A QSeal is applied using a qualified seal certificate issued to an organisation. It proves that the data originated from that organisation, not from any specific employee. This is valuable for official documents, certificates, and regulatory filings.
Three emerging enterprise signing use cases
Qualified electronic seals (QSeal), electronic certificates of conformity (eCoC), and Digital Product Passport (DPP) data controls are distinct concepts that may appear in manufacturing architectures. QSeal is an eIDAS trust service; eCoC requirements depend on the applicable vehicle framework; and ESPR requires DPP data authentication, reliability, and integrity without imposing a universal QSeal requirement.
QSeal, eCoC and DPP compared
| Scope | Who signs | |
|---|---|---|
| QSeal | Qualified electronic seal for organisational documents | Organisation (via device seal certificate) |
| eCoC | Electronic certificate of conformity for products | Manufacturer or authorised representative |
| DPP signing | EU Digital Product Passport data attestation | Data holder (manufacturer, importer, distributor) |
Qualified electronic seal (QSeal): when organisations need to sign
An electronic seal is the organisational equivalent of a qualified electronic signature. It proves the origin and integrity of data on behalf of a legal entity, not an individual.
Under eIDAS Article 36, data sealed with a qualified electronic seal enjoys the presumption of integrity and origin. This is the strongest organisational evidence available under EU law.
QSeals are typically applied by software systems, not individual users. A manufacturing execution system (MES) can seal each product's conformity data as it comes off the production line. A document management system can seal official copies of certificates.
A digital signature proves an individual person signed. An electronic seal proves an organisation attests to the data. For product compliance and regulatory filings, seals are often more appropriate than signatures.
eCoC and DPP: signing product data
Electronic Certificate of Conformity
An eCoC attests that a product meets specified standards. The manufacturer or authorised representative applies a qualified seal to the certificate data. For EU products under CE marking rules, the eCoC may need to be available digitally for market surveillance authorities.
EU Digital Product Passport
ESPR establishes requirements for accurate, complete, up-to-date, interoperable, and protected DPP data, including data authentication, reliability, and integrity. Product-specific delegated acts and technical specifications determine the detailed workflow. A signature or seal may be selected as an evidence control, but QES or QSeal is not a universal ESPR requirement.
Batch signing for production lines
Manufacturers producing thousands of units need batch signing: seal conformity data for each batch or production run automatically via API. The signing platform must support high-volume machine-to-machine signing with minimal latency.
Supply chain integration
DPP data flows across the supply chain: material suppliers provide composition data, manufacturers add production data, distributors add logistics data. Each party signs or seals their contribution. The signing platform must support multi-party sequential signing workflows.
Connecting to ERP, PLM and supply chain systems
To operationalise QSeal, eCoC and DPP signing, integrate the signing platform with enterprise data systems.
Map data flows
Identify which systems hold the data that needs sealing: ERP for product master data, PLM for specifications, MES for production data, CRM for customer-specific certificates.
Provision organisational seal certificate
Obtain a qualified electronic seal certificate from a QTSP. Configure it in the signing platform for machine-applied sealing.
Build API integration
Connect the enterprise system (ERP/PLM/MES) to the signing platform via API. The enterprise system sends data payloads for sealing; the signing platform returns sealed documents or tokens.
Configure batch processing
For high-volume production environments, configure batch signing with queue management. Each production run triggers a sealing request that is processed asynchronously.
Submit to regulatory registries
Implement the applicable registry and data-carrier interfaces when the relevant specifications are available. Store submission responses, change history, access decisions, and any signature or seal validation evidence used by the workflow.
How eSign.AI can fit into a seal and evidence architecture
eSign.AI can provide the workflow and API layer for a configured electronic-seal process. A qualified deployment still depends on the certificate holder, a verified QTSP service, secure key custody, certificate status checks, and the customer's legal and technical design.
QSeal via REST API
MES, ERP, or PLM systems can call a configured signing or sealing API. Before production use, verify HSM and key-custody responsibilities, supported formats, certificate status checking, throughput, failure handling, and the evidence returned by the service.
DPP submission pipeline
A DPP architecture can connect source systems, validation rules, access controls, evidence controls, and applicable registry interfaces. eSign.AI may handle a configured signing or sealing step, while data mapping, delegated-act compliance, and registry submission remain deployment-specific.
eCoC and DPP integration: system architecture and workflow
Technical and operational details for enterprises implementing QSeal at scale.
XML e-seal workflow for automotive eCoC
eSign.AI's eCoC workflow (released 2026-06-11) follows this pattern: manufacturer uploads an XML file containing vehicle type-approval data, the system applies an e-seal using the manufacturer's qualified seal certificate, and the sealed XML is submitted to the relevant EU type-approval authority. The XML SDK (released 2026-06-25) enables developers to integrate this workflow directly into production-line systems.
Data governance for DPP compliance
DPP governance may require several supply-chain participants to contribute data. Define who can add or update each field and preserve attribution and change history. Multiple signatures or seals are one possible control pattern, but they should follow the product-specific rules and system design.
Connecting with PLM and ERP systems
For manufacturers, any signing or sealing step sits within a wider PLM, ERP, quality, and compliance data flow. Confirm the available eSign.AI APIs, webhook events, synchronous or batch behaviour, and throughput against current product documentation before finalising the architecture.
Frequently asked questions
An electronic signature is applied by a natural person (individual). An electronic seal is applied by a legal entity (organisation). Under eIDAS, a qualified electronic seal enjoys the presumption of data integrity and origin — equivalent to a company stamp but cryptographically stronger.







