SES, AES or QES — which do you actually need?
eIDAS defines three levels and they are not grades of quality but legally distinct instruments.
A Simple Electronic Signature (SES) is any electronic indication of intent — typing your name, clicking accept, drawing with a mouse. It is admissible as evidence and valid for most everyday agreements, and it proves very little on its own if challenged.
An Advanced Electronic Signature (AES) is uniquely linked to the signer, capable of identifying them, created using means under their sole control, and linked to the document so any change is detectable. That is a real evidentiary position: you can show who signed and that nothing changed afterwards.
A Qualified Electronic Signature (QES) is an AES created with a qualified signature creation device and based on a qualified certificate from a qualified trust service provider. Under eIDAS it has the same legal effect as a handwritten signature across the entire EU, and — the part that matters — it reverses the burden of proof: the person disputing it has to prove it is invalid, rather than you proving it is genuine.
Most commercial agreements are fine with SES or AES. QES is required for specific transactions in specific countries and is worth having wherever the document would be expensive to lose in a dispute.
What is actually being verified when you sign?
Identity, and this is where the real cost and the real value sit. A signature that anyone could have produced proves nothing regardless of the cryptography behind it.
At SES level, verification is usually just access to an email inbox — which is why it is cheap and why it proves little. AES adds stronger identification, and QES requires identity verification to a standard equivalent to showing a passport, often through a video call, an eID scheme or a bank identity.
Skribble handles all three levels and works through qualified trust service providers for the identity verification behind QES. Signicat treats identity as the whole product rather than a step: KYC, authentication and identity verification alongside signing, with Norwegian BankID integration that lets a Norwegian signer identify themselves with credentials they already have and trust.
That last point is the practical one. The friction in high-assurance signing is the identity check, and using an identity the signer already holds — a bank ID, a national eID — removes it. It is also why the European market fragments by country: the identity schemes are national.
Why does the audit trail matter more than the signature image?
Because the picture of a signature proves nothing and the record around it proves everything.
What makes an electronic signature defensible is the audit trail: who was invited, when they opened the document, from which address, how they were identified, when they signed, and a cryptographic seal showing the document has not changed since. That record is the evidence, not the rendered squiggle.
Yousign, Skribble, Signicat and SignRequest all maintain audit trails, and this is the thing to examine during evaluation rather than the signing interface. Ask what the trail contains, how it is exported, and whether it survives independently of the provider — because if the vendor disappears, an audit trail you cannot produce is worth nothing.
Document security matters equally: the sealed document should be verifiable by a third party without the original platform. A signed PDF with an embedded qualified certificate can be validated by anyone with a standard reader, which is the property that makes it useful five years later in a dispute.
Where does jurisdiction matter in signing?
In two places: where the documents are stored, and whether the provider is a qualified trust service provider recognised under eIDAS.
Signed documents are frequently the most sensitive files an organisation holds — employment contracts, commercial terms, settlements, NDAs. Yousign stores in France and SignRequest in the Netherlands, both EU-established with intra-EEA processing. Signicat is Norwegian, so EEA with the GDPR applying in full.
Skribble is Swiss, operating under both eIDAS and ZertES, the Swiss signature law. That dual compliance is genuinely useful for a company signing with both Swiss and EU counterparties, and Switzerland sits under an adequacy decision rather than intra-EEA processing.
The qualification question is separate and more technical: to issue QES, a provider must be a qualified trust service provider on the EU trusted list. That status is what makes the signature carry its legal weight, and it is verifiable — ask, and check the trusted list rather than the marketing page.
What should you check before rolling this out?
Whether the signing flow works for people outside your organisation, because they are the ones who will abandon it. A counterparty who has to create an account, install something or work out a confusing interface will ask for a PDF to print instead — which defeats the purpose entirely. SignRequest is built around exactly this simplicity, and it is more valuable than any feature list.
Whether the API fits how the documents are actually generated. If contracts come out of your CRM or your HR system, signing should be triggered from there rather than by someone uploading files by hand. Yousign, Signicat and SignRequest all provide APIs, and Yousign supports templates and bulk signing for volume.
What it costs at your volume. SignRequest starts around €7 per month and Yousign around €9, Skribble has a free tier with paid plans from about CHF 12, and Signicat quotes custom pricing because identity verification is priced per check rather than per seat.
And whether you need QES anywhere. If any document in your process legally requires it, that requirement decides the provider before anything else — and only Skribble and Signicat cover the qualified level here.