Sections 30 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Sections 30 to 34 of the Information Technology Act, 2000 set out what a Certifying Authority must do once it holds a licence: follow secure procedures, make sure its people comply with the law, display its licence, surrender the licence if it is suspended or revoked, and disclose key facts about its certificates and any event that affects them. Section 33(2) carries a consequence for failing to surrender the licence, and that consequence is amended by the Jan Vishwas (Amendment of Provisions) Act, 2023.
A Certifying Authority must use secure hardware, software and procedures, ensure compliance by its staff, display its licence at a conspicuous place, surrender it immediately if it is suspended or revoked, and make disclosures about its certificate, certification practice statement and any suspension or revocation. As printed in the copy, failure to surrender is punished with imprisonment up to six months or a fine up to ten thousand rupees, or both; as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the person is liable to penalty which may extend to five lakh rupees.
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of these sections should be checked. Section 33(2) is also explained below as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, Schedule item 32(A). A Certifying Authority that wants its internal duty-checklist reviewed can ask for a legal consultation.
Section 30: procedures to follow
"Every Certifying Authority shall":
| Clause | Duty as printed |
|---|---|
| (a) | make use of hardware, software, and procedures that are secure from intrusion and misuse |
| (b) | provide a reasonable level of reliability in its services which are reasonably suited to the performance of intended functions |
| (c) | adhere to security procedures to ensure that the secrecy and privacy of the electronic signatures are assured |
| (ca) | be the repository of all Electronic Signature Certificates issued under this Act |
| (cb) | publish information regarding its practices, Electronic Signature Certificates and current status of such certificates |
| (d) | observe such other standards as may be specified by regulations |
Clauses (ca) and (cb) are printed in square brackets in the copy, and a stray "[*]" appears after clause (c); we have not treated it as text. Failure to maintain the procedures and standards in section 30 is one of the grounds on which the Controller may revoke a licence under section 25(1)(c); see our article on suspension and revocation of Certifying Authority licence.
Section 31: ensuring compliance by staff
"Every Certifying Authority shall ensure that every person employed or otherwise engaged by it complies, in the course of his employment or engagement, with the provisions of this Act, rules, regulations or orders made thereunder." The duty reaches persons "otherwise engaged", so contractors and outsourced personnel are within the words, not only employees.
Section 32: display of licence
"Every Certifying Authority shall display its license at a conspicuous place of the premises in which it carries on its business." The section is a single sentence and prints no penalty.
Section 33: surrender of licence
Sub-section (1). "Every Certifying Authority whose license is suspended or revoked shall immediately after such suspension or revocation, surrender the license to the Controller."
Sub-section (2), as printed in the consolidated copy. "Where any Certifying Authority fails to surrender a license under sub-section (1), the person in whose favor a license is issued, shall be guilty of an offence and shall be punished with imprisonment which may extend up to six months or a fine which may extend up to ten thousand rupees or with both."
As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023
Item 32(A) of the Schedule says: "In section 33, in sub-section (2), for the words 'punished with imprisonment which may extend up to six months or a fine which may extend up to ten thousand rupees or with both', the words 'liable to penalty which may extend to five lakh rupees' shall be substituted."
| As printed in the consolidated copy | As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023 | |
|---|---|---|
| Consequence | "shall be punished with imprisonment which may extend up to six months or a fine which may extend up to ten thousand rupees or with both" | "liable to penalty which may extend to five lakh rupees" |
| Amount | Ten thousand rupees (fine) | Five lakh rupees (penalty) |
| Imprisonment | Up to six months | Not provided in the substituted words |
Applying the item word for word, the sub-section would read that the person "shall be guilty of an offence and shall be liable to penalty which may extend to five lakh rupees". The words "guilty of an offence" are not touched by the item, and we have not altered them. The item replaces imprisonment or fine with a "penalty" and nothing more is inferred here about who imposes it; the amended section 46 is explained in our article on the adjudicating officer.
Commencement. Section 1(2) of the Jan Vishwas (Amendment of Provisions) Act, 2023 makes it come into force on a date the Central Government appoints, and different dates may be appointed for different enactments. No date is in the sources used here. Check whether the amendment to section 33 has been brought into force before relying on either version.
Section 3 of that Act also provides for an increase of fines and penalties; no figure is computed here.
Section 34: disclosure
Sub-section (1). Every Certifying Authority shall disclose, in the manner specified by regulations:
- (a) its Electronic Signature Certificate (some words are shown as omitted in the copy);
- (b) any certification practice statement relevant thereto;
- (c) notice of the revocation or suspension of its Certifying Authority certificate, if any; and
- (d) any other fact that materially and adversely affects either the reliability of an Electronic Signature Certificate which that Authority has issued, or the Authority's ability to perform its services.
Sub-section (2). Where, in the opinion of the Certifying Authority, any event has occurred or any situation has arisen which may materially and adversely affect the integrity of its computer system or the conditions subject to which an Electronic Signature Certificate was granted, the Certifying Authority shall:
- (a) use reasonable efforts to notify any person who is likely to be affected by that occurrence; or
- (b) act in accordance with the procedure specified in its certification practice statement to deal with such event or situation.
Note the test in sub-section (2): "in the opinion of the Certifying Authority". The duty is triggered by the Authority's own opinion that an event may materially and adversely affect integrity.
A worked example
Sterling Key Trust Private Limited, a Certifying Authority, has its licence suspended by order. Under section 33(1) it must surrender the licence to the Controller immediately after the suspension, not at its convenience. It also notes that section 25(3) bars issue of certificates during the suspension. Meanwhile, the company discovers that a server event may have affected the integrity of its system. Section 34(2) requires it to use reasonable efforts to notify those likely to be affected, or to act in accordance with the procedure in its certification practice statement. If it fails to surrender, the consequence depends on which version of section 33(2) applies: imprisonment up to six months or a fine up to ten thousand rupees, or both, as printed in the copy; or liability to a penalty which may extend to five lakh rupees, as amended. The company's advisers would check the commencement position first.
Need help with Certifying Authority duties?
If you operate or advise a Certifying Authority, we can map your internal procedures against sections 30 to 34 and the disclosure obligations. Ask for a legal consultation and bring your certification practice statement and policy documents.
Key takeaways
- Section 30 lists secure-system, reliability, privacy, repository, publication and standards duties.
- Staff and others engaged must comply with the Act, rules, regulations and orders (section 31).
- The licence must be displayed (section 32) and surrendered immediately on suspension or revocation (section 33(1)).
- Section 33(2): printed punishment of imprisonment up to six months or fine up to ten thousand rupees, or both; as amended, penalty up to five lakh rupees.
- Disclosure and notification duties are in section 34.
Read next
- Sections 35 and 36: issue of electronic signature certificate and representations
- Section 46: adjudicating officer and power to adjudicate
- Sections 28 and 29: Controller's power to investigate and access computers
- Digital Signature Certificate (DSC): how to get, renew and use
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
