A Digital Signature Certificate (DSC) is the legal, cryptographic equivalent of a physical handwritten signature in India. Regulated under the Information Technology Act, 2000, a valid DSC guarantees non-repudiation, signer authentication, and data integrity for all statutory corporate, tax, and procurement filings across Indian government portals.

2026 Regulatory Advisory by the Controller of Certifying Authorities (CCA)

Following CCA regulatory mandates, Class 2 Digital Signatures have been completely discontinued. All filings on the Ministry of Corporate Affairs (MCA V3), GST Network (GSTN), Income Tax e-Filing 2.0, Directorate General of Foreign Trade (DGFT), and government e-Procurement systems (CPPP / GeM) strictly require a Class 3 Digital Signature Certificate stored in a FIPS 140-2 Level 2/3 certified cryptographic USB hardware token.

1. Licensed Certifying Authorities (CAs) in India: Who Issues Your DSC?

Under Section 24 of the IT Act 2000, only licensed Certifying Authorities operating under the root certificate of the Controller of Certifying Authorities (CCA India) are legally empowered to issue digital certificates. Key authorized CAs include:

Certifying Authority (CA) Certificate Types Offered Primary Use Cases Key Advantages
eMudhra Limited Class 3 Individual, Organization, Combo, DGFT MCA V3, Income Tax, GeM, Indian Railways IREPS 99.9% uptime, rapid 15-min paperless eKYC, instant root trust in Adobe Acrobat
Capricorn Identity Services Class 3 Signing, Combo, Organization ROC Annual Filings, GST Invoices, High-Court e-Filing Seamless Capricorn CSP software, easy video KYC, high compatibility with Windows 11
VSign (Verasys) Class 3 Individual, Organization, Combo Corporate Directors, LLP Filings, State e-Tenders Fast mobile OTP verification, robust encryption keys, affordable renewal options
Pantasign & IDSign Class 3 Signing & Combo Trademark Attorneys, Small Business GST, MSME Tenders Cost-effective issuance for entrepreneurs and regional tax professionals

2. Cryptographic USB Token Types: Choosing the Right Hardware Dongle

By CCA mandate, digital signature private keys cannot be saved on local hard drives or exported as software files. They must reside on tamper-evident, FIPS-compliant cryptographic USB dongles. Here is a breakdown of the standard hardware tokens available in India:

Watchdata ProxKey Token

Engineered with high-grade cryptographic smartcard chips. Features built-in auto-run installers for Windows and macOS, zero driver conflict with MCA EmBridge, and ultra-durable metal-reinforced casing.

HYP2003 (HyperPKI) Token

Compliant with FIPS 140-2 Level 3 standards. Universally recognized by Java applets, CPPP tender signers, and Income Tax 2.0 utilities without requiring manual middleware configuration.

mToken CryptoID

Features an advanced Cryptographic Service Provider (CSP) suite. Offers automated certificate caching, intuitive PIN change utilities, and exceptional stability for heavy daily invoice signing.

ePass2003 Auto

The legacy workhorse token used across Indian banks and judicial courts. Offers driver auto-execution and dual RSA/ECC key algorithm support.

3. All Types of Class 3 Digital Signatures Explained

Selecting the wrong certificate type will cause errors during statutory filings. Ensure you select the appropriate certificate profile:

  • Class 3 Individual (Signing Only): Contains the personal identity of the individual. Essential for Directors (MCA DIN filings), Chartered Accountants, Tax Auditors, Company Secretaries, and individual business proprietors.
  • Class 3 Combo (Signing + Encryption): Contains two separate certificates on one USB token. The Signing key authenticates the bidder, while the Encryption key encrypts technical and commercial bids to keep tender proposals sealed until bid opening on CPPP, GeM, and Railways IREPS.
  • Class 3 Organization DSC: Contains both the applicant's name and the registered legal entity name. Mandatory for corporate customs clearance on ICEGATE, corporate banking, foreign remittance filings, and corporate tender bids.
  • DGFT Digital Signature: Customized Class 3 certificate embedded with the organization's 10-digit Import Export Code (IEC). Required on the DGFT portal for duty exemptions, license issuances, and export promotion schemes.

4. Full Lifecycle Operations: Create, Renew, Re-Download & Revoke

  1. Submit your Aadhaar number, PAN, email, and mobile number.
  2. Enter the 6-digit Aadhaar OTP received on your mobile phone to complete instant eKYC.
  3. Record a 20-second selfie video on your smartphone camera showing your original PAN card and stating your name and verification code.
  4. The CA verifies the biometric record and approves the DSC within 30 to 60 minutes. The certificate is downloaded into a new FIPS USB token and shipped to your address.

If you already possess a functional USB token (ProxKey, HYP2003, or mToken), you do not need to pay for a new hardware dongle. Apply for DSC Renewal, complete paperless video verification, and use the CA's certificate utility to download the renewed certificate into your existing token.

If internet disruption or browser closure interrupts the certificate provisioning process onto your USB token, the certificate enters an unconfirmed state. You cannot re-download directly from a browser. Contact our technical team with your CA Application ID and Challenge Code; we initiate a secure token reset protocol with the CA to allow a clean re-download.

Under the IT Act 2000, the subscriber is legally liable for all documents signed by their private key. If your USB token is lost, stolen, or an authorized corporate signatory departs the company, you must submit an immediate Revocation Form along with ID proof. The CA publishes the revoked certificate serial number on the public Certificate Revocation List (CRL) within 2 hours, preventing unauthorized signing.

5. USB Token Driver Setup & Solving Common Portal Errors

Step-by-Step Installation on Windows 10 & 11:

  1. Insert the USB token into your computer's USB port.
  2. Open This PC and locate the Virtual CD Drive representing your token.
  3. Right-click on AutoRun.exe or Setup.exe and select "Run as Administrator".
  4. Complete the setup wizard and verify that the token manager icon appears in your Windows system tray.
  5. Open the token tool, navigate to Change User PIN, and replace the factory default PIN with your secure 8-digit alphanumeric PIN.
Pro-Tip for MCA V3 & Income Tax Portal: If the portal displays "Token Not Detected", ensure that the MCA EmBridge Web Signer service is running in your services manager, ports 8080/8085 are unblocked, and your token driver is fully updated.

Need a Class 3 DSC with Free Driver Setup?

Get your government-approved Class 3 Digital Signature Certificate approved in 30 minutes. Every purchase includes free remote desktop setup support for MCA, GST, and Income Tax portals.