Ensuring the legal validity of electronic documents is critical for digital business. It is based on three principles: authenticity (author identification), integrity (immutability of content), and non-repudiation. In Ukraine, the primary regulatory acts in this area are Laws No. 2155-VIII and No. 851-IV, which equate an electronic document with mandatory requisites to a paper original.
Compatibility of Ukrainian KEP with European QES
EU Regulation No. 910/2014 (eIDAS) regulates cross-border electronic transactions. The highest level of trust is held by the Qualified Electronic Signature (QES). The Ukrainian KEP is technically aligned with its European counterpart, but there is no automatic recognition of Ukrainian signatures in the EU. Full compatibility requires bilateral agreements and verifying the presence of service providers on trust lists.
Long-term preservation and audit trail
Since key certificates have a limited validity period, a standard signature verification after a few years may fail to confirm its legitimacy. To address this issue, Long-Term Validation (LTV) formats are used, such as CAdES-X Long or PAdES-Long. They contain:
- A timestamp that records the exact time of signing;
- Certificate status data (OCSP responses or CRL lists) at the time of signing.
According to the international standard ISO 15489-1:2016, an essential security element is the Audit Trail. This is a secure log of all system events that records access history, timestamps, and certificate verification statuses, serving as key evidence in legal disputes.
Technical implementation in corporate systems
To build a reliable infrastructure, specialized content management platforms are used. For example, the Megapolis.DocNet and Scriptum.DMS systems, based on the UnityBase low-code framework, provide automatic certificate validation, support for long-term archives (LTV), and continuous event logging.
Depending on business needs, three types of signatures are used:
- Simple Electronic Signature (SES) — low level of trust, suitable for internal operations;
- Advanced Electronic Signature (AES) — medium level, for agreements by prior consent of the parties;
- Qualified Electronic Signature (QES/KEP) — high level, fully equivalent to a handwritten signature.
What this means for the market
The lack of automatic recognition of Ukrainian electronic signatures in the EU limits seamless cross-border digital transactions for Ukrainian businesses. Furthermore, failing to implement long-term validation (LTV) standards poses a significant risk of losing the legal validity of archived electronic contracts once key certificates expire, potentially leading to legal disputes and compliance failures.
What to do next
- Adopt LTV formats: Use CAdES-X Long or PAdES-Long formats to embed timestamps and certificate status data, ensuring documents remain legally valid long after certificates expire.
- Deploy compliant DMS platforms: Implement document management systems like Megapolis.DocNet or Scriptum.DMS that support automatic validation, LTV archives, and secure audit trails.
- Match signature types to risks: Use Simple (SES) for internal tasks, Advanced (AES) for agreed-upon bilateral contracts, and Qualified (QES/KEP) for high-stakes transactions requiring maximum legal equivalence to paper.
Prepared by a Software Ukraine member. Original publication.