Every time you file your income tax return with a digital signature, sign a company incorporation document on the MCA portal, or submit a tender online, you are relying on a piece of digital trust infrastructure most people never think about. Somewhere behind that little “verified” tick is a Certifying Authority that issued your digital certificate, and behind that CA sits a government official empowered to keep the whole system honest. This is the Controller of Certifying Authorities, and understanding how this office works is central to understanding how the Information Technology Act, 2000 makes digital signatures legally trustworthy in India.
Table of Contents
- Why the IT Act created a regulator for certifying authorities
- Licensing certifying authorities
- Applying for a licence
- Granting or rejecting an application
- Core functions and duties of the Controller
- Certifying public keys and the root of trust
- Resolving disputes between CAs and subscribers
- Recognising foreign certifying authorities
- Suspension and revocation of licences
- Investigation and compliance powers
- Why this framework matters for e-commerce
Why the IT Act created a regulator for certifying authorities
Digital signatures work because of a chain of trust. A Certifying Authority (CA) verifies a person’s identity and issues them a Digital Signature Certificate, which lets others confirm that an electronic document genuinely came from that person and hasn’t been altered. But this only works if someone is checking that the CAs themselves are trustworthy. Without a regulator, anyone could set up shop as a CA and issue certificates with no real verification behind them, and the entire system of e-commerce and e-governance built on digital signatures would collapse.
The IT Act 2000 solves this by creating a statutory regulator called the Controller of Certifying Authorities, appointed by the Central Government under Section 17 of the Act. The government can also appoint Deputy Controllers, Assistant Controllers, and other officers to assist the Controller, all functioning under the Controller’s general supervision. The Office of the CCA came into existence on November 1, 2000, shortly after the Act was notified, with the specific goal of promoting e-commerce and e-governance through the wide use of digital signatures.
Today, the CCA functions under the Ministry of Electronics and Information Technology (MeitY) and remains the apex authority for India’s public key infrastructure ecosystem.
Licensing certifying authorities
Before any organisation can start issuing Digital Signature Certificates to the public, it needs a licence from the Controller. This licensing process is where most of the Controller’s day-to-day regulatory work happens.
Applying for a licence
Under Section 21 of the Act, any person meeting the prescribed qualifications, expertise, manpower, financial resources, and other infrastructure requirements can apply to the Controller for a licence to issue electronic signature certificates. Section 22 lays down the specific format for these applications, which must include a certification practice statement, identity proof, a payment of the prescribed fee, and any other documents the Controller may require. Licences aren’t permanent either; Section 23 requires CAs to apply for renewal well before their existing licence expires, so the Controller gets a regular opportunity to reassess whether a CA still meets the required standards.
Granting or rejecting an application
Section 24 gives the Controller discretion to grant or reject a licence application after examining the accompanying documents and other relevant factors. Importantly, the Act builds in a safeguard here: no application can be rejected without giving the applicant a reasonable opportunity to be heard. This reflects the principles of natural justice, ensuring the Controller’s power isn’t exercised arbitrarily.
Core functions and duties of the Controller
Section 18 of the Act lists out the wide range of functions the Controller can perform. Broadly, these functions fall into a few categories.
| Function | What it involves |
|---|---|
| Supervision | Overseeing the activities of all licensed Certifying Authorities to ensure compliance with the Act |
| Certification of public keys | Digitally signing the public keys of CAs so users can verify their authenticity |
| Standard-setting | Laying down standards for CAs to maintain accounts and audit their operations |
| Qualification norms | Specifying the qualifications and experience required for CA employees |
| Regulations for conduct of business | Prescribing the form and content of a Digital Signature Certificate and its associated key |
| Dispute resolution | Resolving conflicts between certifying authorities and subscribers |
These functions together make sure a CA isn’t just licensed once and left alone. The Controller has continuing oversight over how a CA actually conducts its business.
Certifying public keys and the root of trust
One of the Controller’s most technically important jobs is establishing the Root Certifying Authority of India (RCAI). Under Section 18(b), the Controller digitally signs the public keys of all licensed CAs in the country. This creates a single “root of trust” at the top of the chain: when your browser or an e-governance portal checks a digital certificate, it can trace that trust all the way back to the Controller’s own signature. The RCAI is operated as per the standards laid down under the Act, and every licensed CA’s public key is ultimately signed by this root authority.
Resolving disputes between CAs and subscribers
The Controller also acts in a quasi-judicial capacity when disagreements arise between a Certifying Authority and a subscriber, for instance over a wrongly issued or revoked certificate. This dispute-resolution power is treated as significant enough that it cannot be delegated to a Deputy or Assistant Controller, unlike most of the Controller’s other functions under Section 27, which do permit delegation in writing.
Recognising foreign certifying authorities
E-commerce doesn’t stop at national borders, and the Act anticipates this. Section 19 empowers the Central Government, with the Controller’s recommendation, to recognise a foreign Certifying Authority for the purposes of the Act. Once recognised, digital certificates issued by that foreign CA carry the same legal validity in India as those issued by a domestic licensed CA. This recognition isn’t unconditional, though. If the foreign CA violates any of the conditions attached to its recognition, the Controller can withdraw or revoke that recognition.
Suspension and revocation of licences
Licensing power means little without enforcement teeth, and this is where Sections 25 and 26 come in.
Under Section 25, the Controller can suspend a CA’s licence if, after due inquiry, they are satisfied that the CA has contravened any provision of the Act, rules, or regulations, or that a certificate was applied for or issued through misrepresentation of facts. During any period of suspension, the CA is barred from issuing new certificates. Crucially, the same safeguard applies here as with rejections: no licence can be suspended or revoked without giving the CA a reasonable opportunity to show cause first.
Once a licence is suspended or revoked, Section 26 requires the Controller to publish a notice of that action in the database maintained for this purpose, so that anyone relying on certificates from that CA is put on notice. Section 33 further requires the CA to immediately surrender its licence once it’s suspended or revoked.
Investigation and compliance powers
Beyond licensing, the Controller (or an officer authorised by the Controller) has the power under Section 28 to investigate any contravention of the Act’s provisions. Section 29 backs this up with access rights to computers, data, and systems where relevant evidence might be found. Section 68 additionally allows the Controller to issue binding directions to a Certifying Authority to ensure it complies with the Act, and failure to comply with such a direction is itself an offence. Together, these provisions mean the Controller isn’t only a gatekeeper at the licensing stage but an active regulator throughout a CA’s operational life, as explained in this detailed breakdown of the Controller’s role.
Why this framework matters for e-commerce
All of this regulatory machinery exists to solve one basic problem: how do you trust a signature you can’t see someone physically make? By licensing CAs, certifying their public keys, resolving disputes, and holding the power to suspend or revoke licences, the Controller ensures that a Digital Signature Certificate issued anywhere in India means the same thing and carries the same legal weight. This is what allows electronic contracts, GST filings, company registrations, and online tenders to hold up as legally valid documents. As one overview of this regulatory structure notes, the CCA framework was designed precisely to give electronic records and digital signatures the same legal sanctity as their paper counterparts, and this framework remains foundational to how digital transactions are secured in India today.
What do you think? If a Certifying Authority in India were found issuing fake certificates, do you think suspension of its licence alone is a strong enough deterrent, or should the Act allow for stricter penalties? And as more transactions move online, should the criteria for becoming a licensed CA be made even tighter than they currently are?
References
- https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
- https://cca.gov.in/about.html
- https://www.digitalindia.gov.in/di_ecosystem/controller-of-certifying-authorities-cca/
- https://cca.gov.in/rti.html
- https://www.legalserviceindia.com/legal/article-5842-role-of-controller-in-issuing-digital-signature-certificates-under-information-technology-act-2000.html
- https://www.taxmann.com/post/blog/regulation-of-certifying-authorities-for-cyber-crimes
Leave a Reply