Information Technology Act, 2000
Controller (CCA) vs Certifying Authority: The Difference Explained
The digital-trust hierarchy has two tiers that are easily conflated: the Controller sits at the apex as regulator and root of trust, and the Certifying Authorities operate beneath it, licensed to issue the certificates ordinary subscribers actually hold. Topics 49 to 51 built both; this note, as asked, is the dedicated comparison.
1. Regulator and Regulated
Figure 1: The apex office against the licensed entity
- The Controller (CCA). The regulator, appointed under ss.17 to 20: it licenses and supervises Certifying Authorities, lays down standards and the e-authentication guidelines, maintains the database of CAs and their public keys, and holds the Root Certifying Authority of India (RCAI) at the apex of the trust hierarchy (Topic 49)
- The Certifying Authority (CA). The regulated entity, licensed under ss.21 to 24: it issues Digital Signature Certificates to subscribers, verifies their identity, publishes a certification practice statement, maintains a repository and manages suspension and revocation of the certificates it issued (Topics 50, 51)
- The trust chain. RCAI signs the CA's certificate; the CA signs the subscriber's certificate: verification of any signature climbs this chain, subscriber to CA to RCAI to Controller, so the Controller is the root the whole system trusts.
2. The Division of Function
- Licensing against issuance. The Controller licenses CAs and can suspend or revoke a licence (ss.21 to 26); the CA issues, suspends and revokes certificates for subscribers (ss.35 to 39), so licensing is the Controller's power and certification the CA's (Topic 51)
- Standards against practice. The Controller lays down the standards, the technical and procedural requirements, and the e-authentication guidelines; the CA follows them in practice, keeping its CPS and repository to the prescribed norms (Topic 135)
- Scale and supervision. There is one Controller, a national office, and several licensed CAs beneath it; the Controller's supervisory audit and the recognition of foreign CAs under s.19 complete its oversight role.
- Liability and recourse. A subscriber's certificate comes from a CA, so disputes over issuance and revocation lie against the CA, with the Controller as the supervisory and standard-setting authority above it.
⚠ Exam trap Fix the tiers: the Controller is the regulator under ss.17 to 20 holding RCAI, the Certifying Authority is the licensed entity under ss.21 to 34 issuing Digital Signature Certificates, so the Controller licenses and the CA certifies. Describe the trust chain in order, RCAI signs the CA, the CA signs the subscriber, verification climbs back up, and do not say the Controller issues certificates to the public, which is the CA's function, or that a CA licenses others, which is the Controller's. |
3. Frequently Asked Questions
What is the difference between the Controller and a Certifying Authority?
The Controller of Certifying Authorities, appointed under Sections 17 to 20, is the regulator: it licenses and supervises Certifying Authorities, lays down standards and the e-authentication guidelines, and holds the Root Certifying Authority of India at the apex of the trust hierarchy. A Certifying Authority, licensed under Sections 21 to 24, is the regulated entity that issues Digital Signature Certificates to subscribers, verifies their identity, and manages suspension and revocation. The Controller licenses; the CA certifies; and verification of a signature climbs the trust chain from subscriber to CA to the Controller's root.
4. Related Topics
- Topic 49: Controller of Certifying Authorities. The Controller's office in full.
- Topic 50: Licensing of Certifying Authorities. The CA licensing scheme.