The signature that expired without telling anyone
It is the last week of the filing season. A director sits down to sign the company's annual return, plugs in the little USB token he has used for two years, and the portal throws an error he has never seen. The certificate on the token expired three weeks ago. Nobody sent a reminder — a digital signature does not warn you, it simply stops working — and now, with a statutory deadline days away, he has to apply for a fresh one, wait for verification, and hope it arrives in time. A new one takes a couple of working days on a good run. The late-filing fee does not wait for it. This small piece of hardware, the Digital Signature Certificate, is the quiet dependency underneath almost everything a company files — and most founders only learn how it works the first time it fails. Here is what a DSC actually is, why there is only one kind that matters now, how you get one, everywhere it is used, and the three things that reliably go wrong.
What a DSC actually is
A Digital Signature Certificate (DSC) is the electronic equivalent of a handwritten signature — a cryptographic credential that proves who signed an electronic document and that it has not been altered since. Its legal force comes from the Information Technology Act, 2000, which gives a validly issued digital signature the same standing as a physical one. A DSC is not something you can make yourself: it must be issued by a licensed Certifying Authority (CA) — names like eMudhra, (n)Code Solutions, Capricorn, VSign, Sify and a handful of others — each of which is licensed and supervised by the Controller of Certifying Authorities (CCA), the office under the Ministry of Electronics and Information Technology that anchors the whole chain of trust. When you sign a form on a government portal with your DSC, the portal is really checking that chain: your certificate, issued by a licensed CA, rooted in the CCA. That is why a signature scanned as an image is worthless for filings and a DSC is not.
Why there is only one class that matters now — Class 3
DSCs used to come in classes, and you will still see old guides mention "Class 2." Ignore them. From 1 January 2021, on the CCA's direction, Class 2 certificates were discontinued and folded into Class 3, and Class 3 is now the only class issued for statutory and commercial use. Class 3 carries the highest level of identity assurance, which is exactly why it replaced everything below it. Practically, this means you no longer choose a class — every company filing, GST return, income-tax filing, tender bid or trade-portal login now runs on the same Class 3 certificate. What you do still choose are two things: whether you want a Sign-only certificate (enough for almost all government filings) or a Sign-plus-Encrypt "combo" (needed mainly for e-tendering, where bids must be encrypted), and whether you need an individual DSC or an organisation DSC — the latter binds you as an authorised signatory of a named company, which is what directors use for MCA work.
How you actually get one
Getting a DSC is faster than it used to be, because it is now almost entirely paperless. You apply to a licensed CA (directly or through a registration authority), and the certificate is issued after identity verification that has two non-negotiable parts: a short video recording of you confirming the request, and identity verification, most commonly Aadhaar-based eKYC (PAN-based verification is the alternative), with mobile and email OTPs along the way. Once verified, the certificate is downloaded onto a FIPS-compliant hardware USB token — a small dongle such as an ePass or ProxKey — and this matters: the private key lives on the token and cannot be copied off it, which is what makes the signature secure and also why you must physically have the token plugged in to sign. A DSC is issued with a validity of one, two or three years (you pick at purchase), renewable on expiry with fresh verification each time; a two-year individual Class 3 with token typically costs somewhere in the region of a few hundred to a couple of thousand rupees. With Aadhaar eKYC, the whole thing is often done within a working day or two.
Everywhere a DSC is used — and the step everyone forgets
The reason a DSC feels foundational is that it sits under almost every official filing a business makes. On the MCA portal it signs company incorporation through SPICe+, the LLP FiLLiP form, the DIN application, every annual filing (AOC-4 and MGT-7) and the yearly DIR-3 KYC. Outside the MCA it signs income-tax filings (mandatory for companies and audit cases), GST returns and registration for companies and LLPs, DGFT filings for import-export, EPFO and ESIC work, customs on ICEGATE, and e-tendering on GeM and government portals. But here is the step almost everyone forgets: being issued a DSC is not the same as being able to use it. Each portal requires you to register or "associate" the DSC once before it will accept your signature — you register it against your PAN on the income-tax portal, associate it with your role on MCA, map it on GST. If the PAN embedded in the certificate does not exactly match the PAN on the portal profile, the registration fails, and so does every signature after it.
The three things that reliably go wrong
Almost every DSC problem is one of three. First, silent expiry — the certificate stops working the day it lapses with no warning, and because it is usually needed at a deadline, it is discovered at the worst possible moment; the fix is to track the expiry date and renew a couple of weeks early, not on the day. Second, the DSC is not registered on the portal, or the PAN does not match — the certificate is perfectly valid but the portal has never been told it belongs to you, so it rejects the signature; this is the classic "my DSC is not working" that is actually a registration problem. Third, the signing utility itself — the MCA and income-tax portals sign through helper software (emSigner and the like) that depends on Java and a small background service, and a blocked port or an out-of-date utility produces cryptic "token not detected" errors that have nothing to do with the certificate. Knowing which of the three you are looking at turns an hour of panic into a two-minute fix.
Where this sits in setting up your business
A DSC is genuinely step zero of building a company, because you need one before the company legally exists. The directors' certificates have to be in hand to sign the SPICe+ incorporation or the LLP registration in the first place, and the same token then follows you through every filing afterwards — the annual DIR-3 KYC that keeps your DIN active, the yearly AOC-4 and MGT-7, and the GST registration and returns your company signs digitally. It is the small credential that makes all of those possible, which is why it belongs at the very top of the setup checklist rather than remembered halfway through. For the full running order of what to obtain and register as you start, the starting-a-business guide is the map this fits into.
How we handle it at RDA, Baner
At RDA Advisory, Baner, we get your directors' DSCs sorted before they hold anything up. We arrange Class 3 certificates for each director or signatory, run the video and Aadhaar eKYC verification, choose individual or organisation and sign-only or combo to match what you will actually file, and register each DSC on the portals you need — MCA, income tax, GST — so the PAN matches and the first signature works rather than fails. We track expiry dates so a certificate never lapses into a deadline, renew ahead of time, and sort out the emSigner and token errors that stall filings, so a piece of hardware never becomes the reason a return is late. Office No. 102, Snehraj Apartment, Baner, Pune 411045 · call +91 77570 45059.
Incorporating, or a DSC about to expire? Get the signatures sorted first
Setting up a company, or caught out by a signature that stopped working? RDA arranges Class 3 DSCs for your directors, registers them on every portal you file on, and keeps the renewals ahead of your deadlines so signing is never the thing that holds a filing up. Book a consult at rdatax.in or call +91 77570 45059, or see our company registration & startup advisory service. RDA Advisory, Baner, Pune.
Verification note: A Digital Signature Certificate derives its legal validity from the Information Technology Act, 2000, and must be issued by a Certifying Authority licensed by the Controller of Certifying Authorities (CCA) under the Ministry of Electronics and Information Technology. Class 2 certificates were discontinued with effect from 1 January 2021 pursuant to CCA guidelines and merged into Class 3, which is now the class issued for statutory and commercial use; issuance requires identity verification including a mandatory video recording and Aadhaar-based eKYC (or PAN-based verification), and the certificate is stored on a FIPS-compliant hardware cryptographic USB token. DSCs are issued with a validity of one, two or three years and are renewable on expiry. Requirements for the hardware token are moving toward the FIPS 140-3 standard, and the classes, verification norms, token specifications, validity periods and portal registration procedures are periodically revised by the CCA and the respective portals, so confirm the current position with your Certifying Authority or advisor before relying on it. This is general information, not legal or professional advice.