Security
What does 'certify the document' mean, and which permission level should I pick?
Certifying means signing as the document's author and stating what anyone else is allowed to do to it afterwards. You choose one of three levels: nothing at all, filling in forms and signing, or those plus comments. Anything beyond the level you chose shows as a change in PDF readers.
In the Digital Signature tool, under "What can change after signing", there is a dropdown called "Certify the document". Most people should leave it on the first option.
The four choices, in plain words
No, an ordinary approval signature. The normal choice. You are one of the people signing. Others can sign after you. This is what you want for a contract, an offer letter or an invoice you are approving.
Certify: no changes allowed. You are the author and the document is finished. Nobody may add anything, not a signature, not a comment, not a filled-in field. Choose this for a finished certificate, a published report, a diploma, a bank statement.
Certify: form filling and signing allowed. You are the author of a form. People may type into the boxes you made and add their signatures. They may not change your text or your layout. Choose this for an application form or a template someone else will complete.
Certify: form filling, signing and comments allowed. The same, plus people may add notes and highlights. Choose this for a draft going round for review, where you want the text itself protected but the comments welcome.
The everyday version
Think of a printed form you hand to a customer.
- Ordinary signature: you sign at the bottom, like everyone else does.
- Certify: no changes: you laminate the whole sheet. It can be read; it cannot be written on.
- Certify: form filling and signing: you laminate everything except the blank boxes. Fill those in; the printed text stays as it is.
- Certify: plus comments: the same, but sticky notes are allowed on top.
What "shows as a change" actually means
Certifying does not physically stop anyone from editing a file. Nothing can. What it does is make any step outside your chosen level visible and provable.
If you certify with "no changes allowed" and somebody adds a page, then anyone who opens the file in a PDF reader (or in Verify PDF Signature) sees that the document was changed after certification. The trust is gone, and it is gone in a way nobody can talk their way out of.
That is the whole point: not prevention, but evidence.
Only the first signature can certify
A document can have one certifying signature, and it must be the first one. This is not our rule; it is how PDF certification is defined. It makes sense: only the author can say what the document is allowed to become.
So in the tool:
- If the document you uploaded already has a signature, the dropdown is switched off, with the note "This document already has a signature. Only the first signature can certify a document."
- If you are signing several documents at once and some of them are already signed, you are warned that those will be reported as not signed rather than silently signed the wrong way.
A document certified with "no changes" cannot be signed again
If you upload a PDF that somebody already certified at the strictest level, the tool refuses it straight away: "This document is certified with 'no changes allowed', so no further signature can be added to it."
That is the certification doing its job. If you need signatures on it, ask whoever made it for a version certified at a level that allows signing, or for an uncertified copy.
Which should you pick?
For nearly everything: No, an ordinary approval signature.
Certify only when you are the one issuing the document and you want to control what happens to it next. Getting this wrong is inconvenient rather than dangerous, but "no changes allowed" on a contract that three other people still have to sign will stop all three of them.
Certifying and locking are not the same thing
Just below the dropdown there is a separate tick box, "Lock the document after signing". That one is narrower. It is about form fields only. The two can be used together, and they are explained separately in what 'lock the document after signing' does.
Common questions
What is the difference between signing and certifying a PDF?
Signing says you agree with the document. Certifying says you are its author and sets the rules for what anyone may do to it afterwards: nothing, form filling and signing, or those plus comments.
Which certification level should I choose?
Use 'no changes allowed' for a finished document nobody should add to. Use 'form filling and signing allowed' for a form others will complete. Use the comments level for a draft under review. If you are simply one of several signers, do not certify at all.
Why is the certify dropdown greyed out?
Because the document already contains a signature. Only the first signature in a document can certify it.
Can someone still edit a certified document?
Yes, a file can always be edited. The difference is that any change beyond the level you allowed shows up clearly in PDF readers and in signature checkers, so it cannot be hidden.
My PDF says it is certified with no changes allowed and I cannot sign it. What now?
That is the certification working as intended. Ask whoever issued it for a version certified at a level that allows signing, or for an uncertified copy.
Is certifying the same as password-protecting a PDF?
No. A password controls who can open or edit a file. Certifying does not restrict access at all. It records what was allowed, so later changes are detectable.