There are two completely different questions hiding inside "is my e-signature valid," and mixing them up is where people get hurt. The first is technical: does the cryptography check out? The second is legal: will a court treat this as a binding signature? You can pass the first and fail the second, or — surprisingly often — fail the first and still win the second. This is about the legal question: what actually makes an electronic signature enforceable, and how to know whether yours clears the bar.
What nearly every e-signature law requires: intent to sign, consent to sign electronically, attribution to the signer, and integrity of the record afterward
The common core of eIDAS, UETA/ESIGN, and the GCC statutes
UETA (1999) and the US ESIGN Act (2000) gave electronic signatures the same legal effect as wet ink — years before the technology was common
Uniform Law Commission / US Congress
eIDAS Regulation (EU) 910/2014 Article 25 — an electronic signature cannot be denied legal effect solely because it is electronic
Regulation (EU) 910/2014
Validity is about evidence, not format
Almost no jurisdiction requires a particular technology for an ordinary commercial contract. A typed name, a drawn squiggle, a checkbox — all can be legally valid signatures. What the law actually asks is whether four things are true, and whether you can prove them if the signature is ever challenged.
Intent
The signer meant to sign — to be legally bound by this document, not merely to acknowledge receipt. Clicking a clearly-labelled 'Sign' button after seeing the document establishes intent.
Consent to sign electronically
The parties agreed to do business electronically. In consumer contexts (UETA/ESIGN) this consent must be explicit and recorded; in B2B it is usually implied by conduct.
Attribution
The signature can be tied to the specific person. This is where evidence matters: an OTP sent to a verified email or phone, an IP and timestamp, an audit trail — the stronger the attribution, the harder the signature is to repudiate.
Integrity
The signed record is tamper-evident and retained. If the document can be altered after signing without detection, its evidential weight collapses. A cryptographic seal makes post-signing changes provable.
The three tiers, and when you actually need them
International practice (eIDAS, and the GCC laws modelled on it) sorts electronic signatures into three tiers. Higher tiers carry more evidential weight and more friction. The most common mistake is reaching for the highest tier when the lowest already binds.
The SES / AES / QES tiers under eIDAS and the GCC statutes that mirror it. The right tier is the lowest one the receiving party will accept — not the highest available.
| Jurisdiction | Law | Cross-border transfer rule | Intensity |
|---|---|---|---|
| SES — Simple | eIDAS Art. 3(10) | Any electronic signature: a typed name, a click, a drawn mark. Legally valid for the vast majority of commercial contracts. Evidential weight depends entirely on the surrounding evidence (audit trail, OTP, timestamps). | Moderate |
| AES — Advanced | eIDAS Art. 26 | Uniquely linked to the signer, capable of identifying them, under their sole control, and tamper-evident. A well-built platform meets this with OTP identity plus a cryptographic seal. The workhorse tier for B2B. | Restricted |
| QES — Qualified | eIDAS Art. 3(12) | AES plus a qualified certificate on a qualified signature-creation device (a national-ID chip or certified HSM). Legally equal to a handwritten signature by force of law. Required only for specific acts — some notarial, government, or high-value instruments. | Strict |
The question is never 'what is the strongest signature I can make.' It is 'what will the counterparty, the registry, or the court that receives this actually require.' For everyday commercial documents across the GCC, a well-evidenced simple or advanced signature is binding today.
— The practical rule for choosing a tier
What a court looks at when a signature is challenged
Validity is theoretical until someone disputes it. When a signer claims "that wasn't me" or "the document was changed," the court weighs the evidence package behind the signature. This is exactly where a bare typed name and a properly-evidenced signature diverge — not in the mark itself, but in what backs it.
The evidence that survives a repudiation challenge
- Signer identity verification
A one-time code delivered to a verified email or phone the signer controls, proving the person at the keyboard could access that channel. Weak identity is the most common reason a signature is successfully disputed.
- A tamper-evident audit trail
A time-ordered log of every event — sent, opened, verified, signed — that cannot be edited after the fact. A hash-chained trail breaks visibly if any historical entry is altered.
- A cryptographic seal on the final document
A digital signature over the completed PDF so any later change is detectable. This is what turns 'we think it's unchanged' into 'we can prove it's unchanged.'
- A trusted timestamp
An RFC 3161 timestamp from an independent authority fixing when the signature was applied, so signing time can't be disputed or backdated.
- A completion certificate citing the governing law
A record that names the statute the signature was executed under and summarises the evidence — the document you hand a court or counterparty first.
The GCC picture in one view
Every GCC state recognises electronic signatures by statute. The tier you need depends on the document and the receiving authority, but for ordinary B2B contracts, the answer across the region is the same: yes, they are valid today.
Electronic signature statutes across the GCC. All recognise e-signatures; each links to a full guide.
| Jurisdiction | Law | Cross-border transfer rule | Intensity |
|---|---|---|---|
| Qatar | Decree-Law 16/2010 + CRA Decision 3/2025 | Recognised since 2010; a formal trust-services and tier framework added in 2025. Binding for commercial documents today. | Restricted |
| Saudi Arabia | Royal Decree M/18 (2007) | Full legal effect since 2007. Nafath-anchored qualified signing available where higher assurance is required. | Restricted |
| UAE | Federal Decree-Law 46/2021 | Recognises simple, advanced, and qualified tiers on an eIDAS-aligned model. Broad commercial validity. | Restricted |
| Bahrain / Kuwait / Oman | National e-transaction laws | Each recognises electronic signatures for commercial use, with country-specific exclusions for personal-status and certain registrable instruments. | Moderate |
What is usually excluded
Even where e-signatures are broadly valid, most jurisdictions carve out a short list of documents that still require wet ink or notarisation: matters of personal status (marriage, divorce, inheritance), some real-estate title transfers, and certain instruments a public registry must record. Everyday commercial paperwork — contracts, offers, NDAs, HR documents, service agreements — is not on that list.
What SahlSign issues: a simple electronic signature backed by OTP-verified identity, a hash-chained audit trail, a PAdES-B-T cryptographic seal, and an RFC 3161 timestamp — the evidence package a court weighs when a signature is challenged.
SahlSign signing pipeline
The takeaway
Your electronic signature is legally valid if it captures intent, rests on recorded consent, ties to the signer, and protects the record's integrity — and if you can prove all four later. The mark itself barely matters. The evidence behind it decides the case. A typed name with no trail is technically a signature and practically indefensible; a simple signature with verified identity, a tamper-evident trail, and a cryptographic seal is what holds up.
Related reading
- How to Verify a Signed PDF — once a signature binds legally, this is how any party confirms the file wasn't altered.
- How to Verify a Digital Signature — the cryptography behind the integrity and attribution the law asks for.
- Is an Electronic Signature Legal in Qatar? — the same four elements, applied to a specific GCC statute.
Sources
- eIDAS Regulation (EU) 910/2014 — Articles 25, 26, and definitions
- US ESIGN Act (2000) — Electronic Signatures in Global and National Commerce Act
- Uniform Electronic Transactions Act (UETA, 1999)
- Qatar Decree-Law No. 16 of 2010 — Electronic Commerce and Transactions
- Saudi Electronic Transactions Law — Royal Decree M/18 (2007)
- UAE Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services