How to submit a public tender with a qualified signature?

Share

Last updated: 5 October 2026

 

If you are bidding for public contracts in the EU, the submission itself is rarely what fails. What fails is the signature: wrong format, wrong assurance level, or a portal that refuses a perfectly valid certificate issued in another Member State. This guide covers the steps in order, and what to do when the portal rejects you.

What the Rules Require Before You Start

Three provisions of the eIDAS Regulation decide most tender outcomes, and knowing them is the difference between re-doing your submission and pushing back on the portal.

 

A qualified electronic signature is legally equivalent to a handwritten one. Article 25(2) states it plainly: "A qualified electronic signature shall have the equivalent legal effect of a handwritten signature." This applies in every Member State, because eIDAS is a regulation rather than a directive.

 

A portal cannot demand more than a QES. Article 27(3) is the provision most bidders have never heard of, and the most useful one to know: "Member States shall not request for cross-border use in an online service offered by a public sector body an electronic signature at a higher security level than the qualified electronic signature." If a procurement platform in another Member State tells you your QES is insufficient, that is the text to point at. Note the wording "for cross-border use", which is what makes it apply to you as a foreign bidder.

 

Every qualified provider is on a published list. Article 22 requires each Member State to publish trusted lists of its qualified providers, and Article 22(2) requires them "in a form suitable for automated processing". A portal has no technical excuse for failing to recognise a qualified certificate from another Member State.

 

Step 1: Read What the Tender Notice Actually Specifies

Before obtaining anything, check the notice for three things, because they vary between contracting authorities in the same country:

 

  • The signature level required. Advanced or qualified. If the notice says qualified, nothing below it will be accepted.
  • The signature format. PAdES for PDF, XAdES for XML, CAdES for detached or binary files, and ASiC where a signed container is required. Member States must recognise the reference formats defined in the implementing acts under Article 27(5), but the notice will usually name the one that platform expects.
  • Which documents need signing. Some authorities require a signature on every attachment, others only on the submission form itself.

 

Getting the format wrong is the single most common reason a technically valid signature is rejected, and it is entirely avoidable at this stage.

 

Step 2: Obtain a Qualified Electronic Signature

A QES requires a qualified certificate issued by a Qualified Trust Service Provider listed on the EU Trusted List. If your provider is not on that list, what you hold is an advanced signature, whatever the product is called.

 

You do not need to appear in person. This is the most persistent misconception in tendering, and it is worth correcting because it causes bidders to abandon cross-border opportunities. Article 24(1a) sets out the permitted identity verification methods, and point (c) allows "other identification methods which ensure the identification of the person with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body". Remote identification is a route the regulation expressly provides for. Physical presence is only one option among several, not a requirement.

 

Nor do you need a smart card or a USB token. Those were the standard a decade ago. A qualified signature can be created on a remote signature creation device operated by the provider and authorised from a phone. For the underlying standard and why most signing platforms do not meet it, see what a qualified electronic signature actually is.

 

If you do not hold a qualified certificate yet, the full process is covered in how to get a qualified electronic signature, including the four identity verification routes the regulation permits and how long each takes.

 

Step 3: Sign the Documents in the Format the Portal Expects

Sign every document the notice requires, in the format it specifies. Two practical points that cause avoidable failures:

 

  • Do not alter a file after signing. Flattening, re-saving, or re-compressing a signed PDF breaks the signature. Sign last.
  • Check whether the portal wants embedded or detached signatures. A detached signature arrives as a separate file that must be uploaded alongside the document. Uploading only one half is a common error.

 

Step 4: Validate Before You Upload

Validate the signature yourself rather than discovering a problem at the submission deadline. The quickest check is to open the signed PDF in Adobe Acrobat Reader and look for the blue bar confirming the signatures are valid.

 

 

For an authoritative check, use a qualified validation service. The EU Trusted List browser lists providers offering qualified validation of qualified signatures across the EU, and several offer it free. If you signed with ZealiD and need help validating, contact support@zealid.com.

 

Step 5: Submit Through the Portal and Keep the Receipt

Register on the e-procurement platform, upload the signed documents in the specified formats, and complete any metadata the platform requires. Submit well before the deadline, because signature validation on the portal side can fail for reasons that take time to resolve.

 

Keep the submission confirmation and any tracking number. If the award is later challenged, the timestamped receipt and the signed files are your evidence that a valid submission was made on time.

 

If the Portal Rejects Your Signature

This is where most cross-border bids are lost, and the useful first question is whose problem it is. Some rejections are yours to fix. Others mean the portal is not meeting its obligations.

 

What the portal says Whose problem What to do
"Signature format not supported" Yours Re-sign in the format named in the tender notice. PAdES for PDF, XAdES for XML, CAdES for detached files.
"Certificate is not qualified", and your provider is not on the EU Trusted List Yours What you hold is an advanced signature. Obtain a certificate from a provider on the EU Trusted List.
Signature valid at home, rejected abroad, certificate issued outside the EU Yours A qualified signature from a third country is not automatically a QES in the EU. You need a certificate from an EU or EEA provider.
"Signature not recognised", and your certificate is from a QTSP in another Member State The portal's Cite Article 22(2): the trusted lists are published for automated processing. There is no technical basis for the refusal.
"We only accept certificates from national providers" The portal's Articles 22 and 27(3) together. A national-only restriction on cross-border use is not permitted.
"A higher assurance level is required than QES" The portal's Article 27(3) prohibits exactly this for cross-border use of a public sector online service.

 

When the problem sits with the portal, put the objection in writing to the contracting authority, cite the article, and do it before the deadline rather than after the award. A refusal recorded in writing before submission closes is a far stronger position than a complaint afterwards.

 

What to Check Before Your Next Tender

Four questions that remove most of the risk from the next submission:

 

  1. Is your certificate issued by a provider on the EU Trusted List, and can you point to the entry?
  2. Can you produce PAdES, XAdES and CAdES, or only one of them?
  3. Can everyone in your organisation who may need to sign a bid do so, including non-nationals without a local eID?
  4. Do you validate before uploading, or only find out when the portal rejects the file?

 

That third question is the one that catches cross-border bidders. A signing process built around a single national eID works until the person who must sign is a foreign director or a colleague in another Member State. The same issue shows up in client onboarding, which we cover in what cross-border onboarding actually requires for identity.

 

ZealiD is a Qualified Trust Service Provider on the EU Trusted List, listed under Sweden and supervised by the Swedish Post and Telecom Authority. Identity is verified remotely from a phone, with no video call and no hardware token, and the resulting signature is a QES recognised for tender submission across the EU.

 

References

  • Regulation (EU) No 910/2014 (eIDAS), Article 22 (trusted lists), Article 24(1a) (identity verification methods), Article 25(2) (legal effect), Article 27(3) and 27(5) (electronic signatures in public services). European Union, 2014, as amended by Regulation (EU) 2024/1183. eur-lex.europa.eu
  • Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. European Union, 2024. eur-lex.europa.eu
  • EU Trusted List browser, for qualified trust service providers and qualified validation services. European Commission. eidas.ec.europa.eu