PAdES Signature Levels Explained
A digital signature on a PDF answers two questions: who signed, and has anything changed since. For many regulated workflows, a third question matters just as much: can this signature still be validated years from now? PAdES, the European standard for advanced electronic signatures in PDF, addresses all three through a set of defined levels. This post explains what each level adds so you can choose the right one for your compliance requirements.
What Is PAdES?
PAdES stands for PDF Advanced Electronic Signatures. It is a set of ETSI standards that defines how to build advanced electronic signatures inside PDF documents, and it is closely tied to the EU's eIDAS regulation. PAdES signatures use standard PDF signature fields, X.509 certificates, and public key infrastructure (PKI), so a signed document is still a normal PDF that opens in Adobe Acrobat and other readers, with signature validation built in.
One distinction is worth making early. PAdES is a signature format, and it does not determine legal status on its own. Under eIDAS, a signature can qualify as an advanced electronic signature (AdES) or a qualified electronic signature (QES), and a QES carries the same legal weight as a handwritten signature in the EU. Reaching QES depends on the certificate and signing device used, not only on the PAdES level you choose.
The Four PAdES Baseline Levels
Each level builds on the one before it.
- PAdES-B-B (Basic): A standard advanced signature. It identifies the signer and protects the document from undetected changes, but it carries no trusted proof of when the signature was created.
- PAdES-B-T (Timestamp): Adds a trusted timestamp from a timestamp authority. The timestamp shows that the signature existed at a specific time, which helps demonstrate it was created while the signing certificate was valid.
- PAdES-B-LT (Long-Term): Adds the validation material needed to check the signature later, such as certificate chains and revocation information (OCSP responses and CRLs), embedded in the document itself.
- PAdES-B-LTA (Long-Term Archival): Adds archival protection through document timestamps, so the signature and its validation data remain verifiable over very long retention periods.
Why the Timestamp Matters
Certificates expire, and they can be revoked. Without a timestamp, a verifier years later has a hard time establishing whether a signature was made while the certificate was still good. A trusted timestamp (commonly based on RFC 3161) fixes the signing time with evidence from a third party. That makes B-T the practical starting point for workflows that need a defensible audit trail.
Note that B-T on its own does not embed revocation information. If a verifier needs to validate the signature offline, long after the signing infrastructure has changed, that is what B-LT adds.
Choosing the Right Level
Requirements vary by regulation, jurisdiction, and record type, so confirm the specifics with your compliance team. As a general guide:
- B-B suits low-risk internal workflows where proof of signing time is not required.
- B-T suits workflows that need proof of when a document was signed, such as contracts, approvals, and records that may be audited.
- B-LT suits documents that must remain verifiable long after certificates expire or validation services change.
- B-LTA suits records retained for many years or decades, where the signature itself must be protected over time.
PAdES B-T in Adobe PDF Library
Datalogics supports PAdES B-T today. Adobe PDF Library includes a dedicated PAdES signature class that handles the components of a compliant B-T signature, so developers do not need to assemble them by hand. You can read more in our announcements on PAdES B-T support and timestamp digital signatures. Support for other levels and platform availability can change between releases, so check the release notes for current details.
Wondering where signing fits in your pipeline? Read Digital Signatures in Compliance Pipelines: Getting the Order of Operations Right.
Signatures and Long-Term Archiving
Long-term validation and archival levels exist because many industries retain records for decades. If your documents also need to meet PDF/A requirements, signing is one step in a larger archiving process, and it works best when planned alongside conversion and validation.
Building an archive? See how to convert PDFs to PDF/A for compliance archiving at scale.
Getting Started
If you are evaluating digital signature options for a compliance workflow, start by identifying the level your regulations call for, then test signing and validation on a sample set of documents. You can start a free trial of Adobe PDF Library to try PAdES B-T signing in your own environment.