Electronic signatures in Morocco

Scope of Khatm for electronic PDF signing projects in Morocco: workflow, Law No. 43-20, PSCo and responsibilities.

Published Sep 9, 2026 · Updated Oct 3, 2026 · 3 min read

Preparing project decisions

Decide with your advisers and providers: signature level, identification, certificate, creation device, retention and validation. Khatm provides the technical workflow; its self-signed demo does not prove those requirements are met.

Summary

In plain language: Khatm provides a technical workflow layer for signing PDF documents. Khatm is not an approved trust service provider (PSCo) in Morocco. Compliance with applicable law and selection of the PSCo remain the client's project responsibility.

1. Scope and responsibilities

This guide describes Khatm's technical positioning for projects located in Morocco. It does not constitute legal advice.

  • Khatm orchestrates the workflow: preparation, signers, fields, journey authentication, tracking and evidence.
  • Khatm does not issue public trust certificates and claims no accreditation under Law No. 43-20.
  • Party identification, PSCo selection and regulatory analysis remain the responsibility of the client and the client's counsel.

2. Architecture

Client application or information system
Khatm workflow layer
Identity and trust (PSCo, certificates, HSM per project)

Separation between the client's information system, the Khatm workflow and the project's trust infrastructure.

LayerPurposeTypical actors
WorkflowPrepare, invite, sign, track and evidencePublisher or integrator and Khatm
IdentityAuthenticate the signer at signing timeClient IdP, business process, local provider
TrustSelected certificate and signature levelDGSSI-accredited PSCo for qualified level

3. Moroccan framework

Law No. 43-20 on trust services for electronic transactions, in force since 13 July 2023, designates DGSSI as the national authority. The law governs trust service providers (PSCo) and signature levels.

  • DGSSI sets the reference frameworks and publishes the list of accredited PSCo (article 53 of Law No. 43-20).
  • Only an accredited PSCo may issue a qualified certificate with the associated presumption of reliability.
  • Decree No. 2-22-687 specifies the implementing framework for providers and the content of qualified certificates.

4. Production deployment

In plain language: the demonstration environment validates the technical journey. A signature intended for production use requires connection of the trust infrastructure selected by the project.

  1. Validate the workflow in the demo or the API sandbox.
  2. Define the required evidence level with the client's counsel.
  3. Select the PSCo or the client's PKI.
  4. Connect identity, certificates and, where applicable, an HSM.
  5. Verify the trust path in the target PDF viewers.

5. Security considerations

  • Do not reuse a demonstration certificate or key in production.
  • Separate test and production environments.
  • Protect the signing private key (HSM or KMS, access control, logging).
  • Do not confuse an “unverified identity” notice in a PDF viewer with document tampering.
  • Plan revocation policy (OCSP or CRL) when document lifetime exceeds certificate lifetime.

General information, not legal advice. Confirm the requirements for your transaction with the appropriate adviser or receiving authority.

Sources

Is Khatm compliant with Law No. 43-20?

Khatm does not claim status as an accredited PSCo or Morocco-specific legal compliance. Khatm provides an adaptable workflow layer. Production compliance depends on the PSCo, certificates and architecture selected by the client's project.

Can the workflow be tested before selecting a PSCo?

Yes, via the public demo or the API sandbox, which really sign in PAdES with a self-signed test certificate. They validate the experience and PAdES format. It does not replace a qualified certificate in production.

Where is the list of accredited PSCo published?

On the DGSSI website, in the section on regulated services and products.