What is a Class 3 Digital Signature Certificate?
A Class 3 Digital Signature Certificate (DSC) is the highest class of cryptographic verification issued under the guidelines of the Controller of Certifying Authorities (CCA), Ministry of Electronics and Information Technology, India. Governed by the Information Technology Act 2000, a Class 3 DSC provides high-assurance security, verifying the authenticity, non-repudiation, and integrity of electronic document submissions. It is mandatory for most online regulatory filings on ICEGATE and DGFT portals for importers and exporters.
Why Your Business Needs a Class 3 DSC
For businesses engaged in international trade, a Class 3 DSC is mandatory for most online regulatory platforms. It is required to file import/export declarations such as bills of entry and shipping bills on ICEGATE, submit licensing requests on the DGFT portal, apply for electronic Registration-cum-Membership Certificates (e-RCMC), and register bank AD Codes at customs ports.
⚠️ The Class 3 DSC Combo Requirement for customs
Standard registrations on the DGFT portal can be executed using a basic Signature certificate. However, registering and mapping bank AD Codes or uploading EDI document filings on the ICEGATE customs portal requires a Class 3 Combo Certificate (which contains both individual Signature and Encryption components stored on a FIPS-compliant USB hardware token).
Signature vs Encryption vs Combo: Which Do You Need?
| Certificate Type | Purpose | Required For |
|---|---|---|
| Signature | Authenticates identity and legally signs documents | DGFT filings, e-RCMC, standard registrations |
| Encryption | Secures sensitive data files before transmission | Encrypted email and data exchange |
| Combo (Recommended) | Both Signature + Encryption on one token | ICEGATE EDI filings, AD Code mapping, full customs clearance |
Certified USB Hardware Cryptographic Tokens
Under CCA security guidelines, digital certificates cannot be downloaded directly as local files onto a computer. Instead, they must be securely stored on password-protected, FIPS-compliant USB hardware tokens (such as ePass2003, mToken, or ProxKey). This physical layer of security prevents unauthorized users from copying or exporting your private keys, protecting your business from transaction fraud.
CCA-Licensed Certifying Authorities We Work With
Class 3 DSCs are issued exclusively by Certifying Authorities licensed by the Controller of Certifying Authorities (CCA), Government of India. As an authorized partner, we procure certificates from the following trusted CAs:
All CAs listed above are licensed by the Controller of Certifying Authorities (CCA), Government of India. View the official CCA licensed CA list.
Procurement and Port-Mapping Process: Step-by-Step
Obtaining and mapping a digital signature involves precise identity verification and software configuration. We assist your trade teams through the process:
Profile Selection & Document Assembly
We analyze your business model to determine whether an Organizational or Individual Class 3 Combo certificate is required, and assemble your corporate registration documents.
Video & OTP Verification Coordination
We guide your authorized signatory through the mandatory mobile OTP and secure 30-second video verification processes required by licensed Certifying Authorities (CAs).
Hardware Token Loading
Once identity verification is complete and approved by the CA, we load the cryptographic keys onto a certified USB hardware crypto-token.
ICEGATE & DGFT PKI Mapping
We configure the necessary browser drivers and run the required Java PKI utilities to register and map your physical USB token inside your corporate ICEGATE and DGFT user profiles.
Required Document Checklist
- PAN card copy of the applicant (authorized signatory).
- Aadhaar Card copy or valid passport/voter ID for address verification.
- For Organizational DSC: Company PAN, Certificate of Incorporation, Board Resolution, or official Authorization Letter.
- An active, linked mobile number and corporate email address for verification.
- FIPS-compliant USB hardware crypto-token (such as ePass2003).