Electronic signatures explained: the three eIDAS tiers (SES, AES, QES), what each one looks like with examples, their legal effect, security, and how signing works in practice.
An electronic signature is a digital way to sign a document that is legally binding, fast, and — with the right method — more tamper-evident than ink on paper. This guide explains what an electronic signature is, the three types defined by EU law, what each one actually looks like, whether they hold up in court, and how the signing process works in practice.
In practice: With top.legal's electronic signature you sign contracts in an eIDAS-compliant way, directly inside your contract workflow — from drafting to an audit-proof close. Want the business case? See the top advantages of digital signatures.
What is an electronic signature?
An electronic signature is the digital version of a signature. EU law (the eIDAS Regulation) defines three tiers: simple (SES) for informal agreements, advanced (AES) with proof of identity, and qualified (QES) — the legal equivalent of a handwritten signature for documents that legally require written form.
An electronic signature is a digital version of a signature, used to confirm the authenticity and integrity of a document. With electronic signatures, digital documents such as contracts or approvals can be signed in a legally binding way.
Unless the law excludes it from the outset, an electronic signature can replace a signature on paper: it unambiguously links the signatory to a defined, tamper-evidently stored document or string of characters. That electronic information is usually a document, but any sequence of characters can be signed electronically.
Electronic signature vs. digital signature
The terms digital signature and electronic signature are often used interchangeably, but they are not the same thing. A digital signature is a class of cryptographic methods (the same technology also used to encrypt network connections). An electronic signature is primarily a legal term, coined by the EU Commission and deliberately defined broadly — so that it covers not only signing procedures based on digital signatures but also other methods. Put simply: the electronic signature is the legal concept; the digital signature is one of the technologies that can make it secure.
What types of electronic signatures are there?
Three tiers under eIDAS: the simple electronic signature (SES) for informal contracts, the advanced electronic signature (AES) with proof of identity for higher evidential value, and the qualified electronic signature (QES) as a written-form substitute for documents that legally require it.
There are basically three types:
The table below summarises the three signature types:
| Signature type | Security | Example | Typical use |
|---|---|---|---|
| Simple (SES) | low | e-mail with a typed name, scanned signature, clicking "I agree" | informal arrangements, internal approvals |
| Advanced (AES) | high | a platform-signed PDF with SMS verification (e.g. top.legal) | contracts, quotes, NDAs, employment contracts |
| Qualified (QES) | very high | signature with a qualified certificate and video identification | documents that require written form (terminations, guarantees) |
What does an electronic signature look like? Examples
An electronic signature is not necessarily an image of a handwritten signature — what matters is the electronic consent, not the appearance. Depending on the type, it can look quite different:
- Simple electronic signature (example): an e-mail that ends with the sender's name, a scanned signature image in a PDF, or a click on "I agree" or a tick-box in an online form.
- Advanced electronic signature (example): a PDF signed through a platform, where the signatory's identity is confirmed (for instance by SMS code or an eID) and a digital certificate is attached. You typically see a signature field with a name, date, and verification information.
- Qualified electronic signature (example): a signature with a qualified certificate from a trust service provider, often including a timestamp and a signature seal embedded in the PDF that can be checked in a PDF reader.
In every case: what makes a signature legally valid is not its visual appearance but the provable consent and — for AES and QES — the technical link between the signatory and the document.
What is the legal effect of electronic signatures?
According to the Official Journal of the European Union of 28 August 2014 (Art. 25(1) of the eIDAS Regulation), an electronic signature may not be denied legal effect or admissibility as evidence in court proceedings solely because it is in electronic form or because it does not meet the requirements for qualified electronic signatures.
A qualified electronic signature has the same legal effect as a handwritten signature. A QES based on a qualified certificate issued in one Member State is recognised as a QES in all other Member States. Documents signed "only" with an advanced electronic signature under Art. 3(11) of the eIDAS Regulation can still be submitted as evidence in court.
What must a legally valid electronic signature meet?
In most circumstances, electronic signatures carry the same legal force as conventional ones. To be legally recognised, however, they should meet a few requirements. Legally binding electronic signatures should generally:
- prove the signatory's identity – demonstrate that the signatory really is the person they claim to be.
- make the intent to sign clear – show that the signatory consciously intended to sign electronically.
- offer the option to decline – for example through a "Cancel" button or another way to refuse the signature.
- allow independent verification – often via IP address, timestamp, mobile number, and an email trail. Two-step identification is useful here too.
By meeting these requirements, electronic signatures serve as a legally binding alternative to cumbersome paper processes for obtaining consent.
How the signatures differ in practice
Electronic signatures differ mainly in how well they protect against forgery. At the bottom of the scale is the simple electronic signature, which does little to ensure the authenticity of the signature.
At the top — with the highest protection against forgery — is the qualified electronic signature, which uses encryption certificates from a trust service to confirm that the signing party really is who they claim to be. This usually requires extensive identity verification with the trust authority via a video-identification process. It is less suited to fast-moving business use, as it puts hurdles in front of the signer that are hard to clear quickly.
The middle ground is the advanced electronic signature. Under Art. 26, an advanced electronic signature must meet all of the following:
- It is uniquely linked to the signatory.
- It is capable of identifying the signatory.
- It is created using electronic signature creation data that the signatory can, with a high level of confidence, use under their sole control.
- It is linked to the signed data in such a way that any subsequent change to the data is detectable.
In practice, this means a signed document must be encrypted with a key under the signatory's sole control. Only then can the recipient be sure the document comes from the person it claims to and that the data was not manipulated in transit. Two-factor authentication (2FA) — for example via a mobile phone — is an additional way to meet this requirement.
Advanced vs. simple electronic signature
Signing with an advanced electronic signature usually requires specialised software. Simple electronic signatures need none: it is generally enough to send an e-mail with your name, add a scanned signature to a document, or scan a signed document and email it. The advanced signature uses encryption so that the public key can establish who signed and whether the signature is valid — something a simple electronic signature cannot guarantee for either authenticity or the document's integrity.
Advanced vs. qualified signature
Within the EU, the advanced signature offers legal validity similar to a handwritten signature, unless the law explicitly requires a conventional handwritten one. Like the advanced signature, the qualified electronic signature also requires specialised software; in addition, physical encryption tokens such as a USB stick or a chip card are used to raise the level of security.
What are the benefits of electronic signatures?
The main advantage of an electronic signature is that a signer can sign documents quickly and easily, without the slow, cumbersome routine of printing, signing, and scanning. This saves time and money.
Our data shows that contract processing on an electronic basis is up to 9 times faster than a paper-based system. We also see higher completion rates in closing contracts, as the simplicity of the system reduces the chance of drop-off.
Are electronic signatures secure?
Yes. Advanced and qualified electronic signatures are tamper-evident thanks to cryptographic methods, timestamps, and identity verification. The simple electronic signature (SES) is low-barrier and fine for informal contracts, but not for documents that legally require written form.
In principle, any signature — electronic or on paper — can be forged. But the electronic signature has clear advantages against manipulation. Unlike checking a signature or an ID card, it gives even a layperson every tool needed to establish beyond doubt whether the signed document was manipulated and whether the signature really came from the person in question.
With current technology, it is easier to fake a handwritten signature than to defeat the encryption mechanism using ordinary IT infrastructure.
On top of that, metadata such as the time of signing and the IP address of the input device are stored as part of the electronic signature. That burden of proof can no longer be reproduced with a physical signature — especially a year after it was made.
Technical implementation of the electronic signature
So that a document's integrity can be established beyond doubt, a hash code is calculated from the electronic document using a hash function.
A hash function is an algorithm that efficiently maps a string of any length (the input) to a fixed-length string (the hash value). In other words, the document is translated into a column of seemingly random characters. The algorithm is public, so the integrity of the process can be verified.
Every user of the same public hash function inevitably gets an identical hash value for the same document. Change any part of the document and the characters of the hash change too. By comparing generated hash values, it is technically straightforward to establish a document's integrity beyond doubt.
The electronic signature process (on top.legal) in practice
This is how electronic signatures work within our CLM software:
- The parties are invited to sign.
- The contract to be signed is moved into signing mode.
- The software calculates the hash value (checksum) including the metadata of the signing parties.
- The hash value is stored in an audit-proof way and embedded in the PDF.
- The hash value is usually encrypted with the signer's private key.
- The encrypted value can also be stored directly in the PDF together with further information (the encryption algorithm used, the public key, and so on).
- The signatories get access to the signed contract by email or a secure link.
- The recipient can use a verification algorithm to check the validity of the signature and confirm the document is the one the signature encloses. Many providers offer free verification tools for this, some of them online.
Introducing electronic signatures in your company
Creating an electronic signature is straightforward, but the process varies with the software you use. Many well-known platforms are used across Europe, yet they often lack a proper framework for contract management. A short guide to getting started:
- List the features that matter – from cost, security, and compliance to custom workflows, reporting, notifications, and branding.
- Research your options – compare providers and decide whether a pure signature tool or an integrated solution fits you better.
- Test your favourites in a demo – narrow down to the three best options and examine them thoroughly.
- Roll the tool out company-wide – involve all departments and clear up open questions early.
- Establish a clear process – make the electronic signature a fixed part of your standard operating procedures so everyone follows the same steps and compliance risks are avoided.
For a detailed feature analysis of the leading providers, see our eBook E-Signature Software Analysis.
Frequently asked questions about electronic signatures
Are electronic signatures legally valid?
Yes. Under the eIDAS Regulation, an electronic signature cannot be denied legal effect solely because it is electronic. Simple, advanced, and qualified signatures are all legally valid; a qualified electronic signature (QES) is strictly required only for documents where the law mandates written form. For the large majority of business contracts, an advanced signature is enough.
What does an electronic signature look like?
It depends on the type — from a plain e-mail signature or a scanned name (simple signature) to a signature field embedded in a PDF with a certificate, timestamp, and verification information (advanced and qualified signatures). Legally, what matters is not the appearance but the provable consent.
What is the difference between an electronic and a digital signature?
The terms are often used interchangeably. "Electronic signature" is the legal umbrella term from the eIDAS Regulation, while "digital signature" refers to the underlying cryptographic method used, for example, in advanced and qualified signatures.
What is an example of an electronic signature?
A typed name at the end of an email is a simple electronic signature; a PDF signed through a platform with SMS identity verification is an advanced one; and a signature created with a qualified certificate and video identification is a qualified one. See the examples section above for what each looks like.
Which types of electronic signature are there?
Three: the simple (SES), the advanced (AES), and the qualified electronic signature (QES). They differ in the degree of identity verification, tamper protection, and legal evidential value — see the comparison table above.
Ready for the next step?
Book a demo with our team and see top.legal in action