Section 3A explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 3A of the Information Technology Act, 2000 lets a subscriber authenticate an electronic record by an electronic signature or electronic authentication technique that is considered reliable and may be specified in the Second Schedule. It lists the tests of reliability in sub-section (2), lets the Central Government add or omit techniques by notification, and requires every such notification to be laid before Parliament.
A subscriber may authenticate an electronic record by an electronic signature or electronic authentication technique which is considered reliable and may be specified in the Second Schedule. A technique is reliable if it meets five tests: link to the signatory alone, control by the signatory alone, detectable alteration of the signature, detectable alteration of the information, and any other condition that may be prescribed. The Central Government may add to or omit techniques from the Schedule by notification, and no technique may be specified unless it is reliable.
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). The text of section 3A is printed in square brackets in the copy, and the Second Schedule carries matter later than 2009. Later amendments and the current position of the section and the Schedule should be checked. For the digital signature route, which this section sits beside, see our article on section 3. If you want help choosing a signing method for contracts or filings, a legal consultation is a sensible start.
Sub-section (1): a second route to authentication
Sub-section (1) begins "Notwithstanding anything contained in section 3, but subject to the provisions of sub-section (2)". A subscriber may authenticate any electronic record by "such electronic signature or electronic authentication technique which (a) is considered reliable; and (b) may be specified in the Second Schedule". The definition of electronic signature in section 2(1)(ta) points the same way: authentication by the electronic technique specified in the Second Schedule, including digital signature. Our article on the definitions of digital signature and electronic signature sets out the wording.
Read the two limbs together: a technique must be reliable and it must be specified in the Schedule. The word "and" joins them in the printed text, although the second limb says "may be specified".
Sub-section (2): the five reliability tests
An electronic signature or electronic authentication technique "shall be considered reliable if":
| Clause | Test as printed |
|---|---|
| (a) | the signature creation data or the authentication data are, within the context in which they are used, linked to the signatory or, as the case may be, the authenticator and to no other person |
| (b) | the signature creation data or the authentication data were, at the time of signing, under the control of the signatory or, as the case may be, the authenticator and of no other person |
| (c) | any alteration to the electronic signature made after affixing such signature is detectable |
| (d) | any alteration to the information made after its authentication by electronic signature is detectable |
| (e) | it fulfills such other conditions which may be prescribed |
Clauses (a) and (b) are about who the signature belongs to and who controls it at the time of signing. Clauses (c) and (d) are about detection: both the signature and the information it covers must show any later change. Clause (e) leaves further conditions to rules. The rules are not in the sources used for this article, so we state no condition under clause (e). The text joins the clauses with "and" after (d), so all five tests are read together.
Sub-section (3): ascertaining who signed
The Central Government "may prescribe the procedure for the purpose of ascertaining whether electronic signature is that of the person by whom it is purported to have been affixed or authenticated". The procedure itself is not printed in the Act.
Sub-sections (4) and (5): changing the Schedule
Sub-section (4) lets the Central Government, by notification in the Official Gazette, "add to or omit any electronic signature or electronic authentication technique and the procedure for affixing such signature from the Second Schedule". The proviso adds that no electronic signature or authentication technique shall be specified in the Second Schedule unless such signature or technique is reliable. Sub-section (5) requires every notification under sub-section (4) to be laid before each House of Parliament.
The Second Schedule as printed
The Schedule is headed "Electronic Signature or Electronic Authentication Technique and Procedure" and refers back to sub-section (1) of section 3A. It has columns for serial number, description and procedure. The copy prints one entry, serial number 1, with the description "e-authentication Technique using Aadhaar e-KYC services".
The layout of the copy is damaged. The three columns are printed with their words interleaved, so the table cannot be read cleanly as a table. What can be read with certainty from the procedure column is this: the authentication of an electronic record is to be done by e-authentication techniques; there are lettered items (a) to (g); the items mention the issue of a Digital Signature Certificate by a Certifying Authority, a "trusted third party service" for key pair generation, storing of key pairs and creation of digital signature, a reference to Form C of Schedule IV of the Information Technology (Certifying Authorities) Rules, 2000, digitally signed verified information from Aadhaar e-KYC services and the electronic consent of the Digital Signature Certificate applicant, manner and requirements as issued by the Controller, standards referred to in rule 6 of the Information Technology (Certifying Authorities) Rules, 2000, and compliance with rules 3 to 12 of the Digital Signature (End entity) Rules, 2015 in so far as they relate to the creation, storage and verification of Digital Signature. One word, the end of item (b), is shown as omitted in the copy by asterisks in square brackets.
The rules named are quoted only as the Schedule names them, and nothing is said here about their content. The Schedule may have been changed since this copy, so check the current Second Schedule.
Electronic signature, digital signature and the rest of the Act
Where later sections speak of an "electronic signature", the Act's definition sweeps in digital signatures, which is why the headings of sections 5 and 6 are worded around electronic signatures. See our article on legal recognition of electronic signatures. A certificate issued to a subscriber is an Electronic Signature Certificate under section 35, covered in our article on issue of an electronic signature certificate.
A worked example
Pradeep runs a small consultancy, Kestrel Advisory LLP. He wants clients to sign engagement letters online without a physical token. Under section 3A he may use an electronic signature technique only if it is considered reliable under the five tests and is one that may be specified in the Second Schedule. His adviser would check that the signing data are linked to the signatory alone, were under the signatory's control alone at the time of signing, and that later changes to the signature or the letter would be detectable, and would then check whether the technique is in the Schedule as it stands. Our post on e-contracts and digital signatures discusses the practical side of signing agreements electronically.
Need help with electronic signature arrangements?
If you plan to move signing for contracts, onboarding or filings online, we can review the technique and the record-keeping with you. Reach out for a legal consultation and bring a sample of the document to be signed.
Key takeaways
- Section 3A is an additional route to authentication beside the digital signature of section 3.
- A technique must be reliable and specified in the Second Schedule.
- Five tests: linked to signatory, controlled by signatory, detectable alteration of signature, detectable alteration of information, other prescribed conditions.
- The Central Government may add or omit techniques by notification laid before Parliament.
- The Second Schedule in the copy is damaged in layout; check the current Second Schedule.
Read next
- Section 3: authentication of electronic records by digital signature
- Section 5: legal recognition of electronic signatures
- Section 35 and 36: issue of electronic signature certificate and representations
- Digital signatures and electronic records under the IT Act: impact on drafting
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
