eID ecosystem governance

Information System Authority (RIA) develops the vision and strategy for the field of eID and is the advocate for and the developer of positions in the field of eID in Estonia. RIA is responsible for the software components of eID aimed at developers and providers of e-services and provides support to developers.

Overview of the Estonian electronic identity ecosystem

This overview has been written to explain the makeup, organisation, and uses of the Estonian e-identity (eID) ecosystem. The overview is meant for readers seeking to learn about the components of the Estonian eID ecosystem, its operating principles and limitations, how the system works in practice, and which state authorities and private companies operate in this space.

The overview was written in summer 2025 and is based on the situation of the eID service market and legal acts in force at the time of writing. As new service providers, tools, etc. become available, some parts of the overview may become obsolete.

Some parts of the overview (Appendix C) are targeted to public sector institutions who are required to ensure the conformity and compatibility with the existing Estonian eID ecosystem (see the 2017 Authentication Requirements [1], Section 5) or need to explain their IT partners what compatibility means or how it can be effectuated.

Trust services

Service users and third parties make binding decisions on the basis of trust services. Therefore, the users of these services trust the information issued by the service provider.

Trust services are regulated by Regulation (EU) no. 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (the eIDAS regulation).

eIDAS establishes the requirements and conditions for all digital trust services and aspects of electronic identity and signature/stamping.

Trust services are provided by (qualified) trust service providers who correspond to the established requirements and have been registered in the list of trust service providers.

Trust service providers in Estonia are SK ID Solutions AS (eID and timestamping) and GuardTime AS (timestamping).

RIA mediates timestamping services to Estonia’s public sector institutions.

The European Union has the following trust services:

  • issuing and life cycle management of personal certificates
  • provision of timestamp services
  • creation of e-signatures
  • verification of e-signatures
  • storage of e-signatures
  • e-data exchange service
  • issuing certificates for web servers

eIDAS

The Council of the European Union and the European Parliament have adopted the eIDAS regulation (regulation for trust services necessary for electronic identification and electronic transactions) with the purpose of simplifying cross-border use of electronic services. This facilitates the achievement of a common digital market and a functioning digital economy. The regulation mainly addresses public electronic services.

The eIDAS regulation aims to create a level of trust in the digital world that would equal that of the physical world. To achieve that, common principles on the acknowledgment of electronic identity and digital signatures were established for European public institutions. The comparability, recognition, and common grounds for operation are also ensured for trust services.

Pursuant to the regulation, all Estonian state and local government institutions and private companies who provide public services must recognise digital signatures from all EU members as of 1 July 2016. Similarly, other public sector institutions of EU Member States must accept digital signatures provided by Estonian citizens. Digital signatures of EU citizens that are equal with nationally used digital signatures must be accepted. In May 2024, amendments to the Regulation entered into force, establishing the European Digital Identity Framework and creating the legal basis for the issuance of the European Digital Identity Wallet (EUDI Wallet).

For a private person to provide a digital signature accepted in Europe or to verify the validity of a digital signature on a document sent from another EU country, the person’s computer must have an up-to-date operation system and the newest DigiDoc client software.

E-identification schemes and their levels of assurance

Pursuant to the eIDAS Regulation, e-identification schemes in the European Union have three levels of assurance:

  • low
  • substantial
  • high

The following national e-identification schemes are in use in Estonia:

E-identification schemeLevel of assuranceAvailable fromRegion of use
ID cardHigh2018Estonia / European Union
Residence cardHigh2018Estonia / European Union
Digital IDHigh2018Estonia / European Union
E-Resident's digital IDHigh2018Estonia / European Union
Diplomatic ID cardHigh2018Estonia / European Union
Mobile-IDHigh2018Estonia / European Union
2022Estonia / European Union

In addition to the national e-identification schemes, there are also private schemes in use in Estonia, the level of assurance of which has been assessed by the Information System Authority as equivalent to the levels specified in the eIDAS Regulation.

The following private sector e-identification schemes have been assessed and are currently in use in Estonia:

E-identification schemeLevel of assuranceAvailable fromValid untilRegion of use
Smart-IDHigh202123.11.2027Estonia

Electronic signatures

Europe uses the term ‘electronic signature’ and divides the signatures into four levels of trust.

The highest of these, a signature equal with a handwritten-signature, is called a digital signature in Estonia.

States may also use electronic signatures with a lower level of trust. Electronic signatures with a lower level of trust may be, but need not be accepted. As a warning, the DigiDoc application marks signatures with a lower level of trust with yellow.

Trust levels of electronic signatures

Qualified electronic signature (QES) – equal with a handwritten signature. This advanced signature is based on qualified certificates and has been provided with qualified means of signing. A qualified certificate guarantees that the identity of a natural person was established during the issuing of the certificate. Qualified means of signature operate as guarantees that the data used for creating the signature (the private key) is strictly under the sole control of the signatory.

Advanced electronic signature with qualified certificates (AdES/QC) – advanced electronic signature that is based on qualified certificates, but does not use qualified means for providing signatures. This means that the data for providing signatures (the private key) may be installed in the user’s computer, for example. At the same time, the key may be located on a smart card, but the means and its creation/sharing has not been audited or certified (it has no guarantee).

Advanced electronic signature (AdES) – corresponds to the following minimum criteria:

  • the signature is only connected to the signatory;
  • the signature allows to identify the signatory;
  • the signature has been created with data necessary for signing and its high level of confidentiality secures that the data is under the sole control of the signatory;
  • the signature is connected with the data of the signatory in a way that allows identifying all later changes in data.

Other electronic signatures are any other solutions that do not comply with the abovementioned requirements. These may be service-based signatures (e.g. EchoSign supported by Adobe Acrobat Reader) as well as signatures drawn by hand /with a stylus on touchscreens.

Verification of electronic signatures

Upon the opening of an electronically signed document, the DigiDoc software checks whether the certificate used for signing has been issued by a trusted establishment.

The software will then notify if the electronic signature is equal with a handwritten signature. If the electronic signature is not equal with a handwritten signature, then it may be accepted for operations that do not require a handwritten signature (but in this case, it should be deliberated whether an electronic signature is necessary at all).

Electronically signed documents may have different file formats. Currently, the most widespread electronically signed document format is PDF and the signature format with the extension .asice.

The DigiDoc software enables users to create digital signatures in the ASiC-E format, which is recognised throughout Europe and has the same legal effect as a handwritten signature across the European Union.

Previously, the BDOC format was used for national digital signatures in Estonia. DigiDoc software continues to support opening .bdoc files and adding additional signatures to them. However, when a new document is signed for the first time, it is automatically created with the .asice file extension.

Private sector establishments decide on their own whether and at which security level to accept electronic signatures. It is recommended to update the information systems that process digital signatures. Only this allows to guarantee that signatures provided in Estonia in the .asice format qualify in the solutions of other countries and vice versa.

Last updated: 21.07.2026

search block image