THE PRINCIPLES
Incorporating a Qualified Electronic Signature solution is essential for organizations that require the highest level of legal assurance, security, and compliance in their electronic transactions.
It not only ensures adherence to regulatory standards, but also enhances trust and efficiency in digital interactions.
In this guide, you will find a list of essential questions to ask your supplier. One list helps vet the supplier, while the other qualifies the product.
All questions are structured as yes/no, and you want to see ‘Yes’ answers!
This is a general list that may slightly vary depending on the use case. However, a vendor that checks all these boxes will be well-equipped to future-proof your operations, and support your business’ long-term scalability.
Some potential use cases for this list include:
- Sealing bank statements and transactions
- Signing customer contracts or employee agreements
- Sealing tax statements, public documents, laws
- Signing B2G/B2B/B2C and e-gov transactions
- and others...
SIGNING AND SEALING SOLUTION
TECHNICAL INTEROPERABILITY
Does the solution use industry standards for protocols and APIs to make integration simple for developers?
PERFORMANCE
Does the architecture meet your performance requirements for both average loads and peak loads?
PRIVACY AND CONFIDENTIALITY
Does the solution ensure that documents remain on-site and that signees can be pseudonymized?
COMPLIANCE
Can the architecture be designed to place the compliance burden where you need it, making onboarding easier for you and your customers?
LEGAL RECOGNITION
Does the solution allow the use of multiple signing schemes and multiple trust service providers to meet your market requirements?
EASE OF OPERATION
Does the solution allow centralized management of users, policies, and signing credentials for greater efficiency?
QUALIFIED AND ADVANCED
Can the same architecture be used for Qualified and Advanced electronic signatures to avoid infrastructure overheads?
SECURITY ARCHITECTURE
Can the vendor provide a detailed security architecture outlining how various threats are mitigated?
SIGNING AND SEALING IN THE SAME SOLUTION
Can the architecture be used for both signing and sealing to avoid infrastructure overheads?
MODULARITY AND REUSE OF EXISTING ARCHITECTURE
Is the solution modular and flexible enough to compose the architecture and reuse as much as possible of your existing infrastructure?
SCALABILITY
Can you increase the over performance by adding more rQSCDs to the centralized pool? Do the other modules support ‘scale-up’ and ‘scale-out’ capacity strategies?
SIGNING AND SEALING VENDOR
-
PEDIGREE OF THE VENDOR
Do they have a strong reputation and long track record within the signing and sealing domain?
-
RESILIENCE
Does the solution provide for high availability, backup, and disaster recovery?
-
STRATEGIC NATURE OF THE PRODUCT
Is the product a core offering rather than a small sideline?
-
COMPLIANCE AND REGULATION
Can the vendor show how it addresses compliance with relevant regulations?
-
CREDIBILITY
Is the product proven, backed up by high-profile references or case studies?
-
FUTURE-PROOFING
Is the product actively maintained and updated in line with market trends, such as regulatory requirements, cloud computing, and post quantum algorithms?
-
SUPPORT
Can the vendor provide professional services to help with design and implementation, as well as high quality of ongoing maintenance and support (on a 24/7 basis if required)?
