This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Electronic signature (ES)

Information Security

An electronic signature is a document attribute obtained as a result of cryptographic transformation, confirming authenticity and authorship.

What is an electronic signature

An electronic signature (ES) is information in electronic form attached to a signed document that allows identifying the signatory and confirming the immutability of the document. Legal regulation is carried out by Federal Law No. 63-FZ "On Electronic Signature". ES is widely used in electronic document management, government services, banking operations and corporate information systems. The use of an electronic signature significantly speeds up business processes and reduces the costs of paper document flow. Certified cryptographic information protection tools (CIPF) are used to create and verify electronic signatures.

Electronic signature — how it works and verification ES cryptographic process: the sender creates a document hash and encrypts it with the private key (CIPF). The receiver verifies the signature with the public key from the certificate, confirming authenticity and authorship. How an electronic signature works Cryptographic process of signing and verifying a document Sender (signatory) Document ES key Hashing + encryption (CIPF) Private key — only the owner has it transfer Receiver (verifier) Document + signature Certificate Signature verification (cryptography) Public key — from the certificate ✅ Signature valid Document is authentic, authorship confirmed ES = document hash encrypted with the private key Verification = decryption with the public key
Electronic signature (ES) — term diagram

An electronic signature is an analogue of a handwritten signature in the digital world. It provides three key properties: integrity (the document was not changed after signing), authenticity (the signature belongs to a specific person) and non-repudiation (the signatory cannot deny the signature).

According to the Ministry of Digital Development, by 2025 more than 90% of legally significant document flow in Russia will be carried out using electronic signatures. This is due to the active development of electronic government and the digitalization of business processes.

Types of electronic signatures

There are three types of electronic signatures. Simple ES — login-password, SMS code, confirms authorship. Enhanced non-qualified ES — based on cryptographic algorithms, confirms authorship and immutability. Enhanced qualified ES (QES) — complies with 63-FZ, uses certified CIPF, has the highest legal force and is equivalent to a handwritten signature. QES is issued by accredited certification authorities (CA). Since 2022, individuals can obtain QES from the certification authorities of the Federal Tax Service of Russia, and legal entities and individual entrepreneurs — from trusted representatives of the Federal Tax Service or in commercial CAs.

A simple ES is used for the internal needs of organizations and in systems with low security requirements. An enhanced non-qualified ES is used in corporate document management systems where confirmation of authorship and immutability is required, but interaction with government bodies is not required.

A qualified ES is the most protected and has full legal force. It is used for interaction with government bodies, participation in public procurement, filing tax reports and in other scenarios that require the maximum level of trust.

How to obtain an electronic signature

To obtain a QES, you must contact an accredited certification authority, provide identity documents and undergo an identification procedure. The validity period of a QES certificate is 15 months. Legal entities must also provide documents on registration and the authority of the head.

Since 2022, individuals can obtain a QES at the certification authorities of the Federal Tax Service of Russia for free. Legal entities and individual entrepreneurs can obtain a QES from trusted representatives of the Federal Tax Service or in commercial CAs. The cost of a QES for legal entities ranges from 3,000 to 10,000 rubles depending on the CA and the set of functions.

To work with a QES, you must install a certified CIPF (for example, CryptoPro CSP), obtain a key information carrier (token or smart card) and configure your workstation. For organizations with a large number of employees, it is recommended to use a cloud electronic signature, in which private keys are stored on CA servers in hardware HSM modules.

Machine-readable power of attorney (MCD)

Since September 1, 2024, requirements on the mandatory use of machine-readable powers of attorney (MCD) when signing electronic documents on behalf of a legal entity by employees acting under a power of attorney have come into force. An MCD is an electronic document in XML format, signed with the QES of the head, which confirms the authority of the employee.

The MCD allows automating the verification of employee authority and reducing the risks of signing documents by unauthorized persons. It is stored in the Unified MCD repository of the Federal Tax Service of Russia and can be used for any electronic documents requiring a signature.

Protected media are used for secure storage of the private key: tokens (JaCarta PKI, Rutoken EDS) and smart cards certified by the FSB of Russia. Products of the Fintech company, such as SINTEZM-T, are a certified CIPF for creating and verifying electronic signatures, ensuring the full legal significance of electronic documents within electronic document management.

Frequently asked questions

How can I create an electronic signature?

The fastest way is to obtain a free signature through the Gosklyuch application (a verified Gosuslugi account is required). For business (LLC/IE), the most reliable method is to contact the Certification Authority of the Federal Tax Service of Russia or its trusted representatives. You can also obtain a QES at commercial accredited certification authorities such as Kontur or Tensor. Working with a signature will require a cryptographic information protection tool, for example CryptoPro CSP.

Where can I find my electronic signature?

Information about electronic signature certificates issued in your name can be found in the personal account of the Gosuslugi portal in the "Profile" — "Electronic signature" section. The physical signature file (private key) is stored on a protected medium (token) or in the register of the certification authority. If you cannot find your signature, contact the CA where it was issued.

Can I create an electronic signature through Gosuslugi?

Yes, through Gosuslugi it is easiest to obtain a non-qualified (ENES) or qualified electronic signature (QES) using the official Gosklyuch application. The process is free and remote. For a QES, you will need to confirm your identity (through biometrics with a new-format foreign passport or in person at an MFC). This is a convenient way to obtain a legally significant signature for personal needs and business.

What does an electronic signature look like?

An electronic signature does not have a single visual appearance. In PDF and Word, it can look like a rectangular stamp with information about the owner, date and time of signing. It can also be represented as a separate file with the extension .sig, .sgn or .p7s. The signature itself is not a picture, but a set of cryptographic data confirming authorship. Its authenticity is verified using public key infrastructure (PKI).

Who issues an electronic signature?

Electronic signatures are issued by accredited certification authorities (CAs). For heads of organizations and individual entrepreneurs, a signature is issued free of charge at the CA of the Federal Tax Service of Russia. For individuals and employees of organizations — at commercial accredited CAs (for example, Tensor, SKB Kontur). The full list of accredited centers is published by the Ministry of Digital Development on the Gosuslugi portal. When obtaining a signature for employees, a machine-readable power of attorney from the head will be required.

What is a machine-readable power of attorney (MCD)?

A machine-readable power of attorney (MCD) is an electronic document in XML format that confirms the authority of an employee to sign electronic documents on behalf of a legal entity. Since September 1, 2024, the MCD has become mandatory when employees use a QES. The MCD is signed with the QES of the head and is stored in the Unified MCD repository of the Federal Tax Service of Russia. This greatly simplifies the verification of authority in electronic document management.

How long is an electronic signature valid?

The validity period of a qualified electronic signature (QES) certificate is 15 months (1 year + 3 months) for most types of certificates. For individuals, the period can be up to 3 years. After the certificate expires, the signature becomes invalid — documents signed with an expired signature lose legal force. You must promptly reissue the certificate at the certification authority. We also recommend familiarizing yourself with the concept of Tokenization.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate electronic signature (es) into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm