What is a Digital Signature? A Complete Technical and Legal Guide
Discover what a digital signature is, how it works, the difference between electronic and digital signatures, and its legal validity in India under the IT Act.
Discover what a digital signature is, how it works, the difference between electronic and digital signatures, and its legal validity in India under the IT Act.
For centuries, the handwritten signature (often referred to as a “wet signature”) was the undisputed gold standard for authorizing contracts, verifying corporate decisions, and executing legal agreements. However, as the global economy shifted to digital transactions, paperless workflows, and remote-first operations, physical ink signatures quickly became a bottleneck. They were slow, expensive to ship, easy to forge, and prone to physical tampering.
Enter the Digital Signature.
Far more than a simple scanned image of a handwritten signature pasted onto a PDF, a digital signature is a highly secure, mathematically validated cryptographic lock. It guarantees that a digital document originates from a specific sender, that the sender cannot deny signing it, and that the document has not been altered in transit.
Today, digital signatures are the cornerstone of modern corporate compliance, legal transactions, and secure e-governance in India. From registering a new company on the Ministry of Corporate Affairs (MCA) portal to filing income tax returns and submitting government e-tenders, digital signatures are legally mandatory. This definitive guide breaks down what a digital signature is, how it works under the hood, how it differs from a standard electronic signature, its legal standing under the Information Technology (IT) Act, 2000, and how to obtain a Class 3 Digital Signature Certificate (DSC) in India.
A Digital Signature is a mathematical technique used to validate the authenticity and integrity of a digital document, message, or software. It acts as a digital fingerprint that uniquely binds the identity of the signer to the electronic data being signed.
To understand why digital signatures are so secure, we must look at the three core pillars of cybersecurity they enforce:
Digital signatures rely on a cryptographic framework known as Public Key Infrastructure (PKI) and a technology called Asymmetric Cryptography.
Asymmetric cryptography uses a pair of mathematically linked keys:
Here is the step-by-step cryptographic workflow of how a document is signed and verified:
[ SIGNING PROCESS ]
┌───────────────────┐
│ Original PDF Doc │
└─────────┬─────────┘
│
▼ (Run Hashing Algorithm)
┌───────────────────┐
│ Unique Hash Value │
└─────────┬─────────┘
│
▼ (Encrypt using Signer's Private Key)
┌───────────────────┐
│ Digital Signature │
└─────────┬─────────┘
│
▼ (Merge with PDF)
┌───────────────────┐
│ Signed PDF Document│
└─────────┬─────────┘
│
▼ (Transmit to Receiver)
│
[ VERIFICATION PROCESS ]
│
┌─────────────────┴─────────────────┐
▼ ▼
┌───────────────────┐ ┌───────────────────┐
│Extract & Decrypt │ │Compute Hash of │
│Signature using │ │Received PDF Doc │
│Signer's Public Key│ │using same Alg │
└────────┬──────────┘ └────────┬──────────┘
│ │
▼ (Reveals original Hash) ▼ (Creates current Hash)
┌───────┴───────────────────────────────────┴───────┐
│ ARE BOTH HASHES IDENTICAL? │
└───────────────────────┬───────────────────────────┘
│
┌───────────┴───────────┐
▼ ▼
[ YES: Valid ] [ NO: Tampered ]
- Identity Verified - Document Modified
- Integrity Intact - Signature Broken
Many business owners, founders, and professionals use the terms “digital signature” and “electronic signature” interchangeably. However, they represent entirely different levels of security, technology, and legal weight.
Here is a side-by-side comparison:
| Feature | Electronic Signature (e-Signature) | Digital Signature (Cryptographic) |
|---|---|---|
| Definition | A broad category representing any digital markup indicating intent to sign (e.g., a scanned image, a clicked check-box, a typed name). | A highly secure type of e-signature based on asymmetric cryptography and Public Key Infrastructure (PKI). |
| Security | Low. Easy to forge or copy. Does not offer built-in tamper detection. | High. Extremely difficult to forge. Features automated mathematical tamper detection. |
| Verification | No formal verification of the signer’s physical identity by an independent authority. | Signer’s identity is verified by a licensed government Certifying Authority (CA) beforehand. |
| Standard Format | Proprietary to the platform (e.g., standard DocuSign, HelloSign markups). | Standardized format (PKCS#7 / PAdES) compatible with Adobe Acrobat, MCA, and global readers. |
| Legal Validity | Limited. Can be disputed in court. Not accepted for government filings. | High. Statutorily backed by the IT Act, 2000. Accepted for all government filings. |
In India, Digital Signature Certificates (DSCs) are issued by private Certifying Authorities licensed by the Controller of Certifying Authorities (CCA) under the Ministry of Electronics and Information Technology (MeitY).
Historically, DSCs were divided into three classes based on the level of identity verification involved. However, the system has been updated:
[!IMPORTANT] A Class 3 DSC is legally mandatory for all MCA corporate registrations (SPICe+, FiLLiP), Income Tax filing (ITR), GST filing, e-Tendering, DGFT (Directorate General of Foreign Trade) applications, and Trademark/Patent filings in India.
One of the most common questions entrepreneurs ask is: Is a digital signature as legally binding as a handwritten one?
Yes. In India, digital signatures have absolute legal equivalence to traditional handwritten signatures.
Under Section 4 and Section 5 of the IT Act, 2000, the Indian government grants legal recognition to electronic records and digital signatures. It states that where any law requires a physical signature, a digital signature that complies with asymmetric cryptography and is issued by a licensed CA satisfies that requirement.
Furthermore, under the Indian Evidence Act, 1872 (Section 65B), digitally signed documents are admissible as primary electronic evidence in a court of law, providing strong legal protection against contractual disputes.
Despite their broad legal validity, the First Schedule of the IT Act, 2000, specifically lists certain documents that cannot be signed digitally. These documents still require physical ink signatures on paper:
Securing a Class 3 Digital Signature Certificate is a quick and paperless process that can be completed online in under 30 minutes with a professional registration partner.
Reach out to an authorized certifying provider linked with licensed Certifying Authorities (CAs) in India (such as eMudhra, Capricorn, VSign, or Protean/NSDL).
Choose the configuration based on your needs:
Once the CA verifies your video and documents, the DSC is approved.
A cryptographic USB token (like an ePass2003) is a physical, password-protected security hardware device. In India, the Controller of Certifying Authorities (CCA) mandates that private signing keys must never be stored directly on a computer hard drive, where they can be hacked or copied. Storing them on a cryptographic USB token ensures the private key cannot be exported or copied.
Generally, no. Standard Class 3 DSCs that reside on a physical USB hardware token require a computer USB port to run. However, for mobile-friendly signing, platforms like Aadhaar eSign allow citizens to sign documents remotely by entering an Aadhaar-linked OTP, which triggers a one-time digital signature in the cloud.
In India, Class 3 DSCs can be issued with a validity of 1 Year, 2 Years, or 3 Years. Once the validity period expires, the certificate must be renewed through identity re-verification.
A Class 3 DSC is issued in the personal name of the individual.
The cryptographic USB token has a security feature: if you enter the wrong PIN/password 10 consecutive times, the token will lock and block access. You will have to use an admin key or return the token to your service partner to reset and re-download the certificate.
No. By design, the private key stored inside a FIPS-compliant cryptographic USB token is non-exportable and write-protected. It cannot be copied, duplicated, or transferred to another device.
There is no limit. You can sign an unlimited number of PDFs, MCA forms, ITRs, and documents as long as your certificate remains active and valid.
If you lose your physical USB token, you must treat it like a lost credit card. Contact your certifying partner immediately to revoke/cancel the active certificate to prevent unauthorized use. You will then need to apply for a fresh Class 3 DSC.
Yes. You can digitally sign scanned JPEG or PDF documents. However, the signature only validates that the file has not been altered after the signature was applied. It does not validate the content written on the paper before scanning.
Yes. Standard Class 3 digital signatures in India use internationally recognized cryptographic formats (PKI, PAdES) that conform to global security standards, making them acceptable by foreign banks, embassies, and immigration agencies (like USCIS).
Absolutely not. Sharing a USB token is equivalent to sharing your handwritten signature. Every director must obtain their own unique Class 3 DSC in their own name to ensure individual accountability under corporate law.
When you open a digitally signed PDF inside Adobe Acrobat Reader, the software automatically verifies the signature against global trust lists. If the signature is valid, it displays a “Signature Valid” green checkmark. If it shows a yellow question mark, it means you must add the certifying authority to your trusted identities list.
Some of the most popular licensed CAs in India include:
No. The entire application and verification process is completely remote. You can complete the identity upload and record the video verification from your smartphone or laptop from the comfort of your home.
As business operations move toward a completely paperless future, understanding and utilizing digital signatures is no longer optional. It is an essential administrative tool that protects your corporate contracts from tampering, ensures your legal filings are approved without delay, and streamlines your offboarding and compliance workflows.
Securing a Class 3 DSC, selecting the correct hardware token, and managing the video verification process require professional support to prevent verification errors and application rejections.
At Kaagzaat, we help business owners, founders, and operators establish their secure corporate identity. From procuring Class 3 DSCs and USB tokens for your board of directors to managing company registrations, trademark applications, and annual ROC filings, our experienced CAs and CSs handle the paperwork so you can focus on building your startup.
Disclaimer: This guide is intended solely for educational purposes and does not represent professional legal counsel. Always consult with a qualified cybersecurity expert or corporate lawyer for specific legal advice.
Complementary legal and compliance solutions for your business.
Complete professional assistance for Academy Brand in India.
Complete professional assistance for Accounting & Bookkeeping in India.
Complete professional assistance for Accounting Firm in India.
Complete professional assistance for Agricultural Machinery in India.
Complete professional assistance for Agriculture Products in India.
Latest circulars and notifications from the Ministry of Corporate Affairs.
Visit Official SiteGovernment initiative for promoting the startup ecosystem in India.
Visit Official SiteAbout the Author
Kaagzaat Editorial is a senior contributor to the Kaagzaat Legal Team, specializing in business compliance and intellectual property law.
Join 10,000+ businesses who trust Kaagzaat for their brand protection and legal compliance in India.
Continue Reading
We Provide Legally Same Day Court Marriage Certificate by Delhi/NCR govt under tatkal or normal scheme. Court Marriage in 1-2 Hours from Delhi NCR At Low price No Hidden Charges. A to Z Court Marriage Services By Best court marriage lawyer. Call +917503782804, +918920187551
Read articleLost or forgot your MSME number? Read this detailed guide on how to find your Udyam Registration Number online, retrieve it via Aadhaar, and verify it on the official portal.
Read articleAn exhaustive, step-by-step guide to Udyam MSME Registration in India. Learn about eligibility, classification rules, documentation, 25 critical FAQs, and how it benefits your business.
Read articleGet expert guidance on WhatsApp now!