eIDAS, Smart-ID, Mobile-ID and the ID card: what makes an e-signature legally binding

Allkiro team

Allkiro team

28.07.2026 · 5 min read

#eidas#smart-id#mobile-id#id-card#legal
eIDAS, Smart-ID, Mobile-ID and the ID card: what makes an e-signature legally binding

Under the EU’s eIDAS regulation, not every electronic signature carries the same legal weight. There are three tiers, and the distinction decides whether your contract survives a dispute.

The three tiers, briefly

Simple electronic signature (SES). Typing your name at the bottom of an email, or clicking “I agree”. Admissible as evidence, but you have to prove it was really you.

Advanced electronic signature (AdES). Uniquely linked to the signer, capable of identifying them, created with something under the signer’s sole control, and tamper-evident — any later change to the document invalidates the signature.

Qualified electronic signature (QES). An advanced signature created with a qualified signature creation device, backed by a qualified certificate from a trust service provider on the EU Trusted List. Article 25(2) of eIDAS gives a QES the same legal effect as a handwritten signature, and Article 25(3) requires every EU member state to recognise a QES issued in any other member state.

Only the third tier gives you automatic, EU-wide equivalence with pen and paper.

Smart-ID, Mobile-ID and the ID card all reach the qualified tier

This is the part people outside the Baltics tend to find surprising: the everyday national eID means in Estonia, Latvia and Lithuania produce qualified signatures, not merely advanced ones.

  • ID card — the chip on the physical card holds the private key. In a browser this works through Web eID, which replaced the older browser plugins.
  • Mobile-ID — the key lives on a special SIM card issued by your mobile operator. You confirm with PIN2 on the phone itself.
  • Smart-ID — the key is split between your device and the provider’s server, so neither half alone can sign. This is what makes Smart-ID work on any phone, without a special SIM or a card reader.
  • Smart-ID+ — the newer generation. The main practical change is that you no longer type your personal identification code into a web page: the session is bound to your Smart-ID app by QR code or app-to-app. That removes the step phishing sites relied on.

Whichever you use, the resulting signature is legally equivalent. Choose on convenience, not on validity.

What you actually get: the ASiC-E container

An Estonian digital signature is not “a PDF with a picture of a signature on it”. Signing produces an ASiC-E container — the .asice file, historically .bdoc — which bundles together:

  • the original document or documents, byte for byte,
  • one signature block per signer,
  • each signer’s qualified certificate,
  • a qualified timestamp, proving the signature existed at a given moment,
  • OCSP validity confirmation for the certificate at signing time.

Two consequences follow, and both matter.

It is tamper-evident. Change one byte of the document and every signature in the container fails validation. You cannot quietly edit a signed contract.

It is portable. Any conforming tool can verify it — you are not dependent on the platform that created it. That is a real difference from signature platforms whose output can only be checked inside their own portal.

How to verify a signed container yourself

You do not have to take any vendor’s word for it. Three independent routes:

  1. DigiDoc4 client — the free desktop application from the Estonian state. Open the .asice file; it shows every signer, their personal identification code, the signing time and the validity verdict.
  2. European Commission DSS validator — an EU-operated tool that validates against the EU Trusted List. Useful when the counterparty is outside the Baltics and does not know DigiDoc.
  3. Any conforming platform — including Allkiro, which validates uploaded containers and shows the signature chain.

If a signature is genuine and qualified, all three agree. If a tool tells you a signature is valid but the DSS validator disagrees, believe the validator.

Common questions

Does a qualified signature work outside Estonia? Yes. Article 25(3) of eIDAS obliges every member state to recognise a QES issued in another member state. In practice, a counterparty unfamiliar with .asice files may still need pointing at the DSS validator.

Can a signature be removed once given? No. A signature is cryptographically bound to the document’s content, so it cannot be lifted out. What you can do is cancel a signing process before everyone has signed, or issue a new version of the document and send it again.

Is there anything a qualified signature cannot be used for? A few instrument types still require notarial form under national law — transfers of real estate, and certain company-law acts, are the usual examples in Estonia. For employment contracts, service agreements, sales contracts, leases and NDAs, a QES is sufficient.

What does a platform add, if the state’s client is free? Nothing at all, at the level of a single signature. What it adds is everything around it: sending a document to several signers in parallel or in a set order, deadlines and automatic reminders, shared folders with role-based access, templates, and search that reads the inside of documents rather than just filenames.

Where Allkiro fits

Allkiro is an Estonian platform that produces qualified eIDAS signatures with Smart-ID, Smart-ID+, Mobile-ID and the ID card, packaged in standard ASiC-E containers you can verify anywhere. Around the signature it adds parallel and sequential workflows, deadlines with automatic reminders, shared team workspaces, folders, tags, reusable templates, and full-text search that reads document contents. Interface in Estonian, English, Latvian and Lithuanian; data in the EU; a free-forever plan with no card required.