Digital certificate, electronic DNI or Cl@ve: which do you need for each procedure

The three systems serve to identify oneself before public administrations, but they do not work the same: the digital certificate and the DNIe allow for electronic signing in a general way, while Cl@ve is mainly designed for simple identification.

6 minutes

fotonoticia 20260710122904 1920

fotonoticia 20260710122904 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

6 minutes

Most read

Making the income tax declaration, consulting an administrative notification, requesting a benefit, or submitting documentation to a public body increasingly requires electronic identification. To do this, there are several options, but the three most common are digital certificate, electronic DNI, and Cl@ve.

Although they can be used for many similar procedures, they are not exactly equivalent. The Electronic Administration Portal indicates that both the software certificate and the electronic DNI allow for electronic identification and signing in the procedures that accept them. Cl@ve, for its part, is mainly oriented towards identification, although there is also Cl@ve Firma for certain services.

The choice fundamentally depends on what procedure you want to carry out, how often digital public services are used, and whether electronic signing is necessary.

System How to obtain it Duration Main uses Identification level Does it allow electronic signing?
Digital certificate Application before a provider such as the FNMT, identity accreditation, and subsequent download and installation on the device. The FNMT individual certificate has a validity of 4 years, unless revoked. Tax office, Social Security, electronic records, document submission, notifications, and numerous administrative procedures. High. Electronically accredits the identity of the holder. Yes.
Electronic DNI Electronic certificates are incorporated into the DNI issued by the Police and can be renewed as long as the document remains valid. The certificates included in the DNIe have a maximum validity of 60 months. Identification and signing before public administrations and other compatible services. High. Uses electronic certificates directly linked to the DNI. Yes.
Cl@ve Online or in-person registration. It can be used through Cl@ve Móvil or Cl@ve Permanente, among other modalities. The registration does not function as a certificate with a unique expiration date. In Cl@ve Permanente the password expires after 2 years and must be renewed. Consultations and numerous procedures with the Tax Office, Social Security, DEHú, and other public bodies. Depends on the registration level and the system used. Some services require reinforced identification. The ordinary Cl@ve is mainly oriented towards identification. Cl@ve Firma allows signing in the procedures that accept it.

Digital certificate: the most versatile option

The electronic certificate of a natural person contains the identifying data of its holder and allows to certify their identity online before the administrations and to carry out electronic signatures.

One of the most used in Spain is the natural person certificate issued by the National Mint and Stamp Factory (FNMT).

Its main advantage is its wide range of use. The Electronic Administration Portal indicates that the software certificate is accepted for identification in any procedure or process of the Administration that contemplates it and allows electronic signing.

Once obtained, it must be installed on the computer, mobile, or other device from which it will be used. If it is to be used on several devices, it must be installed or imported on each of them.

In the case of the natural person certificate from the FNMT, its validity is four years from its issuance, as long as it is not revoked beforehand.

Electronic DNI: identification and signature with the document itself

The electronic DNI or DNIe incorporates digital certificates in the national identity document itself.

It allows to identify electronically as well as to sign documents, thus offering functionalities similar to those of a digital certificate installed on a device.

The difference lies mainly in how it is used.

Instead of installing a software certificate, the user uses the certificates included in the chip of the DNI. Depending on the device, it may be necessary to have a compatible reader or to use the NFC capabilities of certain mobile phones, in addition to the corresponding software.

The electronic certificates included in the DNI have a maximum validity of 60 months, although they can be renewed as long as the document itself remains valid.

This should not be confused with the physical duration of the DNI, which depends on the age of its holder.

Cl@ve: designed for easy identification

Cl@ve is the common system that allows citizens to identify electronically before numerous services of public administrations.

Its main advantage is that it does not require installing a certificate on the device or necessarily using a DNI reader.

Currently, there are different modalities. Cl@ve Mobile allows confirming an identification request from the phone, usually through the Cl@ve application or via a QR code.

...

There is also Cl@ve Permanente, aimed especially at users who regularly access public services and that works through username and password, with additional security mechanisms when the service requires it.

The Cl@ve Permanente password expires after two years, at which point it must be changed.

Cl@ve does not always equate to an electronic signature

This is one of the differences that generates the most confusion.

The usual Cl@ve systems mainly allow identification before the Administration, while the digital certificate and the DNIe also allow electronic signatures in general for compatible services.

There is Cl@ve Firma, which incorporates electronic signature capability, although its availability depends on the specific procedure. The Electronic Administration Portal itself warns that this modality is not available for all procedures.

Therefore, if a procedure expressly requires an electronic signature through a recognized certificate, it is advisable to check in advance which systems that electronic headquarters accepts.

What to use for the Tax Agency

The Tax Agency accepts different identification systems depending on the procedure.

For many procedures of individual citizens, Cl@ve is sufficient and allows access without the need to install a certificate.

However, certain actions may require or be more convenient with electronic certificate or DNIe, especially when procedures are carried out regularly, acting as a representative, or handling more complex administrative procedures.

That is why there is no system that completely replaces the others in all circumstances.

What to use for Social Security

Social Security also allows numerous procedures through different electronic systems.

A citizen who only needs to consult personal data, download certain documents, or carry out occasional procedures may find Cl@ve especially convenient.

Those who carry out frequent procedures or need to sign electronically may prefer a digital certificate, as it is installed on the device and allows direct authentication when the service permits it.

What system serves to consult notifications

To access services such as the Single Enabled Electronic Address (DEHú), electronic identification systems such as digital certificate or Cl@ve can be used.

Therefore, for a person who simply wants to periodically check their administrative notifications, Cl@ve may be sufficient.

However, having an electronic certificate also offers greater versatility for other procedures.

How to obtain each one

The process is also different.

The digital certificate from the FNMT requires requesting the certificate and verifying identity through one of the available procedures before downloading and installing it.

The electronic DNI is obtained with the issuance of the DNI, and its certificates can be managed through the mechanisms enabled by the Police.

To use Cl@ve, you must first register in the system. Registration can be done online or in person, and there are different registration modalities depending on the level of identification.

So, which one is advisable to have?

For an occasional user of electronic Administration, Cl@ve is usually the simplest alternative, especially if they primarily use a mobile phone.

For those who frequently carry out administrative procedures, submit documentation, or need to sign electronically on a regular basis, the digital certificate offers greater versatility.

The electronic DNI provides practically the same possibilities for identification and signing, but its use may depend more on the device and having the necessary system to read it.

In reality, the three systems can complement each other. Being registered in Cl@ve and also having a digital certificate allows choosing the most convenient alternative depending on the procedure and avoids being left without access if an electronic office requires a specific system.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What is the parliamentary procedure to modify the requirements for obtaining the digital certificate in Spain?

To modify the requirements for obtaining the digital certificate in Spain, there is no "special procedure" specific to the subject; instead, the general procedure corresponding to the type of regulation governing those requirements is followed. In practice, it is usually an ordinary law or regulatory norms, but I will explain the parliamentary framework for three scenarios: ordinary law, organic law, and royal decree-law that is later processed as a bill.

a) Modification through ordinary law

If the digital certificate requirements are set in an ordinary law, their modification requires the approval of another ordinary law that alters, adds, or removes the relevant provisions.

  • Initiative: it is usual that it is a government bill, approved in the Council of Ministers and sent to the Congress. It could also be a bill proposed by parliamentary groups or other subjects with legislative initiative.
  • Admission for processing: the Board of the Congress qualifies and admits the bill or proposal for processing.
  • Amendments and general debate: a period for amendments is opened. The following may be presented:
    • Amendments to the entirety (complete rejection or alternative text), which are debated in the Plenary.
    • Amendments to the articles, which propose specific changes, for example, raising or relaxing technical or identification requirements.
  • Committee work: the competent committee (usually related to digital affairs, justice, or economy, depending on the subject) debates and votes on partial amendments and approves a report.
  • Congress Plenary: the report is submitted to debate and voting. The “live amendments” not incorporated in the committee may be defended. The Plenary approves the text to be sent to the Senate.
  • Processing in the Senate: the Senate may approve the text as is, amend it, or veto it. If there are amendments or a veto, the text returns to the Congress, which decides finally (it can lift the veto by absolute majority, or by simple majority after two months).
  • Sanction and publication: the King sanctions the law and it is published in the BOE, at which moment the new conditions for the digital certificate become mandatory under the terms set by the norm itself (immediately or with vacatio legis).

b) Modification through organic law

This only applies if the digital certificate requirements affect matters reserved for organic law (for example, fundamental rights in their core). The parliamentary procedure is very similar to that of ordinary law, with two key differences:

  • Rank and reservation: the content must fit within a constitutionally reserved scope for organic law. It is not enough to “call” the law organic; its subject matter must justify it.
  • Reinforced majority: in the final vote in the Congress Plenary, the organic law requires an absolute majority of deputies; a simple majority is not enough. In the other phases (amendments, committee, Senate), the functioning is analogous to that of ordinary law.

Otherwise, there is a bill or proposal, admission for processing, amendments, committee, Senate, and sanction and promulgation. The practical consequence is that to toughen or relax requirements regulated in organic law, a wider parliamentary consensus is required.

c) Modification through royal decree-law processed as a bill

The Government may resort to a royal decree-law to urgently modify the digital certificate requirements when it perceives an “extraordinary and urgent need” (for example, a massive cyber threat or an immediate European requirement).

  • Approval and entry into force: the Council of Ministers approves the royal decree-law, which is published in the BOE and enters into force immediately. From that moment, the new requirements apply.
  • Initial parliamentary control: the Congress must validate or repeal the decree-law within a maximum period of 30 days, in a specific debate.
  • Processing as a bill: the Congress may agree, in that same debate, that the decree-law be processed as a bill by the urgency procedure. In that case, the following opens:
    • Abbreviated period for submitting amendments.
    • Committee work with report and possibility to introduce modifications on the certificate requirements.
    • Debate and voting in the Congress Plenary and subsequent sending to the Senate, also with shortened deadlines.
  • Final result: the initial content of the decree-law may be confirmed, softened, or toughened by the approved amendments. The final text becomes law and replaces the decree-law, consolidating the regulation of the digital certificate requirements in a stable manner.

In summary, the modification of the digital certificate requirements follows the ordinary path of the type of norm that contains them. The key lies in the normative rank: the higher it is (organic law), the greater the majority requirements; the more urgent (decree-law), the faster the initial process but also the greater subsequent margin for Parliament to introduce changes via amendments.

What competencies does the Directorate General of Police have regarding the issuance of the electronic DNI?

The Directorate General of Police (DGP), through the National Police, is the centrally responsible body both for the physical issuance of the National Identity Document (DNI) and for managing the electronic aspect of the DNIe, including its certification infrastructure. These competencies are supported by several regulations, notably Royal Decree 1553/2005, of December 23, regulating the issuance of the National Identity Document and its electronic signature certificates, Order INT/738/2006, of March 13, and Order INT/859/2023, of July 21, on the structure and functions of the DGP.

1. Competence to issue and renew the DNI/DNIe

Order INT/738/2006, by approving the Declaration of Practices and Certification Policies (DPC) of the Ministry of the Interior for the DNIe, expressly states that, according to Royal Decree 1553/2005, the Directorate General of Police is the body responsible for the issuance and management of the DNI. The DPC text itself indicates that, to implement the electronic National Identity Document, the DGP:

  • Assumes the issuance and management of the new DNI, including the physical medium and its electronic components.
  • Acts as a Certification Authority, associating identity and signature certificates to each citizen holding the DNIe.

In parallel, Order INT/859/2023 configures within the DGP structure an Area of Documentation of Spaniards and Foreigners, with functions of “study, management, and central distribution of activities and means related to the issuance of documentation for Spaniards and foreigners” and coordination and technical support to territorial units. This organises, in organic terms, the network of documentation offices that process the issuance and renewal of the DNI/DNIe.

2. Technical management and security of the electronic DNI

Order INT/738/2006 describes in detail the functions of the DGP as a certification service provider for the DNIe. Among other aspects, the DPC establishes that:

  • The Body responsible for the issuance and management of the DNI (the DGP) will implement a Public Key Infrastructure (PKI) to provide the DNI with the necessary electronic certificates.
  • The DPC regulates the entire certificate lifecycle: application, issuance, use, suspension, and expiration, as well as coordination with the corresponding public registries.
  • The DGP, as a certification service provider, must comply with the requirements established in electronic signature regulations, and the DNIe certificates are configured as recognized electronic certificates, with the legal effects of handwritten signatures.
  • A Policy Approval Authority is foreseen within the DGP, as the executive committee of the DNIe PKI, responsible for drafting and proposing the approval and modification of the DPC, as well as analyzing audits and setting corrective measures.

In sum, the DGP not only issues the document but also designs, maintains, and controls the cryptographic infrastructure and electronic certificates that enable identification and electronic signature through the DNIe.

3. Organization of offices and document control

Order INT/859/2023, which develops the organic structure and functions of the DGP, strengthens the documentation component within the Deputy Directorate General of Logistics and Innovation:

  • The Area of Documentation of Spaniards and Foreigners centralizes the planning and management of document issuance, including the DNI/DNIe.
  • It assumes functions of development and innovation in documentation matters, which includes the technological evolution of the DNIe.
  • It is responsible for control and inspection of documentation units, that is, the offices where the DNI is effectively processed throughout the territory.
4. Coordination with other bodies and administrations

The regulatory texts imply that the DGP must coordinate:

  • Internally, with the Ministry of the Interior itself, through the Policy Approval Authority and other management bodies, for the approval and updating of the DPC and technical standards.
  • With public registries and other administrations, regarding certificate management, identity verification, and the use of the DNIe in electronic services of various public entities.

Organic Law 4/2015, on citizen security protection, also reinforces the evidentiary value of the DNI and expressly contemplates its identification and electronic signature capabilities, which aligns with the DGP’s role as guarantor of the document’s authenticity and its electronic attributes.

Overall, it can be said that the DGP concentrates comprehensive competence over the electronic DNI: from the issuance and renewal of the document, through the technical management of certificates and the PKI, to the organization, supervision, and innovation of the entire network of documentation offices and coordination with the rest of the public sector for the use of the DNIe as a secure identification and signature tool.

What regulations currently govern electronic identification systems in the Spanish Administration?

Electronic identification systems in the Spanish Administration rely on a mixed regulatory “block,” European and national. The core consists of the eIDAS Regulation, Laws 39/2015 and 40/2015, Royal Decree 203/2021, and Royal Decree 311/2022 (National Security Framework), complemented by specific regulations such as Royal Decree-law 14/2019 and Law 59/2003 on electronic signature.

1. European framework: Regulation (EU) No. 910/2014 (eIDAS)

Regulation (EU) No. 910/2014, of July 23, 2014, on electronic identification and trust services for electronic transactions in the internal market (known as eIDAS Regulation), establishes:

  • The security levels of electronic identification means notified by Member States.
  • The regime of trust services (electronic signatures and seals, time stamps, certified electronic delivery services, etc.).
  • The cross-border validity of identification and electronic signature within the EU.

Spain must directly apply this Regulation in its identification and signature systems, and much of the internal regulation explicitly adapts to eIDAS, as acknowledged by Royal Decree 311/2022 when mentioning that the National Security Framework was adapted to the eIDAS Regulation.

2. Law 39/2015: rights of individuals and means of identification

Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (text in the BOE) is the basis of citizen-Administration electronic relations. Among other aspects:

  • Recognizes the right to interact electronically with the Administrations (arts. 13 and 14).
  • Regulates the means of electronic identification and signature of interested parties (arts. 9 and 10), including certificates, concerted key systems, and other systems based on prior user registration.
  • Establishes the basic regime of electronic headquarters, electronic registry, authentic copies, and electronic archive.

Royal Decree-law 14/2019, of October 31 (BOE-A-2019-15790) precisely amended articles 9 and 10 of Law 39/2015 to:

  • Adjust their content to the eIDAS Regulation.
  • Introduce a prior authorization regime by the General State Administration for certain identification and signature systems other than electronic certificates and seals, for public security reasons.

3. Law 40/2015: legal regime of the public sector

Law 40/2015, of October 1, on the Legal Regime of the Public Sector (text in the BOE) regulates the “internal face” of the public sector. Digitally:

  • Imposes that relations between administrations, and between them and their dependent bodies, be conducted by electronic means (art. 3).
  • Extends the scope of the National Security Framework to the entire public sector (art. 156), which directly affects how identification and authentication systems must be configured and protected.

4. Electronic operation regulation: Royal Decree 203/2021

Royal Decree 203/2021, of March 30, approving the Regulation on the operation and functioning of the public sector by electronic means (BOE-A-2021-5032), develops Laws 39/2015 and 40/2015 regarding:

  • Conditions of use of identification and signature systems (including concerted key systems and other systems based on prior registration).
  • General regime of electronic headquarters and associated headquarters, portals, apps, and access channels.
  • General electronic registry, powers of attorney, electronic notifications, and electronic archive.

Numerous recent resolutions creating electronic headquarters (for example, of bodies such as the AEPD, ANECA, port authorities, or state agencies) are issued “in accordance with” this regulation, evidencing that RD 203/2021 is today the central detailed piece for electronic identification in the General State Administration and its institutional public sector.

5. Security of systems: Royal Decree 311/2022 (ENS)

The technical security of identification systems is articulated through Royal Decree 311/2022, of May 3, regulating the National Security Framework (BOE-A-2022-7191). This regulation:

  • Sets the basic principles and minimum requirements for the security of public sector information systems.
  • Requires specific measures for identification and access control, traceability, incident management, and data protection, which condition the design of authentication and signature systems.
  • Explicitly coordinates with the eIDAS Regulation and Organic Law 3/2018 on personal data protection.

6. Law 59/2003 and complementary regulations

Law 59/2003, of December 19, on electronic signature, remains the historical internal reference on electronic signature, although many of its aspects have been integrated or superseded by the eIDAS Regulation. Royal Decree-law 14/2019 modified, for example, article 15.1 to reinforce the role of the electronic DNI as an identity accreditation instrument.

Additionally, there are sectoral regulations governing specific electronic identification systems in particular fields (for example, Royal Decree 1065/2015 on electronic communications in the Justice Administration and the LexNET system, or resolutions creating electronic headquarters and registries of specific bodies, as well as specialized systems such as eSignature for Foreigners (e4F), approved for the headquarters of the State Aviation Safety Agency).

Overall, it can be said that electronic identification in the Spanish Administration today is based on the combination of eIDAS, Law 39/2015, Law 40/2015, RD 203/2021, RD 311/2022 (ENS), RDL 14/2019, and Law 59/2003, along with a constellation of specific provisions for headquarters, registries, and concrete authentication systems.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

Which systems allow identification and electronic signing in most administrative procedures?

Question 1 of 3

What is the maximum validity of the digital certificate for individuals issued by the FNMT?

Question 2 of 3

Which electronic identification system is mainly designed for identification without installing certificates or using readers?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?