What Happens if Someone Denies They Signed Digitally?
The signature carries the burden of proof — but the burden falls back on whoever relied on it if the evidence chain behind the signature isn't complete. Under eIDAS Article 25(2), Qualified Electronic Signatures presume authenticity unless the challenger rebuts it. For Advanced signatures, the party asserting the signature has to demonstrate identity binding, integrity, and time — and courts have been consistent since 2020 that thin proofing evidence loses the case.
The signature carries the burden of proof — but the burden falls back on whoever relied on it if the evidence chain behind the signature isn't complete. Under eIDAS Article 25(2), Qualified Electronic Signatures presume authenticity unless the challenger rebuts it. For Advanced signatures, the party asserting the signature has to demonstrate identity binding, integrity, and time — and courts have been consistent since 2020 that thin proofing evidence loses the case.
An Antwerp-based commodity trader's compliance director called us in April with the outline of a dispute that had been running for six months. A supplier had signed a €4.2 million forward-purchase agreement digitally, the shipment had been executed, the invoice raised, the payment period elapsed — and then the supplier had denied signing, claiming the signature on file was fraudulent. The trader's platform had produced a valid AdES signature at the time. The certificate was in order. The cryptographic chain resolved cleanly. What was in dispute was not the signature; it was whether the signer's identity had actually been established before the signing operation. The commodity trader's counsel had walked into court expecting the signature to speak for itself. It did not. The audit finding underneath the case was that the signing platform's proofing evidence — what the platform had captured about who signed — was too thin to survive challenge. That gap is what this post walks through.
What does "non-repudiation" actually mean in digital-signature law?
The property that a signer cannot later deny having signed a specific document — but the property is a legal outcome of an evidentiary chain, not a technical claim the signature makes by itself.
In cryptography, non-repudiation is often described as a property that follows from the mathematics: only the holder of the private key can produce a signature that verifies against the corresponding public key, so if the signature verifies, the key holder must have signed. That framing is correct at the algorithmic layer and misleading everywhere else. The legal system does not stop at the cryptographic operation. Under Article 25(1) of eIDAS (Regulation (EU) 910/2014), any electronic signature is admissible as evidence. Under Article 25(2), a Qualified Electronic Signature has the equivalent legal effect of a handwritten signature, which shifts the burden of proof: unless the party denying the signature can prove they did not sign — through evidence of key compromise, coercion, or that the key was not in their possession — the QES stands. For Advanced Electronic Signatures under Article 26, no automatic presumption applies. The party relying on the signature carries the burden of proving the identity binding was properly established.
The UNCITRAL Model Law on Electronic Signatures (2001) frames this in more general terms as "reliability" — a signature is considered reliable if it was uniquely linked to the signer, capable of identifying the signer, produced under the signer's sole control, and any subsequent alteration would be detectable. These are the same four conditions eIDAS Article 26 codifies for AdES. The Model Law and eIDAS agree that non-repudiation is not a property of the signature standing alone; it is a property of the evidentiary chain that stands behind the signature.
What I see at the intersection of eIDAS practice and litigation across 2025 and 2026 is that non-repudiation claims fail not because the mathematics is wrong but because the chain is incomplete. The signature verifies. The certificate resolves. The audit finding lands on the identity-proofing event under the certificate — because that is where the challenge actually lands when someone denies signing. "The key holder signed" is a mathematical statement. "The person the certificate names is the person who held the key" is a legal statement, and it depends entirely on how the CA proofed identity before issuing the certificate and how that proofing evidence is retained.
How does an audit walk backward from a denial claim?
In a specific order — from the disputed signature, to the certificate, to the identity-proofing event, to the retained evidence — and the claim breaks at whichever step lacks retrievable evidence.
The reconstruction usually starts at the moment the challenge lands. A denial claim is filed. The party asserting the signature produces the signed document, the signature, the certificate. The ETSI EN 319 102-1 validation procedure is run. Stages 1-4 check the mathematics, the certificate chain, revocation status at signing time, and algorithm policy. If any fails, the signature does not survive the challenge on technical grounds and the audit does not need to go deeper. This is the small minority of cases. The larger majority — the ones that produce the operationally difficult findings — pass every technical stage.
At stage 5 the audit needs the signing-time evidence, and this is where the reconstruction depends on retention. The signing time itself has to be established — a claimed time in the signature is weak evidence; a Qualified Timestamp from a QTSP is strong. If the AdES record was wrapped in a PAdES-LTA / XAdES-A / CAdES-LTA long-term validation profile at signing time, the wrapper contains the timestamp, the revocation data captured at signing time, and the certificate chain in a form the audit can walk. If the record was not wrapped, the audit has to reconstruct each piece from CA archives that may or may not still be online.
Beyond signing time, the audit walks back to the certificate issuance event. This is the ETSI EN 319 411-1 territory: what evidence did the Trust Service Provider retain of the identity-proofing event that preceded certificate issuance? For a Qualified Trust Service Provider, eIDAS Article 24 requires the retention of that evidence and specifies acceptable proofing methods — physical presence, notified eID schemes at substantial or high assurance, previous qualified certificates, or equivalent means. For a non-qualified CA, the proofing evidence may be self-declared name plus SMS OTP, and there may not be a retained record of even that. The audit's ability to walk further backward from the certificate depends entirely on what the CA retained and can produce on demand.
At the deepest layer the audit reaches the specific proofing event: what document was verified, what biometric was checked, what liveness signal was captured, what evidence was retained in a form that binds the document-to-person link. If the proofing was chip-anchored — a passport NFC read against the ICAO Public Key Directory combined with a NIST-tested biometric face match — the evidence is a specific cryptographic record produced at a specific moment, retrievable and independently verifiable. If the proofing was self-declared, the evidence is a form submission and an SMS log, retrievable only from the CA's records, and independently verifiable only if the CA cooperates. The audit's finding depends on which pattern applies to the specific signature under challenge.
Where do most non-repudiation claims actually break in court?
At the identity-proofing evidence layer — almost always. The other layers usually hold; the identity binding is where the case is decided.
The pattern I see across cross-border commercial disputes in 2025 and 2026 is remarkably consistent. In roughly nine out of ten cases where a denial claim is raised against a digital signature and the case is contested through to substantive hearing, the technical validation passes and the court's decision turns on identity-proofing evidence. The specific breaks fall into four categories.
The proofing was self-declared. The signing platform issued a certificate to a signer who provided a name, an email, and confirmed an SMS OTP. There is no retained evidence that ties the certificate's subject to a person whose identity was actually verified against an authoritative document. The signature verifies; the identity claim behind it does not stand up to challenge; the party asserting the signature loses the case because they cannot demonstrate the identity binding.
The proofing evidence exists but was not retained. The signing platform captured proofing at the moment of certificate issuance — a photograph of an ID document, a selfie, a liveness capture — but did not retain it in a form that the audit can retrieve at month twelve, twenty-four, or forty-eight when the challenge lands. The evidence existed once. It does not exist now. The party asserting the signature is in the same position as if proofing never happened.
The proofing was retained but by a party who has since ceased operations. The signing certificate was issued by a CA that has been acquired, wound down, or removed from the EU Trusted List between signing time and challenge time. The proofing evidence lives in the successor entity's archives, or in an insolvency estate, or in an offline backup that would require months to retrieve. The court's practical reality is that evidence that cannot be produced in the timeframe of the proceedings does not exist for evidentiary purposes.
The proofing was retained but is not independently verifiable. The CA can produce the proofing record, but the record itself is a photograph plus an operator's attestation, not a cryptographically anchored artefact. The court accepts the CA's assertion at face value if the CA is credible; the assertion is discounted heavily if the CA has any commercial relationship with the party asserting the signature. What survives challenge is proofing evidence that is independent of any commercial party's assertion — a chip-anchored proofing record verifiable against the ICAO Public Key Directory is such an artefact; an operator-attested photograph is not.
Honestly, the pattern is that the disputes are decided at the identity-proofing layer, not at the signature layer. Vendors sell signature validity; courts weigh identity-proofing evidence. A Frankfurt-based freight-forwarding platform we advised in 2025 restructured their entire signing chain after a €2.8 million dispute turned on exactly this pattern — the signature was fine, the identity-proofing evidence was too thin to demonstrate the signer was who the platform said they were, and the platform's insurance carrier picked up the loss. Their rebuild put chip-anchored proofing at the foundation and retained the evidence alongside every certificate issued through the platform. When the same insurance carrier reviewed their signing chain a year later, the premium came down.
What does a defensible non-repudiation chain look like in 2026?
A signing event where each layer produces its own evidence and the evidence is retained together — proofing, certificate, signature, validation data, timestamp — in a form that a verifier reconstructs at month forty-eight without needing to trust any commercial party's assertion.
The layer that carries the most weight in the reconstruction is the identity proofing at the foundation. If the proofing event is a chip-anchored primitive under ICAO 9303 — passport NFC chip read against the Public Key Directory combined with a biometric face match against a NIST-tested liveness algorithm — the evidence is a specific cryptographic record produced at the signing platform, retrievable and independently verifiable against the ICAO trust framework that no single commercial party controls. That artefact stands alone. It does not require the CA to be still operating; it does not require the signing platform to cooperate; it does not require the verifier to trust the party asserting the signature. What our earlier post on proof of identity in digital signatures framed at the tier level is the same primitive here at the non-repudiation level.
For the 179 ICAO 9303 countries, the chip-read primitive is what produces the strongest evidentiary record available today. For countries whose documents do not carry a chip, the equivalent path is document authenticity verification combined with biometric face match under a NIST IBPC-tested liveness algorithm. Both produce a globally verifiable proofing event: the same primitive verifies a Bangladeshi trader signing an eCMR consignment in Rotterdam and a Turkish contractor signing a services agreement with a Barcelona buyer. That global coverage is what defends non-repudiation in the cross-border commercial disputes that dominate the litigation caseload.
At IdentiGate we ship this specifically. The Identity Verification product produces the chip-anchored proofing record, AdES-bound under eIDAS Article 26, retained with cryptographic integrity independent of any subsequent commercial event. The Signatures product produces the AdES signature whose identity binding traces back to that proofing event. The Evidence Layer product is the layer that keeps proofing, certificate, signature, and validation data together in a form that survives the challenge at month forty-eight — the retention layer whose absence is precisely what breaks non-repudiation claims in the cases I described above.
What I'd push back on hardest in the vendor pitch is the framing that "AdES signatures are non-repudiable". The signature is verifiable. The identity binding underneath it may or may not be defensible at challenge. The gap between those two properties is not a rounding error; it is where cases are decided and where the losses actually accumulate. Non-repudiation is a property of the whole chain, and the chain is only as strong as the identity-proofing primitive at its foundation. Get that right and the denial claim does not survive the audit walk-back. Get it wrong and the challenge is upheld regardless of how mathematically clean the signature was.
Sources
Primary — eIDAS and signature framework
- Regulation (EU) 910/2014 — eIDAS (original) — EUR-Lex
- Regulation (EU) 2024/1183 — eIDAS 2.0 — EUR-Lex
- EU Trusted List (LOTL) browser
Primary — ETSI signature and TSP standards
- ETSI EN 319 102-1 — AdES creation and validation procedures
- ETSI EN 319 122 — CAdES
- ETSI EN 319 132 — XAdES
- ETSI EN 319 142 — PAdES
- ETSI EN 319 411-1 — TSP policy and security requirements
- ETSI EN 319 421 — QTSP time-stamp requirements
Primary — international electronic signature framework
Primary — identity assurance and document standards
- NIST SP 800-63-4 (May 2025 draft) — Digital Identity Guidelines
- ICAO Doc 9303 — Machine Readable Travel Documents
- ICAO Public Key Directory (PKD)
About the author
Mairi Kutberg is co-founder of IdentiGate. She focuses on identity-proofing operations under eIDAS, NIS2, AMLR, the AI Act, the EHDS, and adjacent regulatory frameworks, and on the institutional reality of running cross-border identity verification at scale.