The qualified electronic signature: the level that replaces a signed page

Most electronic signatures are a picture of agreement. One kind is the legal equal of ink on paper, and in Germany it is the only kind that satisfies a statutory written-form requirement electronically. If a loan agreement, a surety or a company resolution has to be in writing, the level of the signature is what decides whether your digital process holds up in court.

Below: the three levels and what separates them, the trust service family beyond signing, the European list that confers qualified status, who supervises providers in Germany, and the Civil Code rule that makes this a finance question and not an IT one.

A smart card, secure signing device and stylus beside a contract represent a qualified electronic signature.

Three levels, and only one of them is equal to a handwritten signature

The eIDAS Regulation defines a ladder. A simple electronic signature is any data in electronic form attached to other data and used to sign: a typed name, a drawn squiggle, a clicked checkbox. An advanced electronic signature adds requirements: it is uniquely linked to the signatory, created with data the signatory can use under their sole control, and connected to the signed data so that any later change is detectable. A qualified electronic signature is an advanced one created by a qualified signature creation device and based on a qualified certificate for electronic signatures.

The qualified level is the one with the legal consequence, since eIDAS gives it the equivalent legal effect of a handwritten signature. The other two are not worthless: for most contracts German law prescribes no form at all, and a clicked agreement binds. The level becomes decisive precisely where the law demands writing, which is why a procurement decision about signing software is really a decision about which documents your business handles.

Trust services are wider than signatures

Signing is one member of a family. An electronic seal does for a legal entity what a signature does for a person, so an insurer issuing thousands of documents a day does not need an employee to sign each one. An electronic time stamp binds data to a point in time, which is what lets you prove later that a document existed before a deadline. Electronic registered delivery evidences that something was sent and received. A website authentication certificate vouches for the identity behind a domain.

Each of these exists in a plain and a qualified variety, with the qualified one carrying stronger legal presumptions. DigiCert's explanation of trust service providers walks the same family. For a financial institution the practical point is that the archive problem and the signing problem are related: a signature whose certificate has expired is easier to defend years later if a qualified time stamp fixes when it was applied.

Appearing on the trusted list is what makes a provider qualified

Qualified status is not a claim a provider makes about itself. Each member state maintains a trusted list of the providers and services its supervisory body has granted qualified status, and the European Commission publishes the List of Trusted Lists, the LOTL, that points at all of them. The Commission's trusted list browser is where you look a provider up.

That gives a verification process something it rarely has: a single authoritative answer. If a counterparty sends a qualified signature, the chain of trust resolves to a service on a member state's list, and if it does not resolve there, the signature is not qualified whatever the file says about itself. Cryptomathic's account of the qualified certificate sets out what the certificate has to contain and the supervisory body's part in granting the status.

Who supervises trust service providers in Germany

The German supervisory body is the Bundesnetzagentur, which supervises electronic trust services under eIDAS for electronic signatures, electronic seals, electronic time stamps and electronic registered delivery, with its tasks laid down in the German Vertrauensdienstegesetz alongside the Regulation. It publishes the German trusted list, which is the national entry the European list of lists points to.

The technical requirements come from elsewhere: the BSI writes the technical guidelines that signature formats, long-term preservation and the cryptographic mechanisms follow. For a bank, that division matters when a vendor claims compliance: supervision answers whether the provider is qualified, and the technical guidelines answer whether what it produces will still verify in ten years.

The Civil Code rule that makes this a finance question

German law states it in one sentence. Section 126a of the Bürgerliches Gesetzbuch provides that where a statutory written form is to be replaced by the electronic form, the person issuing the declaration must add their name and sign the electronic document with their qualified electronic signature, and that in the case of a contract each party must electronically sign an identical document in that manner.

Read that twice if you are designing a lending process, because it carries two traps. The first is that nothing below the qualified level will do, so an advanced signature on a document that needs writing leaves the form requirement unmet. The second is the identical-document rule for contracts: both sides sign the same text, which rules out a workflow where each party signs its own copy. Where the law demands notarization or a handwritten form that cannot be replaced electronically at all, no signature level helps, which is a separate check your legal team makes per document type.

The seal, for an institution that signs at scale

A signature belongs to a human being; a seal belongs to a legal person. That difference is operational before it is legal. A bank sending account statements, confirmations or regulatory filings does not want each of them to depend on a named employee who may leave, and a seal lets the institution itself be the signatory.

A qualified electronic seal carries its own legal presumptions about the integrity of the data and the origin from that legal entity. The usual design pairs them: a seal for the institution's own high-volume output, a qualified signature for the places where an individual's declaration is the point, for instance a customer accepting a loan. Document flows of this kind also appear on the issuance side, which issuing tokenized securities in Germany and tokenized securities distribution cover.

Where eIDAS 2 and the wallet come in

The trust services on this page predate the wallet and continue beside it. The eIDAS amendment adds a European digital identity wallet and changes how a person proves who they are and presents attributes, and it leaves the signature levels and the qualified trust service machinery in place. A wallet holder being able to sign is an addition to this system, not a replacement for it.

eIDAS 2 in finance covers the amendment and the wallet. What belongs here is the boundary: if your question is about the legal effect of a signature on a document, it is answered by the levels above, whichever device the key sat in.

What is the difference between an advanced and a qualified electronic signature?

The device and the certificate, and with them the legal effect. An advanced signature has to be uniquely linked to the signatory, under their sole control and tamper-evident. A qualified one is an advanced signature created with a qualified signature creation device on the basis of a qualified certificate, and eIDAS gives it the equivalent legal effect of a handwritten signature.

Can a loan agreement be signed electronically in Germany?

It depends on whether the law prescribes a written form for that agreement, and the answer differs between a consumer loan, a corporate facility and a surety. Where writing is prescribed and electronic form is allowed to replace it, Section 126a BGB requires a qualified electronic signature from each party on an identical document. Where the law allows no electronic replacement, no signature level helps.

How do I check whether a provider is a qualified trust service provider?

Look it up on the member state's trusted list through the European Commission's trusted list browser, which resolves through the List of Trusted Lists. A provider on a national list for the relevant service is qualified for that service; marketing language on a website is not a substitute. For German providers the list is published by the Bundesnetzagentur as the supervisory body.

What is the difference between a signature and a seal?

Who signs. A signature is made by a natural person and expresses that person's declaration. A seal is made by a legal person and attests the origin and integrity of the data from that organization. An institution producing documents in volume uses seals so the output does not depend on a named employee.

Qualified electronic signatures and Finance Loop

Finance Loop is where the lawyers who decide which documents need a form meet the engineers who have to produce a signature that survives an audit. Finance Loop is the meeting place for digital identity and trust services in German finance, with meetups and conferences on compliance technology, digital contracts and the infrastructure under them. Finance Loop keeps those dates in its event calendar.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.