How a ZertES Qualified Electronic Seal Works: Technical + Legal Explainer (2026)
Standards Compliance

How a ZertES Qualified Electronic Seal Works: Technical + Legal Explainer (2026)

A ZertES qualified electronic seal is Switzerland's highest-assurance digital seal, legally equivalent to a handwritten stamp under Swiss law. This explainer covers how it works technically, when it is qualified vs. advanced, and how it compares to EU eIDAS.

S
Swiss Trust Layer Editorial Team· Legal Content
·June 12, 2026· 7 min read

In September 2024, a Zurich-based SaaS company received a cease-and-desist from a competitor claiming prior ownership of a software module. The company's legal team had version history in GitHub, but GitHub timestamps are self-reported and cannot be independently verified in Swiss court proceedings. The Commercial Registry filing listed the company's founding date, not the module's development history. Without a qualified seal on the software documentation, the burden of proof sat entirely on the company to disprove the competitor's claim, at CHF 230,000 in legal fees before the dispute settled.

A ZertES qualified electronic seal (QES) is an electronic seal created by a legal entity using a qualified certificate issued by a Swiss trust service provider accredited under ZertES (SR 943.03). Under Swiss law (OR Art. 14 para. 2bis and ZertES Art. 2), a qualified seal meets the highest legal standard for organisational authentication and is admissible as evidence in Swiss courts without additional proof of authenticity.

What Is ZertES and Why Does It Matter?

ZertES, short for Bundesgesetz uber Zertifizierungsdienste im Bereich der elektronischen Signatur (Federal Act on Certification Services in the Area of Electronic Signatures, SR 943.03), is Switzerland's primary law governing digital trust services. It defines the legal framework for:

  • Qualified electronic signatures (by natural persons)
  • Qualified electronic seals (by legal entities, such as organisations and companies)
  • Qualified electronic timestamps
  • Certificate authorities (Certification Service Providers, CSPs) operating in Switzerland

ZertES was enacted in 2003 and revised in 2016 to align with the EU's eIDAS regulation. Switzerland is not an EU member, but ZertES is intentionally designed to be functionally equivalent to eIDAS, enabling cross-border recognition between Switzerland and the EU under the bilateral treaty framework.

How Does a ZertES Qualified Electronic Seal Differ From an Advanced Seal?

ZertES establishes a three-tier hierarchy for seals:

LevelStandardCertificate RequiredLegal Force
Qualified (QES)ZertES Art. 2Qualified certificate from accredited CSPHighest: presumption of authenticity in court
Advanced (AES)ZertES Art. 2bCertificate (may be from non-accredited provider)Strong: good evidence, but rebuttable
SimpleNoneNo specific requirementsWeakest: no presumption of authenticity

For a seal to be "qualified" under ZertES:

  1. It must be created using a qualified certificate issued by a CSP accredited by the Swiss Accreditation Service (SAS) under ZertES
  2. The certificate must be linked to the legal entity (not an individual)
  3. The creation device must meet security requirements
  4. The certificate must be valid (not expired or revoked) at the time of sealing

Under Swiss Civil Code / Code of Obligations (OR Art. 14 para. 2bis), a qualified electronic signature (and by extension, a qualified seal) is treated as legally equivalent to a handwritten signature for documents requiring written form.

What Is the Technical Mechanism Behind a Qualified Seal?

At a technical level, a ZertES qualified electronic seal uses:

  1. Public Key Infrastructure (PKI): The sealing organisation holds a private key, with a corresponding public key certified in a qualified certificate.
  2. Asymmetric cryptography: The seal is created by hashing the document content (SHA-256 or SHA-512) and encrypting the hash with the organisation's private key. This produces a digital signature value.
  3. Certificate binding: The qualified certificate links the public key to the legal entity's verified identity (company name, registration number, jurisdiction).
  4. Timestamp embedding: A qualified timestamp from a timestamp authority (TSA) is embedded, proving the exact time of sealing.
  5. PAdES format (PDF Advanced Electronic Signatures, ETSI EN 319 422): The industry standard format for PDF seals, supporting long-term validation (LTV) so the seal remains verifiable after certificates expire.

The result: a sealed document where any modification, even a single character change, invalidates the seal. The seal cannot be forged without the private key, which is held in a Hardware Security Module (HSM) certified to FIPS 140-2 Level 3 or Common Criteria EAL4+.

What Would Have Happened with a Qualified Seal?

If the Zurich SaaS company had sealed each software release manifest using a ZertES qualified electronic seal, the outcome would have been straightforward. Under OR Art. 14 para. 2bis (in conjunction with ZertES Art. 2), a qualified seal carries a legal presumption of authenticity in Swiss courts: the court presumes the seal is authentic and the document has not been tampered with since sealing. The sealed manifest would have established the module's creation date as a legally defensible fact. The burden of proof would have shifted to the competitor. The CHF 230,000 in legal fees would not have been spent.

When Is a Qualified Seal Required vs. Recommended?

Required by law (Swiss examples):

  • Notarial acts in digital form
  • Corporate resolutions to be filed with the Commercial Registry
  • Electronic invoices under Swiss VAT rules (MWSTG Art. 26): authenticity and integrity are legally required. A qualified seal provides the highest-assurance method, but advanced seals also satisfy the requirement
  • Documents requiring "written form" under OR, including suretyship agreements (OR Art. 493), employment non-compete clauses (OR Art. 340), and gift promises (OR Art. 243)

Strongly recommended (best practice):

  • Intellectual property documentation (proving ownership date, authorship)
  • Compliance documentation submitted to FINMA, BAKOM, or cantonal authorities
  • Cross-border contracts with EU counterparties (eIDAS recognition)
  • Software delivery records (proving version history for licensing or litigation)

How Does ZertES Compare to eIDAS?

Switzerland and the EU have worked toward mutual recognition of qualified trust services. Key comparisons:

DimensionZertES (Switzerland)eIDAS (EU)
Legal basisSR 943.03EU 910/2014
Governing bodySwiss Accreditation Service (SAS)National supervisory bodies + EU Trusted Lists
Qualified seal definitionZertES Art. 2eIDAS Art. 35
Cross-border recognitionBilateral recognition via EU-CH frameworkAutomatic within EU
TSP listSAS accredited listEU Trusted Lists (national)
Time stamp standardRFC 3161 (same)RFC 3161 + ETSI EN 319 422
Long-term validationPAdES-LTV (same)PAdES-LTV

In practice: a ZertES qualified seal is not automatically treated as an eIDAS qualified seal under EU law. However, EU courts can and do accept ZertES-sealed documents as high-quality evidence, and many EU counterparties contractually accept ZertES seals as equivalent. Swiss Trust Layer's eIDAS-compliant sealing adds an eIDAS timestamp layer on top of the ZertES framework, producing a document valid under both standards.

Is a ZertES Qualified Seal Admissible as Evidence in Swiss Courts?

Yes. Under OR Art. 14 para. 2bis (in conjunction with ZertES Art. 2), a qualified seal carries a legal presumption of authenticity in Swiss courts: if the qualified certificate was valid at time of sealing, the court presumes the seal is authentic and the document has not been tampered with since sealing. The opposing party bears the burden of rebutting this presumption.

This is the key legal advantage of a qualified seal over an advanced or simple seal. Advanced seals are good evidence, but they can be challenged without shifting the burden of proof. Qualified seals place the burden of proof on the challenger.

Who Are the Accredited ZertES CSPs in Switzerland?

CSPs accredited by the Swiss Accreditation Service (SAS) to issue qualified certificates for ZertES seals include (as of 2026):

  • SwissSign (SwissSign Group AG), backed by Swiss Post
  • Swisscom Trust Services
  • QuoVadis Trustlink (now part of DigiCert)

Swiss Trust Layer integrates with accredited CSPs to issue qualified certificates as part of the sealing workflow. You do not need to separately procure a certificate. The ZertES sealing service includes certificate issuance, timestamping, and document storage in a single step.

What Is the Shelf Life of a ZertES Qualified Seal?

Certificates expire (typically after 1 to 3 years). Without long-term validation (LTV) measures, an expired certificate means the seal cannot be re-verified after expiry. ZertES-compliant seals must include:

  1. OCSP stapling or CRL embedding at the time of sealing, as proof the certificate was valid at that moment
  2. Timestamp renewal (archival timestamps, "re-timestamping") every few years to extend verifiability beyond cryptographic algorithm lifetimes

Swiss Trust Layer applies LTV measures at sealing time and provides archival timestamping services to maintain seal validity for 30+ years, covering the typical document retention period required by Swiss commercial law (OR Art. 958f: 10 years).

Next Steps

The Zurich SaaS company spent CHF 230,000 defending a dispute that could have been resolved in a single court filing, had the software release manifests carried a ZertES qualified electronic seal. The seal documentation cost would have been under CHF 50. For the CHF 150,000 to CHF 400,000 average cost of a Swiss IP dispute (Swiss Arbitration Association), the cost of proof is a rounding error. If your organisation needs to seal documents under Swiss law with the highest legal assurance, a ZertES qualified electronic seal is the appropriate tool. It provides legal presumption of authenticity, court admissibility, and cross-border recognition with EU counterparties. See the ZertES service overview or the compliance framework comparison for how it fits into a broader document governance strategy.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

The qualified signature workflow, start to finish
Legal

The qualified signature workflow, start to finish

A qualified electronic signature involves identity verification, signing ceremony, PAdES application, RFC 3161 timestamping, and public verification. Each step serves a specific legal purpose. This is what the process looks like from upload to verified certificate.

July 19, 2026Read more →
5 documents Swiss businesses should never sign with a basic e-signature
Legal

5 documents Swiss businesses should never sign with a basic e-signature

Swiss law specifies document types where only a qualified electronic signature carries the legal weight of a handwritten signature. Using a simple or advanced e-signature on these documents creates an enforceable gap that surfaces in disputes. Here are the five categories that matter.

July 18, 2026Read more →
DocuSign vs SealMyIdea: where a visual signature isn't enough
Legal

DocuSign vs SealMyIdea: where a visual signature isn't enough

DocuSign provides advanced and simple electronic signatures. For real estate, IP transfers, fiduciary mandates, and employment contracts in Switzerland, only a qualified electronic signature under ZertES Art. 11 carries legal presumption. This is the gap DocuSign cannot close.

July 17, 2026Read more →
For agencies: prove you authored the work and get clean client sign-off
Legal

For agencies: prove you authored the work and get clean client sign-off

Creative and digital agencies lose IP disputes because they cannot prove creation date or obtain legally binding client acceptance. A qualified electronic signature for client sign-off, combined with timestamped delivery, creates the complete audit trail that courts recognise.

July 16, 2026Read more →
Blockchain proves a file existed. It doesn't prove a court will accept it.
Legal

Blockchain proves a file existed. It doesn't prove a court will accept it.

A blockchain timestamp records that a file existed at a point in time. It carries no legal presumption under eIDAS or ZertES. A qualified electronic timestamp issued by an accredited QTSP does.

July 15, 2026Read more →