Qualified Signature Validation vs. Standard Verification—Differences
Skip to content
Skip to content
Autenti / Blog / Qualified validation of an electronic signature vs. standard verification—how do they differ, and when does this difference matter?

Qualified validation of an electronic signature vs. standard verification—how do they differ, and when does this difference matter?

Qualified validation of an electronic signature or seal is a legally binding trust service (in accordance with eIDAS) that provides irrefutable proof of the validity of an electronic signature and an electronic seal, whereas simple verification of an electronic signature is merely a technical reading of the electronic layer of a file by a computer program.

This difference is crucial when a document is submitted to a court or regulatory authorities, or when it involves high-risk transactions.

Imagine a typical scenario: you receive an important contract on your desk that has been electronically signed by a business partner. You open the file in a PDF reader, see a green symbol indicating valid signatures, and consider the matter closed, thinking you have ironclad proof. Alternatively, you upload the document to a free online verifier and receive a message confirming a positive result.

The problem is that neither of these steps gives you anything more than a snapshot of the file’s status at that exact moment. If, in a few years, your business partner challenges the contract in court, today’s “green checkmark” on your computer screen may not be enough to protect your company’s interests. Let’s see why this happens and how to properly secure your company’s documents.

Key Takeaways

  • A standard verification (e.g., in a PDF reader) is merely a technical scan of the file’s electronic layer—the one you cannot see in the visual layer. It does not rely on legal presumptions, and the software developer is not liable for an incorrect result.
  • Qualified signature validation is a formalized trust service. Its result reverses the burden of proof in court, and the provider (e.g., Autenti) assumes full responsibility for the accuracy of the verification.
  • A qualified validator generates a cryptographically sealed report that “freezes” the signature’s status as of a specific date and time. The document will serve as irrefutable evidence even years later, after the certificates have expired.
  • Standard verification is sufficient for internal, low-risk matters. Qualified validation is essential for public tenders (PZP), regulated entities (KNF), and substantiating key contracts.
  • As the only qualified provider on the market, our validator natively recognizes and verifies both the standard Autenti e-signature and the advanced Autenti e-signature, presenting the signer’s complete data.

What exactly is “verification” of an electronic signature?

Standard electronic signature verification is a process in which software—such as popular PDF readers (e.g., Adobe Acrobat) or widely available, free online verifiers—technically checks a layer of the document that is invisible to the naked eye.

When you open a signed document, the program acts like a digital scanner. It checks four basic things:

  1. Whether the document contains embedded cryptographic entries, such as signature certificates or electronic seals, in order to verify them,
  2. Whether the file has been modified since the signature or seal was applied,
  3. Whether the signer’s cryptographic certificate is valid at that specific moment,
  4. And whether the certification path (the so-called “chain of trust”) is consistent.


Standard verification of
of a qualified electronic signature is a very useful tool for day-to-day operational work. It allows you to quickly determine whether the file you received is indeed the contract you were expecting.

However, it has one fundamental flaw: it provides no legal guarantee and does not preserve evidence for the future.

From a legal and business perspective, relying solely on standard verification carries specific risks:

  • Lack of legal presumptions: The result of a standard verification does not benefit from statutory presumptions. In the event of a legal dispute, you will be the one who must prove in court (often by calling on IT experts) that the signature was applied correctly.
  • No provider liability: The developer of a free PDF reader or an independent verification portal bears absolutely no liability for the result. If the program misinterprets the certificate and displays a “green checkmark” for an invalid signature, your organization alone bears the consequences. The same rules apply to validating the integrity of a document after electronic signatures or seals have been applied to it.
  • The Problem of Time: Certificates for electronic signatures and seals have a specific technical validity period (typically one to three years, though so-called “one-time certificates” are increasingly common). If you open the same, properly signed document in a standard PDF reader five years from now, and the signature or seal certificate does not contain a qualified timestamp (LTV—Long Term Validation), the program will most likely report an error and mark the signature as invalid. Without a properly generated proof, reconstructing the historical truth will be extremely difficult.

"Many business owners only painfully learn the difference between a free PDF reader and qualified validation once they’re in a courtroom. A standard program provides only a technological snapshot at a given moment. Only a qualified trust service protects a company’s interests in the long term, effectively shifting the burden of proof.” — Agata Kolorz-Lentini, Information Security Compliance Manager, IOD at Autenti

What Is a Qualified Validation Service and What Sets It Apart

A qualified validation service is a formalized trust service, defined in Articles 32 and 33 of the eIDAS Regulation, which confirms in a legally binding and long-term manner that the electronic signature or electronic seal was valid at the time of its creation and that the integrity of the signed data has not been compromised.

Unlike ordinary software programs, this service may only be provided by entities holding the rigorous status of Qualified Trust Service Provider, listed on the European Trusted List (Trusted List). On the Polish market, this select group currently includes only Asseco, CenCert, and Autenti.

The mechanism of qualified validation is based on providing tamper-proof evidence in the form of a report, the scope of which is defined by a dedicated standard issued by the European Telecommunications Standards Institute (ETSI). From a business and legal perspective, this service differs from ordinary verification in three key aspects:

  1. Legal presumptions under Article 32 of eIDAS: This is the most important advantage. The result of qualified validation enjoys legal protection. According to the regulations, state authorities (e.g., courts, the prosecutor’s office, the National Chamber of Appeal, the Polish Financial Supervision Authority, or the National Labor Inspectorate) cannot reject such evidence. In practice, this means a reversal of the burden of proof: if you present a qualified validation report, the party challenging the contract or the validity of the signatures must prove in court that fraud occurred. You are protected.
  2. Preservation of evidence (freezing in time): Qualified validation documents the state of the signature at the fraction of a second when the service was performed. The generated report is cryptographically secured with a qualified seal from the service provider and a qualified timestamp. Even if your counterparty’s certificate expires or is revoked a year from now, today’s report will serve as irrefutable proof in the future that everything was in order at the time of the transaction.
  3. Detecting changes over time: if it becomes necessary to provide evidence of a specific circumstance related to a contract concluded several years ago, qualified validation is an indispensable tool in your arsenal for any situation. Qualified validation not only provides information about the validity of a signature certificate or electronic seal at the time of submission, but also detects and reports any changes, including certificate revocation (e.g., due to fraud) or unauthorized changes to the certificate or document itself.
  4. Full provider liability: By using qualified signature validation, you transfer the risk to the provider. If the system issues an incorrect report and certifies something false, the qualified provider bears full liability for it.

"The greatest value of qualified validation is providing a complete set of information about the certificates contained in the document. Not just the mere fact of their existence, because, as we know, the mere display of a signature has no legal force in the context of electronic signing, but also all data contained in the certificate, the certificate issuer, its validity, and any unauthorized changes to the document or cryptographic security measures. The tool allows us to effectively combat all forms of abuse, including, above all, potential bad faith on the part of our business partners who present false or manipulated documents as evidence in court." — Agata Kolorz-Lentini, Information Security Compliance Manager, IOD at Autenti

In practice—when is standard verification sufficient, and when do you need qualified verification?

In our practice, we often see companies relying on free verification tools for contracts worth millions. The decision on when to use which tool should be based on your organization’s risk (compliance) analysis.

Standard verification is perfectly sufficient when:

  • You’re processing documents within your organization that don’t carry legal consequences (e.g., vacation requests, circulation forms, approvals of lower-level internal regulations).
  • You simply want to ensure that a file has not been corrupted after being downloaded from an email before forwarding it to another department for review.
  • You are verifying informal documents for which a potential dispute with a business partner is unlikely or the costs of such a dispute would be negligible compared to the processing costs.


Qualified validation is absolutely essential when:

  • You participate in public tenders (Public Procurement Law): As the contracting authority, you are required to verify that the bid has been properly signed. Rejecting a bid due to an incorrect reading by free software will result in immediate protests. Rulings by the National Appeal Chamber (KIO) clearly indicate that contracting authorities should rely on qualified tools when reviewing bids (e.g., KIO 457/22).
  • You are gathering documentation in case of a legal dispute: When documenting the conclusion of a contract with a demanding counterparty. If the authenticity of the contract is disputed (e.g., consumer disputes and so-called fraud in the telecommunications industry), a qualified report allows you to quickly dismiss claims.
  • You are a regulated institution: Organizations such as banks, insurers, and leasing companies are subject to KNF audits and rigorous AML procedures. In their case, evidence of customers’ intent must be indisputable and preserved for years.
  • You verify signatures from foreign counterparties: Validating a qualified signature submitted by an entity from another European Union country requires a robust, real-time updated database of European certificate authorities (the EU Trusted List). Standard readers do not come preloaded with trusted certificate lists for European qualified signatures by default and often get confused by foreign certificates, returning false errors.
  • You are preparing contracts for the board of directors to sign: Board assistants and procurement departments, when accepting contracts from suppliers, assume responsibility for their accuracy. Submitting a contract to board members with a defective contractor’s signature poses a huge legal risk to the entire company.

 



💡
Are you wondering whether the processes and documents in your organization require professional validation?

Schedule a free consultation with an Autenti expert and find out how to minimize legal risks when handling e-documents.



What does the result of qualified validation include—a report and a certificate

Many users of free software are accustomed to the fact that the result of a signature check is simply a message that appears briefly on the screen. The result of qualified validation, however, is permanent, cryptographically secured documents.

At the end of the qualified validation process, you receive two key elements:

  1. Validation Report (XML file): This is a highly technical document created in accordance with the strict standards of ETSI (European Telecommunications Standards Institute). This file is machine-readable, which allows for easy integration of the service via API with corporate document management systems (e.g., ERP, CRM), where the software reads the result automatically without human intervention.
  2. Validation Certificate (PDF file): This is a human-readable visual document that serves as physical proof.


In the Validation Certificate, you will find all transaction details: the signer’s exact information (first name, last name, and sometimes organization), the certificate’s serial number and provider details, the signature format, and the parameters of the timestamp used. The entire document is assigned a unique validation process identifier.

However, the most important element of the report is the final validation indicator, which, under EU standards, always takes one of three statuses:

  • TOTAL-PASSED (Valid): The signature is completely valid, the certificate was valid at the time the signature was created, and the file has not been tampered with.
  • INDETERMINATE (Indeterminate Validation): The system lacks sufficient data to issue an unambiguous, binding result. This may occur, for example, when the signature was created a long time ago without the use of a qualified timestamp, and it cannot be unequivocally determined whether this occurred before the certificate expired.
  • TOTAL-FAILED (Negative Validation): Indicates a critical error. This typically occurs when the cryptographic certificate was invalid at the time of use, or when someone physically tampered with the document’s content after it was signed.


Both files (XML and PDF) are rigorously protected by being affixed with a qualified electronic seal from a Trust Service Provider and a qualified time stamp. This seal guarantees that the report itself has never been tampered with.

A Common Misconception—Are Free Validators “eIDAS-Compliant”?

When choosing a tool to verify documents, it’s very easy to fall into the trap of tech marketing. Many free online validators, as well as popular PDF readers, promote themselves with slogans such as: “eIDAS-compliant tool” or “We support eIDAS standards.” This means they offer so-called “technological compliance,” which, however, does not confer any legal status whatsoever.

Technical compliance with eIDAS simply means that the software has been written to correctly read cryptographic structures (such as XAdES or PAdES) recommended by the European Union. The program’s code does not violate EU guidelines. However, this is like saying that a college diploma printed on a printer has the correct format and uses the appropriate font.

A qualified validation service, as defined in Article 33 of eIDAS, is, in turn, a powerful legal status granted to the entity that issues this diploma. A qualified service is not merely a matter of implementing the code itself, but involves months of audits by certification authorities, inclusion on the European Trusted List, adhering to rigorous security and compliance procedures, and being prepared to bear financial liability for every validation result generated.

The table below helps explain why a “technically compliant” tool is not the same as a qualified service:

Parameter / Feature

Tool technically compliant with eIDAS (basic verification)

Qualified eIDAS validation service

Provider’s legal status

Ordinary software provider (SaaS, desktop application).

Qualified Trust Service Provider listed on the Trusted List, subject to supervision and audits, and required to comply with relevant standards and legal regulations

Responsibility for the result

No liability (always specified in the terms of service).

Full legal and financial liability of the provider for errors.

Proof issued after verification

A message on the screen (often disappears after the file is closed).

Report (XML) and Certificate (PDF) signed with a qualified digital certificate.

Legal presumptions in court

None. The result can easily be challenged by the opposing party.

Full (pursuant to Article 32 of eIDAS). The document has the force of official evidence.

Resilience to certificate expiration

Low. The tool checks the certificate’s validity at the moment the file is opened.

Very high. The validator uses the provided Validation Report to freeze the signature’s status as of the time it was created.

If your goal is to achieve legal certainty, a tool that is technically compliant but provided by an unqualified entity is simply insufficient.



💡
Are you wondering whether the tools you’re using actually protect your company’s interests?

Consult with our expert about implementing qualified validation with our expert and gain 100% evidentiary certainty.



Summary

The fundamental difference between verification and qualified validation of an electronic signature is legal, not technical. Although at first glance both tools may display the same positive message regarding a document’s status, only one of them provides you with hard, enduring evidence of indisputable validity.

Regular software is a great tool for day-to-day, informal file previews. However, if you’re protecting your company’s interests against the risk of financial loss, relying on green messages in a free reader is reckless. Qualified validation relieves you of the burden of proof in the event of a dispute and shifts liability to a certified, regulated provider.

As an authorized Qualified Trust Service Provider listed on both the Polish and European Trusted Lists, we offer solutions that provide 100% legal certainty. Importantly, our validator is the only one on the market that natively supports and fully verifies Autenti e-signatures as well as the Autenti advanced e-signature. Secure the evidence of your contracts and ensure your organization is protected in the long term—check out the Autenti qualified validator.