Are electronic signatures legally binding? Short answer: yes, in both the United States and the European Union, and they have been for over two decades.
The longer answer is that “electronic signature” covers everything from a typed name to a cryptographically bound certificate, and the differences matter when someone disputes one.
What follows is a general framework rather than legal advice. Regulated sectors and cross-border enforcement are worth a lawyer’s hour.
Electronic signature is not the same as digital signature
These get used interchangeably and they belong to different categories.
Electronic signature is a legal concept: any electronic data attached to a document that indicates intent to sign. A typed name, a drawn squiggle, a click on “I agree”.
Digital signature is a technical method: cryptography, usually public-key infrastructure, that binds a signature to a document and a verified identity so any later change breaks the seal.
A digital signature is one way to produce an electronic signature, and the most robust one. Every digital signature is an electronic signature; most electronic signatures are not digital signatures.
This distinction is what the EU framework is built on.
The United States: ESIGN and UETA
Two instruments, working together.
The ESIGN Act (2000) is federal and establishes that a signature, contract or record cannot be denied legal effect solely because it is electronic. UETA is the state-level counterpart, now adopted everywhere except New York, which runs its own equivalent statute instead.
The practical requirements are less about technology than about circumstance:
Intent to sign. The signer meant to sign. A name in an email footer is not a signature.
Consent to do business electronically. For consumer transactions this is explicit, and the consumer must be able to withdraw it.
Association with the record. The signature has to be logically connected to the document it signs.
Retention. The signed record has to be reproducible and retainable by everyone entitled to it.
Notice what is absent: no requirement for a particular technology, certificate or vendor. US law cares about intent and evidence, which is why the audit trail matters more than the signature image.
The European Union: eIDAS and its three tiers
The EU regulates the same question with more structure. eIDAS (Regulation 910/2014) defines three levels.
Simple electronic signature (SES). The broad category: a typed name, a click, a drawn mark. Admissible as evidence and cannot be rejected purely for being electronic. Its evidential weight depends on what else you can show.
Advanced electronic signature (AdES). Must be uniquely linked to the signer, capable of identifying them, created using data under their sole control, and linked to the document so later changes are detectable. Substantially stronger evidentially.
Qualified electronic signature (QES). An AdES created with a qualified signature-creation device and backed by a qualified certificate from a trust service provider on the EU trusted list. A QES has the same legal effect as a handwritten signature across every member state, and it reverses the burden of proof: the person disputing it has to prove it is invalid, rather than you proving it is valid.
Most commercial contracts do not need QES. It requires identity verification of the signer and costs meaningfully more. Standard B2B agreements are routinely signed at SES or AdES level and are enforceable.
The framework was updated by Regulation 2024/1183, which introduces the European Digital Identity Wallet. The three tiers remain the structure to reason about.
What actually decides a dispute
In practice, almost nobody argues that electronic signatures are invalid as a category. They argue about one of three things.
Who signed. Did the person at that email address have authority to bind the company? This is a delegation question, not a technology one, and it is why identity verification steps exist.
Whether it changed. Can you show the signed document is the one that was agreed? Any credible signing flow seals the document so alteration is detectable.
What they saw. Was the signer presented with the full terms before signing? A signature on a document nobody could read is weak.
The common thread is the audit trail: timestamps, IP addresses, the verification method, the sequence of events. A signature image proves almost nothing. The record around it proves everything.
There is a related habit that helps for the third point. If contracts are drafted from a maintained template rather than from a document copied per client, you can say what your standard terms were on a given date, which is a much better answer than reconstructing it from an attachment. Keeping the policies those terms refer to in guidelines serves the same purpose.
What still cannot be signed electronically
Both frameworks carve out exceptions, and they are narrower than people assume but real.
Under ESIGN the excluded categories are specific:
- Wills, codicils and testamentary trusts
- Family-law matters such as adoption, divorce and marriage settlements
- Court orders, notices and filings
- Certain provisions of the Uniform Commercial Code
- Notices terminating utility service
- Foreclosure or eviction notices on a primary residence
- Cancellation of health or life insurance benefits
- Product recalls, and documents accompanying hazardous materials
Worth correcting a common misconception: ordinary real-estate transactions are not excluded. Property contracts can be signed electronically. What is carved out are the consumer-protection notices around default and foreclosure, not the sale itself. Separately, anything a jurisdiction requires to be notarised or witnessed in person has its own rules.
These vary by country and by US state. The reliable rule is that ordinary commercial contracts are fine, and anything touching personal status, the courts or statutory notices needs checking locally.
What this means for how you send contracts
If you are signing standard B2B agreements, you do not need a qualified certificate. You need a flow that captures intent, seals the document and keeps the trail.
A few things follow. Send the document rather than emailing an attachment to be printed, because signing online is what produces the audit trail in the first place. Where several people must approve, route to each signer in order so the sequence itself is recorded. Keep the executed version somewhere citable rather than in a thread, and let clients retrieve their own copies instead of asking you.
This applies equally to changes. An amendment signed electronically is as enforceable as the original. And an amendment drafted but never countersigned is not in force at all, which is a far more common problem than any question about signature validity.
The same is true of the commitment behind recurring work: a retainer agreement is only worth what you can produce when the client asks in month nine what they are entitled to. For agencies running several of these at once, quote to cash covers how the documents connect end to end.
Where this sits in the wider chain
Signature is one link between a deal and the money. Upstream is the master service agreement and the statement of work that define what is being signed; downstream is the invoice and the payment, laid out in the contract-to-cash workflow.
One neighbouring question is worth not confusing with this one. A signed contract is a private document between two parties. An invoice, in much of the EU, has to be transmitted as a structured tax document through a network, which is what e-invoicing through ANAF and PEPPOL handles. Different obligation, different rules.
Enlivy runs contracts, signatures and the billing that follows on one record, sold as separate packs. You can start free.
If you are comparing signing tools specifically, the write-ups on PandaDoc, Dubsado and HoneyBook cover where each of them stops.