An open grading scale for signed documents

Document Trust Grade

How strongly this file proves, on its own, who signed it and that it has not changed — and how long it will keep proving it, without the signing platform.

Current version 0.3.0 · pre-release, open for comment · published 2026-09-26

Why it exists

A signed document is only worth what it can prove. Most validation tools answer with a technical verdict (passed, indeterminate) that tells a specialist something and everyone else very little. It doesn’t say how strongly the signer is identified, whether the proof depends on the platform that produced the signature, or whether the document will still verify in ten years.

The Document Trust Grade exists to make that legible:

It measures verifiability, not legal validity. A low grade does not mean a document is not binding (see Rules for every grade).

How it works

Three questions in strict order: integrity (has it changed?), then trust (does the identity chain to a recognised trust regime?), then durability (will it still verify years from now without anyone's help?). This is a ladder of necessary conditions, not a points total — a file receives the highest grade whose conditions it meets in full, and one failed gate caps it regardless of everything else.

No letter is issued when there is no signature and no evidence package to assess, or the file cannot be read. This is never shown as F. F means we checked and the document failed; absence of proof is a different statement from disproof.

The scale

A+

Qualified, and built to last

The file proves who signed it and that nothing has changed, on its own, and the proof can be kept alive for decades. Embedded evidence packages and similar additions are shown alongside the grade; they do not change the letter.

All of

  • Everything required for A.
  • ETSI baseline B-LTA — the highest ETSI baseline level. An archive timestamp over the signature and its validation data lets the proof be renewed as certificates expire and cryptographic algorithms age.
  • That archive timestamp is a qualified electronic time stamp, issued by a qualified trust service, and it validates. A qualified time stamp carries a legal presumption of the accuracy of its date and time (eIDAS Article 41(2)).
  • No material change after signing — nothing that alters what the document shows, and nothing the validation engine cannot classify (adding validation data, timestamps or further signatures after signing is how a signed PDF is legitimately extended, and does not count).
A

Qualified and self-contained

This is what a properly signed document looks like. It proves who signed it, when, and that nothing has changed — on its own, offline, without the platform that made it.

All of

  • Validation outcome TOTAL_PASSED — intact, chain valid, not revoked.
  • Chains to a trust regime that reaches the top of the scale: an EU/EEA Trusted List, or a third-country list recognised through an eIDAS Article 14 mutual-recognition agreement.
  • Qualifies as a qualified electronic signature (QES) or qualified electronic seal (QESeal).
  • ETSI baseline B-LT or B-LTA — certificates and revocation data embedded, so the file verifies offline without contacting anyone.
  • The signature covers the whole document. Later revisions of the file are allowed only if they add nothing that changes what the document shows — adding validation data, timestamps or further signatures after signing is how a signed PDF is legitimately extended, and does not count.
B

Trusted and time-anchored

An independent third party has proven when this was signed, and it will keep verifying for years.

All of

  • Clears everything required for C, and carries a timestamp (ETSI B-T or better).
  • Misses at least one A requirement: the trust regime’s own ceiling is B; the validation outcome is not TOTAL_PASSED; it is an advanced rather than a qualified signature or seal; it is B-T rather than B-LT/B-LTA; or the signature does not cover the whole document.
C

Trusted, but decaying

Verifies today. There is no independent proof of when it was signed, and once the signing certificate expires or its revocation data goes offline, it may stop verifying entirely.

All of

  • Intact, and chains to a recognised trust regime.
  • Either ETSI baseline B-B — no timestamp, no embedded validation material — or a signature form outside the ETSI baseline profiles, whose durability cannot be assessed against them.
D

Provable file, unprovable signer

You can prove this file has not changed. You cannot prove who signed it. The result also states the grade the file’s own construction would reach with a certificate from a recognised provider — B or C — so a well-built document on a private root is not confused with a self-signed PDF.

All of

  • The signature verifies and the document is intact.
  • The certificate chains to no trust regime we recognise — self-signed, a private CA, or an unknown issuer.
E

A claim, without proof

Something was signed. This file cannot prove it. The proof sits with the signing platform, not with you. Nothing here is wrong — it is simply not self-proving.

All of

  • The file carries a signing claim — an attached evidence package, a platform audit trail, or a visual signature.
  • There is no cryptographic signature over the document that can be independently verified, so integrity cannot be checked at all.
F

Fails

This document does not prove what it claims. Do not rely on it without going back to the source.

Any of

  • The signed content has been modified since signing.
  • The signature is cryptographically invalid.
  • The signing certificate was revoked at the time of signing.

Trust regimes and their ceilings

Which trust regime a signer's certificate chains to sets the highest grade the document can reach.

RegimeWhat it isLegal weightCeiling
EU/EEA qualifiedMember-state trusted lists under eIDAS Article 22, where the service is granted for qualified certificates. Published by each member state, aggregated by the European Commission.Qualified signatures have the legal effect of a handwritten signature (eIDAS Article 25(2)); qualified seals carry a presumption of integrity and origin (Article 35(2)). Advanced signatures and seals — including on qualified certificates — carry neither.A+
Recognised third countryTrusted lists of countries holding an eIDAS Article 14 mutual-recognition agreement — currently Ukraine and Moldova.Legally equivalent to EU-qualified, by agreement.A+
EU/EEA non-qualifiedOn a member-state trusted list, but the service is not granted for qualified certificates.Supervised; no presumption.B
National regulatedA national trusted list operating outside eIDAS recognition — the Swiss list (ZertES, Swiss Accreditation Service) and the UK list (Information Commissioner's Office). Real supervision, real audit, no EU mutual recognition.Regulated nationally; no eIDAS presumption.B
Commercial programmeThe Adobe Approved Trust List — around 300 certificate authorities admitted under Adobe's published technical requirements and independent audit. This is what makes Adobe Acrobat show a green tick.Contractual, not statutory; no presumption.B
Not recognisedChains to no list we carry: self-signed, a private certificate authority, or an unknown issuer.None.D

Rules for every grade

A document's grade is the lowest of its signatures' grades — a contract is only as good as its weakest party's proof. Each signature also carries its own grade, so the roll-up is never opaque.

A grade is never shown as a bare letter. It always appears with the assurance level, the ETSI form, and the trust regime that vouched for it — the letter carries the legibility, the rest carries the defensibility.

This grade measures independent verifiability, not legal validity. Under eIDAS Article 25 an electronic signature cannot be denied legal effect merely for not being qualified. A low grade does not mean a document is not binding.

Every grade is dated and tied to a rubric version. A file graded A today can grade lower in five years as certificates expire — that decay is precisely what the long-term ETSI forms exist to prevent, and a grade is always a point-in-time assessment.

Tindom is not a qualified trust service provider. This grade is independent evidence, not a qualified validation service under eIDAS, and carries no legal presumption of its own.

Versions

The Document Trust Grade uses semantic versioning. A change that could lower any document's grade is a major version; one that can only raise grades is minor; wording that moves no grade is a patch. Versions 0.x are initial development: the thresholds are still being calibrated and grades issued under them are not a settled assessment. From 1.0 onward every published version is permanent and is superseded, never rewritten.

Published versions:

Changelog

0.3.0 · 2026-09-26 · major

A+ is redefined. It no longer depends on a closed list of markers — only one of the four could be assessed, and only in one signing platform’s evidence format, which a neutral scale should not privilege. A+ now means everything required for A, at the highest ETSI baseline level (B-LTA), with an archive timestamp that is a qualified time stamp and validates, and no material change after signing. Rung titles corrected: B-LTA is part of the ETSI standard, not beyond it, and A is not the standard "met in full". Embedded evidence packages are still shown with the result but no longer affect the grade.

Grades affected: Up: B-LTA documents with a qualified, valid archive timestamp that were held at A for want of a marker (A → A+). Down: a B-LTA document that reached A+ only through an embedded evidence package while its archive timestamp is not qualified (A+ → A). Major under the published policy for that reason, although no document validated so far is known to be affected.

0.2.0 · 2026-09-25 · major

The published text and the grading code now say the same thing. (1) Signature scope: validation data, timestamps and further signatures added after signing no longer count as content outside the signature — this is how PAdES B-LT and B-LTA are built, and under 0.1.0 it held every such PDF at B. (2) The A+ condition "no post-signing modification" now means no material change, for the same reason. (3) A multi-signature document now reaches A+ only if every signature meets A in full; before, the result could depend on signature order. (4) The B and C criteria list every reason a document lands there, and B requires a timestamp rather than a qualified one — the qualification of the timestamp was never checked. (5) A D now states the grade the file’s own construction would reach with a recognised certificate. (6) Corrected the legal weight of the EU/EEA qualified regime. Released as 0.2.0 because the scale is still pre-release; under the published policy the change is major, since one grade can go down.

Grades affected: Up: PAdES B-LT/B-LTA documents held at B only by signature scope (B → A); B-LTA documents held at A only by permitted additions can reach A+. Down: a multi-signature document graded A+ where one signature was held at A by something other than the missing marker (A+ → A). No change to the letter of a D. Separately, Norwegian BankID SDO files are no longer graded (previously a false F) and are refused as not yet supported.

0.1.0 · 2026-08-31 · initial release

First published version of the scale. Pre-release under semantic versioning: the thresholds have not yet been calibrated against a real distribution of documents, so they may still move.

Grades affected: Not applicable — no earlier version exists.

Stewardship

The Document Trust Grade is stewarded by Tindom, an independent validation service that is not a signing platform and does not issue certificates. The scale is published so that anyone can check a grade against the rules that produced it, and so that others — validators, signing platforms, trust service providers and relying parties — can adopt it and help shape it.

Before version 1.0 the scale is open for comment, including a proposal to make the grade jurisdiction-neutral and state legal recognition separately for each trust regime. Comments, corrections and questions are welcome at contact@tindom.se.