The vocabulary in this area is used loosely, including by people selling the products, so it is worth being exact before anything else. The exactness is not pedantry: the distinctions carry different legal effects, and choosing the wrong instrument is a mistake that only shows up when it is relied on.
A person signs, an organisation seals
Under eIDAS, an electronic signature is made by a natural person. An electronic seal is made by a legal person. That is the whole distinction, and it decides which instrument belongs on an invoice.
An invoice is issued by a company. It is not issued by whoever in accounts receivable happened to release the batch, and attaching that individual's identity to a hundred thousand documents asserts something nobody intended — that a named employee stands behind each one personally. When they leave, the assertion becomes awkward to explain.
So for invoicing the instrument is normally the seal. Signatures have their place, on documents where an individual genuinely is the author. Invoices are not among them.
What the tiers buy
There are three levels, and the difference between them is not the strength of the cryptography. It is the assurance about who holds the key and how carefully that was established.
| Tier | What it establishes | What it costs to run | When it is not enough |
|---|---|---|---|
| Electronic signature or seal | That something was applied by someone; the identity assurance is whatever the parties arranged | Little beyond the effort of applying it | Whenever the identity behind it is what is in dispute, which is the only reason to have one |
| Advanced | Uniquely linked to and capable of identifying the signatory, created with means under their sole control, and detecting subsequent change | Key management, certificate lifecycle, and a defensible enrolment process | Where a national rule specifically requires the qualified tier |
| Qualified | Advanced, plus a qualified certificate from a provider on the trusted list, created by a qualified device | The above, plus the provider's fees and the constraints of qualified devices | Where the counterparty or jurisdiction accepts nothing less, or where you need the legal presumption |
The last row matters more than the first three. A seal establishes origin and detects alteration. It says nothing about whether the VAT treatment is right, whether the supply happened, or whether the figures agree with the contract. Those are exactly the things an assessment disputes. A business that seals diligently and cannot link its invoices to deliveries has bought evidence for the argument nobody was having.
The trusted list is the part that carries the legal weight
A qualified certificate is qualified because a supervised provider issued it under a regime a Member State supervises, and because that provider appears on the published trusted list for the relevant service.
That is an administrative fact, not a technical one, and it has a practical consequence people miss: a certificate can be technically impeccable and still not qualified. The cryptography is identical. What differs is whether an authority stands behind the identity check that preceded issuance, and whether that standing is recorded somewhere a relying party can check independently.
When someone offers "eIDAS-compliant signing", the question to ask is which tier, from which provider, and whether that provider appears on the trusted list for that service in that Member State. The answer is public and takes a minute to verify.
The framework introduced by the 2024 regulation extends the eIDAS structures towards wallets and attestations of attributes. For invoicing specifically, the immediate effect is limited: the tiers, the trusted list and the legal effects described here are the ones that apply to sealing an invoice today. It is worth knowing the direction of travel without rebuilding anything in anticipation of it.
The cost that arrives later
Adopting sealing is a project. Maintaining it is a permanent obligation, and the second is the one that is not in the business case.
Certificates expire, typically well inside a retention period measured in years. Providers change their offerings or leave the market. And the requirement is not that the seal was valid when applied — it is that authenticity and integrity are assured for the whole retention period, which means somebody has to be able to demonstrate validity long after the certificate has lapsed and possibly after the provider has gone.
That is a preservation problem, and preservation arrangements have to be established while the evidence is fresh. Retrofitting them to a five-year-old archive is either impossible or expensive, and the discovery is normally made by whoever inherited the archive from the person who set it up.
Most implementations seal outbound documents carefully and verify inbound ones not at all. That asymmetry is backwards from a risk perspective. Your own outbound documents are corroborated by your own records. An inbound invoice supporting a deduction is corroborated by nothing except the document itself, and a seal you never check is decoration.
Where a mandate takes the choice away
The directive leaves the method to the taxable person. National mandates frequently do not, and the interaction is where planning goes wrong.
Where a mandate routes documents through a platform, the platform typically applies its own assurance and its records become the evidence for those transactions. That is a good outcome and it has a boundary: it covers what passes through the platform. Transactions outside the mandate's scope — cross-border supplies, categories not yet phased in, documents that are not invoices in the legal sense — are still yours to assure, and they are the ones that fall between two arrangements because each was designed assuming the other covered them. The Italian architecture is the longest-running example, and how the national format handles sealing and transmission is instructive about how much the platform does and does not take on.
The transmission side has its own evidence: what the platform accepted, when, and what it returned. Those receipts and notifications are a distinct and often stronger record than any seal, because they are produced by a third party with no interest in the transaction.
Choosing deliberately
The honest position is that sealing is one instrument among several, that it answers a narrow question well, and that it should be adopted where that question is live rather than as a default posture.
For most businesses the practical arrangement is: seal where a jurisdiction or a counterparty requires it; verify inbound seals where they arrive; and rely on a documented business control for everything else, because the control is what links the invoice to the supply and that link is what an assessment actually attacks.
That combination is unglamorous and it maps onto what the three properties actually require rather than onto what is easiest to buy. The alternative — sealing everything and documenting nothing — produces an organisation that can prove who sent an invoice and cannot prove anything happened afterwards.