Sign This, Dammit!

Live Free, Sign Hard

ad slot · header · set NEXT_PUBLIC_ADSENSE_CLIENT

2026-05-03

Do you need BankID to sign a contract?

No: you do not need BankID to sign most contracts in Norway. BankID is strong identity proof, and as a qualified signature it is QES territory. An ordinary delivery contract, a private lease, an NDA, freelance — SES is enough there, if the parties actually said yes to the text.

Where does the myth come from?

From BankID opening the public sector. Tax, loans, health. The brain adds it up: contract = serious = BankID. Serious in government is 'hit the right person in a register'. Serious in a deal between two companies is 'can we prove yes, and is the text clear'.

Banks also taught customers that everything important happens behind eID. That is good for accounts. It is a bad translation onto a forty-thousand job with a designer you have worked with for two years.

QES salespeople love the myth. It sells seats. It is not a fair picture of contract law.

An internal policy that says BankID on everything is a choice. It may be a bad one. It is still policy. Change it in the board, not in every job.

When is BankID actually required — or wise?

When a regulation or a counterparty with power (pledges, certain public filings, a bank's internal policy) says qualified level or a named eID. Then you do not win with a drawing in Chrome.

When you do not know the person, the sum is large, and a compromised Gmail would wreck you. Then eID is wise. You are buying sleep.

When the board has decided 'we sign like this'. An internal rule is an internal rule. It does not make SES invalid outward, but it can make you look foolish inward.

Clients who always use BankID often have copied-from-the-bank brain. Show the SES trail once. If they still refuse, that is a price on the relationship.

What are you actually asking for when you ask for BankID?

You are asking the other person to have a Norwegian eID, a working app, and patience. A freelancer in Warsaw may have none of those. Then you designed a flow only Norwegians over 18 with a bank relationship can finish.

Say it out loud: 'we require Norwegian BankID'. Then it is a geographic filter. Sometimes you want that. Often you do not — you just copied a pattern.

The alternative is SES: personal link, visible PDF, log, maybe an email code, maybe PAdES against a CA. Identity is weaker. Friction is lower. Honesty is calling it SES.

Do not use BankID as punishment because you are angry they were slow. Level should match risk, not mood.

Can an email link be abused? Yes. So what?

Inboxes get hacked. Addresses get guessed. That is why a naked, forwardable link with no expiry is sloppy. Personal link, short life, a code, is damping. It does not become QES. It becomes less embarrassing in a fight about 'it was not me'.

Context counts. A link sent to an address you have used for three years, after a Zoom where you walked through clause 4, is a different evidence picture than a cold PDF to info@.

If you fear abuse, the answer is eID or a meeting, not pretending SES is impossible. It is not impossible. It is weaker against identity fraud.

What do you tell a counterparty who 'only trusts BankID'?

Ask what they are afraid of. If they fear the wrong person, offer eID or a video call plus SES. If they fear 'it will not count in court', show them the eIDAS default and that SES is used every day. If they fear Acrobat yellow, explain CA lists.

If they only want the brand they know, that is procurement. Then they pay the seat. You can still use SES for the relationships that do not have that fear.

Do not argue law in five emails. Send the document on the track they require, or walk. Time is also risk.

A short decision tree without legal theatre?

You know each other, ordinary sum, Norway/EU, no special statute: SES. Unknown, large, or policy: eID/QES. File integrity on top: PAdES, and say Acrobat may go yellow if the CA is unknown.

International with no Norwegian eID: not BankID. Full stop.

If someone promises BankID level in a free ads product, they are lying. If they promise you do not need BankID to say yes to a PDF, they may be right.

What about employment contracts, leases, and 'in writing' in special statutes?

Employment contracts have form requirements about writing in the Working Environment Act. Writing is not automatically BankID. Electronic writing can suffice. Read the statute and what is normal in your industry, not a vendor blog. When in doubt: a lawyer, not a forum.

Private leases are often SES in practice. Big landlords have portals. The portal wins because they own the keys, not because eIDAS demanded it.

The word written in a regulation can mean text, not ink. It can also point at a specific flow. Do not guess. A lookup takes ten minutes and saves a seat you bought out of anxiety.

FAQ

Can the other side refuse the contract because I did not use BankID?

They can refuse to do business with you. That is different from SES being invalid. A contract may still have been formed, depending on the facts. Do not mix commercial terms with invalidity.

What if I do not have BankID (foreigner, new in Norway)?

Then a BankID requirement is a practical no. SES by email is what actually exists. QES via other eIDs may exist, but not 'just tap BankID'.

Is BankID the same as the PDF being PAdES-signed?

No. BankID is about who. PAdES is about the file's bytes. You can have one without the other.

BankID is an identity tool, not a ticket into contract law. Most PDFs need an honest yes with a trail — not an eID queue.

If you just need a PDF signed without a subscription, that’s what STD is built for.

Norsk