August 19, 2026

Class 2 vs Class 3 DSC: Key Differences (2026)

Summary · 15 min read

Class 2 vs Class 3 DSC: verification levels, security features, use cases, costs, and why Class 3 is now the only certificate available in India.

The core difference between Class 2 and Class 3 Digital Signature Certificates (DSCs) comes down to verification rigor, security level, and intended use. Class 2 certificates provided medium-assurance identity verification for routine filings like income tax and GST returns, while Class 3 certificates required stricter identity proofing — including biometric or video verification — for high-stakes transactions such as e-tendering and e-procurement. In India, the Controller of Certifying Authorities (CCA) discontinued Class 2 DSC issuance from January 1, 2021, consolidating all DSC needs into Class 3, which now carries the object identifiers (OIDs) of both former classes. Today, Class 3 is the only DSC available, and it covers everything Class 2 once handled plus all high-assurance use cases.

What Is a Digital Signature Certificate?

A Digital Signature Certificate is a secure digital key issued by a licensed Certifying Authority (CA) that verifies the identity of the certificate holder and enables tamper-evident signing of electronic documents. DSCs are based on Public Key Infrastructure (PKI), which uses asymmetric cryptography — a pair of public and private keys — to ensure authenticity, integrity, and non-repudiation of signed content. When a user signs a document with their private key, the recipient can verify the signature using the corresponding public key embedded in the certificate.

In India, DSCs are governed by the Information Technology Act, 2000 (IT Act), which grants electronic signatures legal equivalence to handwritten signatures under Section 3, provided they use asymmetric cryptosystems and hash functions. The CCA, under the Ministry of Electronics and Information Technology (MeitY), regulates licensed CAs — such as eMudhra, Sify, and nCode — that issue DSCs to individuals and organizations. The IT Act originally defined three classes of DSCs: Class 1 (basic, low-assurance), Class 2 (medium-assurance), and Class 3 (high-assurance), each calibrated to different transaction risk levels.

For a broader understanding of the term, our guide on what DSC stands for explains how digital signature certificates fit into modern signing workflows beyond the Indian context.

Class 2 Digital Signature Certificates Explained

Class 2 DSCs were designed for moderate-assurance signing scenarios. The issuing CA verified the applicant's identity by cross-checking submitted documents — such as a PAN card, Aadhaar card, or passport — against trusted government databases. This verification confirmed that the subscriber's stated identity matched official records, but it did not require in-person appearance or biometric authentication. Class 2 certificates were primarily used for:

  • Income Tax e-filing for individuals and professionals
  • GST registration and return filing
  • Ministry of Corporate Affairs (MCA) / Registrar of Companies (ROC) filings
  • Director KYC verification
  • EPFO filings and company compliance submissions

Class 2 certificates were typically stored on software-based systems or basic USB tokens. They used standard PKI encryption for signing but lacked hardware-enforced private key protection, meaning the private key could potentially be extracted if the host device was compromised. This made them adequate for moderate-risk transactions but insufficient for high-value or legally sensitive scenarios.

Discontinuation of Class 2 DSC

Under revised CCA guidelines, Class 2 DSCs were discontinued from January 1, 2021. Certifying Authorities stopped issuing and renewing Class 2 certificates on that date. Existing Class 2 certificates remained valid until their original expiry but could not be renewed — holders had to apply for a Class 3 replacement upon expiry. The CCA consolidated the two tiers because Class 3's stronger verification standards and hardware-enforced security made it suitable for all use cases that Class 2 previously served, eliminating the need for a separate lower-assurance tier.

Class 3 Digital Signature Certificates Explained

Class 3 DSCs represent the highest level of assurance available under the Indian DSC framework. The issuance process requires rigorous identity verification, which typically includes:

  • Aadhaar-based OTP authentication or video verification
  • PAN card verification
  • For organizational DSCs: additional validation of company incorporation documents, board resolutions, and authorization letters

Class 3 certificates mandate storage on Hardware Security Modules (HSMs) or FIPS 140-2-certified secure USB crypto tokens. The private key never leaves the hardware token during signing operations, which prevents extraction even if the host computer is compromised. This hardware-enforced protection ensures tamper-proof signing and strong non-repudiation — courts in India recognize Class 3 signatures as robust evidence under the IT Act.

Class 3 DSCs are used for:

  • MCA company filings (incorporation, annual returns, director changes)
  • Income Tax e-filing for companies, LLPs, and audit reports
  • GST registration and filings
  • Government e-tendering and e-procurement (GeM portal, CPPP)
  • ICEGATE import-export filings
  • DGFT/IEC portal submissions
  • Trademark and patent filings
  • EPFO compliance submissions

Because Class 3 certificates now carry the OIDs of both former Class 2 and Class 3 tiers, a single Class 3 DSC covers every portal where either class was previously required.

Class 2 vs Class 3 DSC: Side-by-Side Comparison

FeatureClass 2 DSCClass 3 DSC
Security LevelMedium assuranceHigh assurance
Identity VerificationDatabase cross-check of submitted documentsAadhaar OTP / video verification + document validation
Private Key StorageSoftware-based or basic USB tokenFIPS 140-2-certified HSM or secure USB crypto token
Hardware EnforcementNo hardware-enforced key protectionPrivate key never exposed to host system
Typical Use CasesIncome tax, MCA/ROC, GST, EPFO (historical)All government portals, e-tendering, e-procurement, ICEGATE, DGFT, trademark filing
E-Tendering EligibilityNot permittedMandatory
Organizational ValidationNot requiredRequired for organizational DSC
Issuance Timeline1–2 days (historical)15–30 minutes (online eKYC) to 1–2 days
Cost RangeINR 500–1,500/year (historical)INR 2,000–5,000/year (including token)
Validity Period1–2 years1, 2, or 3 years
Current StatusDiscontinued since January 1, 2021Active and mandatory — the only DSC issued in India

Verification and Identity Assurance Differences

The verification gap between Class 2 and Class 3 was one of the most consequential differences. Class 2 verification relied on document-based database checks: the applicant submitted identity proof (PAN, Aadhaar, passport), and the CA confirmed that the details matched government records. No biometric verification, video call, or in-person appearance was required. This approach was efficient — certificates could be issued within 1–2 days — but it left a gap for impersonation attempts, since document details alone do not prove that the person submitting them is the rightful holder.

Class 3 verification closes that gap through multi-factor identity proofing. The standard process includes Aadhaar OTP authentication (confirming that the applicant controls the Aadhaar-linked mobile number), video verification (a live video call where the CA representative visually confirms the applicant's face matches submitted photographs), and document validation. For organizational Class 3 DSCs, the CA additionally validates the Certificate of Incorporation, board resolution authorizing the signatory, and the authorized signatory's own identity proof. This layered approach significantly reduces impersonation risk and is why government tendering portals require Class 3 — the financial and legal stakes of procurement demand the strongest available identity assurance.

Security Features and Private Key Storage

Security architecture is the second major differentiator. Class 2 certificates were typically stored as software files on a local disk or a basic USB drive. The private key was accessible to the host operating system during signing, which meant that malware or a compromised device could potentially extract the key and sign documents without the holder's knowledge. While PKI encryption itself was sound, the lack of hardware isolation made Class 2 vulnerable to key theft in practice.

Class 3 DSCs eliminate this attack vector by requiring FIPS 140-2-certified hardware tokens — either dedicated USB crypto tokens or HSMs. These tokens are designed so that the private key is generated inside the hardware and never leaves it. When a document is signed, the signing operation occurs inside the token itself; the host computer only sends the hash of the document to the token and receives the signed hash back. The private key is never exposed to the operating system, making extraction effectively impossible through software-based attacks. This hardware-enforced protection is why courts and regulators treat Class 3 signatures as strong non-repudiation evidence.

For a deeper look at the security landscape around electronic signatures, our article on whether electronic signatures are safe for business agreements examines how PKI, audit trails, and hardware-backed signing compare across jurisdictions.

Use Cases: When Each Certificate Class Applied

Understanding which certificate class applied to which transaction was critical for compliance before the 2021 consolidation — and it still matters for understanding the regulatory landscape today.

Class 2 Use Cases (Historical)

Class 2 DSCs were the workhorse certificate for routine compliance filings. They covered:

  • Income Tax e-filing: Individual tax returns and professional tax submissions
  • MCA/ROC filings: Annual returns, director appointments, share capital changes
  • GST compliance: Registration applications and periodic return filings
  • EPFO: Employee provident fund compliance filings
  • Director KYC: Annual Director Identification Number (DIN) KYC verification

Class 2 was not permitted for e-tendering, e-auctions, or any procurement platform requiring high-assurance signing. The CCA reserved those use cases exclusively for Class 3.

Class 3 Use Cases

Class 3 DSCs serve both the routine filings that Class 2 once handled and all high-assurance transactions:

  • All Class 2 use cases: Income tax, MCA, GST, EPFO filings (now via Class 3 with Class 2 OIDs)
  • E-tendering and e-procurement: Government tender submissions on GeM, CPPP, and state procurement portals
  • E-auctions: Bidding on electronic auction platforms
  • ICEGATE: Import-export customs filings
  • DGFT/IEC: Foreign trade portal submissions
  • Trademark and patent filings: Intellectual property registry submissions
  • High-value financial transactions: Share transfers under SEBI regulations, cross-border transactions under FEMA

The consolidation means that organizations no longer need to maintain two separate certificates — a single Class 3 DSC with appropriate validity covers every portal. Our DSC filing documents checklist walks through the documents and workflow needed for each filing type.

Cost and Validity Comparison

Pricing reflected the assurance gap between the two classes. Class 2 DSCs typically cost INR 500–1,500 per year, depending on the validity period and issuing CA. They were accessible through online portals with minimal documentation, making them attractive for small businesses and individual professionals handling moderate compliance volumes.

Class 3 DSCs cost INR 2,000–5,000 per year, with the higher price reflecting the hardware token requirement (typically INR 1,000+ for a FIPS 140-2-certified USB crypto token) and the more rigorous verification process. Organizational Class 3 DSCs cost more than individual versions because of the additional entity validation requirements.

Both classes were issued with validity periods of 1, 2, or 3 years. Renewal processes were similar in structure — document resubmission and identity re-verification — but Class 3 renewals additionally required token re-provisioning if the hardware was replaced. For a detailed breakdown of current DSC pricing, our guide on how much a DSC costs for business signing covers the cost components and what to expect when budgeting for certificates.

It is worth noting that since the discontinuation of Class 2, all new DSC procurement — whether for income tax filing or e-tendering — requires a Class 3 certificate. Organizations that previously held Class 2 certificates should plan for Class 3 replacement upon expiry, as renewal of Class 2 is no longer possible.

Why Class 2 Was Discontinued and What It Means for You

The CCA's decision to discontinue Class 2 from January 1, 2021, was driven by several factors:

  1. Security harmonization: Class 3's hardware-enforced key protection and stricter identity verification made it inherently more secure. Maintaining a separate lower-assurance tier created an unnecessary risk gradient when Class 3 could serve all use cases.
  2. OID consolidation: The CCA configured Class 3 certificates to carry the OIDs of both former Class 2 and Class 3 tiers. This means a Class 3 DSC is recognized by every portal that previously accepted Class 2, so there is no functional loss in moving to Class 3.
  3. Fraud reduction: Stricter identity proofing — including Aadhaar OTP and video verification — reduces impersonation risk, which is particularly important for government portals handling public funds.
  4. Operational simplification: Consolidating to a single certificate class reduces administrative overhead for both CAs and certificate holders. Organizations no longer need to manage two different certificate types for different filing requirements.

What This Means for Current Certificate Holders

If you hold a valid Class 2 certificate that has not yet expired, it remains valid until its original expiry date. However, once it expires, you cannot renew it — you must apply for a new Class 3 DSC. There is no loss of functionality in this transition: the Class 3 certificate will work on all portals where your Class 2 was accepted. The main changes are the stricter verification process (Aadhaar OTP or video verification) and the requirement for a FIPS 140-2-certified USB crypto token for key storage.

For organizations managing multiple signatories, this means budgeting for hardware tokens for each certificate holder and planning for the slightly longer issuance timeline if video verification is required. Our guide on how to make a digital signature certificate safely covers the end-to-end application process, including document preparation and token installation.

How to Choose the Right DSC for Your Needs Today

Since Class 2 is no longer available, the decision framework has simplified considerably. The real question is not "Class 2 or Class 3?" but rather "which type of Class 3 DSC do I need?"

Decision Checklist

Use this checklist to determine the right Class 3 DSC configuration:

  1. Individual vs. Organizational: If you are signing personal tax returns or acting as an individual professional, an Individual Class 3 DSC is sufficient. If you are signing on behalf of a company, LLP, or other entity, you need an Organizational Class 3 DSC, which requires incorporation documents and a board resolution.
  2. Signing vs. Tendering: For standard compliance filings (income tax, GST, MCA), a standard Class 3 DSC (signing-only) works. For e-tendering and e-procurement, you need a Class 3 DSC specifically configured for tendering, which may include additional OID configurations recognized by procurement portals.
  3. Validity Period: Choose 1-year validity for short-term needs or pilot projects, 2-year for standard business use, or 3-year for long-term compliance to minimize renewal frequency.
  4. Token Compatibility: Ensure the USB crypto token is compatible with your operating system and the target portals. Most CAs provide FIPS 140-2-certified tokens that work across Windows, macOS, and Linux.
  5. CA Selection: Choose a CCA-licensed CA with reliable support and fast issuance. Major CAs include eMudhra, Sify, nCode, and Capricorn. Our certificate authority list provides a broader reference for CAs across different signing ecosystems.

Issuance Timeline

With online eKYC verification (Aadhaar OTP + video verification), Class 3 DSCs can be issued within 15–30 minutes. The certificate is then downloaded and installed onto the USB crypto token. Physical token delivery via courier adds 2–3 days if the token is not already in hand.

Choose Nota Sign for Compliant Cross-Border E-Signatures

If your business operates beyond India's borders, managing different digital signature frameworks — India's CCA classes, the EU's eIDAS tiers (SES, AES, QES), Singapore's Singpass, and Hong Kong's iAM Smart — can create significant compliance overhead. Nota Sign, the global e-signature platform from FaDaDa (法大大), streamlines cross-border signing with coverage across 100+ countries and regions.

Nota Sign has been ranked #1 in China's e-signature software market by IDC for consecutive years, reflecting enterprise-grade adoption and infrastructure maturity. The platform delivers deep APAC compliance integration — including native support for Hong Kong's iAM Smart, Singapore's Singpass, and regional QES/AES/SES requirements — with data centers positioned for regional data residency needs.

Unlike per-seat-licensed competitors that charge for every signer seat, Nota Sign charges no per-seat fees, making it accessible for small teams and small businesses that need enterprise-grade signing without enterprise-scale licensing costs. Mid-market and enterprise buyers can request tailored plans calibrated to their volume, jurisdictional coverage, and integration requirements.

Contact Nota Sign to discuss how the platform can support your cross-border signing workflows.

FAQ

Nota Sign helps businesses build compliant agreement workflows, and our content follows strict editorial guidelines.

Discover a better way to e-sign your documents

Start for Free
Contact Sales