Every time you file your income tax return with a digital signature, sign a company incorporation document on the MCA portal, or submit a tender online, you are relying on a piece of digital trust infrastructure most people never think about. Somewhere behind that little “verified” tick is a Certifying Authority that issued your digital certificate, and behind that CA sits a government official empowered to keep the whole system honest. This is the Controller of Certifying Authorities, and understanding how this office works is central to understanding how the Information Technology Act, 2000 makes digital signatures legally trustworthy in India.

Table of Contents

Why the IT Act created a regulator for certifying authorities

Digital signatures work because of a chain of trust. A Certifying Authority (CA) verifies a person’s identity and issues them a Digital Signature Certificate, which lets others confirm that an electronic document genuinely came from that person and hasn’t been altered. But this only works if someone is checking that the CAs themselves are trustworthy. Without a regulator, anyone could set up shop as a CA and issue certificates with no real verification behind them, and the entire system of e-commerce and e-governance built on digital signatures would collapse.

The IT Act 2000 solves this by creating a statutory regulator called the Controller of Certifying Authorities, appointed by the Central Government under Section 17 of the Act. The government can also appoint Deputy Controllers, Assistant Controllers, and other officers to assist the Controller, all functioning under the Controller’s general supervision. The Office of the CCA came into existence on November 1, 2000, shortly after the Act was notified, with the specific goal of promoting e-commerce and e-governance through the wide use of digital signatures.

Today, the CCA functions under the Ministry of Electronics and Information Technology (MeitY) and remains the apex authority for India’s public key infrastructure ecosystem.

Licensing certifying authorities

Before any organisation can start issuing Digital Signature Certificates to the public, it needs a licence from the Controller. This licensing process is where most of the Controller’s day-to-day regulatory work happens.

Applying for a licence

Under Section 21 of the Act, any person meeting the prescribed qualifications, expertise, manpower, financial resources, and other infrastructure requirements can apply to the Controller for a licence to issue electronic signature certificates. Section 22 lays down the specific format for these applications, which must include a certification practice statement, identity proof, a payment of the prescribed fee, and any other documents the Controller may require. Licences aren’t permanent either; Section 23 requires CAs to apply for renewal well before their existing licence expires, so the Controller gets a regular opportunity to reassess whether a CA still meets the required standards.

Granting or rejecting an application

Section 24 gives the Controller discretion to grant or reject a licence application after examining the accompanying documents and other relevant factors. Importantly, the Act builds in a safeguard here: no application can be rejected without giving the applicant a reasonable opportunity to be heard. This reflects the principles of natural justice, ensuring the Controller’s power isn’t exercised arbitrarily.

Core functions and duties of the Controller

Section 18 of the Act lists out the wide range of functions the Controller can perform. Broadly, these functions fall into a few categories.

Function What it involves
Supervision Overseeing the activities of all licensed Certifying Authorities to ensure compliance with the Act
Certification of public keys Digitally signing the public keys of CAs so users can verify their authenticity
Standard-setting Laying down standards for CAs to maintain accounts and audit their operations
Qualification norms Specifying the qualifications and experience required for CA employees
Regulations for conduct of business Prescribing the form and content of a Digital Signature Certificate and its associated key
Dispute resolution Resolving conflicts between certifying authorities and subscribers

These functions together make sure a CA isn’t just licensed once and left alone. The Controller has continuing oversight over how a CA actually conducts its business.

Certifying public keys and the root of trust

One of the Controller’s most technically important jobs is establishing the Root Certifying Authority of India (RCAI). Under Section 18(b), the Controller digitally signs the public keys of all licensed CAs in the country. This creates a single “root of trust” at the top of the chain: when your browser or an e-governance portal checks a digital certificate, it can trace that trust all the way back to the Controller’s own signature. The RCAI is operated as per the standards laid down under the Act, and every licensed CA’s public key is ultimately signed by this root authority.

Resolving disputes between CAs and subscribers

The Controller also acts in a quasi-judicial capacity when disagreements arise between a Certifying Authority and a subscriber, for instance over a wrongly issued or revoked certificate. This dispute-resolution power is treated as significant enough that it cannot be delegated to a Deputy or Assistant Controller, unlike most of the Controller’s other functions under Section 27, which do permit delegation in writing.

Recognising foreign certifying authorities

E-commerce doesn’t stop at national borders, and the Act anticipates this. Section 19 empowers the Central Government, with the Controller’s recommendation, to recognise a foreign Certifying Authority for the purposes of the Act. Once recognised, digital certificates issued by that foreign CA carry the same legal validity in India as those issued by a domestic licensed CA. This recognition isn’t unconditional, though. If the foreign CA violates any of the conditions attached to its recognition, the Controller can withdraw or revoke that recognition.

Suspension and revocation of licences

Licensing power means little without enforcement teeth, and this is where Sections 25 and 26 come in.

Under Section 25, the Controller can suspend a CA’s licence if, after due inquiry, they are satisfied that the CA has contravened any provision of the Act, rules, or regulations, or that a certificate was applied for or issued through misrepresentation of facts. During any period of suspension, the CA is barred from issuing new certificates. Crucially, the same safeguard applies here as with rejections: no licence can be suspended or revoked without giving the CA a reasonable opportunity to show cause first.

Once a licence is suspended or revoked, Section 26 requires the Controller to publish a notice of that action in the database maintained for this purpose, so that anyone relying on certificates from that CA is put on notice. Section 33 further requires the CA to immediately surrender its licence once it’s suspended or revoked.

Investigation and compliance powers

Beyond licensing, the Controller (or an officer authorised by the Controller) has the power under Section 28 to investigate any contravention of the Act’s provisions. Section 29 backs this up with access rights to computers, data, and systems where relevant evidence might be found. Section 68 additionally allows the Controller to issue binding directions to a Certifying Authority to ensure it complies with the Act, and failure to comply with such a direction is itself an offence. Together, these provisions mean the Controller isn’t only a gatekeeper at the licensing stage but an active regulator throughout a CA’s operational life, as explained in this detailed breakdown of the Controller’s role.

Why this framework matters for e-commerce

All of this regulatory machinery exists to solve one basic problem: how do you trust a signature you can’t see someone physically make? By licensing CAs, certifying their public keys, resolving disputes, and holding the power to suspend or revoke licences, the Controller ensures that a Digital Signature Certificate issued anywhere in India means the same thing and carries the same legal weight. This is what allows electronic contracts, GST filings, company registrations, and online tenders to hold up as legally valid documents. As one overview of this regulatory structure notes, the CCA framework was designed precisely to give electronic records and digital signatures the same legal sanctity as their paper counterparts, and this framework remains foundational to how digital transactions are secured in India today.

What do you think? If a Certifying Authority in India were found issuing fake certificates, do you think suspension of its licence alone is a strong enough deterrent, or should the Act allow for stricter penalties? And as more transactions move online, should the criteria for becoming a licensed CA be made even tighter than they currently are?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  2. https://cca.gov.in/about.html
  3. https://www.digitalindia.gov.in/di_ecosystem/controller-of-certifying-authorities-cca/
  4. https://cca.gov.in/rti.html
  5. https://www.legalserviceindia.com/legal/article-5842-role-of-controller-in-issuing-digital-signature-certificates-under-information-technology-act-2000.html
  6. https://www.taxmann.com/post/blog/regulation-of-certifying-authorities-for-cyber-crimes

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

E-Commerce

1 Introduction to E-commerce

  1. Introduction
  2. Meaning of E-Commerce
  3. E-Commerce Web Portal
  4. E-Commerce Software
  5. E-Commerce APIs
  6. M-Commerce and Multi-channel Commerce
  7. Use of Emerging Technologies in E-Commerce
  8. Why E-Commerce
  9. Evolution of E-Commerce
  10. Types of E-Commerce
  11. Advantages and Disadvantages of E-Commerce

2 E-Commerce Business Models

  1. Introduction
  2. What is a Business Model?
  3. Key Elements of a Business Model
  4. E-Commerce Business Models to Understand Target Customer
  5. E-Commerce Design Models
  6. Implementing E-Commerce Models
  7. E-Commerce Revenue Models
  8. Impact of COVID on E-Commerce

3 Technology used in E-Commerce

  1. Introduction
  2. Design Considerations of E-Commerce
  3. Essential Technology Features Required
  4. Difference between App Based and Web-Based Business
  5. Building, Designing and Launching E-Commerce Website
  6. SDLC Cycle for Designing E-Commerce Solutions
  7. Architectural Framework and Network Infrastructure
  8. Impact of Emerging Technologies on E-Commerce
  9. Digital Platforms and E-Commerce
  10. Digitalisation and Digital Transformation in Businesses

4 Electronic Governance

  1. Introduction
  2. Meaning of E-Governance
  3. Differences between E-Government and E-Governance
  4. Differences between E-Governance and E-Commerce
  5. Advantages of Employing Digital Technologies in Governance
  6. Gartnerโ€™s Evolution Model of E-Governance
  7. E-Governance in India
  8. Digital India
  9. E-Governance initiatives in India

5 E-Payment

  1. Introduction
  2. Overview of Payment System
  3. Meaning of E-Payment
  4. Difference between E-Payment & Conventional Payment
  5. Payment Gateways
  6. Steps about Functioning of a Payment Gateway
  7. Types of Payment Gateways
  8. Types of Payment Methods
  9. Requirements Metrics of a Payment System
  10. Merits of E-Payment System
  11. Risks Involved in E-Payment

6 E-Banking

  1. Introduction
  2. Concept of E-Banking
  3. Importance of E-Banking
  4. Technology used in Banking
  5. EFT (Electronic Fund Transfer)
  6. NEFT (National Electronic Fund Transfer)
  7. RTGS (Real Time Gross Settlement)
  8. IMPS (Immediate Payment Service)
  9. UPI (Unified Payments Interface)
  10. Difference between NEFT, RTGS & IMPS
  11. Virtual Currency
  12. Automated Clearing House
  13. Automated Ledger Posting
  14. Distributed Ledger Technology

7 Website Development

  1. Introduction
  2. Meaning of Website
  3. Evolution of Website
  4. Website Usage
  5. HTTP & HTTPS Protocols
  6. Types of Website
  7. Development of Website
  8. Ingredients Required for Website Development
  9. Website Hosting

8 Electronic Commerce Software

  1. Introduction
  2. E-commerce Software Platform
  3. Types of Software Platforms
  4. Shopify – An Online Store Builder
  5. E-Auction Processes the Real-Time Visibility
  6. PayPal Holdings Online Payments
  7. SAP Commerce Cloud
  8. Functions of E-Commerce Software Platforms
  9. Advanced Functions of E-Commerce Software
  10. E-Commerce Software for Small & Midsize Companies
  11. E-Commerce Software for Midsize to Large Business
  12. E-Commerce Software for Large Business
  13. Planning Electronic Commerce Initiatives
  14. Strategies for Developing E-Commerce Websites
  15. Managing E-Commerce Implementations

9 Web Server Hardware and Software

  1. Meaning of Server
  2. Web Server Essentials
  3. Different Types of Web Server
  4. Characteristics of a Web Server
  5. Functioning of a Web Server
  6. Mail Server
  7. Process of Sending E-mails
  8. Operating System
  9. Windows
  10. Linux
  11. Linux vs. Windows
  12. Web Server Hardware
  13. Hardware used in Web Servers
  14. Web Server Software
  15. Application Server Software
  16. Web Server & Application Server
  17. Web Site and Internet Utility Programs

10 Cyber Security

  1. Meaning of Cyber Security
  2. Cyber Security Impact on E-Commerce
  3. Cyber Security Relevance
  4. Information Security V/s Cyber Security
  5. Basics of Cyber World
  6. Need & Concepts behind Security
  7. IoT and Cyber World
  8. Cyber Crime and Law
  9. Security Barriers

11 Cyber Security Measures

  1. Role of Cyber Security Analysts
  2. Essential Cyber Security Measures
  3. Precautionary Cyber-Security Measures Enterprise Takes
  4. IoT and its Impact
  5. Vulnerable Information on Internet
  6. Vulnerabilities of Systems
  7. Internet Vulnerabilities
  8. Wireless Security Challenges
  9. Malicious Software
  10. Hackers and Computer Crime
  11. Cyber Crime
  12. Global Threats: Cyber terrorism and Cyber Warfare
  13. Cyber Forensic
  14. Securing the Business on Internet
  15. Securing Network Transactions
  16. Security Measures and Enforcement

12 IT Act 2000

  1. Definition
  2. Formulation of IT Act 2000
  3. Amendments in IT Act 2000
  4. Digital Signature & Encryption
  5. Attribution
  6. Acknowledgement and Dispatch of Electronic Records
  7. Regulation of Certifying Authorities
  8. Digital Signatures Certificates
  9. Duties of Subscribers
  10. Penalties and Adjudication
  11. Procedure, Working & Legal Position in Digital Signature
  12. Appellate Tribunal
  13. Offences and Cyber-Crimes
  14. E-Signature and Digital Signature
  15. Encryption

13 E-Tailing

  1. E-tailing
  2. E-tailing Models
  3. E-retail Mix-Sale the 7Cs
  4. E-tailing in India

14 E-Services

  1. Meaning of E-Services
  2. Benefits of E-Services
  3. FinTech
  4. eFinancial Services
  5. eTravel Services
  6. eAuction Services
  7. eLearning
  8. Virtual Communities and Web Portals
  9. Online Learning
  10. ePublishing Services
  11. Online Entertainment

15 App Based Commerce

  1. What is an App?
  2. Classification of Apps
  3. Types of Apps
  4. Steps for App Development
  5. Mobile Development Frameworks
  6. App Store
  7. Apps for Various Domains & Segments