A digital signature can provide strong evidence that a document was signed by a particular person and has not changed since signing. It is not, however, a permanent guarantee on its own. Fraud, compromised credentials, misleading document presentation, weak validation and the loss of cryptographic evidence can all undermine a signed document.
The immediate question is whether the right person signed the right content. The long-term question is whether that can still be demonstrated years later.
The main risks behind digital signatures
| Risk | What can happen | Practical mitigation |
|---|---|---|
| Identity or credential misuse | Someone signs with stolen, shared or compromised credentials | Use strong identity verification, controlled signing processes and Qualified Electronic Signatures where the legal risk justifies them |
| Phishing and social engineering | A signer is tricked into approving the wrong document or transaction | Confirm the signing context, use trusted channels and make the document and intent clear before approval |
| Unauthorised signing | A person signs without the required authority or mandate | Verify roles, mandates and approval rules before the signing event |
| Document substitution or manipulation | The visible content differs from what the signer intended, or a PDF is manipulated after signing | Validate the signed file with trusted software and preserve the exact signed object, not a screenshot or reconstructed copy |
| Weak or incomplete validation | The signature appears present, but certificates, timestamps, revocation status or trust chains are not checked correctly | Perform complete validation at signing or ingest and retain the validation result and supporting evidence |
| Certificate revocation | A certificate is revoked after compromise or loss, making later verification harder | Capture reliable time and revocation evidence while it is available |
| Certificate or algorithm expiry | Certificates expire and cryptographic algorithms weaken over time | Apply long-term signature preservation and renew evidence before it becomes unreliable |
| Loss of context | The signed file remains, but information about who signed, why, when and under which process disappears | Preserve the document with provenance, metadata, audit events and the relevant business dossier |
Identity fraud, phishing and unauthorised signing
Digital signing moves trust into credentials, devices and signing workflows. If an attacker obtains access to a signing account, identity token or device, the resulting signature may look technically valid even though the action was fraudulent.
The same problem can arise without a technical breach. A signer may be misled about the content, purpose or consequences of a document, or a staff member may sign outside their authority. Strong authentication is essential, but it must be combined with clear signing intent, mandate checks and a process that shows what the signer approved.
Where legal value matters, a stronger signing method such as a Qualified Electronic Signature can reduce uncertainty about identity and provide the legal effect defined by eIDAS. It does not remove the need for process controls or long-term preservation.
Signed PDF manipulation and validation weaknesses
Security researchers have demonstrated attacks in which signed PDF files can display misleading or altered content while some viewers still present the signature as valid. These findings do not mean that every signed PDF is unsafe. They show that validation software, document structure and the exact file presented to the signer matter.
Organisations should:
- use maintained and trusted validation software;
- validate the complete signed file, not only the visible signature mark;
- reject unexpected changes or ambiguous validation results;
- preserve the exact signed object and its validation evidence;
- avoid converting, printing or rebuilding the file when the original evidence is required.
Research and threat references include the Shadow Attacks paper, the PDF signature validation vulnerability report, the PDF Certification paper and the CERT-EU threat memo on signed PDF manipulation.
Certificate revocation and missing evidence
A signer’s certificate can be revoked quickly if a key, card or account is compromised. A document signed shortly before revocation may still have been valid at the time of signing, but proving that later requires reliable time and revocation information.
If the archive retains only the PDF, a future verifier may no longer be able to obtain the certificate status or trust-chain information that existed when the signature was created. Validation should therefore take place while the required external evidence is available, and the relevant results should be preserved with the signed record.
Why signatures become difficult to verify over time
Certificates expire, algorithms are deprecated, trust anchors change and external validation services disappear. A signature that validates today may become difficult to verify years later if its supporting evidence is not maintained.
This is why long-term records require more than storage. A preservation process can retain validation material, apply trusted timestamps or evidence records and renew cryptographic evidence before the earlier protection becomes too weak.
The objective is not to change the original signed document. It is to maintain the evidence required to demonstrate its integrity, origin and validation status throughout the retention period.
Commission Implementing Regulation (EU) 2025/1946 identifies reference standards and specifications for qualified preservation services for Qualified Electronic Signatures and Qualified Electronic Seals. This is the specialised trust-service layer for maintaining signature and seal evidence beyond its original technological validity.
The role of Qualified Electronic Archiving
Qualified Electronic Archiving and signature preservation solve related but distinct problems.
Signature preservation focuses on keeping electronic signatures and seals verifiable beyond the technological lifetime of certificates and algorithms. Qualified Electronic Archiving governs the broader record, including ingest, metadata, integrity, retention, access, retrieval and controlled deletion.
Commission Implementing Regulation (EU) 2025/2532 requires providers of Qualified Electronic Archiving services to maintain the trustworthiness of qualified signatures and seals in archived documents beyond their technological validity period, at least until the end of the applicable preservation period. The provider may rely on a qualified preservation service for this purpose.
For important signed records, organisations should consider both layers: preserve the signature evidence and govern the full record throughout its lifecycle.
How to reduce digital signature risk
- Match the signing method to the legal and business risk.
- Verify identity, authority and signing intent.
- Present the complete document clearly before approval.
- Validate signatures, certificates, timestamps and revocation status.
- Preserve the exact signed file and its validation evidence.
- Maintain long-term verifiability before cryptographic evidence expires.
- Keep the record with its metadata, audit trail and retention context.
- Test future retrieval and validation instead of assuming that storage is enough.
Learn more about preserving digital signatures and electronic seals and how Qualified Electronic Archiving supports long-term evidence governance.