[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to use qualified electronic signature in romania online

How to Use Qualified Electronic Signature in Romania Online (2026): Qtsps, Remote ID & Mandatory Uses

By Global Law Experts
– posted 3 hours ago

Understanding how to use a qualified electronic signature in Romania online has become a non-negotiable compliance priority for businesses engaging with Romanian public authorities, closing cross-border transactions, or digitising procurement workflows. Regulation (EU) 2024/1183, commonly known as eIDAS 2.0, reshaped the EU-wide framework for trust services and cross-border recognition, while Romania’s own Law no. 214/2024, published on 5 July 2024, introduced national mandates that require QES for an expanding list of official filings and public-sector interactions. This guide translates both layers of regulation into operational steps: choosing a Qualified Trust Service Provider (QTSP), completing remote identity verification, signing documents compliantly, and building the contract clauses and audit trails that protect your organisation in disputes.

Key compliance checklist, at a glance:

  • Obtain a QES certificate from a QTSP listed on Romania’s national Trusted List (published by ADR).
  • Verify the QTSP’s status using the EU Trusted List browser before every procurement or high-value signing event.
  • Record a full audit trail, signer identity, certificate chain, qualified timestamp, and QTSP evidence, and retain it for a minimum of five years.
  • Insert protective clauses in vendor and procurement contracts specifying QTSP acceptance criteria, liability allocation, and log-retention obligations.

Who this guide is for: In-house counsel, procurement managers, CIOs/CTOs, compliance officers, and external advisers working with Romanian entities, public authorities, or cross-border counterparties that require or accept qualified electronic signatures.

What Is a Qualified Electronic Signature (QES), EU Legal Effect and eIDAS 2.0

A qualified electronic signature is the only type of electronic signature that EU law treats as the legal equivalent of a handwritten signature in every Member State, without additional conditions. Grasping this distinction is essential before addressing the qualified electronic signature requirements for Romania online workflows.

Definition

Under Regulation (EU) No 910/2014 (the original eIDAS Regulation), a QES is defined as an advanced electronic signature that is (a) created by a qualified electronic signature creation device and (b) based on a qualified certificate for electronic signatures issued by a QTSP. The certificate must meet Annex I requirements, and the creation device must satisfy Annex II criteria. This layered architecture is what separates a QES from simpler signature types and gives it its unique legal standing.

Cross-Border Legal Effect

Article 25(2) of eIDAS establishes that a QES based on a qualified certificate issued in one Member State must be recognised as a QES in all other Member States. Regulation (EU) 2024/1183 (eIDAS 2.0) preserves and reinforces this principle while introducing the European Digital Identity Wallet framework, which, once fully operational, will offer an additional pathway for identity authentication when obtaining or using a qualified electronic signature. The practical effect for businesses operating in Romania is straightforward: a QES issued by a French, German, or any other EU-listed QTSP carries the same legal weight in a Romanian court as one issued locally.

Difference Between Simple, Advanced, and Qualified Electronic Signatures

  • Simple electronic signature. Any data in electronic form attached to or logically associated with other electronic data, an email footer, a typed name, or a click-to-accept button. No identity verification or device requirements.
  • Advanced electronic signature. Uniquely linked to the signatory, capable of identifying the signatory, created using data under the signatory’s sole control, and linked to the signed data so that any subsequent change is detectable. Stronger than simple, but does not carry automatic legal equivalence to a handwritten signature.
  • Qualified electronic signature. An advanced electronic signature that additionally meets the certificate and device requirements described above, the only tier with presumed equivalence to a wet-ink signature under EU law. The term “certified electronic signature” is sometimes used colloquially in Romania to refer to this category, though the legally precise term remains “qualified.”

Romania-Specific Legal Changes and Mandatory Uses Under Law 214/2024

Law no. 214/2024, published on 5 July 2024, expanded the scope of transactions where Romanian public authorities and regulated entities must accept or require a qualified electronic signature. This section outlines the mandates most relevant to B2B compliance.

Timeline and Key Dates

Law 214/2024 entered into force in accordance with its published timeline, with certain provisions taking phased effect to allow public institutions and QTSPs to adapt their systems. Businesses that interact with Romanian public procurement portals, regulatory filing systems, and healthcare data platforms should treat the law’s mandates as fully operative for 2026 compliance planning. Separately, procedural rules published on the Portal Legislativ, including implementing procedures that govern specific electronic filings, reinforce the requirement for QES in designated administrative workflows.

Which Public Authorities and Transactions Now Require QES

The law’s most immediate impact falls on interactions where documents are submitted to or issued by Romanian public authorities. The key areas include:

  • Public procurement. Electronic tender submissions to contracting authorities increasingly require QES to ensure signer identity and document integrity.
  • Tax and fiscal filings. Certain electronic submissions to Romania’s fiscal authorities mandate the use of a qualified electronic signature.
  • Health records and regulated-sector filings. Specific digital health and regulated-industry documents must be signed with QES where confidentiality and non-repudiation are critical.
  • Corporate registry submissions. Documents filed with the Trade Registry in electronic form may require QES depending on the nature of the filing.

Exceptions, Where an Advanced Electronic Signature Remains Acceptable

Not every transaction demands a QES. Where Law 214/2024 or sector-specific legislation does not expressly mandate a qualified signature, an advanced electronic signature remains legally valid, though it does not benefit from the automatic presumption of equivalence to a handwritten signature. Private commercial contracts between two businesses, for example, generally remain enforceable with an advanced electronic signature unless the parties’ own agreement or a specific regulatory provision requires a higher tier.

Who Can Issue a QES, QTSPs and How to Use Trusted Lists

Only Qualified Trust Service Providers (QTSPs) that appear on a national Trusted List maintained under eIDAS can issue the qualified certificates that underpin a valid QES. Verifying this listing is a non-negotiable compliance step.

ADR’s Role and Romania’s National Trusted List

In Romania, the Autoritatea pentru Digitalizarea României (ADR) serves as the supervisory body for trust services. ADR is responsible for granting, monitoring, and, where necessary, withdrawing qualified status from trust service providers operating within Romania. ADR publishes and maintains Romania’s national Trusted List, which is the authoritative register of all providers and services that hold qualified status. This list is available in both human-readable and machine-readable (XML) formats. Any QTSP that does not appear on this list with an active “granted” status for qualified certificate issuance cannot validly issue the certificates required for a QES in Romania.

How to Read a Trusted List Entry

When verifying whether a provider is a valid QTSP, check the following fields in the Trusted List entry:

  1. Navigate to the EU Trusted List browser maintained by the European Commission, or access Romania’s national Trusted List directly via the ADR website.
  2. Select “Romania” as the country and filter for trust services of the type “QCert for ESig” (qualified certificates for electronic signatures).
  3. Check the service status. The entry must show a status of “granted”, any other status (withdrawn, deprecated, or expired) means the provider cannot currently issue valid qualified certificates.
  4. Review the certificate policy identifiers. These OID (Object Identifier) values confirm which policies the certificate was issued under and whether they align with the eIDAS Annex I requirements.
  5. Confirm the service type. Ensure the listed service covers qualified certificate issuance for electronic signatures specifically, as some providers may hold qualified status for other trust services (e.g., timestamps or seals) but not for signature certificates.

The European Commission’s central List of Trusted Lists (LOTL) aggregates every Member State’s national list, making it possible to verify cross-border QTSPs in a single lookup. Industry observers expect this process to become even more streamlined as the European Digital Identity Wallet infrastructure matures under eIDAS 2.0.

Step-by-Step: Obtaining and Using a Qualified Electronic Signature Online in Romania

This is the core operational section, it explains exactly how to use a qualified electronic signature in Romania through online channels, from onboarding with a QTSP to signing your first document.

Preconditions

Before initiating the process, prepare the following artefacts:

Required artefact Purpose
Valid government-issued identity document (Romanian ID card, passport, or EU national ID) Identity verification during QTSP onboarding
Corporate authorisation letter or power of attorney (for corporate signatories) Proof that the individual is authorised to sign on behalf of the legal entity
Company registration extract (certificat constatator), if signing on behalf of a Romanian entity Confirms entity identity and signatory authority
Active email address and mobile phone number Required for multi-factor authentication during certificate issuance and signing

Remote ID Options

Romanian QTSPs currently offer several pathways for remote identity verification, each complying with applicable eIDAS and national requirements:

  • Video-based identification (Video KYC). A live or assisted video session in which the applicant presents their identity document to a trained operator or an automated biometric system. This is the most widely available fully-remote pathway offered by Romanian QTSPs.
  • eID / electronic identity authentication. Where the applicant holds a Romanian electronic identity card with an activated chip, or a notified eID scheme from another EU Member State, this can serve as the identity proofing step. As eIDAS 2.0 implementation progresses, the European Digital Identity Wallet is expected to become an additional accepted channel.
  • In-person verification with remote certificate delivery. The applicant visits a QTSP registration point or authorised partner location for face-to-face ID verification, after which the qualified certificate is issued to a secure remote signing device (cloud-based QSCD).

Certificate Issuance, Software Integration, and the Signing Process

Once identity verification is complete, follow these steps to obtain your certificate and begin signing:

  1. Select the certificate type. Choose between a certificate stored on a local qualified signature creation device (e.g., a smart card or USB token) and a cloud-based remote qualified signature creation device (QSCD). Cloud-based QSCDs are increasingly standard for organisations that need multiple signatories to sign without physical hardware.
  2. Complete the QTSP’s issuance workflow. This typically involves accepting the QTSP’s terms, confirming your identity data, and setting up multi-factor authentication credentials (PIN, mobile OTP, or biometric confirmation).
  3. Receive and activate the certificate. For cloud-based solutions, activation is usually immediate upon completing the identity and payment steps. For hardware tokens, allow for delivery time (typically one to five business days within Romania).
  4. Integrate with your signing software. Most Romanian QTSPs provide signing applications, browser plugins, or API integrations that work with standard document formats (PDF/A, XML, ASiC). Many also integrate with third-party e-signature platforms, verify that the platform routes signatures through a QTSP-issued certificate and does not substitute its own non-qualified signature.
  5. Sign the document. Open the document in the signing application, authenticate using your multi-factor credentials, review the document content, and confirm the signature. The signing application will embed the qualified certificate, a cryptographic hash, and, where available, a qualified timestamp into the signed file.
  6. Distribute and archive. Send the signed document to the counterparty. Retain the signed file, the certificate chain, and the qualified timestamp evidence in your document management system. This archive forms the core of your audit trail.

Typical timeline: For organisations with documents ready and a pre-selected QTSP, the entire process, from application to first signed document, can be completed within one to three business days using a cloud-based remote signing service. Hardware-token pathways may take up to five business days due to device delivery.

Sample Procurement Signature Flow

For a public procurement tender submission in Romania, the operational sequence is:

  1. Procurement officer prepares the tender documents in the required format.
  2. Authorised signatory authenticates to the QTSP’s cloud signing service using multi-factor credentials.
  3. Signatory reviews and applies a QES to each required document; a qualified timestamp is embedded.
  4. Signed documents are uploaded to the contracting authority’s electronic procurement portal.
  5. Procurement officer archives the signed files, certificate chain, timestamp evidence, and portal submission receipt.

When to Require a Qualified Electronic Signature, Decision Matrix

Not every document demands a QES, but choosing the wrong signature tier for a high-stakes transaction creates real legal risk. The table below maps common document types to their QES requirements under Romanian and EU law.

Document type When QES is required Practical consequence / action
Public procurement tender submissions Mandated for certified submissions to contracting authorities under Law 214/2024 and procurement platform rules Require supplier QES; verify the issuing QTSP in the Trusted List before accepting the submission
Tax and fiscal filings (selected categories) Required where the fiscal authority’s electronic filing system mandates QES authentication Ensure the filing officer holds a valid QES certificate; check expiry dates before submission deadlines
Share transfer / M&A closing documents Recommended; often required by Trade Registry practices or buyer risk policies for cross-border closings Use QES for all signatures; retain the full QTSP certificate chain and qualified timestamp
Board resolutions and corporate approvals Not universally mandated, but increasingly expected by counterparties and registries for electronic filings Use QES where resolutions will be filed with public authorities or relied upon in disputes
Employment termination letters Case-by-case; required where sector rules demand signed proof of delivery and non-repudiation If risk of dispute is material, use QES and include identity verification evidence in the personnel file
Standard commercial contracts (B2B) Not mandated unless parties contractually agree or a specific regulation applies Advanced electronic signature is sufficient, but consider QES for high-value or cross-border agreements
Health sector filings and clinical records Mandated for designated health data submissions under sector-specific rules aligned with Law 214/2024 Healthcare entities must ensure all designated signatories hold active QES certificates

The general principle is that a QES is legally required wherever Romanian or EU legislation expressly mandates it, and strongly recommended wherever the cost of a signature challenge in litigation would exceed the marginal cost of upgrading from an advanced to a qualified signature.

Vendor Selection and Contractual Clauses for QTSP and E-Sign Services

Choosing the right QTSP and embedding protective contract language are as important as the signature itself. This section provides a vendor evaluation checklist and sample clause snippets for SaaS, outsourcing, and public procurement contexts.

When evaluating a QTSP, whether a local Romanian provider or a cross-border EU provider, apply the following checklist:

  • Trusted List entry. Confirm the provider appears with “granted” status for qualified certificate issuance on the relevant national Trusted List (Romania or another EU Member State).
  • Conformity assessment reports. Request the provider’s most recent conformity assessment report issued by an accredited conformity assessment body. This report confirms compliance with ETSI EN 319 401 (general requirements for trust service providers) and, where applicable, ETSI EN 319 411-1/411-2 (policy and security requirements for certificate issuance).
  • QSCD certification. Verify that the qualified signature creation device, whether hardware or cloud-based, holds a valid Common Criteria or equivalent certification.
  • Incident response and revocation procedures. Confirm the QTSP has documented and tested procedures for certificate revocation and security incident response, including notification timelines.
  • SLA for availability and signing throughput. For cloud-based remote signing, agree uptime commitments and maximum transaction processing times, particularly if the service supports high-volume procurement or payroll signing.

Sample Contractual Clause Snippets

The following clauses can be adapted for inclusion in QTSP service agreements, SaaS contracts, or procurement terms:

  • Clause 1, QTSP acceptance criteria. “The Parties agree that electronic signatures applied under this Agreement shall be qualified electronic signatures within the meaning of Regulation (EU) No 910/2014, based on qualified certificates issued by a trust service provider listed with ‘granted’ status on a national Trusted List maintained under Article 22 of that Regulation.”
  • Clause 2, Liability for signature invalidity. “Where a signature is found to be invalid due to the issuing QTSP’s failure to comply with its qualified status obligations, the Party that selected the QTSP shall bear liability for any resulting loss, up to [amount/cap], unless the invalidity results from a force majeure event or a revocation of qualified status that was not publicly notified at the time of signing.”
  • Clause 3, Audit log retention. “The Service Provider shall retain complete audit logs, including signer identity records, certificate serial numbers, qualified timestamps, and authentication event metadata, for a minimum period of [five (5) / ten (10)] years from the date of each signing event, and shall make such logs available to the Client upon reasonable request for litigation or regulatory audit purposes.”
  • Clause 4, Cross-border certificate acceptance. “Each Party shall accept qualified electronic signatures based on qualified certificates issued by QTSPs listed on any EU Member State national Trusted List, in accordance with Article 25(3) of Regulation (EU) No 910/2014, without requiring additional notarisation or legalisation.”
  • Clause 5, Subcontracting and key custody. “The QTSP shall not subcontract the generation, storage, or management of private signing keys to any entity that does not itself hold qualified status or operate a certified QSCD, without the prior written consent of the Client.”

Audit, Retention, Disputes, and Evidentiary Best Practice

A qualified electronic signature is only as defensible as the audit trail that supports it. In the event of a contractual dispute or regulatory investigation, Romanian courts and arbitral tribunals will examine the integrity of the signing process, not merely the signature file itself.

For every QES-signed document, retain the following evidence:

  • Signer identity record: the name, identity document reference, and verification method (video KYC session ID, eID authentication log, or in-person registration reference).
  • Certificate chain: the qualified certificate, intermediate certificates, and root certificate of the issuing QTSP.
  • Qualified timestamp: a timestamp token issued by a qualified time-stamping authority, proving the signature existed at a specific point in time.
  • Authentication event metadata: records of the multi-factor authentication used at the moment of signing (OTP delivery, biometric confirmation, PIN entry).
  • QTSP status snapshot: evidence (e.g., a Trusted List extract or OCSP response) confirming the certificate was valid and the QTSP held “granted” status at the time of signing.

Retain these records for a minimum of five years, and ten years where the signed document relates to real estate, corporate registrations, or transactions with extended limitation periods. When preparing for e-discovery or court proceedings, compile the records into a verification bundle that a technical expert can present to demonstrate the signature’s validity at the time it was applied.

Conclusion

Implementing a qualified electronic signature in Romania online in 2026 requires a disciplined four-step process: select a QTSP verified on the national or EU Trusted List, complete compliant remote identity verification, sign using a certified QSCD with a full audit trail, and embed protective clauses in your vendor and procurement contracts. With Law no. 214/2024 expanding mandatory QES use cases and eIDAS 2.0 reinforcing cross-border recognition, organisations that build these processes now will be positioned for compliant, efficient, and legally defensible digital transactions across Romania and the wider EU.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.

Sources

  1. EUR-Lex, Regulation (EU) 2024/1183 (amending eIDAS)
  2. Portal Legislativ, LEGE nr. 214 din 5 iulie 2024 (Romania)
  3. Autoritatea pentru Digitalizarea României (ADR), e-signature / Trusted List
  4. European Commission, EU Trusted Lists / List of Trusted Lists (LOTL)
  5. eIDAS Trusted List Browser (EFDA)
  6. Portal Legislativ, Procedural Guidance (administrative electronic filing requirements)

FAQs

How do I use a qualified electronic signature?
Obtain a qualified certificate from a QTSP listed on a national Trusted List, complete identity verification (video KYC, eID, or in-person), install or access the QTSP’s signing application, authenticate with multi-factor credentials, and apply the signature to your document. Full step-by-step instructions are provided in the operational section above.
Under Regulation (EU) No 910/2014, a QES is an advanced electronic signature created by a qualified electronic signature creation device and based on a qualified certificate issued by a QTSP. It is the only electronic signature type that all EU Member States must treat as the legal equivalent of a handwritten signature.
DocuSign as a platform is not itself a QTSP. However, DocuSign can be used in Romania if the signature is backed by a qualified certificate issued by a QTSP that appears on an EU national Trusted List. Verify that the specific signing workflow routes through a listed QTSP rather than relying solely on DocuSign’s own standard or advanced electronic signature tiers.
Not by default. DocuSign offers multiple signature tiers, including integrations with QTSPs that enable QES. Whether a specific DocuSign signature qualifies as a QES depends on whether it was created using a qualified certificate from a listed QTSP and a certified QSCD. Always check the Trusted List entry for the issuing provider.
Use the EU Trusted List browser maintained by the European Commission or access Romania’s national Trusted List via the ADR website. Filter by country and service type (“QCert for ESig”), and confirm the provider’s status shows “granted.” Any other status means the provider cannot currently issue valid qualified certificates.
No. Romanian law does not require a QES for every contract. An advanced electronic signature is generally sufficient for standard commercial agreements unless a specific law (such as Law no. 214/2024 for public-authority interactions) or the parties’ own contractual terms mandate a qualified signature. Use the decision matrix above to assess your risk profile.
Yes. Under Article 25(2) of eIDAS, a QES based on a qualified certificate issued in any EU Member State must be recognised in all other Member States, including Romania. No additional legalisation or notarisation is required.
vaitos licence mauritius
By Jonathon Richards

posted 27 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Use Qualified Electronic Signature in Romania Online (2026): Qtsps, Remote ID & Mandatory Uses

Send welcome message

Custom Message