Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

What is a qualified electronic signature (QES) and how does it work?

Under Article 3(12) of the eIDAS Regulation, a qualified electronic signature is an advanced electronic signature created by a qualified electronic signature creation device (QSCD) and based on a qualified certificate for electronic signatures. It is the highest level of electronic signature.

Under Article 25(2) eIDAS the QES has the same legal effect as a handwritten signature. In practice the burden of proof shifts: a QES is presumed valid unless the contrary is proven, whereas with simple and advanced signatures the relying party must establish attribution itself.

Here's how a qualified electronic signature is created:

  • Verified digital identity: The certificate holder is identified at a high level of assurance — via eID, video identification, in person, or by a registration officer within the organisation.
  • Qualified certificate: A qualified trust service provider from the EU Trusted List binds the verified identity to a public key.
  • Qualified signature creation device: The private key is held in a device certified as a QSCD — a smart card, or a hardware security module at the provider.
  • Strong authentication: Before each signature the signatory authenticates with two factors and authorises the specific signing request.
  • Signature and timestamp: The signature is generated and given a qualified timestamp under Article 42 eIDAS.
  • Long-term validation: The certificate chain and revocation data are embedded in PAdES format so the document stays verifiable after the certificate expires.

Typical QES use cases:

  • Documents subject to written form: Employment contracts, consumer credit agreements and every transaction for which the law prescribes written form.
  • High-value contracts: Framework and supply agreements where the evidential position decides the outcome in a dispute.
  • Public sector correspondence: Applications, official notices and attestations exchanged with public authorities.
  • Cross-border transactions: Contracts within the EU single market, recognised as a QES in every Member State under Article 25(3) eIDAS.

primesign enables qualified remote signing through primesign ENTERPRISE, the primesign SIGNATURE SERVER and online signing with an existing eID. As a listed qualified trust service provider, primesign issues qualified certificates, operates the associated signature creation devices with EU hosting, and guarantees 99.8% availability.

Benefits

  • Legal equivalence with a handwritten signature
  • Reversed burden of proof in favour of the signed document
  • Automatic recognition in all EU Member States
  • Statutory written form requirements met without paper
  • Demonstrable integrity across the full retention period

Still have questions?

Ready to sign at qualified level? Talk to a primesign expert.

Talk to an expert