A stamp image, scanned handwritten signature, electronic signature and SHA-256 fingerprint can surround the same invoice, but they identify different actors, protect different things and carry different evidence. Morocco’s Law 43-20 regulates electronic signatures, seals, timestamps and other trust services. Software should name exactly what it provides.

The five mechanisms
- A visual stamp shows a company mark on the page; an image can be copied.
- A scanned signature shows a trace, not the process that authorized its current placement.
- An electronic signature links data to a signer at a defined level with verification means.
- An electronic seal addresses origin and integrity for a legal person.
- SHA-256 detects changed bytes but identifies no signer by itself.
- BelloPOS separates customizable PDF from local technical sealing and claims no qualified signature.
1. The differences in one table
Do not treat a printed company stamp and a regulated electronic seal as synonyms.
| Mechanism | Main function | Essential limit |
|---|---|---|
| Stamp image | Presentation and visual identity | Copyable; does not protect bytes |
| Scanned signature | Reproduce a trace on PDF | Does not alone prove present consent |
| Electronic signature | Link signer to data | Depends on level, certificate and process |
| Electronic seal | Link legal person to data | Needs a real service, not a logo |
| Electronic timestamp | Associate verifiable date and time | Local clock is not a trust service |
| SHA-256 hash | Verify file integrity | Identifies neither author nor time |
Always ask for the verb: display, approve, sign, seal, timestamp or transmit. A show-signature option does not become an electronic signature because the PDF is emailed.
2. Levels presented under Law 43-20
The official DGSSI note says Law 43-20 retained simple, advanced and qualified signatures. It describes simple with no specified technical requirements and no presumption of reliability; advanced with intermediate technical and organizational requirements including a certificate; and qualified with a qualified certificate and cryptographic products, benefiting from a presumption of reliability. Have counsel apply the law and decrees to your case.
- Simple: Simplified use; the note indicates no presumption of reliability.
- Advanced: Stronger link and requirements, more flexible than qualified.
- Qualified: Qualified certificate, high requirements and presumption of reliability under the framework.
- Associated services: Validation, preservation, seal, timestamp, registered delivery and website certificates also appear in the framework.
The note says electronic form should not be rejected merely because it is not qualified, but that does not give equal effect to every mechanism. Context, document obligation, identification and dispute still matter.
3. Decide what your invoice needs
Start with risk and recipient, not certificate shopping.
- Identify who approves internally.
- Ask customer or portal whether a signature and level are required.
- Separate PDF presentation from technical evidence.
- Determine what is signed: PDF, XML or envelope.
- Check certificate, identity, revocation and timestamp validation.
- Retain validation result and future verification information.
- Test one-character modification and certificate expiry.
- Document roles of local hash, signer and trust service.
| Need | Possible mechanism | Question |
|---|---|---|
| Company look | Logo and visual stamp | Who may import or display it? |
| Internal approval | Account, role and log | Who approved and when? |
| XML integrity | SHA-256 | Where is reference protected? |
| Signer commitment | Suitable electronic signature | Which level and certificate? |
| Legal-person origin | Electronic seal | Which provider and validation? |
| Reliable date | Trusted timestamp | How is it checked and retained? |
SHA-256 sealing answers local integrity. It can sit inside a wider process but does not become a signature by proximity. A QR can carry a reference without certifying its creator.

Do not distribute a signature image everywhere
A scanned signature available to every account can be copied onto unapproved documents. Restrict import and display, protect the original, log users and use explicit approval for sensitive operations.
4. Exactly what BelloPOS does
BelloPOS A4 PDFs can display imported stamp and signature when enabled. These are visual footer elements. Issue permissions and activity log support internal control, but the image is not presented as a qualified electronic signature.
For electronic invoicing, Go and Pro build UBL XML and calculate SHA-256 at issue. BelloPOS calls this local sealing: it compares export with issued content, without signer certificate, qualified timestamp or DGI validation.
Pro adds quotations, orders, delivery notes, invoices and credit notes with customizable PDF. Check the BelloPOS pricing page. If a customer requires a trust service, add a suitable provider rather than renaming the hash.
5. Checklist before writing electronically signed
A third party should be able to repeat verification.
- Exact mechanism and level are named.
- Signer or legal person can be identified.
- Covered file or data are unambiguous.
- Validation uses an appropriate source and certificate.
- Date comes from a defined mechanism, not only PC clock.
- Placement and validation rights are restricted.
- Verification result is retained with document.
- Procedure covers expiry, revocation, key loss and dispute.
- Visible PDF and structured XML are not confused.
- No DGI state is added without real administrative response.
Confirm recipient requirement and intended legal effect. A costlier signature is not automatically necessary for every invoice; a cheap image is not automatically sufficient. Text, contract and risk set the level.
Mistakes to avoid
- Calling a stamp image an electronic seal.
- Calling SHA-256 a digital signature.
- Letting all users import the director’s signature.
- Signing PDF while transmitting unrelated XML.
- Using local clock as qualified timestamp.
- Ignoring certificate expiry or revocation.
- Presenting stamp as DGI validation.
- Failing to retain verification result.
Frequently asked questions
Is a scanned stamp an electronic seal?
No. The former is a presentation image; the latter is a trust mechanism with requirements and validation.
Is a handwritten signature image electronic?
The document is electronic, but the image alone does not describe an electronic-signature process or level. Review the entire mechanism.
Does SHA-256 sign the invoice?
No. It provides an integrity fingerprint without signer identity, certificate or trusted time.
Which signatures does Law 43-20 present?
The official note distinguishes simple, advanced and qualified and addresses other trust services. Apply the actual text with counsel.
Does BelloPOS apply a qualified signature?
No. It can display imported stamp and signature and locally seals XML with SHA-256. It does not claim a qualified signature.
Must every invoice be signed?
Do not generalize. Check tax text, contract, sector and recipient requirements for the document.
What to take away
A stamp makes a page recognizable, electronic signature can link a signer, electronic seal can carry legal-person origin, timestamp situates an event and SHA-256 verifies bytes. Strong invoicing names each proof without assigning it another’s role.
Sources
The figures and rules quoted above come from these pages, read on the date given in the article.
- Official presentation note for Law 43-20 on trust services, DGSSI
- Moroccan General Tax Code 2026, DGI, read 29 August 2026
- BelloPOS commercial documents, stamp and signature, read 29 August 2026
- BelloPOS electronic invoicing and UBL export, read 29 August 2026
Customize PDF without overstating evidence
Test stamp, visual signature, issue rights and UBL sealing in BelloPOS, then validate any electronic-signature need with recipient and adviser.
Read next
Other practical guides on the same subject: