PixasignUK Start free trial
Standards, explained

Simple, advanced and qualified electronic signatures in the UK

Three tiers, one regulation, and a great deal of marketing built on top of them. What separates an advanced electronic signature from a qualified one is precise and written down, and mostly not what vendors imply it is.

Pixacomms Ltd, Cardiff · Updated September 2026

If somebody has asked whether your e-signatures are “advanced” or “qualified”, they are using terms with legal definitions rather than marketing ones. This page sets out where the three tiers come from, what each actually requires, which one a UK business needs, and what the higher tier costs in money and in friction.

Where the three tiers come from

All three are defined in the eIDAS Regulation — Regulation (EU) No 910/2014 on electronic identification and trust services — retained in UK law after the transition period and amended by the Electronic Identification and Trust Services for Electronic Transactions (Amendment etc.) (EU Exit) Regulations 2019. What remains in force here is usually called the UK eIDAS Regulation, and it is readable on legislation.gov.uk with the UK amendments marked. Alongside it sits section 7 of the Electronic Communications Act 2000, which makes an electronic signature admissible in evidence as to the authenticity or integrity of a communication. Neither instrument tells a UK business to use a particular tier.

The three eIDAS electronic signature tiers compared
TierWhat it isWhat it takes to produceLegal position
Simple (SES) Any data in electronic form used by the signatory to sign A typed name, a tickbox, a finger-drawn squiggle Valid and admissible; proving it was that person is entirely your problem
Advanced (AES) A signature meeting the four requirements of Article 26 Cryptography binding the signature to the signer and to the document Valid and admissible, with far stronger evidence behind it
Qualified (QES) An AES built on a qualified certificate and a qualified device A qualified trust service provider, identity checks, certified hardware Equivalent legal effect of a handwritten signature

Tier one: the simple electronic signature

Article 3(10) defines an electronic signature as “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign”. That is the whole test: a typed name at the bottom of an email qualifies, and so does a tickbox or a finger-drawn mark on a phone. Article 25(1) then says such a signature “shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures”. A simple electronic signature is not second-class law. Its weakness is evidential: if the other side denies signing, you have a screenshot and a story, and they have a denial.

Tier two: what makes a signature “advanced”

An advanced electronic signature is one meeting Article 26, which sets out four requirements. A signature is advanced if:

The fourth is the one cryptography settles: a PAdES signature over the document’s bytes makes any later change to the signed content detectable, which is exactly what is asked for. The first three are about people and process, and that is where the honesty has to start.

There is no such thing as an AES certification eIDAS defines no test, no auditor and no register for advanced electronic signatures. Nobody grants AES status, so nobody holds it. Whether a given signature meets Article 26 is a question a court would answer on the evidence in front of it. A vendor describing itself as “AES certified” is describing something that does not exist.

The awkward requirement is sole control. On a remote signing platform — ours included, and very nearly all of them — the signing key belongs to the platform, not the signer. It is applied on the signer’s instruction after they have been authenticated through a single-use link sent to an address only they should control. Whether that amounts to sole control is an argument supported by evidence, not a property of the maths. It is why the audit trail matters as much as the seal: who opened the document, from what address, when, from which IP and device, hash-chained so that altering one event breaks every event after it.

Tier three: what a qualified signature actually requires

Article 3(12) defines a qualified electronic signature as “an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures”. That is three separate things, and all three must be present.

A qualified trust service provider

Qualified status is granted by the supervisory body, and the provider then appears on the trusted list. Under Article 22 as it now reads in UK law, the Secretary of State must make arrangements for the maintenance and publication of that list. You cannot self-declare into this category: the status is conferred, supervised and revocable.

A qualified certificate

Issued by a qualified provider and meeting Annex I, it identifies a named human being whose identity the provider has verified before issue — in person, or by a method giving equivalent assurance. This is the tier’s real substance: an identity somebody regulated has checked and stands behind.

A qualified signature creation device

Annex II requires that the confidentiality of the signature creation data is reasonably assured, that the data cannot with reasonable assurance be derived, that the signatory can reliably protect it against use by others, and that the device neither alters the data to be signed nor prevents it being shown to the signatory beforehand. Annex II also states that generating or managing signature creation data on the signatory’s behalf may only be done by a qualified trust service provider. In practice that means a smartcard, a USB token, or a certified remote signing service holding the key in hardware.

The one legal difference that matters

It is a single sentence, Article 25(2): “A qualified electronic signature shall have the equivalent legal effect of a handwritten signature.” What that does in a dispute is move the argument. With a QES you do not have to prove the signature was the person’s; whoever says it was not theirs has to make that case. With an AES you bring your evidence and argue it. For most commercial documents the evidence is strong and the argument short, but it is still yours to make.

A cross-border point that is rarely mentioned: Article 25(3), which required every EU member state to recognise a QES issued in any other, was omitted from the UK version by the 2019 EU Exit Regulations. A qualified signature from a UK provider no longer carries an automatic right of recognition across the EU, so a European counterparty asking for a QES will usually want one from a provider on an EU trusted list.

When a UK business genuinely needs QES

Rarely, and almost always because somebody asked. There is no general UK statutory requirement for a qualified electronic signature. The Law Commission’s 2019 report on the electronic execution of documents concluded that an electronic signature is capable in law of being used to execute a document, including a deed, provided the person signing intends to authenticate it and any formalities relating to execution are satisfied — a conclusion about intention and formalities, not about tiers. The formalities are the real constraint: a deed still needs a witness physically present, whatever the signature is made of.

Where AES is the right answer Quotations, engagement letters, supply contracts, NDAs, purchase orders, employment contracts, method statements, consent forms — the ordinary paperwork of a UK business. What you need is a document nobody can alter undetected, a time you did not set yourself, and a record of who did what. An advanced signature with an independent timestamp gives all three, and a qualified one would not make the document more enforceable in an English court.

The cost and the friction, honestly

QES is uncommon because the friction lands on the wrong person. A qualified certificate is issued to an individual human, so every signer — your client, your subcontractor, the director on holiday — has to pass identity verification with a qualified provider before signing anything: a video session or an in-person check, then a certificate, then a device or a remote signing account. There is a per-signer cost and a delay measured in days. For a subcontractor on site at seven in the morning that is not a high bar, it is a closed door, and a QES nobody completes is worth less than an AES everybody does.

The honest counterweight is that AES is weakest exactly where QES is strong. Control of an email inbox is a thinner assertion of identity than a certificate issued after a video check by a supervised provider. If you are dealing with somebody who might later deny signing and has a real incentive to, that gap is the risk you are carrying. Narrow it with evidence — full timeline, IP and approximate location, device, hashes before and after sealing — and where the stakes justify it, use a qualified provider. That is the trade, stated plainly.

Where Pixasign sits

Pixasign produces an advanced electronic signature. It is not a qualified electronic signature, and no setting in the product will make it one. Pixacomms Ltd is not a qualified trust service provider, holds no qualified status and is on no trusted list. We say the same on our security page, because the alternative is a customer hearing it from their own solicitor.

What we do produce: a PAdES B-T signature under ETSI EN 319 142, RSA-3072 with SHA-256, and an RFC 3161 timestamp issued by DigiCert — independent and publicly trusted, so the time on your document is attested by somebody other than us. With it comes an evidence certificate: a hash-chained audit trail, SHA-256 fingerprints before and after sealing, and the signer’s IP, approximate location and device. Anyone can verify a sealed document at our public checker without an account, or with ordinary PDF tools and no reference to us at all.

If AES is what you need

Pixasign is £29, £59 or £99 a month for 50, 200 or 500 documents, VAT included, with unlimited users. Signers never pay and never need an account. If your situation genuinely calls for QES, we will say so rather than sell you this.

See how it works UK-built and UK-run. Nothing hosted in the United States.

Questions

Is an advanced electronic signature legally binding in the UK?

Yes. Under Article 25(1) of the UK eIDAS Regulation an electronic signature cannot be denied legal effect or admissibility simply because it is electronic or because it is not qualified, and section 7 of the Electronic Communications Act 2000 makes electronic signatures admissible as to authenticity and integrity. The Law Commission concluded in 2019 that an electronic signature is capable in law of executing a document, including a deed, where the signatory intends to authenticate it and the relevant formalities are met. What an advanced signature adds over a simple one is the quality of the evidence behind it.

Do I need a qualified electronic signature to sign a contract in the UK?

For ordinary commercial contracts, no. There is no general UK requirement for one, and using one would not make a contract more enforceable in an English court than an advanced signature with good evidence behind it. You need QES when a counterparty, a regulator or a scheme asks for it, or when a national law elsewhere mandates it for that act. Some documents carry their own formalities regardless of tier, such as the physically present witness a deed requires, and HM Land Registry sets its own rules about which deeds it accepts electronically. Check the specific requirement in front of you rather than any supplier’s general assurance, ours included.

What is the practical difference between AES and QES in a dispute?

Where the burden sits. A qualified electronic signature has the equivalent legal effect of a handwritten signature under Article 25(2), so somebody denying it has to make that case against you. With an advanced electronic signature you establish the link between the signature and the person from your evidence: the audit trail, delivery to a controlled address, the timeline, the timestamp and the integrity of the document itself. For most commercial documents that settles it quickly, but it is still your case to make rather than theirs to rebut.

Is Pixasign a qualified trust service provider?

No. Pixacomms Ltd is not a qualified trust service provider and holds no qualified status under the UK eIDAS Regulation, so nothing Pixasign produces is a qualified electronic signature. What it produces is an advanced electronic signature: a PAdES B-T seal using RSA-3072 with SHA-256, an RFC 3161 timestamp issued by DigiCert as an independent authority, and a hash-chained evidence certificate. Our own signing certificate comes from our own certificate authority, which is why Adobe Reader shows a warning rather than a green tick.