Sign This, Dammit!

Live Free, Sign Hard

ad slot · header · set NEXT_PUBLIC_ADSENSE_CLIENT

2026-07-05

eIDAS, SES, AES and QES explained in plain language

eIDAS is the EU rulebook for electronic identification and trust services, and it applies in Norway through the EEA. SES is the simple signature: a yes. AES is advanced: more tightly coupled to the person and to the data. QES is qualified: a regulated issuer, and the same effect as handwriting where that is required. Most ordinary contracts live in SES. BankID as a qualified signature lives in QES. Do not drag PAdES in as a fourth level — that is PDF mechanics.

What eIDAS is actually trying to do?

Stop people dismissing a deal just because the yes arrived digitally. Put a shared language on levels, so 'secure' stops meaning everything and nothing. Set rules for issuers of qualified certificates.

It is not trying to force BankID into every NDA. It is not trying to make Adobe a court. It is not trying to turn an ads-funded tool into QES.

When a landing page says 'eIDAS-compliant', ask: which level, which issuer, which evidence. Compliant with no level is smoke.

The translation trap: advanced in English sounds like better SES. AES has conditions. If you cannot point at the key, you probably have SES plus marketing.

SES — what people actually use?

You saw the document, you showed intent: draw, type, click. Identity is context: email, the relationship, maybe a code. Evidence is log and file.

SES can bind. It is not 'toy law'. It is the weekday. The weakness is identity fraud and porous links, not the Contracts Act hating thumbs.

An honest product calls this SES. A dishonest one calls it 'bank level' because it is a PDF.

Complaints that the EU makes it too hard hide that SES is easy on purpose. The difficulty sits in QES, on purpose.

AES — the word everyone wants on the box?

An advanced electronic signature should be uniquely linked to the signer, able to identify them, created with data they control, and linked to the document so that change shows. That is a higher bar than 'I drew in a field'.

In practice: certificates, keys, often company PKI. Not a PNG.

Plenty of salespeople say AES about PAdES from a platform key. The platform key identifies the platform more than Kari. Then you are closer to 'integrity' than to the AES textbook. Ask who the key belongs to.

Do not mix eIDAS with the GDPR in one sentence as if they were one stamp. Different regulations. Different fines. Different questions.

QES — when the law wants a handwriting equivalent?

Qualified certificate, qualified issuer, often with an eID like BankID in Norway. eIDAS gives QES the same legal effect as handwriting where handwriting is required. That is what people mean by 'proper electronic'.

It costs. It grinds internationally. It is right when the risk is identity and special statute, not when the risk is that someone forgot to send the NDA.

A free wall product with ads is not QES. If they say it is, leave.

How PAdES fits without pretending to be a level?

PAdES is ETSI rules for a signature inside a PDF. It can carry AES or QES material. It can also carry a platform signature over an SES yes. Bytes are bytes.

Acrobat reads PAdES and then asks whether it trusts the CA. Trust ≠ eIDAS level. A yellow triangle can sit on a technically fine PAdES.

Check the hash and the issuer. Read whether the receipt says SES or QES. Two axes, not one colour.

A sentence you can paste into policy?

'We use SES with a log and optional PAdES against our CA for ordinary contracts. We use QES/BankID where the board or the law requires it. We do not call SES QES.'

It is boring. Boredom is how you avoid buying the wrong seat.

If you need more than SES and less than QES, specify the identity method (eID, certificate, what) instead of buying the letters AES off a brochure.

What about eIDAS 2.0, wallets, and 'this will change everything'?

The rulebook moves. Wallets and new trust services are in the EU conversation. That does not change that today you must call SES SES. Waiting for 2.0 is how the NDA sits unsigned until October.

National eIDs (BankID, MitID, and the rest) map differently onto the levels. Do not assume 'login to the bank' is a QES on this exact PDF. That is often authentication, not a qualified signature on this file.

A policy that cites article numbers nobody on the team has opened is decoration. Three sentences on level, issuer and evidence beat an appendix.

Practise saying the level out loud before you send. If you stammer, you have not chosen. Stammering in a board meeting is how you end up with QES prices on SES work. Three letters, one issuer, one sentence about Acrobat. That is the whole language you need on a weekday.

A table of articles in the regulation belongs with counsel. With the rest of the team belongs: yes, tighter binding, qualified. Translated: SES, AES if we actually have a key, QES with eID. The rest is smoke.

FAQ

Is AES the 'middle' everyone should buy?

Only if you need tighter identity binding than email, but not QES. Many products label SES as AES in marketing. Ask how identity is bound, not for the letters.

Does eIDAS apply in Norway?

Yes, via the EEA. That is why SES cannot be rejected merely for being electronic, and why QES has special effect.

Is PAdES an eIDAS level?

No. PAdES is how a signature can sit in a PDF. You can have SES-level identity and PAdES bytes in the same file.

SES, AES and QES are levels. PAdES is a PDF drawer. BankID lives in QES when it is used that way. Mix them in language and you have already lost the procurement meeting.

If you just need a PDF signed without a subscription, that’s what STD is built for.

Norsk