Advanced electronic signature (AdES)

An advanced electronic signature (AdES) meets all four Article 26 eIDAS criteria: unique link, identification, sole control and tamper detection.

An advanced electronic signature (AdES) is an electronic signature that meets four eIDAS requirements set out in Article 26: it is uniquely linked to the signatory; it is capable of identifying the signatory; it is created using signature creation data under the signatory's sole control; and it is linked to the signed data so that any later change is detectable. Article 3(11) eIDAS defines an AdES by reference to these Article 26 criteria, and Article 25 sets out its legal effect: an electronic signature - including an AdES - cannot be denied legal effect solely because it is in electronic form, though (unlike a QES) it does not receive automatic equivalence to a handwritten signature. In the Netherlands, Article 3:15a of the Dutch Civil Code (BW) gives a QES that automatic equivalence, while an AdES and other electronic signatures have legal effect to the extent the method used is sufficiently reliable given its purpose and all the circumstances - a judge assesses that reliability in case of a dispute. The abbreviation AES is common in everyday use, but eIDAS itself never abbreviates the term - it always writes out 'advanced electronic signature' in full. The abbreviation AdES comes from ETSI and CEN standards and is used to avoid confusion with the unrelated Advanced Encryption Standard (also abbreviated AES).

In practice an AdES is implemented with PKI cryptography: a personal key pair and a certificate, encoded in one of the standard AdES signature formats such as XAdES, PAdES or CAdES. Unlike a QES, the certificate does not have to be qualified and no QSCD is required, which makes an AdES easier to issue but without eIDAS granting it the automatic legal equivalence given to a QES.

Frequently asked questions

Back to glossary