Government & Identity · THE NO-PANIC PLAN
Obtain an Indian Digital Signature Certificate (DSC)
Use this process when an Indian government, business, or professional portal requires a Digital Signature Certificate. First confirm whether that service needs a token-based certificate, a specific signer type or an integrated online eSign; they are not interchangeable in every portal. The Controller of Certifying Authorities (CCA) licenses and supervises Certifying Authorities, while the licensed CA issues a subscriber?s certificate. CCA does not sell a DSC to end users. Do not buy through an unverified reseller or share your private key, crypto-token PIN or one-time code.
MISSION Help an individual or authorized representative obtain an Indian DSC from a CCA-licensed Certifying Authority, verify portal compatibility, and protect the signing credential.
Check the CCA licensed-provider listTHE REAL-WORLD BIT
What happens outside this browser tab?
Confirm the relying portal?s certificate and signer requirements; choose a licensed CA from CCA?s current list and check its service disclosure; apply through that CA with the required identity/address checks and organizational authorization; receive and verify the certificate using the delivery method the portal accepts; then test signing, protect the key and arrange renewal or revocation through the issuing CA.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Confirm exactly what the portal accepts
Ask the government or business portal owner which signer role and certificate type are required, whether it accepts a token-based DSC or online eSign, which certificate category or usage it validates, and what browser or operating-system support it requires. For an organization filing, confirm the named authorized signatory and whether the certificate must include organization details. CCA?s eSign service is an API-integrated online path; it uses e-KYC and one-time key handling, while a token-based DSC has a different custody and compatibility model. Do not purchase a certificate based only on a reseller?s ?Class? label or assume that any DSC works on every portal; check the portal?s current instructions and the CA?s current certificate offering first.
- 02
Choose a licensed Certifying Authority from the CCA list
Open the Controller of Certifying Authorities? current public list of licensed CAs and confirm the provider is active and offers the required certificate form for public users. Read that CA?s current disclosure record, Certification Practice Statement, identity-check choices, supported token/software, price, delivery, validity and help or revocation route. Compare the identity and organization details the CA will certify with the portal?s requirements. CCA licenses CAs and provides the trust framework; the licensed CA issues the subscriber?s DSC. If the portal only supports an integrated eSign, check whether it offers that route rather than purchasing a token certificate.
- 03
Apply through the CA and complete its identity checks
Use the selected licensed CA?s own official application channel, not an unofficial agent link. Select the correct subscriber type and use exact identity details; an organization applicant should provide only the authorization and organization evidence the CA requests. Complete one of the CA?s currently supported identity/address verification methods, which may include paper evidence, Aadhaar e-KYC or bank KYC depending on the CA and applicant. Produce originals when the CA?s instructions require them. Review the application before submission and retain its private reference number and payment receipt. Never send a token PIN, signing private key or an OTP to a salesperson or to Nirmion.
- 04
Receive and verify the certificate before using it
Follow the CA?s instructions to receive or activate the approved certificate on its supported cryptographic token or other portal-approved method. Keep the token physically controlled, set a non-default PIN where required, and store recovery or renewal information separately; never copy or email private-key material. Check the issued subject name, organization/signatory details, issuing CA, certificate dates and permitted usage against the order and the relying portal. Use the CA?s validation or the portal?s official test/registration flow to confirm the certificate is recognized. Stop and contact the CA if the name, organization, validity or intended certificate type is wrong; do not proceed with a mismatch.
- 05
Complete the portal registration and maintain the credential
Install only the signing component or driver linked from the CA or relying portal?s official support page. Register or associate the DSC under the correct portal account and signer role, then complete a low-risk test action before a time-critical filing. Keep the token and PIN private, monitor expiry through the CA?s notices and the portal?s own reminders, and begin renewal early enough for fresh verification. If the token is lost, PIN exposure is suspected, a signatory leaves, or the key may be compromised, stop signing and contact the issuing CA promptly to suspend or revoke the certificate and follow the relying portal?s replacement process. Nirmion has no tool that issues, stores or validates private signing credentials; do not enter identity documents or certificate secrets into unrelated utilities.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-05
- Controller of Certifying Authorities - How to avail services under the India PKI Framework
- Controller of Certifying Authorities - How to get a Digital Signature Certificate
- Controller of Certifying Authorities - Active CA services to the public
- Controller of Certifying Authorities - eSign Online Electronic Signature Service
- Controller of Certifying Authorities - Guidelines