Understanding how to use a qualified electronic signature in Romania online has become a non-negotiable compliance priority for businesses engaging with Romanian public authorities, closing cross-border transactions, or digitising procurement workflows. Regulation (EU) 2024/1183, commonly known as eIDAS 2.0, reshaped the EU-wide framework for trust services and cross-border recognition, while Romania’s own Law no. 214/2024, published on 5 July 2024, introduced national mandates that require QES for an expanding list of official filings and public-sector interactions. This guide translates both layers of regulation into operational steps: choosing a Qualified Trust Service Provider (QTSP), completing remote identity verification, signing documents compliantly, and building the contract clauses and audit trails that protect your organisation in disputes.
Key compliance checklist, at a glance:
Who this guide is for: In-house counsel, procurement managers, CIOs/CTOs, compliance officers, and external advisers working with Romanian entities, public authorities, or cross-border counterparties that require or accept qualified electronic signatures.
A qualified electronic signature is the only type of electronic signature that EU law treats as the legal equivalent of a handwritten signature in every Member State, without additional conditions. Grasping this distinction is essential before addressing the qualified electronic signature requirements for Romania online workflows.
Under Regulation (EU) No 910/2014 (the original eIDAS Regulation), a QES is defined as an advanced electronic signature that is (a) created by a qualified electronic signature creation device and (b) based on a qualified certificate for electronic signatures issued by a QTSP. The certificate must meet Annex I requirements, and the creation device must satisfy Annex II criteria. This layered architecture is what separates a QES from simpler signature types and gives it its unique legal standing.
Article 25(2) of eIDAS establishes that a QES based on a qualified certificate issued in one Member State must be recognised as a QES in all other Member States. Regulation (EU) 2024/1183 (eIDAS 2.0) preserves and reinforces this principle while introducing the European Digital Identity Wallet framework, which, once fully operational, will offer an additional pathway for identity authentication when obtaining or using a qualified electronic signature. The practical effect for businesses operating in Romania is straightforward: a QES issued by a French, German, or any other EU-listed QTSP carries the same legal weight in a Romanian court as one issued locally.
Law no. 214/2024, published on 5 July 2024, expanded the scope of transactions where Romanian public authorities and regulated entities must accept or require a qualified electronic signature. This section outlines the mandates most relevant to B2B compliance.
Law 214/2024 entered into force in accordance with its published timeline, with certain provisions taking phased effect to allow public institutions and QTSPs to adapt their systems. Businesses that interact with Romanian public procurement portals, regulatory filing systems, and healthcare data platforms should treat the law’s mandates as fully operative for 2026 compliance planning. Separately, procedural rules published on the Portal Legislativ, including implementing procedures that govern specific electronic filings, reinforce the requirement for QES in designated administrative workflows.
The law’s most immediate impact falls on interactions where documents are submitted to or issued by Romanian public authorities. The key areas include:
Not every transaction demands a QES. Where Law 214/2024 or sector-specific legislation does not expressly mandate a qualified signature, an advanced electronic signature remains legally valid, though it does not benefit from the automatic presumption of equivalence to a handwritten signature. Private commercial contracts between two businesses, for example, generally remain enforceable with an advanced electronic signature unless the parties’ own agreement or a specific regulatory provision requires a higher tier.
Only Qualified Trust Service Providers (QTSPs) that appear on a national Trusted List maintained under eIDAS can issue the qualified certificates that underpin a valid QES. Verifying this listing is a non-negotiable compliance step.
In Romania, the Autoritatea pentru Digitalizarea României (ADR) serves as the supervisory body for trust services. ADR is responsible for granting, monitoring, and, where necessary, withdrawing qualified status from trust service providers operating within Romania. ADR publishes and maintains Romania’s national Trusted List, which is the authoritative register of all providers and services that hold qualified status. This list is available in both human-readable and machine-readable (XML) formats. Any QTSP that does not appear on this list with an active “granted” status for qualified certificate issuance cannot validly issue the certificates required for a QES in Romania.
When verifying whether a provider is a valid QTSP, check the following fields in the Trusted List entry:
The European Commission’s central List of Trusted Lists (LOTL) aggregates every Member State’s national list, making it possible to verify cross-border QTSPs in a single lookup. Industry observers expect this process to become even more streamlined as the European Digital Identity Wallet infrastructure matures under eIDAS 2.0.
This is the core operational section, it explains exactly how to use a qualified electronic signature in Romania through online channels, from onboarding with a QTSP to signing your first document.
Before initiating the process, prepare the following artefacts:
| Required artefact | Purpose |
|---|---|
| Valid government-issued identity document (Romanian ID card, passport, or EU national ID) | Identity verification during QTSP onboarding |
| Corporate authorisation letter or power of attorney (for corporate signatories) | Proof that the individual is authorised to sign on behalf of the legal entity |
| Company registration extract (certificat constatator), if signing on behalf of a Romanian entity | Confirms entity identity and signatory authority |
| Active email address and mobile phone number | Required for multi-factor authentication during certificate issuance and signing |
Romanian QTSPs currently offer several pathways for remote identity verification, each complying with applicable eIDAS and national requirements:
Once identity verification is complete, follow these steps to obtain your certificate and begin signing:
Typical timeline: For organisations with documents ready and a pre-selected QTSP, the entire process, from application to first signed document, can be completed within one to three business days using a cloud-based remote signing service. Hardware-token pathways may take up to five business days due to device delivery.
For a public procurement tender submission in Romania, the operational sequence is:
Not every document demands a QES, but choosing the wrong signature tier for a high-stakes transaction creates real legal risk. The table below maps common document types to their QES requirements under Romanian and EU law.
| Document type | When QES is required | Practical consequence / action |
|---|---|---|
| Public procurement tender submissions | Mandated for certified submissions to contracting authorities under Law 214/2024 and procurement platform rules | Require supplier QES; verify the issuing QTSP in the Trusted List before accepting the submission |
| Tax and fiscal filings (selected categories) | Required where the fiscal authority’s electronic filing system mandates QES authentication | Ensure the filing officer holds a valid QES certificate; check expiry dates before submission deadlines |
| Share transfer / M&A closing documents | Recommended; often required by Trade Registry practices or buyer risk policies for cross-border closings | Use QES for all signatures; retain the full QTSP certificate chain and qualified timestamp |
| Board resolutions and corporate approvals | Not universally mandated, but increasingly expected by counterparties and registries for electronic filings | Use QES where resolutions will be filed with public authorities or relied upon in disputes |
| Employment termination letters | Case-by-case; required where sector rules demand signed proof of delivery and non-repudiation | If risk of dispute is material, use QES and include identity verification evidence in the personnel file |
| Standard commercial contracts (B2B) | Not mandated unless parties contractually agree or a specific regulation applies | Advanced electronic signature is sufficient, but consider QES for high-value or cross-border agreements |
| Health sector filings and clinical records | Mandated for designated health data submissions under sector-specific rules aligned with Law 214/2024 | Healthcare entities must ensure all designated signatories hold active QES certificates |
The general principle is that a QES is legally required wherever Romanian or EU legislation expressly mandates it, and strongly recommended wherever the cost of a signature challenge in litigation would exceed the marginal cost of upgrading from an advanced to a qualified signature.
Choosing the right QTSP and embedding protective contract language are as important as the signature itself. This section provides a vendor evaluation checklist and sample clause snippets for SaaS, outsourcing, and public procurement contexts.
When evaluating a QTSP, whether a local Romanian provider or a cross-border EU provider, apply the following checklist:
The following clauses can be adapted for inclusion in QTSP service agreements, SaaS contracts, or procurement terms:
A qualified electronic signature is only as defensible as the audit trail that supports it. In the event of a contractual dispute or regulatory investigation, Romanian courts and arbitral tribunals will examine the integrity of the signing process, not merely the signature file itself.
For every QES-signed document, retain the following evidence:
Retain these records for a minimum of five years, and ten years where the signed document relates to real estate, corporate registrations, or transactions with extended limitation periods. When preparing for e-discovery or court proceedings, compile the records into a verification bundle that a technical expert can present to demonstrate the signature’s validity at the time it was applied.
Implementing a qualified electronic signature in Romania online in 2026 requires a disciplined four-step process: select a QTSP verified on the national or EU Trusted List, complete compliant remote identity verification, sign using a certified QSCD with a full audit trail, and embed protective clauses in your vendor and procurement contracts. With Law no. 214/2024 expanding mandatory QES use cases and eIDAS 2.0 reinforcing cross-border recognition, organisations that build these processes now will be positioned for compliant, efficient, and legally defensible digital transactions across Romania and the wider EU.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.
posted 7 minutes ago
posted 27 minutes ago
posted 31 minutes ago
posted 55 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message