Signature validation

Signature validation checks the cryptography, certificate trust chain and validity behind an electronic signature or seal, per eIDAS and ETSI standards.

Signature validation is the process of checking whether an electronic signature or seal conforms to the applicable (advanced or qualified) requirements: the cryptography checks out, the document was not modified, the certificate chain is trusted, the certificate was valid (not expired or revoked) at the time of signing, and - for qualified levels - the provider was on the EU trust list. A validation report confirms this technical conformity; it does not by itself establish the legal validity of the underlying transaction or consent.

eIDAS Article 32 sets out the requirements for validating a qualified electronic signature - including that it must have been created using a qualified signature creation device (Article 32(1)(f)) and that the certificate was valid at the time of signing (Article 32(1)(b)) - and Article 33 defines the qualified validation service that a QTSP may offer. Article 40 extends these signature provisions to qualified electronic seals, which is why seal validation follows the same procedure. The procedure is standardised in ETSI EN 319 102-1, with reference standards fixed by Commission Implementing Regulations (EU) 2025/1945 and (EU) 2025/1942, and applied to AdES signature formats such as PAdES, XAdES, CAdES and ASiC, typically with tooling like the EU's DSS library. The outcome depends on the chosen validation policy - the agreed set of rules and trust anchors the check is run against - and validation time, and results in a validation report per signature (TOTAL-PASSED, INDETERMINATE or TOTAL-FAILED).

Frequently asked questions

Back to glossary