Electronic Signature vs Digital Signature: What's the Difference?
Published August 6, 2026
Quick answer
An electronic signature is a legal category — any electronic symbol or process adopted with intent to sign, defined by the ESIGN Act at 15 U.S.C. § 7006(5) and by eIDAS at Article 3(10). A digital signature is a cryptographic method: a key pair and a certificate used to bind a signature to a document so tampering is detectable. Neither statute defines 'digital signature' at all — both are technology-neutral — so a digital signature is one way to produce an electronic signature, not a separate legal class of it.
The two phrases are used as if they were synonyms. They are not, and the difference is not one of degree — they belong to different categories altogether. One is a legal status. The other is a piece of cryptography. Once that is clear, most of the confusion around the topic dissolves.
The short version
- An electronic signature is a legal category. A law says what counts as one. Under both US and EU law the bar is about intent, not appearance: a typed name, a drawn squiggle, or a click can all qualify.
- A digital signature is a technical method. It uses public-key cryptography — a private key, a matching certificate, and a hash of the document — so that any later change to the file can be detected and the signature traced to the key that made it.
- The two are not rivals. A digital signature is one way of producing an electronic signature. Every digital signature used to sign an agreement is an electronic signature; most electronic signatures are not digital signatures.
What the law actually defines
The ESIGN Act defines an electronic signature at 15 U.S.C. § 7006(5) as:
“an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record.”
The eIDAS Regulation defines it at Article 3(10) as:
“data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.”
Read both definitions again and notice what is missing: no technology. No certificate, no key, no algorithm. That is deliberate. Both instruments are written to be technology-neutral so they do not expire when the cryptography of the day is replaced.
Neither statute defines the term “digital signature” anywhere.
Where the confusion comes from
You will see it written that eIDAS defines “two types of digital signature” — Advanced and Qualified. That is not what the Regulation says, and the error is worth untangling because it is repeated widely.
eIDAS defines three tiers of electronic signature, in three consecutive definitions:
| Tier | Defined at | What it adds |
|---|---|---|
| Electronic signature (commonly “SES”) | Article 3(10) | The baseline. Admissible under Article 25(1). |
| Advanced (AdES) | Article 3(11), via Article 26 | Uniquely linked to and capable of identifying the signatory, under their sole control, with later changes detectable. |
| Qualified (QES) | Article 3(12) | An AdES made on a certified device (a QSCD) using a qualified certificate. |
Three points follow from that:
- They are tiers of electronic signature, not types of digital signature. The word “digital” is doing no work in the Regulation; it is not among the defined terms.
- There are three, not two. Dropping the Article 3(10) baseline is what produces the “two types” claim — and the baseline is the tier that most commercial agreements actually rely on.
- “Simple Electronic Signature” and “SES” are industry shorthand, not statutory terms. The Regulation simply says “electronic signature.” The shorthand is useful and we use it too, but it is worth knowing it is ours and not the legislature’s.
AdES and QES are, in practice, almost always implemented using digital-signature cryptography. That is the kernel of truth the “two types” claim is built on. But the tiers are defined by what a signature must achieve, not by the technique used to achieve it.
Does a digital signature make a document “more legal”?
No — and this is the question the terminology confusion is really hiding.
Legal validity comes from the law: intent to sign, attribution to the signer, consent where it is required, and retention of the record. A document either meets those tests or it does not. Cryptography is not one of the tests.
What cryptography changes is evidence. If a signature is ever challenged, the question stops being “is this type of signature valid?” and becomes “can you show who signed, what they saw, and that the file has not changed since?” That is an evidentiary problem, and it is the one a strong audit trail and tamper-evidence exist to solve.
The one place the tier genuinely changes the legal outcome is under eIDAS, where a QES — and only a QES — carries automatic equivalence to a handwritten signature across all 27 member states. Under ESIGN and UETA there are no tiers at all: a signature either meets the statutory definition or it does not.
Which one does a normal agreement need?
For the large majority of commercial agreements — NDAs, sales contracts, statements of work, employment offers — an electronic signature with a complete audit trail is what the law asks for and what counterparties expect. A digital signature in the cryptographic sense is not required by ESIGN, by UETA, or by the eIDAS baseline.
Reach for AdES or QES when a specific member-state law requires it for that document type. That is a question about the document, not about signing software. Our guide to what makes an electronic signature legally binding covers the underlying requirements in full.
Signatura issues Simple Electronic Signatures, with a complete audit trail and a SHA-256 tamper-evident seal on every completed document. It does not issue AdES or QES.
Frequently asked questions
Is a digital signature the same as an electronic signature?
No. “Electronic signature” is a legal category defined by statute; “digital signature” is a cryptographic technique. A digital signature is one way to create an electronic signature, so every digital signature on an agreement is also an electronic signature — but the reverse is not true.
Does the ESIGN Act require a digital signature?
No. ESIGN defines an electronic signature at 15 U.S.C. § 7006(5) as a symbol or process adopted “with the intent to sign the record.” It prescribes no technology, and it does not use the term “digital signature.”
Does eIDAS define “digital signature”?
No. eIDAS defines “electronic signature” (Article 3(10)), “advanced electronic signature” (Article 3(11)) and “qualified electronic signature” (Article 3(12)). “Digital signature” is not a defined term in the Regulation.
Is a typed name a digital signature?
No — a typed name involves no cryptography. It can still be a valid electronic signature if intent and attribution can be shown; we cover when it holds up in Is a typed signature legally binding?
Is one more secure than the other?
They are not on the same axis. Security depends on what a system actually does — how it authenticates signers, what it records, and whether changes to the finished file are detectable. Cryptographic signing is one strong tool for that, but a signature is only as good as the evidence behind it.
This page explains the law in general terms. It is not legal advice and cannot tell you what your particular document requires — for that, ask a lawyer in your jurisdiction.
Sources: ESIGN Act, 15 U.S.C. § 7006 definitions · 15 U.S.C. § 7001 · Regulation (EU) No 910/2014 (eIDAS), EUR-Lex — see Articles 3, 25 and 26.
Sign documents the modern way
Signatura is an ESIGN- and eIDAS-aligned e-signature platform with AI-assisted field placement. See pricing · How we keep documents secure
Start your 14-day free trialThis article is general information, not legal advice. For how a specific document or jurisdiction applies to you, consult a qualified professional.