Sections 35 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Sections 35 and 36 of the Information Technology Act, 2000 deal with the moment a certificate is issued. Section 35 sets out how any person applies to a Certifying Authority, what accompanies the application, and how the Authority grants or rejects it. Section 36 lists what a Certifying Authority must certify when it issues a Digital Signature Certificate.
Any person may apply to a Certifying Authority for an Electronic Signature Certificate in the prescribed form, with a fee not exceeding twenty-five thousand rupees and a certification practice statement (or, if none, a statement with the particulars specified by regulations). The Authority may grant the certificate, or reject it for reasons recorded in writing, and may not reject without giving the applicant a reasonable opportunity of showing cause. On issuing a Digital Signature Certificate it must certify eight matters, from its own compliance to the accuracy of the certificate.
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of these sections should be checked. Section 35 is a basis for the definition of a Digital Signature Certificate in section 2(1)(q), which refers to sub-section (4) of section 35. A subscriber or a Certifying Authority who needs the application and certification process reviewed can ask for a legal consultation.
Section 35(1): who may apply
"Any person may make an application to the Certifying Authority for the issue of an Electronic Signature Certificate in such form as may be prescribed by the Central Government." The form is prescribed by rules; the rules are not in the sources used here and nothing is said about their content.
Section 35(2): the fee
Every application shall be accompanied by "such fee not exceeding twenty-five thousand rupees as may be prescribed by the Central Government, to be paid to the Certifying Authority". The proviso says different fees may be prescribed for different classes of applicants. The Act prints only the ceiling; the actual amounts are for the Central Government to prescribe.
Section 35(3): certification practice statement
Every application shall be accompanied by "a certification practice statement or where there is no such statement, a statement containing such particulars, as may be specified by regulations". The certification practice statement is defined in section 2(1)(h); see our article on section 2: digital signature, certifying authority and key pair.
Section 35(4): grant or rejection
"On receipt of an application under sub-section (1), the Certifying Authority may, after consideration of the certification practice statement or the other statement under sub-section (3) and after making such enquiries as it may deem fit, grant the Electronic Signature Certificate or for reasons to be recorded in writing, reject the application."
The proviso (the copy prints "" after a line of omitted words): "no application shall be rejected unless the applicant has been given a reasonable opportunity of showing cause against the proposed rejection."
| Stage | Requirement |
|---|---|
| Application | Prescribed form; any person |
| Fee | Not exceeding twenty-five thousand rupees as prescribed; different fees for different classes of applicants |
| Statement | Certification practice statement, or a statement with particulars specified by regulations |
| Decision | Grant, or reject for reasons recorded in writing |
| Safeguard | Reasonable opportunity of showing cause before rejection |
Section 36: representations upon issuance
"A Certifying Authority while issuing a Digital Signature Certificate shall certify that":
| Clause | The Authority certifies that |
|---|---|
| (a) | it has complied with the provisions of this Act and the rules and regulations made thereunder |
| (b) | it has published the Digital Signature Certificate or otherwise made it available to such person relying on it and the subscriber has accepted it |
| (c) | the subscriber holds the private key corresponding to the public key listed in the Digital Signature Certificate |
| (ca) | the subscriber holds a private key which is capable of creating a digital signature |
| (cb) | the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the subscriber |
| (d) | the subscriber's public key and private key constitute a functioning key pair |
| (e) | the information contained in the Digital Signature Certificate is accurate |
| (f) | it has no knowledge of any material fact which, if it had been included in the Digital Signature Certificate, would adversely affect the reliability of the representations made in clauses (a) to (d) |
Clauses (ca) and (cb) appear in square brackets in the copy. Printing slip: clause (f) is printed with "(d )" and a space before the closing bracket; we read it as "clauses (a) to (d)".
How clause (b) links to the subscriber's acceptance
Clause (b) says the subscriber has accepted the certificate. Section 41 explains when a subscriber is deemed to have accepted; see our article on duties of subscribers and control of the private key.
Why the representations matter
The representations are made by the Certifying Authority to those who rely on the certificate. The section says only that the Authority "shall certify" these matters. The text prints no penalty for a false certification in this section, and nothing more is said here about the consequences. A person relying on a certificate can read the representations as the baseline of what the Authority has vouched for: its own compliance, publication, the subscriber's possession of a working key pair, and accuracy of the information.
Where the sections sit in the licence chain
Sections 21 to 24 govern the licence of the Certifying Authority (see our article on licence to issue electronic signature certificates); sections 35 and 36 govern the certificate it issues to a subscriber; sections 37 to 39 govern suspension and revocation of that certificate (see our article on suspension and revocation of a Digital Signature Certificate).
A worked example
Anika is the finance head of Saffron Bakeries Private Limited and applies to a Certifying Authority for a certificate. She submits the prescribed form, the fee prescribed for her class of applicant, and the certification practice statement the Authority provides. The Authority checks the documents and makes enquiries it deems fit. If it intends to reject, it must give Anika a reasonable opportunity of showing cause and record its reasons in writing. If it grants the certificate, it certifies the matters in section 36: among them that Anika holds the private key matching the public key listed, that the pair is a functioning key pair, and that the information in the certificate is accurate. For the practical side of obtaining a certificate, see our guide on how to get a Digital Signature Certificate.
Need help with certificate applications?
If you are applying for certificates for a company, or reviewing a Certifying Authority's representations before relying on its certificates, we can walk through the text with you. Please ask for a legal consultation and bring the application papers.
Key takeaways
- Any person may apply; the form and fee are prescribed, with the fee capped at twenty-five thousand rupees.
- The application carries a certification practice statement or a statement of specified particulars.
- Rejection needs written reasons and a reasonable opportunity of showing cause.
- Section 36 requires the Authority to certify its compliance, publication, the subscriber's key pair, accuracy of information and absence of known adverse facts.
- The text prints no penalty in either section.
Read next
- Sections 37 to 39: suspension and revocation of a Digital Signature Certificate
- Sections 40 to 42: duties of subscribers and control of the private key
- Sections 30 to 34: duties of a Certifying Authority
- DSC (Digital Signature Certificate) for MCA filing: complete guide
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
