Skip to content
Digital Signatures

Digital signature questions, answered

Which certificate, what it costs to get wrong, how issuance actually runs, what happens at renewal, and what to do when a token stops being recognised.

How issuance works

From documents to a working certificate

The same four steps for every certificate. What changes between them is the document list, not the process.

  1. Send your documents

    PAN, Aadhaar or address proof, and organisation documents where they apply. We check them against the certifying authority's requirements before anything is submitted, rather than after a rejection.

  2. Complete verification

    Identity is confirmed against your documents, followed by a short recorded video verification from your own phone. It is required for every Class 3 certificate and cannot be skipped.

  3. Receive the certificate

    The certificate is generated and loaded onto a FIPS 140-3 compliant USB token, which is delivered or collected and tested working before you rely on it.

  4. Register it on the portal

    A certificate does nothing until it is mapped to your account — against your GSTIN, your MCA profile, your EPFO establishment or your IEC. We complete this step with you.

Renewal & re-issue

Validity, renewal and what to do when something goes wrong

What renewal actually means in India, and what changes depending on when you start it.

Renewal is a brand-new certificate
No certifying authority extends an existing one. Each time, you get a fresh serial number and choose the validity term again. "Renewal" is only the industry's name for doing it before the current certificate expires.
Starting before expiry repeats less
Apply while the certificate is still valid and you can usually keep your existing token and move faster, because less has changed since your last verification.
There is no grace period
The moment a certificate expires it stops signing. A new one is then treated as a fresh application, with full verification again.
A lost or damaged token needs revocation, not renewal
Revoking adds the certificate to the certifying authority's Certificate Revocation List, so it cannot sign anything again — even for someone holding the physical token. This should happen immediately, not once the paperwork is convenient.

Renewing soon?

Tell us your expiry date and we will start it before the certificate lapses, so a filing deadline never arrives without a working signature.

Start a renewal
FAQs

DSC questions, answered

Everything we are asked most often about certificates, tokens, validity and renewal.

Ask us something else
  • Individual, if you are signing in your own personal capacity: income tax filing, trademark filing, or acting as a director on MCA where directors sign as officers rather than on behalf of the entity. Organisation, if you are signing on behalf of a company or LLP — ROC filings by an authorised signatory, corporate tender bidding, company GST or EPFO submissions. If you are not sure which applies to you, use the finder above or message us before you order.

  • Usually not. Directors sign MCA forms in their personal capacity as officers of the company, so a Class 3 Individual certificate in your own name is normally sufficient — and it costs less. One thing to check: the PAN on your certificate must match the PAN in your DIN record, including how your name is spelled. Mismatches there are the most common reason association fails on the portal.

  • A Class 3 Combo, which carries both signing and encryption. Most procurement portals require bids to be signed and encrypted before submission. Encryption cannot be added to a signing certificate afterwards, so buying signature-only and discovering the requirement on the closing day means losing the tender rather than delaying it. Send us the tender document and we will confirm what it asks for before you order.

  • Not necessarily, and this is where exporters most often overspend. The DGFT portal validates against your IEC profile. For a proprietorship, a Class 3 Individual or Organisation certificate works where it matches the PAN in that profile. For companies and LLPs, a Class 3 Organisation certificate works where the organisation name matches the PAN database name. A dedicated DGFT token with the IEC embedded is a third option, useful in some cases but not compulsory. Whichever you use has to be registered against your IEC on the DGFT portal before it is recognised there.

  • Yes, and most people should. A single Class 3 Individual certificate covers income tax, GST, MCA and trademark filings. You would need a separate Organisation certificate only where you sign on behalf of an entity, and a Combo only where a portal requires encryption. Tell us everything you file on and we will work out the smallest number of certificates that covers it.

  • It is a short recorded call confirming your identity against your submitted documents, required by the Controller of Certifying Authorities for all Class 3 issuance. It applies to every certificate type — individual, organisation, combo, DGFT and renewals alike — and it cannot be skipped. It takes a few minutes on your own phone and has to happen before the certificate is generated, not after.

  • Both. It is issued to the organisation but carries the named signatory as the certificate holder, since a digital signature is legally tied to an individual acting in an authorised capacity, not to an entity in the abstract. If your authorised signatory changes, the existing certificate stays valid for the original signatory until it expires, but a new one is needed for the new signatory — they are not transferable between people.

  • It is always a fresh certificate — Indian certifying authorities do not extend an existing one's expiry. "Renewal" describes doing this before your current certificate lapses, which usually lets you reuse a working token and moves faster since less has changed since your last verification. Renewing also resets the validity period rather than adding to what was left.

  • Yes. A Class 3 certificate must be stored on a compliant USB crypto token and cannot be held as a file on a computer. The token itself does not expire and can usually be reused when the certificate is renewed. If you already have one, send us the model and we will confirm whether it can be reused.

  • Yes. Foreign applicants use a passport-based route with attested supporting documents rather than Aadhaar. The whole process can be completed from outside India and the token couriered internationally. The attestation route depends on your country — apostille where it is party to the Hague Convention, otherwise attestation by the Indian Embassy or Consulate — so confirm which applies before preparing anything, because getting it wrong means doing it twice.

  • The certificate follows the same standard regardless of issuer, but genuineness and the support you get afterwards depend entirely on going through a properly authorised certifying authority. We issue through a licensed Certifying Authority rather than reselling from an issuer of unknown standing. Class 3 is also the only class still issued — if you are being offered a choice of class, that tells you something about how closely the vendor follows this business.

  • No. Everything is done online, including the verification, which takes a few minutes on your own phone. The token is couriered to you. We work with clients across India and outside it.

  • It depends on the certificate type and the term you choose at issuance — most of our certificates offer a 1, 2 or 3-year term, and a combo (sign + encrypt) certificate is offered at 2 or 3 years. The certificate types section above lists the options for each.

  • Yes — an individual can hold a personal certificate and an organisation certificate simultaneously if they act in both capacities, and a business can hold separate certificates for different authorised signatories. Each certificate is independent of the others.

  • It stops working immediately, with no grace period — any portal or software checking the certificate will reject it from that point on. There's no partial or reduced functionality; it's valid one moment and unusable the next.

  • No. A signature made while the certificate was valid stays valid for that document — revocation only stops the certificate from being used to sign anything new from that point forward. This is exactly why revoking promptly after a loss matters: it can't undo past signatures, but it does stop future misuse.

  • It's the certifying authority's public record of every certificate that's been revoked before its natural expiry, checked automatically by portals and signing software before they'll accept a signature. It's how a lost or compromised certificate is actually blocked from further use, rather than just being reported as lost somewhere informal.

  • The certificate itself keeps working exactly as issued, since it was generated against the details verified at the time. But it will no longer reflect your current details accurately, so it's worth having it re-issued against your updated documents rather than continuing to sign with certificate details that no longer match reality.

  • Most certifying authorities allow this, though it means paying for a new validity term that overlaps with time still left on your current one. It can be worth it if you'd rather not track a renewal date closely, but for most people renewing closer to — but still comfortably before — expiry makes better use of what you've already paid for.

Still working out which certificate you need? The finder asks two questions and names it, with the documents and validity for that one.

Find your certificate

Question not answered here? Ask us directly.

Send the portal, the certificate you hold and what it is doing — most of these are settled in one message rather than a call.