EU · eIDAS Regulation (EU No 910/2014)

eIDAS Compliant Electronic Signatures

The eIDAS Regulation (EU No 910/2014) established a legal framework for electronic signatures across all European Union member states starting July 1, 2016. It defines three levels of electronic signatures: Simple Electronic Signatures (SES), Advanced Electronic Signatures (AdES), and Qualified Electronic Signatures (QES).

eIDAS Regulation (EU No 910/2014)

European Union · Enacted 2014

Key Provisions

Creates a single legal framework for electronic signatures across all EU member states

Defines three signature levels: Simple (SES), Advanced (AdES), and Qualified (QES)

Advanced signatures must be uniquely linked to the signatory and capable of identifying them

The signature creation data must be under the sole control of the signatory

Any subsequent change to the signed data must be detectable

A signature cannot be denied legal effect solely because it is electronic

The eIDAS Regulation (EU No 910/2014) established a legal framework for electronic signatures across all European Union member states starting July 1, 2016. It defines three levels of electronic signatures: Simple Electronic Signatures (SES), Advanced Electronic Signatures (AdES), and Qualified Electronic Signatures (QES). Article 26 sets four requirements for an Advanced Electronic Signature: unique linkage to the signatory, capability of identifying them, creation under their sole control with a high level of confidence, and detectability of any later change. Every signature is uniquely linked to the signatory via their email address and captured metadata. ECDSA P-256 cryptographic verification ensures non-repudiation, and SHA-256 hashing detects any post-signing tampering. SignForge is hosted on Hetzner infrastructure in Nuremberg, Germany — ISO 27001:2022 certified and BSI C5 Type 2 compliant — ensuring EU data residency by default.

What we record

What SignForge records

These are the facts we capture and store for every signature. eIDAS Regulation sets the requirements above — whether what we record satisfies them for a given transaction is a legal question that depends on the circumstances.

Signer uniquely identified via email address, IP address, and user-agent metadata

Sole control ensured through unique cryptographic signing tokens sent only to the signer's email

ECDSA P-256 digital signatures on verification records provide non-repudiation

SHA-256 hashing before and after signing detects any data modification

Hosted on Hetzner infrastructure in Germany — EU data residency

Infrastructure certified ISO 27001:2022 and BSI C5 Type 2

What SignForge does not provide here

  • SignForge is not a qualified trust service provider and appears on no EU Trusted List
  • SignForge does not issue Qualified Electronic Signatures or qualified certificates
  • SignForge does not operate a qualified signature creation device (QSCD)
  • Where a member state reserves an act to written form, Article 25(2) gives that effect to a qualified signature — which SignForge does not issue

256-bit Encryption

TLS 1.3 + SHA-256

ECDSA P-256

Cryptographic proof

Audit Trail

Append-only, immutable

ISO 27001

Certified infrastructure

Frequently asked questions

What level of eIDAS electronic signature does SignForge provide?

eIDAS defines three levels, and Article 26 sets four requirements for the Advanced level: unique linkage to the signatory, capability of identifying them, creation under their sole control with a high level of confidence, and detectability of any later change. On every plan SignForge records the signer's email, IP address and user-agent, a SHA-256 hash before and after signing, and an ECDSA P-256 signature on the verification record. On the Advanced tier it also records the sender's attestation of who the signer is, a one-time code delivered separately from the signing link, and the signer's acceptance of terms whose exact wording is hashed into the record. Which level a given signature reaches is a legal question that turns on your circumstances. SignForge is not a qualified trust service provider and does not issue Qualified Electronic Signatures.

Is SignForge data stored in the EU?

Yes. SignForge runs on Hetzner infrastructure in Nuremberg, Germany. All documents, signatures, and audit data are stored within the EU. Hetzner holds ISO 27001:2022 certification and BSI C5 Type 2 compliance, meeting the highest European standards for data security.

Are eIDAS electronic signatures accepted in all EU countries?

Yes. Under Article 25 of the eIDAS Regulation, an electronic signature cannot be denied legal effect solely because it is in electronic form. This applies across all 27 EU member states, plus EEA countries (Norway, Iceland, Liechtenstein).

General information — not legal advice

This page summarizes electronic signature legislation drawn from primary legal sources and international bodies including UNCITRAL and UNCTAD. It is not legal advice and creates no solicitor–client or attorney–client relationship. Laws change, and how they apply depends on the transaction, the parties, and the document type. Before relying on electronic signatures for a regulated, high-value, or cross-border transaction — or for any document type listed as excluded — take advice from qualified counsel in the jurisdiction whose law governs that transaction. That is a separate question from the governing law of your agreement with SignForge, which is set out in our Terms of Service.

Last reviewed: 10 August 2026

Ready to sign with confidence?

Legally binding e-signatures with 256-bit encryption, cryptographic verification, and an immutable audit trail. Free forever.

Get started free

No credit card required.