Learn · 2 min read

Adobe AATL vs EU LOTL

Both are trust lists a signature can be checked against, and Adobe Acrobat and most validators check both. But they answer different questions: one is a legal mechanism under EU law, the other is a private company’s technical trust program.

TL;DR

Adobe’s AATL and the EU LOTL are both trust lists, but they answer different questions: the LOTL confers EU legal standing, while the AATL is a private software vendor’s trust program. A signature can be on one, both, or neither.

EU LOTL: a legal mechanism

The EU List of Trusted Lists is maintained by the European Commission under eIDAS. Being listed on it, through a member state’s national Trusted List, is what allows a certificate to carry EU legal weight, the Article 25 handwritten-signature equivalence for qualified signatures, or the Article 35 integrity presumption for qualified seals. It exists because EU law says it must.

Adobe AATL: a software vendor’s trust program

The Adobe Approved Trust List is Adobe’s own program, used by Acrobat and Reader to decide which certificate authorities to display with a trusted checkmark when opening a signed PDF. It’s global rather than EU-specific, and includes certification authorities operating well outside the EU regulatory framework, including in the US and elsewhere. It exists because Adobe, a private company, chose to build it, not because any regulation requires it.

The practical difference

A signature can be on the AATL without being on the EU LOTL, and vice versa. A document signed by a US-based provider on the AATL might show a trusted green checkmark in Acrobat, and still carry none of the legal presumptions eIDAS grants to an EU-qualified signature. Conversely, an EU-qualified signature not recognised by Adobe’s program might show as unverified in Acrobat’s default view, despite having stronger legal standing under EU law than an AATL-only signature does.

What Acrobat shows you by default is Adobe’s trust list, not the EU’s. That distinction matters most for anyone in the EU relying on a signature’s legal weight rather than just wanting a green checkmark.

Why check both

Neither list alone tells the full story. A validator that checks both gives a complete picture: whether a signature has EU legal standing, whether it’s recognised by the software most people use to open PDFs day to day, or both. Tindom checks a document against both for exactly this reason — alongside the third-country lists recognised under eIDAS and the Swiss and UK trusted lists, five sources in total.

Was this helpful?