Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

How does an electronically signed document stay verifiable long term?

A signing certificate typically expires after one to three years, yet the signed document remains valid if the signature is created for long-term validation (LTV). The certificate chain, revocation status and a qualified timestamp under Article 42 eIDAS are embedded permanently in the document.

What matters is the moment of signing, not the moment of checking. The timestamp proves the signature was applied while the certificate was still valid. Without embedded validation data, a verification tool cannot establish years later whether the certificate was valid or already revoked at that time.

Here's how long-term validation is achieved:

  • PAdES signature format: For PDF documents, PAdES (ETSI EN 319 142) defines how the signature, timestamp and validation data are embedded in the file.
  • Qualified timestamp: A timestamp from a qualified provider binds the signature to a provable point in time and enjoys a presumption of accuracy under Article 41 eIDAS.
  • Embedded revocation data: Revocation lists and OCSP responses are stored at the time of signing, so verification works offline and independently of time.
  • Complete certificate chain: The full chain up to the root certificate is embedded, keeping the trust path traceable without online access.
  • Automatic verification: Adobe Acrobat Reader shows a green tick and confirms the document was valid at the time of signing, with no configuration by the verifier.
  • Timestamp renewal: For very long retention periods, timestamps are renewed before the cryptographic algorithms in use are considered obsolete.

What this means for your archive:

  • Retention periods: Commercial and tax retention periods of seven to ten years far exceed the lifetime of any signing certificate.
  • Qualified archiving under eIDAS 2.0: Regulation (EU) 2024/1183 introduces qualified electronic archiving as a dedicated trust service.
  • Provider independence: Because PAdES is an open standard, correctly produced documents remain verifiable even after a change of provider.

primesign produces LTV-capable PAdES signatures by default, through both primesign ENTERPRISE and the primesign SIGNATURE SERVER. Because the format is openly standardised, documents remain verifiable independently of primesign — an important point for the exit scenario in any provider contract.

Benefits

  • Documents stay evidential across the full retention period
  • Verification works offline and without access to the provider
  • An expired certificate does not devalue the document
  • Audit-proof archiving requirements are satisfied
  • Provider independence through the open PAdES format

Still have questions?

Talk to us about audit-proof signing and archiving.

Talk to an expert