Advanced vs. Qualified Electronic Signatures Explained

ELECTRONIC SIGNATURES
COMPLIANCE
eIDAS
ELECTRONIC SIGNATURES
August 13, 2026
Illustration comparing advanced electronic signatures (AES) and qualified electronic signatures (QES), highlighting digital certificates, identity verification, and secure electronic signing under eIDAS.

Not all electronic signatures provide the same level of assurance. Under the eIDAS Regulation, advanced electronic signatures (AES) and qualified electronic signatures (QES) each serve different purposes and have different legal characteristics. This article explains the differences, how each works, and why the distinction matters.

The eIDAS Regulation defines three types of electronic signatures, but most discussions focus on two: advanced electronic signatures and qualified electronic signatures. While both rely on strong cryptographic mechanisms and are widely used across Europe, they differ in how they are created, the legal assurances they provide, and the technical requirements behind them. Understanding those differences helps organizations navigate electronic signing requirements with greater confidence.

Electronic Signatures Under eIDAS

eIDAS defines three levels of electronic signature:

Simple Electronic Signatures (SES) cover the broad category: any data in electronic form attached to or associated with other data to indicate agreement. No specific technical requirements apply at this level.

Advanced Electronic Signatures (AES) must meet four specific requirements defined in Article 26 of eIDAS: uniquely linked to the signer, capable of identifying them, created using data under the signer's sole control, and capable of detecting any subsequent changes to the signed data.

Qualified Electronic Signatures (QES) meet all AES requirements and add a further layer: they must be created using a qualified signature creation device and be backed by a qualified certificate issued by a trust service provider on the EU Trusted List.

AES and QES receive the most attention because they are the levels with meaningful legal and technical substance. SES generally provides the lowest level of assurance and may be more difficult to rely on where the authenticity of a signature is disputed.

What Is an Advanced Electronic Signature?

An AES must satisfy four conditions under eIDAS Article 26:

Uniquely linked to the signer. The signature must be tied to a specific individual in a way that cannot be replicated by someone else.

Capable of identifying the signer. The signing mechanism must allow the signer's identity to be established, not just assumed.

Created under the signer's sole control. The signing data, typically a private cryptographic key, must be under the exclusive control of the signer. If others can access it, the signature does not meet this requirement.

Detects changes to the signed document. If the document is altered after signing, the signature must become invalid. This is handled through a cryptographic binding between the signature and the document content.

In practice, AES is typically implemented using a digital certificate and public key cryptography. The signer holds a private key; the signature is verified using the corresponding public key. Any change to the document after signing breaks the cryptographic link and invalidates the signature.

AES does not require a qualified certificate or a regulated trust service provider. The identity verification behind the signing certificate can be handled in different ways depending on the implementation and applicable requirements.

What Is a Qualified Electronic Signature?

A QES meets all the requirements of an AES and adds two further elements:

A qualified certificate issued by a Qualified Trust Service Provider (QTSP). QTSPs are regulated entities that appear on the EU Trusted List maintained by each member state. Obtaining a qualified certificate requires identity verification to a level defined by eIDAS, typically involving in-person or remote verification against an official identity document.

A qualified signature creation device (QSCD). The private key used to create a QES must be held in a device that meets specific security requirements, ensuring the key cannot be extracted or used without the signer's authorization. QSCDs may take different forms, including certified hardware devices and remote signing solutions provided by Qualified Trust Service Providers (QTSPs).

The legal consequence of meeting these requirements is significant. Under eIDAS Article 25(2), a QES has the equivalent legal effect of a handwritten signature across all EU member states. This cross-border legal equivalence is one of the defining characteristics of QES and a primary reason organizations use it for high-assurance transactions.

AES vs. QES: The Key Differences

Advanced (AES) Qualified (QES)
Uniquely linked to signer Yes Yes
Signer identification Yes Yes
Detects document changes Yes Yes
Qualified certificate required No Yes
QTSP required No Yes
Qualified creation device No Yes
Legal equivalence to handwritten signature No Yes (across all EU member states)
Implementation complexity Lower Higher
Cross-border legal recognition Varies Uniform across the EU

Signature levels as defined by eIDAS.

The core distinction is not security in isolation. Both AES and QES use cryptographic mechanisms that provide strong document integrity and signer authentication. The difference lies in the regulated identity verification behind the certificate and the legal standing that follows from it.

When Is Each Used?

The appropriate signature level depends on applicable legislation, the nature of the transaction, and local regulatory requirements. eIDAS does not mandate which signature level must be used for specific transaction types. That determination is made by sectoral legislation, national law, or the parties involved.

As a general principle, the required level of assurance should match the legal and risk profile of what is being signed.

In contexts where parties need confidence about the identity of the signer and that the document has not been altered, AES is often sufficient. The signer's identity is established through the signing mechanism, and document integrity is cryptographically guaranteed.

Where legislation requires the equivalent of a handwritten signature, where cross-border legal enforceability is important, or where the regulatory framework explicitly calls for a qualified signature, QES is the appropriate level. The qualified certificate provides independent, regulated verification of the signer's identity, and the legal equivalence established by eIDAS applies uniformly across member states.

Organizations should assess each use case against the applicable legal requirements in the relevant jurisdiction rather than applying a single signature level across all transactions.

Does eIDAS 2.0 Change Anything?

eIDAS 2.0 expands the existing trust framework in several relevant ways.

The introduction of the European Digital Identity Wallet is expected to make qualified signing services more accessible over time. Rather than requiring a separate enrollment process with a QTSP, a wallet holder may be able to use their verified digital identity to obtain a qualified signing certificate more directly. How this works in practice will depend on implementation across member states, which is still developing.

eIDAS 2.0 also reinforces the role of qualified trust services more broadly, which is likely to increase the availability of QES-compatible infrastructure over time. Whether this changes the balance between AES and QES usage will depend on the applicable legal requirements and how accessible qualified signing becomes for end users.

What eIDAS 2.0 does not do is replace or diminish AES. Both levels remain part of the framework, and the appropriate choice continues to depend on the use case and applicable requirements.

Choosing the Right Level

Rather than asking which signature level is better, the more useful question is what level of assurance a given use case requires and what the applicable legal framework expects.

AES and QES each have a clear role within eIDAS. AES provides strong cryptographic assurance and signer identification without the overhead of a qualified certificate. QES adds regulated identity verification and legal equivalence to a handwritten signature under eIDAS.

Selecting between them is a legal and operational decision, not a technical preference. Organizations that understand what each level provides and what their specific requirements are will be better positioned to implement electronic signing in a way that is both compliant and practical. Wultra's Electronic Signature solution supports both advanced and qualified electronic signatures, enabling secure, compliant, and seamless mobile signing for regulated industries.

Frequently asked questions

What is the main difference between an advanced and a qualified electronic signature?

An advanced electronic signature (AES) uniquely links a signature to the signer, helps identify them, and detects changes made to the signed document. A qualified electronic signature (QES) meets all the requirements of an AES while also relying on a qualified certificate issued by a Qualified Trust Service Provider (QTSP). Under eIDAS, a QES has the legal equivalence of a handwritten signature.

Does eIDAS require qualified electronic signatures for every transaction?

No. eIDAS defines the legal framework for electronic signatures, but does not require every transaction to use a qualified electronic signature. The required signature level depends on the applicable legal and regulatory requirements, which may vary depending on the country and the specific use case.

Can a mobile app support both advanced and qualified electronic signatures?

Yes. Modern electronic signing solutions can support both advanced and qualified electronic signatures within the same application. For example, Wultra's Electronic Signature solution enables organizations to integrate both signature types into mobile workflows while meeting the requirements of regulated environments.

Related articles

CONTACT US

Get in touch

Consider partnering with Wultra to meet compliance standards, deliver a secure and seamless user experience, and deliver additional value to your customers while improving your bottom line.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.