Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)
Magazine

How to Get a PDF Signed Online

Product & Practice

How to Get a PDF Signed Online

A PDF can be sent, signed and archived digitally in a few structured steps. The key is choosing the appropriate signature level, configuring the workflow correctly and retaining complete evidence.

August 10, 2026

What does it mean to get a PDF signed online?

Getting a PDF signed online means making the document available through an electronic signature platform and inviting one or more people to sign it electronically. Each signer opens a protected link, reviews the document and provides their signature. Once the process is complete, the parties usually receive the signed PDF together with supporting evidence of the transaction.

This is not the same as simply inserting a scanned image of a handwritten signature. An image may display a person’s name or mark, but by itself it provides limited evidence of who inserted it or whether the document was changed afterwards. A structured signing process can record identity attributes, timestamps, consent and document versions. Depending on the signature level, it may also use cryptographic methods and qualified certificates.

Step 1: Review the document and requirements

Before uploading the PDF, determine what is being signed, who must sign it and which legal or internal requirements apply. Useful questions include:

  • Is the PDF the final version?
  • Which people or organisations are parties to the agreement?
  • Should everyone sign at the same time or in a defined order?
  • Are there statutory form requirements or contractual requirements?
  • Does a signer need to be identified to a particular standard?
  • Which evidence may be required for an audit, compliance review or dispute?

Electronic processes are not equally suitable for every transaction. Some declarations may be subject to a statutory written form, notarisation or other specific requirements. Whether an electronic signature is permitted, and which level is appropriate, should therefore be assessed for the particular document and relevant jurisdiction.

Step 2: Choose the appropriate signature level

The eIDAS Regulation distinguishes three principal levels of electronic signature.

  • Simple electronic signature (SES): This may include a confirmed click, a typed name or a drawn signature. It is often used for lower-risk transactions without specific form requirements.
  • Advanced electronic signature (AdES): It must be uniquely linked to the signer, be capable of identifying the signer, be created under the signer’s control and make subsequent changes detectable.
  • Qualified electronic signature (QES): It is based on a qualified certificate and created using a qualified signature creation device. Under eIDAS, it has the equivalent legal effect of a handwritten signature.

Under eIDAS, an electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic or does not meet the requirements of a QES. This does not mean that every signature level is sufficient for every agreement. The choice should reflect applicable form requirements, potential impact, identity assurance and evidential needs.

For example, an SES may be appropriate for approving internal meeting minutes. An AdES may be considered for a commercially significant contract. Where legislation requires a written form and does not exclude an electronic equivalent, a QES may be necessary. These examples do not replace an assessment of the individual case.

Step 3: Prepare the PDF for signing

The uploaded PDF should contain the final version of the document. Changes made after the signing process has started will often require a new transaction so that every party signs the same content.

Before sending the document, check that:

  • the file name, contracting parties and attachments are correct;
  • no pages are missing or in the wrong order;
  • empty fields and internal comments have been removed;
  • the document is readable and, where possible, accessible;
  • attachments, terms and privacy information are clearly associated with the agreement;
  • existing PDF password protection does not prevent processing or signing.

Depending on the platform, related files can be sent as a package or merged into a single PDF in advance. In either case, signers must be able to understand exactly which content they are accepting.

Step 4: Upload the PDF and place fields

After uploading the document, add the recipients and place the required fields in the PDF. Common fields include:

  • signature;
  • name and job title;
  • date;
  • company name;
  • selection or confirmation boxes;
  • free-text fields for agreed information.

Every required field should be assigned to the correct person. Otherwise, an internal buyer might accidentally complete a field intended for the supplier. Fields should also be positioned so that they do not cover contractual text, page numbers or attachments.

For multiple signers, decide whether invitations should be sent in parallel or sequentially. A defined order is useful when one person’s approval depends on a previous signature. A parallel workflow is usually simpler when the order has no business significance.

Step 5: Authenticate the recipients

An email address is often the starting point for an invitation, but it is not necessarily strong evidence of identity. Depending on the signature level and risk, additional methods may be used, such as a one-time code sent through a separate channel, an identity document, an electronic identification method or a process supported by a trust service provider.

A QES requires the signer to be identified before the qualified certificate is issued or used. The exact process depends on the qualified trust service provider and the identification methods it supports.

Additional checks can strengthen the evidence associated with a transaction, but they also create more effort and involve more personal data. The strictest available method should therefore not be selected automatically. Authentication should be proportionate to the purpose and risk.

Step 6: Send the invitation

The invitation should explain clearly and concisely:

  • who is sending the document;
  • what the document concerns;
  • when the signature is expected;
  • whom the recipient can contact with questions;
  • whether additional authentication is required.

Confidential contract details do not necessarily belong in the email itself. Emails can be forwarded or displayed in device notifications. Access to the document should take place through a protected connection with appropriate permissions.

For example, a company sends a supplier agreement to its internal head of procurement first. Once that person has approved and signed it, the supplier’s authorised representative automatically receives an invitation. The transaction is completed only after both signatures have been provided.

Step 7: Complete the signature

The invited person opens the link, completes any required authentication and reviews the document. They then fill in the assigned fields and confirm the signature. Before completion, the interface should make it clear that the person is making a legally relevant declaration.

A well-designed process allows the signer to view the complete document and, where appropriate, download it before signing. Required fields, consent statements and the final confirmation should be clearly separated. If the signer declines, recording a reason can help the sender determine the next step.

Step 8: Track status and manage reminders

During the transaction, the platform will typically show whether an invitation has been sent, opened, signed or declined. Automated reminders can help move an incomplete process forward, but their frequency and timing should be appropriate.

If a contact address changes or another authorised signer is required, the recipient should be replaced through a controlled process. An existing signature must not be silently associated with a changed document or a different person. Material changes will generally require a new signing transaction.

Step 9: Retain the signed PDF and audit trail

Once all parties have signed, at least the signed PDF and its supporting evidence should be downloaded or transferred to the designated archive. An audit trail may include:

  • a document identifier or hash value;
  • participants and contact details used in the process;
  • sending, opening and signing timestamps;
  • authentication and confirmation steps;
  • the signature level used;
  • status changes and declined actions.

The audit trail is not automatically the electronic signature itself. It supplements the signed document with evidence about the process. For cryptographically signed PDFs, validation can also indicate whether a signature is valid and whether the document was modified after signing.

The completed file should be opened and checked before it is archived. Visible signature fields alone do not prove that cryptographic validation succeeded. PDF validation software may also require access to certificate status information and relevant trust lists.

Step 10: Address data protection and retention

An electronic signing process involves personal data, including names, email addresses, signature data, timestamps and, in some cases, identity evidence. Organisations should determine which data is necessary, how long it will be retained and who is permitted to access it.

Relevant considerations when selecting and configuring a platform include:

  • a data processing agreement where required;
  • storage locations and subprocessors;
  • technical and organisational security measures;
  • role-based permissions and multi-factor authentication;
  • deletion and retention policies;
  • export options for documents and evidence;
  • safeguards for international data transfers.

Contracts and evidence should not remain in a user account indefinitely merely because the platform allows it. Retention should reflect the purpose of processing and applicable legal or organisational obligations. At the same time, evidence should not be deleted prematurely if it is still required to document the transaction.

Access also needs to be reviewed over time. Former employees, external advisers and temporary project members should not retain permissions once they no longer need them. Central archiving and defined ownership reduce the risk of completed contracts existing only in an individual user account.

Common mistakes to avoid

Many problems arise during preparation rather than during the act of signing. Common examples include choosing a signature level without reviewing the requirements, assigning fields to the wrong person, using ambiguous recipient details, omitting attachments and changing the PDF after invitations have been sent. Keeping only a signature image without supporting process evidence can also make later attribution difficult.

Another mistake is treating every document in the same way. A routine acknowledgement, a supplier contract and a document subject to a statutory form requirement may need different workflows. Templates can improve consistency, but their settings should still be reviewed when the purpose, parties or risk changes.

A reliable process therefore combines three elements: a final and understandable document, an appropriate identity and signature method, and traceable archiving. When these points are resolved before the invitation is sent, the PDF can move through the full contract process without printing, scanning or manual media changes.