Establishing secure connection…Loading editor…Preparing document…

Digital Signature Act

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Digital Signature Ordinance (Signaturverordnung - SigV)

On the basis of § 16 of the Digital Signature Act of 22 July 1997 (Federal Law Gazette I S. 1870, 1872), the Federal Government decrees as follows:

Contents

§ 1 Procedures for issuance, withdrawal and revocation of licenses

§ 2 Costs

§ 3 Application procedure for issuance of certificates

§ 4 Notification of the applicant

§ 5 Generation and storage of signature keys and identification data

§ 6 Handover of signature keys and identification data

§ 7 Validity period for certificates

§ 8 Public register of certificates

§ 9 Procedures for invalidation of certificates

§ 10 Reliability of personnel

§ 11 Protection of technical components

§ 12 Security concept

§ 13 Documentation

§ 14 Cessation of operation

§ 15 Checks of the certification authorities

§ 16 Requirements pertaining to technical components

§ 17 Testing of technical components

§ 18 New digital signature

§ 19 Entry into force

§ 1: Procedures for issuance, withdrawal and revocation of licenses

(1) Licenses for the operation of a certification authority pursuant to § 4 (1) of the Digital Signature Act must be applied for in writing; such applications must be submitted to the competent authority.

Applicant Name:

Competent Authority:

(2) The competent authority shall obtain the information necessary to determine if the applicant fulfils prerequisites for issuance of a license. It can require the applicant to submit necessary documents, especially a current extract from the commercial register and current certificates of good conduct pursuant to § 30 (5) of the Federal Central Register Act for the legal representatives of the certification authority.

Commercial Register Extract Provided:

Certificates of Good Conduct Provided:

Professional Qualifications Evidence:

(3) Before rejecting, withdrawing or revoking a license, the competent authority shall hear the applicant and give him the opportunity to eliminate the reasons for the rejection, withdrawal or revocation.

Hearing Date:

§ 2: Costs

(1) The following public services shall be subject to charges (fees and expenditures):

1. issuance of a license for the operation of a certification authority,

2. rejection of an application for issuance of a license,

3. withdrawal or revocation of a license,

4. complete or partial rejection of an objection,

5. issuance of certificates,

6. review of check reports and confirmations pursuant to § 15 (1),

7. checks pursuant to § 15 (2), if such checks reveal a not solely insignificant violation of the Digital Signature Act or of this Ordinance,

8. taking over of documentation pursuant to § 11 (2) of the Digital Signature Act.

Fee Amount:

Expense Amount:

(2) The following hourly rates shall be used as a basis for calculating fees for public services pursuant to (1) Nos. 1, 5, 6, 7 and 8:

Intermediate Service Rate:

Higher Intermediate Service Rate:

Higher Service Rate:

(3) § 15 of the Administrative Expenses Act shall apply to cases in which an application for issuance of a license is rejected or withdrawn or in which a license is withdrawn or revoked.

Objection Rejected: Objection Withdrawn:

§ 3: Application procedure for issuance of certificates

(1) Pursuant to § 5 (1) Sentence 1 of the Digital Signature Act, the certification authority shall establish the identification of the applicant by means of the applicant's personal identity card or passport, or by other suitable means.

Identification Method:

The applicant must personally sign the application for a certificate in his own hand.

Applicant Signature Confirmed:

If an application for a certificate bears a digital signature of the applicant, the certification authority is not bound to require additional identification and a hand-written signature in the applicant's own hand.

Digital Signature Present:

(2) If representative authority is to be included in a certificate, such authority must be reliably proven, and consent of said third party must be provided.

Representative Authority Evidence:

§ 4: Notification of the applicant

(1) The certification authority shall notify applicants concerning the following necessary measures to ensure the security of digital signatures:

1. The data storage medium with the private signature key must be kept in the applicant's personal custody.

Private Key Stored Securely:

2. Personal identification numbers or other data used for identification must be kept secret.

Identification Data Kept Secret:

3. Technical components shall be used that fulfill the requirements and whose security has been confirmed.

Technical Components Confirmed:

4. If a certificate contains restrictions or information significant for validity, the certificate shall be included with the data and in the digital signature.

Restrictions Noted:

5. If a particular time can be of considerable significance, a time stamp shall be appended.

Time Stamp Required:

6. If data are required in signed form for a prolonged period, a digital signature shall again be appended.

Re-signing Required:

7. In verification of digital signatures, validity checks shall be performed as required.

Verification Checks Acknowledged:

(2) If an applicant already has a certificate, no further notification is required.

§ 5: Generation and storage of signature keys and identification data

(1) If the signature key holder generates signature keys, the certification authority shall reliably establish whether suitable technical components are used.

Suitable Technical Components in Use:

(2) If the certification authority provides signature keys, precautions shall prevent disclosure and storage of private keys by the certification authority.

Private Key Disclosure Prevented:

Identification Data Protection Provided:

§ 6: Handover of signature keys and identification data

If the certification authority provides signature keys or identification data, it shall hand over the private signature key and identification data to the signature key holder in person and obtain written confirmation.

Handover Date:

Written Confirmation Received:

§ 7: Validity period for certificates

The validity period for a certificate shall be no longer than five years.

Certificate Issue Date:

Certificate Expiry Date:

§ 8: Public register of certificates

(1) The certification authority shall keep certificates issued by it within a register.

Register Maintained:

(2) The competent authority shall keep certificates issued by it in a register for the duration of the period mentioned in (1).

Competent Authority Register Maintained:

(3) At the end of the period mentioned in (1), repeat verification of the certificates shall remain possible until the end of the period mentioned in § 13 (2).

Repeat Verification Available:

§ 9: Procedures for invalidation of certificates

(1) The certification authority shall provide a telephone number and authentication procedure for immediate invalidation.

Invalidation Hotline Number:

Authentication Procedure:

(2) The certification authority shall invalidate a certificate upon relevant application or agreed authentication procedure.

Invalidation Requested:

(3) Invalidation must be clearly indicated in the register and may not be rescinded.

Register Updated with Invalidation:

§ 10: Reliability of personnel

The certification authority shall reliably establish the reliability of persons involved in the certification procedure or in issuing time stamps.

Personnel Reliability Verified:

Good Conduct Certificate Required:

§ 11: Protection of technical components

The certification authority shall take precautions to protect private signature keys and technical components from unauthorized access.

Private Keys Protected:

Technical Components Protected:

§ 12: Security concept

(1) The security concept shall include all security measures and an overview of the technical components used and a description of the procedures used in certification.

Security Concept Summary:

(2) The competent authority shall keep a catalogue of suitable security measures and publish it in the Federal Gazette.

Suitable Security Measures Catalogue Reviewed:

§ 13: Documentation

(1) The documentation shall include the security concept, check reports, contractual agreements, and certificates received by the competent authority.

Documentation Prepared:

Records of Identity and Certificates:

(2) Documentation must be kept for at least 35 years from the time of issue of the signature key certificate.

Retention Period End Date:

§ 14: Cessation of operation

(1) If the certification authority wishes to terminate its operation, it must notify the competent authority at least four months in advance.

Termination Notice Date:

(2) Prior to cessation, the certification authority shall notify the relevant signature key holder and state whether another authority will assume the certificate.

Another Authority Assumes Certificates:

Assisting Authority Name:

(3) The notification shall be in digital form with a digital signature, or in writing.

Digital Notification Used:

(4) The authority assuming documentation or the competent authority shall keep the certificates in a register.

Documentation Assumed:

§ 15: Checks of the certification authorities

(1) Before beginning operation, following security-relevant changes and at regular two-year intervals, the certification authority shall arrange for checks and submit a relevant report.

Initial Check Completed:

Security-Relevant Change Check Completed:

Regular Interval Check Completed:

(2) The competent authority can carry out checks at appropriate intervals and whenever there are reasons to suspect violations.

Competent Authority Check Conducted:

§ 16: Requirements pertaining to technical components

(1) The technical components required for generation of signature keys must ensure uniqueness and secrecy of private keys.

Unique Key Assurance:

Private Key Secrecy Assured:

(2) The technical components required for generation or verification of digital signatures must prevent derivation or forgery.

Signature Forgery Prevention:

Biometrical Identification Supported:

(3) Technical components for display and verification of signed data must function properly and securely.

Display Components Verified:

Verification Components Verified:

(4) Technical components used to store certificates in verifiable form must allow only authorized entries and changes.

Authorized Access Only:

(5) Technical components used to generate time stamps must add the valid official time without distortion.

Accurate Time Stamping:

§ 17: Testing of technical components

(1) Testing of technical components must conform to the applicable criteria and test standard.

Test Standard:

Security Strength Rated High:

(2) The competent authority shall publish an overview of suitable algorithms and pertinent parameters.

Suitable Algorithm Name:

Suitability Valid Until:

(3) Confirmation of fulfillment of requirements must include the relevant requirements, usage environment, algorithms, parameters, and security standard.

Confirmation Details:

(4) The competent authority shall publish lists of agencies and technical components receiving confirmation.

Confirmation Published:

§ 18: New digital signature

If data is required in signed form for a period longer than the suitability period of algorithms and parameters, the data shall be given a new digital signature prior to expiration.

New Signature Required:

New Signature Date:

§ 19: Entry into force

This Ordinance enters into force on 1 November 1997.

Entry Into Force Date:

Authorized Signatory Name

Signature Date

Signature

Seal / Stamp

Enter text✕

What the Digital Signature Act represents in U.S. practice

The term Digital Signature Act on this page refers to the statutory and regulatory framework that makes electronic signatures admissible and enforceable in the United States. Federal law (ESIGN Act, 15 U.S.C. ch. 96) and state-level frameworks such as UETA establish four core legal requirements: intent to sign, consent to transact electronically, attribution of the signature, and reliable record retention. 'Digital signature' often denotes PKI-based cryptographic methods while 'electronic signature' is a broader legal category. Certain transactions remain exceptions and may require notarization, witness, or paper.

Why the Digital Signature Act matters for document reliability

Consistent application of ESIGN and UETA principles ensures signed records are legally admissible, reduces turnaround time, and preserves a clear audit trail. Properly executed electronic or digital signatures align authentication level with transaction risk and clarify obligations for retention and disclosure under U.S. law.

Why the Digital Signature Act matters for document reliability

Who commonly uses the Digital Signature Act framework

Professionals across regulated and transactional roles rely on e-signature rules to complete agreements, approvals, and disclosures efficiently.

  • Real estate brokers and agents managing leases, purchase agreements, and state disclosure forms.
  • Healthcare providers and clinics collecting patient authorizations and HIPAA-compliant consent forms online.
  • Banks and financial-services teams sending loan agreements, account authorizations, and payment-related disclosures.

Both small teams and large enterprises adopt electronic signing to reduce paper handling, keep audit records, and meet statutory retention and disclosure obligations.

Primary signers and responsible roles

Contract Administrator

Manages agreement templates, assigns signing order, and verifies party identity. Responsible for retention policy compliance and for ensuring each electronic signature event meets intent, attribution, and consent requirements under ESIGN/UETA.

Compliance Officer

Evaluates authentication strength and data handling. Ensures HIPAA, SOX, or industry-specific recordkeeping standards are met and coordinates any notary or witness requirements for regulated documents.

Security and compliance essentials to include

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Audit Trail: Timestamps, IP, and action log
Certifications: SOC 2 Type II and ISO 27001
HIPAA Support: BAA available where required
21 CFR Part 11: Controls for FDA-regulated records
Accessibility: WCAG 2.0 Level AA compliance

Key penalties and legal risks to avoid

1099 Penalties: $60–$330 per form (IRC §6721)
Intentional Disregard: $660+ per form, no cap
I-9 Violations: $281–$2,789 per violation (8 CFR §274a.2)
HIPAA Record Failures: Civil penalties and corrective action
Notarization Errors: May invalidate deed or POA
Retention Noncompliance: Regulator enforcement and fines

Common preparation errors to watch for

  • Mismatched signer names or incorrect TINs lead to backup withholding or rejected tax filings and may trigger penalties.
  • Failing to obtain consumer consent and deliver ESIGN disclosures for consumer-facing financial records can undermine enforceability.
  • Using weak signer authentication for high-risk transactions increases fraud risk and may not meet industry controls like 21 CFR Part 11.
  • Neglecting to capture a complete audit trail (timestamp, IP, action log) makes it harder to prove attribution in disputes.

Real-world examples of electronic signature use

Brief case summaries show typical workflows and outcomes when organizations use e-signature systems in regulated workflows.

Optica Ventures — COO

Optica moved lease and investor documents online to cut cycle time.

  • Their customers signed remotely with minimal friction.
  • The result: simpler customer experience and consistent audit trails used to resolve occasional signature attribution questions.

Fertility Centers of Illinois — Founder

The clinic digitized patient intake and consent forms for remote visits.

  • Staff used secure workflows and audit logs.
  • This reduced paper handling and preserved HIPAA-required records while keeping clear evidence of patient consent and signature timestamps.

Step-by-step: complete an electronically signed record

Follow these sequential steps to prepare, authenticate, sign, and archive an electronically signed document in line with ESIGN and UETA principles.

  • 01
    Upload Document: Import PDF or DOCX and confirm version control.
  • 02
    Place Fields: Add signature, date, and required data fields.
  • 03
    Select Auth: Choose email, SMS code, or stronger identity checks.
  • 04
    Sign and Archive: Capture audit trail and retain the signed copy.

Where to send or file signed records

Signed records can be routed to recipients, retained in cloud storage, or submitted to public record systems depending on the document type and jurisdiction.

  • Email to Signer: Deliver a secure signing link via email.
  • Cloud Archive: Store final PDF in approved cloud repository.
  • Public Filing: Submit deeds or records to county recorder when required.
  • API Submission: Use API to automate eSubmission to back-office systems.

Typical workflow configuration for electronic signing

Configure these settings to balance signer convenience and transaction security in routine e-signature workflows.

Field Configuration
Authentication Email link, SMS code, or multi-factor
Reminders Auto reminders and resend schedule
Validation Field-level format and required checks
Bulk Send Enable for high-volume distribution

Technical delivery and integration considerations

Consider integrations, file formats, and signer authentication to fit existing systems and compliance needs.

  • Integrations: Salesforce, NetSuite, Microsoft 365, Google Workspace
  • File Formats: PDF, DOCX, HTML, Excel
  • Advanced Auth: SMS code, KBA, SSO/SAML

Timelines and statutory retention or submission points

Observe statutory deadlines and retention requirements that affect how long you must keep signed records and when filings are due.

IRS Records:

Retain tax-related records at least 3 years (IRC §6501(a)).

I-9 Retention:

Keep I-9s 3 years after hire or 1 year after termination, whichever later (8 CFR §274a.2).

HIPAA Retention:

Retain privacy policy and related records 6 years (45 CFR §164.530(j)).

RON Recording:

Audio-video recordings typically retained 5–10 years per state rules.

Consumer Disclosures:

Provide ESIGN consumer disclosure and consent procedures before electronic transactions.

Key process milestones for an electronic signing engagement

A clear milestone sequence helps ensure legal validity, timely execution, and defensible retention of signed records.

01

Document Preparation

Finalize language, attachments, and required fields before sending.

02

Consent and Disclosure

Obtain ESIGN consumer consent where applicable.

03

Authentication and Signing

Authenticate signer and capture signature with audit trail.

04

Archival and Access

Store signed record and make retrieval procedures available.

Electronic signature versus cryptographic digital signature

Compare the legal and technical differences so you choose an appropriate method for each transaction and regulatory requirement.

Criteria Electronic Signature Digital Signature
Legal status broadly accepted subset with cryptographic proof
Technology varied methods pki and x.509 certificates
Non-repudiation audit trail based cryptographic non-repudiation
Typical use agreements, consents high-risk or regulated filings

Representative pricing and feature comparison for common e-signature providers

Pricing models and compliance capabilities differ across vendors; signNow is listed first for comparison. Verify plan details and HIPAA or enterprise features with each vendor before procurement.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently asked questions about the Digital Signature Act and e-signing

Answers to common legal and technical questions about electronic and digital signatures, authentication, notarization, and recordkeeping under U.S. law.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users