Sections 17 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Chapter VI of the Information Technology Act, 2000 regulates Certifying Authorities, the bodies that issue electronic signature certificates. Section 17 provides for the appointment of a Controller and other officers, section 18 lists the Controller's functions, and section 19 allows recognition of foreign Certifying Authorities. Section 20 is omitted in the copy.
The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities, with Deputy Controllers, Assistant Controllers and other staff (s.17). The Controller may perform all or any of fourteen listed functions, from supervising Certifying Authorities to maintaining a public disclosure database (s.18). With the previous approval of the Central Government, he may recognize a foreign Certifying Authority by notification, and the certificates it issues are then valid for the purposes of the Act (s.19).
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of these sections should be checked. Section 20 ("Controller to act as repository") is printed in the copy as omitted by the Information Technology (Amendment) Act, 2008 (10 of 2009), section 13 (w.e.f. 27-10-2009). If you run or plan to run a certifying service, or rely on a foreign certificate, a legal consultation can map your position to Chapter VI.
Section 17: appointment of the Controller and officers
| Sub-section | What it says |
|---|---|
| (1) | The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of the Act, and may by the same or a subsequent notification appoint such number of Deputy Controllers, Assistant Controllers, other officers and employees as it deems fit |
| (2) | The Controller discharges his functions subject to the general control and directions of the Central Government |
| (3) | Deputy Controllers and Assistant Controllers perform the functions assigned to them by the Controller, under his general superintendence and control |
| (4) | Qualifications, experience and terms and conditions of service of the Controller, Deputy Controllers, Assistant Controllers, other officers and employees are such as may be prescribed by the Central Government |
| (5) | The Head Office and Branch Office of the office of the Controller are at such places as the Central Government may specify, and may be established at such places as it thinks fit |
| (6) | There shall be a seal of the Office of the Controller |
"Controller" is defined in section 2(1)(m) as the Controller of Certifying Authorities appointed under sub-section (1) of section 17. See our article on section 2: digital signature, certifying authority and key pair. The qualifications and terms of service are left to rules that are not in the sources used here.
Section 18: functions of the Controller
Section 18 says the Controller "may perform all or any of the following functions". The use of "may" means the list is permissive; he is not required to perform all of them.
| Clause | Function as printed |
|---|---|
| (a) | exercising supervision over the activities of the Certifying Authorities |
| (b) | certifying public keys of the Certifying Authorities |
| (c) | laying down the standards to be maintained by the Certifying Authorities |
| (d) | specifying the qualifications and experience which employees of the Certifying Authorities should possess |
| (e) | specifying the conditions subject to which the Certifying Authorities shall conduct their business |
| (f) | specifying the contents of written, printed or visual materials and advertisements that may be distributed or used in respect of an Electronic Signature Certificate and the public key |
| (g) | specifying the form and content of an Electronic Signature Certificate and the key |
| (h) | specifying the form and manner in which accounts shall be maintained by the Certifying Authorities |
| (i) | specifying the terms and conditions subject to which auditors may be appointed and the remuneration to be paid to them |
| (j) | facilitating the establishment of any electronic system by a Certifying Authority either solely or jointly with other Certifying Authorities and regulation of such systems |
| (k) | specifying the manner in which the Certifying Authorities shall conduct their dealings with the subscribers |
| (l) | resolving any conflict of interests between the Certifying Authorities and the subscribers |
| (m) | laying down the duties of the Certifying Authorities |
| (n) | maintaining a database containing the disclosure record of every Certifying Authority containing such particulars as may be specified by regulations, which shall be accessible to public |
Grouping the functions
- Supervision and standards: (a), (c), (d), (e), (m).
- Public keys and certificates: (b), (f), (g).
- Accounts and audit: (h), (i).
- Systems: (j).
- Subscribers: (k), (l).
- Transparency: (n) the public database; the particulars are "as may be specified by regulations", and the regulations are not in the sources used here.
The text does not say how any function is carried out or by which instrument. It lists subjects on which the Controller may specify or lay down matters.
Section 19: recognition of foreign Certifying Authorities
- Sub-section (1): subject to such conditions and restrictions as may be specified by regulations, the Controller may, with the previous approval of the Central Government, and by notification in the Official Gazette, recognize any foreign Certifying Authority as a Certifying Authority for the purposes of the Act.
- Sub-section (2): where a Certifying Authority is so recognized, "the Electronic Signature Certificate issued by such Certifying Authority shall be valid for the purposes of this Act".
- Sub-section (3): the Controller may, if satisfied that a recognized Certifying Authority has contravened any of the conditions and restrictions subject to which it was granted recognition, "for reasons to be recorded in writing, by notification in the Official Gazette, revoke such recognition".
Note the three safeguards in the text: previous approval of the Central Government, notification in the Official Gazette, and reasons recorded in writing before revocation. Printing slip: sub-section (3) ends with a stray "1" after "recognition" in the copy; we have not treated it as part of the text.
Section 20: omitted
Section 20 is shown as omitted in the copy, as stated above, and is not described here.
A worked example
Pinnacle Trust Services Private Limited wants to offer electronic signature certificates in India. It must deal with the Controller under Chapter VI; the licence process is in sections 21 to 24 (see our article on licence to issue electronic signature certificates). The Controller may specify the contents of its advertisements about certificates under clause (f), the form and content of the certificate under clause (g) and the way it deals with subscribers under clause (k). Separately, if an overseas body that issues certificates is to have its certificates valid under the Act, the Controller must, with the previous approval of the Central Government, recognize it by notification; the Act's words are that the certificate issued by such a recognized Certifying Authority "shall be valid for the purposes of this Act". A business relying on a foreign certificate should check the notification before relying on it. Practical guides to getting a certificate are in our posts on DSC for MCA filing and how to get a Digital Signature Certificate.
Need help with Certifying Authority regulation?
If you issue, rely on or audit electronic signature certificates, we can read the Controller's role and the recognition provisions against your arrangement. Reach out for a legal consultation before you commit to a certificate source.
Key takeaways
- The Central Government appoints the Controller and other officers by notification.
- The Controller acts under the general control and directions of the Central Government.
- Section 18 lists fourteen functions, each performable "all or any".
- Foreign Certifying Authorities can be recognized only with the previous approval of the Central Government, by notification.
- Section 20 is omitted in the copy.
Read next
- Sections 21 to 24: licence to issue electronic signature certificates
- Sections 25 to 27: suspension and revocation of Certifying Authority licence
- Sections 14 to 16: secure electronic record and secure electronic signature
- Digital Signature Certificate (DSC): how to get, renew and use
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
