Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)
Section 63 Certificate Complete Note
The Section 63 Certificate under the Bharatiya Sakshya Adhiniyam, 2023: A Complete Note on the Schedule, the Hash Value and Part B
The certificate under Section 63(4) is the single most litigated document in Indian evidence practice. It is short, it is prescribed in a Schedule, and its absence renders an electronic record inadmissible. The Adhiniyam has made two changes to it that had no counterpart in the earlier law — the hash value in Part A and the expert declaration in Part B — and the Supreme Court upheld both in 2026 while settling the question of who may sign.
1. The Requirement
Section 63(4), BSA In any proceeding where it is desired to give a statement in evidence by virtue of this section, a certificate doing any of the following things shall be submitted along with the electronic record at each instance where it is being submitted for admission, namely — (a) identifying the electronic record containing the statement and describing the manner in which it was produced; (b) giving such particulars of any device involved in the production of that electronic record as may be appropriate for the purpose of showing that the electronic record was produced by a computer or a communication device; (c) dealing with any of the matters to which the conditions mentioned in sub-section (2) relate, and purporting to be signed by a person in charge of the computer or communication device or the management of the relevant activities (whichever is appropriate) and an expert shall be evidence of any matter stated in the certificate; and it shall be sufficient for a matter to be stated to the best of the knowledge and belief of the person stating it, and in the certificate specified in the Schedule. |
Three requirements are contained in this. The certificate must say the things in clauses (a) to (c). It must be signed by a person in charge and an expert. And it must be in the form specified in the Schedule.
2. The Schedule
The Schedule prescribes the form of the certificate and divides it into two Parts, each completed by a different person. The division is new; Section 65B(4) of the Indian Evidence Act prescribed no form at all and required one signature.
2.1 Part A — the party or person in charge
Part A is completed by the party producing the record or by the person in charge of the computer or communication device. It covers, in substance —
- Identification of the electronic record, including what it is and where it came from.
- The manner in which it was produced — how the output was generated from the device or system.
- Particulars of the device involved in the production, sufficient to show that the record was produced by a computer or communication device.
- The matters to which the conditions in Section 63(2) relate — regular use, regular feeding of information, proper operation, and derivation.
- The hash value of the electronic record, obtained through one of the specified algorithms.
2.2 Part B — the expert
Part B carries the declaration of the expert, recording his examination of the record and his statement in relation to the matters the sub-section requires. It is the new element, and it is what converts the certificate from an administrative document into one requiring technical verification.
3. The Hash Value
The requirement to disclose a hash value in Part A is the most technically significant feature of the Schedule, and it is worth understanding why it was included.
A cryptographic hash is a fixed-length digest computed from a file. Two properties matter for evidentiary purposes. The same input always produces the same digest, so a record can be re-verified at any time. And any alteration to the input, however small — a single character, a single bit — produces an entirely different digest, so alteration cannot be concealed.
The Schedule specifies the algorithms by which the hash is to be obtained, and the ones named are the standard families in use — SHA-1, SHA-256 and MD5. Where more than one is available, the stronger should be used, and SHA-256 is the current practical standard.
⚠ The hash must be computed early, and it cannot be supplied afterwards A hash computed at the time of seizure or forensic imaging proves that the record tendered in court is identical to the record as it existed then. A hash computed at the time of tendering proves only that the record has not changed since the party decided to produce it, which establishes nothing about the intervening period. Where no hash was taken at the earliest opportunity, the objection that the record may have been altered cannot be answered at all. This is a matter of investigative and litigation practice rather than of law, and it decides cases. |
The practical consequence is that the hash should be computed and recorded at the first possible moment — when a device is seized, when a forensic image is made, when a record is downloaded from a service provider, or when a party first takes a copy for the purposes of litigation. It should be recorded in the seizure memo, the panchnama or the file note, so that its provenance is established independently of the certificate.
4. Who Signs
Section 63(4) requires two signatures, and the identity of each has been the subject of argument.
4.1 Part A — the person in charge
The sub-section speaks of a person in charge of the computer or communication device, or of the management of the relevant activities, 'whichever is appropriate'. The alternative matters: where a record comes from an organisational system, the person in charge of the activity may be better placed to certify than a technician, and where it comes from a single device, the reverse.
The statement may be made to the best of the knowledge and belief of the person signing. He need not have personal knowledge of every matter, and the sub-section expressly permits belief. This is a practical concession without which large organisational systems could rarely be certified at all.
4.2 Part B — the expert
The addition of an expert signature raised an immediate practical problem. If the expert had to be an Examiner of Electronic Evidence notified under Section 79A of the Information Technology Act, 2000, the requirement would be unworkable, because very few such Examiners have been notified relative to the volume of electronic evidence tendered. The point was taken to the Supreme Court.
📖 Pune Bar Assn. v. Union of India, 2026 SCC OnLine SC 1297 (decided 22 May 2026) Facts: A writ petition challenged the constitutional validity of Section 63(4) read with the Schedule, contending that the requirements of a hash value in Part A and a signed expert declaration in Part B made electronic evidence practically unavailable to ordinary litigants, particularly if Part B could be signed only by a notified Examiner of Electronic Evidence. Held: A three-Judge Bench (Surya Kant, CJI, Joymalya Bagchi and Vipul M. Pancholi, JJ.) upheld the provision. Electronic records are a species of evidence liable to continuous mutation, and the requirements of hash-value disclosure and expert certification bear a rational nexus with the object of securing authenticity and integrity. Reading Sections 39(1) and 39(2) harmoniously, the Court held that the expert who signs Part B is not confined to an Examiner of Electronic Evidence notified under Section 79A. Any person possessing special skill and expertise in computer science or cyber forensics may sign, provided the court is satisfied of the credentials on unimpeachable material. The contrary view of the Madras High Court in R. v. B. was held not to operate as binding precedent, and the question of the scope of Part B certification was expressly left open. Ratio: The certificate regime is constitutionally valid, and the class of persons competent to sign Part B is considerably wider than the text alone suggests. |
The reasoning is that Section 39(2) confers a status on the notified Examiner rather than an exclusive licence, and that the residuary words 'or in any other field' in Section 39(1) keep the general expert category open. Cyber forensics is plainly such a field, and a person skilled in it is an expert whether or not his employer holds a notification.
Two consequences follow for practice. A party may retain a competent cyber forensic examiner and rely on his signature. But the credentials must be established on unimpeachable material, which means the expert's qualifications, training and experience should be proved rather than assumed, and he should be available to be examined about them.
5. When the Certificate Is Not Required
The certificate is required where the record is tendered otherwise than as primary evidence. Two situations therefore fall outside it, and they cover a great deal of ground.
5.1 The original device is produced
📖 Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 Held: A three-Judge Bench restored and clarified Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473. The certificate is mandatory where secondary electronic evidence is relied upon, but is not required where the original device is itself produced by its owner. Where a party is unable to obtain the certificate because the device is in the control of another, the court may compel its production. Shafhi Mohammad v. State of H.P., (2018) 2 SCC 801 was held not to be good law, and Tomaso Bruno v. State of U.P., (2015) 7 SCC 178 was declared per incuriam. Ratio: Production of the original device dispenses with the certificate, and a party unable to obtain one through no fault of his own has a remedy in an application to compel production. |
5.2 The Explanations to Section 57
The Adhiniyam goes further than the decision by deeming certain outputs to be primary evidence.
- Explanation 3 — a record stored simultaneously or sequentially in multiple files: each file is primary evidence.
- Explanation 4 — a record produced from proper custody: primary evidence unless it is disputed.
- Explanation 5 — a video recording simultaneously stored and transmitted or broadcast: each stored recording is primary evidence.
- Explanation 6 — a record in multiple storage spaces, including temporary files: each automated storage is primary evidence.
⚠ Do not rely on Explanation 4 alone A record from proper custody is primary evidence unless it is disputed, and whether it is disputed depends entirely on what the other side pleads. A party cannot know at the time of tendering whether the Explanation will avail him. Obtain the certificate in any event where the record matters, and treat Explanation 4 as an additional argument rather than the principal one. The cost of obtaining a certificate that turns out to be unnecessary is trivial compared with the cost of not having one that turns out to be essential. |
6. Timing and Defects
6.1 When the certificate must be furnished
Section 63(4) requires the certificate to be submitted along with the electronic record at each instance where it is being submitted for admission. The words are new — Section 65B(4) said nothing about timing — and they settle a question that had produced argument.
Two propositions follow. The certificate accompanies the record at the time of tender, not afterwards. And where the same record is tendered on more than one occasion, a certificate is required on each occasion.
6.2 A defective certificate
Where a certificate is furnished but is defective — a signature missing, a hash value omitted, a Part left incomplete, a particular of the device not given — the position depends on how the objection is characterised.
A certificate that is wholly absent is an objection going to admissibility, and under Anvar P.V. and Arjun Panditrao the record cannot be received at all. A certificate that is present but imperfect is more naturally an objection to the mode of proof, and on the authority of R.V.E. Venkatachala Gounder v. Arulmigu Viswesaraswami and V.P. Temple, (2003) 8 SCC 752, such an objection must be taken when the document is tendered so that the defect can be cured, and is waived if not taken then.
The practical advice runs in both directions. A party tendering a record should treat any defect as fatal and cure it before tender. A party objecting should take the point at tender, identifying precisely what is missing, so that the record is marked subject to the objection and the point is preserved.
6.3 Where the certificate cannot be obtained
Arjun Panditrao holds that where a party is genuinely unable to obtain the certificate because the device or the system is in the control of another — a service provider, an opposing party, a public authority — the court may compel its production. The remedy is an application, made in good time, identifying the person who can certify and the material sought.
What the decision does not permit is a party simply asserting that a certificate was unobtainable and asking the court to dispense with it. The inability must be established, and the party must have taken the steps available to him.
7. What the Certificate Establishes — and What It Does Not
The certificate is frequently treated as though it settled the whole question of electronic evidence. It settles one question only.
What it establishes is that the computer output tendered corresponds to the information in the device, and that the system from which it came satisfied the four conditions in Section 63(2). It answers the objection that the printout may not reflect what was actually in the record.
It does not establish that the contents are true. The output is admissible as evidence of a fact only where direct evidence of that fact would have been admissible — the closing words of Section 63(1). A statement in a record that would be hearsay from a witness does not cease to be hearsay because it is in a computer output. It becomes evidence of its truth only where a provision makes it so, most commonly as an admission under Section 15.
It does not establish attribution. That a message was sent from an account or a device is one thing; who was operating it is another entirely. No provision addresses this, and it remains the largest gap in electronic evidence cases.
It does not answer questions of interpretation or completeness. What a fragment means, and whether enough has been produced for its meaning to be understood, are matters for expert opinion under Section 39(2) and for Section 33. A certified record may still be worthless because it cannot be placed in context.
8. A Practical Checklist
- Determine first whether a certificate is needed — check the Explanations to Section 57 and whether the original device can be produced.
- Compute and record the hash at the earliest moment, and record it in the seizure memo, panchnama or file note so its provenance is independent of the certificate.
- Use the stronger algorithm where a choice exists among those the Schedule specifies.
- Identify who is in charge of the device or the relevant activities, and confirm that person can speak to the four conditions to the best of his knowledge and belief.
- Identify the expert for Part B, and prepare to prove his credentials on unimpeachable material — qualifications, training, experience and method.
- Complete both Parts fully. An incomplete Part invites an objection that need never have arisen.
- Submit the certificate with the record at each tender, as the sub-section requires.
- Where the device is with another, apply early to compel production rather than assert that a certificate is unobtainable.
9. The Position Stated Shortly
- The certificate is required where the record is not primary evidence, and its absence renders the record inadmissible.
- The Schedule prescribes the form, in two Parts — Part A by the party or person in charge, disclosing the hash value; Part B by an expert.
- Both requirements are new. Section 65B(4) prescribed no form, required one signature, and said nothing about a hash.
- The hash value must be computed early, at seizure or imaging, and cannot usefully be supplied at the stage of tendering.
- The expert need not be a notified Examiner under Section 79A of the IT Act — Pune Bar Assn. — but the credentials must rest on unimpeachable material.
- The certificate must accompany the record at each instance of tender.
- No certificate is required where the output is primary evidence under an Explanation to Section 57, or where the original device is produced — Arjun Panditrao.
- The certificate does not prove truth, attribution, completeness or meaning, and each of those must be established separately.
10. Related Topics and Provisions
Topic or provision | Connection |
|---|---|
Electronic and Digital Evidence — Sections 61 to 63 | The combined treatment and the line of authority |
Conditions for Admissibility of Computer Output | Section 63(2), which the certificate deals with in Part A |
Electronic or Digital Record as Primary Evidence | The Explanations to Section 57, which determine whether a certificate is needed |
Opinion of the Examiner of Electronic Evidence | Section 39(2), and who may sign Part B |
Forensic Evidence | Forensic imaging, hash verification and chain of custody |
Section 33, BSA | How much of a record must be produced for its meaning to be understood |
Section 15, BSA | Admissions contained in electronic form |
Section 79A, Information Technology Act, 2000 | Examiner of Electronic Evidence |