Electronic signatures in Morocco
Scope of Khatm for electronic PDF signing projects in Morocco: workflow, Law No. 43-20, PSCo and responsibilities.
Published Sep 9, 2026 · Updated Oct 3, 2026 · 3 min read
Preparing project decisions
Decide with your advisers and providers: signature level, identification, certificate, creation device, retention and validation. Khatm provides the technical workflow; its self-signed demo does not prove those requirements are met.
Summary
In plain language: Khatm provides a technical workflow layer for signing PDF documents. Khatm is not an approved trust service provider (PSCo) in Morocco. Compliance with applicable law and selection of the PSCo remain the client's project responsibility.
1. Scope and responsibilities
This guide describes Khatm's technical positioning for projects located in Morocco. It does not constitute legal advice.
- Khatm orchestrates the workflow: preparation, signers, fields, journey authentication, tracking and evidence.
- Khatm does not issue public trust certificates and claims no accreditation under Law No. 43-20.
- Party identification, PSCo selection and regulatory analysis remain the responsibility of the client and the client's counsel.
2. Architecture
Client application or information system Khatm workflow layer Identity and trust (PSCo, certificates, HSM per project)
Separation between the client's information system, the Khatm workflow and the project's trust infrastructure.
| Layer | Purpose | Typical actors |
|---|---|---|
| Workflow | Prepare, invite, sign, track and evidence | Publisher or integrator and Khatm |
| Identity | Authenticate the signer at signing time | Client IdP, business process, local provider |
| Trust | Selected certificate and signature level | DGSSI-accredited PSCo for qualified level |
3. Moroccan framework
Law No. 43-20 on trust services for electronic transactions, in force since 13 July 2023, designates DGSSI as the national authority. The law governs trust service providers (PSCo) and signature levels.
- DGSSI sets the reference frameworks and publishes the list of accredited PSCo (article 53 of Law No. 43-20).
- Only an accredited PSCo may issue a qualified certificate with the associated presumption of reliability.
- Decree No. 2-22-687 specifies the implementing framework for providers and the content of qualified certificates.
4. Production deployment
In plain language: the demonstration environment validates the technical journey. A signature intended for production use requires connection of the trust infrastructure selected by the project.
- Validate the workflow in the demo or the API sandbox.
- Define the required evidence level with the client's counsel.
- Select the PSCo or the client's PKI.
- Connect identity, certificates and, where applicable, an HSM.
- Verify the trust path in the target PDF viewers.
5. Security considerations
- Do not reuse a demonstration certificate or key in production.
- Separate test and production environments.
- Protect the signing private key (HSM or KMS, access control, logging).
- Do not confuse an “unverified identity” notice in a PDF viewer with document tampering.
- Plan revocation policy (OCSP or CRL) when document lifetime exceeds certificate lifetime.
General information, not legal advice. Confirm the requirements for your transaction with the appropriate adviser or receiving authority.
Sources
Is Khatm compliant with Law No. 43-20?
Khatm does not claim status as an accredited PSCo or Morocco-specific legal compliance. Khatm provides an adaptable workflow layer. Production compliance depends on the PSCo, certificates and architecture selected by the client's project.
Can the workflow be tested before selecting a PSCo?
Yes, via the public demo or the API sandbox, which really sign in PAdES with a self-signed test certificate. They validate the experience and PAdES format. It does not replace a qualified certificate in production.
Where is the list of accredited PSCo published?
On the DGSSI website, in the section on regulated services and products.