Qualified validation of an electronic signature vs. standard verification—how do they differ, and when does this difference matter?
Read more
Reading time:
Date of publication:
Qualified validation of an electronic signature or seal is a legally binding trust service (in accordance with eIDAS) that provides irrefutable proof of the validity of an electronic signature and an electronic seal, whereas simple verification of an electronic signature is merely a technical reading of the electronic layer of a file by a computer program.
This difference is crucial when a document is submitted to a court or regulatory authorities, or when it involves high-risk transactions.
Imagine a typical scenario: you receive an important contract on your desk that has been electronically signed by a business partner. You open the file in a PDF reader, see a green symbol indicating valid signatures, and consider the matter closed, thinking you have ironclad proof. Alternatively, you upload the document to a free online verifier and receive a message confirming a positive result.
The problem is that neither of these steps gives you anything more than a snapshot of the file’s status at that exact moment. If, in a few years, your business partner challenges the contract in court, today’s “green checkmark” on your computer screen may not be enough to protect your company’s interests. Let’s see why this happens and how to properly secure your company’s documents.
Standard electronic signature verification is a process in which software—such as popular PDF readers (e.g., Adobe Acrobat) or widely available, free online verifiers—technically checks a layer of the document that is invisible to the naked eye.
When you open a signed document, the program acts like a digital scanner. It checks four basic things:
Standard verification of of a qualified electronic signature is a very useful tool for day-to-day operational work. It allows you to quickly determine whether the file you received is indeed the contract you were expecting.
However, it has one fundamental flaw: it provides no legal guarantee and does not preserve evidence for the future.
From a legal and business perspective, relying solely on standard verification carries specific risks:
"Many business owners only painfully learn the difference between a free PDF reader and qualified validation once they’re in a courtroom. A standard program provides only a technological snapshot at a given moment. Only a qualified trust service protects a company’s interests in the long term, effectively shifting the burden of proof.” — Agata Kolorz-Lentini, Information Security Compliance Manager, IOD at Autenti
A qualified validation service is a formalized trust service, defined in Articles 32 and 33 of the eIDAS Regulation, which confirms in a legally binding and long-term manner that the electronic signature or electronic seal was valid at the time of its creation and that the integrity of the signed data has not been compromised.
Unlike ordinary software programs, this service may only be provided by entities holding the rigorous status of Qualified Trust Service Provider, listed on the European Trusted List (Trusted List). On the Polish market, this select group currently includes only Asseco, CenCert, and Autenti.
The mechanism of qualified validation is based on providing tamper-proof evidence in the form of a report, the scope of which is defined by a dedicated standard issued by the European Telecommunications Standards Institute (ETSI). From a business and legal perspective, this service differs from ordinary verification in three key aspects:
"The greatest value of qualified validation is providing a complete set of information about the certificates contained in the document. Not just the mere fact of their existence, because, as we know, the mere display of a signature has no legal force in the context of electronic signing, but also all data contained in the certificate, the certificate issuer, its validity, and any unauthorized changes to the document or cryptographic security measures. The tool allows us to effectively combat all forms of abuse, including, above all, potential bad faith on the part of our business partners who present false or manipulated documents as evidence in court." — Agata Kolorz-Lentini, Information Security Compliance Manager, IOD at Autenti
In our practice, we often see companies relying on free verification tools for contracts worth millions. The decision on when to use which tool should be based on your organization’s risk (compliance) analysis.
Standard verification is perfectly sufficient when:
Qualified validation is absolutely essential when:
💡 Are you wondering whether the processes and documents in your organization require professional validation?
Schedule a free consultation with an Autenti expert and find out how to minimize legal risks when handling e-documents.
Many users of free software are accustomed to the fact that the result of a signature check is simply a message that appears briefly on the screen. The result of qualified validation, however, is permanent, cryptographically secured documents.
At the end of the qualified validation process, you receive two key elements:
In the Validation Certificate, you will find all transaction details: the signer’s exact information (first name, last name, and sometimes organization), the certificate’s serial number and provider details, the signature format, and the parameters of the timestamp used. The entire document is assigned a unique validation process identifier.
However, the most important element of the report is the final validation indicator, which, under EU standards, always takes one of three statuses:
Both files (XML and PDF) are rigorously protected by being affixed with a qualified electronic seal from a Trust Service Provider and a qualified time stamp. This seal guarantees that the report itself has never been tampered with.
When choosing a tool to verify documents, it’s very easy to fall into the trap of tech marketing. Many free online validators, as well as popular PDF readers, promote themselves with slogans such as: “eIDAS-compliant tool” or “We support eIDAS standards.” This means they offer so-called “technological compliance,” which, however, does not confer any legal status whatsoever.
Technical compliance with eIDAS simply means that the software has been written to correctly read cryptographic structures (such as XAdES or PAdES) recommended by the European Union. The program’s code does not violate EU guidelines. However, this is like saying that a college diploma printed on a printer has the correct format and uses the appropriate font.
A qualified validation service, as defined in Article 33 of eIDAS, is, in turn, a powerful legal status granted to the entity that issues this diploma. A qualified service is not merely a matter of implementing the code itself, but involves months of audits by certification authorities, inclusion on the European Trusted List, adhering to rigorous security and compliance procedures, and being prepared to bear financial liability for every validation result generated.
The table below helps explain why a “technically compliant” tool is not the same as a qualified service:
|
Parameter / Feature |
Tool technically compliant with eIDAS (basic verification) |
Qualified eIDAS validation service |
|
Provider’s legal status |
Ordinary software provider (SaaS, desktop application). |
Qualified Trust Service Provider listed on the Trusted List, subject to supervision and audits, and required to comply with relevant standards and legal regulations |
|
Responsibility for the result |
No liability (always specified in the terms of service). |
Full legal and financial liability of the provider for errors. |
|
Proof issued after verification |
A message on the screen (often disappears after the file is closed). |
Report (XML) and Certificate (PDF) signed with a qualified digital certificate. |
|
Legal presumptions in court |
None. The result can easily be challenged by the opposing party. |
Full (pursuant to Article 32 of eIDAS). The document has the force of official evidence. |
|
Resilience to certificate expiration |
Low. The tool checks the certificate’s validity at the moment the file is opened. |
Very high. The validator uses the provided Validation Report to freeze the signature’s status as of the time it was created. |
If your goal is to achieve legal certainty, a tool that is technically compliant but provided by an unqualified entity is simply insufficient.
💡 Are you wondering whether the tools you’re using actually protect your company’s interests?
Consult with our expert about implementing qualified validation with our expert and gain 100% evidentiary certainty.
The fundamental difference between verification and qualified validation of an electronic signature is legal, not technical. Although at first glance both tools may display the same positive message regarding a document’s status, only one of them provides you with hard, enduring evidence of indisputable validity.
Regular software is a great tool for day-to-day, informal file previews. However, if you’re protecting your company’s interests against the risk of financial loss, relying on green messages in a free reader is reckless. Qualified validation relieves you of the burden of proof in the event of a dispute and shifts liability to a certified, regulated provider.
As an authorized Qualified Trust Service Provider listed on both the Polish and European Trusted Lists, we offer solutions that provide 100% legal certainty. Importantly, our validator is the only one on the market that natively supports and fully verifies Autenti e-signatures as well as the Autenti advanced e-signature. Secure the evidence of your contracts and ensure your organization is protected in the long term—check out the Autenti qualified validator.
Mateusz Kościelak
Mateusz Kościelak brings over 10 years of experience in B2B Sales & Marketing with the specialization in Enterprise B2B SaaS. A V-Shaped marketer experienced in building lead generation machines using content, SEO & performance marketing with the focus on international expansion.
Visit author's profile
Mateusz Kościelak
Read more
Mateusz Kościelak
Read more
Team Autenti
Read more