GuideSigning

What actually counts as a signed quote in Norway and Sweden

Hampus BorgosHampus Borgos

Typed names, click-to-accept, BankID — what each one proves, what the law actually requires, and what a signed quote needs to contain if it ever has to hold up.

A customer accepts your quote. Five months later the job has gone sideways, and they tell you they never agreed to the third phase. What you have is a link, a timestamp, and a name typed into a box.

Is that enough?

The short answer is that it's probably enough for the agreement to be valid, and possibly not enough to prove what was agreed. Those are two different questions, and almost all of the confusion around electronic signatures comes from treating them as one.

This is general information, not legal advice. It reflects the rules as they stood in July 2026 — if real money or a real dispute is involved, ask a lawyer.

Two questions, not one

Is the agreement binding? That's a question about form — what the law requires before a promise counts.

Can you demonstrate what was agreed, by whom, and when? That's a question about evidence — what you can put in front of a customer, an insurer, or a court.

Most quote tools sell you an answer to the first question. The second one is where deals are actually lost.

Almost nothing has to be on paper

Both countries start from freedom of form. Under Norwegian avtaleloven and Swedish avtalslagen, a binding agreement needs an offer and an acceptance. It does not need a signature, and it does not need paper. A verbal yes on a site visit is a contract — which is exactly why the arguments are never about whether an agreement exists, but about what was in it.

On top of that, eIDAS — Regulation (EU) No 910/2014, which applies in Sweden as EU law and in Norway through the EEA and lov om elektroniske tillitstjenester — says an electronic signature can't be denied legal effect purely for being electronic, or for not meeting the highest standard.

There are exceptions with their own form requirements: property transfers, wills, and certain consumer credit and guarantee situations. Ordinary commercial quotes are not among them.

So the pen was never the point. The signature's real job is to be evidence.

The four methods you'll actually meet

eIDAS defines three tiers: simple (SES), advanced (AdES), and qualified (QES). Only a qualified signature is automatically equivalent to a handwritten one across the EU and EEA. That does not make the others worthless — it means they're weighed as evidence rather than treated as conclusive. The 2024 amendment to eIDAS (Regulation (EU) 2024/1183) introduced the EU Digital Identity Wallet; it left these tiers as they were.

MethodTierWhat it actually provesSensible use
Typed or drawn nameSimpleSomeone with the link typed a nameA returning customer, a small job
Click-to-accept with a logged trailSimpleAcceptance from a mailbox the customer controls, at a known time, from a known deviceMost day-to-day B2B work
Click-to-accept plus a second factorSimple / approaching advancedThe signer had something only they should haveNew customer, moderate value
BankID (Norwegian or Swedish)AdvancedThe identity was verified by the person's bank against a national IDAnything contested, regulated, or expensive

The practical difference between the top and bottom rows is not legal weight in the abstract. It's whether the sentence "that wasn't me" is available to the other side. With a drawn signature, it is. With BankID, it effectively isn't.

The question nobody asks: could they sign at all?

A perfect BankID signature from someone who couldn't bind the company is a weaker document than a plain email from someone who could.

Signing authority is public in both countries — signaturrett in Brønnøysundregistrene, firmateckningsrätt in Bolagsverket. For a large B2B deal it's worth thirty seconds to check who's registered, or simply to ask who should sign. Where a project manager has ordered work from you before, authority is usually not a real risk. On the job that's five times bigger than anything they've ordered before, it is.

If several people need to be behind the decision — a couple renovating a house, two partners in a firm, a client and their consultant — have all of them sign rather than one forwarding it to the others.

The document matters as much as the signature

This is the part that gets skipped, and it's the part that decides disputes.

A signature proves someone said yes. It says nothing about what they said yes to, unless the document itself is fixed at the moment of signing. If your quote links out to "our current terms" on a page you update every quarter, you cannot show which version applied in March.

A record that holds up contains:

  • The exact document that was sent, stored unaltered — not regenerated later from current prices
  • Who it went to, and when
  • When it was opened
  • Who signed, by which method, and what identity evidence sits behind it
  • Timestamps, and for the weaker methods, IP and device
  • The document locked against changes after signing
  • All of it retrievable in three years without digging through an old inbox

Consumers: the 14 days after the signature

A signature doesn't end the matter with a private customer. Under Norwegian angrerettloven and Swedish distansavtalslagen, contracts concluded at a distance or away from your business premises give consumers a 14-day right of withdrawal — no matter how strong the signature was.

Two things are worth knowing. If you never gave the required withdrawal information, the period extends dramatically — up to a year. And if the customer wants work to start inside those 14 days, get their express request in writing, or you may not be able to charge for what you've already done if they withdraw.

None of this applies to business customers.

A decision rule

Ask one question: if this goes wrong, who am I showing it to?

  • Yourself, to remember what was agreed — any method works
  • The customer, who has forgotten — a locked document and a timestamp is plenty
  • The customer's partner or colleague, who wasn't in the room — identity starts to matter
  • An insurer, a public client, or a court — BankID, a versioned document, and a full audit trail

Then match the method to the deal rather than picking one for everything. Requiring BankID for a 4,000 kr callout adds friction for no gain. Accepting a typed name on a 400,000 kr renovation is a decision you'll only regret once.

How Dealight handles it

Signing runs through Criipto, and you choose the method per deal: Norwegian BankID, Swedish BankID, a drawn signature, one-click acceptance, or payment-gated signing through Stripe when you want the deposit settled before the signature counts.

Where more than one person has to agree, multi-signatory signing tracks each signer separately, lets you set the order they sign in, and closes the signing order automatically once everyone has signed.

Underneath that, every sent deal becomes an immutable snapshot, so the version the customer accepted is the version you keep — prices, scope, and terms as they were on the day. Opens are recorded, the signed document is stored as a proof attachment, and the whole record stays with the project.

Further reading

Primary sources, as of July 2026:

  • eIDAS — Regulation (EU) No 910/2014, Articles 25–26, and Regulation (EU) 2024/1183 (EUR-Lex)
  • NorwayLov om elektroniske tillitstjenester (LOV-2018-06-15-44), Avtaleloven (LOV-1918-05-31-4), Angrerettloven (LOV-2014-06-20-27) (Lovdata)
  • SwedenAvtalslagen (1915:218), Lag (2016:561) on electronic identification, Distansavtalslagen (2005:59) (Riksdagen)
  • Signing authority — Brønnøysundregistrene (Norway), Bolagsverket (Sweden)
Hampus Borgos

Hampus Borgos

Founder of Dealight