Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)
Magazine

Advanced Electronic Signatures: When Are They Useful?

Product & Practice

Advanced Electronic Signatures: When Are They Useful?

An advanced electronic signature combines traceable identification with document integrity. Whether it is appropriate depends on formal requirements, evidentiary risk and the process context.

August 10, 2026

The advanced electronic signature, or AES, is often described as the middle ground between a simple and a qualified electronic signature. What matters, however, is not the label used by a provider. The relevant questions are whether the procedure meets the requirements of the eIDAS Regulation and whether it is proportionate to the risks of the transaction.

An AES can create a traceable link between a person’s identity, their intent to sign and the integrity of a document. It does not automatically satisfy statutory form requirements, and it does not have the same expressly defined legal effect as a qualified electronic signature.

What an AES must provide under eIDAS

Article 26 of the eIDAS Regulation sets out four requirements. An advanced electronic signature must be:

  • uniquely linked to the signatory,
  • capable of identifying the signatory,
  • created using electronic signature creation data that the signatory can, with a high level of confidence, use under their sole control,
  • linked to the signed data in such a way that any subsequent change is detectable.

The Regulation does not prescribe a single technology for meeting these requirements. An AES may, for example, be based on a personal certificate. A platform-based process may also qualify if it combines reliable identification, personal authentication, cryptographic document binding and a traceable audit trail.

A signature does not automatically become an AES merely because a software interface describes it as “advanced.” The complete process must be assessed: How was the person identified? Who could use the signature credentials? How is the signature bound to the specific document? What evidence remains available if the signature is later disputed?

How AES differs from simple and qualified signatures

A simple electronic signature covers many everyday methods, including a typed name, an inserted image of a handwritten signature or a click on a confirmation button. Such methods can have legal effect, but they do not necessarily provide strong evidence of identity or document integrity.

An AES adds stricter requirements for attribution, control and the detection of changes. Its evidentiary weight nevertheless depends on the technical and organisational implementation and on the circumstances of the individual case.

A qualified electronic signature, or QES, is an advanced signature that meets additional conditions. It must be based on a qualified certificate and created using a qualified electronic signature creation device. Under eIDAS, only a QES is expressly given the legal effect equivalent to a handwritten signature.

An electronic signature may not be denied legal effect or admissibility as evidence solely because it is electronic or does not meet the requirements of a QES. This rule does not mean that simple, advanced and qualified signatures carry identical evidentiary weight in a dispute.

When an AES can be appropriate

An AES is particularly relevant for documents that are not subject to a mandatory statutory form but for which a simple signature offers insufficient evidence given the value, duration or potential for dispute.

Possible use cases include:

  • B2B agreements without special form requirements: Framework agreements, project contracts and supply agreements may require reliable evidence of who signed which version.
  • Non-disclosure agreements: An AES can document attribution and the integrity of the agreed terms more effectively than an inserted signature image.
  • Offers and order confirmations: Stronger evidence may be appropriate where the order value is material or the scope of services is individually negotiated.
  • Approvals with external consequences: Examples include acceptances, authorisations and declarations that may later be challenged.
  • Long-term agreements: The longer a document remains relevant, the more important exportable evidence and a verifiable link between the signature and the final version become.

Consider two companies entering into a negotiated consultancy agreement with substantial payment and liability provisions. If no statutory form applies, an AES may be more appropriate than a basic click-to-sign process, provided identification, authentication and document binding are implemented properly.

When a simple electronic signature may be sufficient

Not every transaction needs an AES. A simple electronic signature may be proportionate for low-risk processes, particularly where the parties are already reliably authenticated within a protected system and the transaction is adequately recorded.

Examples include standard confirmations, low-risk internal acknowledgements or orders with limited consequences. Even in these cases, the intent to sign, document version, time and relevant process events should remain traceable.

Excessive identity checks can create unnecessary friction and lead to the collection of additional personal data. The signature level should therefore be selected on the basis of risk rather than automatically maximised.

When a QES or another method is required

An AES is not sufficient where a transaction is subject to a form requirement that can only be met by a handwritten signature or, where permitted, by an electronic form using a QES. Some laws exclude electronic form entirely.

A well-known German example is the termination of employment. Section 623 of the German Civil Code requires written form for termination notices and termination agreements and excludes electronic form. Neither an AES nor a QES replaces the handwritten signature in that situation.

The applicable rules should also be checked carefully for other formal declarations, consumer transactions, guarantees and cross-border matters. Contractual clauses, sector-specific rules or a counterparty’s policies may impose additional requirements. Legal assessment of the individual case may be appropriate where the position is unclear.

A QES can also be selected without a statutory requirement where the identity risk or likelihood of dispute is especially high. A higher signature level does not, however, verify a representative’s authority or confirm that the contract terms are valid.

Criteria for choosing the signature level

A structured decision can be based on the following questions:

| Criterion | Key question |

|---|---|

| Formal requirement | Does legislation or the contract require a particular form? |

| Identity risk | What would be the impact if the wrong person signed? |

| Risk of denial | How likely is the signatory to dispute the signature later? |

| Economic significance | What financial or operational consequences does the document have? |

| Retention period | How long must the signature and evidence remain verifiable? |

| User context | Has the person already been reliably identified and authenticated? |

| Data protection | Which personal data are needed for identification and evidence? |

An AES is particularly plausible where no QES requirement exists but a simple signature does not provide sufficient attribution and integrity protection.

Technical and organisational implementation

A reliable AES involves more than a visible signature field in a PDF. At a minimum, the following aspects should be considered when selecting and configuring a process:

  1. Identification: The process must be able to explain how the person’s identity was established. The method should be proportionate to the risk.
  2. Personal authentication: A link sent by email does not, by itself, prove who signed if it can be forwarded. Additional factors can strengthen attribution.
  3. Document binding: Hash values and cryptographic signatures should make later modifications detectable.
  4. Intent to sign: The interface should clearly show which document is being signed and the effect of the action.
  5. Audit trail: Events such as delivery, authentication, viewing, consent and completion should be recorded in a traceable manner.
  6. Export and validation: The signed document, certificate information and supporting evidence should be retainable outside the platform and, where possible, independently verifiable.
  7. Permissions: Roles, authority to represent an organisation and internal approval rules must be addressed organisationally.

A timestamp can provide additional evidence of time and integrity. It does not automatically turn a simple or advanced signature into a QES.

Address data protection from the outset

AES processes commonly involve names, contact details, IP addresses, authentication information and technical logs. Under the GDPR, the process should collect only the data required for identification, execution and evidence.

Relevant issues include the legal basis, retention periods, deletion procedures, access controls, processor agreements and possible international data transfers. If identity documents or biometric characteristics are used, necessity and the required level of protection need particularly careful assessment.

Data protection and evidentiary requirements are not inherently contradictory. A defined evidence policy helps avoid both insufficient records and indefinite retention of personal data.

A risk-based choice rather than a default

An AES is useful when a declaration should be reliably attributed to a person, the document must be protected against undetected changes and the process may need to be reconstructed later, while neither the law nor the risk requires a QES.

The decision should therefore start with the document rather than a software feature: Which formal rules apply, what risks exist and what evidence would be needed in a dispute? Only then can an organisation determine whether a simple, advanced or qualified electronic signature—or a handwritten signature—provides the appropriate level.