A qualified electronic signature is not a separate technology from an advanced electronic signature: under eIDAS, a QES is an AdES plus a qualified certificate for electronic signatures and a qualified electronic signature creation device.
This page helps separate the legal effect, certificate and QTSP checks, QSCD evidence, and validation records that make the difference defensible for relying parties and audit reviewers.
Under eIDAS, every must first satisfy the requirements: it must be uniquely linked to the signatory, identify the signatory, use signature creation data under the signatory's sole control with a high level of confidence, and make later changes to the signed data detectable. QES adds two qualification layers: the signature must be based on a issued by a qualified trust service provider, and it must be created by a .
Side-by-side comparison
QES vs AdES under eIDAS: practical differences
This comparison helps decide whether the record needs only evidence or the additional qualified certificate, QTSP, QSCD, and validation evidence needed for .
An advanced electronic signature created by a and based on a .
Second framework
Advanced electronic signature (AdES)
An electronic signature that meets Article 26's requirements for signer linkage, signer identification, signer-control of creation data, and detectable changes to signed data.
Cannot be denied legal effect or admissibility only because it is electronic or not qualified, but it does not receive automatic handwritten-signature equivalence under Article 25.
Use where handwritten-signature equivalence is required, but check any separate transaction formality. Use where the legal need is strong electronic evidence assessed in context.
May use certificates and trust services, but status alone is not proof that the certificate is qualified or that the provider has qualified status for that service.
For , validate QTSP and qualified-certificate status from trusted-list evidence; for , keep certificate and identity evidence without overstating qualified status.
The validation process must confirm certificate qualification, QTSP issuance, certificate validity at signing, matching validation data, signatory data, pseudonym indication if used, QSCD creation, signed-data integrity, and Article 26 compliance.
The evidence should prove Article 26 requirements and, if the signature is based on a qualified certificate, the separate Article 32a validation conditions for that middle category.
A validation report should be retained with trusted-list, certificate, revocation, QSCD, and signed-data-integrity evidence; records should not omit signer identity, signer control, and tamper-detection evidence.
Classify as when the evidence proves Article 26 requirements but the record does not prove every qualified certificate, QTSP, QSCD, and validation condition.
review focuses on whether the Article 26 conditions were met for the signature. If the AdES is based on a qualified certificate, Article 32a adds certificate-at-signing and related validation checks even though the signature is not .
Receives the equivalent legal effect of a handwritten signature under Article 25, without displacing separate transaction formalities in applicable law.
Treat as the higher legal-effect label, then check any separate formality. Treat as the evidence-based option unless a rule specifically asks for qualified status.
Choose when the request or rule calls for handwritten-signature equivalence or when the file must prove qualified status end to end, subject to any separate form requirement.
Cannot be denied legal effect or admissibility only because it is electronic or not qualified, but it does not receive automatic handwritten-signature equivalence under Article 25.
Use where handwritten-signature equivalence is required, but check any separate transaction formality. Use where the legal need is strong electronic evidence assessed in context.
May use certificates and trust services, but status alone is not proof that the certificate is qualified or that the provider has qualified status for that service.
For , validate QTSP and qualified-certificate status from trusted-list evidence; for , keep certificate and identity evidence without overstating qualified status.
The validation process must confirm certificate qualification, QTSP issuance, certificate validity at signing, matching validation data, signatory data, pseudonym indication if used, QSCD creation, signed-data integrity, and Article 26 compliance.
The evidence should prove Article 26 requirements and, if the signature is based on a qualified certificate, the separate Article 32a validation conditions for that middle category.
A validation report should be retained with trusted-list, certificate, revocation, QSCD, and signed-data-integrity evidence; records should not omit signer identity, signer control, and tamper-detection evidence.
Classify as when the evidence proves Article 26 requirements but the record does not prove every qualified certificate, QTSP, QSCD, and validation condition.
review focuses on whether the Article 26 conditions were met for the signature. If the AdES is based on a qualified certificate, Article 32a adds certificate-at-signing and related validation checks even though the signature is not .
Receives the equivalent legal effect of a handwritten signature under Article 25, without displacing separate transaction formalities in applicable law.
Treat as the higher legal-effect label, then check any separate formality. Treat as the evidence-based option unless a rule specifically asks for qualified status.
Choose when the request or rule calls for handwritten-signature equivalence or when the file must prove qualified status end to end, subject to any separate form requirement.
How should teams decide between QES and AdES labels?
Start with the legal or contract requirement: does it require handwritten-signature equivalence, qualified status, or only reliable electronic evidence?
If is required, collect the validation report plus evidence of qualified certificate status, QTSP issuance, certificate validity at signing, revocation status, QSCD support, and signed-data integrity.
If is sufficient, retain signer identity, authentication, signer-control, intent, audit-log, and tamper-detection evidence, and avoid qualified-status claims unless they are independently proven.
Escalate any vendor statement that says without showing the qualified certificate, trusted-list status, QSCD evidence, and Article 32 validation result.
What is the practical difference between a QES and an AdES under eIDAS?
An is the eIDAS signature level defined by the four Article 26 requirements: signer linkage, signer identification, signer-control of creation data, and data-integrity linkage. It can be strong evidence, but eIDAS does not give it automatic equivalence to a handwritten signature.
A is an that also uses a and a . eIDAS Article 25 gives a QES the equivalent legal effect of a handwritten signature, while any electronic signature remains admissible and cannot be rejected only because it is electronic or not qualified.
That handwritten-signature equivalence does not remove separate requirements that Union or national law may impose on a transaction, such as witnessing, notarisation, registration, or a prescribed form. Check the law governing the document before treating as the only formality.
Use language when the evidence question is whether the signer can be identified, the signature is linked to the signed data, and later changes are detectable.
Use language only when the record proves the qualified certificate, the qualified trust service provider, the qualified creation device, and the Article 26 requirements.
Do not call a signature merely because it uses a digital certificate, a strong login, an audit trail, or a vendor label.
Is a qualified electronic signature () just a stronger advanced electronic signature () under EU eIDAS?
Yes, in eIDAS structure: a is an that also has a and is created by a . The added qualified certificate and device requirements are what give QES its special eIDAS legal effect.
Article 2 preserves separate Union and national rules on contract and document formalities; Articles 3, 25, and 26 define AdES and QES, their legal effects, and the four AdES requirements.
Question 2
What must be checked before relying on QES status?
For , the signature validation record should prove more than successful cryptographic verification. It should show that the supporting certificate was a qualified certificate at the time of signing, that it was issued by a qualified trust service provider and valid at that time, that the validation data matched what was provided to the relying party, and that the signed data's integrity was not compromised.
Trusted lists matter because eIDAS requires Member States to establish, maintain, and publish trusted lists with information about qualified trust service providers and their qualified trust services. The trusted-list interpretation rules also explain how qualified certificate and QSCD-related status can be represented through service entries, certificate statements, and qualifications.
Commission Implementing Regulation (EU) 2025/1945 has applied since 20 October 2025. It sets reference standards for validating and the middle category of based on a qualified certificate. A process that complies with those standards benefits from the regulation's presumption of compliance for the referenced validation requirements, but the result still has to distinguish QES from AdES without QSCD proof.
Keep the signed object or detached signed data with the exact signature package that was validated.
Keep the validation report showing the result, validation time or best-signature-time, certificate chain, revocation status, and security-relevant warnings.
Keep evidence that the certificate was qualified for electronic signature, issued by a QTSP, and valid at the time of signing.
Keep evidence that the signature was created by a QSCD or remote QSCD service where status is claimed.
Keep the trusted-list or LOTL evidence used to establish the QTSP, qualified service, certificate, and QSCD status.
Identifies Commission eSignature resources, including the eIDAS Dashboard, Trusted List Browser, and validation tooling for signature verification work.
Sets the current reference standards for QES validation and for validation of AdES based on qualified certificates; it entered into force on 20 October 2025.
Question 3
When is AdES enough, and when should a team require QES?
may be enough where the applicable contract, service design, risk analysis, or law only requires strong evidence of signer identity, signer control, and document integrity. eIDAS preserves the admissibility of non-qualified electronic signatures; the weight given to that evidence depends on the applicable law and transaction record.
Require when the applicable law, public-service requirement, customer mandate, procurement clause, or organisation risk decision specifically requires qualified status or handwritten-signature equivalence. Then check separately for any witnessing, notarisation, registration, or other form requirement. A normal audit trail is incomplete for a QES claim unless it also proves the qualified certificate, QTSP, QSCD, and validation conditions.
For , document the identity proofing and authentication method, signer intent, signer-control evidence, signed-data hash or signature linkage, and tamper-detection result.
For , add qualified certificate details, QTSP/trusted-list status, QSCD or remote QSCD evidence, certificate validity or revocation status at signing, and the qualified validation result.
For advanced signatures based on qualified certificates, do not assume : eIDAS Article 32a has validation requirements for that middle case, but it lacks the QSCD requirement that distinguishes QES.
Article 25 preserves admissibility for electronic signatures generally, Article 32 validates QES, and Article 32a covers AdES based on qualified certificates.
Recommended next step
Build a QES or AdES evidence record that reviewers can rerun
Sorena can help convert the eIDAS distinction into a cited signature policy, validation checklist, supplier evidence request, and record-retention format for your signing workflow.
Sets the current reference standards for QES validation and for validation of AdES based on qualified certificates; it entered into force on 20 October 2025.
Identifies Commission eSignature resources, including the eIDAS Dashboard, Trusted List Browser, and validation tooling for signature verification work.
"creation and verification of electronic signatures"