Skip to content

Qualified signatures with CMD

Mobile Digital Key is the Portuguese State’s electronic identity service. In AssinaJá it is the only way to produce a QES — a signature legally equivalent to signing by hand across the European Union.

What makes a signature qualified is not the platform that collects it, but who issues the certificate and where the private key lives.

Issuer AMA — Agência para a Modernização Administrativa, a QTSP on the Portuguese EU Trust List
Private key In AMA’s HSM — never on your phone, never in AssinaJá
eIDAS level QES
Identity verification High

The qualified character comes exclusively from AMA, not from AssinaJá — see the limits, stated plainly.

Your Chave Móvel Digital must have Digital Signature activated. Having CMD for authentication is not enough — signing is a separate feature, activated at autenticacao.gov.pt.

If AMA does not return the signing certificate, AssinaJá shows:

AMA did not return the signing certificate for this number. This may be a temporary failure: please try again in a moment. If it persists, check that the number is correct and that the digital signature of your Chave Móvel Digital is active at https://www.autenticacao.gov.pt.

The CMD wizard has four steps — Identification, Authentication, Processing and Completion. You enter your phone number and your signing PIN (not the authentication one), then the 6-digit security code, within 2 minutes. Your visual signatures must be done first: CMD seals the document. What you see on each screen is in Sign a document.

This is the distinction that confuses most, and it states simply:

  • CMD proves who signed.
  • CMD with Professional Attributes (SCAP) proves in what capacity they signed — and that capacity is attested cryptographically by the certifying body itself, not by the signer and not by AssinaJá.

SCAP is the State-run Sistema de Certificação de Atributos Profissionais. A lawyer signing with SCAP is not merely signing as a citizen: the document gains an additional signature from the professional body, confirming that on that date they held that capacity.

The SCAP option is only offered to whoever prepares the document when the organisation meets two conditions at once:

  • it has an Enterprise subscription in force — the plan’s validity counts with the same 10-day margin as the plan’s quota;
  • its entitlement to sign with professional attributes is switched on. It comes on for every organisation; AssinaJá can switch it off for a particular one.

If either is missing, the SCAP type is not offered when sending, and the server refuses a document that asks for it. On the plan cards, the CMD signature with professional attributes line only shows as included in Enterprise.

Whoever signs needs none of this: the decision belongs to the sender, and a guest who receives a SCAP zone signs it.

CMD CMD with Attributes
Prior authentication — OAuth at autenticacao.gov.pt
Choosing attributes — At least one, from those available
Authorising the capacities to be included — Required, at the Confirmation step
Phone + PIN Yes Yes
Security code Yes Yes
Signatures on the final PDF Platform seal + your QES Platform seal + your QES + one per certifying body

The SCAP wizard has six steps: Attributes, Confirmation, Identification, Authentication, Processing and Completion. The capacities are chosen first, before identification.

In the attributes step each body appears with its attributes as checkboxes. You may pick several, including across different bodies, but at least one is required — “Select at least one attribute”.

Next, the Confirmation step exists only to confirm the choice:

Confirm the capacity you are signing in

These are the capacities recorded in the signature: {n} across {n} entity(ies). They cannot be changed once you sign.

Each entity appears with its NIPC beside the name — which is what tells two similarly named companies apart — and the chosen capacities listed underneath. If something is wrong, Change selection goes back a step.

Below the list is the wizard’s only mandatory checkbox:

I authorise including the selected qualifications in this document’s signature.

Unless it is ticked, the wizard does not move on and shows “Authorise including the qualifications to continue.” The authorisation is given document by document.

The capacity you sign in stays in the document and cannot be corrected afterwards — which is why it has a step of its own.

A signature with attributes adds three lines to the stamp, beyond name and date:

Line Content
Certificado com: SCAP
Certificado Por: The certifying bodies
Atributos Certificados: The chosen attributes, per body

The same information appears in the Completion Report and is recorded as evidence attached to the signer.

Rule What it means
One qualified zone per signer and document “You can only have one signature of this kind for each signer/document combination.” In the editor, a second attempt gives “Each signer signs with the Digital Mobile Key only once per document. Remove the existing qualified zone before placing another.”
One certificate-based method per signer CMD, SCAP or LDC (Local Digital Certificate): a signer can hold visual signatures and one of these three, never two
The phone belongs to the signer The number is not asked for when preparing the document: the signer enters it in the Chave Móvel Digital wizard
Already-signed documents A PDF that already carries digital signatures accepts only CMD or CMD with Attributes, so the existing ones stay valid
“Sign now” does not support CMD The owner’s immediate signing does not go through AMA; the document has to be sent for signature

Both methods consume the same CMD quota from the subscription. When it runs out, the send does not go: the dialog “You need {n} more Chave Móvel Digital signatures to send this document” opens — see Send a document for signature.

The waiting and refusal screens common to any signature are in Sign a document. These are the messages specific to Chave Móvel Digital:

Message Meaning
The Chave Móvel Digital (AMA) signature failed “This is a failure of the AMA (Chave Móvel Digital) service, not of the document. You can try again.”
The Mobile Digital Key service is not available! Please try again later. AMA-side outage
The security code is incorrect. Wrong code
The security code has expired. The 2 minutes elapsed
The pin you provided is incorrect. Wrong signing PIN
Invalid mobile number. Phone number format
The signing session has expired. Please start the process again. Start the process again
No response from the signing server. Please check your connection and try again. Check the connection and retry
This document currently has no qualified signature available for you. Please contact whoever sent you the document. None of your CMD/SCAP zones is open right now — AMA is not even contacted, and your code is not spent

The first two are AMA’s, not AssinaJá’s and not the document’s. Retrying later usually resolves them.

You always see one of these sentences, never an internal code such as Documents.CMD.AuthErrorMessages.….

Closing the wizard releases your row on the document immediately — see Sign a document.

A CMD signature sits at the PAdES-BASELINE-T profile: fully valid, without the revocation information embedded. What that changes, and why you should keep the signed PDF and the Completion Report together, is in Long-term validation (LTV).

UNVERIFIED: the profile of a CMD with Professional Attributes signature. The two sources disagree: the signature policy (§3) places CMD and CMDSCAP at PAdES-BASELINE-T; the only measurement so far, taken in a test environment (docs/eidas/proof/2026-08-22/dss/summary.md, M5), reports the signer’s signature without a qualified timestamp — PAdES-BASELINE-B. A measurement on a production SCAP signature is still missing.