September 13, 2026

Second Schedule. Electronic Signature or Electronic Authentication Technique and Procedure – Information Technology Act, 2000

Schedules
Information Technology Act, 2000

The Second Schedule

[See sub-section (1) of section 3A]

Electronic Signature or Electronic Authentication Technique and Procedure

1. e-authentication technique using Aadhaar or other e-KYC services

Authentication of an electronic record by e-authentication Technique which shall be done by–(a) the applicable use of e-authentication, hash, and asymmetric crypto system techniques, leading to issuance of Digital Signature Certificate by Certifying Authority; (b) a trusted third party service by subscriber’s key pair-generation, storing of key pairs and creation of digital signature provided that the trusted third party shall be offered by the certifying authority; the trusted third party shall send application form and certificate signing request to the Certifying Authority for issuing a Digital Signature Certificate to the subscriber; (c) issuance of Digital Signature Certificate by Certifying Authority shall be based on e-authentication, particulars specified in Form C of Schedule IV of the Information Technology (Certifying Authorities) Rules, 2000, digitally signed verified information from Aadhaar or other e-KYC services and electronic consent of Digital Signature Certificate applicant; (d) the manner and requirements for e-authentication shall be as issued by the Controller from time to time; (e) the security procedure for creating the subscriber’s key pair and other e-KYC services shall be in accordance with the e-authentication guidelines issued by the Controller; (f) the standards referred to in Rule 6 of the Information Technology (Certifying Authorities) Rules, 2000 shall be complied with, in so far as they relate to the certification function of public key of Digital Signature Certificate applicant; (g) the manner in which the information is authenticated by means of digital signature shall comply with the manner and standards specified in Rules 3 to 12 of the Digital Signature (End entity) Rules, 2015 in so far as they relate to the creation, storage, and verification of Digital Signature.

2. e-authentication technique and procedure for creating and accessing subscriber’s signature key facilitated by trusted third party

Authentication of an electronic record by e-authentication technique which shall be done by–(a) the applicable use of e-authentication, hash and asymmetric crypto system techniques leading to issuance of Digital Signature Certificate by Certifying Authority, provided that Certifying Authority shall ensure the subscriber identity verification, secure storage of the keys by trusted third party and subscriber’s sole authentication control to the signature key; (b) identity verification of Digital Signature Certificate applicant shall be in accordance with the Identity Verification Guidelines issued by Controller from time-to-time; (c) the requirement to operate as trusted third party shall be specified under e-authentication guidelines issued by the Controller; (d) a trusted third party shall (i) facilitate identity verification of Digital Signature Certificate applicant; (ii) establish secure storage for subscriber to have sole control for creation and subsequent usage of subscriber’s signature key by sole authentication of subscriber; (iii) facilitate key pair-generation, secure storage of subscriber’s signature key and facilitate signature creation functions; (iv) facilitate the submission of DSC application form and certificate signing request to the Certifying Authority for issuing a Digital Signature Certificate to the DSC applicant; and (v) facilitate revocation of Digital Signature Certificate and destruction of subscriber’s signature key; (e) the manner and requirements for authentication and storage of keys shall be as issued by the Controller from time to time under e-authentication guidelines; (g) the security procedure for creating the subscriber’s key pair shall be in accordance with the e-authentication guidelines issued by the Controller; (h) the standards referred to in Rule 6 of the Information Technology (Certifying Authorities) Rules, 2000 shall be complied with, in so far as they relate to the certification function of public key of Digital Signature Certificate applicant; (i) the manner in which information is authenticated by means of digital signature shall comply with the manner and standards specified in Rule 3 to 12 of Digital Signature (End entity) Rules, 2015 in so far as they relate to the creation, storage and verification of Digital Signature.