Skip to main content

Norms and standards

The legal provisions of ESigA and ESigO are designed to be technology-neutral. When using electronic signatures in practice, however, it is essential that signature services, validation systems, signatories, recipients of signed documents and software manufacturers can rely on certain technical characteristics. This is where norms and standards come into play. Standards relating to electronic signatures have been drawn up by various organisations, primarily the ISO (International Organisation for Standardisation), the ETSI (European Telecommunications Standards Institute) and the IETF (Internet Engineering Task Force [RFCs]).

The Swiss TAR (Technical and Administrative Regulations on Certification Services in the Field of Electronic Signatures and Other Applications of Digital Certificates) designates a number of standards as mandatory for certification service providers (CSPs) seeking accreditation. They cover aspects such as the format, issuing and management of regulated certificates and keys, security management and similar matters.

However, it does not specify any norms or standards regarding the format of the files to be signed or the technical design and implementation of electronic signatures. There are numerous other standards relating to this; to name but a few:

  • ISO 32000: Defines the PDF format.
  • ETSI EN 319 102: Defines generic procedures for the creation and validation of signatures and associated trust services, as well as timestamps and procedures for long-term validation.
  • ETSI EN 319 122 (CAdES): Defines CMS-based signature containers that can be saved as separate files or, depending on the file format of the signed file, embedded within the signed file.
  • ETSI EN 319 142 (PAdES): Defines signature formats and profiles for signing PDF files in particular, specifically the structure and embedding of electronic signatures, as well as time-stamping and long-term validation.
  • ETSI EN 319 132 (XAdES): Defines signature formats and profiles for XML files.

The relevant standards are modular in structure and coordinated with one another. There are also equivalents to ETSI standards in ISO standards, for example.

Even though the standards mentioned above and others are not expressly declared to be binding in various legal systems, there is nevertheless a general consensus that they should be regarded as authoritative and should be applied.

For example, in Switzerland and across Europe, it is widely accepted that, in practice, PDF files are almost always signed in accordance with the PAdES standard. One consequence of this is that, in practice, electronic signatures for PDF files are always embedded within the PDF document itself and are not generated as a separate file (although this would technically be possible under CAdES); as a result, common validators, including the Federal Validator, can only verify electronic signatures that are embedded within PDF files.

Standards on which the Validator is based

For the current Validator (version 2), the relevant ETSI standards and technical standards are of particular importance. Further standards, particularly those relevant to certification services, can be found on the website of the OFCOM.

ETSI TS 119 312 V1.4.1
Electronic Signatures and Infrastructures (ESI); Cryptographic Suites; 2021-08
[https://www.etsi.org/deliver/etsi_ts/119300_119399/119312/01.04.01_60/ts_119312v010401p.pdf]

ETSI EN 319 102-1 V1.3.1
Electronic Signatures and Infrastructures (ESI); Procedures for the Creation and Validation of AdES Digital Signatures; Part 1: Creation and Validation; November 2021
[https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/01.03.01_60/en_31910201v010301p.pdf]

ETSI EN 319 142-1 V1.1.1
 Electronic Signatures and Infrastructures (ESI);PAdES digital signatures; Part 1: Building blocks and PAdES baseline signatures; 2016-11
[https://www.etsi.org/deliver/etsi_en/319100_319199/31914201/01.01.01_60/en_31914201v010101p.pdf]

ETSI EN 319 412-1 V1.4.4
Electronic Signatures and Infrastructures (ESI); Certificate Profiles;Part 1: Overview and common data structures; 2021-05
[https://www.etsi.org/deliver/etsi_en/319400_319499/31941201/01.04.04_60/en_31941201v010404p.pdf]

ETSI EN 319 412-2 V2.2.1
Electronic Signatures and Infrastructures (ESI), Certificate Profiles, Part 2: Certificate profile for certificates issued to natural persons; 2020-07
[https://www.etsi.org/deliver/etsi_en/319400_319499/31941202/02.02.01_60/en_31941202v020201p.pdf]

ETSI EN 319 412-3 V1.2.1
Electronic Signatures and Infrastructures (ESI), Certificate Profiles, Part 3: Certificate profile for certificates issued to legal persons; 2020-07
[https://www.etsi.org/deliver/etsi_en/319400_319499/31941203/01.02.01_60/en_31941203v010201p.pdf]

ETSI EN 319 412-5 V2.3.1
Electronic Signatures and Infrastructures (ESI), Certificate Profiles Part 5 : QCStatements; 2020-04
[https://www.etsi.org/deliver/etsi_en/319400_319499/31941205/02.03.01_60/en_31941205v020301p.pdf]

ETSI EN 319 422 V1.1.1
Electronic Signatures and Infrastructures (ESI), Time-stamping protocol and time-stamp token profiles; 2016-03
[https://www.etsi.org/deliver/etsi_en/319400_319499/319422/01.01.01_60/en_319422v010101p.pdf]

ETSI TS 119 102-2 V1.3.1
Electronic Signatures and Infrastructures (ESI), Procedures for Creation and Validation of AdES Digital Signature, Part 2: Signature Validation Report; 2021-09
[https://www.etsi.org/deliver/etsi_ts/119100_119199/11910202/01.03.01_60/ts_11910202v010301p.pdf]

ETSI TS 119 441 V1.1.1
Electronic Signatures and Infrastructures (ESI); Policy requirements for TSP providing signature validation services; 2018-08
[https://www.etsi.org/deliver/etsi_ts/119400_119499/119442/01.01.01_60/ts_119442v010101p.pdf]

ETSI EN 319 142-2 V1.1.1
Electronic Signatures and Infrastructures (ESI); PAdES digital signatures; Part 2: Additional PAdES signatures profiles; 2016-04
[https://www.etsi.org/deliver/etsi_en/319100_319199/31914202/01.01.01_60/en_31914202v010101p.pdf]