance of terms and conditions, internal forms, low-value online orders, or satisfaction surveys. It is unsuitable for any document likely to be contested in court.

AES: the advanced signature, balancing security and practicality

The four cumulative criteria of Article 26 eIDAS

The advanced electronic signature (AES, Advanced Electronic Signature) is defined in Article 3(11) eIDAS and must satisfy four conditions listed in Article 26:

  1. Be linked uniquely to the signatory: a unique identifier connects the signature to a determined natural person.
  2. Make it possible to identify the signatory: identity verification is carried out (email, phone number, identity document depending on the service provider).
  3. Have been created using data that the signatory can use with a high level of confidence under his or her exclusive control: typically a one-time password (OTP) sent to his or her phone or a software certificate.
  4. Be linked to the data signed in such a manner that any subsequent change in the data is detectable: the signature is based on a cryptographic hash of the document.

Technologies used and assurance levels

In practice, AES is implemented via digital certificates of substantial level (within the meaning of eIDAS regulation), multi-factor authentication mechanisms, or documentary identity solutions (identity document scan, biometric comparison). Qualified trust service providers such as Certyneo offer AES signature workflows incorporating remote identity verification, compliant with ANSSI frameworks and ETSI EN 319 401 standards.

AES offers an excellent compromise between security and user experience fluidity. It is recommended for standard commercial contracts, HR documents, partnership agreements or service contracts. Consult our comprehensive guide to electronic signature in business to deepen your understanding of professional applications.

Limitations of AES for certain acts

AES remains insufficient for authentic acts or those where the law expressly requires a qualified signature. In France, Article 1367 of the Civil Code reserves the maximum presumption of reliability to qualified signatures alone within the meaning of eIDAS. AES may be set aside by a judge if the opposing party demonstrates insufficiency in the identity verification process.

Regulatory definition and technical requirements

The qualified electronic signature (QES, Qualified Electronic Signature) is defined in Article 3(12) eIDAS as an advanced signature created by a qualified signature creation device (QSCD) and based on a qualified electronic signature certificate. These two components are inseparable.

The qualified certificate is issued by a qualified trust service provider (QTSP) registered on the national trust list (Trusted List) published by each Member State. In France, this list is administered by the ANSSI. The QTSP must have been audited and accredited according to the requirements of Annex I of eIDAS regulation and ETSI EN 319 411-2 standards.

The QSCD (qualified signature creation device) is a secure hardware or software medium — typically a smart card, a cryptographic USB token or a remote Hardware Security Module (HSM) — guaranteeing that the signatory's private key cannot be extracted or copied. QSCD requirements are detailed in Annex II of eIDAS regulation.

The irrefutable legal presumption of Article 25(2)

Article 25(2) of eIDAS regulation grants QES a legal effect equivalent to a handwritten signature in all Member States of the European Union. This presumption is automatic: unlike AES, the party producing a QES does not have to prove the reliability of the process. It is for the opposing party to rebut this presumption, which is in practice very difficult as long as the QTSP and QSCD are properly qualified.

In France, Article 1367 paragraph 2 of the Civil Code transposes this requirement into domestic law: the reliability of the electronic signature procedure is presumed until proven otherwise when the qualified eIDAS electronic signature is used. This presumption also covers document integrity.

Process for obtaining a qualified certificate

Obtaining a qualified certificate requires face-to-face identity verification or an equivalent remote process with the same level of assurance (for example, video identification compliant with EN ISO/IEC 18013 or the specifications of Implementing Regulation 2015/1502). The process involves:

  • Collection of official identity documents
  • Verification of their authenticity (forgery detection)
  • Biometric registration of the signatory
  • Certificate issuance by the QTSP after validation

This level of requirement explains why QES is reserved for high-risk acts: private agreements with high financial stakes, electronic notarial documents, public procurement, sensitive medical documents, or in sectors where sectoral regulations expressly require it. To compare the solutions available on the market, our comparison of electronic signature solutions will guide you in your choice.

Comparative table and selection criteria in 2026

Summary of structural differences

Three axes allow you to quickly distinguish the three levels:

Identity verification: none for SES, documentary or OTP for AES, face-to-face or equivalent for QES. Cryptographic support: non-existent for SES, software certificate for AES, certified QSCD for QES. Legal presumption: absent for SES, partial for AES, total and automatic for QES.

In terms of user friction, the equation is reversed: SES is almost transparent, AES requires a few minutes of verification, QES assumes a prior registration process that may take from a few minutes (video identification) to a few days.

Impact of eIDAS 2.0 on these distinctions in 2026

eIDAS 2.0 regulation (EU 2024/1183), whose implementing acts have been progressively published since 2024, strengthens several key points. It introduces the European Digital Identity Wallet (EUDI Wallet), which will eventually allow European citizens to store their qualified certificate directly in their smartphone, significantly reducing the friction associated with QES. It also clarifies the requirements applicable to QTSPs and strengthens the governance of national trust lists.

Furthermore, eIDAS 2.0 extends the scope of mutual recognition of qualified signatures between Member States, which is particularly significant for enterprises operating in several EU countries. The comprehensive guide to eIDAS 2.0 regulation details all these regulatory developments. Finally, the question of qualified electronic time-stamping — complementary to QES to preserve the probative value of documents over time — also deserves attention when designing your document architecture.

The hierarchy of electronic signatures rests on a dense regulatory corpus, articulating European law and French domestic law.

eIDAS Regulation No. 910/2014: this foundational text defines at Articles 3(10), 3(11) and 3(12) the three levels of signature. Article 25 establishes the principle of non-discrimination (§1) and the presumption of equivalence to handwritten signature for QES (§2). Article 26 lists the four cumulative conditions for an advanced signature. Annexes I and II specify respectively the requirements applicable to qualified certificates and to qualified signature creation devices (QSCD).

eIDAS 2.0 Regulation — EU 2024/1183: entered into force on 20 May 2024, it substantially amends the 2014 regulation, notably through the introduction of the European Digital Identity Wallet (EUDI Wallet), the extension of qualified trust services and the strengthening of QTSP governance. Implementing acts continue to be published in 2026.

French Civil Code, Articles 1366 and 1367: Article 1366 recognizes electronic writing as evidence on the same footing as paper writing, provided that the person from whom it originates can be duly identified and that it is established and preserved under conditions such as to guarantee its integrity. Article 1367 paragraph 2 establishes the presumption of reliability for qualified eIDAS signature, in direct transposition of Article 25(2) of the regulation.

Decree No. 2017-1416 of 28 September 2017: clarifies in French law the conditions allowing to benefit from the presumption of reliability, explicitly referring to the requirements of eIDAS regulation for qualified signatures.

ETSI standards: ETSI EN 319 102-1 standards (signature creation and validation procedures), ETSI EN 319 132 (XAdES format), ETSI EN 319 122 (CAdES format) and ETSI EN 319 142 (PAdES format) technically frame the creation of compliant electronic signatures. Qualified providers must implement these formats to ensure European interoperability.

GDPR — EU Regulation 2016/679: the collection of biometric data in the context of identity verification for the issuance of qualified certificates constitutes processing of special category data within the meaning of Article 9. The QTSP must have an explicit legal basis, inform individuals and implement appropriate technical safeguards. An impact assessment (DPIA) is generally required.

NIS2 Directive — EU 2022/2555: applicable to operators of essential services and digital service providers, it imposes strengthened cybersecurity requirements that apply indirectly to QTSPs operating critical electronic signature infrastructure.

Organizations that deploy electronic signature solutions without respecting the level required by the legal nature of the act expose themselves to nullity or opposability risks of the signed documents, as well as litigation risks that may result in significant financial harm.

Use cases: choosing the right level according to context

Case 1 — Industrial SME managing hundreds of supplier orders

An industrial SME processing about 400 purchase orders and supplier contracts per year has deployed AES for all its standard commercial documents. The signature workflow relies on verification via secure email link and SMS one-time password, with generation of a timestamped audit report for each act. The average signature time has decreased from 4.5 days (registered mail) to less than 3 hours. The rate of contractual disputes remained zero over 18 months of operation, with the audit trail providing sufficient evidence in case of commercial disagreement. The reduction in printing, postage and document management costs reaches approximately 60% according to internal estimates, consistent with ranges published by European sector studies (Billentis Report, 2025).

Case 2 — Law firm specializing in business law

A law firm specializing in business matters with about fifteen associates has implemented a two-level infrastructure: AES signature for internal correspondence, representation mandates and fee agreements; QES signature for high-stakes private agreements (sale of partnership interests, settlement protocols, financial guarantees). Obtaining qualified certificates for partners was achieved through a video identification session compliant with eIDAS, without physical travel, in less than 20 minutes per person. The legal presumption attached to QES allows the firm to present its acts before any European court without having to prove the reliability of the process, significantly reducing procedural risk.

Case 3 — Hospital group digitizing its HR and medical acts

A hospital group of approximately 1,200 beds has chosen a differentiated approach depending on the nature of the documents. Employment contracts, amendments and job descriptions are signed in AES, allowing the 800 agents concerned to sign from their smartphone without heavy infrastructure. For specific medical agreements and documents requiring strong authentication imposed by health regulations (HDS), QES is deployed for designated signatory practitioners. This hybrid model reduces by 75% the time needed to compile HR files during recruitment, a gain that is particularly critical during periods of pressure on medical resources. It also ensures compliance with CNIL obligations relating to health data processing.

Frequently asked questions

What is the main difference between QES and AES in eIDAS?

The fundamental difference lies in two elements: the certificate and the signature device. QES is necessarily based on a qualified certificate issued by an accredited provider (QTSP) and on a qualified signature creation device (QSCD) that is physically secure. AES may use a software certificate and less strict identity verification. Direct consequence: QES benefits from a legal presumption of equivalence to a handwritten signature throughout the European Union, which AES does not automatically guarantee.

In which cases is it mandatory to use a QES signature?

No European text mandates QES in general, but several sectoral or national regulations require it implicitly or explicitly. This is the case for certain electronic authentic acts, specific public procurement, digitized notarial acts, or in regulated sectors such as banking (PSD2, enhanced KYC) or health. The general rule is as follows: the higher the legal or financial stakes of the act, the more recourse to QES is recommended to eliminate any risk of contestation.

Yes, SES signature is legally admissible in France under the non-discrimination principle laid down in Article 25(1) of eIDAS regulation and Article 1366 of the Civil Code. It cannot be set aside as evidence solely on the ground that it is electronic. However, it carries no presumption of reliability: in case of dispute, the party invoking it must prove its robustness by other means (logs, IP address, audit trail). Its use should therefore be reserved for low-risk acts.

Is a qualified certificate obtained in France recognized throughout the European Union?

Yes. Article 25(2) of eIDAS regulation and the mechanism for mutual recognition of national trust lists (Trusted Lists) guarantee that a qualified certificate issued by a QTSP accredited in France is recognized in all Member States of the European Union with the same legal effect. eIDAS 2.0 (EU 2024/1183) further reinforces this principle by extending recognition to new qualified trust services introduced by the revised regulation.

How can you verify that a signature service provider is properly qualified eIDAS?

Each Member State publishes and maintains an official trust list (Trusted List) listing all qualified trust service providers (QTSP) accredited in its territory. In France, this list is published and updated by ANSSI on its official website. The European Commission aggregates all national lists on the EU Trusted List Browser portal (tlbrowser.tsl.europa.eu). Verify that a provider is listed there before entrusting it with the issuance of qualified certificates or the creation of QES signatures.

Conclusion

The three levels of electronic signature defined by eIDAS regulation — SES, AES and QES — respond to fundamentally different legal and operational needs. SES is suitable for low-stakes acts, AES covers the majority of standard professional contracts with an excellent balance between security and fluidity, while QES is necessary for high-value legal acts thanks to its legal presumption of equivalence to handwritten signature throughout the European Union. In 2026, with the progressive entry into force of eIDAS 2.0, mastering these distinctions is more strategic than ever for any organization digitizing its document processes.

Certyneo enables you to deploy all three signature levels according to your real needs, with a unified interface compliant with eIDAS and ANSSI requirements. Discover our offers or estimate your gains right now using our electronic signature ROI calculator, or contact our team for a personalized audit of your document workflows.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 free envelopes per month, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.