What are the types of digital certificates from ICP-Brasil?

Table of Contents

Os digital certificates ICP-Brasil are electronic identities issued within the official Brazilian infrastructure to prove authorship, preserve document integrity, and give legal validity to signatures. Therefore, knowing the... types of ICP-Brasil digital certificates It helps to understand which model makes sense for an individual, company, system, or automated operation without choosing an option that is incompatible with the routine, the expiration date, or the technological environment used on a daily basis.

In business operations, this issue affects issuance time, renewal costs, ease of use, compatibility with ERPs, public portals, tax issuance, and signature workflows. It also affects risk: an inadequate certificate can lead to access failures, rework, dependence on physical media where it is not necessary, or, conversely, the purchase of a simple format for a scenario that requires stricter controls.

Summary

  • ICP-Brasil certificates are divided between classic models and new formats created by regulatory modernization.
  • Individuals and legal entities do not follow exactly the same logic regarding issuance and use.
  • Formats in software, hardware, and cloud are changing the operational experience, timeline, and compatibility.
  • KPIs such as validity, issuance time, failure rate, and system adherence help in making better choices.

Quick facts

  • According to gov.br, the service Obtain a Digital Certificate It states that the A1 certificate is valid for 1 year, the A3 certificate can be valid for up to 5 years, and the cloud certificate is listed as a usage option.
  • According to the Digital Government, in CNPJ linking on gov.br e-CNPJ A1 or A3 certificates are accepted, while a personal identification certificate is not valid for this operation.
  • According to SEF/MG, in Frequently asked questions about NF-e (Brazilian electronic invoice). The company's certificate can be A1, stored on the computer, or A3, on a smart card or token, as long as it is issued by a Certification Authority (CA) accredited by ICP-Brasil.

How to understand the types of ICP-Brasil digital certificates

The starting point is to separate purpose, holder, and storage. Broadly speaking, ICP-Brasil has historically worked with signature and confidentiality certificates, while the regulatory update has more clearly distinguished between certificates for personal signatures, electronic seals for legal entities, and specific applications. For those dealing with contracts, powers of attorney, petitions, and corporate authentication, this distinction reduces ambiguities and helps align legal use with technical architecture.

This organization also discusses related topics, such as electronic signature and digital certificateThis is because not all electronic signatures depend on an ICP-Brasil certificate, but all ICP-Brasil signatures follow a more formal standard of identity and chain of trust. In regulated areas, this often outweighs the simple convenience of signing quickly.

The classic types that many people still find on the market.

For many years, the conversation about digital certificates revolved around the A and S families. In everyday use, the best known were the... A1 digital certificate and the A3 digital certificate, especially in the commercial e-CPF versions and e-CNPJThe S1 to S4 models, on the other hand, were geared towards encryption and secrecy, which explains why they became less popular outside of specific technical contexts.

According to ITI, ICP-Brasil defined eight classic types of certificates for holders, classified as A1, A2, A3, A4, S1, S2, S3 and S4, information available in the Concepts Guide.This helps explain why so many older materials still use this classification, even though more recent regulations have introduced new formats.

Classic typeMost commonly associated useTypical storagePractical observation
A1Signature and authenticationFile in softwareSimpler to install, integrate, and automate.
A3Signature and authenticationToken, card, or cloud, as offered.More dependent on media or authorization workflow.
A4Signature on more robust hardwareHardwareLess common for the general public.
S1 and S4Secrecy and encryptionSoftware or hardware, depending on the profile.Rarely seen in simpler corporate demands.

Individuals and legal entities follow different logics.

In practice, personal digital certificates remain linked to the individual actions of the holder. They are used to sign documents, access systems, and represent one's own digital identity. Corporate digital certificates, on the other hand, involve the organization as the holder and a natural person as the responsible user, which changes governance, revocation, and internal controls.

This connects to widespread corporate use. According to ITI, ICP-Brasil certificates for legal entities marketed as e-CNPJ, NF-e, or e-PJ were for broad and unrestricted use, without automatic limitation to a single purpose.In operational terms, this avoids the mistake of thinking that a certificate labeled for invoices can only be used for invoices, when it is the policy of the issuing CA and the destination system that need to be checked.

A1, A3, A4 formats and cloud computing in practical operation.

The market has accustomed the public to comparing A1 and A3, so this remains a good practical guide. A1 tends to appeal to teams that need simple installation, system integration, and less friction for recurring use. A3, in turn, is usually associated with a token, card, or additional authorization, which can make sense when the company prefers to keep the key off the computer or when a system requires this format.

There's also the cloud experience, which changes the legal nature of the certificate less and its usage more. For those who want to reduce their dependence on physical tokens, it's worth looking at how a cloud-based system works. digital certificate in the cloud And when it best fits multiple devices, remote approvals, and distributed operations. In some companies, this choice reduces IT calls related to drivers, USB ports, and media loss.

A simple way to compare is to look at four criteria at the same time:

  1. Issue timeThe more in-person steps, validations, and local setup required, the greater the initial effort.
  2. Shelf lifeThe deadline alters the renewal schedule and lifecycle cost.
  3. System compatibilityERP systems, tax portals, gov.br, signers, and integrations do not always accept the same payment methods.
  4. Failure reductionErrors related to installation, access, or misuse need to be reported to the account.
CriterionA1A3Cloud
InstallationSimplerMore dependent on media and configuration.It depends on the app or remote workflow.
Student ExchangeMediaLow to mediumHigh
AutomationIt tends to make things easier.It may require further adaptation.It depends on the provider and the system.
operational riskCareful attention to backup and access is required.Requires care with physical media.Requires remote authentication management.

What changed with SE-S, SE-H, AE-S and AE-H?

Regulatory modernization has reorganized the portfolio and better separated personal signatures, electronic seals, and specific applications. According to ITI, Resolution CG ICP-Brasil No. 211/2024 created the SE-S, SE-H, AE-S, and AE-H types and eliminated A1, A2, and S1 to S4 within the scope of the new rule, with details publicly available on the standard's specific page.In practice, this shifts some of the old logic toward models that are more compatible with corporate automation and the identification of organizational origin.

The SE-S and SE-H are certified for electronic seal For legal entities, these serve to guarantee the origin and integrity of a document issued by the organization, without transforming that act into a personal signature of an individual. AE-S and AE-H, on the other hand, were designed for equipment, servers, applications, and devices within closed ecosystems, which directly relates to system integrations, machine-to-machine authentication, and automated operations.

This issue becomes even clearer when a company compares what needs to be signed personally with what only needs to be identified and protected as originating from an institutional source. In some workflows, the problem isn't "which certificate signs better," but rather "which certificate avoids using a personal signature where the correct approach is to use a specific seal or application." This distinction reduces the risk of inadequate legal design and improves governance.

Regulatory transition and attention to legacy systems.

Migration doesn't mean everything disappears overnight. Digital certificates issued in chains Previous certificates continue to coexist during a transition period, which requires the company to map current inventory, integrated systems, and renewal schedules. This information is especially relevant for legal, tax, and IT departments that operate with multiple certificates in parallel.

Check out these related articles as well:

Choosing the right type reduces friction, cost, and failure.

Choosing the right document doesn't just depend on price or nominal validity. The best approach is to consider legal purpose, storage method, acceptance within the company's systems, and internal support effort. In terms of management, the most useful KPIs are average issuance time, expiration date, call rate due to incompatibility, number of usage failures, and time saved in workflows that previously depended on paper, movement, or recurring manual installation.

When a company documents these indicators, the choice between classic models, cloud computing, and new formats ceases to be a decision based on habit. It becomes a decision of operational architecture.

If you're looking for predictability, legal certainty, and less friction in daily use, understanding the... types of ICP-Brasil digital certificates This step prevents you from making the wrong purchase now and having to redo the work during the next renewal, as well as helping with the evaluation. To learn more about how ZapSign functions as a Certification Authority, click here..

Frequently Asked Questions (FAQ)

What are the most well-known types of digital certificates from ICP-Brasil?

The most well-known types on the market were A1 and A3, especially in e-CPF and e-CNPJ offerings. Historically, ICP-Brasil also worked with A2, A4, and the S1 to S4 confidentiality certificates. With regulatory modernization, SE-S, SE-H, AE-S, and AE-H also emerged, each with a more specific purpose within the new regulatory framework.

What is the difference between a certificate for an individual and a certificate for a legal entity?

A personal digital certificate represents the digital identity of the holder and is typically used to sign and access systems on behalf of that person. A corporate digital certificate, on the other hand, has the organization as the holder and a specific individual as the responsible user. This changes the rules regarding governance, revocation, proof of authority, and internal usage controls.

Do A1 and A3 serve the same purposes?

In many scenarios, both can fulfill similar authentication and signing functions, but the user experience differs significantly. A1 is usually a file installed in software, while A3 typically relies on cryptographic media or an equivalent stream. Therefore, the comparison should consider compatibility with the target system, operational routine, mobility, and the company's security requirements.

What are SE-S and SE-H?

SE-S and SE-H are electronic seal certificates created for legal entities. Instead of representing someone's personal signature, they serve to guarantee the origin and integrity of documents issued by the organization. The main difference between the two lies in the storage medium: software in SE-S and hardware in SE-H, respecting the applicable policy.

How to choose the most suitable digital certificate?

The choice should be based on the actual intended use. It is advisable to verify whether the certificate will be used by an individual, company, application, or piece of equipment, as well as to analyze its validity, storage method, system integration, acceptance on public portals, and historical failure rate. When these criteria are considered in the purchasing process, the chance of rework and hidden costs tends to decrease.

Leave a comment

six + six =

zapsign

Start your free trial today!

Try our digital signature tool for free.
The first 5 documents
are free!

Share this article

Do you want to stay informed?

Subscribe to our blog

Related articles