Jacob Christiansen knows what it’s like to build for convenience. Before Penneo, his world was e-commerce and B2C, products where the goal is simple: make it easy, make it fast, make it forgettable.

Then he joined Penneo. And the stakes changed.

Jacob is a Principal Product Manager at Penneo. On paper, the job description looks similar to any other PM role: talk to customers, talk to stakeholders, define strategy, work with engineers and designers, measure results, repeat. But ask him what Penneo actually does, and the answer stops you in your tracks.

“We provide authentic evidence of who approved what and when,” he says. “Authentic meaning we use cryptographic technology, and we are certified according to international standards. But we make it easy enough that customers and signers never have to worry about those details. They just use their electronic ID.”

That gap, between the complexity underneath and the simplicity on top, is where Jacob lives. And it turns out, building something that has to be both legally airtight and genuinely easy to use is a very different challenge from getting someone to click “buy now” faster.

Critical infrastructure

Ask Jacob what sets Penneo apart and he could talk for hours. But what reframes everything is something he mentions almost as a footnote: ‘We’re legally defined as critical infrastructure.'”

It’s not a marketing claim. It’s a regulatory designation, and it changes how you think about every decision you make. When your product is the thing that makes signatures and data legally valid, ensures a document hasn’t been tampered with, and gives a compliance officer the evidence they need to pass an audit, getting it wrong isn’t just a bad quarter. It’s a real consequence for a real business.

“That’s actually the nature of our product,” Jacob says. “It is the promise we have given our customers, the evidence they need if something is ever disputed.”

The weight of that became clearest for Jacob in conversations with compliance officers and senior decision makers at organisations handling high-value, high-risk transactions. People discussing eIDAS compliance and digital signature validity with very specific requirements and very little tolerance for ambiguity. These aren’t users who need onboarding tips. They need to know that what they’re signing will hold up in court.

The question behind every decision

Ask Jacob what question he always comes back to when evaluating whether to build something, and the answer is disarmingly simple.

“What problem are we trying to solve? And what happens if we don’t do it now?”

It sounds obvious. But in practice, he says, the hardest part of the job isn’t answering that question, it’s making sure you’re asking it about the right thing in the first place.

“Customers come to us with ideas. But an idea is really just a representation of a need. Once you understand the need, you can often find solutions that help more customers or work better than the original idea. We want customers to bring us the need as well as the idea.”

At Penneo, compliance, stability and security aren’t trade-offs. They’re the baseline. “You can’t compromise on those things the way you might in other contexts.”

The decision he’s most proud of

Not every product decision carries the same weight. But when Jacob thinks about the one he’s most proud of, not for its technical elegance, but for what it meant for the people relying on it, he points to international signing. He is referring to how Penneo introduced ways for signers to use their passports to identify themselves, when they did not have access to the national electronic IDs supported by Penneo (such as MitID and BankID):

“We went from covering most cases to covering all cases. That sounds simple. But what it really means is that the same signature process will always be usable for Penneo’s customers, consistently and regardless of where a signer is based.”

Because identity verification isn’t optional. It’s a necessary part of signing a deal. Before, when a signer in another country couldn’t reliably confirm who they were, the contract didn’t just slow down, it stopped.

For customers operating across Europe, that shift wasn’t a feature update. It was a fundamental change in the promise Penneo makes.

What’s coming next

Jacob doesn’t shy away from the bigger picture. Trust in digital processes, he believes, is only going to become more important.

“AI makes it easier to fake things, documents, data, identities. The question of how you trust who approved what and when is going to become more critical. That’s the space Penneo is building for.”

For companies still handling critical business processes without a proper trust layer, his message is direct: “It’s possible to operate that way. But you have to ask yourself how much you’re willing to risk, financially, legally, and reputationally.”

It’s not a scare tactic. It’s just what happens when you spend your days thinking about what’s at stake.

JC

Jacob Christiansen

Principal Product Manager, Penneo

Before she was answering questions about qualified electronic signatures and EU compliance regulations, Esther van den Haak was cleaning teeth in the Netherlands.

It’s not the most obvious career pivot. But spend five minutes talking to Esther, one of our CX Specialists, and it starts to make complete sense.

“Being a dental hygienist is actually a lot about listening,” she says. “You’re identifying a problem, explaining it clearly, and helping someone feel less anxious about something they don’t fully understand. That part didn’t change when I joined Penneo, everything else did.”

What changed was everything else.

A morning at Penneo

Esther’s day starts the same way every day: open Zendesk, check for new tickets, and scan for anything urgent. By the time most people have finished their first coffee, she’s already working through a queue that can hit ten tickets before noon: more on Mondays and Tuesdays, when the weekend’s backlog hits at once.

Most people assume the job is straightforward. Someone can’t log in, you help them log in. But the reality, Esther says, is a lot more layered than that.

“People are often surprised when I tell them what’s actually involved,” she says. “It’s not just ‘did you try turning it off and on again.’ There are certificates, regulatory requirements, different security standards depending on the country, a lot is happening behind the scenes that customers never see.”

That invisible complexity is part of what makes the support role at Penneo unusual. The product sits at the intersection of legal validity, data sovereignty, and everyday workflow. When something goes wrong, or a customer just needs to understand what they’ve signed up for, the person they reach is Esther.

The Belgian customer and the Dutch form

Ask Esther about a moment that stuck with her, and she doesn’t hesitate. A customer in Belgium was struggling. Not dramatically, no crisis, no emergency,  but stuck in a way that was slowing them down and creating friction every time they used the platform. Standard troubleshooting hadn’t clicked. Something wasn’t landing.

So Esther helped them troubleshoot it. In Dutch.

“I just thought,  if this is how they can get to the answer themselves, then that’s what we should do,” she says. “It wasn’t a big thing. It just made sense.”

For the customer, it was a big thing. It gave them a way to diagnose and resolve issues independently, and the feedback was immediate. What had been a recurring point of friction became something they could handle on their own.For the customer, it was a big thing. It gave them a way to diagnose and resolve issues independently, and the feedback was immediate. What had been a recurring point of friction became something they could handle on their own.

It’s a small story. But it says something important about how we see support: not as a cost centre to be minimised, but as a place where problems actually get solved.

18 min

Average first response during working hours

20–30 min

Typical full resolution for straightforward cases

Your language

Support across multiple European languages

What customers say when they get a human

One of the things Esther hears most often is surprise. Surprise that someone answered quickly. Surprise that the answer was actually helpful. And sometimes, surprise that the person on the other end of the chat spoke to them in their own language without being asked.

“Customers really appreciate it,” she says. “English is set as the default language, but if I can help someone in their own language, why wouldn’t I? A screen-sharing call in Dutch just lands differently than an email in formal English.”

Penneo’s average first response time during working hours sits at around 18 minutes, and for straightforward issues, a full resolution can come in 20 to 30 minutes. In enterprise software support, where ticket numbers and three-day turnarounds are common, that tends to come as a genuine relief.

“People are used to faceless support,” Esther says. “They expect a bot, or a form, or a response that doesn’t quite answer what they asked. When they get a real person who actually reads their message, that’s when you hear it.”

What she’d want every customer to know

Penneo is currently expanding its help centre: more articles, better videos, a smarter chatbot for questions that don’t need a human. Esther supports that. Faster resolution for simple issues means more time for the ones that actually need attention.

But she’s clear about what the chatbot is for, and what it isn’t.

“The help centre is great for getting started, finding settings, and understanding regulations. But if you’re stuck,  really stuck,  just reach out. We’re here. And we’ll answer in your language.”

We say trust is at the core of everything we do. Esther is part of the reason that’s actually true.

EH

Esther van den Haak

Customer Experience Specialist, Penneo

Need help from a real person?

Our support team responds in your language, usually within 18 minutes.

Visit help centre ↗

You might already be using digital signatures, but if you’re looking to make your processes more compliant and secure, it’s time to talk about the Qualified Electronic Signature, or QES.

We see QES as the gold standard for a reason. It is the only electronic signature with the same legal effect as a handwritten signature across all EU member states, as stipulated by Regulation (EU) No 910/2014, also known as eIDAS

This isn’t about a minor tech upgrade; it’s about fundamentally transforming your operations and mitigating legal risk in a way that’s impossible with a basic solution. We are here to make the complex feel easy and to give you peace of mind.

QES is the only electronic signature that is legally equivalent to a handwritten signature, which is crucial for certain documents in Belgium.

What makes a signature “qualified”?

In the world of digital signing, there are three main types of electronic signatures: Simple, Advanced, and Qualified. While a simple signature might be a quick check-the-box, it leaves a lot to chance. The QES, on the other hand, is the highest level of security and legal validity. It’s the only electronic signature that holds the same legal weight as a handwritten signature in the EU.

This legal equivalence is crucial in Belgium, where certain local legislation mandates the use of a QES for certain documents like employment contracts and consumer credit agreements.

When you use a QES, two things happen to make it the most trusted option:

  • Verified identity: The QES links the signature directly to a verified identity. 
  • Tamper-proof documents: Once a document is signed with a QES, it becomes encrypted and cannot be changed or altered. 
  • Maximum security: A document signed with a QES is encrypted at the highest level. 

This high level of security and legal proof is why a QES is often chosen for high-stakes documents, such as financial agreements or specific HR contracts, like employment agreements. It’s also built for compliance with EU regulations like GDPR. 

The core of trust: A QES is more than a signature

To understand the value of a QES, you need to understand what it protects. A QES provides the highest level of security and legal validity, which is especially important for high-stakes documents. It establishes trust in two crucial ways.

First, it guarantees the identity of the signer. When a document is signed with a QES, the identity is linked directly to the signature. This means you know with 100% certainty that the person who signed the document is who they claim to be. This is critical for legal and financial agreements where identity is paramount.

Second, it ensures the document’s integrity. The document is encrypted and tamper-proof. Once it has been signed, it cannot be changed or altered in any way, which makes it less susceptible to fraud. This ensures that the signed agreement is exactly what was intended.

This level of certainty is a legal game-changer. The eIDAS regulation, which governs electronic signatures in Europe, specifies that a QES has the same legal value as a handwritten signature. This means that the burden of proof is reversed. When you sign with itsme®, the burden of proof is on them to prove that it was you who actually signed the document. This means that if a document signed with a QES through itsme® is ever challenged in court, itsme® is responsible for proving the validity. This is a drastic reduction in risk for any business.

Transforming your business operations

Moving from slow, manual processes to fast, automated, and compliant workflows is a key benefit of adopting a digital signing solution. A digital solution doesn’t just make signing a document faster; it streamlines entire business processes and helps you to avoid common pitfalls.

Operational efficiency and accelerated workflows: The classic “send a PDF and hope it comes back” process is a major time sink. With a digital signing solution, your documents are signed quickly and returned fast. You can send multiple documents for signing in one go. You also don’t have to waste time with follow-up emails, as automatic reminders can be sent at an interval that you can determine. The process of a document getting from your desk to a signed agreement can be reduced from days to mere minutes.

Audit-readiness and compliance: Compliance with a growing list of regulations, from GDPR to eIDAS, is no longer a choice, it’s a requirement. A QES is the most effective way to meet these standards. Every signature and document has a complete digital trail, which is essential for audits. This provides a verifiable record of who signed, when they signed, and how, giving you the peace of mind that your records are fully compliant.

Eliminating human error: Relying on physical paperwork or simple digital solutions leaves room for error. Documents can be lost, signed incorrectly, or misplaced. An automated QES solution prevents these errors by automating the workflow and guaranteeing the correct authentication is used every time.

Real-world use cases in Belgium

The benefits of a QES are not just theoretical; they are tangible and apply to a wide range of industries in Belgium.

  • Human Resources: For many companies, a QES is legally required for employment contracts and other high-stakes HR documents. Using a QES facilitates remote onboarding and contract finalization, making the process much faster and fully compliant.
  • Finance and Accounting: Accountants often have to get multiple elements of a yearly report signed by different people. A QES solution can map the document flow so that each person only signs the parts of the document they are required to. This reduces the risk of errors and ensures that all documents are signed on time. For financial agreements and consumer credit contracts, a QES is often a legal requirement and always mitigates risk by guaranteeing the identity of the signer, which is critical for high-value contracts.
  • Legal Services: Law firms and legal departments often handle high-value contracts that require a legally binding signature. A QES is an ideal solution for mitigating risk, as it provides irrefutable proof of signature and document integrity. In cases such as certain corporate documents or forms filed with public authorities, a QES is mandatory.

In Belgium, a trusted digital identity like itsme® makes the QES process seamless. itsme® is a widely recognized and used identity provider, which means your clients and partners can sign with a tool they already know and trust. This also supports multiple nationalities, so your signing process remains consistent even with international clients.

The path to implementation

Implementing a QES solution can sound daunting, but it doesn’t have to be. For many businesses, it can be up and running very quickly. The process is intuitive and designed to integrate with your existing systems, like CRM or ERP packages, via APIs. This means you can begin to see the benefits of a QES solution almost immediately.

Adopting a QES isn’t just about a better signature; it’s about building a more trustworthy, resilient, and forward-thinking business. It’s about giving people peace of mind.

Penneo and itsme®: The right fit for Belgian business

To make qualified signing as simple as possible, Penneo has partnered with itsme®, a trusted and widely-used digital identity in Belgium.

Here’s how we work together to simplify your signing process:

  • A familiar flow: With itsme®, your employees, clients, and partners can sign with a tool they already know and trust. This removes friction and makes the process incredibly easy to adopt.
  • Security for several nationalities: itsme® can be used by citizens of 24 different European countries. This means your standardised signing process won’t change if you’re dealing with a partner in Denmark or a client in Spain.
  • Seamless integration: We make it easy to integrate Penneo into your existing CRM or ERP systems, so you can automate your document flow and make your signing process even more efficient.
  • A beautiful user experience: Penneo’s platform can be fully customised to reflect your company’s branding and logo. When a client receives a document, they see a familiar and trusted brand, not a generic signing tool. This reinforces trust and professionalism.

Ready to upgrade your signing process?

If you read this far, you’re likely thinking about how to improve your document workflows. We make it simple. Penneo offers a solution that gives you the highest level of security and legal validity, without the headaches.

Does this sound like the kind of solution your business needs? Book a demo today to see how easy secure signing can be.

Most companies don’t think twice after getting a contract signed. It’s done, it’s filed, and the deal can move forward. Until one day, someone comes back and says: “That’s not my signature.”

Now what?

If that signature is later challenged in court, it can trigger a complex legal process. And unless you’ve used a Qualified Electronic Signature (QES), you’ll likely be the one who has to prove that the signature is real, valid, and legally binding.

Reverse burden of proof: Why it matters

In most legal disputes involving contracts, the burden of proof lies with the party presenting the document. That means you have to prove two things:

  1. That the document hasn’t been changed since it was signed
  2. That the person in question really did sign it

In traditional settings, this often requires internal logs, audit trails, testimonies from colleagues, or even forensic analysis.

If the document was signed with a Qualified Electronic Signature, the burden of proof reverses.

That means, the person disputing the signature now has to prove that they didn’t sign it or that the document was tampered with.

That’s a high bar to clear – and one that protects your business.

How QES makes this possible

A QES isn’t just a digital scribble or a typed name. It’s a legally recognised signature, anchored in a trust framework built on identity verification and document integrity.

Here’s how it works:

  • The signer’s identity is verified through a recognised method, for example certain nationally approved eIDs (e.g. Belgium’s .beID) or passport and biometric face check via an app like ID Verifier.
  • That identity is then bound to a Qualified Certificate issued by a Qualified Trust Service Provider (QTSP).
  • The signature is created using a Qualified Signature Creation Device – a secure, certified cryptographic system that ensures the document and identity can’t be altered without detection.

This layered process creates an auditable, tamper-evident trust chain that binds the signer’s identity to the document and to the time of signing. And because the legal and technical standards behind QES are so high, EU law treats QES as equivalent to a handwritten signature.

More importantly, it means the legal system assumes the signature is valid – unless proven otherwise.

What this means in practice – example:

Let’s say you close a major deal and both parties sign the sales contract. Weeks later, your client tries to back out – claiming the contract was never signed or approved.

If the agreement was signed using a QES, the embedded certificate shows:

  • Who signed it
  • When it was signed
  • That the content hasn’t been changed

And thanks to the reverse burden of proof, you don’t need to scramble for evidence or dig through logs. Unless your client can provide credible proof that the signature is invalid – something that’s nearly impossible with a properly issued QES – the contract stands.

Less legal hassle, more peace of mind

Using QES gives you more than compliance. It gives you breathing room.

You don’t need to second-guess your signatures.
You don’t need to prepare for courtroom debates.
You don’t need to worry about proving your process every time a question arises.

You’ve already done your due diligence – and the law recognises that.

In summary

Reverse burden of proof is a powerful legal protection, and QES is the only type of digital signature that offers it under EU law. This shifts legal responsibility away from your business and onto the party contesting the signature. That means less time spent defending your contracts, and more time focusing on your actual work.


Learn more about the validity of digital signatures

In an era where data protection and compliance are critical for every business, it’s essential to understand how companies like Penneo are dedicatedly working in these areas. With over 3000 companies putting their trust in Penneo, including Big 4 accounting firms, it’s not just our technology and user friendliness that sets us apart, but also our commitment to upholding the best practice standards for information security and privacy.

The Importance of ISO Certifications

ISO 27001 and ISO 27701 are among the most recognized global standards for information security and data protection. Our ISO certifications are fundamental for us, as they are proof that we have the right measures in place to protect our customers’ data, provide reliable services, and continuously work on further enhancing our security efforts in an ever changing environment. Furthermore, they serve as a quality stamp on our data protection efforts.

ISO 27001 covers a wide range of information security measures, while ISO 27701 focuses on privacy and personal data, which is critical in light of GDPR.

Best Practices and Industry Standards

We follow the standards set by ISO 27001 and ISO 27701, ensuring comprehensive protection across organisational, technical, and physical domains.

Robust Security Framework with ISO 27001

ISO 27001 encompasses mandatory management controls, as well as further controls, which are grouped into four categories:

  • Organisational controls
  • People controls
  • Physical controls
  • Technological controls

Examples of these measures include ISMS policies, access control, backups, encryption, and awareness training.

Comprehensive Privacy Protection with ISO 27701

Building on ISO 27001, ISO 27701 introduces privacy-specific requirements for organisations acting as controllers and/or processors of personal data. Penneo adheres to both, ensuring lawful data processing, consent management, privacy by design and default, and efficient handling of data access, correction, and erasure requests.

Our customers’ require us to ensure confidentiality and the integrity of their data as well as a reliable service that ensures the availability of that same data. Also, since our customers are based within the EU and need to be GDPR compliant, they extend that requirement to their vendors and therefore need assurance about our compliance. ISO 27001 and 27701 make sure we at Penneo cover all those aspects that are so very important to our customers.

Building trust and security

One of the major advantages of Penneo is our ability to integrate these security standards into our daily operations, ensuring that both large and small customers experience a secure and reliable service. Our clients choose us not only for our technology but also for the trust and security we offer through our certifications and our accessibility.

Besides certifications, Penneo is known for its high level of service. Our strong support team and dedicated account managers are always ready to assist and tailor solutions that meet specific needs. As a company, our top priority is to protect your data and ensure compliance. By choosing Penneo, you can be assured that your data is handled with the utmost care and protection, supported by leading industry standards and a knowledgeable support system.

The challenges facing our world today—AI, climate change, and the erosion of trust in digital environments—require more than just new technologies; they demand intentional leadership and responsible action. At the Sustain Tomorrow 2024 conference, the focus was clear: how can we ensure that the tools of the future, like AI, contribute to a better, more equitable world rather than deepening existing problems?

Futurist Mark Stevenson posed a crucial question during his keynote: What will the future ask of us? This resonated with me deeply, prompting thoughts about how today’s decisions on AI, sustainability, and digital trust will shape our collective future. From protecting democratic institutions to maintaining Europe’s competitive edge, the questions we face are urgent—and the answers must be deliberate.

Here are four key areas where we should make an impact today, and not wait 20 years from now.

1. Preventing generative AI from undermining democracy

The rise of generative AI is a double-edged sword. It has unlocked remarkable creative potential, allowing individuals to produce high-quality content at a fraction of the cost. But it also poses serious threats to democratic processes. Deepfakes and AI-generated content are now so realistic that separating fact from fiction is becoming nearly impossible.

This is especially risky during elections, where bad actors can manipulate voters with fake news and polarising narratives. Social media algorithms amplify this problem by creating echo chambers of misinformation.

At Penneo, as an EU-trusted service provider, we believe it is possible to increase the trustworthiness of digital content. Expanding the use of digital signatures—commonly used for text documents—to video content could help. Imagine verifying the authenticity of a video, whether it’s a news clip or advertisement. Platforms could flag unsigned content as unverifiable, offering more transparency in an AI-driven world.

While no solution is perfect, adding this layer of accountability can help reduce misinformation and protect our democracies.

2. Keeping Europe competitive amidst regulatory complexity

Europe faces the challenge of balancing regulatory oversight with digital innovation. Complex regulations like GDPR, AML, and AI laws, while vital for privacy and ethics, can slow technology adoption and hinder efficiency if not carefully implemented.

For example, getting car insurance in Germany still requires printing six copies of a contract, and wet ink signatures are often mandatory for employment agreements—outdated processes that create unnecessary barriers.

At Penneo, we’re already making strides to address this issue by replacing paper-based processes with secure, digital alternatives. Our digital signature solution allow businesses to move faster without sacrificing compliance or security. But the broader challenge lies in Europe’s regulatory framework.

By 2026, the EU will require all member countries to offer interoperable eIDs for cross-border digital signatures. While promising, success depends on widespread adoption and trust in these solutions. Regulatory bodies must focus on enabling digital transformation without excessive red tape. 

At Penneo, we believe trust, efficiency, and innovation can coexist. A supportive regulatory environment is essential for Europe to stay competitive while keeping trust central to digital interactions.

3. Addressing the social experiment of Generation K (1996–2007)

Generation K, a subgroup of Generation Z born between 1996 and 2007, is entering the workforce with deep mistrust. Raised amid wars, terrorism, and climate change, many feel disillusioned. As Noreena Hertz noted, 8 in 10 feel lonely, and only 6% trust corporations to act responsibly.

How do we build trust with a generation that feels disconnected? At Penneo, we’re fostering a workplace culture that resonates with Gen K values by promoting authentic connections. Whether through virtual or in-person interaction, our office social club, we mindfully aim to create opportunities for meaningful engagement.

By encouraging initiatives like sustainability days, where employees can contribute to projects they care about, and fostering more social interaction, we can help reduce turnover and increase engagement. After all, studies have shown that teams with stronger social bonds perform better.

4. Preventing AI from widening economic divides

The rise of AI brings with it the risk of widening the economic gap between the rich and poor. Those with access to advanced AI tools may reap significant rewards, while those without could be left behind. At Penneo, we believe that technology should be a force for equality, not division.

While I don’t have a concrete answer to this challenge, ongoing dialogue and action are essential. We must continue to explore how we can develop AI solutions that promote fairness and accessibility, ensuring that the benefits of technology are shared by all.

What will the future ask of us?

The future is asking tough questions of us, and how we answer them will determine the path we take as a society. Whether it’s preventing AI from undermining democracy, ensuring Europe stays competitive, or fostering trust with the next generation, we must act with intention, sincerity, and intelligence. At Penneo, we’re committed to being part of this journey, driving digital trust, and innovation while contributing to a future where technology serves everyone.

Digital signatures have become an integral part of everyday life in many companies. They make it easy and secure to handle sensitive documents, whether they are employment contracts, powers of attorney, annual reports or other legal documents.

But there are many options for digital signature solutions, and it can be difficult to figure out what features are really important. Which solution best suits your needs? And how do you ensure that it is secure, easy to use and works well with your existing systems?

In this article, we guide you through 9 key points you should consider before choosing a digital signature solution.

1. Legally binding digital signatures

Pens, paper, scanning, and emails back and forth… Manual signing can be slow and tedious. With digital signatures, the process is completed online, quickly, securely, and without unnecessary steps.

While all three electronic signatures are legally valid under eIDAS regulation, Qualified Electronic Signatures (QES) are preferred for high-value or sensitive documents, as they carry the same legal weight as a handwritten signature across the EU.

→ Read more about the three types of electronic signatures here 

An Advanced Electronic Signature (AdES) provides more evidentiary weight than a Simple Electronic Signature (SES), as it is uniquely linked to the signer, enables identification, remains under their sole control, and detects any tampering.

2. Using wide variety of eIDs to sign and confirm identity

Both you and your customers already use digital identities (eIDs) in your everyday lives. Solutions such as MitID, BankID and itsme® have become standard tools for securely confirming your identity both privately and at work.

Your digital signature tool should be able to integrate with the most widely used national eIDs in Europe. This allows signers to use an identification method they already know and trust, rather than having to create new logins or learn new systems.

The result is a signing process that feels easy, secure and familiar, especially when documents need to be signed across borders. The easier it is to verify your identity, the faster the documents will reach their destination.

3. Possibility of signing with passport

Although many European countries have strong eID solutions, not everyone has access to one. Some customers or partners may reside in countries where a national eID either does not exist or is not widely used.

Your digital signature solution should also be able to accommodate international signers in other ways. A good signature tool allows you to identify yourself with a passport or national ID card and still sign with either AdES or QES.

This provides the necessary flexibility in practice without compromising security. No matter where the signers are located, they can complete the signing process in a safe and secure manner.

4. Sending documents for signing in the correct order

In many industries, signature processes are rarely straightforward. Such as sales agreements, employment contracts or annual reports, where several people have to sign several documents in a specific order.

It’s important that your digital signature solution can handle these more complex scenarios. You need to be able to easily define who signs what and when, so that the process follows the correct steps from start to finish.

Automatic notifications and reminders are also a great help. They ensure that the process does not stall and save you from having to manually chase up customers or colleagues. This way, you can keep up with the task and meet deadlines.

5. Being able to sign on any device, anytime

Today, people work from computers, tablets and especially smartphones. Therefore, your digital signature tool should make it possible to sign documents from all types of devices without any technical bumps along the way.

When the solution is both accessible and mobile-friendly, signers can add their signature whenever it suits them, whether they are in the office, at home or on the go. This makes the entire process more flexible, fast and user-friendly, and increases the likelihood that documents will be signed on time.

6. Easy integrations with industry-specific software

To save time and avoid errors, it is important that your digital signature tool can work with the software you already use. This could be accounting or auditing systems such as Caseware, Silverfin, Ratios or M-Files.

With a strong integration, you can create, manage and send documents for signature directly from your existing software. This means you don’t have to switch between programmes and minimises the risk of errors.

Pre-built integrations are a major advantage. But what if your workflows are more complex? Or if you rely on a custom-built system? In that case, it should be easy to build your own integration.

A strong digital signature solution provides a user-friendly and well-documented API, enabling you to automate signature processes directly within your own systems.

7. Customise your client communication

People are naturally more and more cautious about opening emails from unknown senders, which can slow down the signing process. That’s why it’s a big advantage if you can customise the emails that are sent with the documents.

A good solution allows you to:

  • Tailor the text of the email to the signer’s language
  • Add your company’s branding and logo

When the email looks professional and recognisable, it builds trust with your customers and increases the likelihood that the document will be signed quickly.

8. Access control for extra security

When sending sensitive documents, security is paramount. A reliable digital signature tool should therefore offer access control so that only the right person can view and sign the document.

This could be, for example:

  • Confirmation with Social Security Number (SSN)
  • SMS codes sent only to the signer’s phone number

In addition, it is a great advantage if the solution has an activity log that shows who has had access to the document and when. This provides both an overview and extra security in the process.

9. Digital archive for secure document storage

Once documents have been signed, it can quickly become difficult to keep track of them. Storing files in emails, on file-sharing platforms or on your desktop does not meet the requirements of the GDPR.

Therefore, your digital signature tool should include a secure digital archive where all signed documents:

  • Are stored in accordance with GDPR
  • Are easily accessible when you need them
  • Are protected against loss, theft or physical damage

A digital archive gives you an overview, peace of mind and security, so that documents are always where they should be and can be retrieved quickly and easily.

Conclusion

Choosing the right solution for digital signatures is not just about efficiency, but also about securing your business and reducing risks when working with sensitive documents. With the right security measures for signatures, the risk of errors, misuse and potential disputes is significantly reduced.

It is crucial to choose a solution that combines high security with user-friendliness, flexibility and strong integrations with your company’s existing software. When identities are validated correctly, processes are automated, and documents are stored securely in accordance with GDPR, the company is in a much stronger position, both in terms of minimising legal risks and increasing operational agility.

A well-designed digital signature solution is therefore not just an efficiency tool, but a strategic investment in protecting your business, building trust with customers and partners, and ensuring that critical processes run smoothly from start to finish.

Would you like to see how Penneo makes digital signatures easy, secure and ready for all the requirements that come with digital agreements?

Small and medium-sized businesses in the accounting industry face major challenges in a digitalised world. Manual processes can be time-consuming and error-prone, increasing the risk of inefficiencies. At the same time, legislation is constantly tightening and non-compliance can be costly. Small businesses also find it difficult to compete with larger players who have the resources for advanced digital solutions and can better attract labour.

How can small and medium-sized businesses best meet these challenges? How do you embrace digitalisation and engage your employees in the transformation? In this article, I will share my experience of digital transformation in accounting firms and my top tips for becoming competitive, achieving efficiency and ensuring regulatory compliance at the same time.

Embracing digitalisation

Take the first steps in preparing your business for change

  1. Recognise the potential of digitalisation: The first step is to recognise what digitalisation can do for your business. This realisation needs to come from within the company itself, preferably in the management team. Manual handling of processes can be time-consuming and fraught with extra costs, such as postage and manual data entry. Especially in the accounting industry, efficiency is a key driver, as every minute saved means more time to serve the customer.
  2. Leadership and responsibility: Choose a responsible person to lead the digitalisation process. This could be an existing employee with a particular digital interest or mindset, the creation of a new position for the purpose, or perhaps getting external help from a company that specialises in the field.
  3. Evaluate readiness: Once the potential is recognised, the company should assess its readiness. This involves a realistic assessment of the organisation’s current systems and processes, as well as the willingness of employees to change the way they work.
  4. Identifying needs: It’s important to identify which specific digital solutions will be most beneficial to the organisation. This should be based on current challenges and future goals. With stricter legislation and higher fines, compliance has become as important as cost savings. It’s not just about finances, but also about minimising the risks of non-compliance.

“The common denominator for success in digitalisation has often been thorough preparation, clear communication, and strong leadership.” – Kasper Behrens

How to get your IT ecosystem up and running

There are many types of software and technology that are valuable for small to medium-sized businesses. Some of the most effective solutions include:

  • Accounting and auditing software: These newer production tools can automate many of the routine tasks and minimise errors. These can also free up time for more value-added and meaningful tasks for the individual employee. Most importantly, it can integrate easily with other processes.
  • CRM systems: Customer Relationship Management systems help organise and analyse customer interactions and data throughout the customer lifecycle. It is beneficial to gather customer data in one place where the system can provide an overview of customer interactions, case status and deadlines and help the accountant provide informed advice.
  • ERP systems: Enterprise Resource Planning systems integrate key business processes and help streamline operations. Typically, ERP systems are integrated into large organisations, but new solutions tailored to small and medium-sized businesses are emerging.
Challenges and solutions

How to tackle IT costs, compliance, and changing mindsets

SSmall to medium-sized businesses often face challenges such as high IT costs and strict compliance requirements. It’s essential to stay on top of professional standards and be prepared for quality control. Modernisation and streamlining are necessary to stay competitive and attract new employees.

Data and security must be the foundation

As organisations move to digital systems, data protection is crucial. Small to medium-sized businesses should follow data protection best practices and comply with regulations like GDPR. This includes encrypting data, regular security checks and training employees on data security.

Thorough research on compatibility and integration options

It’s important to choose software with good integration capabilities to ensure new digital solutions work well with existing systems and processes. It’s especially important to evaluate the compatibility of software solutions before implementation. This requires thorough research with potential suppliers before launch.

Training and support are key

Businesses should invest time and resources in training their employees in the use of new digital tools. The management or partner’s direct involvement in digitalisation plays a crucial role in whether employees accept and support the changes. If management doesn’t see the value in digitalisation and the big changes that come with it, reluctant employees won’t support the project either.

Adjust future perspectives and mindset

There are several technological trends that will be relevant to small to medium-sized businesses in the coming years, including artificial intelligence and automation. Getting qualified advice and finding relevant cases for the small business can still be challenging, but more and more digital tools for specific industries are becoming available. To prepare for future technological shifts, companies should be open to innovation and continuously evaluate their digital strategies. It’s also a question of a mental shift that needs to affect the entire organisation.

How do you know if it’s worth it?

Companies can measure the success and ROI (Return on Investment) of their digitalisation initiatives by monitoring key indicators such as time savings, cost reductions, and customer satisfaction. It’s important to have clear goals and regularly evaluate progress to ensure digitalisation is living up to expectations. When these results can be measured and shared across the business, it will accelerate the adoption of digitalisation in the future.

By following these steps, small and medium-sized businesses can start their digitalisation process effectively and achieve both short-term and long-term benefits.

Where you know you need to take action but don’t know where to start, seek help from an advisor with industry knowledge.

Read more about how Penneo can help digitise your accounting firm.

3 years since its initial proposal in June 2021, eIDAS 2.0 (Regulation (EU) 2024/1183) has now been finalised and published in the Official Journal of the European Union. This amending regulation enters into force 20 days after this publication, on May 20th 2024 and marks a significant evolution in the EU’s digital framework. Let’s explore what eIDAS 2.0 entails and its implications for digital transactions.

Understanding eIDAS: The foundation of trust

The original eIDAS (Electronic Identification, Authentication, and Trust Services) regulation, established in 2014, was adopted to create a secure and interoperable environment for electronic transactions across EU member states. It introduced standards for electronic identification and trust services, such as electronic signatures, electronic seals, time stamps and website authentication.

Read more about eIDAS 1.0 here

What’s new in eIDAS 2.0?

eIDAS 2.0 reflects the EU’s ambition to create a more integrated digital market, improve the security and privacy standards of digital services, and ensure that these services are accessible to all EU citizens. The highlights include:

Enhanced digital identities

eIDAS 2.0 introduces the idea of a common EU digital identity wallet (EUDIW), enabling EU citizens to securely store and manage their data and official documents (such as identity cards, driver’s licence, diplomas, banking details, travel cards etc.) and facilitate online interactions with authorities, businesses and citizens across EU member states. The EUDIW is still being tested through 4 large-scale pilot projects (POTENTIAL Consortium, EU Digital Wallet Consortium, Digital Credentials for Europe, NOBID Consortium), each project focusing on different aspects of the use of digital identities.

Increased security and standardisation

The amending regulation emphasises enhanced interoperability of digital identification systems among member states and introduces stricter security measures and more rigorous standards across member states. By introducing stricter authentication methods and enhanced security standards to follow, eIDAS 2.0 aims to increase trust in digital transactions and promote a more secure digital market in the EU.

Impact on digital signatures and identity

As eIDAS 2.0 is designed to harmonise and strengthen the framework for electronic identification and trust services across the EU, making sure that all member states adhere to the same standards. Member states will have to provide technical and organisational measures to ensure a high level of protection of personal data used for identity matching across member states. Additionally, eIDAS 2.0 introduces new trust services such as the electronic attestation of attributes, the electronic archiving, or the recording of electronic ledgers. The Commission will establish a list of standards to be used by the end of 2024.

As a Penneo user, eIDAS 2.0 will not have any direct impact on how you use the tool.

What’s next?

The adoption of eIDAS 2.0 will lead to the implementation of a comprehensive set of acts detailing technical standards and security protocols. These standards are essential for ensuring interoperability and security of digital identities and trust services. By 2026, each member state must make a digital identity wallet available to its citizens and accept EUDIWs from other member states according to the amended regulation.

Conclusion

The amending eIDAS 2.0 regulation represents a significant leap forward in the EU’s digital agenda, aiming to enhance the security, privacy, and convenience of online services. As we anticipate its implementation, it’s clear that eIDAS 2.0 will not only reshape the landscape of digital interactions within the EU but could also serve as a model for other regions looking to improve their digital infrastructure.

As a Penneo customer, you can rest assured that our solution is designed to align with and leverage these legal advancements, ensuring that your digital transactions remain secure, compliant, and efficient in this new regulatory environment.

In order for advanced & qualified electronic signatures and seals to be valid and recognized throughout Europe, they must be based on one of the three ETSI standards according to the EU Commission’s Implementing Decision 2015/1506 — i.e., PAdES, XAdES, CAdES.

PAdES, XAdES, and CAdES are all equally reliable and valid from a compliance standpoint, but they differ for use cases, and each of them presents specific benefits and drawbacks, which we will analyze in this article.

Background information: Why are signature standards needed?

The EU eIDAS Regulation — which provides the legal framework for the cross-border enforceability of electronic signatures and other trust services — defines the legal requirements that electronic signatures and seals must meet to be considered advanced or qualified.

However, it does not specify the technical standards on which electronic signatures and electronic seals need to be built to meet those requirements.

The Regulation delegated to the EU Commission the adoption of implementing acts to define such technical standards. Moreover, eIDAS established that Member States must recognize and presume the validity of advanced electronic signatures and seals based on those standards.

To ensure a high level of security and interoperability of electronic identification and trust services throughout the EU, the Commission has taken into account the technical specifications drawn up by the European Telecommunications Standards Institute (ETSI) — an independent organization supporting the development of globally applicable standards in the IT field.

The EU Commission fulfilled its mandate with the Implementing Decision 2015/1506, which establishes that Advanced Electronic Signatures and Advanced Electronic Seals must comply with one of the three ETSI baseline profiles:

  • PDF advanced electronic signature (PAdES), based on PDF signatures;
  • XML advanced electronic signature (XAdES), based on XML signatures;
  • CMS advanced electronic signature (CAdES), based on Cryptographic Message Syntax (CMS).

PAdES

PAdES stands for PDF Advanced Electronic Signature and can only be used to sign PDF documents.

When implementing PAdES to sign a PDF, the resulting signature will be in PDF format. More specifically, the signature will be directly applied to the PDF — i.e., encoded into it.

Consequently, it won’t be possible to update the content of the PDF after it has been signed; it will only be possible to apply an additional PAdES signature, which will create a new version of the PDF containing all the signatures.

Let’s suppose that multiple people need to sign a document:

  1. Signer 1 signs the original Document, thereby creating a new Document (Document V2). Document V2 contains Document V1’s content and Signer 1’s PDF signature embedded in it.
  2. Signer 2 then signs Document V2; by doing so, Document V3 is created. Document V3 contains the content of Document V2 with Signer 1 and Signer 2’s PDF signatures embedded in it.
  3. Signer 3 then signs Document V3, and Document V4 is created — and so on.
PAdES signatures

As a result, it’s not possible for multiple people to sign simultaneously. If multiple people try to sign at the same time, or within quick succession of each other, then all but one will need to wait.

There are many benefits of using PAdES:

PAdES signatures are directly applied to the PDF — i.e., encoded into it. Therefore, the signatures cannot be misplaced, as they remain part of the self-contained PDF files, which can be copied, stored, and distributed as simple electronic files.

PAdES allows for the addition of a visible graphic signature to the document (besides the cryptographic signature).

The resulting file, which contains the signature, is a PDF file that, as such, can be opened and viewed using any widely available PDF reader.

The PDF signatures can be validated using publicly available tools like Adobe Reader, which is beneficial when signing documents with a general audience, such as in a B2C or C2C context. Below is an example of PAdES signature validation with Adobe Reader.

PAdES signatures

The PDF signatures can also be validated using custom-built validation tools, like Penneo’s Validator, as well as official tools, such as the EU Commission’s Digital Signature Services (DSS) validation tool.

XAdES

XAdES stands for XML Advanced Electronic Signatures.

When using the XAdES standard, the resulting signature is in XML format.

XAdES standard can be used to sign XML-based electronic document formats, which is suitable for a large variety of business use cases. For example, a company’s board and auditor can use the XAdES standard to sign documents in iXBRL format and comply with ESEF reporting requirements when submitting their financial statements to the authorities.

XML files are both human-readable and machine-readable, which is optimal for storing data in a structured way and extracting information into other systems.

However, users need specific software to validate the XAdES signatures – which makes them not appropriate when signing documents with a general audience — i.e., in a business-to-consumer or consumer-to-consumer context, as a person receiving a XAdES signature file might not know how to validate it.
Additionally, it’s not as easy to validate a document signed with XAdES signatures — but it is possible to use the EU DSS Validator to verify the validity of the individual XAdES signatures.

CAdES

CAdES stands for CMS Advanced Electronic Signature.

Just like XAdES, CAdES standard can be used to sign most types of files. While being very versatile, CAdES signatures present a series of disadvantages:

  • When using the CAdES standard, the resulting signature is in .p7m format; therefore, users need a specific software to view the signature and validate it.
  • Just like PAdES, and unlike XAdES, it’s not possible for multiple people to sign at the same time as each signature creates a new .p7m envelope.
  • Unlike PadES, the CAdES standard does not allow for the addition of a visible graphic signature on the document.

Below is a more detailed overview of the three signature standards and their features:

 PAdESXAdESCAdES
Stands forPDF Advanced Electronic SignatureXML Advanced Electronic SignatureCMS Advanced Electronic Signature
ETSI StandardPAdES Baseline Profile ETSI TS 103 172 v.2.2.2.XAdES Baseline Profile ETSI TS 103 171 v.2.1.1.CAdES Baseline Profile ETSI TS 103 173 v.2.2.1.
E-signature file formatPDFXMLp7m
Signing by multiple people at the same timeNOYESNO
Human-readableNOYESNO
Machine-readableYESYESYES
Visual representation of the signature on the documentYESNONO
Signature ValidationPAdES signatures can be validated using Adobe Reader, Penneo’s Validator, and the EU DSS Validator. Read more about the validation of documents signed via Penneo here.A specific software is needed to open XML files. XAdES signatures can be validated using the EU DSS Validator and Penneo’s Validator. Read more about the validation of documents signed via Penneo here.A specific software is needed to open the .p7m file and validate CAdES signatures.

Benefits of using ETSI standards

Legal validity: eIDAS established that Member States must recognize and presume the validity of advanced electronic signatures and seals based on those standards.

Cross-border validation: PAdES, XAdES, and CAdES are all ETSI standards and are therefore recognized and used internationally — which means that it is possible to create an advanced electronic signature based on any of them in any Member state, and anybody across countries will be able to perform the signature validation.

Assessment and record of the Certificate status: Whenever a certificate is used as a part of the signing process, the ETSI standards provide for the verification of the status of the certificate at the time of signing. The digital signing software checks whether the certificate is valid, expired, or revoked, and the result of this check is added to the resulting XAdES/PAdES/CAdES signature.

Long-term validation (LTV): The main benefit of all three standards is that they support Long Term Validation (LTV), which is a signed document’s ability to stay valid for years or even decades after signing — even after the platform that created the document has become inaccessible. Documents signed using one of the above ETSI standards contain records of the certificates used for signing and their validity at the time of signature. At any time in the future, despite technological and other advances, it will be possible to verify that the signature was valid at the time it was made.

Content integrity: If the document is edited after the signing process is completed, then the signature is invalidated. Thus, a valid signature serves as proof of both who signed and what they signed.

Which signature standard should you use?

PAdES, XAdES, and CAdES are all equally valid internationally, but their individual characteristics make them most suitable for specific use cases.

If you need to sign PDF documents, PadES is the best option. Anybody can view the final signed PDF with a PDF reader and validate the signatures with Adobe Reader — whereas someone receiving an XML or .p7m file might not know how to open it.

If you need to sign non-PDF files and want to be able to easily export the signatures’ data into other systems, XAdES and CAdES are to be preferred.

Considering the pros and cons provided by each of these signature standards, some trust service providers offering electronic signature services employ both XAdES and PAdES standards in their signing processes to benefit from the advantages each of them brings. And that’s, for example, what Penneo does when creating electronic signatures.

Which standards does Penneo follow when creating advanced electronic signatures?

Penneo’s advanced electronic signatures and electronic seals are based on XAdES and PAdES standards.

Here is how the process works:

  1. PDF documents are sent for signature via Penneo to the signers
  2. Each signer can view the documents as PDFs and proceed to sign them
  3. When the signer proceeds to sign the documents, Penneo generates an XML structure of the document details, including hashes of the PDFs. This XML file is then signed. Whenever multiple documents are sent for signature together, this is done for all documents together, so that the signers only need to sign once.
  4. The resulting signature is an XAdES signature, and there will be as many XAdES signature files as there are signatures/signers
  5. Penneo embeds these XAdES signatures into the original PDF document/s as attachments
  6. Penneo also adds a visual representation of the signatures on a dedicated page, which becomes an integral part of the PDF itself as its last page. The signature page is readable with any PDF reader and printable, along with the rest of the document. Besides the graphic representation of the signatures, this final page also contains additional identifying information on each signer, such as

    • their name, their role, the entity on whose behalf they sign if applicable, their IP address (in partially anonymized form), and

    • a timestamp for each signature — i.e., a digital record of the time when each signature was applied – which is also cryptographically bound to the document as it’s included in the XML signature.
    • Below is an example of what the final page with the visual representation of the signatures would look like.Visual representation of the signatures
  7. Penneo uses the attachment capability to embed an audit log in the final document/s — a complete record of activities up until the conclusion of the signature process. It can be used as evidence (even in court), and by including it in the document, it’s by default available to all parties. Thereby, disputes can be handled without further input from Penneo. You can see the audit log as a .txt file by opening the document in Adobe Reader and clicking on the paperclip icon in the left tab.
    XML signatures
  8. When all signers have signed the documents, Penneo seals the signed documents with the embedded XAdES signatures and audit trail according to the PAdES standard. This is done by applying qualified electronic seals — i.e., Penneo’s author signature — and it achieves the benefits of the PAdES standard. You can see the seal by opening the documents in Adobe Reader; it will appear as a blue bar at the top.
    Sealed XML signatures

Penneo’s Seal

By applying the final seal to the documents following PAdES standards, it’s as if Penneo acted as the last and final signer of the documents. The seal is incorporated directly within the signed PDFs – as much as an ink signature becomes an integral part of a paper document.

This ensures that the documents never lose their legal reliability, as the complete self-contained PDF files contain everything you need to verify the signatures’ validity and remain valid for long periods. At the same time, PDFs can be copied, stored, and distributed as simple electronic files.

How to check the validity of signatures and seals based on XAdES and PAdES standards

As explained above, documents signed via Penneo are PDFs with attached XML signatures (based on XAdES standard) and sealed with a qualified electronic seal (based on PAdES standard).

The validity of documents signed via Penneo can be verified through Adobe Reader and Penneo’s Validator as a PAdES-compliant validation platform. Additionally, users can upload their documents on the EU DSS Validator to get information on the signature’s status, scope, and time, as well as on the certificate chain, timestamps, and LTV (Long Term Validation).

You can follow the steps described in this article to check the validity of your signatures created via Penneo.