Learn · 2 min read

"We use e-signatures" vs "our e-signatures are ETSI-compliant"

These sound like the same claim. They aren’t, and the gap between them is where most organizational exposure to signature disputes actually lives.

TL;DR

Adopting an e-signature tool is a procurement decision. ETSI compliance is a property of the specific signature format and validation process the tool actually produces, and the two don’t automatically go together. An organization can use e-signatures for years without anyone confirming whether the second claim is true.

Why the two get conflated

"We use e-signatures" describes a decision made once, usually by procurement or IT, to adopt a signing tool instead of wet-ink. "Our e-signatures are ETSI-compliant" is a specific technical claim about the signature format the tool produces (PAdES, XAdES, or CAdES, per ETSI EN 319 122/132/142), the trust list its certificates chain to, and the legal level (simple, advanced, or qualified) it actually issues. The first claim gets made once, at rollout. The second is rarely checked at all, because nobody’s job description says to.

Who owns which claim

Procurement or IT typically owns the first claim: the tool is deployed, integrated, and in use. Compliance, legal, or an internal auditor is the one who should own the second, but often doesn’t know it’s their responsibility until a dispute forces the question. That handoff gap, between the team that adopted the tool and the team accountable for its compliance properties, is exactly where the exposure sits.

What "ETSI-compliant" actually requires checking

It isn’t a single yes/no property of a vendor. It depends on the specific format produced, whether the certificate chains to a recognized trust list, which legal level applies, and whether the signature will still be checkable years from now. See a practical checklist for auditable digital signatures for the specific things to verify, rather than assuming the vendor relationship settles it.

Why this doesn’t surface on its own

Most signed documents are never scrutinized closely enough to expose the gap. A signature that isn’t independently verifiable still looks, functionally, exactly like one that is, right up until someone needs to prove it in a dispute or an audit. There’s no natural trigger that forces the check earlier, which is why it has to be a deliberate one.

Closing the gap

Confirm what your signing process actually produces, not what the procurement decision assumed it produced, and confirm it specifically enough to answer the questions an auditor or a disputing counterparty would actually ask. See what actually happens when a non-compliant e-signature gets challenged for what that looks like when it’s tested for the first time in a live dispute rather than a calm review.

Was this helpful?