
Many companies looking for providers of qualified electronic signatures to implement digital signatures in a legally sound manner. However, it quickly becomes apparent that this is not just about a function, but about the question of which provider can reliably map the entire process.
Because with a qualified electronic signature, or QES for short, it’s not just about being able to sign documents digitally. Much more important is what happens in the background. How does the identity verification work? Who issues the qualified certificate on which the signature is based? And is the entire process structured in such a way that it really holds up legally in case of a dispute?
This is precisely why it’s worth taking a closer look when choosing a provider for qualified electronic signatures. A good solution should not only work technically but also fit your own process, be clearly structured, and create trust. Because in the end, the best signature solution is of little use if it’s too complicated in practice or leaves legal questions unanswered.
The qualified electronic signature is the highest signature level within the eIDAS framework. It has the same legal effect as a handwritten signature and is based on a qualified certificate that is used with a qualified signature creation device. This is precisely why it is always relevant when particularly robust digital signing is required or when there is a requirement for written form.
Who is allowed to offer qualified electronic signatures?
Not every provider that offers digital signatures is automatically allowed to provide qualified electronic signatures. For qualified trust services, a complex and costly certification process is required. A provider or trust service provider must first be audited by an accredited conformity assessment body. In Germany, this is the Federal Network Agency. After that, the competent supervisory authority reviews the evidence. Only when this review is completed positively and the service is listed in the EU Trusted List may the qualified service be offered at all.
For companies, this means: When selecting a provider for qualified electronic signatures, you should not only look at the website or sales slides but check whether the relevant qualified service is actually listed in the Trusted List. These lists have constitutive effect according to eIDAS. In other words: A service is only qualified if it is actually registered as qualified there.
It is also important to distinguish between solution providers and qualified trust service providers. Some companies offer an intuitive signature platform or an efficient workflow but work with a QTSP for the issuance of qualified certificates. This is not automatically a disadvantage, but you should know that other parties are involved in the process.
What companies should consider when choosing a provider for qualified electronic signatures
First, you should look at what role the provider plays in the process. Are they themselves a qualified trust service provider or do they work with one? A look at the Trusted List is also important: Is the qualified service listed there with a valid status? Especially with qualified signatures, this is crucial for legal robustness.
Then comes the question of how well the provider fits your own process. The best QES solution is of little use if the identification of signatories is unnecessarily complicated, if the process is not understood internally, or if the signature gets stuck at the interface with HR, procurement, sales, or specialized procedures. A good provider therefore doesn’t just think in terms of certificates but in processes: Who signs, when does someone sign, how are they invited, how is it documented, and what happens in case of questions or interruptions? The European Commission recommends that companies first clearly define their requirements. This includes, above all, the question of which documents should be digitally signed and in which use cases this happens. Only based on this should the signature type, technical requirements, and the appropriate solution be selected.
Another point is the user experience. Especially with QES, you shouldn’t pretend that everything is just technology. If signatories don’t understand the process or experience too many hurdles, acceptance decreases. Therefore, it’s worth asking a provider not only about compliance but also about the actual process for business units, external contract partners, and recurring signatories. Because a solution only becomes good when it’s not just correct but also usable.
Technical and legal requirements at a glance
Technically and legally, a provider of qualified electronic signatures should at least be sound where the actual trust basis is created: with the qualified certificate, the secure signature creation, and the verifiability. The EU Commission states that qualified certificates offer higher guarantees regarding the identity of the signatory and are typically used together with a qualified signature creation device. The private signature creation information must be particularly protected; this is exactly what the QSCD is for.
In addition, there is ongoing supervision. Qualified trust services are not checked once and then left to themselves forever. The qualified status is maintained through regular conformity assessments; currently, a cycle of 24 months is typically provided for this. In Germany, the Federal Network Agency is responsible for supervising electronic signatures, seals, timestamps, validation, electronic registered mail, and preservation. At the same time, security requirements apply that include technical and organizational measures as well as reporting obligations for significant security incidents.
For provider selection, this means: Don’t just ask whether QES is possible, but how it is specifically implemented. Where does the qualified certificate come from? Who takes on the qualified role? How is the signature validated? How is it documented that the process ran smoothly? It’s precisely at these points that it becomes clear whether a provider is truly robust or just has the term QES in their portfolio.
Which solution fits which use case?
Not every company needs the same type of solution. Those who only want to digitize individual documents or rather manual processes are often well served with an immediately usable signature platform that can be operated directly in the browser without software download. Those who want to integrate electronic signatures directly into existing processes or interfaces should pay more attention to APIs, integration capabilities, and role models. In regulated or particularly sensitive environments, local solutions often come into focus. They give companies more influence over hosting, process control, and traceability and therefore play an important role in the selection.
The question of the right provider for qualified electronic signatures is closely linked to your own level of maturity. Is it about external contract signing? About recurring processes? About high volumes? Or about particularly sensitive approvals? The European Commission explicitly recommends that companies first determine their own document types and use cases. Only then does selecting a provider really make sense.
Conclusion
When selecting a provider for qualified electronic signatures, you shouldn’t just look at the surface. More important is whether the process behind it is properly structured – legally, technically, and reliably. Because this is what determines whether digital signing ultimately becomes a viable process.
As a qualified trust service provider, we at SIGN8 accompany companies on this path. If you want to get an idea of what this can look like in practice, we would be happy to show you our solutions in a demo.
FAQ: Providers of Qualified Electronic Signatures
How can you recognize a suitable provider for qualified electronic signatures?
A suitable provider not only meets legal and technical requirements but also fits your own process. Important aspects include, for example, how identity verification, certificate issuance, and the signature process are implemented, and whether the solution is user-friendly in everyday use.
How can you recognize a reputable provider for qualified electronic signatures?
An important point is whether the provider is a qualified trust service provider themselves or works with one. It should also be transparent how identity verification, certificate issuance, and the signature process work. A look at the Trusted List can also be useful.
Does every provider of digital signatures also have to be able to offer qualified electronic signatures?
No. Not every provider of digital signatures is automatically allowed to offer qualified electronic signatures. Especially with QES, special legal and technical requirements apply.
What should companies pay particular attention to when selecting a provider?
Companies shouldn’t just look at features or price. It’s especially important that the solution fits your own process, is legally sound, and remains understandable and practical for the signatories.








