“Digital signature” and “electronic signature” are two terms that are often used interchangeably, but they are not the same thing. Understanding the difference matters, because they offer different levels of security, serve different legal purposes, and are not interchangeable in regulated workflows. The confusion between these terms is understandable: they sound similar, they both involve computers and documents, and in casual conversation people rarely need to distinguish them. But for businesses managing contracts, compliance, and legal risk, the distinction is fundamental.
At Namirial, as a Qualified Trust Service Provider (QTSP) accredited under eIDAS, we work with both concepts daily. This article explains what each term means, how they relate to each other, and how to choose the right approach for your specific needs.
What Is an Electronic Signature?
An electronic signature is a legal concept. According to eIDAS (EU Regulation No. 910/2014), an electronic signature is “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.”
In essence, an electronic signature is any electronic indication of intent to sign: from a typed name at the bottom of an email, to a click-to-accept button on a terms and conditions page, to a sophisticated biometric signature capturing hundreds of data points. The key characteristic is that it expresses the signatory’s intent to be bound by the content of the document.
The breadth of this definition is intentional. The European legislator deliberately created a wide concept that could encompass many technologies, both existing and future, while establishing a hierarchy of legal assurance through three levels.
The Three Levels of Electronic Signature under eIDAS
Simple Electronic Signature (SES): the most basic form, with no specific technical requirements. This includes PIN codes, username/password combinations, a scanned handwritten signature pasted into a document, or a click-to-accept button. SES is legally admissible under Article 25 of eIDAS but offers limited proof of who signed, since anyone could provide these inputs.
Advanced Electronic Signature (AES): uniquely linked to the signatory, allows the signatory to be identified, is created under the signatory’s sole control, and makes any subsequent change to the signed document detectable. AES requires a specific technical implementation to satisfy these four requirements: which is where digital signatures become relevant.
Qualified Electronic Signature (QES): the highest level, legally equivalent to a handwritten signature in all EU Member States. Based on a qualified certificate issued by a QTSP and created using a qualified electronic signature creation device (QSCD). A QES has full legal effect equivalent to wet ink across all 27 EU member states without local notarisation.
What Is a Digital Signature?
A digital signature is a technical concept: a specific cryptographic implementation that underpins advanced and qualified electronic signatures.
It uses public key infrastructure (PKI) and mathematical algorithms to create a unique encrypted code attached to a document. This code performs three functions: it confirms the identity of the signer, ensures the document has not been modified after signing, and provides non-repudiation, meaning the signer cannot later credibly deny having signed it.
How Digital Signatures Work
When a document is digitally signed, the following process occurs:
- A mathematical algorithm computes a unique hash of the document, essentially a fixed-length fingerprint that is unique to that exact document content. Even changing a single character in the document will produce a completely different hash.
- This hash is encrypted using the signer’s private key. The private key is known only to the signer (or to the QTSP infrastructure that manages it on their behalf) and is mathematically unique to them.
- The encrypted hash, the digital signature, is attached to the document along with the signer’s public key certificate, which identifies the signer.
- Anyone verifying the document can use the signer’s public key to decrypt the hash and compare it against a freshly computed hash of the received document. If the two hashes match, the document is unmodified and the signature is genuine. If they differ even slightly, the verification fails, indicating the document has been altered after signing.
This mechanism provides mathematical proof of three properties: authenticity (the signature was created by the holder of the private key), integrity (the document has not been changed since signing), and non-repudiation (the signer cannot deny signing without denying ownership of their private key).
The Key Distinction
The relationship between the two concepts is this: every digital signature is an electronic signature, but not every electronic signature is digital.
A simple electronic signature (like an ATM PIN entered to authorise a transaction) is an electronic signature but not a digital signature: it does not involve public-key cryptography or hash functions.
An advanced or qualified electronic signature, built on cryptographic PKI technology, is both an electronic signature and a digital signature.
Electronic signatures validate intent. Digital signatures validate identity, integrity, and security through cryptographic proof.
This distinction has a direct practical consequence: if a signed document is ever challenged in court, a simple electronic signature provides limited grounds for defence (anyone could have typed that name or clicked that button). A digital signature provides cryptographically backed evidence that is mathematically sound and extraordinarily difficult to fake or deny.
Why This Matters in Practice
In regulated sectors, banking, insurance, healthcare, public administration, real estate, documents may be legally challenged. A simple electronic signature may not hold up in disputes because it cannot reliably prove who signed or whether the document was altered after signing.
A digital signature provides mathematically backed evidence that is far more robust. Combined with additional contextual evidence (biometric data, device information, geolocation, IP address, timestamps) it creates an evidential package that can be confidently presented in any European court.
The more electronic evidence captured during the signing process, the stronger the signature becomes from a legal and evidentiary standpoint. Namirial’s advanced electronic signature captures:
- Biometric data: 500+ data points encoding the velocity, acceleration, pressure and position of the signing gesture
- Device information: the make, model and operating system of the signing device
- Geolocation: GPS coordinates at the moment of signing
- IP address: both origin and destination
- Qualified timestamp: certifying the exact moment of signing to UTC
- Email and phone linkage: the unique identifiers used to deliver the signing request to the specific individual
All of this evidence is compiled into an audit trail, also called a probative document, that can be presented as legal evidence in any EU Member State.
Digital Certificates and Their Role
The bridge between the signer’s identity and their private key is the digital certificate. A digital certificate is a file issued by a Certification Authority (CA) that cryptographically binds a person’s identity to their public key.
When a document is signed with a digital signature, the certificate is included in or attached to the signature. Any party verifying the signature can read the certificate to know: who holds the corresponding private key, which organisation issued and vouches for this certificate, and when the certificate was valid.
For qualified certificates, the CA must be a QTSP listed on a national Trust List maintained under eIDAS. This means that when someone uses Namirial to sign a document with a qualified signature, the signature carries the institutional weight of a government-accredited trust service provider, not just the word of a private company.
Namirial’s Digital Signature Solutions
Namirial is a certified Qualified Trust Service Provider (QTSP) accredited under eIDAS, with presence in Spain, Italy, France, Germany and other European countries. Our electronic signature platform supports all three levels of signature defined by eIDAS: Simple, Advanced, and Qualified, as well as all major digital signature formats: PAdES, CAdES, and XAdES.
Our solutions include:
- Remote qualified signatures: using a qualified certificate stored in Namirial’s secure cloud HSM, accessible from any device without a physical token
- Disposable digital certificates: for one-time use in specific high-stakes transactions
- Smart card and USB token devices: for organisations that require hardware-based key storage
- API-based integration: for embedding signing workflows directly into existing business applications, CRM systems, and document management platforms
- Biometric advanced signatures: capturing 500+ control points for the strongest possible evidentiary basis without requiring a certificate
All solutions comply with eIDAS 2.0, GDPR, the EU AI Act (where AI components are involved), and applicable national legislation in the countries where we operate.
Whether you need a simple click-to-sign workflow for internal approvals, an advanced biometric signature for commercial contracts, or a fully qualified digital signature for high-stakes legal documents, Namirial provides the right level of assurance for each use case, and the expert guidance to choose correctly.







