Providers - Certification levels & authentication options

Created by Lise LI, Modified on Fri, 5 Jun at 4:28 PM by Lise LI

This article covers two things for each provider: the eIDAS certification levels available per module, and the specific authentication options you can use to reach those levels. The right authentication method determines the legal weight of your signature — always choose it based on the sensitivity of the document.


⭐ Summary — Certification levels by provider and module

The table below shows which eIDAS levels are available for each provider, on each module.

ProviderCLM — SESCLM — AESBP/LEM/DR — SESBP/LEM/DR — AES
DocuSign
Adobe Sign
YouSign
Universign
Connective (Nitro Sign)
DropBox Sign / HelloSign
Signaturit
Box Sign

Need QES? Contact your Customer Success manager to discuss options.


⚡ Authentication options by provider

For each provider, the options below determine the eIDAS level of the signature. Only options available through DiliTrust's integration are listed — options marked ❌ are not currently supported.

⚠️ "Unconfirmed" means the eIDAS classification for this option has not been formally validated. Contact support if you need clarification.

DocuSign

DocuSign offers the widest range of authentication options, covering both SES and AES on CLM and BP/LEM/DR.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo ID proofing required
Standard Electronic Signature Advanced⚠️ Not eIDASSMS validation — signer authenticates via phone. Not eIDAS-compliant despite the name
EU Advanced with ID VerificationAES3 sub-options: Phone Authentication (SMS/call code, per-use fee), Knowledge-Based-Authentication (identity questions from public records — US only, per-use fee), ID Verification (government ID matched against envelope data)
DocuSign ID Verification for EU QualifiedQESRemote ID verification — results stored in signer's Identity Wallet
DS EU Qualified with in-person ID checkQESQualified signature with prior in-person ID verification
IDnow — EU QualifiedQESQualified signature with remote ID verification via IDnow
Signer Held EU QualifiedQESQualified signature using a digital certificate stored on a computer, smart card or USB drive

Adobe Sign

Through DiliTrust's integration, standard SES and AES Phone Authentication are available on both modules.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo verification required
Acrobat Sign AuthenticationSESSigner must log in with an Adobe account
OTP emailSESOne-time passcode sent to signer's email address
(2FA) PasswordSESSigner enters a password defined by the sender
(Advanced) Phone authenticationAES6-digit code delivered to recipient's phone
Knowledge-Based AuthenticationAESSigner answers personal questions from public records — mainly used in financial institutions
Government ID authentication⚠️ UnconfirmedSigner provides a government-issued photo ID and a selfie
Cloud-based digital signatures⚠️ UnconfirmedSigner authenticates via a third-party identity provider

YouSign

YouSign supports SES on both modules. AES (ID Verification) is not currently available through DiliTrust's integration.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo specific identification required
Standard with OTP AuthenticationSESOTP code sent to the signer for double identity check
ID VerificationAESSigner's ID automatically verified. Additional manual check if needed
Qualified SignatureQESMaximum security with facial verification in addition to ID check

Universign

Universign supports both SES and AES on CLM and BP/LEM/DR.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard SignatureSESOTP SMS authentication required
Advanced SignatureAESSigner must submit a valid identity document
Advanced Signature with Qualified CertificateQESFace-to-face identity verification by an authorized person required
Qualified SignatureQESQualified certificate issued through a certified IT system

Connective (Nitro Sign)

Connective supports SES on both modules. AES options are not currently available through DiliTrust's integration.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESAcceptance via scanned image, drawn signature, or "I accept" click
SMS OTP and Mail Access Code (2FA)SESSMS or email verification code sent to the signer
ID Verification + OTP (SES or AES)SES / AESEnhanced security with SSO and 2FA options
ID Verification + OIDCAESIdentity verification via OIDC methods
Remote Hash SigningQESQualified signature via remote hash signing
Smart cardsQESQualified signature via smart card

DropBox Sign (CLM) / HelloSign (BP/LEM/DR)

DropBox Sign and HelloSign are the same product — HelloSign was rebranded by Dropbox. SES is available on both modules. AES via eID is not currently supported.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo specific identification required
SMS authenticationSESSMS verification sent to the signer
eIDAES / QESIdentity verification via eID document for AES and QES signatures
NOM 151 certificateQESDigital certificate verifying document integrity under Mexican regulations

Signaturit

Signaturit supports SES and AES on both modules. Note that AES via ID Verification is only available on CLM.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo specific identification required
OTP verificationAESSMS verification sent to the signer
ID verificationAESAutomated real-time identity check with liveness detection
Biometric ID verification⚠️ UnconfirmedFingerprint, facial recognition or iris scan
Proof of liveness⚠️ UnconfirmedUser performs actions (blinking, head movement) to confirm active presence

Box Sign

Box Sign supports SES only. Standard Signature and SMS authentication are available on both modules.

OptioneIDAS levelDescriptionCLMBP/LEM/DR
Standard Electronic SignatureSESNo specific identification required
Box loginSESRecipient must log in to Box account before signing — Enterprise Plus and Advanced plans only
SMS authenticationSESBox sends an SMS to verify the recipient's identity
PasswordSESRecipient enters a sender-provided password before accessing the document
CAC/PIV⚠️ UnconfirmedAuthentication via Common Access Card (CAC) or PIV card on Windows with Box Tools

Related articles


If you have questions about which authentication option to use for your specific use case, contact your administrator or our support team.

The right authentication method ensures your signatures hold up legally — always match the option to the sensitivity of the document. ✨

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article