- A Certificate Authority (CA) verifies applicants and issues digital certificates that connect an identity with a public key.
- Digital certificates and digital signatures work together to let recipients check who signed a document and whether the signed content has been changed.
- Singapore’s Electronic Transactions Act (ETA) recognises electronic signatures and sets out specific provisions for secure electronic signatures and digital signatures.
- Sign with Singpass lets eligible Singapore Citizens, Permanent Residents, and FIN holders digitally sign documents through the Singpass app.
- Businesses signing documents across Singapore and other markets should check certificate trust, identity verification, document integrity, and how recipients can validate the signature.
When a company signs a contract electronically, the signature itself is only part of what the recipient may need to verify. For certificate-based digital signatures, a Certificate Authority (CA) issues the digital certificate that connects the signer’s identity with a public key.
Most explanations of Certificate Authorities focus on SSL certificates and website security. That is one common use of a CA. The same concept also applies to digital signatures, where businesses need to know who signed a document and whether the file was changed afterwards.
Singapore adds another piece to the picture through Singpass. Eligible users can use the Singpass app to sign documents through Sign with Singpass, while Singapore’s legal framework sets out how electronic and secure electronic signatures are treated. Understanding how these pieces fit together makes it easier to choose the right signing method for business documents.
What Is a Certificate Authority?
A Certificate Authority (CA) is a trusted entity that issues and revokes digital certificates. According to NIST, a CA is responsible for issuing and revoking public key certificates.
A digital certificate contains information that links an entity with a public key. Before issuing the certificate, the CA carries out identity checks based on its certification policies and procedures.
The CA does not sign your contract for you. Its role comes earlier. It provides the certificate that others can use to check whether a public key belongs to the person or organisation named in the certificate.
CAs are used for different purposes, including website certificates, software signing, and digital signatures. In a document signing context, the certificate is part of the mechanism that lets another party verify the signature.
How Does a Certificate Authority Work When Signing a Document?
Take a simple example. A company in Singapore sends a supplier agreement to its finance director for signing. The director uses a certificate-based digital signature rather than inserting an image of a handwritten signature into the PDF.
- The signer is verified. The relevant identity checks are completed before a certificate is issued or used for signing.
- A digital certificate is issued. The certificate contains information linking the signer or entity to a public key.
- The document is signed. Cryptographic keys are used to create the digital signature.
- The signature is checked. The recipient’s software can check the signature, certificate information, and whether the document has changed.
- The certificate can be checked again later. Its validity and revocation status can affect whether the signature can still be trusted.
The exact process depends on the signing service and certificate provider. What stays the same is the basic idea: the certificate gives the recipient information they can use to check the signer and the signature.
What Is the Difference Between a CA, Digital Certificate, and Digital Signature?
These terms are often used together, but they refer to different things.
| Term | What it is | Role in digital signing |
|---|---|---|
| Certificate Authority (CA) | An entity that issues and revokes digital certificates | Provides the certificate used to establish trust in the signer’s public key |
| Digital certificate | An electronic credential that links an identity with a public key | Lets recipients check who the certificate belongs to |
| Digital signature | A cryptographic signature applied to electronic data | Lets recipients verify the signature and detect changes to the signed content |
A useful way to remember the relationship is simple: the CA issues the certificate, the certificate identifies the public key, and the digital signature is created using cryptographic keys.
For a wider explanation of how digital signatures work in Singapore, see our guide to digital signatures in Singapore.
What Does a Certificate Authority Have to Do With Singapore?
Singapore’s Electronic Transactions Act 2010 provides the legal framework for electronic records, electronic signatures, and electronic contracts. The Act also contains specific provisions for secure electronic signatures and digital signatures.
Singapore also has a regulatory framework for Certification Authorities. IMDA maintains information on Public and Accredited Certification Authorities in Singapore.
As of September 2026, IMDA lists the Government Technology Agency of Singapore (GovTech) as a Public Certification Authority. IMDA also lists Netrust Pte Ltd as an Accredited Certification Authority.
This gives businesses a local reference point when they assess certificate-based signing. Legal and IT teams can look at the certificate issuer, the identity checks involved, and the type of signature produced instead of judging a signing service only by its user interface.
How Does Singpass Fit Into Digital Signing?
For people working in Singapore, Singpass is one of the most familiar ways to establish digital identity. GovTech describes Singpass as Singapore’s national digital identity, and the Singpass app can be used to digitally sign documents through services that support Sign with Singpass.
Eligibility also extends beyond Singapore Citizens. GovTech states that Singapore Citizens, Permanent Residents, and Foreign Identification Number (FIN) holders aged 15 and above are eligible for Singpass.
Sign with Singpass is separate from the idea of a Certificate Authority. Singpass provides the identity and signing service used by the person, while the certificate used in the signing process comes from Singapore’s certification infrastructure. GovTech states that signatures made with Sign with Singpass are regarded as Secure Electronic Signatures (SES) under the Electronic Transactions Act.
This is particularly useful for companies with a mix of local and foreign employees. A Singapore-based company may have directors, employees, consultants, or contractors who hold FINs rather than Singapore citizenship or permanent residency. Their eligibility for Singpass can therefore matter when the company sets up a signing process.
Why Does the Certificate Matter When a Business Signs a Contract?
Consider what happens after a contract is signed. The document may be downloaded, emailed to another party, stored in a document system, or reviewed months later by Legal or Compliance. The recipient needs more than the appearance of a signature if the document has to be checked later.
A certificate-based signature gives the recipient technical information that can be used to check the signer and the document. Depending on the signing system, the recipient may be able to inspect the certificate, its issuer, its validity, and the signature status.
Document integrity is another part of the check. When a digitally signed PDF is altered after signing, the signature validation process can indicate that the document is no longer in the same state as when it was signed.
These checks become especially useful when a document moves between companies or countries. A Singapore company may sign an agreement with a customer in Australia, a supplier in Malaysia, or an overseas parent company. Each party may have its own expectations for identity verification and signature validation.
What Is AATL and Why Does It Matter for Signed PDFs?
Businesses that exchange signed PDFs may come across another name: Adobe Approved Trust List (AATL).
AATL is Adobe’s list of trusted certificates and trust service providers used for digital signing. Adobe states that certificates from AATL members can be trusted when recipients open digitally signed documents in Adobe Acrobat and other supported Adobe products.
AATL is different from Singapore’s ETA and IMDA framework. It is an Adobe trust programme that affects how certificates are recognised in Adobe products.
That distinction matters for companies sending signed PDFs to customers, suppliers, or other external parties. A signature can meet the requirements of the signing process while the recipient may still have questions about how the certificate appears in their software. Certificate recognition can therefore be part of the technical checks a business makes before choosing a signing service.
What Should Businesses Check Before Choosing a Digital Signing Service?
A business does not need to become a PKI expert to assess a signing service. Legal, Procurement, IT, and Compliance teams can start with a few practical questions.
| Question | What to look for |
|---|---|
| How is the signer identified? | Check whether the service uses Singpass, another identity verification method, or a combination of controls. |
| Who issues the signing certificate? | Identify the CA or certificate provider behind the signing method. |
| Can the recipient verify the signature? | Check what information appears when the recipient opens or validates the signed document. |
| Can the recipient detect changes? | Confirm that the signing method protects the integrity of the signed document. |
| Will the signature work for overseas recipients? | Check certificate recognition, recipient software, and the requirements that apply in the other jurisdiction. |
| What happens after signing? | Look at document storage, audit records, access control, and how signed contracts are retrieved later. |
The last question is easy to overlook. A company may sign hundreds or thousands of documents each year, so Legal and Operations teams also need a practical way to find the final signed copy, check its history, and know who signed it.
How Does Mekari Sign Support Digital Signing in Singapore?
Mekari Sign supports Sign with Singpass for document signing in Singapore. The signer completes the signing process through the Singpass app, while the document is prepared and sent through Mekari Sign.
Mekari Sign also offers certificate-based signing options for documents that need digital certificates recognised outside a local signing environment. Its GlobalSign certificates are recognised in Adobe’s Approved Trust List, making them suitable for workflows where recipients use Adobe products to validate signed PDFs.
For a Singapore business working with customers, suppliers, employees, or partners overseas, the signing method can therefore be selected according to the people involved and the document being signed. Local Singpass signing can suit eligible Singapore-based signers, while certificate-based signing can be considered when document verification needs to work across markets.
Explore Mekari Sign for Singapore businesses to see the available digital signing options.
