Certificate fraud is rising. Here is how to make your certificates verifiable.
Legal

Certificate fraud is rising. Here is how to make your certificates verifiable.

Anyone can copy a PDF certificate in minutes. If your organisation issues qualifications, the question is no longer whether someone will forge one, but whether a third party can tell. Here is how verifiable certificates work.

S
Swiss Trust Layer Editorial Team· Certificate Integrity
·July 27, 2026· 8 min read

An organisation that issues certificates has a problem it usually does not see until someone else finds it. The certificate leaves the building as a PDF, and from that moment the issuer has no control over what happens to it. It can be edited, duplicated, backdated, or invented outright by someone who never attended anything.

The awkward part is not that forgery is possible. It is that the person receiving the certificate, an employer, a regulator, a client, usually has no way to check. They look at a logo, a signature image, and a date, and they decide whether it feels genuine. That is not verification. It is an impression.

Why a PDF certificate proves very little

A standard PDF certificate carries no evidence of its own origin. The visual elements that make it look official, the seal graphic, the scanned signature, the reference number, are all just pixels. Any of them can be reproduced by someone with basic design software and an afternoon.

Three specific weaknesses follow from that:

  • The content can be altered. A name, a grade, or a completion date can be changed without leaving a trace in the file.
  • The date can be moved. Nothing in an ordinary PDF establishes when it was actually created, so a certificate can appear older or newer than it is.
  • The issuer cannot be confirmed. There is no cryptographic link back to the organisation that supposedly issued it.

Registry lookups help, but only partly. They require the verifier to know your registry exists, to find it, and to trust it. They also break when the issuing organisation restructures, changes systems, or stops maintaining the lookup page.

What makes a certificate verifiable

A verifiable certificate carries its own proof. Instead of asking the recipient to trust the appearance of the document, it lets any third party confirm three things independently, without contacting the issuer at all.

Integrity. A cryptographic hash of the certificate is created at issuance. If a single character changes afterwards, the hash no longer matches and verification fails. This is what turns tampering from something invisible into something detectable.

Time. A qualified timestamp records when the certificate existed, issued by an accredited timestamp authority rather than by the issuer. Under eIDAS Regulation (EU) No 910/2014, a qualified timestamp carries a legal presumption as to the accuracy of the date and time it records. That presumption is the difference between claiming a date and being able to rely on it.

Origin. A qualified electronic seal binds the certificate to the issuing organisation itself rather than to an individual employee. Seals are the organisational counterpart to signatures, and they survive staff changes, which matters for a body that issues certificates for decades.

The legal weight behind it

In Switzerland, electronic signatures and seals are governed by ZertES (SR 943.03), which sets out the requirements for qualified certificates and accredited providers. Where a qualified electronic signature is used, Article 14 paragraph 2bis of the Swiss Code of Obligations treats it as equivalent to a handwritten signature.

Within the EU, the equivalent framework is eIDAS, which gives qualified electronic signatures the same legal effect as handwritten signatures across member states and establishes the status of qualified seals and timestamps.

Separately, and often overlooked by certificate issuers, the underlying course material, assessment content, and curriculum are protected as original works under the Berne Convention. Protection arises automatically on creation, but proving that you held a specific version on a specific date is a separate evidential problem, and one that a sealed and timestamped record solves.

What this looks like in practice

For an organisation issuing qualifications, the change is smaller than it sounds. The certificate is generated as normal. Before it is sent, it is sealed and timestamped, which produces a file that carries its own verification data inside it. The recipient gets a document that looks familiar. The difference appears when someone checks it.

A verifier opens the file and confirms the seal, the timestamp, and the integrity of the contents. If the certificate has been altered in any way, that check fails immediately and visibly. No login, no registry, no phone call to your office.

This also removes an administrative burden most issuers carry quietly. Verification requests from employers and regulators stop landing in your inbox, because the person asking can answer the question themselves.

Where to start

Begin with the certificates that carry the most consequence if forged, usually those tied to regulated practice, safety, or professional standing. Those are the ones where a fake causes real harm and where a verifier is most likely to check.

From there, apply the same process to your standard issuance run. The technical work is the same whether you issue fifty certificates a year or fifty thousand, because the sealing step happens automatically at the point of generation.

You can verify any sealed document, including certificates issued by others, using the public validator at swisstrustlayer.com/validate. No account is required.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

The qualified signature workflow, start to finish
Legal

The qualified signature workflow, start to finish

A qualified electronic signature involves identity verification, signing ceremony, PAdES application, RFC 3161 timestamping, and public verification. Each step serves a specific legal purpose. This is what the process looks like from upload to verified certificate.

July 19, 2026Read more →
5 documents Swiss businesses should never sign with a basic e-signature
Legal

5 documents Swiss businesses should never sign with a basic e-signature

Swiss law specifies document types where only a qualified electronic signature carries the legal weight of a handwritten signature. Using a simple or advanced e-signature on these documents creates an enforceable gap that surfaces in disputes. Here are the five categories that matter.

July 18, 2026Read more →
DocuSign vs SealMyIdea: where a visual signature isn't enough
Legal

DocuSign vs SealMyIdea: where a visual signature isn't enough

DocuSign provides advanced and simple electronic signatures. For real estate, IP transfers, fiduciary mandates, and employment contracts in Switzerland, only a qualified electronic signature under ZertES Art. 11 carries legal presumption. This is the gap DocuSign cannot close.

July 17, 2026Read more →
For agencies: prove you authored the work and get clean client sign-off
Legal

For agencies: prove you authored the work and get clean client sign-off

Creative and digital agencies lose IP disputes because they cannot prove creation date or obtain legally binding client acceptance. A qualified electronic signature for client sign-off, combined with timestamped delivery, creates the complete audit trail that courts recognise.

July 16, 2026Read more →
Blockchain proves a file existed. It doesn't prove a court will accept it.
Legal

Blockchain proves a file existed. It doesn't prove a court will accept it.

A blockchain timestamp records that a file existed at a point in time. It carries no legal presumption under eIDAS or ZertES. A qualified electronic timestamp issued by an accredited QTSP does.

July 15, 2026Read more →