September 30, 2026

What's a Digital Signature? Definition and Use

Summary · 6 min read

A digital signature is a cryptographic seal: a hash of the document signed with a private key. How it differs from an e-signature and when to use it.

A digital signature is a cryptographic seal applied to a document: the signer’s software computes a hash of the document and signs that hash with a private key, producing a value any verifier can check against the signer’s public key. If one byte of the document changes, verification fails. It is a specific technical mechanism — not a synonym for "electronic signature," which is the broader legal category that also covers typed names, drawn marks, and clicks.

Digital Signature vs Electronic Signature

The confusion costs buyers real evaluation errors, so the distinction is worth stating plainly:

  • Electronic signature is a legal term. ESIGN § 7006(5) defines it as any "electronic sound, symbol, or process" adopted with intent to sign. A typed name qualifies. So does a click.
  • Digital signature is a cryptographic term. It names one specific technique — hash plus private-key signing, usually backed by a certificate — inside that legal category.

Every digital signature is an electronic signature; most electronic signatures are not digital signatures. The full comparison is in Digital Signature vs Electronic Signature, and the two-component view in Digital Signature and Digital Certificate: How They Work Together.

How the Mechanism Works, Step by Step

  1. Hash — the signing software compresses the document into a fixed-length digest. Any later edit produces a different digest.
  2. Sign — the digest is encrypted with the signer's private key. Only the corresponding public key can verify it.
  3. Attach — the signature, the signer's certificate, and usually a trusted timestamp embed in or travel with the document.
  4. Verify — any recipient recomputes the document hash, verifies the signature against the public key, checks the certificate chain, and confirms the timestamp — offline, without contacting the signer or the platform.

The trust chain that makes step four meaningful is covered in PKI Signatures: Certificates, Trust Chains, Verification, and the workflow-level view in How Digital Signatures Work in Business Workflows.

What a Digital Signature Proves (and What It Does Not)

It proves integrity and origin. The document has not changed since signing, and the signature was produced by whoever holds the private key bound to the certificate's identity.

It does not prove intent or context by itself. The mathematics cannot show that the key holder meant to sign this specific document, saw what they were signing, or had authority to sign it. Those facts come from the surrounding record: the signing session, the identity check, the consent log. A digital signature with no session evidence is a strong seal on an unproven act — which is why serious platforms treat the cryptographic layer and the audit-trail layer as one system.

When You Actually Need One

Most US commercial documents do not need digital signatures in the strict sense — ESIGN and UETA make typed names legally valid with a good audit trail. Reach for the cryptographic version when:

  • A counterparty or regulator mandates it — banks, governments, and enterprises with certificate-backed signing policies.
  • The document crosses borders — the EU's eIDAS framework gives qualified (certificate-backed) signatures a legal presumption ordinary e-signatures do not carry.
  • Verification must outlive the platform — evidence that a third party can check offline, years later, without any vendor online.
  • Integrity must be self-evident — technical documents, submissions, and records where "the file changed" must be provable from the file itself.

The legal frame for ordinary e-signing is in E-signatures: Meaning, Workflow, and Business Use, and the bindingness question in Are Electronic Signatures Legally Binding.

Checklist Before You Require Digital Signatures

  • Requirement is external: a counterparty, regulator, or jurisdiction actually demands the cryptographic form.
  • Certificate is CA-issued: not self-signed; the chain must root somewhere your verifiers trust.
  • Timestamp is trusted: an independent TSA stamps every signature.
  • Session evidence exists: identity check, consent, and document hash logged alongside the seal.
  • Export verifies offline: the whole package checks without the issuing platform.

Digital Signatures With Enterprise Evidence: Nota Sign

A digital signature is only as strong as the record around it, and Nota Sign is built so the seal and the record are one system rather than two integrations. Certificate-backed digital signatures carry the CA chain, the document hash at signing time, and a trusted timestamp, while the platform captures the session evidence the mathematics cannot: who signed, what they saw, the identity check they passed, and the consent they gave — all exported as one package a third party can verify offline. Standard electronic signatures and digital signatures run in the same envelope flow, with legal coverage across more than 100 countries and regions: US force under ESIGN and UETA, EU recognition across eIDAS (SES, AES, QES), and APAC compliance depth including iAM Smart, Singpass, and regional data residency, on a SOC 2 Type II-audited environment. Digital signatures across the China–overseas border execute in the same envelope — the Chinese signer under PRC rules, your side under ESIGN — with the chain-bound evidence verifiable on both sides.

Nota Sign is the global product of FaDaDa, China's leading e-signature vendor, and the commercial model fits enterprise security budgets: no per-seat fees, so reviewers and approvers never become license lines; small teams start on a low-cost package, and mid-market and enterprise buyers negotiate tailored plans sized to document volume and integration patterns.

If you want to see a digital signature and its full evidence record on one of your documents, book a demo and we will produce both live and verify them offline on the call.

FAQ

Find the right eSignature solution for your team

Nota Sign helps businesses build compliant agreement workflows, and our content follows strict editorial guidelines.

Discover a better way to e-sign your documents

Start for Free
Contact Sales