eIDAS • Legal Certainty • Audit-Ready

Legal & Standards
Compliance Built In

rSign is designed from the ground up for full eIDAS compliance and long-term legal certainty.
Every signature module produces evidence that meets European and regional regulatory expectations
for banks and financial institutions.

Art. 25
Handwritten equivalence
27+1
EU + Adriatic recognition
QES
Highest legal strength
LTV
Long-term validation ready

Legal foundation of every rSign signature

Two essential pillars that give banks confidence in every signed document.

Regulation

eIDAS

The European legal framework that defines electronic identification and trust services.
Understand signature levels (SES / AES / QES), Article 25 legal effect, Qualified Certificates,
QSCD requirements and mutual recognition across Member States.

  • Regulation (EU) No 910/2014 & eIDAS 2.0
  • Qualified Electronic Signature requirements
  • QTSP & QSCD roles
  • How each rSign module complies

Explore eIDAS →

Evidence

Signature Validation

Cryptographic and legal checks that confirm a signature is authentic, intact and still valid —
at the moment of signing and years later. Essential for audits, disputes and long retention periods
typical in banking.

  • Certificate path & revocation checks
  • Qualified timestamps
  • PAdES / AdES long-term levels (LT / LTA)
  • Audit-ready evidence packages

Explore Validation →

Why legal strength and validation matter

High-value products require evidence that stands up in court and before regulators.

Loans, mortgages & guarantees

Documents that must remain enforceable for 10–30 years need the highest legal certainty and long-term validation support.

Dispute resistance

A full QES + qualified timestamp + proper validation data dramatically reduces successful challenges of signature authenticity.

Regulatory & audit readiness

Supervisors and internal audit expect clear proof of origin, integrity and non-repudiation for electronically signed records.

Cross-border operations

eIDAS mutual recognition means a QES created in one Member State is recognised as a QES across the entire EU and many neighbouring markets.

How rSign modules meet legal requirements

All four modules are designed to produce signatures with strong evidentiary value under eIDAS.

PAES — On-site AES

Advanced Electronic Signature with biometric handwriting capture on signature pads.
High evidentiary value + qualified timestamp. Ideal when full QES is not required.

OQES — On-site QES

Face-to-face identification by bank clerk + one-time Qualified Digital Certificate from a QTSP.
Full Qualified Electronic Signature with Art. 25 equivalence — no hardware pads needed.

IQES — In-App QES

Already-authenticated banking-app users. Bank acts as Registration Authority;
QTSP issues a short-lived one-time QDC. Full QES without leaving the app.

RQES — Remote QES

Fully remote signing via trusted cloud identity providers or national eID schemes.
Full QES with remote QSCD operated under QTSP control.

What every bank should know

1. Only QES = handwritten

Under eIDAS Article 25(2), only a Qualified Electronic Signature has the equivalent legal effect of a handwritten signature.

2. Qualified Certificate is mandatory

A QES must be based on a qualified certificate issued by a supervised QTSP that appears on the EU Trusted List.

3. QSCD protects the private key

The signature must be created using a Qualified Signature Creation Device (local or remote) under the sole control of the signatory.

4. Validation data must survive time

Certificates expire and revocation services disappear. Long-term validation (LT / LTA) embeds the evidence needed for future verification.

Legal certainty, one API away

rSign delivers full eIDAS QES and validation-ready signatures for every banking scenario —
on-site, in-app or remote.

Scroll to Top