All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Licensing of Certifying Authorities: Sections 21 to 34 IT Act

Certificates are trusted because the businesses that issue them are licensed, inspected and, when they fail, shut down. Sections 21 to 34 contain that machinery: who may become a Certifying Authority, how the licence is obtained, renewed, suspended, revoked and surrendered, what the CA must do while it operates, and what powers the Controller has to investigate and enter its systems. Topic 49 covered the Controller's office; this note follows the licence itself through its whole life.

1. The Licence Follows the Trust

A bank is trusted with deposits because a licence stands behind it, and behind the licence stands a regulator who checked the promoters, audits the books, can send inspectors in, and can shut the counter. Chapter VI builds the same cage for the businesses that issue signature certificates. Read it as one story: getting the licence (ss.21 to 24), losing it (ss.25, 26, 33), being watched (ss.27 to 29), and living by its terms (ss.30 to 32, 34).

The life of a Certifying Authority licence

Figure 1: The life of a Certifying Authority licence

2. Getting the Licence: Sections 21 to 24

Section 21, Information Technology Act, 2000 (substance)

(1) Subject to sub-section (2), any person may make an application to the Controller for a licence to issue Electronic Signature Certificates.

(2) No licence shall be issued unless the applicant fulfils such requirements with respect to qualification, expertise, manpower, financial resources and other infrastructure facilities, which are necessary to issue Electronic Signature Certificates, as may be prescribed by the Central Government.

(3) A licence granted under this section shall (a) be valid for such period as may be prescribed; (b) not be transferable or heritable; (c) be subject to such terms and conditions as may be specified by the regulations.

Eligibility and the character of the licence

Figure 2: Eligibility and the character of the licence

  • Eligibility in the rules. The Information Technology (Certifying Authorities) Rules, 2000 prescribe the requirements, including financial capacity, infrastructure and security compliance; the licence runs for the prescribed period and is renewable.
  • Application (s.22). The application must be in the prescribed form and be accompanied by a certification practice statement, a statement including the procedures with respect to identification of the applicant, fees not exceeding ₹25,000 as prescribed, and such other documents as prescribed.
  • Renewal (s.23). An application for renewal must be in the prescribed form with fees not exceeding ₹5,000, and must be made not less than forty-five days before the expiry of the licence.
  • Grant or rejection (s.24). The Controller may, on being satisfied after considering the documents and such other factors as he deems fit, grant the licence or reject the application. Reasonable opportunity before rejection: no application may be rejected unless the applicant has been given a reasonable opportunity of presenting his case.

3. Losing the Licence: Sections 25, 26 and 33

Grounds and safeguards under Section 25

Figure 3: Grounds and safeguards under Section 25

  • Grounds for revocation (s.25(1)). The Controller may revoke a licence if satisfied, after an inquiry, that the CA has (a) made a statement in or in relation to the application which is incorrect or false in material particulars; (b) failed to comply with the terms and conditions of the licence; (c) failed to maintain the procedures and standards specified in Section 30; or (d) contravened any provision of the Act, rule, regulation or order.
  • Hearing before revocation. No licence may be revoked unless the CA has been given a reasonable opportunity of showing cause against the proposed revocation.
  • Suspension (s.25(2)). Pending the inquiry, the Controller may suspend the licence if he has reasonable cause to believe that a ground for revocation exists; but no licence may be suspended for more than ten days unless the CA has been given a reasonable opportunity of showing cause.
  • Effect of suspension (s.25(3)). No Certifying Authority whose licence has been suspended shall issue any Electronic Signature Certificate during the suspension.
  • Notice and publication (s.26). On suspension or revocation, the Controller publishes notice of it in the database maintained by him; the database is made available through a website accessible round the clock, and he may publicise its contents as he considers appropriate. The public must be able to discover that a CA has fallen.
  • Surrender (s.33). A CA whose licence is suspended or revoked must surrender the licence to the Controller immediately. Failure to surrender was an offence punishable with up to six months or ₹10,000; since 30 November 2023 it is a civil penalty of up to ₹5 lakh under the Jan Vishwas Act (see Topic 40)

How the world learns of a suspension or revocation

Figure 4: How the world learns of a suspension or revocation

4. The Controller's Supervisory Powers: Sections 27 to 29

Delegation, investigation and access

Figure 5: Delegation, investigation and access

  • Delegation (s.27). The Controller may, in writing, authorise the Deputy Controller, an Assistant Controller or any officer to exercise any of his powers under Chapter VI.
  • Investigation of contraventions (s.28). The Controller or any authorised officer shall take up for investigation any contravention of the Act, rules or regulations, and for that purpose exercises powers like those conferred on income-tax authorities under Chapter XIII of the Income-tax Act, 1961, subject to prescribed limitations.
  • Access to computers and data (s.29). The Controller or an authorised person shall, on reasonable cause to suspect a contravention of the Chapter, have access to any computer system, apparatus, data or other material connected with it, to search for and obtain any information or data contained in or available to it; and he may, by order, direct any person in charge of or connected with the system to provide reasonable technical and other assistance.
  • Related powers outside this range. Directions to CAs under Section 68 (non-compliance now a penalty of up to ₹25 lakh) and the power to recognise foreign CAs under Section 19 complete the supervisory picture (see Topic 49)

5. Living by the Licence: Sections 30 to 32 and 34

Section 30, Information Technology Act, 2000 (substance)

Every Certifying Authority shall (a) make use of hardware, software and procedures that are secure from intrusion and misuse; (b) provide a reasonable level of reliability in its services which are reasonably suited to the performance of intended functions; (c) adhere to security procedures to ensure that the secrecy and privacy of the electronic signatures are assured; (ca) be the repository of all Electronic Signature Certificates issued under this Act; (cb) publish information regarding its practices, Electronic Signature Certificates and current status of such certificates; and (d) observe such other standards as may be specified by regulations.

Procedures every Certifying Authority must follow

Figure 6: Procedures every Certifying Authority must follow

  • Reliable and secure systems. Clauses (a) to (c) are the operational core: systems secure against intrusion and misuse, services reliable enough for their function, and security procedures assuring the secrecy and privacy of signatures. Clauses (ca) and (cb), added in 2008, make each CA the repository of its certificates and oblige it to publish their current status, which is what relying parties check.
  • Confidentiality and privacy. The secrecy duty in s.30(c) pairs with Section 72, under which disclosure of information obtained under the Act without consent attracts a penalty (civil since 2023), and with the CA's obligations in its CPS.
  • Compliance (s.31). Every CA must ensure that every person employed or otherwise engaged by it complies, in the course of employment or engagement, with the Act, rules, regulations and orders.
  • Display (s.32). Every CA must display its licence at a conspicuous place of the premises in which it carries on business.

Everyday and disclosure duties

Figure 7: Everyday and disclosure duties

  • Disclosure (s.34(1)). Every CA must disclose, in the manner specified by regulations, its own Electronic Signature Certificate containing the public key corresponding to the private key it uses, its certification practice statement, notice of the revocation or suspension of its CA certificate if any, and any other fact that materially and adversely affects either the reliability of its certificates or its ability to perform its services.
  • Duty to notify adverse events (s.34(2)). Where an event has occurred, or a situation has arisen, that may materially and adversely affect the integrity of the CA's computer system or the conditions subject to which a certificate was granted, the CA must use reasonable efforts to notify any person likely to be affected, or act in accordance with the procedure in its CPS.
  • Regulations and rules. The Certifying Authorities Rules, 2000 and the CCA's regulations flesh out audits, security guidelines and the disclosure record; the Controller's database under Section 18(n) mirrors these disclosures for the public.

⚠ Exam trap

Keep the numbers apart: application fee up to ₹25,000 (s.22) and renewal fee up to ₹5,000, applied for at least 45 days before expiry (s.23); suspension of a CA licence beyond ten days needs a hearing (s.25(2)), while suspension of a subscriber's certificate beyond fifteen days needs one (s.37). And remember the pairs of hearings: before rejecting an application (s.24) and before revoking a licence (s.25(1)).

6. Quick Revision and Memory Aids

  • 'Get it, lose it, watched, live by it'. The four movements of ss.21 to 34.
  • 'QEMFI'. Qualification, Expertise, Manpower, Financial resources, Infrastructure (s.21(2))
  • '25,000 to enter, 5,000 to stay, 45 days early'. ss.22 and 23.
  • 'False, breach, s.30, contravention'. Grounds of revocation.
  • 'Ten days for the CA, fifteen for the subscriber'. s.25(2) and s.37.
  • 'Secure, reliable, secret, repository, publish'. Section 30.
  • 'Certificate, CPS, fall, facts'. The four disclosures of s.34(1)

7. Frequently Asked Questions

On what grounds can a Certifying Authority's licence be revoked?

Under Section 25: a materially false or incorrect statement in or about the application, failure to comply with licence terms, failure to maintain the Section 30 procedures and standards, or contravention of the Act, rules, regulations or orders, and only after a reasonable opportunity of showing cause.

What powers does the Controller have to investigate a Certifying Authority?

He may delegate powers to Deputy and Assistant Controllers and officers (s.27), investigate contraventions with income-tax style powers (s.28), and, on reasonable suspicion of a contravention of the Chapter, access the CA's computer systems and data and direct persons connected with them to assist (s.29).

8. Related Topics

  • Topic 49: Controller of Certifying Authorities. The regulator wielding these powers.
  • Topic 51: Electronic Signature Certificates. What licensed CAs issue, suspend and revoke.