Sole control assurance level (SCAL)
Sole Control Assurance Level (SCAL) measures remote signing security; SCAL2 requires strong authentication for qualified electronic signatures.
Sole Control Assurance Level (SCAL) is a technical framework, originally defined in CEN/TS 419241 (now superseded by EN 419241-1, server signing), that measures how well a remote signing system enforces sole control of the signature creation data. The standard defines two levels, SCAL1 and SCAL2, based on how strongly the signatory's authorization is bound to the actual signing operation, through authentication factors, user intent confirmation and protection against key misuse. SCAL1 relies on basic authentication without confirming intent for each individual signature and supports advanced electronic signatures, where the stricter sole-control guarantees of SCAL2 are not legally required. SCAL applies specifically to server-based remote signing systems, as distinct from locally held signing devices such as smart cards; only SCAL2 requires the server-side system to be certified as a QSCD, while SCAL1 systems used for advanced electronic signatures need not carry that certification.
Remote qualified electronic signatures require SCAL2: each signing operation must be authorized by signature activation data, generated from the signatory's authentication and confirmed intent and validated within a Signature Activation Module, combined with strong authentication using multiple independent factors, so that the signatory alone can trigger the signature. SCAL2 is tied to QSCD certification under EN 419241-2, the protection profile for a QSCD for server signing: its target of evaluation is the signature activation module, which together with the cryptographic module forms the QSCD. That makes SCAL2 the assurance level underpinning auditable and trustworthy remote signing scenarios.
Two developments sit next to this framework. Since eIDAS 2, Article 29a makes the management of remote qualified signature creation devices a qualified service in its own right, with the rules for it laid down in Commission Implementing Regulation (EU) 2025/1567 - so the server-side operator is regulated as well as certified. And Cleverbase has published SCAL3, its own proposal for verifying sole control beyond SCAL2 (github.com/cleverbase/scal3), used in its wallet: read SCAL1 and SCAL2 as the standardised levels and SCAL3 as work in progress, not as a third level of the standard.