Home About Us Products Solutions Industries Resource Center Partners Support Contact
   Home > Products > CoSign > CoSign Regulatory Information

Legislation and Regulation Policies for Electronic and Digital Signatures

CoSign Regulatory Information

Here you will find regulatory information, including electronic signature directives and policies for digital signatures (standard electronic signatures), pertaining to the use of CoSign® digital signatures in various countries.

Compliance with digital signature directive legislation & regulations

For many organizations, it is critical to protect their data at all times with PKI-standard based methods that meet the toughest regulations. CoSign complies with the most stringent regulations recognized worldwide, allowing organizations to take advantage of this built-in capability and meet these regulations and policies for digital signatures.

CoSign adheres to the digital signature and data-integrity requirements of the following legislations, regulations and standards:

Legislation

» U.S. - Electronic Signature in Global and National Commerce Act (ESIGN)
» U.S. - Uniform Electronic Transactions Act (UETA)- adopted by 48 states
» U.S. - Digital Signature And Electronic Authentication Law (SEAL)
» U.S. - Government Paperwork Elimination Act (GPEA)
» U.S. - The Uniform Commercial Code (UCC)
» Canada - Uniform Electronic Commerce Act (UECA)
» UK - Electronic Communications Act 2000 (chapter 7)
» Europe - EU Directive for Electronic Signatures (1999/93/EC)
» Europe – EU VAT Directive
» China - Electronic Signature Law of the People's Republic of China

Industry Regulations and Standards

» Life Sciences - FDA's 21 CFR Part 11
» Healthcare - Health Insurance Portability and Accountability (HIPAA)
» Homeland Security - Public Law 108-390
» Finance - Financial Services Modernization Act of 1999 (Gramm-Leach-Bliley)
» Environmental - Cross-Media Electronic Reporting Regulation (CROMERR)
» Public Companies - Sarbanes Oxley Act of 2002
» BioPharma - Signatures and Authentication for Everyone (SAFE)
» Veterinary/Equine - USDA EIA (Coggins) Testing
» Aviation - FAA's CFR Title 14 - This includes support for: air carriers, operators, persons performing airmen certification, individuals performing maintenance or preventive maintenance, repair stations, and aviation maintenance technical schools.
» European Telecommunications Standards Institute (ETSI)
» ISO (9001:2000)

CoSign protects your business in a court of law and will not be questioned for compliance.

CoSign certifications for Digital Signature Directives

» CoSign is FIPS 140-2 Level 3 validated.
» CoSign is SAFE BioPharma certified.

CoSign also follows the internationally approved Common Criteria security standard (ISO/IEC 15408), by using smartcards that are Common Criteria CWA 14169 certified within the CoSign hardware enclosure. The Common Criteria SSCD validation provides compliance with EU Electronic Signature Directives (European Union Directive 1999/93/EC on Electronic Signature).

Typical legislation requirements for Digital Signature Directives

Digital signature regulations vary from country to country. Taking the European Electronic Signature Directive (EC Directive 99/93 on Electronic Signatures) as an example, the requirements for a standard (advanced) Electronic Signature are:

a it is uniquely linked to the signatory;
b The signature-creation-data used for signature generation cannot, with reasonable assurance, be derived and the signature is protected against forgery using currently available technology;
c it is created using means that the signatory can maintain under his sole control; and
d it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable;

Is CoSign a Secure Signature Creation Device (SSCD)?

The European Directive (EC Directive 99/93 on Electronic Signatures) defines SSCD as:

1. Secure signature-creation devices must by appropriate technical and procedural means to ensure at the least that:

» The signature-creation-data used for signature generation can practically occur only once, and that their secrecy is reasonably assured;
» The signature-creation-data used for signature generation cannot, with reasonable assurance, be derived and the signature is protected against forgery using currently available technology;
» The signature-creation data used for signature generation can be reliably protected by the legitimate signatory against the use of others.

2. Secure signature-creation devices must not alter data to be signed or prevent such data from being presented to the signatory prior to the signature process.

CoSign complies with the SSCD requirements defined by the EU electronic signature directive in the following ways:

» CoSign is FIPS 140-2 level 3 validated for those EU member states requiring such a certification for SSCD devices.
» The CoSign SSCD model includes CWA approved smartcards for EU member states requiring this specific certification for SSCD devices.

Regulatory Compliance Statements

Forum of European Supervisory Authorities for Electronic Signatures (FESA) on Server Based Signature Services - click here.
European Union (EU) - English
Germany - German or English
Quick Links
    See a Demo
    Contact
    ROI Calc
    FAQ
    Case Studies
    White Papers
    Product Brochure
    Attend a Webinar
    Legal Compliance
© 2008 ARX, All Rights Reserved. Terms of Use | Privacy Policy | Legal | Site Map
About Us | Products | Solutions | Industries | Resource Center | Partners | Support | Contact
English | French | German | Italian | Spanish