Informational

Simple vs Advanced eSignature under eIDAS (2026)

eIDAS electronic signatures: SES vs AES for consent forms, contracts, and clinical documents. Legal validity and appropriate use cases.

By Platform EditorialPublished 7 min read
Simple vs Advanced eSignature under eIDAS (2026)
Summary

eIDAS electronic signatures: SES vs AES for consent forms, contracts, and clinical documents. Legal validity and appropriate use cases. It covers the three levels defined, which level does a medical or allied health practice need, how Tregovia implements esign, and common misconceptions.

Simple vs Advanced Electronic Signature under eIDAS (2026)

The eIDAS Regulation (EU No 910/2014) defines three levels of electronic signature: Simple Electronic Signature (SES), Advanced Electronic Signature (AES), and Qualified Electronic Signature (QES). These are not marketing categories — they are legally defined assurance levels with different evidentiary weight, technical requirements, and appropriate use cases.

Most software platforms that offer "e-signature" functionality provide SES. Fewer provide AES. QES requires a qualified trust service provider and is typically used only for high-stakes legal documents.

Understanding the difference matters for any EU business using electronic signatures for consent forms, contracts, or treatment agreements.

The Three Levels Defined

Simple Electronic Signature (SES)

Legal definition: Any data in electronic form attached to or logically associated with other data in electronic form, and used by the signatory to sign. (eIDAS Article 3(10))

In practice: A typed name at the end of an email, a checkbox confirming agreement, a scanned handwritten signature attached to a PDF, or a "sign here" click in a web form — all qualify as SES.

What SES proves: That someone interacted with the document. It does not verify who that person is, whether the document was tampered with after signing, or whether the email address used corresponds to the claimed signatory.

Appropriate for: Low-risk consents where the identity of the signatory is not in dispute and the consequence of a disputed signature is low. General terms of service, newsletter opt-ins, appointment booking confirmations.

Advanced Electronic Signature (AES)

Legal definition: An electronic signature that meets all four requirements under eIDAS Article 26:

  1. Uniquely linked to the signatory
  2. Capable of identifying the signatory
  3. Created using data under the signatory's sole control
  4. Any subsequent change to the data is detectable

In practice: AES typically involves:

  • Email or mobile verification of the signatory's identity before signing
  • A unique signing link sent to the verified address
  • Cryptographic linking of the signature to the document (so any tampering is detectable)
  • A complete audit trail recording: who signed, when, from which IP address, in which sequence

What AES proves: That a specific identified person signed a specific document at a specific time, and that the document has not been altered since signing.

Appropriate for: Treatment consent forms for clinical procedures, therapy services agreements, employment contracts, financial agreements, real estate transactions, and any document where the identity of the signatory and document integrity may later be questioned.

Qualified Electronic Signature (QES)

Legal definition: An AES created by a Qualified Electronic Signature Creation Device (QESCD) based on a Qualified Certificate for Electronic Signatures, issued by a qualified trust service provider listed on an EU Member State's trusted list.

In practice: Requires the signatory to hold a qualified certificate — typically issued via a smart card (similar to some national ID cards), a qualified USB token, or a mobile-based qualified signing service. The trust service provider is audited and listed by a national supervisory authority.

What QES proves: Equivalent legal effect to a handwritten signature in all EU Member States under eIDAS Article 25(2). Non-repudiation is extremely strong.

Appropriate for: Notarial acts, corporate filings, real estate deeds, and other contexts where legal equivalence to a handwritten signature is explicitly required by law.

Which Level Does a Medical or Allied Health Practice Need?

The right answer depends on the specific document and the applicable member state law.

Appointment booking confirmation

SES is sufficient. The client confirms an appointment via email or online booking. The commercial risk if disputed is the appointment fee — low enough that SES provides adequate protection.

General intake questionnaire (health history)

SES is typically sufficient. The patient completes and submits a form. For non-clinical questions, SES confirmation of submission is adequate. For forms that include clinical disclosures that may be referenced in treatment decisions, AES is preferable.

Consent to treatment for routine procedures

AES is recommended. For informed consent to physiotherapy, chiropractic treatment, dental procedures, or aesthetic treatments, AES provides a legally stronger record than a simple checkbox. If consent is later disputed — by the client, in litigation, or in a regulatory investigation — an AES audit trail with identity verification is significantly stronger evidence than a checkbox in a web form.

Consent to treatment for high-risk procedures

AES is strongly recommended; QES may be required by member state law. For surgical procedures, implant placements, anaesthesia consent, and procedures with material risk, AES is the minimum appropriate level in most EU jurisdictions. Some member states' medical regulation or case law may require QES for specific procedure categories — verify applicable law in your jurisdiction.

Therapy services agreement (ongoing treatment contract)

AES is recommended. A therapy services agreement covers fees, cancellation policy, confidentiality terms, and the scope of the therapeutic relationship. If the agreement is later disputed (fee recovery, scope of treatment claims), an AES record with full audit trail is stronger evidence than a SES checkbox.

Employment contracts, supplier agreements

AES is standard. Employment contracts and commercial agreements in the EU are increasingly executed via AES. QES is not typically required unless the contract type is subject to formality requirements under member state law.

How Tregovia Implements eSign

Tregovia's Contracts eSign module (EUR 15/month) provides AES-level electronic signatures:

  • Identity verification: Signatory receives a unique signing link via their verified email address
  • Document integrity: Cryptographic hash links the signature to the document version at signing; any post-signing modification is detectable
  • Audit trail: Complete record of: document created, link sent, link opened (timestamp + IP), signature applied (timestamp + IP), completion confirmation sent
  • Signer portal: Signatories can access and download signed documents from a secure portal
  • Notification: Both clinic and client receive completion confirmation with a copy of the signed document

The module supports multi-party signing (e.g., both client and practitioner sign a therapy agreement), signing sequence control, and expiry links for unsigned documents.

Common Misconceptions

"A PDF with a signature field is legally binding." A PDF with a typed or drawn signature is SES. It is legally binding in the sense that contracts can be formed via SES — but it provides weak evidentiary support if the signatory later claims they didn't sign or the document was altered.

"Checkbox consent is the same as a signed consent form." Under eIDAS, a checkbox is SES. It is legally valid for low-risk consent. For clinical consent to procedures with material risk, a checkbox alone is weak evidence. Most clinical risk managers and medical defence organisations recommend AES-level consent for any procedure where a patient could plausibly claim they didn't understand what they were consenting to.

"e-Signatures aren't legally valid in [country]." eIDAS applies across all EU Member States. Electronic signatures at AES or QES level have legal effect equivalent to handwritten signatures for documents that don't require a specific formality (such as notarisation). The Regulation directly applies without member state transposition.

FAQ

Is a "wet" (handwritten) signature legally stronger than AES?

Not necessarily. A handwritten signature on paper is SES in the eIDAS framework — it proves someone signed, but doesn't cryptographically link the signature to an unaltered document or verify identity beyond recognition. AES provides stronger evidence of who signed, when, and that the document hasn't changed. In practice, courts treat both as valid; the strength of the evidence depends on what can be corroborated.

Do I need QES for therapy consent forms?

QES is not typically required for therapy consent in EU member states — AES is sufficient for clinical consent in most jurisdictions. QES is required primarily for documents that member state law specifically requires to have "written form" equivalent. Verify applicable requirements in your specific member state, particularly for high-risk interventions or regulated therapy modalities.

Can clients sign from their phone?

Yes. AES signing in Tregovia's Contracts eSign module works from any device with a browser — phone, tablet, or desktop. The client receives a signing link via email, opens it on their device, reviews the document, and applies their signature. No app installation required.

What happens if a client loses their copy of the signed document?

Signed documents are accessible through Tregovia's signer portal for the document retention period. The client can log into the portal to download their copy at any time. The clinic's copy is stored in the client record with the full audit trail.

Is eSign consent valid if the client signs on behalf of a minor?

Yes, with important caveats. For a parent or guardian signing consent on behalf of a minor, the signing process should be configured to capture the parent/guardian's details as the signatory, with the minor's details recorded separately. The document text should clearly identify who is signing (parent/guardian name, relationship to patient). AES verification applies to the parent/guardian's identity. This is the appropriate workflow for paediatric consent in most EU jurisdictions — verify your member state's specific requirements for minor consent.

What is the difference between the eIDAS Regulation and eIDAS 2.0?

eIDAS 2.0 (Regulation 2024/1183) builds on the original eIDAS and introduces the EU Digital Identity Wallet framework. The three signature levels (SES, AES, QES) are preserved; eIDAS 2.0 adds the EU Digital Identity Wallet as a new qualified trust service for QES. For everyday clinical consent and contract signing, eIDAS 2.0 does not change the practical approach — AES remains the appropriate standard for most clinical and commercial consent workflows.

14-day free trial

Try Platform free for 14 days

See for yourself how Platform compares. Start with the base CRM, then evaluate the modules your business actually needs.