Under Türkiye's Electronic Signature Law No. 5070, a secure electronic signature has the same legal effect as a handwritten signature. It must rely on a qualified electronic certificate (NES, nitelikli elektronik sertifika) from a certificate service provider authorised by the Information and Communication Technologies Authority (BTK), and it must be created with a secure signature-creation device such as a smart card, USB token, mobile SIM or a Turkish ID card loaded with a certificate. Transactions that the law subjects to official form or a special ceremony, and most guarantee contracts, are excluded.
Documents that must stay verifiable for years should carry a timestamp and a long-term profile such as PAdES B-LTA.
This article is general information, not legal advice.
Types of electronic signature and their legal weight
Not everything called an "e-signature" carries the same weight. A signature drawn on a tablet, a scanned signature image, a tick box and an SMS one-time code are all electronic signatures in the broad sense. Only a secure electronic signature is treated as equal to a wet signature.
Article 4 of the Law sets four conditions. A secure electronic signature must:
- be linked exclusively to the signatory
- be created with a secure signature-creation device under the signatory's sole control
- identify the signatory on the basis of a qualified electronic certificate
- make any later change to the signed data detectable
| Type | How it is created | Legal weight in Türkiye |
|---|---|---|
| Simple electronic signature | Click-to-accept, scanned image, SMS code, drawn signature | Can be submitted as evidence. Its weight depends on the facts and the court's assessment |
| Secure electronic signature (with NES) | Smart card, token or Turkish ID card + PIN | Same effect as a handwritten signature. Properly e-signed data counts as a deed (senet) in civil proceedings |
| Mobile signature | Operator SIM carrying an NES + PIN | A secure electronic signature, because it relies on an NES |
The Turkish Code of Obligations (No. 6098, art. 15) also states that a secure electronic signature has all the legal consequences of a handwritten one. Under the Code of Civil Procedure (No. 6100, art. 205), data created with a secure electronic signature counts as a deed. In practice, most contracts that require written form can be validly signed with an NES.
For readers who know the EU framework: a Turkish secure electronic signature is broadly comparable to a qualified electronic signature (QES) under eIDAS, and an NES to a qualified certificate. Türkiye is not part of eIDAS, though. Foreign certificates are recognised under Law 5070's own rules, without automatic EU equivalence.
What is an NES and how do you get one?
A qualified electronic certificate binds the signatory's signature-verification data (their public key) to their identity. In Türkiye, NES certificates are issued to natural persons by electronic certificate service providers (ESHS) authorised by the BTK. Kamu SM, part of TÜBİTAK BİLGEM, serves public-sector staff. Commercial providers serve businesses and individuals.
Getting a certificate usually involves these steps:
- apply to a provider and complete identity verification, in person or through remote methods the regulation permits
- sign the certificate commitment form
- have the certificate installed on a signature device such as a card, token, SIM or ID card
- install the signing software and card-reader drivers
Certificates are time-limited and usually valid for one to three years. An expired or revoked certificate cannot create new signatures. Signatures made while it was valid stay verifiable, provided the right signature profile was used.
Signing with the Turkish ID card (TCKK)
The chip-based Turkish ID card (TCKK) can act as a secure signature-creation device, so no separate token is needed. According to the General Directorate of Population and Citizenship Affairs (NVİ):
- the NES is obtained from a BTK-authorised provider, which charges for the certificate
- the certificate is loaded onto the card at Nüfusmatik kiosks in civil registry offices, and NVİ charges no separate fee for loading
- up to three e-signature certificates can be on one card at the same time
- signing requires a card reader and the card's signature PIN (depending on the signing app, NFC-capable phones may also work)
For a business, this means employees and customers can sign with a card they already carry. Token distribution, replacing lost tokens and driver problems largely go away. Sign handles ID-card and NES signing, RFC 3161 timestamps and the PAdES-B-LTA profile in the same signing workflow.
Timestamps
Article 3 of Law 5070 defines a timestamp as a record, verified by the certificate service provider's electronic signature, that establishes when electronic data was created, modified, sent, received and/or recorded. Most services implement it with RFC 3161 (Time-Stamp Protocol):
- A hash of the signed document is computed.
- Only the hash goes to the timestamp authority. The document itself is never sent.
- The authority binds the hash to a trusted time, signs the result with its own certificate and returns a token.
Computer clocks are easy to change, so the "signing time" field inside a signature proves little on its own. A qualified timestamp is the standard way to show that a signature was made while the certificate was valid, even if the certificate is later revoked or expires.
PAdES levels: B-B, B-T, B-LT and B-LTA
For PDF documents, signature formats follow the PAdES baseline profiles in ETSI EN 319 142. Each level builds on the previous one:
| Level | What is added | What it proves | Typical use |
|---|---|---|---|
| PAdES B-B | Signature, signer certificate, signed attributes | Who signed and whether the document changed | Short-lived internal documents |
| PAdES B-T | Trusted timestamp on the signature | Independent proof of signing time | Sensible minimum for most commercial contracts |
| PAdES B-LT | Certificate chain, OCSP responses and CRLs embedded in the file | Validation even when the CA's services are unreachable | Documents kept for years |
| PAdES B-LTA | Document (archive) timestamp, renewed as needed | Validation beyond certificate lifetimes and algorithm ageing | Contracts, HR files, archives, official correspondence |
The terms ES-BES, ES-T, ES-X-L and ES-A are still common in Türkiye. They are the equivalents of these levels in the older ETSI CAdES terminology. XAdES (for XML) and CAdES (for arbitrary binary data) use the same level structure.
What cannot be signed electronically
The second paragraph of Article 5 of Law 5070 sets out two exceptions:
- Legal transactions that the law subjects to official form or a special ceremony. These require an official such as a notary, land registry officer or marriage officer. Examples:
- transfer of real estate at the land registry, and real-estate sale promise agreements drawn up by a notary
- official wills, inheritance waiver agreements and lifetime maintenance contracts
- ceremony-bound acts such as marriage
- Guarantee contracts. Guarantees such as personal suretyships cannot, as a rule, be concluded with a secure electronic signature. This exception has been narrowed twice. Law No. 6728 (2016) carved out bank letters of guarantee, and Law No. 7349 (2021) carved out surety bonds issued by insurance companies established in Türkiye.
The distinction matters because written form and official form are different things. Lease, service, employment, NDA and supply contracts can be validly signed with an NES, whether they need written form or no form at all. Sector rules in areas such as banking or capital markets may add requirements, so check current legislation for critical transactions.
Long-term validation: why signatures stop verifying
A signature that validates cleanly today may show "could not be verified" five years from now. There are three reasons:
- Certificate lifetime: the signer's certificate expires, and OCSP/CRL services may stop answering for old certificates.
- Timestamp certificates: the timestamp authority's own certificate is also time-limited and gets renewed.
- Cryptographic ageing: hash and signature algorithms that are considered secure today may weaken over time.
To manage these risks:
- Sign at PAdES B-T or higher, with a timestamp.
- Embed the validation data (chain, OCSP, CRL) at signing time to reach B-LT.
- Add a document timestamp to archive copies to reach B-LTA.
- Add a fresh archive timestamp before the underlying certificate expires or its algorithm weakens.
- Verify the file with an independent validator as well as with the signing party's own software.
Frequently asked questions
Is a printout of an e-signed PDF equivalent to a wet-signed document?
No. The legal value of a secure electronic signature is in the electronic file and the signature data inside it. A printout is only a copy. Keep the signed electronic file and present that file if you ever need proof.
How do I load an e-signature onto my Turkish ID card?
First apply for a qualified electronic certificate from a BTK-authorised provider. Then have it loaded onto your card at a Nüfusmatik kiosk in a civil registry office. Loading is free, and you pay the provider for the certificate. To sign, you need a card reader and your signature PIN.
Is an e-signature without a timestamp invalid?
No. An NES-based signature is still a secure electronic signature without a timestamp. Without one, though, it is much harder to prove when the signature was made and that the certificate was valid at that moment. That is why B-T or higher is recommended for commercial documents.
Can a personal guarantee be signed electronically in Türkiye?
As a rule, no. A suretyship is a guarantee contract, so the Article 5 exception applies. The only carve-outs are bank letters of guarantee and surety bonds issued by insurance companies established in Türkiye.
When do I need PAdES B-LTA?
When a document must remain verifiable for longer than the signer's certificate is valid. Typical examples are contracts, personnel files, records with long statutory retention periods and corporate archives.
- #e-signature
- #law 5070
- #qualified certificate
- #timestamp
- #pades