What the Standards Prove: PAdES, eIDAS, C2PA and PDF/A
Only one of these detects a change to a document. What each standard actually asserts, where signatures stop covering the file, and why a missing set of content credentials proves nothing at all.

A supplier sends a PDF and tells you it is "digitally signed and PDF/A compliant, so it can't have been altered". Two standards, both real, both correctly named — and the conclusion is wrong. One of them proves something about change; the other is a filing format with no security properties at all.
This is not an obscure confusion. It shows up in procurement requirements, in RFP responses, and in courtrooms. So here is what each of the relevant standards actually asserts, in the order of how much weight it can carry.
Key takeaways
- Only cryptographic signatures detect change. Everything else on this page is about format, archiving or disclosure.
- A signature proves the bytes it covers are unchanged — not that the signer is who they claim, and not that content added afterwards is covered.
- PDF/A is an archiving profile. It says nothing whatsoever about authenticity.
- C2PA proves what a file says about its own history, signed by whoever made that claim. Its absence proves nothing at all.
PDF itself (ISO 32000)
The PDF format has been an ISO standard since 2008; PDF 2.0 is ISO 32000-2. The specification defines how a file is structured — objects, pages, fonts, content streams, incremental updates.
What it proves about authenticity: nothing directly. But knowing the specification is what makes forensic analysis possible in the first place. The reason an edited PDF often still contains its earlier text is that the standard permits incremental updates, and the reason a signature can cover only part of a file is that the standard defines a ByteRange. Nearly every finding in a structural report is an argument about how the file departs from, or exploits, this specification.
The PDF Association publishes accessible material on it, which is worth having to hand when you are trying to decide whether a structural oddity is suspicious or just how one particular producer behaves.
Digital signatures and PAdES
This is the only entry on this page that detects tampering.
A digital signature performs a cryptographic operation over a defined range of the file's bytes. If any of those bytes change afterwards, verification fails. That is a strong, checkable property, and it does not depend on trusting the person who shows you the document.
PAdES — PDF Advanced Electronic Signatures, standardised by ETSI — profiles how these signatures are built inside PDFs, with particular attention to long-term validity: keeping a signature verifiable years later, after certificates have expired, by embedding revocation data and timestamps.
What it proves: that the covered bytes are unchanged since signing, and that whoever held the private key signed them.
What it does not prove, and these matter:
- Identity. A self-signed certificate verifies perfectly and identifies nobody. Identity comes from the certificate chain and whether you trust the authority at the top of it.
- Coverage. Content appended after signing is not covered by the signature. The signature can verify while the document a reader sees differs from the document that was signed. This is the finding people most often miss, and it is why a good report states the ByteRange explicitly.
- Time. The signer's own clock is not evidence. An RFC 3161 timestamp from an independent authority is what proves when.
- Truth. A validly signed lie is a lie with a valid signature.
Read the verification detail, not the green tick. Most readers show a tick for "the cryptography checks out" and place the interesting caveats behind another click.
eIDAS and legal weight
The EU's eIDAS regulation defines three tiers of electronic signature — simple, advanced, and qualified — with a qualified signature carrying legal effect equivalent to a handwritten one across member states, backed by a trust-service provider on an official list.
What it proves: a legal status, resting on the technical properties above plus a vetted issuer. When you actually have a qualified signature from a listed provider, you have both cryptographic integrity and a verified signer identity, which is about as good as document evidence gets.
Where it is misread: "electronic signature" in the loose sense — a typed name, an image of a scrawl, a click-to-agree box — is a simple electronic signature. It is legally meaningful in most jurisdictions. It detects nothing. Somebody saying "it's an eIDAS signature" without naming the tier has told you almost nothing.
PDF/A
An ISO profile for long-term archiving. It requires fonts to be embedded, forbids external dependencies, forbids encryption, and generally insists a file be self-contained so it renders identically in fifty years.
What it proves about authenticity: nothing. Producing a PDF/A file is a save option. A forged document can be PDF/A compliant, and frequently is, because whoever built it used a template that happened to be conformant.
It appears in this article only because "PDF/A compliant" gets quoted as though it were a security property in procurement documents with some regularity. It is a preservation property. Useful, unrelated.
C2PA and Content Credentials
The newest entry, and the most interesting. C2PA is an open specification for attaching signed provenance to media: a manifest recording how a file was created and what edits were applied, cryptographically signed by the tool that made the claim, with each edit chaining onto the last. Camera makers, editing tools and several generative-AI systems have adopted it.
What it proves when present and valid: that a specific signer asserted a specific history, and that the manifest has not been altered since. On a chain of edits, it can show that an image came from a particular camera and passed through particular tools.
What it does not prove:
- That absence means anything. Most files in the world carry no manifest. A stripped manifest and a file that never had one are indistinguishable, and stripping is trivial. C2PA is evidence when present, never when absent.
- That the content is true. A signed manifest on a photograph of a staged scene is a well-provenanced photograph of a lie.
- That the signer is trustworthy. Same problem as any signature: the manifest is only as good as the key and whoever holds it.
The direction of travel is genuinely positive, and provenance-by-default would change this field. But the deployment reality in 2026 is that a verification process cannot yet lean on it, and any product that treats missing content credentials as a negative signal is going to be wrong constantly.
Two standards people ask about that are not what they hope
Blockchain notarisation. Publishing a document's hash to a public ledger proves that the hash existed at a point in time. That is a real property and it is the same one an RFC 3161 timestamp gives you, usually with less ceremony. It proves nothing about the document's contents, its authorship, or whether the thing it describes ever happened.
Certified or notarised copies. A notary attests that a copy matches an original they were shown. That is a statement about two pieces of paper in a room, not about whether the original was genuine. Our guide covers how notarial acts are verified, and how forged stamps get caught.
Putting it together
If you need to be able to prove a document has not changed since issue, there is one answer: have it digitally signed, with a certificate from an authority you can validate and an independent timestamp, and check on receipt that the signature covers the whole file.
Everything else — format profiles, archiving conformance, ledger anchoring, notarisation, provenance manifests — is either about something other than tampering, or is evidence that only counts when it happens to be present.
Which is the entire reason forensic analysis exists. The overwhelming majority of documents any business receives carry no signature, no manifest and no trusted timestamp. For those, you are reasoning from structure, content and corroboration — inference rather than proof, done carefully and stated honestly.
Frequently asked questions
Does a digitally signed PDF prove it has not been altered?
It proves the bytes covered by the signature are unchanged. Content appended after signing is not covered, so a document can verify successfully while showing a reader something different from what was signed. Always check what the signature's ByteRange actually covers.
Is PDF/A more secure than a normal PDF?
No. PDF/A is an archiving profile that makes files self-contained and stable over time. It carries no security or authenticity properties, and a forged document can be fully PDF/A compliant.
Does C2PA stop document fraud?
Not on its own. When a valid manifest is present it is strong evidence of a file's history, but manifests are trivially stripped and most files never had one, so their absence means nothing. It is a positive signal, never a negative one.
What is the difference between an advanced and a qualified electronic signature?
Under eIDAS, an advanced signature is uniquely linked to the signer and detects subsequent changes. A qualified signature adds a certificate from a trust-service provider on an official EU list and a qualified signature-creation device, which gives it legal effect equivalent to a handwritten signature across member states.
Check the PDF you are holding
Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.
Keep reading
The Document Forensics Glossary, in Plain English
Fifty-plus terms from PDF structure, image forensics and the signature world, defined for the person reading a forensic report rather than writing one — including what each one does not mean.
Apostille vs. Legalization: Verifying Documents Across Borders
International documents carry authentication chains most reviewers have never been taught to read. How apostilles and consular legalization work — and how both get faked.
Chain of Custody for Digital Documents: Making Evidence Hold Up
A forensic finding is only as strong as the custody story behind the file. Hashes, handling, and documentation — how to keep digital document evidence defensible.