Nirmion
HelpLog in Find a tool

Security & Privacy · THE NO-PANIC PLAN

Revoke a lost or compromised Indian Digital Signature Certificate

Treat a missing DSC token, exposed token PIN or suspected private-key compromise as a security incident. A Digital Signature Certificate is issued by a licensed Certifying Authority under India's CCA framework; the subscriber's revocation request and identity checks are handled by the issuer under its current Certificate Policy and Certification Practice Statement. There is no single universal request form or turnaround time. Do not email a private key, token PIN, one-time code or token itself to a support contact. Stop using a questionable certificate, preserve evidence, and work only through verified CA and organization channels. If the certificate was used to sign an unauthorized filing or agreement, contact the affected portal/organization and qualified legal or security advisers promptly; this workflow does not decide the legal effect of a signature.

MISSION Help an Indian DSC subscriber contain a lost hardware token or suspected private-key compromise, request certificate revocation from the issuing licensed CA, verify the status and restore authorized signing access safely.

Read the CCA's current licensed-CA revocation procedures

THE REAL-WORLD BIT

What happens outside this browser tab?

Stop use and secure the remaining token/PIN; record the certificate holder and issuer using existing purchase/registration records without exposing secrets; contact the issuing licensed CA through its verified official channel, report loss or suspected compromise and request suspension/revocation under its current policy; complete the CA's identity-verification steps; obtain written acknowledgement and confirm revoked status using the CA's stated status service; investigate any unexpected signing activity; then obtain a new certificate only through an authorized identity and issuance process, update approved portal registrations and retain the revocation evidence.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Stop signing and contain the suspected exposure

    Do not use the missing token or affected certificate for any new filing or approval. If the token is still with you but may be exposed, keep it under your control, disconnect it from unattended devices and do not test the PIN repeatedly. Tell the organization's designated DSC administrator or security contact through the approved channel so they can pause its use in internal signing procedures and preserve relevant access logs. If a token is lost, a PIN was shared, malware may have accessed the signing device or the private key may otherwise be exposed, treat it as a suspected compromise even if you do not know whether someone used it. Record when the issue was discovered, the device/location and observed facts; do not put the PIN, private key file, OTP or complete token secrets into an incident note.

  2. 02

    Identify the issuing CA and the affected certificate safely

    Use the original CA enrollment receipt, certificate copy, organization inventory or authenticated CA account to identify the licensed Certifying Authority and the affected subscriber certificate. Capture only the certificate holder, certificate class/use, issuer and serial/reference number needed for the CA's authenticated revocation request; keep this information in the organization's controlled incident record. Use the CCA's official ‘How to avail services’ page to find its licensed-CA list, then reach the issuer through contact details on that CA's independently verified official site or authenticated subscriber account. Do not trust a search advertisement or caller-supplied number. The CCA states that licensed CAs publish their own certificate-revocation and identity-authentication procedures, including special handling for private-key compromise. Do not send the USB token, PIN or private key to a person claiming to be support.

  3. 03

    Request suspension or revocation through the CA's verified process

    Contact the issuing CA using its verified subscriber portal or official support channel and state clearly whether the token is lost, the PIN may be exposed or the private key is suspected to be compromised. Ask for the appropriate immediate suspension or revocation and follow that CA's current identity-verification instructions. The India PKI Certificate Policy describes revocation requests and recognizes loss or compromise of a subscriber's private key; it does not create one identical form flow for every CA. If the certificate is mapped to an employer, director, authorized signatory or filing account, notify the organization's DSC administrator so they can disable the old certificate in internal approvals and assess portal-specific consequences. Save the request ID, time, CA response and any identity-check acknowledgement in restricted records; never bypass verification by asking an agent to use your token or credentials.

  4. 04

    Confirm revocation and check for activity during the exposure window

    Ask the CA how subscribers can check the certificate's current status and when the revocation should appear in its official status channel. Follow the issuer's Certificate Policy or CPS for subscriber-certificate status; the CCA's CRL/OCSP services page primarily describes the CA trust-chain status service and should not be mistaken for the only lookup path for every subscriber certificate. Confirm the issuer's response says the specific certificate is suspended or revoked, and retain the timestamped evidence. Review organization and government-portal activity available to the authorized account holder for unexpected filings or signature requests from the discovery time onward. If anything is unfamiliar, preserve the record and report it to the portal, organization security contact and affected recipients through their official channels. Do not assume revoking a certificate automatically reverses a filing or determines the legal validity of earlier signatures.

  5. 05

    Restore signing access with a new certificate and close the incident

    Once the issuer confirms the old certificate's status and the organization approves restoration, obtain a new DSC from a licensed CA using its current identity, key-generation and delivery process. Use a clean, organization-approved device and hardware token, set a unique PIN, restrict who can access the token and store recovery details according to local security policy. Ask each relevant filing portal or administrator how to remove the old certificate mapping and register the replacement; do not assume a new certificate automatically updates GST, MCA or other accounts. Test a low-risk authentication/signing action only after the replacement is properly registered. Document the final status, affected services, any unauthorized activity, the new certificate's custodian and preventive changes; keep the original incident record restricted. If there is evidence of misuse or an official notice, follow the applicable authority's process and obtain qualified legal/security advice.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-05