Not all electronic signatures are the same. Any company that has tried to submit a digitally signed document to a public administration and been told that the type of signature was not valid knows this. So does any lawyer who has tried to challenge an electronically signed contract and realised that the burden of proof differs depending on the instrument used.
Regulation (EU) No 910/2014 (eIDAS) distinguishes between three types of electronic signature, each with different technical requirements and legal effects. They are not interchangeable levels: they are instruments designed for different contexts, with different procedural consequences in the event of a dispute. In Spain, the legislation adds a fourth category, the advanced electronic signature based on a qualified certificate, which does not exist in the rest of the Union but is the most widely used for procedures involving public administrations.
This article explains exactly how each type differs, what legal effect it has, when the law requires one type or another and what happens in litigation with each type of signature.
Concepts for understanding electronic signatures
Simple electronic signature (SES)
Any electronic data expressing a person’s intention to accept the content of a digital document. It does not require a certificate or identity verification. The burden of proof falls on the party submitting it.
Advanced electronic signature (AES)
A signature that meets the four requirements of Article 26 of the eIDAS Regulation: unique linkage, identification of the signatory, sole control and detection of modifications. It has high evidential value but no automatic legal presumption.
Advanced electronic signature based on a qualified certificate
A Spanish form of advanced electronic signature that uses a qualified certificate but not a QSCD. It is expressly recognised by Laws 39/2015 and 40/2015 and by Royal Decree-Law 6/2023 for procedures involving public administrations and the justice system. It benefits from a rebuttable presumption of authenticity in Spain.
Principle of non-discrimination
Established in Article 25.1 of the eIDAS Regulation. It prevents an electronic signature from being denied legal effect or admissibility as evidence solely because it is electronic or is not qualified.
Rebuttable presumption
A legal presumption that is regarded as true unless evidence to the contrary is provided. In the context of an advanced electronic signature based on a qualified certificate in Spain, this means that the signature is presumed authentic until someone proves otherwise, partially reversing the burden of proof.
The principle governing everything: no signature can be rejected because it is electronic
Before discussing levels, there is a fundamental rule clearly established by Article 25.1 of the eIDAS Regulation: an electronic signature shall not be denied legal effect or admissibility as evidence in legal proceedings solely because it is in electronic form or because it does not meet the requirements for qualified electronic signatures.
This is the principle of non-discrimination. It means that a simple electronic signature, the most basic type of all, has legal effect and may be submitted as evidence in legal proceedings. The difference between the three types is not whether they are valid: it is how much weight they carry, which presumptions they automatically trigger and who must prove what when a dispute arises.
Simple, advanced and qualified electronic signatures are all valid. What changes is the legal certainty provided by each one and who bears the burden of proving its authenticity when it is challenged.
Simple electronic signature (SES): the basic option with limited evidential strength
The simple electronic signature is the most basic form of electronic signature. The eIDAS Regulation does not define it expressly, but instead uses the definition of an electronic signature in Article 3: “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign”.
In essence, it is any electronic method that demonstrates a person’s intention to accept or approve the content of a digital document. The examples are so commonplace that many people do not recognise them as “signatures”: a name at the end of an email, clicking an “I accept” button on a website, scanning an image of a handwritten signature and inserting it into a document, accepting cookie policies or terms and conditions, or signing using a signature link sent by email.
Its main characteristic: convenience in exchange for limited evidential strength
The main advantage of a simple electronic signature is that it is quick and easy to use and does not require complex identity verification methods. Its disadvantage is that, in the event of a legal dispute, the burden of proof falls on the party submitting the signed document: the party presenting it must prove that it is authentic.
To defend its validity in litigation, it is essential to provide a robust set of evidence that may include: a detailed chronological record of every stage of the process, including the sending, opening and viewing of the document and the explicit signing action; identity details of the signatory, such as name, national identity document number, email address and telephone number; and evidence of the document’s integrity, such as a digital fingerprint (hash) and a qualified electronic time stamp proving that the document was not altered after it was signed.
The completion certificate generated by Signature Manager is an example of this type of evidential document: it records all the evidence from the simple electronic signature process and certifies it so that it can withstand a challenge.
When a simple electronic signature is appropriate
In the private sector, a simple electronic signature is valid for a wide variety of documents when the parties accept it voluntarily: acceptance of terms of use, offboarding and onboarding procedures in human resources processes, low-risk internal authorisations, order confirmations or basic confidentiality agreements in well-established business relationships.
It is not appropriate for highly significant documents, such as contracts with substantial financial consequences, corporate transactions or employment contracts containing special conditions, or for procedures involving public administrations.
Advanced electronic signature (AES): the standard for most corporate processes
The advanced electronic signature represents a significant step up from the simple electronic signature. To qualify as “advanced”, it must meet four requirements under Article 26 of the eIDAS Regulation:
It must be uniquely linked to the signatory. It must be capable of identifying the signatory. It must be created using electronic signature creation data that the signatory can use, with a high level of confidence, under their sole control. It must be linked to the signed data in such a way that any subsequent modification is detectable.
These four requirements can be met using technologies such as one-time passwords (OTPs) sent by SMS, which act as a second authentication factor (2FA), demonstrating that the signatory has control of the process.
Legal value and burden of proof for an advanced electronic signature
An advanced electronic signature has high evidential value. Although the burden of proof formally remains with the party submitting it, the strength of the audit trail makes it considerably easier to demonstrate its validity. In practice, a challenge is very difficult to sustain when evidence such as two-factor authentication or biometric data is provided: the legal dispute shifts to the technical analysis of that evidence, often involving a computer forensics expert.
In other words, anyone signing with an AES who can provide evidence of the process has a strong defence against any challenge. It does not benefit from the automatic legal presumption provided by a qualified electronic signature, but successfully challenging a properly implemented advanced electronic signature is extremely difficult in practice.
When an advanced electronic signature is appropriate
An advanced electronic signature is appropriate for most corporate processes: employment contracts, contracts with customers and suppliers, rental agreements, minutes of board meetings, service agreements and most documents used in everyday business relationships.
Qualified electronic signature (QES): equivalent to a handwritten signature
The qualified electronic signature provides the highest level of security and is the only type of signature that has the same legal effect as a handwritten signature in every EU Member State. Article 25.2 of the eIDAS Regulation expressly establishes that a qualified electronic signature shall have the equivalent legal effect of a handwritten signature.
To be qualified, an advanced electronic signature must meet two additional conditions on top of the four requirements under Article 26. First, it must be based on a qualified certificate issued exclusively by a qualified trust service provider (QTSP), such as EADTrust, following rigorous verification of the signatory’s identity. Second, it must be created using a qualified electronic signature creation device (QSCD), a certified hardware or software device that ensures the signing key is protected and under the signatory’s sole control.
Reversed burden of proof: the decisive procedural advantage
A QES benefits from the strongest presumption of legal validity. In litigation, the burden of proof is reversed: the party challenging the signature must prove that it is not authentic, rather than the party submitting it having to prove that it is.
In addition, a qualified electronic signature based on a qualified certificate issued in one Member State will be recognised as qualified in every other Member State, without any additional procedure. Interoperability is automatic.
Acts that legally require a qualified electronic signature
The eIDAS Regulation establishes the framework, but national laws require a QES for acts of particular significance. Most EU countries require a QES for public procurement procedures, tax filings or judicial procedures.
The Spanish peculiarity: the advanced electronic signature based on a qualified certificate
This is where the feature that distinguishes the Spanish legal system from the rest of the European Union comes into play. While the eIDAS Regulation establishes three clear levels, Spanish legislation introduces a fourth category that does not exist in other Member States: the advanced electronic signature based on a qualified certificate.
What exactly is it? It is an advanced electronic signature that uses a qualified electronic certificate, such as those issued by EADTrust or included in the Spanish electronic identity card, to meet the requirement of “identifying the signatory”. However, unlike a qualified electronic signature (QES), it does not require the signature to be created using a qualified electronic signature creation device (QSCD). In practice, this makes it possible to sign with a high level of legal certainty using software certificates installed on a computer or centralised cloud-based signature systems, without requiring a card reader or a specific USB token.
Its advantages in Spain
This signature has two crucial advantages under Spanish law. First: a presumption of authenticity in legal proceedings. The Spanish Civil Procedure Act grants it a rebuttable presumption of authenticity and accuracy. Although it does not have the same effect as a handwritten signature under eIDAS, it provides greater evidential strength than a standard advanced electronic signature, requiring anyone who challenges it to present evidence against it.
Second: widespread acceptance by Spanish public administrations. Laws 39/2015 and 40/2015, together with the regulations governing the Recovery and Resilience Plan, expressly recognise this type of signature as valid for the vast majority of procedures involving the public sector and the justice system, including those governed by Royal Decree-Law 6/2023 in the judicial field.
This contrasts with the practices of other public authorities in the EU, which often require a QES created using a QSCD for procedures of a similar level.
Comparison table: the four levels in Spain
| Aspect | Simple electronic signature (SES) | Advanced electronic signature (AES) | Advanced electronic signature based on a qualified certificate | Qualified electronic signature (QES) |
|---|---|---|---|---|
| Legal basis | Art. 3 eIDAS | Art. 26 eIDAS | Law 39/2015, Royal Decree-Law 6/2023 | Art. 25.2 eIDAS |
| Qualified certificate | No | No | Yes, but no QSCD | Yes + QSCD |
| QSCD device | No | No | No | Yes |
| Legal effect | Valid as evidence | High evidential value | Rebuttable presumption in Spain | Equivalent to a handwritten signature throughout the EU |
| Burden of proof | Party submitting it | Party submitting it, although difficult to challenge | Party challenging it in Spain | Party challenging it throughout the EU |
| Cross-border validity | Depends | Depends | Only in Spain | Recognised throughout the EU |
| Recognised by Spanish public administrations | Case by case | Subject to conditions | Generally yes | Always |
When should each type be used? A practical guide
Choosing the type of signature is not just a technical matter: it is a decision about the balance between convenience, cost and the level of legal certainty required by each process.
Simple electronic signature: low-risk procedures where speed is the priority and the context reduces the risk of challenge, acknowledgements of receipt, acceptance of general terms and conditions, internal authorisations with limited financial impact and initial communications with unknown parties where evidence of acceptance is required.
Advanced electronic signature: the standard option for the majority of corporate contracts, including employment, commercial, service and property agreements, where the parties are identified, the context is clear and the audit trail from the signing process can provide sufficient evidence in the event of a dispute. This is the level provided by Signature Manager by default for processes involving third parties.
Advanced electronic signature based on a qualified certificate: the standard option for procedures involving Spanish public administrations, remote notarial acts, judicial proceedings under Royal Decree-Law 6/2023 and high-value contracts where a rebuttable presumption is required without the need for a physical token. It is the most widely used signature in Spain for high-responsibility corporate processes.
Qualified electronic signature (QES): mandatory when expressly required by law, including public procurement procedures, procedures involving European public administrations and contracts requiring the equivalent effect of a handwritten signature throughout the Union, and recommended when the risk of cross-border litigation is high or when the counterparty may require the highest level of assurance.
The practical effect in litigation: what really matters
The difference between the three levels becomes completely apparent in legal proceedings. Consider three scenarios involving the same contract signed in different ways:
Scenario 1 – Simple electronic signature. One party challenges the signature. The company submitting the contract must prove that the person actually signed it: it must provide process logs, identity evidence, email records and confirmation that the document was opened. The technical debate may last for weeks and may require an expert witness.
Scenario 2 – Advanced electronic signature with OTP or biometrics. One party challenges the signature. The company submitting the contract provides the completion certificate containing the process logs, the OTP sent to the signatory’s mobile phone and the biometric evidence. A technical dispute is still possible, but a successful challenge is very difficult: the combined evidence makes the challenge practically unviable unless it can be demonstrated that the process was fraudulent.
Scenario 3 – Qualified electronic signature. One party challenges the signature. The judge applies the legal presumption: the signature is authentic. The party challenging it must prove that it is not. Without robust technical evidence demonstrating manipulation, the challenge will not succeed and the costs of verification will be borne by the party that challenged it.
The difference is not whether the signature is valid. It is who bears the costs of uncertainty when a dispute arises. The higher the signature level, the lower the uncertainty and the lower the expected cost in the event of litigation. Choosing the appropriate level is ultimately a legal risk management decision.
Frequently Asked Questions (FAQ)
In the private sector, yes. The principle of freedom of form allows the parties to agree on any signing method. The risk is that, in the event of a dispute, the company submitting the contract will have to prove its authenticity. For contracts with significant financial consequences, an advanced electronic signature or an advanced electronic signature based on a qualified certificate provides a much stronger defence.
Not necessarily. This category exists specifically under Spanish law and has no direct equivalent in other EU Member States. For documents with cross-border effects in other European countries, it is advisable to use a qualified electronic signature (QES), which is automatically recognised throughout the European Union.
In contexts where legislation expressly requires it: certain public procurement procedures, the submission of documents subject to specific qualified signature requirements before certain EU public authorities and legal acts for which the law expressly establishes that level. For most procedures involving Spanish public administrations, an advanced electronic signature based on a qualified certificate is sufficient.
An FNMT certificate is a qualified certificate when it has been issued in accordance with the requirements of the eIDAS Regulation and the FNMT is included in the EU Trusted List as a QTSP. FNMT certificates for natural persons are qualified electronic signature certificates. The Spanish electronic identity card also contains qualified certificates. All three enable advanced electronic signatures based on a qualified certificate in Spain.
Signature Manager supports simple and advanced electronic signatures. For qualified electronic signatures, which require a qualified certificate issued by a QTSP and a QSCD, EADTrust can provide the corresponding qualified certificates.
The choice of signature type has real consequences in the event of litigation, for the counterparty’s requirements and for recognition by national and European public administrations. There is no single answer: it depends on the risk, context and legal obligations of each process.
EADTrust is a qualified trust service provider (QTSP) included in the EU Trusted List. We provide simple and advanced electronic signatures through Signature Manager, as well as qualified certificates for every signature level.



