The word "signature" in the name is what misleads everybody, because a signature is something you do and this is something you have. A digital signature certificate is your capacity to sign, issued to you after somebody checked that you are you, and kept inside a small device in a drawer. And anything you have can be held by somebody else. Which makes the real subject of this page not technology but custody, and everything here sorts by one question: who can physically use this right now, and would anything show the difference? The answer to the second half is the fact this whole page is built on, and almost nobody has been told it. Nothing in the signed record shows whose finger pressed the button. A filing made by your consultant, holding your token and your PIN, is not merely hard to tell apart from one you made yourself — it is identical. There is no field for it and no log to examine. Three consequences follow. The PIN is not the protection people think it is: it guards against a thief, who has the device and not the code, and not against delegation, because the token is useless without the PIN and so everybody hands over both. Revocation is a door, not a time machine — it stops what can be signed from today and reaches back to unmake nothing, which is exactly where this differs from paper: a lost certificate can usually be reissued, and a filing made in your name cannot be unmade. And the name on it binds, which produces a failure that baffles people: when the details on your certificate do not match the details the system already holds against you, the certificate works perfectly and the filing is rejected. We are not going to lecture you about the thing everybody does. Handing the token to your accountant is how a great deal of routine compliance actually gets done, and if you are going to do it, there are four things worth doing and they are set out plainly below. But the one habit worth more than all four is smaller than you expect: keep the device, and be in the room when it is used. Ten seconds to enter your own PIN at the end of somebody else's work is the difference between handing over your ability to act and watching a filing. And the line we will not cross, however normal the request is in this market: we do not hold anybody's token, and we do not sign in anybody's name.
What this guide covers
The misunderstanding is built into the name, so it is worth taking apart before anything else.
A signature is an act. You perform it, it happens in a moment, and nobody can perform it for you without forging it — and forgery is detectable, because the act leaves traces of whoever actually performed it.
A digital signature certificate is not an act. It is a thing, and the thing is your capacity to produce a valid signature.
The entire difference in one line
An act cannot be lent. A thing can. And when the thing that has been lent is the capacity to sign as you, there is nothing in the result that distinguishes your use of it from anybody else's.
Everything in the rest of this page follows from that sentence, including the parts that sound like security advice and the parts that sound like business advice. It is one idea.
Stated without technical detail, because the technical detail does not help anybody make a decision and goes out of date.
A certifying authority checks who you are. Having satisfied itself, it issues a certificate that says, in effect: signatures produced with this belong to this named person. The means of producing those signatures is then placed inside a small device, and the device is given to you.
Three parts, and notice what the arrangement is designed to guarantee and what it is not. It is designed to guarantee that a signature came from this certificate. It is not designed to establish, and cannot establish, which human being operated it.
So here is the question to put to every arrangement in your own setup, and it is the question this page sorts by:
Who can physically use this right now — and would anything show the difference?
Not "who is authorised". Not "who would I say is allowed to". Who could, today, if they chose. Because in this subject those are the same thing, and the gap between them is where everybody's comfortable assumptions live.
| Where the token and PIN are | Who has your signing ability |
|---|---|
| In your drawer, PIN known only to you | You |
| In your drawer, PIN written on a note beside it | You, and anybody who opens the drawer |
| With your accountant, PIN shared | You and them, equally and indistinguishably |
| With a former consultant you no longer use | You and a firm with no reason to think about you |
| With a staff member who has left | You and somebody outside your organisation |
| Unaccounted for | Unknown — and the PIN is the only thing in the way |
This is the fact that changes people's minds, and it is worth stating three times in three ways because the first two do not land.
Why this matters to you specifically
If you ever need to say that a particular filing was not yours, there is nothing in the technology that helps you say it. People assume the trace exists somewhere, and build their comfort on that assumption. It does not exist.
Note what is not being claimed. This is not a reason to distrust your accountant, who is in all probability entirely reliable. It is a reason to understand that reliability is the only thing standing in the gap, and to decide knowingly rather than by default.
Go and answer it, now, about your own. It takes a minute and it is the only diagnostic on this page.
Almost everybody who does this exercise finds one item they had not thought about, and it is nearly always the third one.
Now the practice everybody follows, named plainly and without disapproval, because disapproval is useless here.
You gave the token and the PIN to your accountant, your company secretary, or your consultant. It was not careless; it was practical. They do the filings, the filings need signing, you are not sitting next to them, and the deadline was that week. A very large share of routine compliance in this country runs exactly this way.
We are not going to tell you to stop
Partly because you may not be able to, and partly because a page that issues an instruction nobody can follow has achieved nothing. What is worth doing is making the arrangement a decided one rather than a default one — which means knowing exactly what it is, and then taking the four cheap steps that make it survivable.
Said precisely, because the precision is the useful part. When you hand over the token and PIN, you are consenting to:
Read the fourth one twice, because it is the one that catches people. The arrangement does not expire when the relationship does. Nothing happens automatically.
And the part that is usually not dishonesty
Much of the trouble we see in this area is not misuse but assumed scope. Somebody signed something they genuinely believed they were authorised to sign, because nobody had ever said where the authority ended. That is a communication failure, not a betrayal — and it is the easiest of all of this to fix.
The honest second best. None of these prevents misuse; together they make the arrangement one you can live with.
| Do this | What it achieves | What it does not |
|---|---|---|
| 1. Write down what it is for. A short note to them listing which filings they may sign, and that anything else is asked first. | Removes assumed scope, which is most of the real trouble | It is not a legal instrument and will not stop anybody |
| 2. Ask for a note of each use — what was filed, when. | Lets you notice, later, which is the only way these things get discovered by you rather than for you | Prevents nothing, undoes nothing |
| 3. Diarise the expiry, and treat renewal as the moment to reconsider the arrangement rather than continue it. | Gives the arrangement a natural review point instead of running for years | Does not address the period before it |
| 4. Revoke promptly in the three situations below. | Closes the door, which is the only lever you actually have | Does not reach anything already signed |
The three situations in which people reliably do not revoke, and should: you changed consultants and the old firm still has it; a staff member who was a signatory has left; it cannot be accounted for and is being treated as mislaid rather than as unaccounted for.
None of those three is an accusation
You do not need a reason, a suspicion or a conversation. Revocation in those circumstances is routine housekeeping, it costs very little, and nobody competent will take offence at it — a professional firm would rather not be holding it either.
Worth its own section because it is where almost everybody's comfort actually comes from, and it is misplaced.
| The PIN protects against | The PIN does nothing about |
|---|---|
| A stranger who finds the device | The person you handed both to |
| A thief who takes the device | Their colleague at the next desk |
| The device lying in an unlocked drawer | A firm you stopped working with |
| Casual opportunism | Anything you consented to by handing it over |
Put another way: the PIN is protection against loss, not against use. And since no delegation is possible without handing over both — a token with no PIN is a paperweight — the PIN has, by design, already been surrendered in exactly the situation people are relying on it for.
The single most effective thing on this page, and it is much smaller than people expect.
Keep the device. Be in the room. Enter the PIN yourself.
Your accountant prepares the whole filing — every form, every attachment, every check. At the end, you type the PIN. Ten seconds. The work remains entirely theirs; the capacity never leaves you.
Why it works where the four mitigations only help:
And the honest observation: a large share of people who say this is impossible have never put it to their accountant. It is worth one conversation before accepting that it cannot be done.
One more reason the habit is worth pressing for, and it is about how these arrangements decay rather than how they start. An arrangement where you keep the device has a natural check built into it: you see each filing go out, so you know roughly what is happening in your own compliance. An arrangement where somebody else keeps it tends, over a few years, to become an arrangement in which you have no idea what has been filed on your behalf at all — not through anybody's fault, simply because nothing ever prompted you to look. Then a notice arrives about something from two years ago and you are starting from nothing.
So the ten seconds buys two different things. It keeps the capacity with you, which is the security point. And it keeps you informed about your own affairs, which over a long period is probably the more useful of the two.
The structural fact that makes this subject different from everything else we write about documents.
Almost every documentary problem has a repair. A lost certificate is usually reissuable. A wrong affidavit can be redrafted. A mismatch can be explained. A missing paper can be applied for again.
A signature made in your name cannot be unmade
There is no reissue, no correction and no administrative route that makes it not have happened. Whatever remedy exists afterwards is a legal question about your position and your liability — and that is an advocate's work, not a technician's and not ours.
Which is why the one lever you have needs to be understood for what it is.
Revocation tells the world that this certificate should no longer be relied on. It is genuinely valuable, it should be used immediately whenever control is in doubt, and it is cheap.
Revocation is a door, not a time machine
Which gives the only rule that matters when something has gone wrong: revoke first, understand later. Understanding takes days and the exposure grows while you do it.
Worth laying out side by side, because people arrive here with paper intuitions and the intuitions mislead in both directions.
| A paper original | A signing certificate | |
|---|---|---|
| The harm is | Losing it | Somebody using it |
| Can it be replaced | Usually yes, at a cost | A new one, yes — but that is not the problem |
| Does a handover record help | Yes, enormously — it makes a loss recoverable | Only to notice afterwards; it changes nothing |
| Is a copy dangerous | No. Copies are the remedy. | Yes — which is why it cannot be copied |
| Can the damage be reversed | Usually | No |
| So the discipline is | Record every handover | Do not hand it over |
If you have read our guide on physical custody of documents, this table is the deliberate contrast to it. There, the record is close to a complete answer. Here the record is only a way of finding out, and the answer is possession.
Now a change of subject, and from here the page becomes practical rather than cautionary.
The certificate does not merely enable signing. It asserts an identity — a named person, with the details that were verified. Which means it has to agree with something, and the thing it has to agree with is not your own sense of your name but whatever the system you are filing into already holds against you.
Producing the failure that confuses people more than any other in this subject, and that costs them money unnecessarily.
The certificate is valid. Every test passes. The filing is rejected.
And the natural conclusion is that the device is faulty, so people buy a second certificate — which fails in exactly the same way, because the device was never the problem.
What is actually happening is a mismatch between the details on the certificate and the details the receiving system holds. The usual culprits are small and familiar:
The old problem of Indian documentation, arriving in a new costume. If you have a name mismatch across your own documents, it will follow you here.
So before any application, the question to answer is not "what is my name" but: what does the system I will file into already think my name is?
This is most of what careful help actually consists of
Not the ordering, which is straightforward. The twenty minutes spent making the details agree before anything is applied for — because the same twenty minutes afterwards is a rejected filing, a wasted certificate and a deadline.
Three small practices that prevent nearly all of the above.
One further note on the mismatch, because it has a second form that is harder to spot. Sometimes the certificate and the system agree perfectly and the problem is that you have two identities on the same system — an older record under a slightly different name and a newer one, both live, and the filing is being attempted against whichever the portal resolves to. No certificate will fix that. It is a cleanup job on the underlying records, and the only way to find it is to look at what the system holds rather than at the device in your hand.
Which is the general lesson of this half of the page. When a signing failure appears, look at the records before looking at the hardware. The device is the part that almost never fails, and it is the part everybody suspects first because it is the only part they can see.
The useful question is never "should I have a DSC". It is: which specific filing is asking me for one?
Because a certificate is not a general qualification or a mark of seriousness. It is a key to particular doors, and if you are not going through any of those doors you do not need a key.
The doors that commonly require one:
Ask the system, not the seller
The authority on whether you need one, and of what type, is the system you will file into. A seller's answer to "do I need a DSC" has a predictable bias, including when the seller is right.
Worth saying, because people buy these pre-emptively.
A common and avoidable waste: people end up with three certificates because three different consultants each arranged one.
A certificate identifies you. In most cases the same one serves across different filings and different systems. Where a second genuinely is needed, the reason is usually one of two things, and neither is "a different website":
The question to ask a seller
"Which system is refusing the one I already hold, and what exactly does it say?" A clear answer means you need a second. A vague answer means somebody is selling a second.
There are different types, distinguished broadly by how rigorously the holder's identity was established and by what the certificate is intended to be used for. Higher assurance means a more thorough verification at issuance.
We are deliberately not reciting the current classes and their rules here, and the reason is practical rather than coy: which type a particular system requires is set by that system and changes, and a page that names them confidently is the way somebody ends up buying the wrong one with complete confidence, on a guide's authority.
A distinction that causes real confusion and is simple once stated.
When you sign something for an organisation, two separate facts are in play:
A certificate proves identity, not authority
Your authority to sign for a company comes from your position and from whatever the company has resolved or recorded — not from the device. Which is why revoking a departed signatory's certificate does not remove their authority, and removing their authority does not disable their certificate. Both steps are needed, and people do one.
There is a practical consequence of the identity-not-authority distinction that catches people in the other direction too. Because a certificate says nothing about capacity, the same certificate can be used to sign in several capacities — for yourself personally, for a company you direct, for a firm you are a partner in. That is normally fine and it is how most people operate. But it means the certificate is not compartmentalised: the one device signs across all of your roles, and anybody holding it can sign in any of them. If you have one role you are relaxed about delegating and another you are not, the certificate does not know the difference, and handing it over for the first hands it over for the second as well.
Stated flatly because it is asked constantly in the form "how do I get a DSC for my company".
You do not. A certificate is issued to a person, after that person's identity is verified. A company is not a person who can stand in front of a camera. So filings for a company are signed by individuals — directors, designated partners, authorised signatories — using their own certificates.
Three practical consequences that follow directly:
What to settle before the application, in this order, because each answer determines the next.
Described in general shape rather than in steps, because the steps and the acceptable documents are set by the issuing authority and are revised.
Why no step-by-step list here
The acceptable documents, the form of verification and the mechanics are set by the certifying authorities and change. A page reciting last year's procedure is how somebody arrives with the wrong document and a confident belief. We go by what is current at the time of your application, and so should anybody helping you.
Two honest things about it, one reassuring and one not.
The reassuring one. It is supposed to be slightly inconvenient. The verification is the only reason anybody downstream trusts the certificate at all, and a process that verified nothing would produce a certificate worth nothing. The fifteen minutes is the product.
The other one. It is also the moment at which you should be most alert to who is arranging things for you.
You complete your own verification
The live step — a video, a biometric step, whatever the current requirement is — exists to establish that the person named is the person present. Anybody who offers to complete it on your behalf is offering to defeat the only thing that makes the certificate meaningful, and you would be the person named on the result.
Prosaic but worth a paragraph, because it is the physical object the whole subject depends on.
Because people ask, usually while asking whether the inconvenience is necessary.
A file can be copied, and a copy of a signing ability is a second person able to sign as you, with nothing in any record to indicate which copy was used. The device exists so that there is one of it, and so that the one can be in a known place.
The nuisance is the feature
Anybody offering you something materially more convenient on this specific point — no device, usable from anywhere, shareable — is offering you something weaker, whether or not they put it that way.
One instruction, and the unusual thing about this decision is how easy it is.
Revoke it. A token you cannot account for is a signing ability in a place you cannot see, with only the PIN between it and use. Then obtain a fresh one.
The same first step, faster, and then it stops being our subject.
The short version, for anybody reading this because something has already gone wrong.
| Order | Do | Why in this order |
|---|---|---|
| 1 | Revoke | The exposure grows while you think |
| 2 | Write down what you know — dates, who had it, when you last saw it | It is clearest now and will not be tomorrow |
| 3 | Find out what has been filed, and when | Facts before conclusions |
| 4 | Take advice on what is already signed | It is a legal question, and the sooner the better |
| 5 | Obtain a fresh certificate | Last, because your deadlines are not the emergency |
Note what is not on the list: confronting anybody. That may well be necessary and it is not step one, and doing it first routinely costs people the first two steps.
You choose a period at issuance, within the limits the rules allow, and it expires at the end of it. We are not printing a number, because the permitted periods are set by the rules and have been revised.
Two practical points that matter more than the number:
The misconception that produces the most avoidable emergencies in this subject.
Renewal is a fresh issuance, not a reactivation
It involves application and verification again. It is not a button, it is not instant, and it cannot be done in the hour before a deadline. Treating it as a renewal in the sense of a subscription is how an expired certificate and a filing date meet.
So the rule: renew with weeks in hand, not days. And use the occasion for the two things that only happen at renewal if they happen at all — checking the details still match the receiving system, and reconsidering who is going to hold the device.
A specific and miserable situation worth anticipating.
A filing is prepared, the deadline is near, and the certificate expires between preparation and signing — or expires with the filing part-completed. There is no clever recovery. The certificate cannot be used, a fresh issuance takes its own time, and the deadline does not move for any of it.
A question people worry about unnecessarily, and the answer has a reassuring half and an unreassuring one.
The reassuring half. Expiry means you can no longer sign with it. It is not an erasure. Things validly signed while it was live do not evaporate because the certificate later lapsed, and you do not have to re-sign your history every few years.
The unreassuring half is the same fact seen from the other side, and it is the thesis of this page returning at the end: a signature applied by somebody else in your name does not evaporate either. Neither expiry nor revocation reaches it. That is why the page spends its first half on possession and its second half on housekeeping, in that order.
The most common serious exposure we see in small companies, and it is almost always an oversight rather than a dispute.
Somebody was made a director or an authorised signatory. They obtained a certificate in their own name for that purpose. They have now left — amicably, with a handover, on good terms — and the certificate is still live and still theirs.
Two separate steps, and companies reliably do one
Doing the second without the first leaves a working certificate in somebody's hands. Doing the first without the second leaves the records saying they can still sign.
And the practical note: do it during the handover, when goodwill is highest and everybody is being helpful, rather than three months later when it has become a phone call nobody wants to make.
The second most common, and the one people are most reluctant about because it feels like an insinuation.
It is not. A token sitting in a firm you no longer work with is not a comment on that firm. It is a live ability to sign as you, in a drawer belonging to people who have no current reason to think about you at all — which is exactly the condition in which things get mislaid, reused by a junior who does not know the engagement ended, or simply forgotten.
And the situation where all of the above becomes urgent rather than tidy: a partner, a co-director, a family member or a former associate with whom things have gone wrong, who holds a certificate in your name or a certificate that signs for your company.
Revoke on day one, and do not wait for the dispute to clarify
Disputes take months and signing takes a minute. Whatever the merits, and whoever turns out to be right, a live certificate in the hands of somebody in conflict with you is an exposure that grows daily and cannot be reversed afterwards.
After that it is not our subject. Who may sign for an entity in dispute, what happens to filings already made, and what can be done about them, is work for an advocate — and the honest advice is to get there in the first week rather than the second month. What we can do is establish, from the records, what was filed and when, which is the factual groundwork anybody advising you will want.
A related situation that is worth naming because it is genuinely common in family businesses and is nobody's fault: a certificate obtained in the name of a person who is not really running anything. An elderly parent made a director for structural reasons, a spouse added as a partner, a sibling who signed once years ago. The certificate is in their name, the token is in the firm's drawer, and the person named has no idea what is being signed with it or when.
That arrangement is not illegitimate and we are not going to pretend it is unusual. But the exposure is theirs rather than the firm's, which is the part nobody has told them, and two things are worth doing. Tell them what the thing is — in the terms at the top of this page, not as a technicality. And keep a use record for their certificate in particular, because they are the one person in the arrangement who has no way of knowing and the most to be surprised by.
A small habit, recommended with its limitations stated plainly, because overselling it would undo the point of the page.
Keep a short note of each use. One line, like any other record we recommend:
14 Oct 2026 — annual filing signed. Requested by Sharma & Co. Token operated by me, at my desk.
Stated honestly, because this is where the contrast with paper has to be held to.
| A use record does | A use record does not |
|---|---|
| Let you notice a signing on a date when nothing should have been signed | Prevent anything |
| Give you a timeline to hand to an advocate | Undo anything |
| Make your own compliance legible to you | Prove, by itself, who operated the token |
| Remove the vagueness that lets misuse continue unnoticed | Substitute for keeping possession |
Noticing is the whole value, and it is not small
In practice, misuse is almost never discovered by the person affected. It is discovered for them — by a notice, a query, a bank, a counterparty, months later. A record is the only mechanism by which you find out first, and finding out first is most of what can be salvaged.
Collected, in the order we hear them.
Four situations, in the order we hear them.
Short, and asked in this order because each answer changes the next.
The service, described as what it actually is: getting it issued, correctly, into your own hands.
| We do | We do not |
|---|---|
| Establish whether you need one, and of which type | Hold your token, ever |
| Match the name and details to the receiving system before applying | Know or ask for your PIN |
| Prepare the application and the documents | Complete your verification step for you |
| Take you through the verification | Sign anything in your name |
| Get it issued onto a device that is handed to you | File on your behalf using your certificate |
| Tell you the expiry and what to diarise | Hold it "for safekeeping" between filings |
| Help establish what was filed and when, if something is wrong | Advise on what any of it means for you |
And once it is issued, it is yours and it stays yours. There is no ongoing arrangement in which we keep anything of yours, because there is nothing of yours we should be keeping.
The refusal, stated last because it is the one that costs us work, and it will be a disappointment to some people reading this.
We do not hold anybody's token and we do not sign in anybody's name
Not for a regular client. Not for convenience. Not for a deadline. Not when you ask us to, and not when you insist that everybody else does it. Not for a fee, and not as a favour.
The reason, and it is the whole page compressed:
We know this is the most ordinary request in this market, and that saying no to it loses work to people who say yes. We would rather tell you here, before you order, than be the firm that held your signing ability for three years and then had a difficult conversation with you about a filing.
Our part for a digital signature certificate — establishing whether you need one and of which type, matching the name and details to the system you will actually file into, preparing the application, taking you through the verification, and getting it issued onto a device handed to you — is ₹1,299, with a turnaround of 1 – 2 days.
What is separate:
And the honest framing. Most of the value here is in twenty minutes nobody charges separately for — deciding whether you need one at all, which type, and making the details agree with the receiving system before anything is applied for. The ordering itself is straightforward and plenty of people sell it. If you already know which type you need, your details already match, and you are clear that the device stays with you, then this is a simple purchase and you do not need us for the thinking part. We will say so.
Court work is for your advocate, whose fee is engaged and paid by you directly; we do not quote, collect or share it.
We work out whether you need one and of which type, match the name and details to the system you will actually file into so the certificate does not fail at a deadline, take you through your own verification, and hand you the device — which stays with you, because we do not hold anybody’s token and do not sign in anybody’s name.
Where the general positions on this page come from
The Indian legislation on information technology and electronic records, under which digital signatures are given legal recognition, certifying authorities are licensed and regulated by a controller appointed under that legislation, and subscribers are placed under duties in respect of the means of creating their signatures — including the duty to exercise reasonable care to retain control of them and to communicate without delay where control is compromised, which is the statutory background to everything this page says about possession and about prompt revocation; the rules and guidelines made under that legislation and issued by the controller, which set the classes of certificate, the identity verification required for each, the permitted validity periods, the specifications for the devices on which signature creation data is held, and the grounds and procedure for suspension and revocation, all of which are revised from time to time; the company and tax legislation and the rules under which particular filings must be signed by particular persons in particular capacities, which is why a certificate establishes identity and not authority; and the published requirements of the individual portals and authorities as to which class or type of certificate they will accept, which are administrative and change. No class names, no validity periods, no certifying authority names, no portal names, no fee figures and no procedural steps are stated on this page, because each is set by the authority concerned and revised; the controlling source for your own case is the current requirement of the system you are filing into together with the current rules of the certifying authority issuing to you. Nothing here is advice on any legal question, and where a signature has been applied in your name, or where authority to sign is in dispute, that is a matter for an advocate.
The filings a certificate signs are only the output. What has to sit behind them — and why those records cannot be written up later — is in statutory registers and minutes — the day somebody asks.
One expiry that catches people mid-closure: the certificate needed to sign the filings. Why that matters, and what else must be true before a company can be closed, is in company strike off — a company you stopped using has not stopped existing.
Two doors, both free. Clients search a factual directory of enrolled advocates. Advocates apply to be listed on it — no fee, no commission, nothing paid in either direction.
Search Bar Council enrolled advocates by what your matter is about, by court, or by city. Searching and sending a request are both free.
Enrolled advocates anywhere in India can apply to be listed. Your entry is published only after we verify your enrolment number with your State Bar Council.
Would rather not pick anybody? Tell us the matter instead — one form goes to every advocate at once, and the first to take it up calls you.
This directory carries no ratings, no reviews, no rankings and no fees — only the factual particulars the Bar Council of India permits, published at each advocate's own request. Browse the network · Terms for Advocates