This page explains the legal frameworks that apply to electronic signatures. It isn’t legal advice. Whether a given document can be signed electronically — and which signature tier it needs — depends on the laws of the relevant jurisdiction and the specific document. Consult qualified local counsel for your use case.
The three tiers of electronic signature under eIDAS
eIDAS (EU Regulation 910/2014) doesn’t certify individual products as “compliant” or “non-compliant.” Instead, Article 25 sets out three tiers of electronic signature, each with a different legal effect. Industry shorthand for the baseline tier is “Simple Electronic Signature” (SES) — the Regulation itself doesn’t use that label, but defines the tier in Article 3(10).
Only QES carries the automatic “equivalent to handwritten” presumption and automatic cross-border recognition. AES and SES are still legally valid and admissible everywhere in the EU — they just don’t carry that automatic presumption, so their evidentiary weight is argued on the facts if a signature is ever challenged.
What Firma provides
Firma’s signing process is designed to meet the Advanced Electronic Signature bar:- Signer identity capture — every signer’s name and email are recorded and linked to their signature, with optional one-time-passcode (OTP) verification as an additional identity factor.
- Full audit trail — every document view, field interaction, signature, and decline is logged with a timestamp, actor identity, and IP address. See the Audit Trail guide for the full event schema.
- Tamper-evident digital seal — on completion, Firma applies a PAdES digital seal (the ETSI standard signature format for PDFs) to the final document. The seal embeds the signing certificate, a trusted timestamp, and revocation information directly in the file, so it can be verified independently of Firma’s own servers.
- Certificate of completion — a summary of the signing process is embedded in the final PDF alongside the seal.
- EU-hosted infrastructure — Firma’s database and document-processing services run in EU data centers (Supabase and AWS Lambda both in
eu-west-3).
What Firma does not provide
To be direct about the boundary:- Firma is not a Qualified Trust Service Provider (QTSP). It isn’t on the EU Trusted List, and it doesn’t issue Qualified Certificates.
- Firma does not produce Qualified Electronic Signatures (QES) or Qualified Electronic Seals. The digital seal on your completed documents is an AES-level seal, not a QES — it does not carry the Article 25(2) presumption of equivalence to a handwritten signature or the Article 25(3) automatic cross-border recognition that QES gets.
- SOC 2 and ISO 27001 aligned. Firma’s security practices are designed around the SOC 2 Trust Services Criteria and ISO 27001 controls. See Security & Compliance for details.
- No Adobe Approved Trust List (AATL) membership — see below for what that means in practice.
Electronic signatures in the United States: ESIGN and UETA
The US doesn’t use eIDAS’s tiered model. The federal ESIGN Act and the state-level Uniform Electronic Transactions Act (UETA, adopted by nearly every state — New York uses its own similar Electronic Signatures and Records Act instead) both work on the same principle: a signature or record can’t be denied legal effect solely because it’s in electronic form, provided the process shows:- Intent to sign — the signer took an affirmative action to sign.
- Consent to do business electronically — particularly important for consumer transactions, where ESIGN requires specific disclosures about the right to receive a paper copy and withdraw consent.
- Attribution — the signature can be tied to the person who signed.
- Record retention — the signed record can be accurately reproduced later.
Country-specific notes
These are the questions we hear most often from signers and senders in specific EU countries. They’re general context, not a substitute for local legal advice.Italy
Italian users often ask whether Firma qualifies as firma elettronica avanzata (FEA) under Italian domestic law. eIDAS AES and Italy’s domestic FEA concept are related but not identical — Italy’s implementing rules (under the Codice dell’Amministrazione Digitale and AgID technical guidelines) impose additional technical requirements on FEA solutions for certain regulated use cases within Italy. Firma’s signature meets the EU-wide eIDAS AES bar described above; we don’t claim compliance with Italy’s domestic FEA technical specification. Where Italian law requires firma elettronica qualificata (Italy’s term for QES) or notarization — real estate transfers, for example — consult Italian counsel.Spain
Under Spain’s Civil Code freedom-of-form principle and Ley 6/2020 (Spain’s domestic implementation of eIDAS), an AES like Firma’s is generally sufficient for private contracts and is admissible as evidence. Certain acts require a notarial deed (escritura pública) regardless of signature technology — real estate transfers, mortgages, and specific corporate resolutions are common examples. Those require an in-person notary, not any tier of electronic signature.France
French Civil Code Article 1367 (formerly 1316-4) ties an electronic signature’s legal weight directly to the eIDAS tiers, and French courts have historically scrutinized whether the AES criteria — identity verification and tamper-detection — are actually met, more closely than in some other member states. That’s one reason a complete audit trail and an identity-verification step (Firma supports OTP as an additional factor) matter specifically in France: if a signature is ever challenged, you want documented proof that the AES criteria were met, not just the label. Certain French acts still require a notarial deed (acte authentique) — real estate transfers and matrimonial agreements among them — regardless of signature tier.Germany
German civil law imposes strict statutory written-form (Schriftform) requirements on certain contract types. Where the law requires Schriftform under § 126 BGB, only a Qualified Electronic Signature — not an AES — can substitute for it electronically, under § 126a BGB. Firma’s AES-level signature is not sufficient for those documents. Some statutory form requirements go further and exclude electronic form entirely, requiring a wet-ink signature regardless of tier — termination of an employment contract under § 623 BGB is a well-known example. For contracts not subject to a statutory form requirement — the majority of commercial agreements, NDAs, and consumer contracts, under German law’s general freedom-of-form principle — AES is legally sufficient. If you’re unsure whether your document falls under a Schriftform requirement, check with German counsel before relying on Firma alone.Why there’s no green checkmark in Adobe Acrobat
Adobe Acrobat and Reader show a green checkmark automatically only for signatures whose certificate chains to a root on the Adobe Approved Trust List (AATL) — a curated list of certificate authorities that ship pre-trusted inside Adobe’s software. Acrobat can also be configured to trust certificates chaining to the EU Trusted List (EUTL), the list of EU-recognized QTSPs. Firma is neither an AATL member nor a QTSP on the EUTL, so the certificate behind Firma’s digital seal doesn’t chain to either list. Acrobat will typically show the seal as present, but without the automatic green checkmark — you may see a neutral or unverified trust indicator instead, even though the seal itself is fully valid. This is a limitation of Acrobat’s default trust store, not a defect in the signature. The seal is still cryptographically verifiable independent of Adobe:- Recipients can check the signature panel in Acrobat/Reader to inspect the certificate directly.
- Anyone can independently verify a signed document’s seal at app.firma.dev/validate-signature — Firma’s public signature validator — without relying on any PDF viewer’s trust store at all.
What holds up as evidence
If a signature is ever disputed, what typically matters — under Article 25(1) eIDAS, ESIGN, or UETA alike — isn’t a technology label by itself, but whether you can show who signed, when, with clear intent, and that the record hasn’t changed since. Firma’s combination of identity capture, a complete audit trail, a tamper-evident PAdES seal, and an embedded certificate of completion is designed to answer exactly that, for both AES-sufficient use cases in the EU and ESIGN/UETA use cases in the US. That said, no vendor can guarantee an outcome in litigation — sufficiency of evidence is ultimately decided by the relevant court or authority on the facts of the case. For high-value transactions, or any document that might fall under a QES, notarization, or statutory written-form requirement in your jurisdiction, confirm the requirement with local counsel before relying on Firma alone.Related guides
- Audit Trail — the full event schema behind every signing request
- Webhooks — get notified in real time when a certificate is generated or a signature completes