Guides & comparisonsInvoicingRetail in Morocco

Stamp, signature and electronic seal: three different things

PDF image, signer’s act, trust service or local hash: compare function, evidence and limits before calling an invoice signed.

By BelloCommerce

·

A stamp image, scanned handwritten signature, electronic signature and SHA-256 fingerprint can surround the same invoice, but they identify different actors, protect different things and carry different evidence. Morocco’s Law 43-20 regulates electronic signatures, seals, timestamps and other trust services. Software should name exactly what it provides.

Stamp, signature and sealing on an invoice
Stamp, signature and sealing on an invoice.

The five mechanisms

  • A visual stamp shows a company mark on the page; an image can be copied.
  • A scanned signature shows a trace, not the process that authorized its current placement.
  • An electronic signature links data to a signer at a defined level with verification means.
  • An electronic seal addresses origin and integrity for a legal person.
  • SHA-256 detects changed bytes but identifies no signer by itself.
  • BelloPOS separates customizable PDF from local technical sealing and claims no qualified signature.

1. The differences in one table

Do not treat a printed company stamp and a regulated electronic seal as synonyms.

MechanismMain functionEssential limit
Stamp imagePresentation and visual identityCopyable; does not protect bytes
Scanned signatureReproduce a trace on PDFDoes not alone prove present consent
Electronic signatureLink signer to dataDepends on level, certificate and process
Electronic sealLink legal person to dataNeeds a real service, not a logo
Electronic timestampAssociate verifiable date and timeLocal clock is not a trust service
SHA-256 hashVerify file integrityIdentifies neither author nor time

Always ask for the verb: display, approve, sign, seal, timestamp or transmit. A show-signature option does not become an electronic signature because the PDF is emailed.


2. Levels presented under Law 43-20

The official DGSSI note says Law 43-20 retained simple, advanced and qualified signatures. It describes simple with no specified technical requirements and no presumption of reliability; advanced with intermediate technical and organizational requirements including a certificate; and qualified with a qualified certificate and cryptographic products, benefiting from a presumption of reliability. Have counsel apply the law and decrees to your case.

  • Simple: Simplified use; the note indicates no presumption of reliability.
  • Advanced: Stronger link and requirements, more flexible than qualified.
  • Qualified: Qualified certificate, high requirements and presumption of reliability under the framework.
  • Associated services: Validation, preservation, seal, timestamp, registered delivery and website certificates also appear in the framework.

The note says electronic form should not be rejected merely because it is not qualified, but that does not give equal effect to every mechanism. Context, document obligation, identification and dispute still matter.

3. Decide what your invoice needs

Start with risk and recipient, not certificate shopping.

  1. Identify who approves internally.
  2. Ask customer or portal whether a signature and level are required.
  3. Separate PDF presentation from technical evidence.
  4. Determine what is signed: PDF, XML or envelope.
  5. Check certificate, identity, revocation and timestamp validation.
  6. Retain validation result and future verification information.
  7. Test one-character modification and certificate expiry.
  8. Document roles of local hash, signer and trust service.
NeedPossible mechanismQuestion
Company lookLogo and visual stampWho may import or display it?
Internal approvalAccount, role and logWho approved and when?
XML integritySHA-256Where is reference protected?
Signer commitmentSuitable electronic signatureWhich level and certificate?
Legal-person originElectronic sealWhich provider and validation?
Reliable dateTrusted timestampHow is it checked and retained?

SHA-256 sealing answers local integrity. It can sit inside a wider process but does not become a signature by proximity. A QR can carry a reference without certifying its creator.

Electronic signature and trust service
Electronic signature and trust service.

Do not distribute a signature image everywhere

A scanned signature available to every account can be copied onto unapproved documents. Restrict import and display, protect the original, log users and use explicit approval for sensitive operations.

4. Exactly what BelloPOS does

BelloPOS A4 PDFs can display imported stamp and signature when enabled. These are visual footer elements. Issue permissions and activity log support internal control, but the image is not presented as a qualified electronic signature.

For electronic invoicing, Go and Pro build UBL XML and calculate SHA-256 at issue. BelloPOS calls this local sealing: it compares export with issued content, without signer certificate, qualified timestamp or DGI validation.

Pro adds quotations, orders, delivery notes, invoices and credit notes with customizable PDF. Check the BelloPOS pricing page. If a customer requires a trust service, add a suitable provider rather than renaming the hash.

5. Checklist before writing electronically signed

A third party should be able to repeat verification.

  • Exact mechanism and level are named.
  • Signer or legal person can be identified.
  • Covered file or data are unambiguous.
  • Validation uses an appropriate source and certificate.
  • Date comes from a defined mechanism, not only PC clock.
  • Placement and validation rights are restricted.
  • Verification result is retained with document.
  • Procedure covers expiry, revocation, key loss and dispute.
  • Visible PDF and structured XML are not confused.
  • No DGI state is added without real administrative response.

Confirm recipient requirement and intended legal effect. A costlier signature is not automatically necessary for every invoice; a cheap image is not automatically sufficient. Text, contract and risk set the level.

Mistakes to avoid

  • Calling a stamp image an electronic seal.
  • Calling SHA-256 a digital signature.
  • Letting all users import the director’s signature.
  • Signing PDF while transmitting unrelated XML.
  • Using local clock as qualified timestamp.
  • Ignoring certificate expiry or revocation.
  • Presenting stamp as DGI validation.
  • Failing to retain verification result.

Frequently asked questions

Is a scanned stamp an electronic seal?

No. The former is a presentation image; the latter is a trust mechanism with requirements and validation.

Is a handwritten signature image electronic?

The document is electronic, but the image alone does not describe an electronic-signature process or level. Review the entire mechanism.

Does SHA-256 sign the invoice?

No. It provides an integrity fingerprint without signer identity, certificate or trusted time.

Which signatures does Law 43-20 present?

The official note distinguishes simple, advanced and qualified and addresses other trust services. Apply the actual text with counsel.

Does BelloPOS apply a qualified signature?

No. It can display imported stamp and signature and locally seals XML with SHA-256. It does not claim a qualified signature.

Must every invoice be signed?

Do not generalize. Check tax text, contract, sector and recipient requirements for the document.

What to take away

A stamp makes a page recognizable, electronic signature can link a signer, electronic seal can carry legal-person origin, timestamp situates an event and SHA-256 verifies bytes. Strong invoicing names each proof without assigning it another’s role.

Sources

The figures and rules quoted above come from these pages, read on the date given in the article.

Customize PDF without overstating evidence

Test stamp, visual signature, issue rights and UBL sealing in BelloPOS, then validate any electronic-signature need with recipient and adviser.

Read next

Other practical guides on the same subject: