A digital signature proves a document was signed by a specific certificate holder at a specific time — but only as long as the underlying certificate and the evidence around it remain verifiable. Certificates expire. Revocation lists get pruned. Trust anchors change. A signature that validates perfectly today can become unverifiable in five years unless someone took steps to protect its long-term validity.
That set of steps has a name in the standards world: Long-Term Validation, or LTV. This guide explains why signatures stop validating over time, how timestamping and revocation evidence fix the problem, what "LTV-compliant" actually means in practice, and what to ask your e-signature vendor before you trust it with records you will need for years.
Why a valid signature stops validating over time
Think of a digital signature as a chain of three promises: the signer's certificate proves who signed, a timestamp proves when they signed, and revocation information proves the certificate was still valid at that moment. Each of those promises has a shelf life:
- Certificates expire. Signing certificates typically live for one to three years. After expiry, a naive verifier has no way to know whether the certificate was valid at signing time unless that evidence was archived with the document.
- Revocation lists disappear. Certificate authorities publish revocation information (CRLs and OCSP responses) on a schedule. If a signature relies on checking a CRL that is no longer published, the check fails even though the signature was perfectly valid when created.
- Trust anchors change. Root and intermediate CAs are added, rotated, and retired over time. A verifier in 2031 may no longer trust the root that issued a 2026 certificate.
- Hash and key strength assumptions age. Standards bodies raise minimum key sizes and move to stronger hash algorithms, which can leave older signatures outside supported parameters in future tooling.
None of these are defects in the original signature. They are properties of time — and they are exactly what LTV exists to neutralize.
What long-term validation actually does
The core idea of LTV is to archive, at signing time, the evidence that future verifiers will need, so the signature does not depend on today's infrastructure still existing tomorrow. The widely documented building blocks are:
- Time-stamping (RFC 3161). A trusted timestamp authority signs a statement that a specific document hash existed at a specific moment. Because the timestamp itself is a fresh digital signature, it establishes when signing happened without depending on the signer's own certificate staying valid.
- Revocation evidence capture. The signer's software fetches the CRL or OCSP response that proves the certificate was valid at signing time and stores it alongside the signature. Future verifiers read the archived evidence instead of asking a CA that may no longer answer.
- Signature archival formats. Standards such as PAdES (PDF Advanced Electronic Signatures) define how to embed the signature, timestamp, and revocation evidence into the PDF itself so the document is self-contained. Archives that keep these elements separate risk losing the linkage.
- Periodic re-validation. For very long retention, some workflows re-sign or refresh archived documents on a schedule so that each cycle restarts the validity window with fresh timestamps.
The output is a signed document that carries its own proof: anyone with a compliant verifier can confirm the signature as of signing time, without needing the CA, the signer, or the original infrastructure to be reachable.
Why "valid today" and "valid for 10 years" are different buying questions
Most e-signature products talk about the signing moment: audit trails, completion certificates, identity verification. Those matter, but they are not the same as long-term validity. The questions diverge sharply:
If you are keeping signed documents for internal notes, the left column is fine. If you are keeping contracts, certificates, or compliance records for years — and especially if you sign in jurisdictions where digital signature standards are formalized, such as under eIDAS with SES/AES/QES levels — the right column is the one that matters. Our guide to how digital signatures work in real business workflows covers the baseline mechanics, and the eIDAS compliance guide for global teams explains where formal validity levels come in.
How to check whether your signing workflow preserves LTV
You can audit a signing setup against LTV requirements without being a PKI expert. Run through this checklist:
- Does the tool embed a timestamp at signing? Ask for the verification report or test a signature and look for an RFC 3161 timestamp block.
- Are revocation checks archived, not just performed? A product that checks CRL/OCSP at signing but discards the response is not preserving evidence for later.
- What format do signed exports use? PDF exports should carry signature, timestamp, and revocation evidence (PAdES-style). If "export" gives you a flat PDF without embedded evidence, it is not LTV.
- Can a fresh verifier validate an old file offline? Download a signed file from two years ago — if your current tool can verify it without contacting the original CA, that is a strong signal.
- Is there a re-validation policy for long retention? Ask what happens to archives on multi-year schedules: periodic refresh, re-timestamping, or storage as-is.
- Does the certificate chain stay resolvable? Check whether the tool archives intermediate certificates, not just the signer's leaf certificate. Our certificate authority list primer shows why chain resolvability matters.
- Are self-signed certificates excluded? Self-signed certificates have no external trust chain and generally cannot provide durable third-party validation. Our analysis of whether self-signed certificates are secure for business contracts explains the risk in detail.
Common mistakes that quietly break long-term validity
Even teams that buy a capable product manage to break LTV in operation:
- Exporting through the wrong pipeline. If the signed PDF is re-saved, flattened, or converted before archival, embedded signature evidence can be stripped even though the file "looks the same."
- Storing only the completion certificate. The vendor's certificate is a summary of the workflow; it is not the signature's cryptographic evidence. Archive the actual signed file.
- Treating screenshots as evidence. A screenshot of a signed page proves nothing cryptographically. The signature must live inside the file.
- Assuming the vendor archives forever. "We have it in our account" is a service promise, not a format guarantee. Verify that the vendor's export preserves LTV elements, and plan your own archival copy.
- Ignoring format churn. If your long-term archive will be read by future systems, prefer archival-oriented formats (PDF/A-class) so the rendering and the evidence survive tool changes.
To see what proper verification looks like in practice, our guides to validating a signature in a PDF and verifying a DocuSign signature's evidence walk through the verification report and what each field means.
What to ask your e-signature vendor about long-term validation
Before you commit documents that will outlive your current tooling, put these questions in writing:
- Does the product embed RFC 3161 timestamps in signed PDFs by default?
- Are CRL/OCSP responses archived with the signed file, or only checked at signing time?
- What archival format is exported, and does it carry the full evidence chain?
- Can the product re-timestamp or refresh signatures on a schedule for long retention?
- Which signature levels and standards are supported (for example SES/AES/QES under eIDAS)?
- What happens to validity evidence if you stop subscribing?
Keep signed records verifiable for years with Nota Sign
If you are choosing a signing platform for records that need to stay valid for years, signature-level support is the first thing to check. Nota Sign, the global e-signature platform of FaDaDa, supports SES, AES, and QES signature levels backed by regional data centers — the tiers long-term validation depends on — and is ranked #1 in China's e-signature software market by IDC for consecutive years, with legal coverage across 100+ countries and regions.
For teams with long retention requirements, the practical questions are signature-level support and cost structure. Nota Sign does not charge per-seat fees, so signing stays affordable for teams with occasional senders — not just heavy users — and mid-market and enterprise buyers can get tailored, customized plans matched to their volume and compliance needs. APAC compliance depth — iAM Smart in Hong Kong, Singpass in Singapore — rounds out the picture for records that cross borders. If you want to understand how Nota Sign's signing and archival options fit your retention requirements, our team can walk you through them.









