A qualified electronic signature (QES) is the highest level of electronic signature recognised under the eIDAS regulation. It carries the same legal effect as a handwritten signature across all EU Member States and is the only signature type that automatically achieves this equivalence by law. Under eIDAS 2.0, the rules around how QES is created and accepted are being updated to reflect new technologies, including the European Digital Identity Wallet. This article walks through the key questions organizations need to understand about qualified electronic signatures today.

How does a qualified electronic signature differ from other eIDAS signature types?

A qualified electronic signature is the strongest of the three signature types defined under eIDAS. The other two are simple electronic signatures (SES) and advanced electronic signatures (AdES). The key difference is the level of identity assurance, the technical requirements, and the legal presumption attached to each type.

A simple electronic signature is essentially any electronic indication of intent, such as typing your name in a form or clicking an “I agree” button. It offers minimal security and limited legal standing. An advanced electronic signature goes further: it must be uniquely linked to the signer, capable of identifying them, and created using data under the signer’s sole control. However, it does not automatically carry the same legal weight as a handwritten signature across all Member States.

A qualified electronic signature adds one more layer on top of AdES: it must be created using a qualified electronic signature creation device (QSCD) and based on a qualified certificate issued by a Qualified Trust Service Provider (QTSP) listed on an EU Trusted List. This combination is what gives QES its automatic legal equivalence to a handwritten signature throughout the EU.

What legal value does a qualified electronic signature carry under eIDAS 2.0?

Under the eIDAS regulation, a qualified electronic signature has the same legal effect as a handwritten signature in all EU Member States. This is not a presumption that can be challenged on technical grounds alone. No Member State may refuse to recognise a QES that meets the regulation’s requirements, which makes it uniquely powerful for cross-border transactions.

This legal equivalence matters enormously in practice. It means that a contract signed with a QES in the Netherlands is legally binding in Germany, France, or any other EU country without requiring additional authentication steps or local notarisation. For organizations operating across borders, this removes a significant source of legal uncertainty.

eIDAS 2.0 reinforces and extends this framework. It does not weaken the legal standing of QES but broadens the ecosystem in which it can be used, particularly by connecting it to the European Digital Identity Wallet. The regulation also strengthens oversight of Qualified Trust Service Providers, which further supports the reliability and enforceability of QES-based transactions.

What are the requirements for issuing a qualified electronic signature?

Issuing a qualified electronic signature requires meeting a specific set of technical and regulatory conditions. Three elements must be in place: a qualified certificate, a qualified electronic signature creation device, and a Qualified Trust Service Provider to issue the certificate.

  • Qualified certificate: This is a digital certificate that binds the signer’s identity to a cryptographic key. It must be issued by a QTSP that appears on an EU Trusted List and must meet the requirements set out in eIDAS, including verification of the certificate holder’s identity.
  • Qualified electronic signature creation device (QSCD): This is a secure hardware or software environment in which the private signing key is stored and used. The key must never leave the QSCD in a usable form. Common examples include hardware security modules (HSMs) and smart cards.
  • Identity verification: Before a qualified certificate can be issued, the identity of the signer must be verified to a high level of assurance. This typically involves face-to-face verification or an equivalent remote process approved under eIDAS.
  • Qualified Trust Service Provider (QTSP): Only a QTSP that is officially supervised and listed on a national Trusted List may issue qualified certificates. These providers are subject to regular audits and conformity assessments.

Under eIDAS 2.0, remote management of QSCDs is being formally recognised as a qualified trust service. This means that cloud-based signing solutions can now qualify as QSCDs under certain conditions, making QES more accessible without reducing its security guarantees.

Which use cases and documents require a qualified electronic signature?

Not every document requires a qualified electronic signature, but certain legal and regulatory contexts either require it explicitly or make it the most appropriate choice. QES is typically required or strongly recommended when the stakes are high, the legal enforceability must be unambiguous, or cross-border recognition is essential.

Common use cases where QES is either required or highly recommended include:

  1. Financial services contracts: Opening accounts, loan agreements, and investment mandates often require the highest level of signature assurance to meet KYC, AML, and PSD2 obligations.
  2. Healthcare and pharmaceutical consent: Informed consent documents, clinical trial agreements, and prescription authorisations in regulated settings benefit from QES to ensure legal validity and auditability.
  3. Government and public sector transactions: Applications for official documents, procurement contracts, and public service agreements increasingly require QES, particularly in cross-border contexts.
  4. Employment contracts: In several EU Member States, employment agreements must be signed with a legally equivalent signature, making QES the appropriate choice for remote hiring.
  5. Real estate and notarial acts: Some jurisdictions require QES or an equivalent for property transactions, especially when conducted digitally.

For organizations in financial services or healthcare, understanding exactly where QES is required versus where a lower signature type suffices is an important part of compliance planning. Using QES where it is not required adds unnecessary friction, while using a lower-grade signature where QES is required creates legal risk.

How does eIDAS 2.0 change the way qualified electronic signatures are created?

eIDAS 2.0 introduces two significant changes to how qualified electronic signatures are created. First, it formally recognises remote signing using cloud-based QSCDs as a qualified trust service. Second, it integrates QES creation with the European Digital Identity Wallet, enabling citizens and businesses to sign documents directly from their wallet.

Under the original eIDAS regulation, QSCDs were typically physical devices such as smart cards or USB tokens. While remote signing was technically possible, it existed in a grey area. eIDAS 2.0 resolves this by explicitly classifying the remote management of QSCDs as a qualified trust service. This means a QTSP can now host and manage a signing key on behalf of a user in a certified cloud environment, and the resulting signature still qualifies as a QES.

The connection to the EUDI Wallet is equally significant. Citizens will be able to use their wallet to authenticate themselves and trigger a qualified signature without needing a separate smart card or token. For organizations, this means that the user experience of signing with QES can become much smoother, while the legal and technical guarantees remain fully intact. The wallet essentially becomes the interface through which identity is verified and signatures are authorised.

These changes lower the barrier to adoption significantly. Cloud-based QES solutions are easier to integrate into digital workflows, and wallet-based signing reduces the need for users to manage physical devices. Organizations exploring digital identity solutions should factor these changes into their technology planning now.

How should organizations prepare to accept and issue qualified electronic signatures?

Organizations should start preparing for qualified electronic signatures by mapping their existing signature workflows against eIDAS requirements, identifying where QES is legally required, and selecting a Qualified Trust Service Provider that fits their technical and compliance needs.

A practical preparation roadmap looks like this:

  1. Audit your current signing processes: Identify which documents and workflows use electronic signatures today and assess whether the current signature type meets legal requirements.
  2. Determine where QES is required: Work with legal and compliance teams to clarify which transactions require QES under applicable law, sector regulation, or contractual obligation.
  3. Select a Qualified Trust Service Provider: Choose a QTSP that is listed on an EU Trusted List and whose services align with your technical infrastructure, volume requirements, and sector-specific needs.
  4. Plan for EUDI Wallet integration: As the wallet rolls out across Member States, organizations should assess how their signing workflows will connect with wallet-based authentication and signature initiation.
  5. Update your audit and record-keeping processes: QES requires a complete and long-term verifiable audit trail. Ensure your systems can store and retrieve signed documents in a way that preserves their legal validity over time.
  6. Train relevant teams: Compliance, legal, IT, and customer-facing teams all need to understand what QES means, when to use it, and how to handle it in practice.

Organizations in government and other regulated sectors should also monitor national transposition of eIDAS 2.0, as Member States may introduce sector-specific requirements on top of the EU baseline. Staying close to supervisory guidance and industry working groups will help organizations stay ahead of changes rather than react to them.

How TrustTech helps with qualified electronic signatures

TrustTech supports organizations at every stage of their qualified electronic signature journey, from initial compliance assessment to full production deployment. Whether you need to issue QES, accept it from counterparties, or integrate it into a broader digital identity workflow, TrustTech provides the infrastructure and expertise to make it work.

Specifically, TrustTech helps organizations with:

  • Identity-linked signing: Every qualified signature issued through TrustTech’s platform is cryptographically tied to a verified identity, creating a complete and auditable record of who signed what and when.
  • eIDAS 2.0 readiness: TrustTech’s platform is built to align with eIDAS 2.0 requirements, including support for remote QSCD management and EUDI Wallet integration as it becomes available.
  • Reusable compliance: Rather than repeating identity verification for every signature event, TrustTech enables organizations to reuse verified identity data across workflows, reducing friction without compromising assurance.
  • Sector-specific implementation: TrustTech works with organizations in finance, healthcare, government, and other regulated sectors, adapting QES workflows to meet the specific legal and operational requirements of each industry.
  • End-to-end support: From first verification to final signature, TrustTech connects every step in a single trusted platform, with an implementation approach designed to reach production in less than five months.

If your organization is ready to move from understanding qualified electronic signatures to implementing them, get in touch with TrustTech to discuss your specific situation and find out how we can help you get there.