Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

Sections 17–19 of the Information Technology Act, 2000: Controller of Certifying Authorities, appointment and functions

The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities, with Deputy Controllers, Assistant Controllers and other staff...

Published
Updated
Reading time
8 min
Views
3
Questions
6 answered
  • Expert Reviewed
  • High Complexity
  • In-Depth Guide
Topic
Cyber & Data Protection
Published
October 2, 2026
Last updated
Oct 8, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Chapter VI of the Information Technology Act, 2000 regulates Certifying Authorities, the bodies that issue electronic signature certificates. Section 17 provides for the appointment of a Controller and other officers, section 18 lists the Controller's functions, and section 19 allows recognition of foreign Certifying Authorities. Section 20 is omitted in the copy.

Source and scope

This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of these sections should be checked. Section 20 ("Controller to act as repository") is printed in the copy as omitted by the Information Technology (Amendment) Act, 2008 (10 of 2009), section 13 (w.e.f. 27-10-2009). If you run or plan to run a certifying service, or rely on a foreign certificate, a legal consultation can map your position to Chapter VI.

Section 17: appointment of the Controller and officers

Sub-sectionWhat it says
(1)The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of the Act, and may by the same or a subsequent notification appoint such number of Deputy Controllers, Assistant Controllers, other officers and employees as it deems fit
(2)The Controller discharges his functions subject to the general control and directions of the Central Government
(3)Deputy Controllers and Assistant Controllers perform the functions assigned to them by the Controller, under his general superintendence and control
(4)Qualifications, experience and terms and conditions of service of the Controller, Deputy Controllers, Assistant Controllers, other officers and employees are such as may be prescribed by the Central Government
(5)The Head Office and Branch Office of the office of the Controller are at such places as the Central Government may specify, and may be established at such places as it thinks fit
(6)There shall be a seal of the Office of the Controller

"Controller" is defined in section 2(1)(m) as the Controller of Certifying Authorities appointed under sub-section (1) of section 17. See our article on section 2: digital signature, certifying authority and key pair. The qualifications and terms of service are left to rules that are not in the sources used here.

Section 18: functions of the Controller

Section 18 says the Controller "may perform all or any of the following functions". The use of "may" means the list is permissive; he is not required to perform all of them.

ClauseFunction as printed
(a)exercising supervision over the activities of the Certifying Authorities
(b)certifying public keys of the Certifying Authorities
(c)laying down the standards to be maintained by the Certifying Authorities
(d)specifying the qualifications and experience which employees of the Certifying Authorities should possess
(e)specifying the conditions subject to which the Certifying Authorities shall conduct their business
(f)specifying the contents of written, printed or visual materials and advertisements that may be distributed or used in respect of an Electronic Signature Certificate and the public key
(g)specifying the form and content of an Electronic Signature Certificate and the key
(h)specifying the form and manner in which accounts shall be maintained by the Certifying Authorities
(i)specifying the terms and conditions subject to which auditors may be appointed and the remuneration to be paid to them
(j)facilitating the establishment of any electronic system by a Certifying Authority either solely or jointly with other Certifying Authorities and regulation of such systems
(k)specifying the manner in which the Certifying Authorities shall conduct their dealings with the subscribers
(l)resolving any conflict of interests between the Certifying Authorities and the subscribers
(m)laying down the duties of the Certifying Authorities
(n)maintaining a database containing the disclosure record of every Certifying Authority containing such particulars as may be specified by regulations, which shall be accessible to public

Grouping the functions

  • Supervision and standards: (a), (c), (d), (e), (m).
  • Public keys and certificates: (b), (f), (g).
  • Accounts and audit: (h), (i).
  • Systems: (j).
  • Subscribers: (k), (l).
  • Transparency: (n) the public database; the particulars are "as may be specified by regulations", and the regulations are not in the sources used here.

The text does not say how any function is carried out or by which instrument. It lists subjects on which the Controller may specify or lay down matters.

Section 19: recognition of foreign Certifying Authorities

  • Sub-section (1): subject to such conditions and restrictions as may be specified by regulations, the Controller may, with the previous approval of the Central Government, and by notification in the Official Gazette, recognize any foreign Certifying Authority as a Certifying Authority for the purposes of the Act.
  • Sub-section (2): where a Certifying Authority is so recognized, "the Electronic Signature Certificate issued by such Certifying Authority shall be valid for the purposes of this Act".
  • Sub-section (3): the Controller may, if satisfied that a recognized Certifying Authority has contravened any of the conditions and restrictions subject to which it was granted recognition, "for reasons to be recorded in writing, by notification in the Official Gazette, revoke such recognition".

Note the three safeguards in the text: previous approval of the Central Government, notification in the Official Gazette, and reasons recorded in writing before revocation. Printing slip: sub-section (3) ends with a stray "1" after "recognition" in the copy; we have not treated it as part of the text.

Section 20: omitted

Section 20 is shown as omitted in the copy, as stated above, and is not described here.

A worked example

Pinnacle Trust Services Private Limited wants to offer electronic signature certificates in India. It must deal with the Controller under Chapter VI; the licence process is in sections 21 to 24 (see our article on licence to issue electronic signature certificates). The Controller may specify the contents of its advertisements about certificates under clause (f), the form and content of the certificate under clause (g) and the way it deals with subscribers under clause (k). Separately, if an overseas body that issues certificates is to have its certificates valid under the Act, the Controller must, with the previous approval of the Central Government, recognize it by notification; the Act's words are that the certificate issued by such a recognized Certifying Authority "shall be valid for the purposes of this Act". A business relying on a foreign certificate should check the notification before relying on it. Practical guides to getting a certificate are in our posts on DSC for MCA filing and how to get a Digital Signature Certificate.

Need help with Certifying Authority regulation?

If you issue, rely on or audit electronic signature certificates, we can read the Controller's role and the recognition provisions against your arrangement. Reach out for a legal consultation before you commit to a certificate source.

Key takeaways

  • The Central Government appoints the Controller and other officers by notification.
  • The Controller acts under the general control and directions of the Central Government.
  • Section 18 lists fourteen functions, each performable "all or any".
  • Foreign Certifying Authorities can be recognized only with the previous approval of the Central Government, by notification.
  • Section 20 is omitted in the copy.

Read next

Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Sections 17

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who appoints the Controller of Certifying Authorities?

The Central Government, by notification in the Official Gazette (section 17(1)).

What does the Controller do?

Section 18 lists fourteen functions he may perform, including supervising Certifying Authorities, certifying their public keys, laying down standards and keeping a public database of disclosure records.

Keep the acknowledgement. A filing you cannot prove is a filing you may have to defend.

— TaxClue Compliance Desk

Sections 17: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

The Central Government, by notification in the Official Gazette (section 17(1)).

Section 18 lists fourteen functions he may perform, including supervising Certifying Authorities, certifying their public keys, laying down standards and keeping a public database of disclosure records.

Section 17(2) says the Controller discharges his functions subject to the general control and directions of the Central Government.

Yes, under section 19(1), by the Controller with the previous approval of the Central Government and by notification in the Official Gazette, subject to conditions and restrictions specified by regulations.

Under section 19(3), if the Controller is satisfied that a condition or restriction was contravened, he may, for reasons recorded in writing and by notification, revoke it.

It is printed in the copy as omitted by the Information Technology (Amendment) Act, 2008 (10 of 2009), section 13 (w.e.f. 27-10-2009).