For a new personal or organisational-person signing DSC in 2026, obtain a Class 3 signing certificate from a CCA-licensed certifying authority after checking the exact portal and role. Current CCA guidance says standalone Class 2 individual signing certificates are not issued; the Class 3 certificate carries both Class 2 and Class 3 policy identifiers and qualifies as both. Not every filing requires a DSC, and signing, encryption and document-signer certificates serve different purposes.
The useful question in 2026 is not simply "Which class costs less?" It is "Which certificate will this portal accept for this person, role and transaction, and where must the private key be generated and stored?"
The older Class 2 versus Class 3 comparison still appears in tenders, portal help pages and search results. But current CCA issuance guidance has changed the product decision. A founder, professional or authorised signatory should now validate five things: the relying portal, the required certificate purpose, the subscriber category, the identity fields and the approved key-storage method.
What a Digital Signature Certificate actually proves
Under the Information Technology Act, 2000, a digital signature uses an asymmetric cryptosystem and a hash function to authenticate an electronic record. The subscriber signs with a private key; a relying party uses the corresponding public key and certificate chain to verify the signature.
This can support authentication of the signer and detection of changes made after signing. It does not, by itself, make the underlying statement true, approve the signer's authority for every transaction or keep the document confidential. Confidentiality requires the appropriate encryption process and certificate where the application specifies one.
Section 5 of the Information Technology Act gives legal recognition to prescribed electronic signatures. A portal may still require a particular certificate purpose, subscriber role, identity field, token setup or account association before it accepts a filing.
What happened to Class 2?
Historically, Class 2 and Class 3 described different identity-assurance levels. Class 2 was used for transactions with moderate risk, while Class 3 involved higher assurance and was used for high-risk or high-value activity. The CCA's current certificate-policy material still explains those assurance concepts.
The issuance rule for individual signing certificates is now more important. The CCA Identity Verification Guidelines, updated on 16 June 2026, direct certifying authorities to issue a Class 3 individual signing certificate with both the Class 2 and Class 3 object identifiers in its policy field. They must not issue a standalone Class 2 individual signing certificate. The combined certificate qualifies as both Class 2 and Class 3 for relying applications.
This is why two apparently conflicting statements can both appear online:
- New individual signing issuance is handled through the current Class 3 certificate model.
- Some official portal manuals still state that a valid Class 2 or Class 3 certificate is accepted.
The transition stopped standalone Class 2 issuance for the relevant certificate category; it did not convert every unexpired certificate into an invalid signature overnight. In 2026, however, most certificates issued before that transition will have reached expiry. Check the actual certificate validity and revocation status.
Class 2 vs Class 3 DSC in 2026
This comparison applies to individual signing certificates. Document-signer, encryption, SSL/server and code-signing certificates have different purposes and controls. Do not transfer the conclusion to those categories without checking the relevant CCA guideline and relying application.
The TargoLegal DSC Selection Test
This is an editorial decision framework, not a CCA scoring model. Use it before ordering a certificate or handing an application to an intermediary.
- Relying application
- Ask: Which portal, form, tender or counterparty will verify the certificate? Evidence: a current official manual or tender clause. Warning: a reseller says "works everywhere." First check: save the relevant portal instruction and its date.
- Certificate purpose
- Ask: Is the key required for signing, encryption, both through separate keys, or another purpose? Evidence: explicit key-usage wording. Warning: "DSC" is used as if every certificate is interchangeable. First check: match the portal wording to the CA product profile.
- Subscriber identity
- Ask: Is the signer acting personally, for an organisation, or through an automated system? Evidence: portal role and authorisation records. Warning: the name, PAN or organisation is different from the portal account. First check: compare all identity fields character by character.
- Assurance level
- Ask: What class does the application specify? Evidence: Class 2, Class 3 or higher-assurance requirement in official instructions. Warning: an old blog is the only basis. First check: use the current Class 3 signing model where a new individual signing certificate is required.
- Key storage
- Ask: Must the key be generated in a hardware token or HSM? Evidence: CCA and portal requirements. Warning: the private key is emailed, exported or retained by an agent. First check: confirm device validation, custody and PIN control before issuance.
Signing, encryption and subscriber role are separate choices
"Class 3 DSC" is incomplete as an order description. The certificate purpose and subscriber category must also match the transaction.
Signing certificate
Used to create a digital signature on an electronic record. It supports verification of the subscriber and the record's integrity after signing. This is the usual requirement for statutory filings and many approvals.
Encryption certificate
Used where confidentiality is required, such as encrypting bid data for a tender system. Some procurement processes may require both signing and encryption capabilities. Follow the tender specification; do not assume a signing-only certificate can perform the encryption step.
Personal and organisational-person certificates
A personal certificate identifies the individual in a personal capacity. An organisational-person certificate also connects the individual to an organisation and requires proof of association and authorisation. The organisation name in a certificate does not itself create board, employment or contractual authority; the underlying authorisation must be valid.
Document-signer and automated certificates
Automated document signing is a distinct certificate and key-management use case. It should not be implemented by leaving a director's personal token connected to a server or sharing the token PIN with staff.
How current portal instructions differ
- Income Tax e-Filing
The official Register DSC manual says the service is available to registered users and requires the relevant signing utility and USB token. The portal FAQ states that an existing, unexpired and unrevoked Class 2 or Class 3 certificate of the specified class can be used. But DSC is not the only e-verification route for every individual return; the portal also supports eligible Aadhaar OTP, EVC, net-banking and other methods.
- GST portal
The current GST tutorial says DSC registration is PAN-based and describes acceptance of Class 2 and Class 3 certificates. The authorised signatory's PAN must match. Other GST instructions distinguish between DSC, e-signature and EVC by workflow and entity type; companies and LLPs are directed to use DSC in specified registration workflows. Read the exact filing page rather than extrapolating from a different GST process.
- Central e-Procurement
The Central Public Procurement Portal instructs bidders to obtain a valid Class III signing certificate from a CCA-licensed certifying authority and to enrol it. A tender may also specify an encryption certificate or additional role mapping. Start from the tender and portal instruction, not from a general compliance filing certificate.
- MCA and other portals
Requirements can depend on the form, signer's capacity, certificate association and portal release. Confirm the current form instruction and help page before purchase or renewal. This is especially important when a person changes organisation, authorised role, PAN record, browser utility or token.
The CCA Interoperability Guidelines say an application owner decides the assurance level based on risk and must accept a certificate from any licensed CA if it is of the specified class or higher. The application should not impose unnecessary certificate-field or storage requirements outside the CCA framework.
Current KYC and key-storage requirements
A certifying authority, not the CCA itself, issues a DSC to the end subscriber. Use the CCA's live list of licensed certifying authorities and verify the exact certificate service offered.
Verification is not one Aadhaar-only route
The 2026 Identity Verification Guidelines provide approved paths involving eKYC, documents, banking relationships, authorised organisational processes and CA-assisted verification. The available path depends on citizenship, applicant category and the certifying authority's approved process. Video verification applies in relevant paths, with current freshness requirements for issuance.
Organisational-person applications need more than individual KYC
Expect evidence that the organisation exists, proof connecting the applicant to it, an authorisation letter and verification of the authorised signatory or responsible organisational process. The applicant's personal identity and the organisation's authority chain are separate checks.
The signing key must stay under proper control
For Class 3 individual signing certificates, the key pair must be generated on a validated hardware cryptographic module or token meeting the CCA requirement. Organisational deployments may use a qualifying HSM in the permitted circumstances. A vendor should not generate an exportable private key and send it by email.
How to obtain and deploy the right DSC
Read the relying application's current instruction
Record the portal, transaction, signer's role, certificate purpose, assurance class, identity field and required signer utility. For a tender, retain the tender clause.
Choose a CCA-licensed certifying authority
Verify the CA on the official licensed-CA list. Compare the certificate profile, validity choice, hardware, reissue process, invoice and support terms. Do not choose solely through an unverified reseller.
Select the subscriber category and purpose
Specify personal or organisational person, and signing or encryption as required. If an organisation is involved, align the certificate details with the portal account and authorisation records.
Complete the approved identity-verification route
Provide accurate identity and organisational evidence. Complete the applicable eKYC, video or other approved process within the CA's stated time window.
Generate the key in the approved device
Use the validated token or permitted HSM. Set a strong PIN known only to the authorised subscriber or properly controlled signatory function.
Inspect the certificate before portal enrolment
Check subscriber name, PAN or identifier, organisation, class policy, key usage, issuer, serial number and validity. Correct an error before signing a filing.
Install only official portal utilities
Download the signer utility from the portal's official page, associate the DSC with the correct account and test before a filing or tender deadline.
Record custody, use and expiry
Document who holds the token, which acts are authorised, how use is approved and when replacement planning begins. Revoke promptly if the key is compromised.
Token, PIN and signing controls
- The subscriber or authorised organisation keeps physical custody of the token.
- The PIN is not shared through email, messaging apps, spreadsheets or browser notes.
- An intermediary does not retain the token after completing setup.
- Every use is supported by the required internal approval or authority.
- Portal utilities are downloaded only from official sources and kept updated.
- Certificate expiry and role changes are tracked centrally.
- Loss, suspected copying or unauthorised use triggers immediate escalation to the issuing CA.
- Revocation and reissue details are updated on each relying portal.
A digital signature can bind an organisation to a filing, bid, tax statement or other electronic act. Convenience is not a reason to leave the token and PIN with an accountant, employee or bid consultant without documented controls.
Common DSC mistakes
- Buying "Class 3" without a purpose
- A signing certificate may not satisfy an encryption requirement. Read the key-usage requirement before ordering.
- Assuming every filing needs DSC
- Some portals provide EVC, eSign, Aadhaar OTP or other verification methods for eligible users. Entity and transaction rules differ.
- Using mismatched identity details
- A PAN, subscriber name, organisation or authorised-signatory mismatch can cause rejection even when the class is correct.
- Relying on an old portal screenshot
- Signer utilities and account-association processes change. Use the current official help page on the filing date.
- Sharing the private-key PIN
- The token is not an office stamp. Shared custody undermines accountability and increases the risk of unauthorised filings.
- Waiting for a tender deadline
- KYC, organisational authorisation, token delivery, utility installation and portal enrolment can each fail. Complete and test the setup before submission day.
- Calling a fresh certificate a simple renewal
- Expiry, role changes or rekeying may require new verification, issuance and portal registration. Confirm the CA's reissue process.
Class 2 and Class 3 DSC FAQs
Is Class 2 DSC discontinued in India?
For current individual signing certificates, the CCA Identity Verification Guidelines say a certifying authority must not issue a standalone Class 2 individual signing certificate. It issues a Class 3 individual signing certificate carrying both Class 2 and Class 3 policy identifiers, so it qualifies at both assurance levels. Some official portal manuals still refer to accepting Class 2 or Class 3 certificates, which explains why the older label remains visible.
Can an unexpired Class 2 DSC still be used?
Use depends on the certificate's validity, revocation status, key usage and the relying portal's current rules. CCA interoperability guidance requires a portal that specifies a class to accept the same or a higher class from a licensed certifying authority. Because most Class 2 certificates issued before the transition will now have expired, check the certificate and the live portal rather than relying on its label alone.
Is a Class 3 DSC mandatory for every income-tax or GST filing?
No. The Income Tax portal provides several electronic verification methods for eligible users, while DSC requirements vary by taxpayer and filing. GST also permits different authentication routes in different workflows, although DSC is mandatory for specified entity types and processes. Check the exact filing, entity type and current portal instruction.
Do I need a signing certificate or an encryption certificate?
A signing certificate is used to authenticate and sign an electronic record. An encryption certificate is used where a portal requires data or a bid to be encrypted for confidentiality. They are not interchangeable merely because both are called DSCs. Follow the tender or portal specification for certificate purpose and key usage.
Is Aadhaar compulsory to obtain a Class 3 DSC?
Not in every issuance route. Current CCA identity-verification guidance permits multiple approved verification paths, including specified eKYC, document, banking and organisational processes. Aadhaar-based verification is one route. The available route depends on the applicant, citizenship, certifying authority and certificate category.
Can the same Class 3 DSC be used on several portals?
Often yes, if the certificate remains valid, has the required key usage and class, contains matching identity details, and each portal permits that subscriber and certificate type. Registration or association may have to be completed separately on each portal. A certificate issued for signing cannot automatically perform an encryption-only function.
What should I do if the DSC token or PIN is lost or compromised?
Stop using the certificate and contact the issuing certifying authority immediately. If the private key may have been exposed, request revocation and obtain a new certificate. Do not share token PINs or allow an intermediary to retain the token. Portal registrations may need to be updated after reissue.
Curated official sources
- CCA Identity Verification Guidelines, version updated 16 June 2026
- CCA Interoperability Guidelines, version updated 16 June 2026
- CCA explanation of certificate classes and verification routes
- CCA list of licensed certifying authorities
- Information Technology Act, 2000 on India Code
- Income Tax e-Filing portal: Register DSC user manual
- GST portal: Register or update DSC guidance
- Central Public Procurement Portal: DSC information for bidders
Legal note: This guide provides general information as checked on 17 July 2026. CCA guidelines, certifying-authority processes, tender conditions and portal instructions can change. The correct certificate depends on the transaction, subscriber, organisation, key usage and relying application. Confirm the live requirement with the portal, tender authority and CCA-licensed certifying authority before purchase or use. Professional review is pending.
Corrections: To report a factual or source update, contact TargoLegal with the page title, affected passage and supporting official source.