Skip to main content
API Home Page - Desktop Site Logo
Blog

What is a digital signature? How it works and why it matters

August 23, 2026 8 min

What is a digital signature? How it works and why it matters

Most business professionals have used an electronic signature, but not everyone understands what a digital signature is or why the two differ. The distinction matters when a contract needs to hold up in court, cross a border, or meet a regulatory standard.

This guide explains what digital signatures are, how the technology works, and when your team needs one.

What is a digital signature?

A digital signature is a cryptographic mechanism that verifies the identity of the person who signed a document and that the document hasn't been altered since signing. It uses a mathematical algorithm called public key infrastructure, or PKI, to generate a unique encrypted fingerprint tied to the signer and the document at the moment of signing.

Think of it like a wax seal on a letter, but mathematical: it proves who sent it and whether anyone has opened it since.

Unlike a typed name or drawn e-signature, a digital signature doesn't just indicate agreement; it creates a verifiable, tamper-evident record that courts and regulators can rely on.

How does a digital signature work?

how does a digital signature work

Digital signatures use public key infrastructure (PKI),  a system built around two mathematically linked keys: a private key held only by the signer, and a public key shared with anyone who needs to verify the signature.

Here's what happens when a document is signed:

The signing software generates a hash, a fixed-length string that represents the document's exact content at that moment, down to the last character. The signer's private key encrypts that hash to produce the digital signature. That signature is then attached to the document.

When a recipient receives the signed document, their software uses the signer's public key to decrypt the hash. It also generates a fresh hash of the document as received. If the two hashes match, the document is authentic and unaltered. If they don't match, even by a single character, the signature is invalid.

A certificate authority (CA), a trusted third party such as DigiCert or GlobalSign, issues and validates digital certificates that link a signer's public key to their verified identity. This chain of trust is what gives a digital signature its legal and security weight. Without it, you'd have a key pair but no proof of who holds the private key.

Digital signature vs. electronic signature: what's the difference?

An electronic signature is any digital mark used to indicate agreement, such as a typed name, a drawn signature, or a checked box. It's legally valid in most jurisdictions for most document types, but it doesn't use cryptographic verification. There's no mathematical proof of who signed or whether the document was changed afterward.

A digital signature is a specific type of electronic signature that uses PKI cryptography to verify identity and document integrity. 

All digital signatures are electronic signatures, but not all electronic signatures are digital signatures.

For most business documents, like sales contracts, NDAs, and offer letters, a standard electronic signature is sufficient. The distinction becomes material in regulated industries where specific legal standards (eIDAS, 21 CFR Part 11) require a higher level of identity verification and tamper-evidence. In those contexts, a standard e-signature may not meet the requirement.

For a full breakdown of the two, see our digital signature vs. electronic signature comparison. If you're new to the category more broadly, our guide to types of electronic signatures explains where digital signatures sit within the full e-signature spectrum.

Are digital signatures legally binding?

Yes, in most jurisdictions, digital signatures are legally binding when they meet the applicable standard for that use case and region. Here are the frameworks that matter most for business use:

ESIGN Act (USA)

The Electronic Signatures in Global and National Commerce Act gives electronic signatures, including digital signatures, the same legal standing as handwritten signatures for most commercial transactions. See our ESIGN Act guide for the full breakdown.

UETA (USA)

The Uniform Electronic Transactions Act provides the same framework at the state level and has been adopted by 49 states. Our UETA Act guide covers what it means for your contracts. For more on how PandaDoc satisfies both, see how PandaDoc complies with UETA and the ESIGN Act.

eIDAS (EU)

The EU's Electronic Identification, Authentication and Trust Services regulation defines three tiers of electronic signature: simple (SES), advanced (AES), and qualified (QES). A qualified electronic signature (QES) uses digital signature technology with a certificate from an accredited Trust Service Provider. It carries the highest legal weight in the EU and is equivalent to a handwritten signature across all EU member states. eIDAS 2.0, which came into force in 2024, further strengthens the framework by introducing updated identity verification requirements.

21 CFR Part 11 (USA — life sciences)

FDA regulation requires electronic records and signatures in the pharmaceutical and biotech industries to meet specific controls; digital signatures with full audit trails are typically required for compliance.

PandaDoc is compliant with ESIGN, UETA, HIPAA, and SOC 2, and supports qualified electronic signatures (QES) meeting EU eIDAS standards. For a broader look at legal standing, see is an electronic signature legal?

Want to see PandaDoc’s eSignature and compliance features in action? Request a demo

When do you need a digital signature vs. a standard e-signature?

A standard electronic signature covers most business needs. For most sales contracts, NDAs, proposals, offer letters, and vendor agreements in the US, UK, and EU, a compliant e-signature is sufficient.

A digital signature or qualified electronic signature (QES) is required or strongly recommended in these situations.

Regulated industries

Healthcare documents subject to HIPAA or 21 CFR Part 11 require a higher verification standard. See our guides to HIPAA electronic signatures and HIPAA-compliant e-signature workflows. Financial services under SEC or FINRA rules, government contracts, and pharmaceutical trial documentation similarly require digital-grade verification.

EU cross-border contracts

Where the highest legal equivalence to a handwritten signature is required under eIDAS, particularly in jurisdictions where QES is the minimum standard, a basic eSignature won't satisfy the requirement. PandaDoc's QES support covers this directly.

High-value or high-risk agreements

Where tamper-evidence and a full cryptographic audit trail are material to enforceability. For example, with M&A agreements, real estate transactions, or multi-party enterprise contracts, a digital signature provides the verifiable record a standard e-signature can't.

Legal and notary documents

In some jurisdictions, wet ink or its cryptographic equivalent is required for certain document types. Check your jurisdiction's specific requirements before choosing an approach.

The practical test: check the regulatory requirements for your industry and jurisdiction. If you're an SMB in the US handling standard commercial contracts, a ESIGN/UETA-compliant e-signature is almost certainly sufficient. If you're in healthcare, pharma, EU cross-border work, or government procurement, verify the specific standard before selecting a tool. The advanced electronic signature (AES) sits between simple eSignatures and QES and may satisfy certain intermediate requirements.

What is a digital signature certificate?

A digital signature certificate is a digital document issued by a certificate authority (CA) that links a signer's public key to their verified identity. Think of it like a digital ID card. It proves that the public key in the certificate actually belongs to the person or organization it claims to represent.

A certificate contains the holder's name and organization, their public key, the issuing CA's identity, the certificate's validity period, and the CA's own digital signature confirming the certificate hasn't been tampered with. That final element, the CA's signature on the certificate, is what creates the chain of trust that makes digital signatures verifiable by anyone, not just the signing parties.

Certificate authorities are trusted third parties, organizations like DigiCert, GlobalSign, or national Trust Service Providers (TSPs) in the EU, that verify a signer's identity before issuing a certificate. In the EU eIDAS framework, accredited TSPs are the organizations authorized to issue qualified certificates for QES. PandaDoc partners with a trusted third-party CA to validate documents and offers its own identity verification options at the point of signing: passcode, SMS verification, ID check, or knowledge-based authentication (KBA). Certificates also create a trackable record, capturing each signer's name, IP address, and timestamps showing when a document was sent, viewed, and completed.

Learn more about using digital signature certificates with PandaDoc. 

Certificates expire and must be renewed. A document signed with an expired certificate may not be independently verifiable. Enterprise e-signature platforms handle certificate management automatically — signers don't need to manage key pairs or renewal cycles manually.

How to create a digital signature in PandaDoc

PandaDoc handles the cryptographic layer automatically. Users don't manage certificates, key pairs, or certificate authorities; the platform handles them in the background while users focus on getting documents signed.

Every document signed in PandaDoc receives a tamper-evident digital certificate and a full audit trail: who signed, when, from which IP address, in what order, and on which device. That record creates a verifiable signing event that withstands legal scrutiny.

For teams requiring qualified electronic signatures (QES) that meet EU eIDAS standards, PandaDoc partners with accredited Trust Service Providers (QTSPs), with built-in Identity Providers (IdPs), such as Okta or Azure AD, for real-time identity verification. QES signing follows a strict, sequential order, with each recipient verifying their identity before signing.

Before sending a document for signature, PandaDoc's pre-send checks automatically flag unassigned fields, missing recipients, and unfilled variables. PandaDoc's AI Assistant can help you find, summarize, and understand your documents. For multi-party documents, setting a signing order ensures each recipient receives and signs in the right sequence.

For developers building digital signature workflows into custom applications, PandaDoc's API supports programmatic document creation, recipient assignment, and signature collection. See the API documentation for technical details.

Take the guesswork out and ensure your eSignatures are secure and legally binding. Try PandaDoc today.

Frequently asked questions

  • A digital signature is a cryptographic mechanism that verifies a document's signer identity and confirms the document hasn't been altered since signing. It uses public key infrastructure (PKI) to generate a unique encrypted fingerprint tied to both the signer and the document, making it tamper-evident and independently verifiable by any recipient.

  • An electronic signature is any digital mark used to indicate agreement, a typed name, a drawn signature, or a checkbox. A digital signature is a specific type of electronic signature that uses PKI cryptography to verify identity and document integrity.

    All digital signatures are electronic signatures; not all electronic signatures are digital signatures. For the full comparison, see our digital signature vs. electronic signature guide.

  • Yes. Digital signatures are legally binding in most jurisdictions when they meet the applicable standards: ESIGN and UETA in the US, eIDAS in the EU, and sector-specific regulations such as 21 CFR Part 11 in the life sciences.

    In the EU, a qualified electronic signature (QES) carries the same legal weight as a handwritten signature across all member states. PandaDoc supports QES and complies with ESIGN, UETA, HIPAA, and SOC 2.

  • A digital signature certificate is a document issued by a certificate authority (CA) that links a signer's public key to their verified identity, serving as a digital ID card. It contains the holder's name, public key, the issuing CA's identity, and the validity period. The certificate enables recipients to independently verify a digital signature without trusting the signer directly.

  • A digital signature is not identical to a handwritten signature, but legally equivalent in many contexts. A handwritten signature attests to agreement through physical presence and writing style. A digital signature proves agreement cryptographically, through verified identity, a tamper-evident record, and an auditable signing event. Under the ESIGN Act and UETA in the US, and under eIDAS QES in the EU, digital signatures have the same legal standing as wet-ink signatures for the document types those frameworks cover.

  • A valid digital signature means three things: the signer's certificate was issued by a trusted certificate authority, the certificate was valid at the time of signing, and the document hasn't been altered since the signature was applied. Most e-signature platforms, including PandaDoc, provide a verification report or audit trail after signing that confirms each of these. If the document is tampered with after signing, signature verification will fail automatically.

Author

Anna Gallese - Avatar

Anna Gallese

Product Marketing Manager, eSign and Enablement

Anna Gallese is a Product Marketing Manager at PandaDoc, where she blends storytelling, strategy, and sales enablement to help revenue teams connect product value to real-world customer outcomes. With a background in enablement and a passion for simplifying the complex, Anna has built impactful programs that drive adoption, fuel growth, and empower teams to sell smarter. When she’s not crafting go-to-market strategies or collaborating on launch plans, you can find her exploring the outdoors with her doggy named Happy or traveling to new places just to taste their cuisine.

Reviewed by

Keith Rabkin - Avatar

Keith Rabkin

CEO of PandaDoc

Keith has been working in technology organizations for the past 15 years and is currently the Chief Executive Officer for PandaDoc. Prior to this, he had roles leading Growth for Adobe's Digital Media business, Gmail, YouTube, and Google Fiber.

Streamline your document workflow & close deals faster

Get personalized 1:1 demo with our product specialist.

  • Tailored to your needs

  • Answers all your questions

  • No commitment to buy

  1. 1Fill out the form
  2. 2Book a time slot
  3. 3Attend a demo

By submitting this form, I agree that the Terms of Service and Privacy Notice will govern the use of services I receive and personal data I provide respectively.

Chili Piper

ChiliPiper increased their close rate by 28% after implementing PandaDoc.