Banking and Insurance - Laws and Practice · Digital Banking
Digital Signature Certificates: Issuance and Representations under Section 36
Updated 11 October 2026 · Fact-checked
A Digital Signature Certificate is issued by a Certifying Authority after application and enquiry. Under Section 36 of the IT Act, 2000, the Authority must certify the matters in clauses (a) to (f), including the inserted clauses (ca) and (cb), eight clauses in all: its own compliance, publication and acceptance, the subscriber's key pair, accuracy of the information, and no knowledge of any adverse material fact.
Understand Digital Signature Certificates: Issuance and Representations
A Digital Signature Certificate (the Act now also uses the term electronic signature Certificate) links a subscriber to a public key. Banks, companies and regulators rely on it when they accept e-filings, e-instruments and online instructions. Without a trusted issuer, nobody could rely on it.
The issuer is a Certifying Authority. It must first hold a licence from the Controller (Section 21). The licence is not transferable or heritable, is valid for a prescribed period, and is subject to prescribed terms and conditions. The applicant must meet requirements on qualification, expertise, manpower, financial resources and infrastructure.
A person applies to the Certifying Authority in the prescribed form, with the prescribed fee (not more than ₹25,000; different fees may be set for different classes of applicants) and a certification practice statement, or a statement with the particulars specified by regulations (Section 35). The Authority considers these, makes such enquiries as it thinks fit, and either grants the certificate or rejects the application for reasons recorded in writing. It cannot reject unless the applicant has had a reasonable opportunity to show cause.
Section 36 is the heart of the topic. When issuing the certificate, the Authority certifies: (a) it has complied with the Act, rules and regulations; (b) it has published the certificate or made it available to those relying on it, and the subscriber has accepted it; (c) the subscriber holds the private key matching the public key listed; (ca) the subscriber holds a private key capable of creating a digital signature; (cb) the listed public key can verify a signature made by that private key; (d) the keys form a functioning key pair; (e) the information in the certificate is accurate; and (f) it has no knowledge of any material fact which, if included, would adversely affect the reliability of the representations in (a) to (d).
Why it matters: these representations are what a third party, such as a bank, relies on. The Authority stands behind the certificate. The subscriber has separate duties on acceptance (Section 41) and over the private key (Section 42).
Key rules to remember
- Section 36 representations (a) to (f)
- (a) compliance with Act; (b) published and accepted; (c) subscriber holds private key; (ca)+(cb) key can sign and verify; (d) functioning key pair; (e) information accurate; (f) no knowledge of adverse material fact
- Clauses (ca) and (cb) were inserted in 2009. Clause (f) protects only the reliability of clauses (a) to (d).
- Licence to issue certificates (Section 21)
- Application to Controller; prescribed requirements met; licence valid for prescribed period; not transferable or heritable
- Licence terms and conditions are as specified by regulations.
- Application for certificate (Section 35)
- Prescribed form + fee ≤ ₹25,000 + certification practice statement; grant, or reject with written reasons after reasonable chance to show cause
- Different fees may be prescribed for different classes of applicants.
- Certifying Authority procedures (Section 30)
- Secure hardware, software and procedures; reasonable reliability; secrecy and privacy of signatures; be repository of certificates; publish practices, certificates and status; follow specified standards
- Use this with Section 36 when asked for duties of a Certifying Authority.
How to solve Digital Signature Certificates: Issuance and Representations questions
Use this order for any problem or theory question on issuance and representations.
- 1Identify the party: Certifying Authority, subscriber or relying third party.
- 2State the stage: licensing (Section 21), application (Section 35), issuance (Section 36) or later events.
- 3List the Section 36 representations that the facts touch, using clause letters.
- 4Compare each fact with the clause. Ask: was the key pair working, was the information accurate, was the certificate accepted?
- 5Check procedural safeguards: written reasons and a chance to show cause on rejection.
- 6Check whether the issue is really suspension, revocation or subscriber duty, and cite Sections 37, 38, 41 or 42 if so.
- 7Conclude clearly: whether the Authority's representation was correct, and what follows.
Quickest way: Clause-by-clause recall for Section 36
When to use it: When you need a complete answer in a few minutes, or an open-book check is not enough time.
- Write: Authority certifies at issuance.
- Tick off compliance, publication and acceptance, private key held, key pair works, information accurate, no adverse knowledge.
- Add the one-line purpose: third parties rely on it.
- Link to the facts in one or two sentences and conclude.
Common mistakes in Digital Signature Certificates: Issuance and Representations
Listing only five or six points and missing clauses (ca) and (cb).
Older notes and bare-act memory omit the 2009 insertion.
Fix: Remember the key-pair group: holds private key, can sign, public key can verify, functioning pair.
Saying the subscriber gives the Section 36 representations.
Confusion with Section 41, where the subscriber certifies on acceptance.
Fix: Section 36 is by the Certifying Authority; Section 41 is by the subscriber.
Stating that clause (f) covers all representations.
Careless reading.
Fix: Clause (f) refers to the reliability of clauses (a) to (d) only.
Saying an application can be rejected without hearing the applicant.
Students remember only that the Authority may reject.
Fix: Rejection needs recorded reasons and a reasonable opportunity to show cause (Section 35).
Confusing Section 36 of the IT Act with Section 36 of the Payment and Settlement Systems Act, 2007.
Same section number in banking-related Acts.
Fix: Always name the Act. The Payment and Settlement Systems Act section protects good-faith action by the Government and Reserve Bank.
Worked examples
Example 1
Sigma Certs Ltd, a licensed Certifying Authority, issues a Digital Signature Certificate to Mr Rao. Later it is found that the public key listed cannot verify signatures created by Mr Rao's private key. Advise whether Sigma Certs made a correct representation under Section 36.
Show the solution
- Provision: Section 36 requires the Authority to certify that the public key listed in the certificate can be used to verify a digital signature affixed by the subscriber's private key, and that the subscriber's public key and private key constitute a functioning key pair (clauses (cb) and (d)).
- Analysis: the listed public key cannot verify signatures made by Mr Rao's private key, so there is no functioning key pair.
- Conclusion on representation: the certification under clauses (cb) and (d) was incorrect.
- Consequence: the certificate's reliability is affected. The most natural ground for revocation is Section 38(2)(b), that a requirement for issuance of the certificate was not satisfied. Section 38(2)(a), that a material fact represented in the certificate is false or has been concealed, applies only if the false fact is one represented in the certificate itself. The facts do not make that clear, so do not assert that both grounds clearly apply.
- Procedure: revocation under Section 38(2) is subject to Section 38(3), so it can happen only after Mr Rao has been given an opportunity of being heard. On revocation, the Authority must communicate it to Mr Rao (Section 38(4)) and publish a notice in the repository specified in the certificate (Section 39).
Answer: No. Sigma Certs' representations under Section 36(cb) and (d) were incorrect, because the listed public key cannot verify signatures made by Mr Rao's private key. The Authority may revoke the certificate, most naturally under Section 38(2)(b) (a requirement for issuance not satisfied), or under Section 38(2)(a) if the false fact is represented in the certificate. This can be done only after giving Mr Rao a hearing (Section 38(3)). It must then communicate the revocation to him (Section 38(4)) and publish notice of it (Section 39).
Example 2
An applicant's request for a certificate is rejected by a Certifying Authority by a brief email saying it was 'not suitable'. No show-cause notice was issued. Is the rejection valid?
Show the solution
- Provision: under Section 35(4) the Authority may grant the certificate or, for reasons recorded in writing, reject the application.
- Proviso: no application shall be rejected unless the applicant has been given a reasonable opportunity of showing cause.
- Analysis: here no show-cause opportunity was given, and the reason 'not suitable' is vague rather than recorded reasons tied to the application and statement.
- Conclusion: the rejection does not meet the Act's requirement.
Answer: The rejection is not valid. The Authority must record reasons in writing and give the applicant a reasonable opportunity to show cause before rejecting.
Exam tips
- Write the Section 36 clauses as a lettered list; examiners mark clause by clause.
- Always name the Act: Information Technology Act, 2000.
- In case questions, tie each fact to a specific clause before concluding.
- Link issuance to Sections 35, 21 and 30 for extra marks, but keep the main answer on Section 36.
- Mention that the representations exist so that third parties can rely on the certificate.
Practice questions from Digital Banking
- Ananya Iyer accepted a DSC issued for her use in internet banking authorisations. Under Section 41(2), by accepting it, what does she certif…
- Ramesh knows that a Digital Signature Certificate has been revoked, yet he shares it with a vendor solely so that the vendor can verify a si…
- Sunrise Cooperative Bank applies to a Certifying Authority (CA) for a Digital Signature Certificate for its CFO, Mr. Iyer. While issuing the…
- Vikram Joshi gave false information about his business address to the Certifying Authority when applying for a DSC, and later accepted the c…
- Hackers breached Sarthak Bank's systems, and the Adjudicating Officer ordered compensation under the IT Act, 2000. The police also want to p…
Digital Signature Certificates: Issuance and Representations in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Digital Signature Certificates: Issuance and Representations: frequently asked questions
What does Section 36 of the IT Act, 2000 say?
It lists what a Certifying Authority must certify when it issues a Digital Signature Certificate. These cover its compliance with the Act, publication and acceptance, the subscriber's key pair, accuracy of the information, and no knowledge of adverse material facts.
How do I get a Digital Signature Certificate?
You apply to a licensed Certifying Authority in the prescribed form, with the prescribed fee and a certification practice statement or the statement required by regulations. The Authority makes enquiries and then grants the certificate, or rejects it for written reasons after giving you a chance to show cause.
Is the fee for a certificate fixed in the Act?
The Act sets only a ceiling: the fee must not exceed ₹25,000. The Central Government prescribes the actual fee and may set different fees for different classes of applicants.
Who gives the representations under Section 36?
The Certifying Authority gives them at the time of issuing the certificate. The subscriber gives separate certifications when accepting the certificate under Section 41.