Skip to content

What makes an electronic signature valid

Athenty signs documents on its own authority. It operates its own root certificate authority, permanently, and issues a certificate to each individual signer — so a signature says “signed by Jane Smith using Athenty,” not “sealed by Athenty Technology Inc.” Athenty is not a member of Adobe’s Approved Trust List and is not applying to become one; that is settled architecture, not a pending application.

That design raises a fair question from anyone relying on one of these documents: if the signature isn’t backed by a household certificate authority, is it legally valid?

It is — and the reason is more interesting than a yes. The statutes that govern electronic signatures in Canada and the United States are deliberately technology-neutral. They do not require public-key cryptography. They do not require a certificate. They do not require a timestamp. What they require is narrow, and what they reward is reliability.

This page covers the jurisdictions Athenty’s customers most commonly work in. It is not an exhaustive account of the world’s electronic-signature law, and it does not assume your document is governed by any one of them — find the jurisdiction that governs your document first, then read its row.

So this page separates two things, because they are different kinds of thing:

  • Tier 1 — what the law actually requires. A short list, with a statutory hook you can read for yourself in each jurisdiction covered here.
  • Tier 2 — what makes a signature hold up when it is challenged. Not legal requirements. Reliability and evidentiary practice — the things that decide whether you can prove a signature when someone disputes it years later.

Read Tier 2 as a warning against the opposite mistake. Because a certificate is not legally mandatory in most of the jurisdictions on this page, it is tempting to conclude the cryptography is decorative. It is not. The governing legal test for a contested signature is reliability, and reliability is exactly what Tier 2 buys.


First: which statute actually governs your document

Section titled “First: which statute actually governs your document”

Jurisdiction is the first question, not the last one. Getting it wrong is the most common error in vendor marketing on this subject — including, until this page, some of our own.

If the document is…The statute that does the workNote
A private commercial document under Ontario law — a retainer, a closing document, an authorisation, a consentOntario Electronic Commerce Act, 2000The general provincial e-commerce statute. It covers ordinary private commercial instruments between parties, not dealings with the federal government.
A document where a federal law contemplates the use of paper, and that federal law is listed in Schedule 2 or 3PIPEDA Part 2 (ss. 31–51) and the Secure Electronic Signature Regulations, SOR/2005-30Narrow and federal-government-facing. See the PIPEDA correction — this is not the law for a private contract.
A document under Québec lawCivil Code of Québec art. 2827 and the Act to establish a legal framework for information technology (LCCJTI)A distinct civil-law regime with a genuinely different rule on integrity.
A United States transactionESIGN (federal) together with the state’s UETA enactmentUETA is enacted in almost every US state, plus the District of Columbia and US territories. New York is the sole holdout, and runs its own statute, ESRA.

PIPEDA Part 2 is frequently cited — including in Athenty’s own earlier material — as though it governs the validity of electronic signatures generally. It does not.

  • The correction is one of scope, not section numbering. Part 2 is ss. 31–51 — Electronic Documents — and Part 3, which amends the Canada Evidence Act, begins at s. 52. The range is not the point; s. 32 is.
  • s. 32 confines Part 2 to circumstances “where federal laws contemplate the use of paper.”
  • ss. 41, 43 and 47 bite only where the federal law in question is listed in Schedule 2 or Schedule 3.

For a private retainer, a closing document, or a client authorisation governed by Ontario law, PIPEDA Part 2 and SOR/2005-30 are not the operative law — Ontario’s Electronic Commerce Act, 2000 is. We do not lead on PIPEDA, and we do not lead on any one country’s law either: the statute that governs is the one that governs your document, in your jurisdiction.

SOR/2005-30 is nonetheless worth knowing, for one reason given in Tier 2: it is the only instrument in any of these four jurisdictions that actually prescribes public-key cryptography. It remains in force (current to 2026-06-17, last amended 2011-03-10). It is not repealed.


Three items. The first two are conditions of a valid signature. The third is not a validity condition anywhere — it is how you prove the first two, and it is labelled accordingly.

The mark has to have been made in order to sign. This is the one criterion with a strong, uniform statutory hook in all four jurisdictions, and it is the closest thing to a universal rule in this area.

  • Ontario — ECA, 2000, s. 1: an “electronic signature” is electronic information a person creates or adopts in order to sign a document, and that is in, attached to, or associated with the document.
  • United States (federal) — ESIGN §7006(5): an electronic sound, symbol or process attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record.
  • United States (states) — UETA §2(8): the same definition, which is why the rule is uniform across the UETA states.
  • Québec — CCQ art. 2827: a signature is the affixing by a person, to a writing, of a name or a mark distinctive to that person which they regularly use, to signify that person’s consent. Note the difference from the ESIGN and UETA formulation above — Québec’s in-force text says consent, not intention, and has since the 2016 amendment (2016, c. 4, s. 328). LCCJTI art. 39 carries that into technology-neutral form: a signature may be affixed to a technology-based document by any process that allows the person’s identity to be confirmed and the link between the person and the document to be established.

What Athenty does about it. A signer is presented with the document and takes a deliberate, attributed act to sign it. Nothing is signed as a side-effect of opening or viewing.

Nobody can be forced to transact electronically. This one has a real statutory hook too, but it is narrower and more nuanced than the marketing usually suggests.

  • Ontario — ECA, 2000, s. 3: nothing in the Act requires a person to use or accept information in electronic form without their consent — but consent may be inferred from the person’s conduct. Inferable consent is the practical rule; it is not a demand for a signed opt-in form.
  • United States (states) — UETA §5(b): the Act applies only between parties that have each agreed to conduct transactions electronically, and that agreement is determined from the context and surrounding circumstances, including the parties’ conduct.
  • Québec — LCCJTI art. 29: the free-choice-of-medium principle — a person may not be required to acquire a specific technology in order to transact.

What Athenty does about it. Consent is captured and persisted per signer — see What Athenty actually implements, which records exactly what is and is not shipped.

3. Audit trail — an evidentiary requirement, not a validity requirement

Section titled “3. Audit trail — an evidentiary requirement, not a validity requirement”

This is the limb people mislabel most often. An audit trail is not a condition of a valid signature in any of these four jurisdictions. No statute below says a signature is invalid without one.

What an audit trail does is discharge evidentiary burdens — the burden that arrives the day someone disputes the document, which is the only day any of this matters:

  • Canada (federal) — Canada Evidence Act, ss. 31.1–31.5: authentication of electronic documents, and satisfaction of the best-evidence rule by proving the integrity of the electronic documents system in which the record was recorded or stored.
  • Ontario — Evidence Act, s. 34.1(5): a record-integrity test — the best evidence rule is satisfied on proof of the integrity of the electronic record, and s. 34.1(5.1) makes integrity of the records system, or evidence that reliable encryption techniques were used, a permitted route of proof rather than the test itself. The system-integrity framing is the federal provision’s — CEA s. 31.2(1)(a).
  • Québec — LCCJTI arts. 6–7: integrity of the document, and the allocation of who must prove what about it.
  • United States — UETA §9(a): an electronic record or signature is attributable to a person if it was that person’s act, and the act may be shown in any manner — including by showing the efficacy of any security procedure applied.

So: no statute requires the audit trail. Every evidence statute makes you grateful you have one.


Tier 2 — What makes a signature hold up when it is challenged

Section titled “Tier 2 — What makes a signature hold up when it is challenged”

Everything in this section is reliability and evidentiary practice. None of it is a legal requirement, with the two narrow exceptions flagged in place (federal SOR/2005-30 documents; Québec integrity).

That framing cuts both ways, and both halves matter:

  • A PKI certificate is not legally mandatory in Ontario, Québec or the United States. Anyone who tells you a signature is invalid without one is describing a product, not the law.
  • Items 4–7 are not optional in any practical sense. The legal test for a contested signature is reliability, and these four are how reliability is demonstrated rather than asserted.

The governing test is reliability, not any particular technology

Section titled “The governing test is reliability, not any particular technology”

Three of these four express the same idea. The federal instrument is the outlier — it prescribes a technology rather than stating a test:

JurisdictionThe testWhere it lives
Ontario”reliable”ECA, 2000, s. 11(3) — see the caveat immediately below
Canada (federal)the outlier — no reliability test for a signature: the “secure and reliable manner” in s. 4 is what the President of the Treasury Board must verify before recognising a certification authority. The instrument prescribes a specific technology (s. 2) instead of stating a reliability test.SOR/2005-30, ss. 2 and 4
United Statesthe “efficacy of any security procedure” appliedUETA §9(a)
Québecthe link between signer and document maintained “au moment de la signature et depuis” — at the moment of signature and sinceLCCJTI art. 39

4. Cryptographic match — reliability practice

Section titled “4. Cryptographic match — reliability practice”

The signature verifies mathematically against the signer’s public key.

  • Statutory status: a hook exists in exactly one place — SOR/2005-30, s. 2, and only for federal-government-facing documents. There is no such requirement in Ontario, Québec or the United States.
  • What Athenty does: each signature is a cryptographic signature over the document’s signed byte range, made with a private key whose certificate was issued by Athenty’s own CA to that named signer — not to the organisation. Per-signer attribution is the property the whole architecture exists to protect.
  • How a relying party checks it: open the document in Adobe Acrobat Reader and inspect the signature properties. Every claim in this section is meant to be verifiable by the person relying on the document, not taken on our word. The one-time trust install is covered by Verifying Athenty-Signed PDFs.
Section titled “5. Document integrity — a legal requirement in Québec only; evidentiary practice elsewhere”

The bytes have not changed since signing.

  • Statutory status: this is a validity condition only in Québec — LCCJTI arts. 5, 6 and 39 tie the legal value of a technology-based document to the maintenance of its integrity. Everywhere else it is evidence law, not signature law: an altered document does not become an invalid signature, it becomes an unprovable one.
  • What Athenty does: the signature covers the document byte range. Any modification after signing breaks verification, and a viewer that validates signatures will say so rather than silently accept the change.

6. Valid certificate — reliability practice

Section titled “6. Valid certificate — reliability practice”

The signer’s certificate was in force, and not revoked, at the moment of signing.

  • Statutory status: SOR/2005-30, s. 2(e)(iv) requires verification that the certificate is valid in accordance with s. 3, and s. 3(1)(b) makes that turn on the certificate not having expired or been revoked at the time the document is signed — federally, and only for documents in that narrow scope. Québec’s arts. 40 and 47 are permissive, not mandatory: a certificate “peut servir à établir” — may serve to establish — identity or the attributes of a person. That is an offer of a method, not a requirement to use it. There is no certificate requirement in Ontario or the United States.
  • What Athenty does: leaf certificates carry a CRL distribution point — when the CRL URL is configured. That conditional is deliberate and is part of the claim; see What Athenty actually implements.

7. Timestamping — reliability practice, with no statutory hook at all

Section titled “7. Timestamping — reliability practice, with no statutory hook at all”

Independent proof of when the signature was made.

  • Statutory status: none. There is no statutory hook for trusted timestamping in any of the four jurisdictions on this page. Nothing in Ontario’s ECA, PIPEDA Part 2, SOR/2005-30, the LCCJTI, ESIGN or UETA requires a trusted timestamp. It is included here because a signature whose time rests solely on the signer’s own clock is weaker to defend, not because a statute demands it.
  • What Athenty does: RFC-3161 timestamping is on by default, and timestamp failures are recorded rather than silently dropped — a recorded failure is what lets you tell the difference between a timestamp that is absent and one that never existed.

Documents that cannot be signed electronically

Section titled “Documents that cannot be signed electronically”

Both directions of the exclusion list matter to a practice doing estates and real estate, which is to say: to most of our users.

The Act does not apply to the documents listed in s. 31(1):

  • wills and codicils;
  • trusts created by wills or codicils;
  • powers of attorney, to the extent that they are in respect of an individual’s financial affairs or personal care;
  • negotiable instruments;
  • documents that are prescribed or belong to a prescribed class — no such regulation has been confirmed to exist; see Citations still being confirmed.

Documents of title sit in their own subsection: s. 31(2) puts them outside the Act except for s. 23, contracts for the carriage of goods.

§7003(a) — §7001 does not apply to a contract or other record to the extent it is governed by:

  • a rule of law governing the creation and execution of wills, codicils or testamentary trusts;
  • a state rule of law governing adoption, divorce, or other matters of family law;
  • the Uniform Commercial Code, as in effect in any State, “other than sections 1-107 and 1-206 and Articles 2 and 2A” — so Articles 2 (sales) and 2A (leases) remain within ESIGN (those two section numbers are pre-2001 Article 1 numbering Congress never updated — 1-107 is now 1-306, and 1-206 was repealed).

§7003(b) — §7001 also does not apply to:

  • court orders or notices, and official court documents — briefs, pleadings and other writings — required to be executed in connection with court proceedings;
  • notices of the cancellation or termination of utility services (including water, heat and power); of default, acceleration, repossession, foreclosure or eviction, or the right to cure, under a credit agreement secured by — or a rental agreement for — an individual’s primary residence; of the cancellation or termination of health insurance or benefits, or life insurance benefits (annuities excluded); and of the recall of a product, or a material failure of a product, that risks endangering health or safety;
  • any document required to accompany the transportation or handling of hazardous materials, pesticides, or other toxic or dangerous materials.

Neither list is a technical limitation. Athenty can render and sign any of these documents; the statute simply does not confer electronic-signature validity on them. Whether a particular instrument may be signed electronically is a decision for the responsible licensed professional, on the current law of the governing jurisdiction.


The Tier 2 claims above are claims about Athenty’s own code, not about the law. They are recorded here so they can be checked rather than assumed.

ClaimStatus
Consent captured per signerPersisted per signer.
Certificate revocation reachable by a relying partyLeaf certificates carry a CRL distribution point — when the CRL URL is configured. Where it is not configured, they do not.
Signing time independently attestedRFC-3161 timestamping is on by default, and failures are recorded.

Athenty publishes the verification status of its own citations rather than presenting every one of them as settled. The rows below are Suggested — verify: they are attorney-review-pending, and the linked authority — not this page — is what you should check before relying on one. Everything not listed here traces to the official text linked in Sources & authorities.

ItemVerified fromStatus
Québec — LCCJTI arts. 2, 5, 6, 7, 29, 39, 40, 47Annotated lccjti.ca, in French⚠️ Suggested — verify. The article numbers are pending confirmation against LégisQuébec, and the official English text has not yet replaced the French annotated source.
UETA §§2(8), 5(b), 9(a)Uniform text published by the Uniform Law Commission⚠️ Suggested — verify. The uniform text is linked below, but the operative text in any given matter is the enacting state’s own statute, which may differ from it.
The number of UETA enactments—⚠️ Suggested — verify. UETA is enacted in almost every US state, plus the District of Columbia and US territories; the exact count is not independently confirmed here.
New York — State Technology Law, art. 3 (ESRA)New York State Senate — consolidated lawsConfirmed. New York runs its own statute rather than a UETA enactment; the official text is linked below.
Ontario — ECA, 2000 s. 11(3) prescribed documents—⚠️ Suggested — verify. Whether any documents have in fact been prescribed by regulation is unconfirmed, and the s. 11(3) framing above depends on it.
UNCITRAL Model Law on Electronic Signatures (2001) — the source of the “appropriate in the circumstances” phrasingUNCITRAL — official page⚠️ Suggested — verify. The official page is linked below; the specific article carrying that phrasing is not confirmed here, and the point made above does not depend on it.

Every assertion on this page traces to a statute or regulation. Links go to official text or CanLII. Rows marked ⚠️ are Suggested — verify: the citation is attorney-review-pending, and you should read the linked authority before relying on it.

JurisdictionAuthorityUsed on this page forLink
OntarioElectronic Commerce Act, 2000, S.O. 2000, c. 17 — ss. 1, 3, 11(3), 31Intent (s. 1); consent (s. 3); reliability of prescribed documents (s. 11(3)); exclusions (s. 31)e-Laws — official text
OntarioEvidence Act, R.S.O. 1990, c. E.23 — s. 34.1Audit trail as evidentiary, not validitye-Laws — official text
CanadaCanada Evidence Act, R.S.C. 1985, c. C-5 — ss. 31.1–31.5Authentication and best-evidence for electronic documentsJustice Laws — official text
CanadaPIPEDA, S.C. 2000, c. 5 — Part 2, ss. 31–51 (esp. s. 32, and ss. 41, 43, 47 with Schedules 2 and 3)The scope limit: Part 2 applies where federal laws contemplate paperJustice Laws — official text
CanadaSecure Electronic Signature Regulations, SOR/2005-30 — ss. 2, 3, 4s. 2 prescribes the digital-signature process — the only PKI prescription in any of these jurisdictions; s. 3(1)(b) certificate validity and revocation tested at the time of signing; s. 4 recognition of a certification authority (“secure and reliable manner”)Justice Laws — official text
QuébecCivil Code of Québec, art. 2827Signature as a mark signifying consentLégisQuébec — official text
Québec ⚠️Act to establish a legal framework for information technology (LCCJTI), CQLR c. C-1.1 — arts. 2, 5, 6, 7, 29, 39, 40, 47Integrity as a validity condition; technology neutrality; signature; permissive certificatesLégisQuébec — official text · verified only against the French annotated lccjti.ca — article numbers pending confirmation against LégisQuébec
United StatesESIGN Act, 15 U.S.C. §7006(5)Intent to signUS Code — Office of the Law Revision Counsel
United StatesESIGN Act, 15 U.S.C. §7001(c)Consumer-disclosure consent only — not general contract formationUS Code — Office of the Law Revision Counsel
United StatesESIGN Act, 15 U.S.C. §7003ExclusionsUS Code — Office of the Law Revision Counsel
United States ⚠️UETA §§2(8), 5(b), 9(a) — enacted in almost every US state, plus the District of Columbia and US territoriesIntent; agreement inferable from conduct; attribution and efficacy of a security procedureUniform Law Commission — Electronic Transactions Act · the operative text in any given matter is the enacting state’s own statute
United StatesNew York — State Technology Law, art. 3 (ESRA), ss. 301–309 — the sole non-UETA jurisdictionWhy “UETA” is not a synonym for “US law”New York State Senate — official text
International ⚠️UNCITRAL Model Law on Electronic Signatures (2001)The lineage of the “appropriate in the circumstances” phrasing that ESIGN and UETA do not containUNCITRAL — official page · article carrying the phrasing not confirmed here