Security
What does an archive timestamp add to a signed PDF?
An archive timestamp is a second, independent timestamp taken over the whole finished file (signature, evidence and all) so that the stored evidence itself is proved to be original and untouched. It is the last step for documents meant to survive decades.
The third tick box under Long-term proof in the Digital Signature tool is "Add an archive timestamp". It is off by default, and most people do not need it. Here is who does.
What is already in place before it
By this point you have, in order:
- The signature: proof the document has not changed and who signed it.
- [A trusted timestamp](/blog/what-is-a-trusted-timestamp-on-a-signed-pdf): proof of when the signature was made.
- [Long-term validation](/blog/what-long-term-validation-ltv-means): the certificates and cancellation checks, packed into the file so it can be judged later without the internet.
That is already a strong file. So what is left?
The gap it closes
Step 3 stores evidence. But that evidence was added after signing, and it is not itself covered by the original signature. In a hundred-year archive, someone eventually asks the awkward question: *how do we know that evidence is the original evidence, and not something swapped in later?*
The archive timestamp answers it. It wraps a fresh, independent timestamp around everything (the document, the signature, the first timestamp, and the stored evidence) and says: all of this existed together, exactly like this, on this date.
The everyday version
Think of a box of papers going into a records office.
- The signature is the signed contract inside.
- The trusted timestamp is the date stamp on the contract.
- Long-term validation is the supporting paperwork you put in the box alongside it.
- The archive timestamp is the records office sealing the whole box and writing the date across the seal.
Break the seal and everyone can see. Nothing inside can be quietly replaced.
Why it needs the other two
The tick box is greyed out until long-term validation is on, which in turn needs the trusted timestamp. The tool's hint says it directly: "Seals the whole file, including the validation data, for archiving. Needs long-term validation."
There is no point sealing a box that has nothing in it to protect.
Who actually needs it
Turn it on for:
- documents going into a long-term archive: deeds, permits, court filings, medical or academic records,
- anything you are told must follow a formal archiving rule, often described as B-LTA or "long-term archival",
- files you genuinely expect to be reopened in twenty or thirty years.
Leave it off for:
- ordinary contracts and offer letters,
- invoices and approvals,
- anything where five to ten years of proof is more than enough.
What it does not do
It does not make your signature more valid. It does not add anything about who you are. It does not change whether a reader shows a green tick. It is purely about keeping the whole package provably intact over a very long time.
What happens if the attempt fails
Timestamping the finished file means one more call to an independent service. If that call fails, the tool does not quietly carry on and let you think it worked. The result page shows either "An archive timestamp seals the whole file, including the validation data" or "The archive timestamp was not added."
Your document is still signed either way. You simply know exactly what you have.
Can I add one to a file that is already signed?
Yes. In principle, an archive timestamp is a seal over a file, not a signature by a person, so it can be added to a finished document. In the Digital Signature tool it is applied as part of the signing you are doing now, at the end of the same run.
How to see whether a file has one
In Verify PDF Signature, a document timestamp shows up as its own entry in the list of signatures, and the PAdES level noted beside a signature moves up to B-LTA when everything is in place.
Common questions
What is an archive timestamp in a PDF?
It is a timestamp taken over the whole finished file. The document, the signature, the earlier timestamp and the stored validation evidence. Proving that the entire package existed in exactly that form at a known date.
How is it different from the trusted timestamp?
The trusted timestamp covers the signature and says when it was made. The archive timestamp comes last and covers everything, including the evidence added after signing.
Do I need an archive timestamp?
Only for documents meant to last a very long time, or when an archiving rule asks for it. For ordinary contracts and forms, a trusted timestamp with long-term validation is already strong.
Why can't I tick the archive timestamp box?
It needs long-term validation switched on, which in turn needs the trusted timestamp. Turn those on first and the box becomes available.
What does B-LTA mean?
It is the name for the most complete level of PDF signature: a signature, a timestamp, stored validation evidence, and an archive timestamp over all of it. You will see it written beside a signature in the verification result.
What if the archive timestamp cannot be added?
The result page says so plainly. The document is still signed and still carries its other protections; only the final seal is missing.