Electronic signature vs digital signature: what's the difference?
Updated
Short answer
An electronic signature is any electronic way to show you agree to a document, such as typing your name, drawing a signature or clicking a button. A digital signature is a specific technology: a cryptographic seal based on a certificate that shows which certificate signed and whether the document changed afterwards. For most business contracts an electronic signature with a solid audit trail is enough.
The short version: a legal concept and a technology
Electronic signature is the broad, legal term. The US ESIGN Act defines it as an electronic sound, symbol or process attached to or logically associated with a record and adopted by a person with the intent to sign. The EU eIDAS Regulation uses a similar definition: data in electronic form that the signer uses to sign. A typed name, a signature drawn on a screen and an "I agree" button can all qualify.
Digital signature is a technical term. Signing software uses a private key that belongs to a digital certificate to create a cryptographic signature over the document. Anyone can check that signature with the matching public key: it shows which certificate signed and whether the document has changed since. The system of keys, certificates and certification authorities behind this is called public key infrastructure (PKI).
So the two are not opposites. A digital signature is one way to create an electronic signature.
Electronic and digital signatures side by side
- What it is: an electronic signature is a way to show agreement; a digital signature is a way to seal data with a certificate.
- Examples: a typed name, a drawn signature, a checkbox or a signing link versus a certificate-based signature embedded in a PDF.
- What it proves on its own: a typed name or a signature image proves little by itself, so its value depends on the evidence recorded around it, such as verification and an audit trail; a digital signature proves that the document is unchanged and which certificate signed it.
- Identity: a digital signature identifies a certificate, not automatically a person. How well the person behind it was checked depends on the certification authority that issued the certificate.
- Legal status: both count as electronic signatures in law. Neither is automatically invalid, and neither automatically wins in court.
Where SES, AES and QES fit in
The EU divides electronic signatures into three levels. Many other countries use similar ideas, even if the names differ.
- Simple electronic signature (SES): any electronic signature. Used for most business documents; its weight depends on the evidence you keep.
- Advanced electronic signature (AES): uniquely linked to the signer and capable of identifying them, created with data under the signer's sole control, and linked to the document so that any later change is detectable. In practice this usually means a digital signature with a verified identity.
- Qualified electronic signature (QES): an advanced signature created with a qualified signature creation device and based on a qualified certificate from a qualified trust service provider. In the EU it has the same legal effect as a handwritten signature.
Which one do you need?
For quotes, sales and service contracts, NDAs, employment contracts and most other business agreements, an electronic signature with a strong audit trail is the common choice. That is what e-signature platforms such as DocuSign, Adobe Acrobat Sign and BuiltSign are mostly used for.
You need more when the law or the other party asks for it, for example a qualified signature for certain filings in the EU or a certificate-based signature that an authority prescribes. Some documents, such as wills and property transfers in many countries, still need ink, witnesses or a notary. Read are electronic signatures legally binding for an overview per country.
How BuiltSign handles this
BuiltSign creates simple electronic signatures (SES). For every completed signing it creates an audit certificate that records who received the link, how each signer was verified, the times in UTC, the IP address and device, and SHA-256 hashes of both the original upload and the final signed PDF. For the hash of the signed PDF, BuiltSign requests an RFC 3161 timestamp from DigiCert, an independent timestamp authority, as outside proof of when that exact file existed. At builtsign.com/verify anyone can drop a signed PDF: the browser calculates its hash and checks whether it matches a document signed through BuiltSign, and if so shows who signed and when. With SES+ the signer first has their ID document and a selfie checked.
SES+ is BuiltSign's name for a simple electronic signature with an extra ID check. It is not a separate legal level under eIDAS, and an ID check alone does not make a signature advanced (AES), because AES has more requirements. BuiltSign does not offer qualified electronic signatures (QES) either. If a document legally requires an AES or QES, use a provider that offers it. This article is general information, not legal advice.
Frequently asked questions
- Not automatically. Both count as electronic signatures. A digital signature gives stronger technical proof that the document is unchanged, and in the EU a qualified signature has the strongest legal status. For most contracts the evidence around the signature matters more than the label.
- Yes, if the person typed it with the intent to sign. On its own it is weak evidence, because it does not show who typed it. That is why signing platforms add email or SMS verification, timestamps and a document hash.
- No. A scan is an image of a handwritten signature. It contains no certificate and does not show whether the document changed after signing.

