What Makes a Digital Signature Legally Valid?
Three things stacked in the right order under eIDAS Article 25: non-discrimination in principle for any electronic signature, equivalence to a handwritten signature only for Qualified Electronic Signatures under Article 25(2), and successful validation under the Article 32 procedure. The gap that costs cases in court is between 'the signature exists' and 'the signature validates against Article 32 requirements' — and the identity-proofing under the signing certificate is where most legal-validity claims quietly break.
Three things stacked in the right order under eIDAS Article 25: non-discrimination in principle for any electronic signature, equivalence to a handwritten signature only for Qualified Electronic Signatures under Article 25(2), and successful validation under the Article 32 procedure. The gap that costs cases in court is between "the signature exists" and "the signature validates against Article 32 requirements" — and the identity-proofing under the signing certificate is where most legal-validity claims quietly break.
The distinction between technically valid and legally valid landed on a Rotterdam-based container-terminal operator's general counsel the week after her carrier's opposing party produced a digitally signed haulage authorisation that met every technical spec in the vendor manual — cryptographically valid, verifiable public key, certificate in date. The court accepted the signature as admissible evidence of intent under Article 25's non-discrimination principle. It rejected the identity claim on grounds that the proofing supporting the certificate did not meet the assurance level the counterparty's counsel argued for on the record. The signature was legally valid in principle. It failed at the proof the court expected. This post is that gap.
What does eIDAS actually mean by "legal validity"?
Not a single concept but three layered ones, and mixing them is where most operational confusion happens.
The first is the admissibility principle under Article 25(1) of eIDAS (Regulation (EU) 910/2014): "an electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures." This is the non-discrimination rule. A court cannot throw a signature out for being digital. Any electronic signature — even a typed name at the bottom of an email — has to be admitted as evidence and evaluated on its merits. The bar for admissibility is intentionally low.
The second is the equivalence principle under Article 25(2): "a qualified electronic signature shall have the equivalent legal effect of a handwritten signature." This applies only to QES — signatures produced under a Qualified Trust Service Provider's qualified certificate stored on a Qualified Signature Creation Device (QSCD). Under Article 25(2), the burden shifts: a QES is treated as if it were a wet-ink signature, and the party challenging it has to prove otherwise. For Advanced Electronic Signatures (AdES) and Simple Electronic Signatures (SES), no automatic equivalence applies. The court weighs the signature's evidentiary weight against the risk of the transaction, the retention of proofing evidence, and the practical question of whether the signature can be independently verified against a defensible chain.
The third is the validation procedure under Article 32 and ETSI EN 319 102-1. A signature that is admissible in principle and equivalent under Article 25(2) still has to pass the technical validation the regulation defines — which is the five-stage procedure we walked through in our earlier post on verifying signature authenticity. Passing validation is what turns admissibility and equivalence from doctrinal principles into a specific evidentiary weight in a specific case. Failing validation is the point at which legal validity, in the operational sense, breaks.
What I see at the intersection of eIDAS and litigation practice is that lawyers and engineers use "legally valid" to mean different things. The lawyer means: admissible under Article 25(1), possibly equivalent under 25(2), evidentiary weight sufficient to carry the case. The engineer means: the cryptographic operation succeeds and the certificate resolves. The two meanings intersect but do not coincide, and every audit finding I have watched turn into a court proceeding hinges on the gap.
Where does non-discrimination end and full-effect equivalence begin?
At the boundary between AdES and QES — and the practical answer depends on which one your risk profile actually needs.
Under Article 25(1) any electronic signature is admissible. That does not mean any electronic signature carries meaningful evidentiary weight. A checkbox on a click-through terms-of-service page is technically an SES. It is admissible. It is also comparatively weak evidence of consent to a specific clause — a court will admit it but weigh it against the transaction's risk, the user's ability to understand the terms, and the retention of the click record. Non-discrimination is a floor, not a ceiling. What sits above the floor is the practical question of whether the signature can carry the weight the transaction requires.
Article 25(2) sets the ceiling. A Qualified Electronic Signature — produced under a qualified certificate issued by a Qualified Trust Service Provider on the EU Trusted List, using a Qualified Signature Creation Device — is treated as legally equivalent to a wet-ink signature. The presumption runs in the signer's favour: unless the party challenging the signature can prove it was not produced by the signer or was applied under duress, the signature stands. That presumption is why QES is the choice for high-stakes contracting — real estate transactions in certain Member States, notarial acts, corporate resolutions, cross-border wills. QES carries the weight because the identity-proofing behind it is defined, audited, and documented by a QTSP under ETSI EN 319 411-1 requirements.
The Advanced Electronic Signature space between admissibility and full equivalence is where most commercial contracting lives — and where most operational disputes about legal validity actually happen. An AdES under Article 26 requires the signature to be uniquely linked to the signatory, capable of identifying the signatory, produced under the signatory's sole control, and detectable of subsequent changes to the signed data. Those four requirements produce a signature that is admissible under Article 25(1) and evidentially stronger than SES, but does not carry Article 25(2)'s automatic equivalence. Evidentiary weight depends on the proofing supporting the certificate, the retention of validation data, and the specific facts of the dispute.
Honestly, if you sit inside a compliance team, the practical framing is: AdES is what you use for cross-border commercial contracting where evidentiary weight matters; QES is what you use for the small number of transactions where the law of a specific Member State requires the wet-ink equivalence explicitly. Getting the mapping wrong — using SES where AdES would carry the weight, or using AdES where the transaction actually needs QES under Member State law — is the pattern that costs enforcement actions and litigation outcomes.
What actually breaks legal validity in an audit or court case?
Almost never the cryptographic primitive. Almost always the layer under the certificate — the identity-proofing, its retention, and its resolvability at the moment the challenge lands.
The pattern I see across audit findings and litigation reports in 2025 and 2026 is remarkably consistent. The signature validates cryptographically — the hash matches, the certificate resolves, the algorithm is acceptable at signing time, the revocation status is clean. The failure appears at Article 32's validation report where the outcome is INDETERMINATE rather than TOTAL_PASSED, and the specific reason lands at the identity chain. The court or auditor does not need to reject the signature outright; they need to note the identity link is not established at the assurance level the transaction required, and the signature no longer carries the evidentiary weight the party relying on it needs.
Concretely, the ways I see legal validity break in cross-border commercial contracting:
Identity-proofing evidence is not retained. The signing platform produced the signature and the certificate, but no record of what proofing event the CA relied on before issuing the certificate has been retained by either party. The signature is admissible under Article 25(1); it is not evidentially strong because the identity binding cannot be walked back to a specific proofing event with retained evidence. The party who relied on the signature carries the burden of demonstrating identity, and cannot.
Certificate has expired and revocation status is no longer retrievable. Under Article 32(1) of eIDAS and ETSI EN 319 102-1 stages 3-4, the validation procedure requires establishing the certificate's status at the signing moment. A signature made in 2022 with a certificate that expired in 2024, verified in 2026, produces INDETERMINATE at stage 3 if the CA's revocation records for the pre-expiry period are no longer online. The signature is not invalid; it is not verifiable. The court treats it as evidence with degraded weight.
Time of signing cannot be established. The claimed signing time in the signature is the signer's clock, which is not authoritative. A Qualified Timestamp from a QTSP would anchor the moment cryptographically; a self-signed timestamp does not. Under Article 32 stage 5, if the signing time cannot be anchored, the signature is verifiable but the time assertion is weak — and the specific dispute about when the signature was made becomes evidentially decisive in cases where sequence matters (competing claims, deadline compliance, retrospective consent).
Algorithm policy at signing time was inadequate. Under ETSI TS 119 312, the cryptographic suites acceptable for AdES evolve. A signature produced in 2016 with SHA-1 was acceptable then; it is not now. A dispute in 2026 over a 2016 SHA-1 signature will pass mathematical validation but fail Article 32 stage 4 policy check — and the signature's evidentiary weight is discounted by the algorithm's since-established weakness.
Retention gap between signature and proofing evidence. Even when both signature and proofing were properly executed, if the two records are held by different parties without a cryptographic binding between them, a court reconstructing the chain at month 48 has to trust each party's record separately. That trust is thinner than a single wrapped evidence record. Under PAdES-LTA / XAdES-A / CAdES-LTA long-term archival profiles, the wrapper is designed to hold both together — and where the wrapper is missing or discontinued, evidentiary weight quietly degrades.
Where I disagree with the loud vendor position is the framing that "AdES gives you legally valid signatures". It gives you signatures admissible under Article 25(1) with potential evidentiary weight above SES. Whether they carry that weight in a specific court or audit turns on the identity-proofing chain, the retention, and the completeness of Article 32 validation at the moment the challenge lands. The vendor sells the signature; the identity-proofing primitive is what actually carries the case.
Where does identity-proofing sit in the validity chain?
At the foundation — the layer that makes every stage above it defensible or fragile. Get it right and admissibility, equivalence, and validation land where the regulation intends. Get it wrong and each stage above degrades quietly.
This is where the global-digital-identity question becomes a legal-validity question. A signing certificate issued to a signer whose identity was proofed through a chip-anchored event under ICAO 9303 — passport NFC chip read against the ICAO Public Key Directory, combined with biometric face match to bind the document to the presenter — produces evidence that is defensible at NIST SP 800-63-4 IAL2 or higher. The proofing event is a specific, retained record. It binds the certificate's subject to a person the CA has actually verified against a state-issued document with cryptographic integrity of its own. That is the identity anchor a court can trace and an auditor can validate.
For the 179 ICAO 9303 countries, the chip-read primitive gives the strongest evidentiary anchor available today. For the small remaining set of countries — those whose documents do not carry a chip — the document authenticity verification combined with biometric face match under a NIST IBPC-tested liveness algorithm produces the equivalent IAL2 evidence chain. Both paths produce global identity coverage: the same primitive works for a Nigerian founder onboarding into a Frankfurt fintech and for a Filipino contractor signing a services agreement with a Warsaw manufacturer. That is the layer we ship at IdentiGate through the Identity Verification product, producing an AdES-bound proofing record under eIDAS Article 26 that the Signatures product uses to produce signatures whose identity binding is verifiable back to the proofing event.
The Evidence Layer product is where the pieces stay together for the long term. A signature at month one and a signature at month forty-eight are the same cryptographic object; the difference is whether the wrapper around the signature — the certificate chain, the revocation records at signing time, the algorithm policy reference, the proofing event evidence, the Qualified Timestamp if the AdES profile calls for one — is still retrievable in a form the verifier can read. That retention layer is what turns a signature from "we have the file" into "we have the evidence that survives the dispute at month 48."
The way I usually walk through this with a customer's counsel is by pointing at the specific breakdown pattern in cases where the signing chain collapsed. It is almost never the signature or the certificate as an object. It is one of three things: the proofing event was not retained in a form the party could produce at the point of challenge; the certificate's validation data was not retrievable at the moment the audit ran; or the two records were held separately and could not be independently walked back to a single moment. Fix those three and legal validity becomes a defensible operational property rather than a claim the vendor makes on the box.
Sources
Primary — eIDAS and signature framework
- Regulation (EU) 910/2014 — eIDAS (original) — EUR-Lex
- Regulation (EU) 2024/1183 — eIDAS 2.0 — EUR-Lex
- EU Trusted List (LOTL) browser
- Commission Implementing Decision (EU) 2015/1505 — Trusted Lists format
Primary — ETSI signature and TSP standards
- ETSI EN 319 102-1 — Procedures for AdES creation and validation
- ETSI EN 319 411-1 — TSP policy and security requirements
- ETSI EN 319 421 — QTSP time-stamp requirements
- ETSI TS 119 312 — Cryptographic suites
Primary — international electronic signature frameworks
Primary — identity assurance and document standards
- NIST SP 800-63-4 (May 2025 draft) — Digital Identity Guidelines
- ICAO Doc 9303 — Machine Readable Travel Documents
- ICAO Public Key Directory (PKD)
About the author
Mairi Kutberg is co-founder of IdentiGate. She focuses on identity-proofing operations under eIDAS, NIS2, AMLR, the AI Act, the EHDS, and adjacent regulatory frameworks, and on the institutional reality of running cross-border identity verification at scale.