The Adobe Approved Trust List (AATL) is Adobe's vetting program for certificate authorities (CAs). When a signing certificate chains up to an AATL-approved CA, Adobe Acrobat, Acrobat Reader, and Acrobat Sign automatically treat the signature as trusted — the familiar green checkmark — without the recipient installing any extra software or root certificates.
That automatic trust is not magic; it is the result of a specific group of certificate providers passing Adobe's audits. This guide focuses on those providers: who they are, how the list relates to Europe's EUTL and eIDAS qualified signatures, and how your team can verify a certificate trust chain before relying on a signed PDF in a high-value transaction.
If you are evaluating e-signature platforms for cross-border contracts, understanding the provider layer behind AATL will save you from unpleasant surprises at audit or dispute time.
What the Adobe Approved Trust List Actually Does
AATL is a curated trust framework. Adobe reviews and approves CAs against strict criteria — including WebTrust for CA audit principles covering cryptographic standards, key management, and operational security — and then embeds those CAs' root certificates directly into Acrobat and Reader updates. Because the roots ship with the software, any signature built on an approved chain validates out of the box.
The practical payoff is threefold: tamper-evidence (any post-signing edit breaks the cryptographic hash), verifiability (anyone with a standard PDF reader can confirm the signature), and non-repudiation (the signer cannot credibly deny an intact, certificate-backed signature). For a foundational overview of the program itself, see What Is AATL and Why It Matters for Trusted Digital Signatures. This article goes one level deeper, into the provider and operations layer.
Who the AATL Certificate Providers Are
Following its recent updates, the list includes more than 30 approved CAs. Rather than a single type of organization, it spans well-known global CAs and regional trust service providers (TSPs). Based on 2026 public listings, the providers fall into three broad groups:
Global CAs sell signing certificates in many jurisdictions and are the usual choice for multinational PDF workflows. European qualified trust service providers (QTSPs) are supervised at the national level and can issue qualified certificates for qualified electronic signatures (QES). Regional TSPs anchor trust to government-backed identity schemes — for example Hong Kong's iAM Smart or Singapore's Singpass — which matters when counterparties and regulators expect local trust anchors.
A word of caution: provider lineups change as Adobe refreshes the list, so always confirm the current roster on Adobe's official pages rather than relying on any static snapshot, including this one.
AATL vs EUTL: How the Two Trust Frameworks Interact
Teams operating between the US and EU often assume AATL and the EU Trusted List (EUTL) are competing programs. They are complementary. Under eIDAS (EU) No 910/2014, each member state supervises its QTSPs and notifies them to the EUTL; once notified, those providers' qualified certificates enjoy trust recognition inside the Adobe ecosystem as well. AATL then extends coverage to non-European CAs that would never appear on the EUTL.
The legal effect differs by layer. eIDAS defines three signature levels — simple (SES), advanced (AES), and qualified (QES) — and only QES, which requires a qualified certificate from a QTSP, carries the same legal presumption as a handwritten signature across the EU. AATL trust in Acrobat is a technical signal; QES status is a legal one. For a deeper dive into the regulation, read What Is eIDAS and Why It Matters for Trusted Digital Signatures?.
How the Certificate Trust Chain Works in a Signed PDF
Every trusted PDF signature rests on a chain: the AATL root CA sits at the top, an intermediate CA issues below it, and the signer's end-entity certificate sits at the bottom. When someone signs, the software hashes the document, encrypts that hash with the signer's private key, and embeds the certificate chain plus — in well-configured workflows — a trusted timestamp. Acrobat validates by walking the chain upward until it reaches an embedded AATL root, then checking revocation status through CRL or OCSP responses.
This certificate-based mechanism is precisely what separates a digital signature from a simple electronic signature like a typed name or scanned image; the differences are unpacked in Digital Signature vs. Electronic Signature: Understanding Their Differences and Uses. Looking ahead, the cryptographic algorithms underneath today's chains will eventually migrate to post-quantum standards — a transition worth tracking in Quantum-Resistant Cryptography and Digital Signatures: What You Need to Know in 2026.
How to Verify a Signer's Certificate Chain in Practice
Verification takes minutes and should be standard practice for high-value agreements:
- Open the PDF in Acrobat or Reader and click the signature panel to view each signature's status.
- Open "Signature Properties" and then "Show Signer's Certificate" to inspect the chain: end-entity, intermediate, and root.
- Confirm the root chains to an AATL-embedded CA — a green checkmark means it does; a question mark or warning means the root is unknown or the document changed after signing.
- Check the signing time and whether a trusted timestamp was applied, and review revocation status for the signing date, not just today.
- Save the validation report alongside your audit trail so the evidence survives later disputes.
If a signature is invalid, expired, or attached to the wrong certificate, the cleanest remedy is usually to re-sign on a correct chain rather than patch the file. When a signature genuinely must be cleared first — for example, a test signature on a template — follow a controlled process such as the one in How to Remove a Digital Signature from a PDF Without Losing Control of the Signing Record, and keep the signing record intact.
Legal Weight Across Regions: ESIGN, eIDAS, and APAC
A trusted chain strengthens your position almost everywhere, but the legal framing differs. In the US, ESIGN and UETA make electronic signatures enforceable when intent, consent, and record retention are shown — certificate-backed signatures plus a complete audit trail make that showing far easier. In the EU, eIDAS gives QES handwritten-equivalent presumption, while AES and SES remain valid with supporting evidence. Japan's Act on Electronic Utilization (2000), India's IT Act (2000), and China's Electronic Signature Law (2005) each recognize electronic signing with their own evidentiary nuances; note that Adobe exited the mainland China market in 2023, so China-facing workflows often run on regional platforms instead.
If your team needs a refresher on baseline enforceability concepts like intent and consent, What Is an E-Signature? A US Business Guide to Intent, Consent, and Records covers the groundwork.
What to Ask Your e-Signature Vendor About Certificate Providers
Industry surveys suggest roughly 70% of enterprises now prioritize trusted-certificate support for high-value transactions. Before signing a vendor contract, audit the provider layer with questions like these:
- Which CAs and QTSPs issue the certificates behind your signatures, and are they on the current AATL or EUTL?
- Chain visibility: does the audit trail expose the full certificate chain, timestamps, and revocation evidence, or only a "signed" flag?
- Regional coverage: for APAC deals, can the platform route signing through local trust schemes such as iAM Smart or Singpass where counterparties expect them?
- Data residency: where are signature evidence and identity data stored, and does that align with GDPR or sector rules?
- Signature levels: can you require AES or QES per envelope when the transaction value justifies it?
A vendor that cannot answer these cleanly is telling you something about its trust architecture.
Why Teams Verify Cross-Border Trust Chains With Nota Sign
Nota Sign is built for teams that sign across jurisdictions and need certificate trust to hold up everywhere:
- Every signature level, one platform. SES, AES, and QES signing routes through qualified trust service providers, with the full certificate chain, timestamp, and revocation evidence preserved in the audit trail.
- Regional trust anchors built in. APAC schemes such as iAM Smart and Singpass sit alongside European QTSPs, so counterparties see a trust anchor their regulators recognize.
- Verification your team can replay. Signed files validate in standard PDF readers, and the evidence export hands auditors the full chain without vendor assistance.
If you are mapping certificate provider requirements onto a real signing workflow, talk to our team about your trust chain needs.








