← Back to Services

Start

Digital Signature Certificate (DSC)

A Digital Signature Certificate links a verified subscriber to a cryptographic key so that supported electronic documents and portal filings can be signed with identity and integrity assurance.

National law / regulated trust service

Last Reviewed: 29 July 2026
Next scheduled review: 29 October 2026
Reviewed by: IndiaBusiness.ai Editorial

Who it’s for

Directors, designated partners and authorised signatories filing on portals that require a DSC.
Bidders and suppliers using e-procurement or tender systems that specify a permitted DSC class.
Professionals who certify or sign statutory electronic forms.
Organisations that need a reusable certificate rather than a transaction-specific Aadhaar eSign.

When you may not need it — You may not need a reusable DSC if the receiving portal expressly accepts OTP authentication, Aadhaar eSign or another electronic-signature route. The receiving application—not the consultant—decides the certificate class, certificate fields and signing method it accepts.

Verified at-a-glance facts

Regulator
The Controller of Certifying Authorities licenses and regulates Certifying Authorities in India
Common high-assurance certificate
Class 3; CCA states that a Class 3 individual certificate can satisfy a lower-assurance Class 2 requirement
Private-key storage
For Class 3, CCA requires an approved hardware cryptographic device / permitted HSM arrangement, subject to the applicable certificate type
Validity
Read the validity shown in the certificate and licensed CA product; do not promise one universal validity period
Legal distinction
Aadhaar eSign commonly uses a short-validity transaction certificate and is not the same as a reusable token-based DSC

Key facts and choices

DecisionOptionsWhat the user must know
Subscriber identityIndividual / organisational person / device or system certificateAn employee’s certificate remains tied to the subscriber; the organisation must not retain or use the person’s signing key after authority ends
Intended useSignature / encryption / combined, where offeredA signature certificate does not automatically provide encryption capability
Assurance classDetermined by the relying portal and riskDo not sell a class merely because it is more expensive
Key environmentApproved USB crypto token or permitted HSMThe private key and PIN must remain under authorised control
PAN or organisation fieldsIncluded only where the receiving application requires themA technically valid DSC can still be rejected if required certificate fields are absent

Scope and exclusions

IndiaBusiness can help identify the required certificate, coordinate licensed-CA KYC, help install middleware and register the DSC on a supported portal. IndiaBusiness does not issue the certificate, control the private key, guarantee compatibility with every portal, or sign a document in place of the subscriber.

Process

StageIndiaBusinessApplicantIssuer / portal
Requirement checkConfirms portal, role, class, PAN/organisation-field and signing environmentConfirms intended use and authorityPortal publishes acceptance requirements
ApplicationPre-checks data and documentsCompletes KYC, authentication and subscriber agreement personallyLicensed CA performs identity verification
Key issuanceHelps with approved software/token setupMaintains control of token and PINCA issues certificate under its approved practice statement
Portal activationGuides registration and performs a non-sensitive signing testLogs in and authorises actionsRelying portal validates certificate
LifecycleRecords expiry and role-change remindersReports loss, compromise or role exit immediatelyCA revokes or re-keys where appropriate

Documents needed

  • PAN and accepted proof of identity/address, as required by the licensed CA route selected.
  • Applicant-controlled mobile number and email.
  • Video or physical verification inputs where prescribed.
  • Entity proof and authority letter for an organisational-person certificate.
  • Exact legal name and role used on the receiving portal.
  • Existing token details only for compatibility checks; never disclose the PIN.

What IndiaBusiness takes care of

  • DSC requirement matrix for the intended portals.
  • Licensed-CA application coordination and discrepancy review.
  • Token driver / signer utility checklist.
  • MCA, income-tax, DGFT or other supported portal registration guidance.
  • Expiry, role-exit and revocation control sheet.

Questions founders ask

Is a scanned signature or an image of a signature a DSC?

No. A DSC relies on a certificate and private key. A pasted signature image does not authenticate the signer cryptographically or show whether the document changed after signing.

Can my employee or consultant keep my token and sign for me?

The subscriber must control the signing key. Never share the token PIN or permit an unauthorised person to sign as the subscriber.

Can one Class 3 DSC be used everywhere?

Not automatically. Portals can require specific certificate fields, organisation mapping, middleware or signing formats. Compatibility must be checked portal by portal.

What happens if the token is lost or the key may be compromised?

Stop using it and ask the issuing CA to revoke the certificate promptly. Replacement is not merely a reprint; a new key/certificate process may be required.

Can IndiaBusiness issue the DSC?

No. A DSC is issued by a CCA-licensed Certifying Authority. IndiaBusiness can facilitate the process without representing itself as the issuer.

Information is general and reflects sources reviewed on the date shown. Eligibility, documents, fees, timelines and outcomes depend on the applicant’s facts and the current law, authority portal or platform policy. IndiaBusiness provides advisory and execution support; approval and enforcement decisions remain with the relevant authority, certification body, platform, bank or other decision-maker.