Skip to main content

    AATL vs Qualified Electronic Signature: What Your Certificate Actually Buys

    AATL decides whether Acrobat trusts your signature. eIDAS decides whether it equals a handwritten one. Two different things. How to check which you have.

    MS
    My-SSL Team
    ·
    13 min read
    ·
    Published October 1, 2026
    ·
    Last updated October 1, 2026

    The short answer

    These are two separate tests, and most buying guides run them together. The Adobe Approved Trust List decides whether Acrobat shows your signature as trusted the moment someone opens the PDF. eIDAS decides what the signature means in law, and only a qualified electronic signature — an advanced signature made with a qualified certificate on a qualified signature creation device — carries the handwritten-signature equivalence that Article 25(2) grants. A standard AATL document signing certificate passes the first test and stops at advanced on the second.

    If the first test is what you need — PDFs and Office files that open as trusted in Acrobat and Reader with nothing for the recipient to configure — that is a standard document signing certificate, and it is what My-SSL sells. If you need the second, read the eIDAS section before ordering anything, because a qualified signature is a different product from a different part of a CA's catalogue, with its own identity checks.

    Trust-list membership and eIDAS signature level plotted as two independent axes, showing that an AATL document signing certificate is trusted automatically while reaching only the advanced levelA chart with two axes. The horizontal axis runs from signatures that need the recipient to establish trust by hand, on the left, to signatures Acrobat trusts automatically, on the right. The vertical axis is the eIDAS level, with simple at the bottom, advanced in the middle and qualified at the top. Three certificate types are plotted. A self-signed or internal CA certificate sits bottom left: the recipient must trust it by hand. An AATL document signing certificate, highlighted in gold, sits on the right at the advanced level: trusted the moment the file opens, but not equivalent to a handwritten signature. A qualified certificate on a qualified signature creation device sits top right, carrying handwritten-signature equivalence under Article 25 paragraph 2. The top left region is empty by design, because a qualified certificate comes from a provider Acrobat already trusts.Two different questions, two different answersLeft to right: will Acrobat trust it on open? Bottom to top: what does eIDAS say it means?QualifiedAdvancedSimpleRecipient trusts it by handTrusted automaticallyEmpty by design: a qualified certificatecomes from a provider Acrobat already trusts.Self-signed or internal CAa warning until trust is addedAATL document signing certtrusted on open, advanced levelthis is what most people buyQualified cert on a QSCDequal to a handwritten signatureArticle 25(2), EU-wideAATL answers the horizontal axis only. eIDAS answers the vertical axis only.Moving right is a purchase. Moving up is a different product.
    Almost every argument about document signing certificates is two people standing on different axes. Separate them and the answer to "is this legally valid" stops being a yes-or-no question.

    Two bodies of writing cover this subject and they never meet. E-signature platforms explain the eIDAS levels at length and never mention trust lists, because their product hides the certificate from you entirely. Certificate authority documentation explains AATL, key storage and timestamping, and never says which eIDAS level the certificate reaches, because that depends on which class you bought. The gap between them produces a support ticket we see several times a year: someone buys an AATL certificate, signs a contract that opens with a green check mark, and is then told by the counterparty's lawyer that a qualified signature was required. Nothing was misrepresented. Two different questions were answered as though they were one. This page is the mapping.

    What are the two questions people mix up?

    The first question is technical: will the recipient's software validate this signature without being configured? That is what trust-list membership answers. The second is legal: what does this signature count as under eIDAS? That is set by the class of certificate and where its private key lives. A certificate can score perfectly on the first and only mid-range on the second, and the one most organisations buy does exactly that.

    The confusion is understandable, because both questions get answered by the same green tick in a PDF reader. Acrobat's validity indicator is reporting two facts: the signing certificate chains to a root Acrobat trusts, and the document has not been modified since it was signed. Neither fact says anything about eIDAS. A signature can be valid, trusted and intact while sitting at the advanced level, and it can be qualified while showing a warning in a reader that cannot resolve the trust.

    Keeping the questions apart also fixes the pricing confusion. Moving right on the horizontal axis is a purchase: buy from a CA that is on the trust lists. Moving up the vertical axis is not a purchase upgrade so much as a different process, because qualified status requires a vetted issuer, a vetted device and an identity check on the person signing.

    What does Adobe AATL actually get you?

    AATL gets you automatic trust in Acrobat and Acrobat Reader. Adobe distributes the root certificates of member authorities to its readers, so a signature made with a certificate from an AATL member validates on open with no configuration by the recipient. That is the whole of what membership guarantees. It is a statement about distribution and about the member's audited practices, not a statement about European law.

    Getting onto the list is not trivial, which is why AATL carries real weight. Adobe's technical requirements oblige members to keep subscriber private keys in a medium that prevents export and duplication, backed by certified hardware — FIPS 140-2 Level 2 or a Common Criteria evaluated device are the benchmarks cited, with higher levels used in practice for CA keys — and to run strong identity and authorisation procedures they can document to Adobe. Minimum key sizes are RSA 2048 or ECC P-256.

    The key-protection rule is why cloud document signing exists without being a shortcut. The requirement is that the key sits in hardware that will not surrender it, not that the hardware sits on your desk. A CA-operated HSM satisfies it as well as a USB token does, which is the mechanism behind every "no physical device" document signing product, including the cloud-based document signing certificates we issue through Certum.

    What AATL does not do is tell a lawyer anything. There is no eIDAS level implied by membership, and the list contains both qualified and non-qualified authorities. Reading a green check mark as legal equivalence is the single most common mistake in this area, and it is the one that only surfaces when somebody disputes a document.

    What are the three eIDAS signature levels?

    eIDAS defines three: simple, advanced and qualified. A simple electronic signature is any data in electronic form used to sign — a typed name will do. An advanced signature must pass the four tests in Article 26. A qualified signature is an advanced one plus a qualified certificate and a qualified signature creation device, and only it carries the handwritten-signature equivalence in Article 25(2). Each level contains the one below it.

    The legal framework is Regulation (EU) No 910/2014, amended by Regulation (EU) 2024/1183, which is the text people call eIDAS 2.0. Article 25(1) does the quiet heavy lifting: a signature cannot be denied legal effect or admissibility as evidence just for being electronic, or for failing to meet the qualified requirements. That is the sentence worth remembering when someone claims an advanced signature is "not legally valid". It is admissible. What it lacks is the automatic equivalence, and the reversal of the argument that comes with it.

    The three eIDAS electronic signature levels as nested steps: simple, advanced with its four Article 26 tests, and qualifiedThree stacked panels. The bottom panel is the simple electronic signature: any data in electronic form attached to or logically associated with other data, such as a typed name or a scanned image. The middle panel is the advanced electronic signature under Article 26, which must pass four tests shown as four boxes: uniquely linked to the signatory, capable of identifying the signatory, created using data under the signatory's sole control, and linked to the data so that any later change is detectable. The top panel, highlighted in gold, is the qualified electronic signature under Article 3 point 12: an advanced signature plus a qualified certificate meeting Annex I plus a qualified signature creation device meeting Annex II, issued by a qualified trust service provider on an EU trusted list. A note states that Article 25 paragraph 2 gives this level the legal effect of a handwritten signature, and that each level contains the one below it.Each level contains the one below itQualified electronic signature (QES) — Article 3(12)An advanced signature, plus a qualified certificate (Annex I), plus a qualified signaturecreation device (Annex II) — from a qualified trust service provider on an EU trusted list.Article 25(2): the legal effect of a handwritten signature, in every Member State.Advanced electronic signature (AdES) — Article 26All four tests must hold:uniquely linkedto the signatorycapable ofidentifying themkey under theirsole controllater changesare detectableSimple electronic signature (SES)Any data in electronic form used to sign: a typed name, a scanned image, a tick box.A certificate is what moves you from the bottom panel to the middle one. Where the key lives moves you to the top.
    Note what the top panel adds: not a stronger algorithm, but a vetted issuer and a vetted place to keep the key. Qualified status is a statement about process, not cryptography.

    Article 26's four tests are where certificates do their work. A certificate binds a verified identity to a key pair, which handles "uniquely linked" and "capable of identifying". Hardware key storage handles "sole control". The signature's own cryptography handles tamper detection. This is why a PKI-based signature reaches the advanced level almost by construction, while a drawn squiggle in a web form has to be argued for.

    The jump to qualified adds no cryptography at all. It adds supervision: the issuer must hold qualified status granted by a Member State supervisory body, the certificate must meet Annex I, and the device holding the key must meet Annex II. Qualified status is a statement about process and oversight, and that is the reason it cannot be bought as an add-on to a certificate you already hold.

    Is a document signing certificate a qualified signature?

    Not unless it is sold as a qualified certificate. A commercial document signing certificate from an AATL member produces an advanced electronic signature: identity-validated, hardware-held, tamper-evident, trusted in Acrobat. It becomes qualified only when the issuer holds qualified trust service provider status for that service and the key is on a qualified signature creation device. Those are catalogue entries, not configuration options.

    Certum, whose certificates we resell, is a useful illustration because it appears in both places. Its Document Signing Certificate is an AATL product aimed at PDFs and Office documents. Its qualified electronic signature services are listed separately, under qualified services, because they are a different class of certificate issued under its qualified trust service provider status. Most CAs that do both split their catalogue the same way, and the split is the fastest way to tell what you are looking at: if a product page talks about AATL and Acrobat trust, it is the advanced product; if it talks about trusted lists, supervisory bodies and identity verification sessions, it is the qualified one.

    What you are comparingAATL document signing certificateQualified certificate on a QSCD
    Trusted in Acrobat on openYesYes, via the EU trusted lists
    eIDAS level reachedAdvanced (Article 26)Qualified (Article 3(12))
    Equivalent to a handwritten signatureNoYes, Article 25(2)
    Issuer requirementCA audited and listed by AdobeQualified status from a Member State supervisory body
    Key storageCertified hardware: token or CA-operated HSMQSCD meeting Annex II, local or remote
    Marked inside the certificateNo qualified statementsQcCompliance, usually QcSSCD and QcType
    Typical useContracts, invoices, reports, internal approvalsStatutory written form, registries, regulated filings

    One row deserves emphasis, because it is where the two axes finally touch. Both certificates are trusted in Acrobat, and they get there by different routes: one through AATL, the other through the European Union Trusted Lists. The route is recorded, and that is what makes the level checkable from inside a PDF.

    What is the EUTL, and how does Acrobat use it?

    The European Union Trusted Lists are the public registry of trust service providers granted qualified status by a Member State supervisory body under eIDAS. Acrobat and Acrobat Reader ship with support for them, built as an extension of the same framework that maintains AATL roots. A signature made under a certificate published through the EUTL validates in Acrobat without special software, and the reader records that the trust came from the EU lists rather than from AATL.

    That recorded distinction is more useful than it first appears. Open the signature properties of a signed PDF and the trust source is named. Wording that points at the European Union Trusted Lists means a qualified trust service provider stands behind the certificate, which is the single fastest practical indicator that you are looking at something more than an advanced signature. It is not a formal determination of qualified status — a provider can be on the EUTL for one service and not another, so a complete answer still needs the certificate itself — but as a first check it takes about five seconds.

    The lists are also how cross-border recognition works in practice. Article 25(3) makes a qualified signature based on a qualified certificate issued in one Member State qualified in all of them, and the trusted lists are the machine-readable plumbing that lets a verifier in Lisbon resolve a provider supervised in Warsaw. Certum, as a Polish qualified trust service provider, is on the list for exactly that reason.

    How do I check whether a certificate is qualified?

    Look inside the certificate for the qualified certificate statements extension, OID 1.3.6.1.5.5.7.1.3, and specifically for the ETSI QcCompliance statement, 0.4.0.1862.1.1. That statement is the issuer declaring the certificate qualified under Regulation (EU) No 910/2014. If it is absent, the certificate is not qualified, and no amount of trust-list membership changes that.

    Where qualified status is recorded inside an X.509 certificate: the qcStatements extension and the ETSI object identifiers it carriesOn the left, a certificate drawn as a stack of fields: subject, issuer, validity, key usage, extended key usage, a gold-highlighted row for the qualified certificate statements extension with object identifier 1.3.6.1.5.5.7.1.3, and revocation pointers. A connector leads to a panel on the right that expands that extension into three ETSI statements. QcCompliance, object identifier 0.4.0.1862.1.1, is the issuer declaring the certificate qualified under Regulation (EU) No 910/2014. QcSSCD, 0.4.0.1862.1.4, declares that the private key resides on a qualified signature creation device. QcType with the esign value, 0.4.0.1862.1.6.1, declares the certificate is for electronic signatures rather than seals or website authentication. A footnote states that no QcCompliance statement means the certificate is not qualified, and that the statements are the issuer's assertion, so the provider should also be confirmed on the EU trusted list.Qualified status is written inside the certificateSigning certificate (X.509)SubjectIssuerValidityKey UsageExtended Key UsageQualified Certificate Statements1.3.6.1.5.5.7.1.3CRL / OCSP pointersSignatureRFC 3739 profileWhat the extension carries0.4.0.1862.1.1QcCompliance"This is a qualified certificate underRegulation (EU) No 910/2014."0.4.0.1862.1.4QcSSCD"The private key is on a qualifiedsignature creation device."0.4.0.1862.1.6.1QcType: esign"For electronic signatures — notseals, not website authentication."Defined in ETSI EN 319 412-5No QcCompliance statement means the certificate is not qualified.These are the issuer's own assertions, so confirm the provider on the EU trusted list as well.
    This is the check that settles the argument without anyone having to open a PDF: if QcCompliance is absent, no amount of trust-list membership makes the signature qualified.

    The extension comes from the qualified certificates profile in RFC 3739; the statements inside it are defined by ETSI EN 319 412-5. Three are worth knowing. QcCompliance (0.4.0.1862.1.1) is the qualified declaration itself. QcSSCD (0.4.0.1862.1.4) says the private key lives on a qualified signature creation device, which is the other half of the qualified-signature requirement. QcType (0.4.0.1862.1.6) says what the certificate is for, with 0.4.0.1862.1.6.1 meaning electronic signatures, as opposed to electronic seals or website authentication.

    OpenSSL will show you the extension is present, but not what it says. There is no built-in profile for it, so the contents print as a hex dump rather than as names:

    # Does the certificate carry qualified statements at all?
    openssl x509 -in signing-cert.pem -noout -text | grep -A6 "1.3.6.1.5.5.7.1.3"
    
    # The ETSI OIDs are inside that dump; OpenSSL does not decode them.
    # For a readable answer, use one of the checks below instead.

    So in practice, run three checks in this order. Open the signed PDF in Acrobat and read the trust source in signature properties — thirty seconds, and it usually settles the question. Then look the provider up in the European Commission's Trusted List Browser and confirm it holds qualified status for the service you care about, since a provider qualified for timestamping is not automatically qualified for signature certificates. Only then go to the certificate bytes, which is where you confirm QcCompliance and QcSSCD rather than taking a product page's word for it.

    Worth keeping in mind: the statements are the issuer's own assertion. They are checkable against the trusted list, and an issuer that misstates them is risking its qualified status, which is a strong deterrent. But the authoritative source for "is this provider qualified" is the list, not the certificate. The certificate tells you what the issuer intended this particular certificate to be.

    Which level do you actually need?

    Work backwards from whoever can refuse the document. If you and the counterparty decide between yourselves, an advanced signature is normally sufficient and that covers most commercial contracts, invoices, reports and internal approvals. If a statute, court, registry or regulator requires written form or names a qualified signature, nothing below qualified will do. The expensive mistake is choosing on how much assurance sounds comforting.

    A decision tree choosing between an advanced and a qualified electronic signature based on who can demand whatA decision tree starting from the question: who decides whether this signature is good enough? Three branches follow. If you and the counterparty decide between yourselves, as with internal approvals, purchase orders or ordinary commercial contracts, an advanced electronic signature from an AATL document signing certificate is normally sufficient. If a counterparty's policy names a level, match whatever their policy says and get it in writing before signing, because retrofitting a signature level after the fact means re-signing. If a statute, court, registry or regulator requires written form or names a qualified signature, a qualified electronic signature is required and nothing else substitutes; this branch is highlighted in gold. A closing note advises choosing the lowest level that survives a dispute you can actually picture, since the higher level costs more and adds identity verification steps.Who gets to decide whether the signature is good enough?Start here: who sets the bar?Not how much assurance sounds reassuring.You and the other sideinternal approvals, POs,ordinary commercial contractsAdvanced is enoughAATL document signingcertificateTheir procurement policya bank, an enterprise buyer,a tender portalMatch their policyget the level in writingbefore you sign anythingA statute or a registrywritten form required, or aregulator names the levelQualified, or nothinga qualified certificate on aQSCD, from a QTSPPick the lowest level that survives a dispute you can actually picture.The qualified level costs more and adds identity checks for every signer. Buy it when something requires it.
    The middle branch is the one that causes re-work. Ask for the required level in writing before signing, because changing it afterwards means signing the document again with a different certificate.

    The middle branch is where real money gets wasted. Enterprise procurement portals and tender systems often specify a signature level in a document nobody reads until the submission is rejected, and a signature level cannot be upgraded after the fact — you re-sign with a different certificate, which means re-collecting approvals from everyone who already signed. Ask for the required level in writing before the first signature, not after.

    There is also a reason not to default to qualified when nothing demands it. Qualified certificates require identity verification of each individual signer, which for a team means a verification session per person, repeated at renewal. For a finance department sending out three hundred signed invoices a month, an organisation-level document signing certificate signs in the company's name and avoids that entirely. The choice is partly legal and partly about who is actually doing the signing.

    A practical rule that has held up well: pick the lowest level that survives a dispute you can actually picture. If you cannot describe the scenario in which the signature gets challenged and an advanced signature loses, you are buying insurance against nothing.

    Do timestamps change any of this?

    Timestamps do not change the eIDAS level, but they decide whether the signature still verifies in five years. A signature with no timestamp becomes unverifiable once the signing certificate expires, because a verifier cannot tell whether the signature was made while the certificate was valid. Long-term validation, the LTV mechanism in PAdES, embeds a trusted timestamp plus the revocation data needed to check the chain as it stood at signing time.

    This matters more for document signing than for anything else a CA sells, because documents outlive certificates by design. A supply contract signed today may be litigated in 2034, long after the certificate that signed it expired and possibly after the issuing CA has retired the intermediate. Without a timestamp, the reader has a signature it cannot date. With one, the signature carries its own evidence.

    The practical advice is short: timestamp every signature, and if you are pursuing a qualified signature, use a qualified timestamp, since eIDAS defines qualified electronic timestamps as their own trust service with their own presumption of accuracy. Mixing a qualified signature with an unqualified timestamp is a common and avoidable gap. The same reasoning drives timestamping in code signing, where a signed binary has to keep validating after the certificate behind it expires.

    What changed under eIDAS 2.0?

    Regulation (EU) 2024/1183 entered into force on 20 May 2024 and added three new qualified trust services, one of which matters directly here: the management of remote electronic signature and seal creation devices. Remote qualified signing — the key held in a provider-operated HSM instead of on a card in your hand — is now a supervised qualified service in its own right, not an arrangement left to each provider.

    The alignment date has passed. Implementing regulations setting the reference standards for managing remote qualified devices were published on 30 July 2025, and 21 May 2026 was the date by which providers had to bring their remote device management into line with them. As of 1 October 2026, that means a concrete check you can run: if you sign with a cloud-based qualified signature, the provider's qualified status for remote device management should be visible on the trusted list, alongside its status for issuing the certificates.

    The other change worth tracking is the European Digital Identity Wallet, which is designed to let citizens create a qualified electronic signature from a phone. If that lands as intended, the practical barrier to the qualified level stops being the card reader and becomes the identity-verification step, and the calculation in the section above shifts. It has not shifted yet, and buying decisions made now should be based on what providers are supervised for today rather than on wallet timelines.

    Frequently Asked Questions

    Answers to common questions about certificates and our services.

    Is an Adobe AATL document signing certificate a qualified electronic signature?

    No, not on its own. AATL membership means Adobe distributes the issuing CA's root to Acrobat and Reader, so the signature validates without the recipient configuring trust. Qualified status under eIDAS is a separate test: the signature must be made with a qualified certificate issued by a qualified trust service provider on an EU trusted list, and the private key must live on a qualified signature creation device. A standard commercial document signing certificate meets the requirements for an advanced electronic signature and is trusted in Acrobat, which is a different claim from legal equivalence with a handwritten signature.

    What is the difference between an advanced and a qualified electronic signature?

    A qualified electronic signature is an advanced one plus two specific additions. Article 26 of eIDAS defines the advanced level through four tests: the signature is uniquely linked to the signatory, it can identify them, it is created using data under their sole control, and any later change to the signed data is detectable. A qualified signature meets all four and is additionally based on a qualified certificate for electronic signatures and created by a qualified signature creation device. Only the qualified level carries the handwritten-signature equivalence in Article 25(2).

    Is an advanced electronic signature legally valid in the EU?

    Yes, in the sense that matters most often. Article 25(1) of eIDAS says an electronic signature cannot be denied legal effect or admissibility as evidence in legal proceedings solely because it is electronic or because it does not meet the qualified requirements. What an advanced signature does not get is the automatic equivalence with a handwritten signature that Article 25(2) reserves for qualified signatures. Where national law requires written form for a particular act, or a registry or regulator specifies a qualified signature, an advanced signature will not satisfy it.

    How can I tell if a certificate is qualified?

    Look for the qualified certificate statements extension, OID 1.3.6.1.5.5.7.1.3, and specifically the ETSI QcCompliance statement, 0.4.0.1862.1.1. That statement is the issuer declaring the certificate qualified under Regulation (EU) No 910/2014. A companion statement, QcSSCD (0.4.0.1862.1.4), declares that the private key sits on a qualified signature creation device. Confirm the issuer independently in the European Commission's Trusted List Browser, since the statements are the CA's own assertion rather than proof.

    Will Acrobat show a green check mark for a non-qualified document signing certificate?

    Yes, provided the issuing CA is on the Adobe Approved Trust List and the signature is otherwise intact. Acrobat's validity indicator answers whether the certificate chains to a root it trusts and whether the document has been altered since signing. It is not a statement about the eIDAS level. Acrobat does distinguish where the trust came from: signature properties name the trust source, and the European Union Trusted Lists wording is the clue that a qualified trust service provider is behind the certificate.

    Do I need a hardware token for an AATL document signing certificate?

    The key has to be in hardware, though not necessarily hardware you hold. Adobe's AATL technical requirements oblige members to keep subscriber keys in a medium that prevents export and duplication, with certified hardware such as a FIPS 140-2 Level 2 or Common Criteria evaluated device. In practice CAs satisfy this with either a USB token or a cloud HSM the CA operates on your behalf, which is why cloud document signing exists without weakening the key-protection rule.

    Does a qualified electronic signature work outside the EU?

    It validates anywhere the verifier can resolve the trust, but its special legal status is an EU construct. Article 25(3) of eIDAS makes a qualified signature based on a qualified certificate issued in one Member State recognised as qualified in all the others, which is the cross-border guarantee. Outside the EU there is no equivalent rule, and a counterparty in the United States or Asia will usually treat a qualified signature as simply a well-validated digital signature under their own electronic signature law.

    Still Have Questions?

    Contact our support team with questions about certificates, installation, or technical issues.

    Working out which one you need

    If an advanced signature covers your case, an AATL document signing certificate is the product: PDFs and Office files that open as trusted in Acrobat and Reader, with the key held in certified hardware and no device to carry. My-SSL issues these through Certum, which is on both the Adobe Approved Trust List and the EU trusted list — so if it turns out you need the qualified level instead, tell us what the counterparty is asking for and we will say which product answers it rather than selling you the one you opened the page looking for.

    Related reading