What Happened to Class 1, 2, and 3 Certificates? A Guide to India’s DSC Validation Levels

Certificate validation levels in India are officially defined by the Controller of Certifying Authorities (CCA) as Class 1, Class 2, and Class 3, each requiring a different depth of identity verification and a different standard of private key storage. If you’ve come across a Digital Signature Certificate (DSC) and wondered why some are issued to individuals and others to organizations for automated signing, the class assigned to that certificate is where the answer starts.

This post looks specifically at how these classes work within India’s PKI ecosystem under the CCA, and how the class of a certificate typically lines up with two very different real-world use cases: an individual signing documents themselves, and an organization signing large volumes of documents automatically.

Content Table

  1. What CCA Actually Defines: Class 1, 2, and 3
  2. Document Signer Certificates: Typically Issued at Class 2
  3. Individual DSCs: Typically Issued at Class 3
  4. Why the Verification Depth Matches the Use Case
  5. Choosing the Right Class for Your Business
  6. Conclusion
  7. FAQs

1. What CCA Actually Defines: Class 1, 2, and 3

According to the Controller of Certifying Authorities (CCA), India’s official classes of Digital Signature Certificates are defined primarily by two things: the identity verification method required before issuance, and the standard for private key generation and storage.

Class 1 requires Aadhaar eKYC (biometric or OTP-based) or a paper-based application with supporting documents, and its private key can be generated and stored in software rather than dedicated hardware.

Class 2 requires the same verification options as Class 1 — Aadhaar eKYC biometric, Aadhaar eKYC OTP with video verification, or paper-based application — but raises the bar on key protection, requiring private key generation and storage on a hardware cryptographic device validated to FIPS 140-2 Level 2.

Class 3 requires the same verification methods, but adds a stricter identity confirmation step: physical personal appearance before the CA, or video verification, in addition to Aadhaar eKYC options. Like Class 2, the private key must be generated and stored on FIPS 140-2 Level 2 validated hardware.

Every licensed CA in India issuing a given class of certificate follows the same assurance level, since CCA’s India PKI Certificate Policy applies uniformly across the ecosystem — the price may vary between CAs, but the underlying trust and verification standard does not.

2. Document Signer Certificates: Typically Issued at Class 2

A document signer certificate is issued to an organization, tied to the verified identity of an authorized signatory, and built to be embedded into automated systems that sign large volumes of documents without a human involved in each individual signature — invoices, statements, generated reports, and similar high-volume outputs.

In practice, this certificate type is commonly issued at the Class 2 assurance level. The eKYC verification of the authorized signatory establishes accountability for the organization upfront, and the FIPS 140-2 Level 2 hardware key protection requirement ensures the private key powering thousands of automated signatures is properly secured, even though no individual human is manually approving each one.

This pairing makes practical sense: Class 2’s verification depth is well suited to establishing organizational accountability once, at issuance, rather than requiring the heavier in-person or video verification burden of Class 3 for every certificate an organization might need for its automated systems.

3. Individual DSCs: Typically Issued at Class 3

An individual DSC represents a specific person and is used for deliberate, one-at-a-time signing actions — filing income tax returns, signing MCA (Ministry of Corporate Affairs) documents, submitting GST filings, or executing a specific contract personally.

Because an individual DSC is meant to represent one person’s legally binding signature on specific, often high-stakes documents, it’s typically issued at Class 3, which requires the strictest identity confirmation CCA defines: physical personal appearance before the CA or a supervised video verification, on top of Aadhaar eKYC options. This higher assurance level reflects the legal weight an individual’s signature carries when it’s applied to a government filing, a regulatory submission, or a legally significant personal document.

(For more on how document signer certificates work in automated signing contexts, see our guide: What Is a Document Signer Certificate?)

4. Why the Verification Depth Matches the Use Case

It’s worth pausing on why this pairing — Class 2 for document signer, Class 3 for individual DSC — tends to make practical sense, rather than being an arbitrary assignment.

A document signer certificate protects a high volume of relatively routine, system-generated documents, where the accountability question was already answered once, upfront, through the authorized signatory’s eKYC verification. The risk profile is about protecting the private key from misuse at scale, which is exactly what the Class 2 hardware key storage requirement addresses.

An individual DSC, by contrast, protects a smaller number of much higher-stakes actions, each one deliberately triggered by a specific person. Class 3’s added requirement of physical or video verification directly confirms that the person behind each signature is who they claim to be, at the moment the certificate is issued — appropriate given how consequential an individual’s digital signature can be on something like a company incorporation filing or an income tax return.

Neither class is “better” in an absolute sense. Each is suited to the accountability model of the situation it’s built for.

5. Choosing the Right Class for Your Business

If your business generates high volumes of documents that need automated signing — invoices, statements, system-generated reports — a document signer certificate at Class 2 assurance is generally the right fit, since it’s built specifically for embedding into automated workflows.

If you or specific individuals in your organization need to sign documents personally — MCA filings, income tax returns, GST submissions, or individually executed contracts — an individual DSC at Class 3 assurance is what CCA-licensed CAs will typically require for these use cases.

If you’re not sure which applies, the deciding question is usually: is a specific person deliberately signing this document themselves, or is a system signing documents automatically on the organization’s behalf? That answer generally points you to the right certificate type and class.

(See our companion post on evaluating certificate authority options: What Is a Certificate Authority?)

6. Conclusion

India’s CCA defines certificate classes by verification depth and key protection standard, not by use case directly — but in practice, those technical requirements line up closely with two very different real-world needs: an organization signing documents automatically at scale, and an individual signing documents deliberately and personally. Document signer certificates typically fit the Class 2 profile; individual DSCs typically fit Class 3.

Understanding this pairing makes it much easier to have an informed conversation with your CA when setting up document signing for your business, whether that’s automating your invoicing pipeline or getting an authorized individual set up to sign government filings personally.

7. FAQs

1. What are the three classes of Digital Signature Certificates in India?

CCA defines Class 1, Class 2, and Class 3 certificates, differentiated primarily by identity verification requirements and private key storage standards.

2. What class is a document signer certificate typically issued at?

Document signer certificates, issued to organizations for automated bulk signing, are typically issued at Class 2 assurance, which requires hardware-based key storage validated to FIPS 140-2 Level 2.

3. What class is an individual DSC typically issued at?

Individual DSCs, used for personal signing of documents like tax filings or MCA submissions, are typically issued at Class 3, which adds a requirement for physical or video identity verification.

4. What is the difference between Class 2 and Class 3 verification requirements?

Both classes accept Aadhaar eKYC or paper-based verification, but Class 3 additionally requires physical personal appearance before the CA or video verification, making it the stricter of the two.

5. Can a Class 2 certificate be used where a Class 3 certificate is required?

According to CCA, a higher assurance Class 3 certificate can be used wherever an application requires a lower assurance certificate, though the reverse is not the case.

6. Does every licensed CA in India issue all three certificate classes?

No, CCA allows licensed CAs to opt out of issuing any particular class of certificate at their discretion, though the assurance level of a given class is uniform across all CAs that do issue it.

7. Is a document signer certificate legally valid for signing documents in India?

Yes, digital signatures created using a properly issued document signer certificate are legally recognized under India’s IT Act 2000, provided the certificate was issued by a CCA-licensed certifying authority.

8. Why does an individual DSC require stricter verification than a document signer certificate?

An individual DSC represents a specific person’s deliberate signature on often high-stakes documents, so CCA requires the stricter Class 3 verification to confirm that person’s identity directly.

9. What is FIPS 140-2 Level 2, and why does it matter for certificate classes?

FIPS 140-2 Level 2 is a hardware security standard for cryptographic key protection, required for both Class 2 and Class 3 certificates in India to ensure private keys cannot be easily extracted or misused.

10. Where can I find the official CCA definitions of certificate classes?

The current official definitions are published on the Controller of Certifying Authorities website under its Classes of Certificates page.


1 thought on “What Happened to Class 1, 2, and 3 Certificates? A Guide to India’s DSC Validation Levels”

Leave a Reply

Discover more from ZeeroTrust

Subscribe now to keep reading and get access to the full archive.

Continue reading