Penneo now supports QES (Qualified Electronic Signature) through MitID and MitID Erhverv. This article explains how MitID QES differs from regular MitID (AdES), what the signing process looks like, and how to configure it for your company.
MitID QES is available for both MitID Private and MitID Erhverv (business).
MitID QES vs. MitID AdES
From the signer's perspective, the main difference between the two signing methods lies in the identity verification step. The most important difference, however, is the legal validity of the signature: a QES is presumed to be valid — meaning the burden of proof is reversed in case of dispute — because the QES is issued following certified processes and components.
| Feature | Regular MitID (AdES) | MitID QES |
|---|---|---|
| Legal Validity | Valid electronic signature, but its validity must be demonstrated if challenged. | Presumed valid: the burden of proof is reversed, as the QES is issued following certified processes and components. |
| Identity Verification | Signer enters their MitID credentials. No CPR (social security number) is required from the signer during the flow. |
Signer enters their MitID credentials. Signers must manually enter their CPR number during the flow. |
| Penneo Backend | The signer's name is obtained from MitID. | The signer's name is obtained from the CPR register via MitID. |
| Signature Page | Shows the signer's name, role, certificate serial number, masked IP address, and signing time (UTC). No QES logo. | Shows the same signer details, plus a QES logo. Important: The signer's CPR number never appears on the signature page. |
| Signer Identifier (serialNumber) | Standard serialNumber display. | The serialNumber shown on the PDF signature page is a shortened representation The complete serialNumber is always included in the signing certificate embedded in the XML file attached to the finalized PDF. |
| Penneo Validator (CPR match) | The CPR match verification field is only available if the sender explicitly requested CPR validation before signing the document. | A field for CPR match verification is automatically available for all QES-signed documents. The sender can input the signer's CPR number into the Validator at any time to instantly check for a match. |
| Name and Address Protection (NAP) | If signing with a hidden name is allowed: a separate MitID identification with CPR entry is required. | If signing with a hidden name is allowed: no need for a second MitID identification. |
Signer's archive
When signers have access to a personal archive, they can save their documents to the same archive when using MitID AdES and MitID QES.
How to Enable MitID QES (For Administrators)
Company administrators can manage these settings from the Company Settings dashboard.
-
Enable signing methods individually: Administrators can enable Regular MitID and MitID QES independently, depending on the company's requirements.
-
Linked NAP settings: If both signing methods are enabled, enabling Name and Address Protection (NAP) for Regular MitID will automatically enable NAP for MitID QES as well.
- Flexible signing method selection: Once MitID QES has been enabled by an administrator, senders can choose the signing method for each individual signer. This option is available only when the case file is created through the Simple Casefile Creation interface or via the API. It is not available in the legacy Standard Casefile Creation workflow.