CAdES

CAdES is the ETSI standard for advanced electronic signatures (AdES) using CMS/PKCS#7 binary data, used when content is not a PDF or XML file.

CAdES (CMS Advanced Electronic Signatures) is the ETSI standard (EN 319 122) that defines how an electronic signature or electronic seal is embedded in or associated with data using CMS (Cryptographic Message Syntax, RFC 5652) - the binary format historically known as PKCS#7, recognisable by file extensions such as .p7s, .p7m or .p7c. Unlike PAdES or XAdES, CAdES does not assume any particular document type: it works with any binary data and is typically produced as a separate signature object rather than a document you can open and view with the signature visible inside.

Like the other members of the AdES signature formats family, CAdES is built up in baseline levels - B-B for a basic signature, B-T once a timestamp is added, B-LT once revocation and certificate data are embedded, and B-LTA for periodic re-timestamping to support long-term validation. CAdES-BASELINE is one of the signature formats that public sector bodies across the EU are required to be able to validate under eIDAS interoperability rules. Because a bare CAdES signature has no human-readable rendering, it is often packaged in an ASiC (Associated Signature Containers) container together with the signed file, or used in system-to-system settings - structured data exchange, machine-generated files, archival records - where no visual preview is needed.

Frequently asked questions

Back to glossary