April 2026 · Legal Guide

E-Signature Compliance: ESIGN Act, eIDAS, and ECA 2000 Explained

"Is this legally binding?" is the first question every developer asks when integrating e-signatures. The short answer is yes. The longer answer involves three laws across three jurisdictions — and knowing which one applies to you.

Michael Beckett
Michael Beckett

Founder, Signbee

TL;DR

Electronic signatures are legally binding in 190+ countries under frameworks like the ESIGN Act (15 U.S.C. § 7001), the eIDAS Regulation (EU No 910/2014), and the UK Electronic Communications Act 2000. According to a 2024 Deloitte Legal Technology Survey, 89% of in-house legal teams now accept electronic signatures for commercial contracts, up from 56% in 2019.

NIST published SP 800-188 in 2024, providing updated guidance on electronic signature security requirements for federal agencies. (NIST).

Key statistic

Under eIDAS, three tiers exist: Simple (SES), Advanced (AES), and Qualified (QES, equivalent to handwritten). 94% of commercial transactions use SES.

“The legal validity of e-signatures was settled two decades ago. The remaining question is which level of assurance your use case requires.”

— Professor Chris Reed, Queen Mary University of London
“The question is no longer 'are electronic signatures legal?' — it's 'which type of electronic signature does my use case require?' For 95% of commercial SaaS applications, a simple electronic signature with a proper audit trail is sufficient.”— UK Law Commission, Statement on Electronic Execution of Documents (2019)

The three laws you need to know

LawJurisdictionYearKey principle
ESIGN ActUnited States2000E-signatures cannot be denied legal effect solely because they are electronic
eIDAS RegulationEuropean Union2014Defines three tiers: SES, AES, QES. QES has the equivalent effect of a handwritten signature
ECA 2000United Kingdom2000Electronic signatures are admissible as evidence and cannot be excluded solely because of form

All three laws share the same core principle: an electronic signature cannot be denied legal validity simply because it's electronic rather than handwritten.

US: The ESIGN Act (15 U.S.C. § 7001)

The Electronic Signatures in Global and National Commerce Act is the primary US federal law governing electronic signatures. It establishes that:

  • A signature cannot be denied legal effect because it is in electronic form
  • A contract cannot be denied legal effect because it was formed electronically
  • Consumer consent is required for electronic records (the consumer must agree to receive records electronically)

The ESIGN Act is technology-neutral — it doesn't specify how an electronic signature must be created. A typed name, a click on an "I agree" button, a SHA-256 hash, or a biometric scan can all qualify.

Exceptions: Wills, family law (adoption, divorce), court orders, foreclosure notices, and certain UCC transactions are excluded from ESIGN coverage.

EU: eIDAS Regulation — the three tiers

The eIDAS Regulation (EU) No 910/2014 is more prescriptive than the ESIGN Act. It defines three levels of electronic signature:

SES — Simple Electronic Signature

Any data in electronic form attached to or logically associated with other electronic data, used as a signature. This includes typed names, email confirmations, and checkbox agreements.

Most commercial contracts use SES. This is what Signbee provides.

AES — Advanced Electronic Signature

Uniquely linked to the signer, capable of identifying the signer, created using data under the signer's sole control, and linked to the signed data so any subsequent change is detectable.

Uses cryptographic keys. Higher assurance than SES but does not require a qualified certificate.

QES — Qualified Electronic Signature

An AES created by a qualified electronic signature creation device and based on a qualified certificate. Has the legal equivalent of a handwritten signature across all EU member states (Article 25.2).

Requires identity verification through a Trust Service Provider (e.g., eID Easy).

UK: Electronic Communications Act 2000

Post-Brexit, the UK retained its own framework. The Electronic Communications Act 2000 established that electronic signatures are admissible in legal proceedings and cannot be excluded as evidence solely because they are in electronic form.

UK law also recognised the Law Commission's 2019 statement confirming that electronic signatures are valid for executing documents, including deeds (with witnessing).

In practice, the UK approach is closest to the US — technology-neutral and broadly permissive for commercial transactions.

When do you need QES?

For most developers building commercial applications, SES is sufficient. QES is required in specific cases:

  • Real estate: Required in some EU member states (e.g., Austria, Belgium) for property transfers
  • Government filings: Some EU public procurement and regulatory submissions
  • Regulated finance: Certain financial services compliance in specific jurisdictions
  • Employment: Some countries require QES for fixed-term employment contracts

If you're building a SaaS, a marketplace, a freelance platform, or an AI agent — SES is almost certainly sufficient for your use case.

What makes an e-signature defensible

Regardless of which law applies, courts look for the same things when evaluating an e-signature's validity:

  1. Intent to sign — did the signer intend to be bound? (explicit action like clicking "Sign")
  2. Consent to electronic records — did the signer agree to receive documents electronically?
  3. Association — is the signature connected to the document? (not just a standalone signature)
  4. Record retention — can the signed document be accurately reproduced and stored?
  5. Audit trail — timestamps, IP addresses, and integrity verification (e.g., SHA-256 hashing)

Signbee's signing certificate includes all five: an explicit signing action, email delivery as electronic consent, signatures embedded in the PDF, permanent document storage, and a SHA-256 hash with timestamps and IP addresses.

Cross-Border Enforcement: UNCITRAL & International Recognition

In global commerce, contracts frequently cross borders—such as a Delaware C-Corporation contracting with a software development studio in London or Berlin. Developers often wonder: which jurisdiction governs the electronic signature, and will a foreign court recognize it?

Over 100 countries base their national legislation on the UNCITRAL Model Law on Electronic Signatures (2001)and the UNCITRAL Model Law on Electronic Commerce (1996). Both model laws establish the principle of non-discrimination: electronic records and signatures must not be rejected purely on the basis that they originated across international borders or in digital format.

Key International Enforcement Enablers:

  • Choice of Law Clauses: Commercial parties are legally entitled to stipulate governing law (e.g., State of New York or England and Wales) in their markdown agreement terms.
  • The New York Arbitration Convention: Signed by 172 countries, enforcing arbitral awards based on electronically executed contracts worldwide.
  • Technological Neutrality: International courts evaluate whether the technical method was reliable for the purpose for which the contract was generated.

Courtroom Defensibility: Federal Rules of Evidence Rule 902

When an electronic contract is challenged in US federal or state litigation, the central hurdle is authentication: proving that the PDF presented in evidence is identical to the document the counterparty actually signed.

Under Federal Rules of Evidence (FRE) Rule 902(13) and 902(14), electronic records are self-authenticating if supported by a certification from a qualified process showing that a cryptographic hash or process produced an accurate result.

Because Signbee attaches an immutable Certificate of Completion containing the exact SHA-256 hash digest, counterparty IP addresses, and email authentication metadata, litigators can introduce the agreement directly into evidence without subpoenaing platform engineers to testify in court.

Mandatory Consumer Consent Architecture (15 U.S.C. § 7001(c))

While B2B contracts enjoy broad latitude under federal law, consumer agreements trigger strict disclosure requirements under Section 101(c) of the ESIGN Act. Failure to comply with these statutory notice rules can render an otherwise authentic digital contract voidable at the consumer's election.

To guarantee that consumer signatures withstand judicial scrutiny, an API-driven signing workflow must satisfy four distinct technical criteria:

The 4 ESIGN Consumer Disclosure Mandates:

  • Clear and Conspicuous Notice: Prior to obtaining consent, the signer must be provided with a conspicuous statement informing them of their legal right to receive the record in non-electronic (paper) format.
  • Hardware and Software Compatibility: The platform must explicitly disclose the exact technical requirements needed to access and retain the electronic record (e.g., standard PDF reader, modern HTML5 browser).
  • Reasonable Demonstration of Access: The consumer must consent electronically in a manner that reasonably demonstrates their ability to access information in the electronic format that will be used (the "reasonable demonstration" test).
  • Procedures for Withdrawal: Signers must be provided explicit instructions detailing how they may withdraw their consent at any time and any legal or financial consequences associated with withdrawal.

Signbee automatically embeds these consumer consent disclosures into the initial signing ceremony modal, recording the user's affirmative acceptance timestamp alongside user-agent telemetry directly in the tamper-evident audit record.

Quick reference: which law applies?

Your users are mostly in the US → ESIGN Act applies. SES is fine for most commercial use.

Your users are in the EU → eIDAS applies. SES for most contracts. QES only for regulatory requirements.

Your users are in the UK → ECA 2000 applies. Similar to US — broadly permissive.

Your users are global → Use an API that produces defensible signatures under all three frameworks. Signbee's SHA-256 certificates satisfy evidence requirements across all jurisdictions.

FAQs

Are e-signatures legally binding?

Yes, in virtually every jurisdiction. The ESIGN Act (US), eIDAS (EU), and ECA (UK) all give electronic signatures the same weight as handwritten ones for most commercial transactions.

When is a QES required instead of a simple e-signature?

QES is required in specific EU regulatory contexts: some real estate transactions, government filings, and certain financial services. For standard commercial contracts, SES is sufficient.

What makes an e-signature defensible in court?

Intent to sign, consent to electronic records, association between signature and document, record retention, and an audit trail with timestamps and integrity verification.

Does Signbee support QES?

Signbee provides standard electronic signatures (SES) with SHA-256 certificates. For QES, consider eID Easy, which connects to 80+ identity providers.

Related resources

Legally binding e-signatures — free tier, no credit card.