An advanced electronic signature (AES) is an electronic signature that meets the four requirements set out in Article 26 of the eIDAS Regulation (EU) No 910/2014. In terms of evidential strength an advanced electronic signature (AES) sits between a plain electronic signature and a qualified electronic signature (QES).
What are the four requirements that make a signature “advanced”?
Article 26 sets four tests. A signature that fails any one of them is not an AES, this is regardless of what the vendor calls it in the product name.
| Article 26 requirement | What it requires of your signing flow |
| Uniquely linked to the signatory | Signature creation data tied to one identified person, not a shared account or a generic company credential |
| Capable of identifying the signatory | Signature data that resolves back to a verified identity, usually through a certificate or a provider-held identity record |
| Created under the signatory’s sole control, with a high level of confidence | An authentication step only that person can pass at the moment of signing |
| Linked to the signed data so any subsequent change is detectable | Cryptographic binding to the document, not a pasted image of a signature |
Article 26 is technology neutral. It tells you what the signature must achieve but not which cryptography or identity method to use. In practice, almost every compliant implementation uses public key infrastructure with a hash of the document, because nothing else satisfies the fourth requirement cleanly.
Signer Identification
Identification is the requirement most implementations get wrong, because an email address is not an identity. In order to satisfy Article 26(b), there needs to be evidence that the person holding the credential is who they claim to be, captured before or at the point of signing. That normally means a document check, a biometric face check against the document photo, or a reusable electronic identification (eID) credential issued after an equivalent check.
The failure mode, however, is subtle. A flow that verifies identity once at account creation, then lets anyone with the password sign months later, identifies an account rather than a signatory. If the signature is challenged, you end up defending your password policy instead of the identity.
Sole control of the signature creation data
Sole control means the signatory, and only the signatory, can trigger the signature. Two models are common for this:
- Local keys: The private key lives on a smart card, a USB token, or in the secure element of the signer’s phone. The control is physical.
- Remote signing: The key is held by a trust service provider inside a hardware security module and released only when the signer authenticates. Control is procedural and depends entirely on the strength of that authentication.
Remote signing is where sole control usually breaks. If the one-time passcode goes to a shared inbox, if an administrator can trigger signing on a user’s behalf, or if the authentication step is a single reused password, you no longer have “a high level of confidence” in sole control, and you no longer have an AES.
Tamper Detection
The signature must be linked to the signed data so that any subsequent change is detectable. In practice, the signing service hashes the document, signs the hash with the private key, and embeds the result in the file. Change one character and the recomputed hash stops matching, so validation fails.
This is what separates an AES from a drawn signature image, which proves nothing about the content it sits on. Keep the signed artefact rather than a re-exported copy, because flattening or re-processing a PDF can strip the signature structure and leave you unable to validate later.
How AES compares with SES and QES
eIDAS defines three tiers. “Simple electronic signature” (SES) is industry shorthand rather than a legal term, and it covers any electronic signature under Article 3(10) that does not meet the Article 26 bar.
| SES | AES | QES | |
| Identity assurance | None required | Signatory identifiable | Identity verified by a qualified trust service provider |
| Certificate | Not required | Not required to be qualified | Qualified certificate required |
| Signing device | None specified | None specified | Qualified signature creation device required |
| Legal effect | Admissible, weight decided by the court | Admissible, stronger evidential position | Equivalent legal effect of a handwritten signature |
| Typical effort to sign | Seconds | Identity check plus authentication | Full qualified onboarding |
The line that matters for a compliance decision is Article 25. No electronic signature can be denied legal effect or admissibility just for being electronic, but only a QES carries automatic equivalence to a handwritten signature. An AES is not automatically equivalent. What it gives you is a much stronger evidential record to put in front of a court or a regulator if the signature is disputed.
How does an Advanced Electronic Signature Work?
Public key infrastructure is used for almost every compliant infrastructure and runs the same five steps, this is regardless of whether the key sits on a smart card or with a remote provider. Following are the steps that define the working of an AES.
- Verification of the Signer, identity is established by a document and biometric check or an existing eID credential, which is then bound to the signing credential.
- The signature creation data must be issued, a key pair is generated for that person, it can be held on their own device or a provider’s hardware security module.
- Authentication at signing is also a crucial step. The signer passes a step which can only be cleared by them.
- Hash and sign, the service hashes the document and that hash is signed with the private key, it binds the signature to that exact content.
- Packaging and logging is the final step for the functioning of an AES. The signature, certificate and time stamp go into the file, with an audit trail of the identity and authentication evidence.
Where is AES used?
AES is the default choice where you need defensible proof of who signed, but the law does not demand a qualified signature:
- Account opening and customer agreements in banking, lending, and insurance
- Employment contracts, NDAs, and supplier agreements
- Loan documentation, leases, and mandates where the counterparty may later dispute the terms
- Cross-border business contracts inside the EU, where a single AES standard beats reconciling national rules
- Public sector online services, where Commission Implementing Regulation (EU) 2026/248 sets the formats of advanced electronic signatures that public sector bodies must recognise, replacing Commission Implementing Decision (EU) 2015/1506
The residual risk is repudiation. An AES shifts the argument from “did you sign this” to “how do you know it was me”, so the identity evidence captured at signing time is what you will actually be defending.
Frequently Asked Questions
Is an advanced electronic signature legally binding?
Yes, in the sense that Article 25(1) prevents any electronic signature from being denied legal effect for being electronic. Only a qualified electronic signature has automatic equivalence to a handwritten signature.
Does an AES require a digital certificate?
Not a qualified one. Article 26 does not mandate a certificate at all, but a certificate is the usual way to satisfy unique linkage and signatory identification.
When is an Advanced Electronic Signature Required?
eIDAS does not require an AES for any transaction. The requirement comes from national or sectoral law. An AES is required when the document carries real repudiation risk like credit agreements or mandates or when a public body or counterparty specifies it.
What is the difference between AES and QES?
A QES is an AES created on a qualified signature creation device using a qualified certificate issued by a qualified trust service provider. That extra layer is what earns it handwritten-signature equivalence.
Who verifies the signer's identity for an AES?
eIDAS does not prescribe a method, so the responsibility sits with you or your signing provider. Common approaches are document and biometric verification at signing, or reuse of an existing verified eID credential.
Can an advanced electronic signature be used across the EU?
Yes. eIDAS applies directly in all member states, so an AES created in one member state is recognised as an AES elsewhere in the EU.
















