The EU-India electronic signature arrangement went live in January. It links trust lists, not signature laws.
What the January 2026 Administrative Arrangement actually changes for cross-border contracts between Indian and EU counterparties, and what it doesn't.
On 27 January 2026, India's Ministry of Electronics and Information Technology and the European Commission's digital directorate, DG CONNECT, signed something with an unglamorous name: an Administrative Arrangement on Advanced Electronic Signatures and Seals. Six months later, at the third India-EU Trade and Technology Council meeting in Brussels on 15 July 2026, both sides pointed back to it as a marker of deepening digital cooperation.
Coverage since January has repeated the same phrase: cross-border digital trust. What the EU-India electronic signature arrangement actually does is narrower than that phrase suggests, and the gap between the headline and the legal reality matters if your company signs contracts with counterparties on the other side of that border.
Inside the EU-India electronic signature arrangement
The arrangement sits between two specific institutions, not two governments in the treaty sense. On the Indian side, it was signed by MeitY, with implementation running through the Controller of Certifying Authorities (CCA), the body that licenses and supervises India's certifying authorities under the IT Act, 2000. On the EU side, it was signed by DG CONNECT, the European Commission department that runs digital policy including eIDAS, the regulation governing electronic identification and trust services across the EU.
The stated objective is an expressed intent to link the two sides' Trusted Lists: the registries each jurisdiction keeps of trust service providers it recognises as licensed and supervised. When the third TTC concluded in Brussels this July, co-chaired on the Indian side by external affairs minister Dr S. Jaishankar, commerce minister Piyush Goyal and electronics and IT minister of state Jitin Prasada, the joint statement folded this arrangement into a wider set of commitments on trusted technology and trade. It's real, and it's a sensible next step. It is not, by itself, a change to what either jurisdiction's courts do with a signature.
An Administrative Arrangement is not a treaty
Words matter here, because international cooperation has a rough hierarchy. A treaty gets ratified by national legislatures and creates binding obligations enforceable between states. A mutual recognition agreement typically sits under a treaty framework and creates specific, litigable commitments. An administrative arrangement, by contrast, is a working-level understanding between two agencies about how they will cooperate technically. It doesn't need ratification, it doesn't bind either country's courts, and it doesn't amend either side's domestic law.
That's not a knock on the document. Administrative arrangements are how a lot of genuine technical cooperation gets done, because they move faster than treaties. But it means MeitY and DG CONNECT agreed to work towards linking two registries. Neither agency can tell an Indian or European court how to weigh a foreign electronic signature as evidence — that's a legislative question, and neither the IT Act nor eIDAS has been amended to answer it for the other jurisdiction's signatures.
What linking Trusted Lists actually verifies
Under eIDAS, every EU member state publishes a Trusted List: a machine-readable registry of which trust service providers are supervised, and which of their certificates qualify for which signature tier. Software that verifies a signed document — a PDF reader, a bank's intake system — checks the signing certificate against these lists to confirm the issuing provider is licensed, rather than trusting the certificate on its own say-so.
India runs a structurally similar registry: the CCA licenses certifying authorities under the IT Act and publishes which of them may issue digital signature certificates. Linking the two lists means, in principle, that a European verification system could look up whether an Indian CA is licensed, and an Indian system could do the same for a European qualified trust service provider, without a person pulling licensing records by hand.
That's a real reduction in due-diligence friction for anyone building document-verification software that has to handle both regions. It is a technical convenience for checking whether a certificate came from a supervised issuer. It says nothing about whether the underlying signature carries legal weight in the other jurisdiction's courts — that's a separate question, governed by each side's own law, and it's the one most of the January coverage skipped past.
eIDAS grades signatures. India's law doesn't, not the same way
The structural mismatch becomes clearer once the two frameworks sit side by side.
| Tier / test | European Union (eIDAS) | India (IT Act) |
|---|---|---|
| Baseline signature | Simple Electronic Signature (SES) — any electronic data attached to show intent, minimal evidentiary weight on its own | No separate 'basic' tier; falls back to general contract-law evidence rules |
| Enhanced signature | Advanced Electronic Signature (AdES) — uniquely linked to the signatory, under their sole control, tamper-evident | Section 3A 'reliable' electronic signature — the same three tests, without a distinct label |
| Top-tier signature | Qualified Electronic Signature (QES) — AdES plus a qualified certificate plus a qualified signature creation device; automatic legal equivalence to a handwritten signature EU-wide under Article 25 | Digital signature certificate from a CCA-licensed CA (Section 3) — treated as reliable, but no statutory 'automatic equivalence' label distinct from Section 3A |
| Government-backed authentication | eIDAS-notified national eID schemes | Aadhaar-based eSign, listed under the Second Schedule |
| Registry of trusted issuers | Trusted Lists, published per member state, aggregated EU-wide | CCA-maintained list of licensed certifying authorities |
Under eIDAS, a Qualified Electronic Signature gets automatic legal equivalence to a handwritten signature in every member state, by operation of Article 25 of the regulation. That's the point of the tiering: it tells a court exactly how much weight to give a signature based on which box it ticks.
India's Section 3A takes a different approach. It asks whether a signature is reliable — linked uniquely to the signatory, under their sole control, and able to reveal tampering — and whether the method is listed in the Second Schedule. Digital signature certificates from CCA-licensed CAs and Aadhaar-based eSign both qualify today. But the IT Act doesn't sort signatures into tiers the way eIDAS does, so there's no clean mapping from 'qualified' to an Indian equivalent. A CCA-licensed certificate functions much like a qualified signature in practice, anchored to a government-supervised root, but the statute doesn't say so in those terms, and nothing in the January arrangement changes that.
The documents this arrangement can't touch, whichever way it goes
There's a further wrinkle that has nothing to do with the EU and everything to do with India's own law. The IT Act's First Schedule excludes a specific list of documents from the Act's electronic-signature and electronic-record provisions altogether: negotiable instruments other than cheques, powers of attorney, trusts, wills and other testamentary dispositions, and contracts for the sale or conveyance of immovable property or any interest in it.
For those categories, the answer to whether a document can be signed electronically is no — regardless of certificate tier, regardless of whether the counterparty is in the EU, and regardless of any arrangement between MeitY and DG CONNECT. This carve-out is written into Indian law itself. A bilateral technical cooperation document between two agencies has no power to touch it.
What actually decides enforceability in a dispute
Strip away the January headline and the question a contracts lawyer has to answer is an old one: if this agreement ends up argued in a Delhi court or a Berlin court, which law applies, and how will that court treat the signature in front of it?
That's answered by the contract's own governing-law and jurisdiction clauses, and by each forum's private international law rules where the contract is silent. An Indian court weighing a signature from an EU qualified trust service provider looks first to whether Indian law, including whatever the Trusted List link makes easier to verify, treats that certificate as reliable under Section 3A. A European court facing an Indian digital-signature-certificate-signed document runs the equivalent analysis under eIDAS and its own procedural rules. Neither court is bound by what the other jurisdiction's framework says about its own signatures, absent the treaty-level recognition that hasn't been agreed.
“Linking two trust registries makes it easier to check who signed. It doesn't decide who has to accept that signature in court.”
A checklist for contracts you're signing today
None of this makes cross-border deals with EU counterparties harder than they were in December. It means the signature technology was never the load-bearing part of enforceability, and this arrangement doesn't change that yet. A few things worth doing regardless:
- Write an explicit governing-law and dispute-resolution clause into every cross-border contract — don't rely on a court defaulting to a convenient answer.
- Keep a full audit trail of who signed, when, from where, and with what authentication method, independent of which signature tier applies. That's the evidence a court actually asks for once a dispute starts.
- Check the IT Act's First Schedule before assuming a document can be signed electronically at all. Some categories need wet-ink and registration regardless of where the counterparty sits.
- Treat the Trusted List link as a due-diligence convenience for verifying certificate issuers, not as a legal opinion on enforceability.
- Revisit this once the Digital India Act, pending since its 2023 draft, moves — that's the more likely point where a cleaner tier mapping to eIDAS becomes possible.
What could actually change this
The Digital India Act, intended to replace the IT Act, has been in draft form since 2023 and had not been introduced in Parliament as of this arrangement. Legal commentators have floated signature tiers closer to eIDAS's structure as one area it might address. Probably not before the Act itself moves past the draft stage, because a tiering change of that kind touches certificate issuance, liability and evidentiary rules across the whole IT Act framework, not only the signature section.
The more immediate path is technical: if the Trusted List link moves from expressed intent to a working integration, it narrows the due-diligence gap for anyone verifying certificates across the two regions. That's worth having. It's just a different thing from the mutual recognition treaty the January headlines implied.
The EU-India arrangement is a real, useful step in a narrow direction: two agencies teaching their systems to recognise each other's licensed certificate issuers. Treat it as that, and treat the governing-law clause in the next cross-border contract as the part still doing the actual work.
Frequently asked questions
Related reading
The Supreme Court upheld Section 63 BSA. Most audit trails still can't produce its certificate.
In May 2026 the Supreme Court upheld the BSA's dual-certificate rule for electronic evidence. Here's what it actually asks of your audit trail.
B2B stablecoin payments hit $6bn a month. In India, the same transfer is an FEMA violation waiting to happen.
Global B2B stablecoin volume is surging and traditional trade-finance firms are adopting it. India’s regulators are moving the opposite direction, and FEMA doesn’t recognise stablecoins as currency at all.
RBI's digital lending rules aren't a compliance patch. They're four permanent states in your loan engine.
RBI's digital lending framework reads like a disclosure checklist. In a loan-servicing codebase it's four states: who can touch the money, who's allowed on the platform, and two clocks it can't ignore.