September 16, 2026

eIDAS Regulation & Electronic Signatures: A Guide

Summary · 10 min read

What the eIDAS Regulation (EU) 910/2014 means for cross-border contracts: the three signature levels, QTSPs, mutual recognition, and a compliance checklist.

The eIDAS Regulation (Regulation (EU) 910/2014) is the European law governing electronic identification and trust services, including electronic signatures. It applies directly in all 27 EU member states, defines three signature levels with different evidentiary weight, and guarantees that a qualified signature issued in one EU country is recognized in every other.

What Regulation (EU) 910/2014 actually regulates

eIDAS stands for electronic IDentification, Authentication and trust Services. It was adopted on 23 July 2014 and has been fully applicable since 1 July 2016. Because it is a regulation rather than a directive, it has direct effect: no transposition into national law is required, and its text is identical across the Union.

The regulation rests on two pillars. The first is electronic identification (eID), which lets citizens and businesses use their national identity means with public services in other member states. The second — and the one that matters most to companies — is trust services: electronic signatures, seals, timestamps, registered electronic delivery, website authentication, and preservation.

Its central principle is non-discrimination of the electronic format: an electronic signature cannot be denied legal effect or admissibility as evidence in court solely because it is electronic. How much weight a given signature carries, however, depends on the level used.

Where eIDAS applies: direct effect across 27 countries

eIDAS governs the 27 EU member states and has also been incorporated into the European Economic Area agreement. For any business trading in Europe, this means the same signing rules hold in Berlin, Paris, or Warsaw — there is no need to study a different signature law for every country.

The regulation also reaches companies based outside the EU. If a third-country company signs with European partners, the validity of those signatures before a European court is assessed under eIDAS. The United Kingdom, after Brexit, maintains its own framework — UK eIDAS — whose content is substantially similar.

The three signature levels: SES, AES, and QES

Simple electronic signature (SES). This is the general category: any data in electronic form attached to, or logically associated with, other electronic data and used by the signatory to sign. A typed name at the end of an email, a scanned image of a handwritten signature, or a click on "I accept" are all simple signatures. They are legally valid, but enjoy no presumption: if challenged, their probative value depends entirely on the evidence the business has retained.

Advanced electronic signature (AES). An advanced signature must meet four requirements: it is uniquely linked to the signatory, capable of identifying them, created using data under their sole control, and linked to the signed data so that any later change is detectable. In practice this is achieved by combining signer authentication with cryptography, and it is the sensible standard for most ordinary business contracts. We break down the four requirements and how to implement them in our guide to the advanced electronic signature as the business standard.

Qualified electronic signature (QES). A qualified signature is an advanced signature created with a qualified signature creation device (QSCD) and based on a qualified certificate issued by a supervised provider. It is the only level with a legal presumption: it has the equivalent legal effect of a handwritten signature across the entire EU.

Not every document needs the qualified level. The usual criterion is to match the level to the risk: QES when a sectoral rule demands it or litigation exposure is high, AES for ordinary commercial contracts, and SES for low-value transactions. For a practical walkthrough of choosing and deploying each level, see our guide to getting an eIDAS-compliant electronic signature.

Trust services and QTSPs: certificates, timestamps, seals, and validation

eIDAS regulates more than signatures — it governs the entire ecosystem that supports them. Trust service providers (TSPs) are the entities that issue certificates, timestamps, and related services. Their qualified version, the QTSP, is supervised by a national body and appears on the trusted lists published by the European Commission.

Among the qualified services, the most relevant for businesses are: issuing qualified certificates for electronic signatures and seals, managing qualified signature creation devices, qualified timestamps (which carry a presumption of accuracy and integrity), qualified validation, and long-term preservation.

The certificate is the piece that binds an identity to cryptographic keys: it attests who stands behind a signature. Before relying on a certificate, it is worth knowing how to check a digital certificate and confirm its type, validity, and issuing provider.

Cross-border mutual recognition: the principle that makes eIDAS unique

The regulation's golden rule is mutual recognition: a qualified electronic signature based on a qualified certificate issued in one member state must be recognized as qualified in all the others — and the same applies to qualified electronic seals and qualified timestamps. No member state may require, for a cross-border formality, a signature level higher than qualified.

In practice, this turns eIDAS into the legal infrastructure of the European contract. A Spanish company and a French company can sign with full legal certainty without travel, couriers, or apostilles. The same logic underpins any cross-border deal signed within the Union.

As for third countries, trust services provided outside the EU are recognized only through specific international agreements. There is no automatic recognition: the status of each country must be verified before relying on a foreign trust service.

eIDAS and Spain's Ley 6/2020: how the two texts fit together

In Spain, two legal texts coexist. The eIDAS Regulation applies directly and sets the substantive rules: signature levels, legal effects, and mutual recognition. Ley 6/2020, of 11 November, regulating certain aspects of electronic trust services, organizes what the regulation leaves to national hands: who supervises providers in Spain, how they are accredited, which technical requirements they must meet, and which sanctioning regime applies.

The practical reading is simple. If you sign or receive signatures in Spain, eIDAS tells you what legal effects your signature has, and Ley 6/2020 tells you what guarantees the Spanish providers behind it must offer. Both layers operate at once, and a compliant workflow has to satisfy each.

eIDAS 2.0: what Regulation (EU) 2024/1183 changes

In 2024 the EU published Regulation (EU) 2024/1183, which amends the original text — it does not repeal it. Its central novelty is the European Digital Identity Wallet (EUDI Wallet), together with new trust services such as qualified electronic attestations of attributes. The amending regulation entered into force in May 2024, and its various obligations apply on a staggered schedule.

For businesses, the message is twofold: the electronic signature rules currently in force do not change, and it is advisable to check the dates attached to each implementing act before planning system changes. The details that matter — which obligations start when — are set out in those implementing acts, not in the base regulation.

An eIDAS compliance checklist for your business

Use this table as a quick audit of your current signing process:

Review areaeIDAS requirementCommon failure
Signature levelMatched to riskSimple level for everything
CertificateQualified for QESExpired certificate
ProviderSupervised QTSPUnlisted provider
TimestampQualified and reliableNo timestamp at all
EvidenceComplete audit trailSignature image only
ValidationVerify on receiptNothing ever verified
RetentionLong-term custodyNo retention plan

Two rows deserve special attention. Validation: signing well is not enough if your company never verifies the signatures it receives; our guide to validating a signature in a PDF shows the procedure step by step. And evidence: when a signature is challenged, what decides the dispute is the complete evidence package — authentication records, timestamps, traceability — not the image of the squiggle. Our analysis of whether digital signatures hold up in court explains what judges actually look for.

Retention deserves the same rigor. Certificates expire and cryptographic algorithms age, so a signature that verifies today may not verify in ten years unless you plan for it; our guide on long-term validation (LTV) covers how to keep signed evidence verifiable over time.

One flow from Berlin to Singapore: Nota Sign

For a business that negotiates beyond the EU, the practical question is not what eIDAS says but how to operate it daily alongside the signature frameworks of every other country where it signs. Nota Sign, FaDaDa's global e-signature platform, answers with consolidation: the SES, AES, and QES levels of the European framework live on the same platform as the signing mechanisms of more than 100 countries and regions, including integrations with Asia-Pacific identity systems such as Singpass in Singapore and iAM Smart in Hong Kong. The contract with your German supplier and the one with your Singaporean customer come out of the same flow, each with its own exportable evidence package.

Cross-border evidence demands custody to match. The platform runs regional data centers to respect the data residency expectations of each jurisdiction and has passed the SOC 2 Type II audit, the independent benchmark for security, availability, and confidentiality of service. Consolidation also shows up on the invoice: with no per-seat fees, opening a new market does not mean buying more licenses, and mid-market and enterprise buyers can opt for customized plans based on volume. If your operation crosses borders, talk to our team and we will walk you through how your specific case would look.

FAQ

Find the right eSignature solution for your team

Nota Sign helps businesses build compliant agreement workflows, and our content follows strict editorial guidelines.

Discover a better way to e-sign your documents

Start for Free
Contact Sales