PQC Impacts: Digital Signatures and Non-Repudiation Risk
What quantum computing does to digital signature validity
Quantum computing does not invalidate existing signatures directly. It removes the assumption they depend on. Once a private key can be derived from its public key, no verifier can distinguish a signature genuinely produced in 2026 from one forged later and dated to 2026, so non-repudiation fails retrospectively rather than only from the point of capability.
How digital signing provides non-repudiation
A digital signature carries evidential weight because of a single assumption: that only the holder of the private key could have produced it. Everything else follows from that. Integrity is established because any change to the document invalidates the signature. Authenticity is established because the certificate binds the key to an identity. Non-repudiation is established because the signer cannot credibly claim someone else produced it.
The assumption holds while deriving the private key from the public key remains computationally infeasible. RSA and ECDSA, the algorithms behind almost all deployed digital signing, rest on exactly that infeasibility.
What quantum computing does to digital signing
Shor's algorithm removes the assumption. A quantum computer of sufficient capability recovers the private key from the published public key, at which point any party can produce signatures indistinguishable from those of the legitimate key holder.
The consequence that is frequently missed is the direction of the damage. Encryption exposure is prospective in the sense that new data can be protected with new algorithms, even though harvested traffic is lost. Signature exposure is retrospective. Every document signed with a key that is later compromised becomes questionable, including documents signed and archived years earlier, because a signature carries no inherent evidence of when it was created.
A verifier examining a contract in 2033 sees a signature, a certificate and a date field inside the document. If the signing key can by then be derived from the certificate, none of those establish that the signature existed before the key was compromised. The document may be entirely genuine. The point is that it can no longer be proved to be.
This is why the risk applies to organisations that consider themselves to have little confidentiality exposure. A retailer with no long-lived secrets may still hold twenty years of signed contracts whose evidential value depends on algorithms scheduled for withdrawal.
Which digital signing use cases carry evidential risk
Exposure follows the period over which a signature must remain relied upon, not the sensitivity of the document.

What the legal position actually is
A signature does not become void because the algorithm behind it has weakened. Under the UK's retained eIDAS framework and the Electronic Communications Act 2000, electronic signatures are admissible in evidence, and admissibility is distinct from evidential weight.
The practical question is weight and burden. Where the technical basis for non-repudiation has degraded, a party relying on the signature may find the evidential burden shifting towards other supporting material: contemporaneous records, audit trails, witness evidence and the surrounding commercial context. That is a materially weaker position than a signature that stands on its own.
Qualified frameworks anticipate this. eIDAS establishes qualified electronic signatures, qualified timestamps and qualified preservation services precisely because signature technology has a finite service life. A qualified preservation service exists to maintain the evidential value of a signature beyond the security lifetime of the algorithms used to create it.
This article describes technical consequence rather than legal effect, and Unsung is not a law firm. Organisations relying on signed instruments over long periods should take their own legal advice on evidential position.
How timestamps preserve evidential value
The mechanism that solves this is well established and predates the quantum question entirely.
A trusted timestamp, as defined in RFC 3161, is a signature by a trusted authority attesting that a given document hash existed at a given moment. Applied at the point of signing, it establishes that the signature existed before any subsequent compromise of the signing key. A verifier can then reason that even if the key is now derivable, the signature demonstrably predates that capability.
The timestamp itself uses cryptography, so it inherits the same problem on a longer horizon. The answer is chaining. Archival timestamping, standardised in the ETSI AdES formats as the LTA level and in RFC 4998 evidence record syntax, applies a fresh timestamp over the existing evidence before the previous algorithms weaken. Each renewal moves the evidential foundation onto current algorithms, and the chain as a whole rests ultimately on hash functions, which quantum computing weakens but does not break.
Two operational conditions determine whether this works. The timestamp must be applied at signing rather than retrospectively, since a timestamp applied after a key is compromised proves nothing. And the verification material, meaning certificates, revocation data and trust anchors, must be preserved alongside the document, or the signature cannot be validated at all once the issuing authority's data is no longer published.
How to protect digital signing evidence now
Identify signatures with long reliance periods
Inventory signed artefacts by how long they must remain relied upon, not by document type or sensitivity. Deeds, long-dated agreements, regulated records and signed firmware are the classes that matter.
Apply trusted timestamps at the point of signing
Where long-reliance documents are signed without a timestamp today, this is the highest-value change available and it can be made immediately, before any post-quantum decision. It is a configuration change in most signing platforms.
Move to long-term validation formats
Adopt the LTA or equivalent archival level of the relevant AdES format, so that verification material is embedded and the evidence can be renewed. Preservation is a process rather than a file format decision.
Schedule re-timestamping
Set a renewal interval and an owner. Evidence that is never renewed will eventually rest on withdrawn algorithms, at which point the chain cannot be repaired retrospectively.
Set policy for new long-life signatures
Require post-quantum or hybrid signatures for new artefacts with reliance periods extending beyond 2035. For firmware and infrequent high-assurance signing, LMS, XMSS or SLH-DSA are the appropriate choices, as covered in our comparison of the NIST post-quantum algorithms.
Preserve the verification chain
Archive certificates, revocation responses and trust anchors with the signed material. This is routinely omitted and it is the most common reason a technically valid signature cannot be verified a decade later.
Common mistakes
The first is assuming migration solves the problem. Deploying post-quantum signatures protects documents signed from that point onwards. It does nothing for the archive, which requires timestamping and preservation instead.
The second is treating the document date as evidence of signing time. A date typed into a document, or recorded in metadata, is not cryptographically bound to the signature and carries no weight once forgery is possible.
The third is applying timestamps only to some artefacts. Selective timestamping produces an archive where evidential strength varies unpredictably, which is difficult to defend and difficult to remediate.
The fourth is losing revocation data. Long-term validation requires the certificate status information as it stood at signing time. Once an issuing authority decommissions, that data is generally unrecoverable.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.
We assess signing and timestamping architecture as part of our PKI health check, identify where evidential exposure sits, and design signing infrastructure that supports trusted timestamping, long-term validation and post-quantum readiness. We work with signing and validation platforms including ADSS Server and SigningHub, selected against requirements rather than partner preference.
For the wider threat concept, see our analysis of trust now, forge later.
Frequently asked questions
Do existing digital signatures become invalid when quantum computers arrive?
Does a trusted timestamp fix the problem?
Can we timestamp documents that were signed years ago?
Which signatures should be prioritised?
What is long-term validation?
Should we move to post-quantum signatures for new documents now?


