The signing certificate: what it is and what the VCA want

Every eCoC file has to carry a digital signature or the VCA reject it. In the last fortnight we've seen a manufacturer sent three different things when someone asked for "the signature": a password-manager login, a Word document of scanned handwritten signatures, and a PDF with a signature image on it. None of them is it.
What it actually is
A certificate issued to the company, not a person, by a trust service provider. Think of it as an electronic company stamp. Software uses it to produce a block of characters, derived from the file's contents, that proves the file came from your company and hasn't been changed since. Alter one character in the file and the signature no longer matches.
The technical name is an electronic seal, under the eIDAS regulations. The VCA's guidance says to sign the way EU manufacturers do, and the VCA currently check that a signature is present rather than which tier of seal was used. Seals come in two grades, "advanced" and "qualified". In conversation the VCA have told us they expect qualified, the higher grade; we've asked for that in writing and will update this post when it arrives. The signature format is a standard XML signature (XMLDSig). EU eCoCs use the XAdES form and the VCA's guidance says to sign as EU manufacturers do, but the VCA confirmed to us in writing on 17 September 2026 that their portal currently rejects files carrying a XAdES signature, and that a change to accept XAdES is being considered by their eCoC project board. CoC AutoDocs signs in the format the portal accepts today and will switch when the VCA do.
Where it comes from
From a trust service provider, in the company's name. For a qualified seal that means one of the three providers on the ICO's UK trusted list. Before issuing, the provider verifies the company: a Companies House check, a director confirming they can act for it, sometimes a callback to a published number. That takes weeks, not days, and it is the part that catches people out in November.
With CoC AutoDocs the seal is included: we hold it for you with a provider on the UK trusted list, in your company's name, and every certificate you make carries it. You never see a certificate, install anything or renew anything; the only part that needs you is the verification, which we walk you through. If you are arranging a seal yourself, ask the provider for a qualified electronic seal in the company's name, not a personal signature, and start now.
The two halves of a seal
Two things: a certificate (the public half, which goes into every sealed file) and a private key (the secret half). For a qualified seal the key is made and kept in the provider's certified hardware and never leaves it; each file is sealed by asking the provider. That is the arrangement we use for the included seal, so nobody handles a key file. If your company already owns a certificate as a .pfx or .p12 file, the app can use it in the browser on the PC that makes the files instead.
What to do in the meantime
Don't wait. The VCA currently only check that a signature is present, so a test key gets files through the test portal today. CoC AutoDocs has one built in. Use it to get your setup, your models and your first uploads sorted; your files move onto the company seal once the provider has verified your company.
If your company holds its own certificate, never paste the private key into an email, a chat or a support form: load it into the software on the PC that makes the files. With the included seal nobody handles a key file at all.
The short version of all this, kept up to date as the VCA confirm things, is at The certificate you need before November.