Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

How do electronic signatures satisfy audit and compliance requirements?

Electronic signatures deliver the two things auditors ask for: proof of who approved a document, and proof that it has not changed since. For frameworks such as NIS2, Regulation (EU) 2022/2554 on digital operational resilience in the financial sector (DORA) and ISO/IEC 27001, it is equally decisive that this evidence is logged completely.

It must also stay verifiable across the full retention period — that is, long after the original signing certificate has expired. This is exactly where a robust signing architecture separates itself from a simple click confirmation.

Here's what auditors actually want to see:

  • Identity evidence: At what level of assurance were signatories verified, and how is that process documented?
  • Authorisation evidence: Who was permitted to sign which document at which level, and how is that enforced technically?
  • Integrity evidence: Is the signature long-term validatable with a qualified timestamp, so it holds across the retention period?
  • Operational evidence: Which certifications, conformity reports and availability commitments exist for the trust service?
  • Complete logging: Are dispatch, opening, signature and rejection each documented with a timestamp?
  • Third-party risk management: For organisations in DORA scope: are availability, notification paths and exit scenarios contractually governed?

Practical safeguards in daily operation:

  • Anchor the level in the template: The permitted signature level belongs in the document template, not in a work instruction — that makes compliance technically demonstrable.
  • Reuse the provider's evidence: Qualified trust service providers are audited regularly by a conformity assessment body; those reports form part of your evidence chain.
  • Check the exit scenario: Correctly produced PAdES documents with LTV stay verifiable without the provider — a point increasingly raised in audits.

primesign publishes evidence, root and CA certificates and revocation lists in the primesign Trust Center, guarantees 99.8% availability, and operates a publicly accessible status page showing maintenance windows. Premium support is available 24/7 on request — relevant for organisations within DORA scope.

Benefits

  • A complete evidence chain from identity through to integrity
  • Compliance enforced technically rather than merely asserted
  • Substantially shorter audit cycles through prepared evidence
  • Verifiability across the full statutory retention period
  • Trust service conformity evidence transfers directly into your audit

Still have questions?

Prepare your next audit with our compliance experts.

Talk to an expert