---
title: eIDAS levels and EU path
description: Which eIDAS assurance Seal produces today, and the roadmap to AES/QES
---

# eIDAS levels and EU path

CompAI EIDAS-1 / SEA-47. This page states Seal's **current** assurance level and
the honest path to Advanced / Qualified Electronic Signatures for EU deals.
It is documentation, not a product claim of QES.

## What Seal produces today

| Market frame | Seal level | What that means |
| --- | --- | --- |
| **eIDAS** | **SES** — Simple Electronic Signature | Identity + intent + integrity of the *record* (and, at Level 1, of final PDF bytes via platform PAdES-B). Not AES/QES. |
| **US ESIGN / UETA** | Electronic signature with demonstrable consent | ESIGN consent + privacy notice + sealed audit trail + Certificate of Completion. |

SES under eIDAS Art. 3(10) is still legally valid for many B2B flows. It is **not**
equivalent to an Advanced or Qualified signature for regulated EU use cases that
require AES/QES.

### What backs SES on Seal

1. **Identity / attribution** — recipient email + optional graded auth (`none` /
   `access_code` / `email_otp`, SEA-48); actor recorded on every sealed audit row.
2. **Intent** — ESIGN consent gate + optional privacy notice (SEA-45 / SEA-52).
3. **Integrity of the record** — per-org tamper-evident `audit_logs` hash chain
   (SEA-44); Certificate of Completion sidecar (SEA-50).
4. **Integrity of final PDF bytes** — flatten + platform PAdES-B on completed
   envelopes (SEA-49 Level 1). Verifiable offline without trusting Seal's DB.
   Platform cert is Seal-operated (self-signed or org-managed) — Acrobat will
   show “identity unknown” until a public-CA / trust-service path is added.

### Explicit non-claims

- Seal does **not** currently issue AES (unique-to-signer cert under sole control).
- Seal does **not** currently issue QES (qualified certificate + QSCD / certified
  remote signing).
- Certificate of Completion is an **audit summary**, not a PAdES seal.
- Platform PAdES-B is a **platform seal of the final artifact**, not a
  per-signer qualified identity.

## Roadmap to AES / QES

Ship only when a deal requires it. Levels match SEA-49:

| Step | Product | eIDAS mapping | Dependency |
| --- | --- | --- | --- |
| **Today** | SES + platform PAdES-B (L1) | SES | Shipped |
| **PAdES-T** | RFC 3161 TSA at seal time | Still SES/AES-adjacent evidence | SEA-49 Level 2 — TSA vendor + ops cost |
| **PAdES-LT/LTA** | Embed OCSP/CRL + archival timestamp | Long-term validation | SEA-49 Level 3 — enterprise/EU sales |
| **AES** | Per-signer certificates under sole control of the signer | Advanced Electronic Signature | TSP integration; signer key custody (device or remote) |
| **QES** | Qualified certificates + QSCD / CSC-style remote signing | Qualified Electronic Signature | EU trust-service provider; certified device/CSC; different regulatory company |

**Rule:** do not market “eIDAS compliant” without naming the **level**. Default
copy: “SES with sealed audit trail and platform-sealed final PDF; AES/QES via
TSP roadmap.”

## For EU RFPs

Answer with this page + [Trust & evidence](/getting-started/trust-and-evidence)
+ [Production checklist](/getting-started/production). If the RFP requires AES
or QES as a go-live gate, escalate — that is a TSP partnership, not a weekend
feature.
