Harun Raaj & AssociatesHarun Raaj & Associates
Business Compliance & Labour Lawvia CCA-licensed Certifying Authority; registered on MCA21, incometax.gov.in, gst.gov.in, DGFT

Digital Signature (DSC) Services

Digital Signatures

Start — upload documents, pay when ready →Talk to a CAWhatsApp us
SCOPEConfirmed in writing

Regulatory Framework

Digital signatures derive their legal effect from the Information Technology Act, 2000. Section 3 provides that a subscriber may authenticate an electronic record by affixing a digital signature; Section 3A extends this to other electronic signatures notified in the Second Schedule (including Aadhaar e-Sign). Section 5 gives legal recognition: where any law requires a document to be signed, that requirement is satisfied by an electronic signature affixed in the manner prescribed. Section 15 defines a "secure electronic signature". Chapter VI (Sections 17–34) creates the Controller of Certifying Authorities and the licence under which Certifying Authorities issue certificates; Section 35 governs the application for a certificate and Section 38 its revocation.

Portal requirements sit in the filing law, not the IT Act: the Companies (Registration Offices and Fees) Rules, 2014 require MCA e-forms to be signed with a DSC; Rule 26 of the CGST Rules, 2017 requires companies to verify GST filings by DSC (proprietors and partners may use Aadhaar e-Sign); the Income-tax e-filing portal accepts a DSC registered to the signatory's PAN.

Overview

A Digital Signature Certificate (DSC) is the electronic equivalent of a handwritten signature, issued by a Certifying Authority licensed by the Controller of Certifying Authorities (CCA) under the Information Technology Act, 2000. The Act gives it legal standing: Section 3 provides for authentication of electronic records by digital signature, Section 5 gives an electronic signature the same legal recognition as a handwritten one where the law requires a signature, and Section 15 sets the conditions for a "secure electronic signature". Chapter VI of the Act (Sections 17–34) establishes the CCA and the licensing of Certifying Authorities that issue certificates. In practice, DSCs are the keys to the government's digital systems: MCA21 filings, income tax e-filing, GST returns, DGFT and the e-tender platforms.

The DSC is the identity behind every online filing a business makes. When a director signs a form on the MCA portal, a partner signs a GST return, or an authorised signatory files an ITR, the DSC is what the government accepts as that person's signature. Since 1 January 2021 only Class 3 certificates are issued; the certificate must be registered on each portal before it can sign there.

The failure mode of DSCs is operational: an expired certificate stops every filing on the portals that require it, and a certificate tied to a person who has left the company creates a signature gap. Each of these is discovered at the filing deadline, which is exactly when a fix is hardest.

This service is for individuals and companies that need DSCs issued, renewed or managed. We identify the right certificate for your filings, coordinate the identity verification and issuance with a CCA-licensed Certifying Authority, register the certificate on the portals, and track renewals so no filing is ever blocked by an expired key.

From 21 September 2026, every new DSC is issued on a FIPS 140-3 validated USB token — the older FIPS 140-2 standard is discontinued for fresh issuances on CCA's directive. If your DSC is already loaded on a FIPS 140-2 token, it remains valid until its expiry date; nothing changes for live certificates.

What does change: the new tokens require emSigner version 3.3 or later to function on the GST portal. Older versions of emSigner will not recognise the new hardware. A renewal or fresh procurement after 21 September means we set up the FIPS 140-3 token and confirm emSigner compatibility before handing over, so the signing step works the first time you need it.

How It Works

  1. 1

    DSC Requirement Mapping

    We identify the certificate class and type needed for your filings and portals.

    Harun Raaj & Associates does this1 day
  2. 2

    Identity Verification

    You complete the KYC and identity verification with the Certifying Authority.

    You do this1-2 days
  3. 3

    Certificate Issuance

    We coordinate the issuance from a licensed Certifying Authority under the IT Act 2000.

    Harun Raaj & Associates does this1-2 days
  4. 4

    Installation & Portal Mapping

    We install the DSC and map it to the MCA, income tax, GST and DGFT systems.

    Harun Raaj & Associates does this1 day
  5. 5

    Renewal Management

    We track validity and renew certificates before expiry so filings are never blocked.

    Harun Raaj & Associates does thisOngoing

Frequently Asked Questions

Which class of DSC is mandatory for filing company forms on the MCA21 portal?
Class 3 DSC is mandatory for all filings on the MCA21 V3 portal, including incorporation forms such as SPICe+, and annual filings such as AOC-4 and MGT-7A. This requirement flows from the Information Technology Act 2000 read with the Companies (Registration Offices and Fees) Rules 2014. A Class 2 DSC is no longer accepted by the Controller of Certifying Authorities (CCA) as the CCA discontinued Class 2 issuance from January 1, 2021. The DSC must be issued by a licensed Certifying Authority under Section 24 of the IT Act 2000 and registered on the MCA21 portal before any e-form can be digitally signed.
What is the validity period of a Class 3 DSC and how do we renew it before it expires?
A Class 3 DSC is typically issued with a validity of one or two years from the date of issuance, as permitted by the Certifying Authority under the Information Technology (Certifying Authorities) Rules 2000. Renewal must be initiated before the existing certificate expires, because an expired DSC cannot be used to sign any e-form on MCA21, the Income Tax e-filing portal, or the GST portal. The renewal process requires fresh identity and address verification with the Certifying Authority, though some CAs offer paperless Aadhaar-based e-KYC renewal under the IT (CA) Rules. We track DSC expiry dates for all authorised signatories and initiate renewal at least 30 days in advance to avoid filing disruptions.
Our company director is an NRI — can they obtain a Class 3 DSC, and what documents are needed?
Yes, an NRI director can obtain a Class 3 DSC from any CCA-licensed Certifying Authority in India, but the documentation requirements differ from resident applicants. Acceptable identity proof includes a valid passport, and the documents must be attested by the Indian Embassy or Consulate in the country of residence, or apostilled as applicable under the Hague Apostille Convention where the country is a signatory. The verification process is governed by the Information Technology (Certifying Authorities) Rules 2000, Schedule I, which lists acceptable identity and address proof categories. Physical presence in India is not mandatory if the CA supports video-based verification or Embassy attestation.
Is a separate DSC required for GST filings, or can the same DSC used for MCA be used on the GST portal?
The same Class 3 DSC can be registered and used across multiple government portals — MCA21, the Income Tax e-filing portal (www.incometax.gov.in), and the GST portal (www.gst.gov.in) — provided the PAN of the authorised signatory matches across portals. Under Rule 26 of the CGST Rules 2017, a company must mandatorily use a DSC for filing on the GST portal if the applicant is a company incorporated under the Companies Act 2013. The DSC must be registered separately on each portal, and the USB token containing the private key must be accessible at the time of signing. Individual proprietors and partners may use Aadhaar-based e-Sign as an alternative under the same Rule 26.
What happens if a DSC is compromised or the USB token is lost — is there a revocation process?
Yes, a compromised or lost DSC must be revoked immediately by submitting a revocation request to the issuing Certifying Authority under Section 38 of the Information Technology Act 2000, which empowers CAs to suspend or revoke certificates. Once revoked, the certificate is listed on the CA's Certificate Revocation List (CRL), and no portal will accept signatures made with it. The subscriber is legally responsible for all actions taken with the DSC until revocation is confirmed, so prompt action is critical. After revocation, a fresh DSC must be procured with new key generation; the old private key from the lost token cannot be reissued.

Ready to get Digital Signature (DSC) Services?

File a request in under 2 minutes. Our team contacts you within 24 hours.

Start — upload documents, pay when ready →