Two documents, one week, the same signature
An NDA went out on a Tuesday. A corporate guarantee went out on the Thursday. Both were signed the same way: a click on a link, a name typed into a box, a PDF back by lunchtime.
Nobody will ever ask about the NDA. The guarantee is the problem. If the counterparty says that was not me, somebody must prove not that a click happened, but that a specific human being clicked. That evidence was never collected, because the workflow for a two page NDA was reused for a document worth millions.
The reverse failure costs more, more often: everything gets the heaviest signature available, and every internal sign-off goes through an identity check it never needed. Both mistakes come from treating the signature level as a company-wide setting. It is a per document decision.
The one question that drives the answer
Not is this legal. eIDAS answers that. Article 25(1) of Regulation (EU) No 910/2014 says an electronic signature "shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures".
So the simple signature is not invalid. Saying otherwise is the most common error in this market. The right question is different:
If this document were challenged, what would you need to prove, and to whom?
Three inputs, all answerable before the envelope goes out.
Form requirement. Does the applicable national law impose a written form for this contract type? Then the level is not a choice. This varies by Member State and contract type, so check rather than guess.
Exposure. What if the signature is not accepted at face value? For an internal approval, nothing. For a guarantee, the whole amount is in play.
Friction tolerance. A supplier signing a routine order will click a link. Asked to photograph a passport for that same order, they call your account manager instead.
The three rarely agree, which is why this is a decision rather than a lookup.
The three levels, and what separates them
Article 3(10): an electronic signature is "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign". Deliberately wide. A click qualifies.
Article 3(11): an advanced electronic signature is "an electronic signature which meets the requirements set out in Article 26".
Article 3(12): a qualified electronic signature is "an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures". Two extra components, both supervised.
And Article 25(2): "A qualified electronic signature shall have the equivalent legal effect of a handwritten signature." The only place the law hands you equivalence instead of asking a court to weigh evidence. The difference between the levels is not validity. It is who carries the burden when someone disputes the signature.
Which makes Article 26 the line that matters, since it is what turns a simple signature into an advanced one. Four requirements, all of which must be met.
It is uniquely linked to the signatory. One person, not a shared account or departmental mailbox.
It is capable of identifying the signatory. The signature carries who signed, rather than leaving you to infer it from an email address anyone with mailbox access could use.
It is created using electronic signature creation data that the signatory can, with a high level of confidence, use under his sole control. The means of signing is theirs alone. A shared password fails this.
It is linked to the data signed therewith in such a way that any subsequent change in the data is detectable. Alter one character of the PDF and the signature reports it.
Together they are an evidence specification: a signature that answers who signed this, and has it changed since, without reconstructing it from logs afterwards. A simple signature can be backed by strong evidence, and a well built one usually is. The difference is that there the evidence is a case you build, while an advanced signature carries part of it inside itself.
A decision table you can actually use
The middle column is guidance for a typical case, not a legal rule. The right hand column is the part you cannot skip.
| Document category | What you would prove if challenged | Usually proportionate | Check in national law |
|---|---|---|---|
| Internal approval or sign-off | A named employee approved it, on a date | Simple | Rarely a form rule; policy may set its own bar |
| NDA, standard terms acceptance | This counterparty agreed to these terms | Simple; advanced if they are unknown to you | Usually none |
| Standard commercial order | The person binding the company was that person, text unchanged | Simple at routine value, advanced as value rises | Sector rules may apply |
| Employment contract | Identity of the employee, the terms, the date | Advanced; qualified where written form is imposed | Heavily national; some clauses carry own form rules |
| Corporate guarantee or high value commitment | Identity beyond argument, authority to bind, integrity of the text | Qualified | Guarantees commonly carry form requirements |
| Anything a statute requires in written form | That the statutory form was met at all | Qualified, the level Article 25(2) equates to a handwritten signature | The rule is national and contract-specific |
| Signed in a professional capacity | The signer held that capacity or power to bind when signing | A signature certifying the professional attribute alongside identity | Depends on profession and country |
The employment contract row is where most cross-border mistakes happen, because the answer differs by Member State. Germany is the clearest published example: §126a BGB provides that a qualified electronic signature satisfies the statutory written form, covered in signing German contracts as a US company.
The statutory written form row is not one you can eyeball. Ask whoever advises you on the governing law, before the template is built rather than after the contract is signed. Which level your document and jurisdiction call for is what a table cannot close, because it turns on the governing law and on what the signature is doing.
The friction side of the decision
The compliance argument gets the attention. The commercial one decides more cases. Every step between the link and the signature loses some percentage of signers. Identity verification is a real step: photograph a document, complete a face and liveness check, wait for the result. For a guarantee, time well spent. For a routine order, a reason to close the tab and deal with it later.
So set the level per signer when the envelope is created, and let levels differ inside one envelope where that is defensible. On a supply agreement, board members committing the company and a technical lead confirming a scope annex are doing different things. That structure has limits, covered in signing order in multi-party contracts.
Decided per document category, the level becomes a template setting rather than a judgement call under deadline: standard order simple, employment contract advanced, guarantee above a threshold qualified. Made once by the people qualified to make it, it survives staff turnover. If your contracts also touch the United States, the tiering is EU-specific, compared in eIDAS versus the ESIGN Act.
The evidence you keep at any level
Whichever level you choose, the record around the signature is what you reach for if the document is questioned. Per signer: when they were notified, first opened the document, last viewed it, how often the link was accessed, when they signed, the IP address and user agent. Plus a SHA-256 hash of the original and the signed document, so a signed PDF can be looked up by its hash to find its envelope. Documents are timestamped, and the envelope is sealed cryptographically once every signer is done.
That does not turn a simple signature into an advanced one. Article 26 sets that bar, and audit logging is not among its four requirements. It builds the case you would otherwise assemble under pressure, which is the work a higher level moves off your desk.
What the EU Digital Identity Wallet changes
Regulation (EU) 2024/1183 amended eIDAS to establish the European Digital Identity Framework. Member States are to make EU Digital Identity Wallets available to citizens, and once onboarded to a wallet a natural person will be able to sign with a qualified electronic signature free of charge for non-professional purposes. The rollout is under way.
It does not change the legal effect of the three levels. Article 25 reads the same before and after. What changes is availability: the cost and effort of reaching a qualified signature drops for individuals with a wallet.
That moves the friction input, and only that one. The legal analysis does not shift. A qualified signature never depended on a national eID anyway, which is a separate misconception.
Frequently asked questions
Is a simple electronic signature legally valid? Yes. Article 25(1) of eIDAS says an electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic or not qualified. The difference between the levels is evidential weight and who carries the burden if it is disputed, not validity.
When is a qualified electronic signature required? When the applicable national law imposes a written form for that contract type, since Article 25(2) gives a qualified electronic signature the equivalent legal effect of a handwritten signature. Beyond that it is a risk decision, not a legal requirement. Form requirements are national and vary by contract type, so the rule depends on the governing law.
What is the difference between an advanced and a simple electronic signature? An advanced signature meets the four requirements in Article 26: uniquely linked to the signatory, capable of identifying the signatory, created using signature creation data the signatory can use under sole control with a high level of confidence, and linked to the signed data so any later change is detectable. A simple signature is any electronic data used by the signatory to sign, under Article 3(10).
Can different signers use different signature levels on the same document? Yes. The level is set per signer when the envelope is created, and different levels can coexist in one envelope. Whether that is appropriate depends on what each signature is doing and on the governing law. A stronger signature on the binding commitment and a simpler one on an acknowledgement is a common structure.
Will the EU Digital Identity Wallet make qualified signatures the default? It changes availability, not law. Regulation (EU) 2024/1183 provides for wallets to be made available and for a natural person onboarded to a wallet to sign with a qualified electronic signature free of charge for non-professional purposes. The legal effect of the three levels is unchanged.
This is general information about Regulation (EU) No 910/2014, not legal advice on a specific contract or jurisdiction.
Working out which level each of your document types needs? Talk to us.

