The complete guide to DSC signatures for growing teams

What a Class 3 Digital Signature Certificate actually is, where it is required, how it differs from Aadhaar eSign, and how to roll it out without slowing your team down.

Most teams meet the Digital Signature Certificate the same way: someone in finance is told a filing needs one, a USB token arrives, and nobody quite knows what happened. Then the question spreads. Can we use this for our contracts? Is the thing we have been emailing around actually binding? What did we buy?

This is the short version, written for the person who has to make the decision rather than for a compliance auditor.

What a DSC actually is

A Digital Signature Certificate is a cryptographic credential issued to a named person by a Certifying Authority licensed by India's Controller of Certifying Authorities. It does two things at once. It proves that a specific person signed, and it proves that the document has not changed by so much as a comma since they did.

That second property is the one people underestimate. A scanned signature proves nothing about the pages it sits on. A DSC signature is mathematically bound to the exact bytes of the document, so any later edit breaks the seal visibly rather than quietly.

Class 3 is the level that matters for business. It requires the signer's identity to be verified in person or through a video KYC process, and it is what statutory filings, tenders and high-value agreements expect.

Where the law puts it

The Information Technology Act, 2000 gives digital signatures the same legal standing as handwritten ones, with a short list of exclusions. Section 5 establishes the equivalence. The First Schedule sets out what still requires wet ink — negotiable instruments other than cheques, powers of attorney, trusts, wills and contracts for the sale or conveyance of immovable property.

Read that list carefully, because what is not on it is most of what your business signs. NDAs, master services agreements, offer letters, vendor contracts, statements of work, purchase orders, board resolutions and consultancy agreements are all outside the exclusions.

DSC and Aadhaar eSign are not the same thing

Both are legally recognised. They fit different situations.

A DSC lives on a hardware token held by a named individual and is typically valid for one to three years. Because the credential is physically in that person's possession, it suits the small number of people in a business who sign frequently and on behalf of the company — a director, a company secretary, an authorised signatory.

Aadhaar eSign authenticates the signer at the moment of signing, through an OTP against their Aadhaar record, and issues a one-time certificate. There is no token to carry and nothing to renew, which makes it the right instrument for the people who sign once: a candidate accepting an offer, a vendor countersigning a contract, a client approving a statement of work.

Most businesses need both, and the mistake is choosing one and forcing it on the other case.

The rollout problem nobody warns you about

The technology is not the hard part. The hard part is that a DSC is issued to a person, and people go on leave, change roles and resign.

Three things worth deciding before you buy tokens:

  1. Who signs what, in writing. Map the agreement types to authorised signatories and record the value thresholds. This is the document your auditor will ask for, and writing it after the fact is much harder.
  2. What happens when a signatory is unavailable. A single-signatory setup means one person's holiday stops your contracts. Two authorised signatories per agreement class is the usual answer.
  3. Renewal dates, tracked somewhere real. An expired DSC fails at exactly the wrong moment, and the lead time to reissue is days, not minutes.

Why the token is rarely the bottleneck

Here is what we see when we measure a signature cycle end to end. The cryptographic act takes seconds. The delay is everywhere around it: finding the current version of the template, getting three approvals over email, working out who is authorised to sign this particular value, sending it out, and then chasing.

Which is why buying DSC tokens and carrying on emailing PDFs changes very little. The credential is only worth what the process around it can prove.

What good looks like

A working setup has four properties, and all four are process rather than cryptography.

The document starts from a template your legal team published, so nobody is negotiating a clause that was settled two years ago. Approvals are recorded against the document rather than in an inbox. The signature method is chosen by who is signing, not by what the business happens to own. And every one of those steps lands in a single audit trail that exports as one file.

Get that right and the certificate does exactly what it should: it disappears into the process, and the only thing anyone notices is that agreements now come back the same week they went out.

All articlesSchedule a Demo

See the same workflow on your own paperwork.

Bring one template and one live agreement. Thirty minutes is enough.

Schedule a Demo