Nevtan Sign is a digital agreement platform that automates document approvals, contracts, onboarding, and secure e-signatures — with workflows connected to your CRM, HR, Legal, and business systems. This guide explains all three signature types so you can pick the right one for each document, stay compliant, and move faster.
TL;DR
SES — Basic, low security, no identity verification. Best for internal, low-risk documents.
AES — High security, uniquely linked to the signer, tamper-evident. Best for most business contracts.
QES — Highest tier, legally equal to a handwritten signature in the EU. Required for certain regulated documents.
Match the signature level to the document's risk. Nevtan Sign supports all three and can apply the right level automatically per workflow.
What are the three types of electronic signature?
Electronic signatures are defined in three tiers by the eIDAS Regulation (Electronic Identification, Authentication and Trust Services) in the European Union. In the United States, the ESIGN Act and UETA make electronic signatures legally binding but do not divide them into SES, AES, and QES — that tiered model is specific to the EU framework.
A quick note on currency: the original 2014 eIDAS regulation was updated by eIDAS 2.0, which introduces the EU Digital Identity Wallet. The core SES/AES/QES definitions below are unchanged under the update, so this framework remains the reference point for choosing a signature level.
Before you choose a tier, it helps to assess three things: the type and volume of documents you sign (internal HR forms vs. high-value contracts vs. regulated records), your compliance requirements (finance, healthcare, and legal often mandate higher assurance), and whether your platform — such as Nevtan Sign — supports the signature types you need.
What is a Simple Electronic Signature (SES)?
A Simple Electronic Signature (SES) is any electronic data attached to, or logically associated with, other data that the signatory uses to sign. Common examples include a typed name at the end of an email, a scanned image of a handwritten signature, or clicking an "I Agree" button on a website.
SES is the easiest tier to implement and needs no special technology — just a document and a way to capture intent. The trade-off is the lowest level of security and legal certainty. Because there is no unique identification of the signer, an SES is easier to dispute: if someone types "John Smith" at the bottom of a contract, it is hard to prove that John Smith actually typed it.
Best for: internal memos, non-binding agreements, and acknowledgments where the stakes are low.
Pro tip: Use SES only where the signer's identity is already known and trusted — for example, internal policy acknowledgments. For external contracts, step up to AES or QES.
What is an Advanced Electronic Signature (AES)?
An Advanced Electronic Signature (AES) is defined under eIDAS Article 26 by four criteria: it is uniquely linked to the signatory, capable of identifying the signatory, created using signature data the signatory can use under their sole control, and linked to the signed data so that any later change is detectable.
In practice, AES typically relies on a digital certificate issued by a Trust Service Provider (TSP) that verifies the signer's identity, together with multi-factor authentication — such as a one-time password sent to a mobile phone — to create a tamper-evident seal. (The certificate is the standard way to meet the four criteria, though the regulation defines AES by function rather than by mandating a specific technology.)
AES gives significantly stronger legal validity than SES. If a sales contract is signed with AES, the signer cannot credibly claim they didn't sign it, because the signature is uniquely tied to them and any tampering is detectable.
Best for: most business contracts — sales agreements, vendor contracts, NDAs, and employment offers.
Pro tip: Make sure your TSP is accredited under eIDAS (or the equivalent in your jurisdiction). Nevtan Sign partners with trusted TSPs to provide compliant AES out of the box.
What is a Qualified Electronic Signature (QES)?
A Qualified Electronic Signature (QES) is the highest tier under eIDAS. It is an advanced signature created by a qualified electronic signature creation device (QSCD) and based on a qualified certificate issued by a qualified Trust Service Provider (QTSP). Under eIDAS Article 25(2), a QES is legally equivalent to a handwritten signature across all EU member states.
To obtain a QES, the signer verifies their identity with a registration authority — in person or through a remote video identification process — and signs using either a hardware token (smart card or USB token) or a cloud-based qualified signature creation device. QES delivers the highest level of security and non-repudiation, and shifts the burden of proof: if a QES is challenged, the challenger must prove it invalid, rather than you proving it valid.
Best for: documents where the law requires a handwritten-equivalent signature — such as certain real estate deeds, court filings, and specific financial agreements.
Pro tip: QES is not needed for everyday contracts. Reserve it for transactions where the law explicitly requires it, and lean on AES for the rest.
SES vs AES vs QES: side-by-side comparison
Feature | SES | AES | QES |
|---|---|---|---|
Security level | Low | High | Highest |
Identity verification | None (self-declared) | Multi-factor (e.g. OTP) | In-person or video ID |
Legal validity | Basic (can be disputed) | Strong (tamper-evident) | Equivalent to handwritten |
Technology required | None (typed name, click) | Digital certificate (usually via TSP) | Qualified certificate + QSCD |
Relative cost | Lowest | Moderate | Highest (varies by delivery model) |
Non-repudiation | Low | High | Very high |
Best for | Internal, low-risk docs | Business contracts, HR forms | Regulated documents, deeds |
On cost specifically: SES is essentially free, AES adds a small per-signature fee, and QES is the most expensive tier. QES pricing varies widely by delivery model — remote/cloud QES is typically far cheaper per signature than legacy hardware-token setups — so treat it as a range rather than a fixed figure and confirm current pricing with your provider.
Pro tip: Nevtan Sign lets you configure signature levels per workflow, so you can mix SES, AES, and QES across your agreement lifecycle.
How to choose the right signature type
Choosing between SES, AES, and QES comes down to five questions:
What does the law require? In the EU, eIDAS mandates QES for certain documents. In the US, the ESIGN Act doesn't require specific tiers, but courts weigh the strength of identity verification.
What is the document worth, and how risky is it? Low-risk internal approvals can use SES; medium-value contracts suit AES; high-value or regulated documents call for QES.
Who is signing? External, unknown signers need the identity assurance of AES or QES. Internal, already-verified signers may be fine with SES.
How much friction is acceptable? SES is a single click; QES involves ID verification and a qualified device. Balance assurance against user experience.
What's the cost? SES is effectively free, AES is a few dollars per signature, and QES costs more — so reserve it for documents that genuinely require it.
A simple rule: SES for low-risk, AES for medium-risk, QES for high-risk or legally mandated documents.
How to implement the right signature type in your workflow
Once you understand the tiers, apply them systematically:
Categorize documents by risk. Low-risk (internal newsletters, non-binding proposals) → SES. Medium-risk (sales contracts, NDAs) → AES. High-risk (loan agreements, real estate transfers) → QES.
Enforce the rules in your platform. In Nevtan Sign, create templates with pre-set signature levels so the correct tier is required automatically when a document is sent.
Train your team so they select the right tier when starting a workflow.
Keep a complete audit trail for every signed document. Nevtan Sign's audit-ready records capture every view, edit, and signature event.
Pro tip: Automate assignment with conditional logic — for example, require QES automatically when a contract value exceeds a set threshold. This removes manual error and keeps you compliant.
Real-world example
Consider CloudFlow Inc., a mid-sized SaaS company using Nevtan Sign to manage its agreement lifecycle. (This example is illustrative.) CloudFlow handles three document types and applies a different tier to each:
Employee onboarding — SES for policy acknowledgments like the code of conduct, since the employee's identity is already verified during hiring.
Customer subscription agreements — AES, because customers sign online and the digital certificate provides strong non-repudiation if a charge is later disputed.
Enterprise partnership contracts — QES, because these involve revenue sharing and legal liability. The authorized signer completes video identification, receives a qualified certificate, and signs via a cloud-based QSCD, making the contract handwritten-equivalent across EU jurisdictions.
The result: contract turnaround drops from weeks to days, printing and courier costs disappear, and every signature is backed by a verifiable audit trail — reducing both administrative overhead and the risk of disputes.
How electronic signatures actually work
These tiers exist to balance security, convenience, and legal certainty. AES and QES are built on public key infrastructure (PKI): you sign with a private key that only you control, and the matching public key sits inside a digital certificate issued by a trusted authority. That creates a cryptographic link between you and the document. If anyone alters the document after signing, the cryptographic seal breaks and the tampering becomes detectable.
SES works differently — it relies on demonstrated intent rather than cryptographic proof. That makes it easy to deploy but harder to defend if challenged. The decisive difference across all three tiers is non-repudiation: the signer's ability to deny signing. AES provides strong non-repudiation; QES provides the strongest, with legal presumption of validity on its side. Nevtan Sign applies these cryptographic principles to deliver tamper-evident, audit-ready signatures across every tier.
Common mistakes to avoid
Using SES for high-value contracts. It's easy, but it leaves you exposed to disputes. Set automatic signature-level rules so high-value documents require AES or QES.
Ignoring jurisdictional requirements. One tier does not fit every country — a document type may require QES in one EU member state but not elsewhere. Check the law in each market you operate in.
Not verifying your Trust Service Provider. An unaccredited TSP can render an AES or QES legally invalid. Confirm your provider appears on the EU Trusted List (or the local equivalent).
Overcomplicating workflows. Requiring QES for everything creates friction and slows approvals. Match the tier to the risk.
Neglecting audit trails. Even a QES is easier to defend with a complete event log. Nevtan Sign captures every event automatically.
Frequently asked questions
What is the difference between SES and AES?
SES is any electronic data used to sign — a typed name or scanned signature — with no identity verification. AES requires a signature that uniquely identifies the signer and is tamper-evident, usually via a digital certificate. AES provides stronger legal validity and non-repudiation.
Is QES required for all business contracts?
No. QES is only required for specific regulated documents, such as certain real estate deeds, court filings, and some financial agreements. For most business contracts, AES provides sufficient legal validity, and using QES unnecessarily adds cost and friction.
Can I use SES for international contracts?
SES may be accepted, but its enforceability varies by jurisdiction. For cross-border agreements, AES or QES is recommended to ensure enforceability under eIDAS or equivalent frameworks. Nevtan Sign supports multi-jurisdictional compliance.
How do I obtain a QES certificate?
Apply to a qualified Trust Service Provider (QTSP) on the EU Trusted List. The process involves identity verification (in person or by video) and issuance of a qualified certificate. Nevtan Sign integrates with QTSPs to streamline this.
What happens if a document signed with AES is tampered with?
AES creates a cryptographic seal that breaks if the document is altered after signing, so any tampering is detectable during verification. Nevtan Sign validates signature integrity automatically each time a document is accessed.
Are electronic signatures legally binding in the US?
Yes. Under the ESIGN Act and UETA, electronic signatures are legally binding in the US. The US simply doesn't use the SES/AES/QES classification. Nevtan Sign ensures compliance with US federal and state laws.
Can Nevtan Sign handle all three signature types?
Yes. Nevtan Sign supports SES, AES, and QES, and can apply the right tier automatically based on document type, value, or signer role — keeping you compliant and efficient.

