12 August 2026

Digital signature in Costa Rica: the problem is not signing, it is signing thirty times

A digital signature carries the same validity as a handwritten one. What almost nobody tells you is what it costs to use when there is more than one document.

In Costa Rica a digital signature carries legal equivalence with a handwritten one. An electronic document signed with your certificate is worth the same as one signed by hand, and that equivalence is established by Law 8454 on Certificates, Digital Signatures and Electronic Documents.

So far so good. The problem shows up when what you have to sign is not one document but forty.

What the law actually requires

Three things worth being clear on before talking about tools:

  • The certificate is issued by a registered certification authority, not by just anyone.
  • That certificate lives on a physical device — card or token — meeting the FIPS 140 level 2 standard. That is why there is a reader and why there is a PIN.
  • The signature allows verifying the document's integrity and uniquely identifying who signed it.

None of that is negotiable, and no serious tool skips it.

The timestamp: the detail everyone overlooks

Here is the point that causes the most trouble later.

A digital signature says who signed. The timestamp says when. Without it, the document's date is whatever the clock on the signing computer said, and that helps nobody who later has to prove something.

There are documented warnings about the validity of signed documents precisely because the timestamp was omitted. It is the kind of mistake you do not notice on signing day and do notice two years later, when someone disputes the date.

The SINPE timestamp solves that: it stamps a time that does not depend on your machine.

And now the real problem

Signing one document with the official tool takes: open the program, load the file, enter the PIN, wait, save. A minute, if you are lucky.

Multiply that by a payroll's receipts, by a professional association's certificates or by a month-end's paperwork. Forty documents means forty PINs and a whole morning. And there is no technical reason for it: the certificate is the same, the reader is the same, the resulting signature is identical. The only thing that changes is how many times you repeat the same gesture.

What to look for in a bulk signing tool

If you are going to solve this, these are the questions that matter:

  1. Does it sign a batch with one PIN? That is what turns a morning into two minutes.
  2. Does it include a timestamp? If not, you are signing without a trustworthy date.
  3. Does it produce PAdES-LTV? That is the format that lets a signature be validated years later, even after the certificate has expired. Without it, the signature becomes hard to verify over time.
  4. Do the documents leave your machine? If the file is uploaded to a server to be signed, you are handing a third party exactly what you meant to protect.
  5. Can you verify without uploading anything? Checking that a document is intact should not require giving it to anyone.

What we did about it

Firmático came out of this specific problem. You drag the files in, enter the PIN once and the whole batch comes out signed with full PAdES-LTV and a SINPE timestamp. There is a watched folder for dropping documents through the day and signing them all at the end, and verification runs locally.

It runs on Windows, macOS — Apple Silicon and Intel — and Ubuntu, with the same signing engine on all three. The free plan is twenty documents a day with no account; unlimited is nineteen dollars a year.

It changes the legal validity of nothing. It changes how much of your day goes into the procedure.


Firmático is the bulk signing tool we built at egobytes. If your case is stranger than usual, tell us.

Sources: MICITT — Law 8454 · Central Bank of Costa Rica — Digital Signature Regulation

If you can imagine it, we can build it.

Tell us what you need. We'll get back with a clear proposal, no jargon.