The vocabulary in this area is used loosely, including by people selling the products, so it is worth being exact before anything else. The exactness is not pedantry: the distinctions carry different legal effects, and choosing the wrong instrument is a mistake that only shows up when it is relied on.

A person signs, an organisation seals

Under eIDAS, an electronic signature is made by a natural person. An electronic seal is made by a legal person. That is the whole distinction, and it decides which instrument belongs on an invoice.

An invoice is issued by a company. It is not issued by whoever in accounts receivable happened to release the batch, and attaching that individual's identity to a hundred thousand documents asserts something nobody intended — that a named employee stands behind each one personally. When they leave, the assertion becomes awkward to explain.

So for invoicing the instrument is normally the seal. Signatures have their place, on documents where an individual genuinely is the author. Invoices are not among them.

What the tiers buy

There are three levels, and the difference between them is not the strength of the cryptography. It is the assurance about who holds the key and how carefully that was established.

The tiers, what they establish, and when the lower one stops being enough
TierWhat it establishesWhat it costs to runWhen it is not enough
Electronic signature or sealThat something was applied by someone; the identity assurance is whatever the parties arrangedLittle beyond the effort of applying itWhenever the identity behind it is what is in dispute, which is the only reason to have one
AdvancedUniquely linked to and capable of identifying the signatory, created with means under their sole control, and detecting subsequent changeKey management, certificate lifecycle, and a defensible enrolment processWhere a national rule specifically requires the qualified tier
QualifiedAdvanced, plus a qualified certificate from a provider on the trusted list, created by a qualified deviceThe above, plus the provider's fees and the constraints of qualified devicesWhere the counterparty or jurisdiction accepts nothing less, or where you need the legal presumption

The last row matters more than the first three. A seal establishes origin and detects alteration. It says nothing about whether the VAT treatment is right, whether the supply happened, or whether the figures agree with the contract. Those are exactly the things an assessment disputes. A business that seals diligently and cannot link its invoices to deliveries has bought evidence for the argument nobody was having.

A qualified certificate is qualified because a supervised provider issued it under a regime a Member State supervises, and because that provider appears on the published trusted list for the relevant service.

That is an administrative fact, not a technical one, and it has a practical consequence people miss: a certificate can be technically impeccable and still not qualified. The cryptography is identical. What differs is whether an authority stands behind the identity check that preceded issuance, and whether that standing is recorded somewhere a relying party can check independently.

When someone offers "eIDAS-compliant signing", the question to ask is which tier, from which provider, and whether that provider appears on the trusted list for that service in that Member State. The answer is public and takes a minute to verify.

What the digital identity framework changes

The framework introduced by the 2024 regulation extends the eIDAS structures towards wallets and attestations of attributes. For invoicing specifically, the immediate effect is limited: the tiers, the trusted list and the legal effects described here are the ones that apply to sealing an invoice today. It is worth knowing the direction of travel without rebuilding anything in anticipation of it.

The cost that arrives later

Adopting sealing is a project. Maintaining it is a permanent obligation, and the second is the one that is not in the business case.

Certificates expire, typically well inside a retention period measured in years. Providers change their offerings or leave the market. And the requirement is not that the seal was valid when applied — it is that authenticity and integrity are assured for the whole retention period, which means somebody has to be able to demonstrate validity long after the certificate has lapsed and possibly after the provider has gone.

That is a preservation problem, and preservation arrangements have to be established while the evidence is fresh. Retrofitting them to a five-year-old archive is either impossible or expensive, and the discovery is normally made by whoever inherited the archive from the person who set it up.

Sealing on the way out, verifying on the way in

Most implementations seal outbound documents carefully and verify inbound ones not at all. That asymmetry is backwards from a risk perspective. Your own outbound documents are corroborated by your own records. An inbound invoice supporting a deduction is corroborated by nothing except the document itself, and a seal you never check is decoration.

Where a mandate takes the choice away

The directive leaves the method to the taxable person. National mandates frequently do not, and the interaction is where planning goes wrong.

Where a mandate routes documents through a platform, the platform typically applies its own assurance and its records become the evidence for those transactions. That is a good outcome and it has a boundary: it covers what passes through the platform. Transactions outside the mandate's scope — cross-border supplies, categories not yet phased in, documents that are not invoices in the legal sense — are still yours to assure, and they are the ones that fall between two arrangements because each was designed assuming the other covered them. The Italian architecture is the longest-running example, and how the national format handles sealing and transmission is instructive about how much the platform does and does not take on.

The transmission side has its own evidence: what the platform accepted, when, and what it returned. Those receipts and notifications are a distinct and often stronger record than any seal, because they are produced by a third party with no interest in the transaction.

Choosing deliberately

The honest position is that sealing is one instrument among several, that it answers a narrow question well, and that it should be adopted where that question is live rather than as a default posture.

For most businesses the practical arrangement is: seal where a jurisdiction or a counterparty requires it; verify inbound seals where they arrive; and rely on a documented business control for everything else, because the control is what links the invoice to the supply and that link is what an assessment actually attacks.

That combination is unglamorous and it maps onto what the three properties actually require rather than onto what is easiest to buy. The alternative — sealing everything and documenting nothing — produces an organisation that can prove who sent an invoice and cannot prove anything happened afterwards.