Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that a claimed QES…
Identity Beyond IAM

What are the signs that a claimed QES offering is actually only AdES?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Identity Beyond IAM

Common warning signs include simplified identity checks, very fast onboarding, no clear mention of a QSCD, and vague statements about regulatory compliance. If the provider cannot show qualified status or explain how the signature creation process meets QES requirements, the solution is unlikely to deliver the higher legal assurance that businesses expect from QES.

How to Tell Whether the Offering Meets QES Rather Than AdES

A QES claim should stand up to evidence, not marketing language. The key distinction is that a Qualified Electronic Signature depends on a qualified trust framework, stronger identity assurance, and a qualified signature creation device or equivalent qualified setup, while an Advanced Electronic Signature can still be valid but does not carry the same legally anchored status. If a provider cannot show the qualified chain, the claim should be treated cautiously.

One practical indicator is whether the provider can explain the signing flow in terms a compliance or legal team can verify. A genuine QES offering should identify the certification basis, the trust service status, and the role of the signing component in a way that is specific enough to audit. By contrast, AdES products often rely on broad statements about security, biometrics, or “high assurance” without tying those claims to the qualified requirements that matter for legal weight and cross-border recognition.

Another useful check is whether the service can distinguish identity proofing from signature qualification. Strong identity checks are not enough on their own, because a well-run AdES service can also perform robust verification without becoming QES. In practice, many security and legal teams discover the gap only when they ask for the qualified evidence trail and receive language that describes confidence, not qualification.

You can also look for how the provider handles the signing key or signing device lifecycle. A QES claim should not depend on opaque, convenience-first key handling that leaves the qualification status unclear. If the provider cannot explain the controls around the signing process, or if the description sounds interchangeable with a standard high-assurance e-signature platform, the claim is weak.

Documentation and Trust Signals That Should Be Explicit

The strongest sign that an offering is really QES is that its documentation is precise enough for a reviewer to separate trust-service claims from product claims. That means the provider should name the qualified service, the applicable supervisory or certification context, and the component that actually supports qualified signature creation. If these elements are missing, the phrase “QES” may be being used as a loose synonym for “secure e-signature,” which is not the same thing.

Look for whether the provider publishes evidence that is independently checkable rather than self-descriptive. A serious QES service should make it possible to verify status, not just read assertions. Helpful clues include a clear trust-service listing, a qualified workflow description, and unambiguous wording about when the signature is intended to meet QES requirements rather than ordinary advanced-signature requirements.

It also matters whether legal assurance is described as a product feature or as a regulated status. QES is not mainly about user experience or speed; it is about whether the service sits inside a qualification regime that changes the legal interpretation of the signature. That is why very polished onboarding and identity steps can be misleading if they are not tied to the qualified framework.

If the documentation repeatedly uses terms such as “bank-grade,” “enterprise-grade,” or “compliant” without naming the qualification basis, that is usually a sign to dig deeper. Regulators and counterparties care about whether the service is qualified, not whether it sounds secure. In practice, many teams uncover the difference only after procurement asks for the exact status evidence rather than the sales deck.

Edge Cases Where AdES Looks Close Enough to Confuse Buyers

Tighter trust claims often increase verification overhead, so buyers have to balance convenience against legal certainty.

Some offerings sit close enough to QES in user experience that the distinction is easy to miss. A provider may use strong remote identity proofing, multifactor authentication, and tamper-resistant signing flows, yet still stop short of QES if the qualification requirements are not met end to end. That is a genuine operational tradeoff, because the service can feel “qualified” to users while remaining only AdES in legal terms.

Another common edge case is where the provider supports multiple signature tiers. In those services, one workflow may deliver QES while another defaults to AdES, depending on the signer journey, jurisdiction, or user profile. The label on the front page can therefore be less important than the exact workflow being used for the transaction you care about.

There is also a consensus gap in how buyers interpret biometrics and identity verification. Strong identity proofing improves trust, but it does not by itself transform an advanced signature into a qualified one. The practical test is whether the provider can map the specific signing path you intend to use to the qualified status it claims. If it cannot, the safe assumption is that the service should be treated as AdES until proven otherwise.

NIST SP 800-53 Rev 5 Security and Privacy Controls can help teams structure verification around evidence, access control, and auditability, but it does not replace the legal question of whether the signature service is truly qualified. That distinction is exactly where many evaluations go wrong.

Risk and Threat Considerations

The main risk is false assurance: organisations may treat an AdES workflow as if it has QES-level legal weight, only to discover later that the signature does not meet the required status for a dispute, regulated process, or cross-border acceptance. The exposure is not just technical, because the failure can undermine evidentiary value, contract enforceability, and governance decisions built on the signature claim.

Failure mechanism: The breakdown usually happens when identity assurance, onboarding speed, or security branding is mistaken for qualification. If the provider does not actually operate within the qualified trust chain, or if the specific signing path used by the business is not the qualified one, the organisation may have an advanced signature with strong controls but without QES status.

Impact: The signature may still be valid as an AdES, but it may not deliver the higher legal presumption or recognition the buyer expected. That can create rework, contractual challenge, regulatory friction, and a weak evidentiary position if the signature is later scrutinised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity Management, Authentication, and Access ControlQES claims hinge on identity assurance and controlled signing access.
Recommendation — Verify the signing workflow's identity and access controls before accepting a QES claim.
CIS Controls v85 — Account ManagementQualified signing depends on disciplined account and signing-identity governance.
Recommendation — Confirm the signer account lifecycle and ownership before treating the service as qualified.
NIST SP 800-63IAL — Identity Assurance LevelThe question turns on whether identity proofing is strong enough for the claimed assurance.
Recommendation — Map the provider's proofing evidence to the required assurance level, not to marketing language.
PCI DSS v4.012 — Support Information Security with Organizational Policies and ProgramsBuyers need documented evidence and governance around security claims and service assurance.
Recommendation — Require documented evidence and governance review before relying on the signature service.

Practitioner Guidance

What to verify: Ask for evidence that the exact signing flow you intend to use is qualified, not just that the vendor offers a qualified product somewhere in its catalogue. Verify the trust-status evidence, the role of the signature creation component, and the jurisdictional scope before relying on the claim.

Common mistake: Teams often overread strong identity proofing and polished onboarding as proof of QES. That shortcut is risky because AdES can also look robust on the surface while lacking the qualification status that changes legal treatment.

Practitioner takeaway: Treat QES as a status claim that must be proven for the specific signing journey, not as a branding claim inferred from security features.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org