Electronic signatures in Paraguay: what is legally valid, how to get one and how to verify it

Paraguayan law distinguishes an electronic signature in general from a qualified electronic signature. Both can have legal effect, but only the qualified signature is expressly given the same legal effect as a handwritten signature. This guide explains the legal consequences, F1/F2/F3 certificates, the current qualified providers, signing through the chip cédula or private providers, SIFEN and other uses, and how to validate, revoke and renew a certificate.

Electronic signatures in Paraguay: what is legally valid, how to get one and how to verify it

A scanned signature pasted into a PDF, clicking “I accept”, a cryptographically signed document and Paraguay’s new chip identity card are often described with the same words. Legally and technically, they are not the same thing.

Since Law No. 6822/2021, Paraguay has operated under a broader framework for electronic trust services. For an ordinary user, one distinction matters most: an electronic signature can have legal effect and evidentiary value, while a qualified electronic signature is expressly given the same legal effect as a handwritten signature.

That distinction determines when a simple electronic process may be enough and when a qualified certificate is required. It also explains why some transactions need only an account or electronic consent, while others require a chip card, cryptographic token or centrally managed signing service.

Three concepts to separate first

TermWhat it means in practiceLegal effect
Electronic signatureElectronic data attached to or logically associated with other electronic data and used by the signer to sign.Cannot be denied legal effect or admissibility merely because it is electronic or not qualified.
Qualified electronic signatureA signature based on a qualified certificate and created through a qualified signature-creation device or qualified infrastructure.Law No. 6822 expressly gives it the same legal effect as a handwritten signature.
Electronic seal / timestampRelated trust services used to establish origin, integrity or a reliable time.They do not automatically replace a person’s signature but can be crucial for company documents and proof of date.

The statute deliberately defines “electronic signature” broadly. A scanned signature or simple electronic acceptance is therefore not automatically worthless, but it is not automatically a firma electrónica cualificada either. The stronger statutory equivalence applies only when the qualified requirements are satisfied.

Why a qualified signature is legally stronger

Article 39 of Law No. 6822/2021 makes two points at the same time. First, legal effect and admissibility cannot be denied to an electronic signature solely because it is electronic or because it does not meet the requirements of a qualified signature. Second, the law expressly states that a qualified electronic signature has the same legal effect as a handwritten signature.

The distinction also matters in a dispute. A challenged ordinary electronic signature is assessed under the general evidentiary rules. For a qualified signature, the law instead provides for technical verification of the qualified certificate and qualified signature-creation process. If those checks are positive, authenticity is treated as established; in principle, the person alleging that the signature is false carries the burden of challenging it.

For electronic private instruments, the statute contains another important nuance: a qualified signature establishes authenticity of the signature and identity of the signer, but it does not automatically establish a legally certain date. Where the date itself needs stronger proof, a qualified electronic timestamp becomes relevant.

For electronic public instruments, the law expressly requires a qualified electronic signature. Specific transactions can still have special formalities: Law No. 6822 itself excludes situations in which another law, the nature of the transaction or particular requirements make electronic form incompatible.

F1, F2 and F3: three practical certificate models

Paraguay’s public-key infrastructure uses the labels F1, F2 and F3 for qualified signing certificates. They are not three simple grades of legal validity. All can be qualified certificates; the practical difference is mainly the intended use and how the signing key is held and managed.

TypeTypical usePractical model
F1Primarily tax-related applicationsUsed, among other things, as a qualified tax certificate for tax-administration systems.
F2General qualified signingThe private key is typically held on a qualified physical device such as a smart card or cryptographic token. The Police chip cédula uses F2.
F3Centralised qualified signingSigning data are managed in qualified infrastructure operated by the provider, allowing signing without the user carrying a USB token in some implementations.

The right option depends on the use case. A taxpayer who only needs e-Kuatia’i should first check the certificate path provided for that tax process. Someone regularly signing contracts, SIARA documents or other PDFs may need a more general F2 or F3 solution.

Who may issue qualified certificates?

The Ministry of Industry and Commerce (MIC), through its electronic-commerce authority, maintains the official trust list. On 1 October 2026, seven qualified trust-service providers are listed as authorised to issue qualified electronic-signature certificates:

ProviderCurrently listed signature types
VIT S.A.F1, F2, F3
CODE100 S.A.F1, F2, F3
Documenta S.A.F1, F2, F3
Ministry of the Interior / National PoliceF2
Confirma S.A.F1, F2, F3
ITTI S.A.E.C.A.F1, F3
SOS Tecnología y Gestión de Información Ltda.F1, F2, F3

The official list matters more than a provider’s advertising. A qualified provider may start offering a qualified service only once the qualification appears on the trust list. Because providers and authorised services can change, check acraiz.gov.py again before buying a certificate.

Route 1: a qualified signature on the new chip cédula

The most visible new route is the electronic cédula issued by the Identification Department of the National Police. The Ministry of the Interior has itself been a qualified trust-service provider since 2023 and may issue F2 certificates through Identificaciones.

An important caveat: having a chip cédula does not necessarily mean an active signing certificate is installed on it. Portal Paraguay recommends checking the card with a smart-card reader or asking the MITIC desk at the central Identificaciones office to verify the certificate.

If you do not yet have a chip cédula, the current official guidance says to request the qualified certificate expressly when renewing the identity card. At collection, the holder should set a four-digit PIN. A person who already has the chip card but no certificate can request installation through Identificaciones.

Installation of the certificate on an existing chip card is currently offered without an additional fee, although the ordinary document fee applies if the cédula itself has to be renewed. By law, a qualified certificate may be valid for no more than four years, so the certificate and the identity card do not necessarily share the same lifecycle.

What is actually needed to sign with the cédula

The card alone is not enough on a computer. Current Identificaciones instructions require:

  • a chip cédula with an active qualified certificate;
  • the four-digit PIN created when the card was collected;
  • a computer or notebook;
  • a smart-card reader compatible at least with PC/SC and ISO 7816;
  • the relevant reader/card drivers and management software;
  • Paraguay’s public-key-infrastructure certificates;
  • signing software such as Adobe Acrobat Reader, JSignPDF or another PKCS#11-compatible program.

Identificaciones provides installers for Windows, macOS and Linux at its download page.

Signing a PDF with the chip cédula

  1. Connect the smart-card reader and confirm that the operating system recognises it.
  2. Insert the cédula and check that the certificate, holder name, issuer, serial number and validity period appear.
  3. Open the PDF in compatible software.
  4. In Adobe Acrobat Reader, for example, choose the certificate/digital-sign option.
  5. Select the certificate issued by the Ministry of the Interior.
  6. Confirm the signature area or appearance and save the file.
  7. Enter the four-digit PIN. The cryptographic signature is created at this point.

The visible image of a signature inside the PDF is not what creates qualified status. The legally relevant part is the cryptographic signature data bound to the document. A PDF can be properly qualified-signed without displaying a pretty autograph; conversely, a pasted image of a handwritten signature does not make the document qualified-signed.

Route 2: a private provider, hardware token or centralised signing

The chip cédula is not the only route. Qualified private providers offer F1, F2 and/or F3 certificates according to their authorisations. In an F2 implementation, the private key is typically held on a qualified token or smart card. With F3, qualified key infrastructure is managed centrally by the provider and signing is triggered through its authorised process.

That can be useful for businesses or people who need to sign from more than one device or want to avoid a local card reader. Several providers are now explicitly authorised to identify applicants remotely by video for specified certificate types. Requirements, prices, included signature volumes and validity periods differ by provider and product.

Before buying, compare more than price: certificate type, accepted applications, hardware dependence, signature quotas in centralised plans, renewal and revocation procedure, and whether the target platform accepts the particular certificate.

Route 3: free tax certificates through DNIT

There is a special route for smaller electronic invoicers. The National Directorate of Tax Revenue (DNIT) states that users of e-Kuatia’i can obtain a qualified electronic-signature certificate free of charge through designated tax offices. It is used to sign the electronic tax documents submitted to the National Electronic Invoicing System (SIFEN).

For the larger e-Kuatia model using a company’s own software, DNIT likewise requires a qualified certificate and directs taxpayers to MIC-authorised trust-service providers. A tax-oriented certificate should therefore not automatically be assumed to replace a certificate needed for every other signing workflow.

Where qualified signatures are used today

Current practical uses include:

  • SIFEN / electronic invoicing: electronic tax documents are cryptographically signed;
  • SIARA: certain company and registry filings are submitted with electronic signatures;
  • BECAL and other public platforms: Portal Paraguay identifies qualified signing as part of some end-to-end digital applications and declarations;
  • contracts, declarations, permits, authorisations and powers: where the specific transaction permits electronic form;
  • electronic files and administrative/judicial decisions: the statute expressly uses qualified signatures for numerous official records;
  • electronic transferable records and promissory-note systems: qualified signatures and timestamps form part of the integrity and evidence chain.

Technical capability does not mean every authority or counterparty must accept the same signature in every context. Public bodies may impose additional objective conditions for their procedures, and special formal requirements can still apply.

How should a received signature be validated?

Do not judge a signed document only by whether Acrobat displays a green icon or whether a visible signature graphic appears. For a qualified signature, the relevant questions include:

  • Was the supporting certificate qualified at the time of signing?
  • Was it issued by a qualified trust-service provider?
  • Was it valid and not revoked when the signature was created?
  • Does the certificate identify the claimed signer?
  • Has the document remained unchanged since signing?
  • Was the signature produced through a qualified signature-creation process?

These are substantially the checks required by Article 47 of Law No. 6822. With the chip cédula, local PDF software may need Paraguay’s root certification chain installed before it can validate the signature correctly. Identificaciones publishes a separate validation guide for that purpose.

A certificate that expires later does not by itself mean the signature was invalid when created: the statute expressly tests whether the certificate was valid at the time of signing. For long-lived documents, however, qualified timestamps and qualified preservation services can make later verification more robust.

Lost token, compromised PIN or expired certificate

A signing certificate should not be treated like an ordinary password. If a token is lost, misuse is suspected or the signing credentials are no longer under the holder’s exclusive control, the certificate should be suspended or revoked promptly through the issuing provider.

The law expressly permits revocation at the signer’s request, among other grounds. Once a qualified certificate is revoked, that revocation is final; the certificate cannot become valid again. A new certificate must then be issued.

For the chip cédula, Identificaciones directs users who forget the PIN or have an expired certificate back to its service desks. Private providers follow their own published certification practices.

Companies: a person’s signature or an electronic seal?

An electronic signature is created by a natural person. For legal entities, the statute also provides for an electronic seal, whose purpose is primarily to establish the origin and integrity of data issued by an organisation.

The distinction has a useful legal consequence. If a transaction requires a qualified electronic seal from a legal entity, the qualified signature of its authorised representative must also be accepted. The reverse is not true: where the law or procedure requires the qualified signature of a person, a company seal cannot simply replace it.

Identidad Electrónica is not the electronic signature

Paraguay’s Identidad Electrónica is the government authentication account used for Portal Paraguay and connected systems. Its primary question is: who is logging in?

A qualified electronic signature answers a different question: who signed this exact electronic document, and has it remained unchanged since?

A platform can therefore require Identidad Electrónica for login and then require a qualified signing certificate for the actual legal act. One does not replace the other.

Which route fits which need?

NeedReasonable starting point
Only access to Portal Paraguay and public online servicesIdentidad Electrónica; no qualified certificate is needed merely to log in
Occasional qualified PDF signing and you are already renewing your cédulaCheck the F2 certificate on the chip cédula
Frequent remote signing from different devicesCompare F3 services from qualified providers
Prefer a USB/local hardware solutionF2 token from an authorised provider
Small taxpayer using e-Kuatia’iCheck DNIT’s free certificate route first
Own SIFEN/e-Kuatia softwareCheck DNIT requirements and an authorised qualified provider

Five checks before signing

  1. What type of signature is actually required? Not every process needs a qualified signature.
  2. Is the issuer currently qualified? Check MIC’s trust list, not only the provider’s website.
  3. Is the certificate appropriate for the task? F1, F2 and F3 have different practical models.
  4. Do you need a legally stronger date? A qualified timestamp can matter for important contracts.
  5. Can the recipient validate it? For cross-border use or third-party IT systems, confirm accepted certificates and formats in advance.

Information checked: 1 October 2026. Provider lists, certificate types, pricing, authorised identification methods and technical requirements can change. Before paying for a certificate, recheck Paraguay’s official trust list and the exact requirements of the system in which the signature will be used.

Official sources

Share WhatsApp Facebook LinkedIn

Sources (9)

Updated: