Verifying eIDAS Signatures for Professional Services
Your firm signed a client agreement electronically last month. A counterparty now questions whether that signature meets eIDAS requirements. You pull up the document, and the first problem becomes clear: you have no structured way to verify whether the signature is simple, advanced, or qualified.
This guide walks through what eIDAS signature verification means in practice, how the three signature tiers differ, where to check a signature's compliance status, and how to build verification into your firm's standard workflows. ZealiD, an EU-listed Qualified Trust Service Provider, operates the infrastructure behind qualified signatures that survive exactly this kind of scrutiny.
Key Takeaways: Verifying eIDAS Signatures
- eIDAS defines three signature tiers with different legal weight, and only a qualified electronic signature (QES) equals a handwritten signature across the EU.
- The European Commission provides a free Digital Signature Service (DSS) validation tool that checks any signed document against eIDAS technical requirements.
- Verification confirms four things: signer identity, document integrity, certificate validity, and whether the issuing provider holds qualified status.
- ZealiD issues qualified electronic signatures backed by ETSI-certified identity proofing, giving professional services firms verification-ready evidence from the start.
- Building verification into your document acceptance workflow protects your firm from unenforceable agreements and regulatory exposure.
What Does eIDAS Signature Verification Mean?
eIDAS signature verification is the process of confirming that an electronic signature on a document meets the technical and legal requirements set by EU Regulation 910/2014. It answers a specific question: does this signature carry the legal weight the parties believe it does?
Verification checks several elements at once. It confirms the document has not been altered, that the certificate was valid at signing time, and that it was issued by a provider on the EU Trusted List. For professional services firms, this matters when a regulator or court asks for proof.
Without verification, you are trusting a visual mark on a PDF. With it, you have a technical chain of evidence linking the signature to a verified identity, a valid certificate, and an unaltered document.
The Three eIDAS Signature Tiers and Their Legal Weight
eIDAS, the EU regulation governing electronic identification and trust services, defines three distinct levels of electronic signature. Each carries different legal standing and evidential strength. Understanding these tiers is the first step in knowing what to verify and why.
Simple Electronic Signature (SES)
A simple electronic signature is any electronic data attached to or logically associated with other electronic data, used as a method of authentication. Typing your name in an email, clicking an "I accept" checkbox, or pasting a scanned image of your handwriting all qualify.
SES has limited evidential value. In a dispute, the burden of proving that the signer intended to be bound falls on the party relying on the signature. For low-risk internal approvals, SES may be sufficient. For client-facing agreements in regulated industries, it is not.
Advanced Electronic Signature (AES)
An advanced electronic signature must meet four requirements defined in Article 26 of the eIDAS Regulation. It must be uniquely linked to the signatory, capable of identifying the signatory, created using signature creation data under the signatory's sole control, and linked to the signed data so that any subsequent change is detectable.
AES provides stronger evidential force than SES. Courts generally presume its validity unless challenged with specific evidence. Most commercial contracts across the EU use AES as the baseline for legally defensible signing.
Qualified Electronic Signature (QES)
A qualified electronic signature is an advanced electronic signature created by a qualified signature creation device and based on a qualified certificate issued by a Qualified Trust Service Provider (QTSP). Under Article 25(2) of the eIDAS Regulation, a QES has the legal effect equivalent to a handwritten signature.
QES carries mandatory cross-border recognition across all EU member states. In a dispute, the burden of proof shifts to the party challenging the signature. For professional services firms handling cross-border matters, notarial work, or regulated transactions, QES is the tier that holds up under audit.
Why Professional Services Firms Need Signature Verification
Professional services firms, including law practices, accountancies, financial advisors, and consulting firms, handle documents with direct legal and financial consequences. A signed engagement letter, a share purchase agreement, or an audited financial statement carries weight that depends entirely on whether the signature behind it is enforceable.
The risk is not theoretical. Firms that accept signed documents without checking the tier may discover, during a regulatory inspection, that the signature does not meet the required standard. An unverifiable signature on an onboarding form can mean a failed AML check. An unqualified signature on a cross-border contract can mean the agreement is unenforceable.
Verification is not an administrative extra. It is the step that confirms your signed documents will stand when challenged.
What Signature Verification Checks
When you verify an eIDAS-compliant signature, the validation process examines several distinct layers of trust. Each layer answers a different question about the signature's reliability.
Document Integrity
The verification tool computes a cryptographic hash of the document and compares it to the hash recorded at the moment of signing. If the document has been modified after signing, even by a single character, the hashes will not match. This confirms that the version you hold is identical to what the signatory approved.
Certificate Validity
The tool checks whether the digital certificate used to create the signature was valid at the time of signing. Certificates have defined validity periods, typically one to two years. A signature made with an expired or revoked certificate will return an invalid or indeterminate result.
Revocation Status
Even a certificate valid when issued may have been revoked by the QTSP. Revocation can happen because of a compromised private key, a change in the signatory's details, or a direct request. The verification tool queries the provider's revocation service (via OCSP or CRL) to confirm the certificate was in good standing at signing time.
Trust Chain and Provider Status
For a signature to qualify as QES, the certificate must trace back to a QTSP listed on the EU Trusted List maintained by the relevant member state's supervisory body. The verification process walks the entire certification chain from the signing certificate up to the root authority, confirming that every link is valid and trusted.
eIDAS Level Classification
Based on all the checks above, the tool classifies the signature as SES, AES, or QES. This is the answer that matters most to a compliance officer or legal counsel: what legal weight does this signature carry?
How to Verify an eIDAS Signature: Step by Step
The European Commission provides a free, publicly available tool for verifying electronic signatures against eIDAS standards. It is called the Digital Signature Service (DSS), and it is the reference implementation used by EU institutions.
Step 1: Access the DSS Validation Tool
Navigate to the European Commission's DSS validation page. The tool is browser-based and requires no software installation. It supports signed documents in PAdES (PDF), XAdES (XML), CAdES, and ASiC container formats.
Step 2: Upload the Signed Document
Select the file you want to verify. If the signature is detached (stored separately from the document), you will also need to upload the original unsigned file. The tool accepts both embedded and detached signature formats.
Step 3: Review the Validation Report
The tool runs its checks automatically and generates a report. The Simple Report shows the overall status: VALID, INVALID, or INDETERMINATE. It also identifies the signatory, the certificate issuer, the signing timestamp, and the detected eIDAS level.
An INDETERMINATE result does not necessarily mean the signature is bad. It can mean the tool could not reach a revocation server or that the timestamp could not be fully verified. In those cases, check the Detailed Report for specifics.
Step 4: Download or Archive the Report
The DSS tool lets you export the validation report as a PDF. For professional services firms, archiving this report alongside the signed document creates a verifiable record that the signature was checked at a specific point in time. This is useful for audit trails, regulatory inspections, and client file documentation.
How Qualified Trust Service Providers Enable Verification
Verification relies on a regulated chain of trust. At its foundation sits the Qualified Trust Service Provider, the entity that verifies the signatory's identity and issues the certificate.
A QTSP must be assessed by an accredited conformity assessment body, supervised by a national authority, and listed on the EU Trusted List. These requirements ensure a verification tool can trust the identity claim on the certificate.
ZealiD is listed on the EU Trusted List under Sweden, supervised by PTS. Conformity assessments are performed annually by SRC Security Research and Consulting GmbH. ZealiD holds certifications under ETSI EN 319 401, EN 319 411-1, EN 319 411-2, and TS 119 461.
When a document is signed with a ZealiD-issued QES, the certificate traces to a provider whose practices have been independently audited. Verification resolves to a published, regulated trust anchor.
Identity Proofing: The Step That Makes Verification Meaningful
A signature is only as trustworthy as the identity behind it. Verification confirms the certificate is valid, but the real assurance comes from the identity proofing that happened before the certificate was issued.
Under eIDAS, a QTSP must verify the signatory's identity before issuing a qualified certificate, meeting the requirements of Article 24(1). ZealiD performs remote identity verification without a video call, using an AI liveness selfie and a document scan. The process is certified at the Extended Level of Identity Proofing under ETSI TS 119 461.
For professional services firms, this means the person who signed is the person they claimed to be, verified against a government-issued identity document, not just an email address or a typed name. When your compliance team runs verification on a signed engagement letter, the result traces back to a real, proofed identity.
Building Signature Verification Into Your Firm's Workflow
Knowing how verification works is one thing. Making it a consistent part of your firm's operations is another. Here is how to approach it.
Define Which Documents Require Verification
Not every document needs the same level of scrutiny. Start by mapping your document types to risk levels. Client engagement letters, regulatory filings, cross-border contracts, and any document you might need to present to a court or regulator should be on the verification list. Internal approvals and low-risk communications may not need it.
Set a Minimum Signature Tier for Client-Facing Work
If your firm operates across EU jurisdictions, consider requiring QES for all client-facing agreements. A qualified signature carries mandatory cross-border recognition and shifts the burden of proof to any party challenging it. That is a concrete legal advantage, not a theoretical one.
Verify at the Point of Document Acceptance
Run verification when a signed document arrives, not months later when a dispute forces you to check. The DSS tool is free and browser-based. Archiving the validation report alongside the document takes minutes and creates a timestamped record of the signature's status.
Choose Signing Infrastructure That Produces Verifiable Signatures
If your firm sends documents for signature, the choice of signing provider determines whether the resulting signatures will pass verification. ZealiD issues QES through a regulated QTSP infrastructure, meaning every signature your clients and counterparties create comes with a qualified certificate that traces back to the EU Trusted List.
ZealiD Trust Circle gives professional firms a workspace where documents are shared, signed, and stored with identity verification built into every step. Signing is one use of a circle, but the underlying value is that every person in the workspace has been identity-proofed, and every document action is traceable.
Common Verification Results and What They Mean
When you run a document through the DSS tool or any eIDAS-compliant validator, you will see one of three results. Understanding what each means helps your team respond correctly.
VALID
All checks passed. The document has not been altered, the certificate was valid at signing time, the certificate has not been revoked, and the certification chain traces to a trusted provider. If the detected level is QES, the signature has the legal effect of a handwritten signature across the EU.
INVALID
At least one check failed. Common causes include a document modified after signing, a revoked certificate, or a certificate issued by a provider not on the EU Trusted List. An invalid result means the signature should not be relied upon without further investigation. Contact the signing party and request a new signature if needed.
INDETERMINATE
The tool could not complete all checks. This often happens when a revocation server was temporarily unreachable. An indeterminate result is not the same as invalid, but it means you cannot confirm the signature's status yet. Retry after some time, or check the Detailed Report for the specific issue.
eIDAS Signature Verification and AMLR Obligations
Professional services firms subject to the Anti-Money Laundering Regulation (AMLR) face specific obligations around client identification. AMLR applies from 10 July 2027, and its requirements intersect directly with signature verification.
When a firm onboards a client, it must verify the client's identity as part of its KYC obligations. If that client signs an engagement letter electronically, the strength of the identity verification behind the signature matters. A QES created through a QTSP with certified proofing provides a higher standard of assurance than a basic "click to accept" flow.
Verification confirms not just that the document is intact, but that the identity claim attached to the signature was issued by a regulated provider that met eIDAS identity-proofing requirements. For firms building their AMLR compliance framework, integrating signature verification into document acceptance is a practical way to strengthen the evidential chain.
Signature Formats and What Your Validator Needs to Support
Electronic signatures can be packaged in several standard formats defined by the European Telecommunications Standards Institute (ETSI). Understanding these formats helps your team confirm that incoming documents can be verified.
PAdES (PDF Advanced Electronic Signatures) embeds the signature directly in a PDF. This is the most common format for business documents and is supported by most PDF readers.
XAdES (XML Advanced Electronic Signatures) is used for XML-based documents and is common in government and procurement workflows.
CAdES (CMS Advanced Electronic Signatures) is a binary format used for signing arbitrary data types.
ASiC (Associated Signature Containers) packages signed documents into a single container file. This format is common in public procurement contexts.
The DSS tool supports all four formats. If your firm uses a commercial validation tool, confirm it covers the formats you encounter most.
Long-Term Validation: Keeping Signatures Verifiable Over Time
A signature verified today may not be verifiable in five years. Certificates expire, revocation services may go offline, and cryptographic algorithms can become deprecated. Long-term validation (LTV) addresses this by embedding all the verification data, including certificates, revocation responses, and timestamps, into the signed document at the time of signing.
eIDAS defines signature levels that support LTV. A PAdES-LTA or XAdES-LTA signature includes everything a future validator needs, even if the issuing QTSP's services are no longer reachable. For firms required to retain documents for 10 or 15 years, LTV-enabled signatures are the only way to guarantee verifiability at the point it matters.
ZealiD supports LTV for qualified signatures, meaning the verification evidence is captured and embedded at the moment of signing. When your firm archives a document signed with ZealiD, the validation data travels with it.
In Conclusion: How to Make eIDAS Signature Verification a Standard Practice
eIDAS signature verification is not a technical exercise reserved for IT departments. It is a compliance practice that belongs in every professional services firm's document workflow. The tools are free. The process takes minutes. The alternative, discovering that a critical signature is unenforceable after a dispute begins, costs far more.
Start by understanding the three signature tiers and what each requires. Use the European Commission's DSS tool to verify signatures on incoming documents. Require QES for client-facing agreements where cross-border enforceability matters. And choose signing infrastructure, such as ZealiD, that produces signatures with a regulated trust chain from the start.
The ZealiD Data Exposure Check is a free self-assessment for law firms and accountancies. It evaluates how your processes handle client identity and document security, and it identifies gaps before a regulator does.
FAQs About eIDAS Signature Verification
What is the difference between a qualified and an advanced electronic signature?
An advanced electronic signature (AES) is uniquely linked to the signer and detects document changes, but it does not require a qualified certificate. A QES adds a qualified certificate from an EU-listed QTSP and a qualified creation device. Only QES equals a handwritten signature in legal effect across all EU member states.
Can I verify an eIDAS signature for free?
Yes. The European Commission's Digital Signature Service (DSS) is a free, browser-based tool that validates signatures in PAdES, XAdES, CAdES, and ASiC formats. It checks document integrity, certificate validity, revocation status, and eIDAS level classification without requiring any software installation.
Why does a verified QES shift the burden of proof?
Under Article 25(2) of the eIDAS Regulation, a QES equals a handwritten signature in legal effect. The party challenging the signature must prove it is invalid, rather than the relying party proving it valid. ZealiD issues QES through a regulated QTSP infrastructure, providing your firm with this evidential advantage from the moment a document is signed.
How does ZealiD verify a signer's identity before issuing a QES?
ZealiD performs remote identity verification using an AI liveness selfie and a government-issued document scan, certified at the Extended Level of Identity Proofing under ETSI TS 119 461. The process covers 50+ nationalities, 150+ document types, and completes without a video call. This certified proofing makes the resulting QES verifiable against the EU Trusted List.
What should I do if a verification result is INDETERMINATE?
An INDETERMINATE result means the tool could not complete all checks, often because a revocation server was temporarily unreachable. It does not mean the signature is invalid. Check the Detailed Report for the specific issue, retry after some time, or contact the QTSP that issued the certificate for confirmation.
Does signature verification satisfy AMLR client identification requirements?
Signature verification strengthens your evidential chain for client identification, but it does not discharge AMLR obligations on its own. A QES created through a QTSP with certified proofing, such as ZealiD, provides a higher standard of identity assurance. Firms should integrate verification into their broader KYC and onboarding workflows.