Europe grades its signatures. The US does not.
If you have only ever signed documents under US law, the European approach can be surprising. In the United States, the ESIGN Act and UETA take a broad, technology-neutral view: an electronic signature is more or less any electronic mark made with intent to sign, and it is generally valid without the law caring much how it was produced. Europe takes a different path.
Under the EU's eIDAS Regulation — Regulation (EU) No 910/2014, the framework behind international e-signing in Europe — electronic signatures come in three defined legal tiers, each with escalating technical requirements and escalating legal weight. Understanding those three levels, what separates them, and when each is appropriate is essential for anyone signing with European counterparties. This article walks through all three. It is general guidance, not legal advice — the correct signature level for a given transaction is fact- and jurisdiction-specific, so confirm high-stakes cases with qualified counsel in the relevant country.
The three tiers at a glance
eIDAS defines a ladder:
- Simple Electronic Signature (SES) — the baseline. Any data in electronic form attached to or logically associated with other data, used by the signatory to sign. A typed name, a scanned signature image, a checkbox, or a click can qualify.
- Advanced Electronic Signature (AES) — a signature that meets four specific technical requirements around identity and integrity.
- Qualified Electronic Signature (QES) — an AES created with a qualified signature-creation device and backed by a qualified certificate from an accredited trust service provider. This is the top tier.
The legal payoff climbs with the tier, but so does the friction. The art is matching the level to the transaction, not reflexively reaching for the highest one.
SES: valid, but weighted by evidence
A Simple Electronic Signature is the entry level, and it is the one most everyday e-signing produces. Crucially, eIDAS says a signature cannot be denied legal effect solely because it is electronic or because it is "only" an SES. An SES is admissible and can be perfectly enforceable.
What an SES lacks is any built-in guarantee about who signed or whether the document changed afterward. Its evidentiary strength therefore depends entirely on the surrounding record — the audit trail, timestamps, and tamper-evident certificate the signing platform captures. A well-audited SES is genuinely strong; a bare typed name with no supporting record is weak. In practice, a good e-signature platform elevates an SES with exactly the kind of evidence — IP, device, trusted timestamps, consent capture, and an integrity seal — that makes it hold up if challenged.
SES is appropriate for the vast bulk of commercial documents: sales agreements, NDAs, order forms, internal approvals, and most B2B contracts where the parties know each other and the relationship itself supplies context about identity.
AES: identity and integrity, built in
An Advanced Electronic Signature raises the bar with four requirements that eIDAS spells out precisely. To be an AES, the signature must be:
- Uniquely linked to the signatory — tied to one specific person, not a shared credential.
- Capable of identifying the signatory — the mechanism must be able to establish who signed.
- Created using electronic signature creation data that the signatory can, with a high level of confidence, use under their sole control — typically a private key or credential only that person holds.
- Linked to the signed data in such a way that any subsequent change in the data is detectable — an integrity guarantee, usually delivered cryptographically.
Notice what these four requirements describe: essentially a digital signature using public-key cryptography, where the signer holds a private key and the document carries a cryptographic seal that breaks if the file is altered. AES is stronger than SES because identity and integrity are baked into the signature itself rather than reconstructed from an audit log.
AES suits higher-value or higher-risk transactions where you want more assurance of the signer's identity than a relationship alone provides — significant financial agreements, certain regulated documents, and dealings with parties you do not otherwise know well. It does not require an accredited certificate, which keeps it more flexible than the top tier.
QES: the legal equivalent of ink, across the EU
A Qualified Electronic Signature is an AES with two additional, strictly regulated components:
- It is created using a Qualified Signature Creation Device (QSCD) — certified secure hardware or an equivalently certified remote service that protects the signing key.
- It is based on a qualified certificate issued by a Qualified Trust Service Provider (QTSP) that appears on an EU member state's official trusted list, after that provider has verified the signer's identity to a high standard.
The reward for meeting this bar is the strongest statement in the whole regulation: a QES has the same legal effect as a handwritten signature, and it is granted this equivalence automatically across every EU member state. A QES executed under one country's QTSP must be recognized in all the others. No other tier gets this guarantee.
That equivalence is why QES exists. Certain transactions in certain member states are required by national law to carry a handwritten (or equivalent) signature — some real-estate transfers, certain notarial acts, particular employment or consumer documents, specific corporate filings. For those, only a QES will do, because only a QES is legally deemed handwriting's equal. QES also shifts the practical burden: because the signer's identity was verified by an accredited provider and the key lived in certified hardware, it is far harder for a signer to later disown a QES than an SES.
The catch: QES has real friction
QES is powerful precisely because it is demanding, and that demand is felt by the signer. Obtaining a qualified certificate means the signer must undergo identity verification by a QTSP — historically in person, now often via qualified remote identification such as a supervised video session. The signer needs access to a QSCD, whether physical (a smart card and reader) or a remote signing service. This is meaningful onboarding friction, and imposing it on a counterparty who does not already hold a qualified certificate can stall a deal or lose a signer entirely.
That is why the honest guidance is: do not default to QES. Use it where national law actually requires a handwritten-equivalent signature, or where the value and risk of the transaction genuinely justify the strongest possible non-repudiation. For the everyday flow of commercial contracts with European parties, a well-audited SES — or an AES where you want built-in identity assurance — is both legally sufficient and dramatically easier to complete. Over-engineering the signature level is a real and common mistake; it adds cost and drop-off without adding enforceability you needed.
How to choose the right level
A workable decision process:
- Start by asking whether any law mandates a specific form. Is this a document type that a member state requires to be handwritten or notarized? If yes, you are likely in QES territory — confirm with local counsel, and remember that some documents sit outside ordinary e-signing entirely.
- If no form is mandated, weigh value and counterparty risk. Routine B2B agreement with a known party? A well-audited SES is appropriate. High-value deal, unfamiliar counterparty, or elevated fraud risk? Consider AES for built-in identity and integrity.
- Match identity verification to the tier. SES pairs well with platform-level identity verification such as SMS one-time codes; AES and QES rely on cryptographic credentials and, for QES, accredited identity proofing.
- Reserve QES for when equivalence to handwriting is genuinely required. Do not pay its friction cost for transactions that do not need it.
Looking ahead: eIDAS 2.0
The framework is evolving. The eIDAS 2.0 reform and the EU Digital Identity Wallet aim to make high-assurance identity — and, with it, easier access to qualified signatures — available to every EU resident through a government-backed wallet on their phone. If that vision lands, the historical friction of QES could fall substantially, because millions of people would carry a ready means of qualified identification. That would not change the three-tier structure, but it could shift where the practical line between "worth it" and "too much friction" sits.
The bottom line
eIDAS grades electronic signatures into three tiers, and the distinction is not academic — it determines legal weight and the effort a signer must expend. SES is the flexible baseline, valid and enforceable, with strength that comes from the audit record around it. AES bakes identity and integrity into the signature itself through cryptography. QES adds accredited identity proofing and certified hardware to earn the one prize the others cannot: automatic equivalence to a handwritten signature across the entire EU.
The skill is not reaching for the highest tier — it is choosing the right tier. Use QES where the law demands handwriting's equal; use a well-audited SES or an AES for nearly everything else. Get that judgment right and you sign with European counterparties on solid legal footing without drowning routine deals in unnecessary friction. See how Hitt Hosting Sign captures evidence or start free.
This article is general guidance on eIDAS signature levels, not legal advice. Whether a transaction requires SES, AES, or QES depends on the document type and the member state; confirm high-stakes cases with qualified counsel in the relevant country.