E-Governance
eSign and Digital Signature for Government Documents
Affix Center · · 6 min read

Government offices across Maharashtra have moved many services online, yet a large number of workflows still stop at one step: the signature. Certificates are printed, signed by hand, scanned and uploaded again. Approval notes wait for an officer to return to the office. Contractors travel to submit signed bid documents. Using eSign and digital signature for government documents removes this bottleneck, and both methods are legally recognised in India when used correctly.
The confusion lies in choosing the right method. Departments often mix up eSign, Digital Signature Certificates (DSC) and simple scanned signatures, or apply one method to every use case. This guide explains the difference, where each fits in government workflows, and what departments should check when building signing into their portals and systems.
The Legal Basis in India
The Information Technology Act, 2000 gives legal recognition to electronic records and to electronic signatures. Section 3A allows an electronic signature technique listed in the Act's Second Schedule to be used, and that schedule includes e-authentication using Aadhaar or other e-KYC services, which is the basis of eSign. Digital signatures using public key infrastructure are recognised under Section 3.
The Controller of Certifying Authorities (CCA), under the Ministry of Electronics and Information Technology, licenses Certifying Authorities that issue DSCs and sets guidelines for eSign Service Providers. All valid certificates chain up to the Root Certifying Authority of India.
A few documents are excluded from the Act by its First Schedule, including wills, powers of attorney, trusts, most negotiable instruments other than cheques, and contracts for the sale or conveyance of immovable property. Check this list before digitising any signing workflow.
eSign vs DSC: The Key Differences
eSign (online electronic signature)
eSign is a signing service provided by licensed eSign Service Providers (ESPs). The signer authenticates, usually with Aadhaar-based OTP or biometric e-KYC, and a one-time key pair is created to sign the document. The application normally sends only a hash of the document to the ESP, not the document itself.
- No hardware token needed
- Works on mobile and in browsers
- Paid per signature, through the ESP or an aggregator
- Suits citizens and occasional signers
Digital Signature Certificate (DSC)
A DSC is a certificate issued to a person or organisation by a licensed Certifying Authority after identity verification, typically stored on a secure USB crypto token. Since Class 2 certificates were discontinued from January 2021, Class 3 is the standard for individuals and organisations.
- Valid for a fixed period, usually one to three years
- Requires the physical token and a PIN
- Widely used for e-tendering, statutory filings and procurement portals
- Suits officers and vendors who sign often
What a scanned signature is not
A scanned image of a handwritten signature pasted into a PDF is not an electronic signature under the IT Act. It offers no proof of identity or integrity and should not be used for documents that need legal validity.
Where Each Method Fits in Government Workflows
- Citizen applications and declarations: eSign lets applicants sign forms on a portal without visiting an office.
- Certificates issued to citizens: income, caste, domicile and similar certificates can be digitally signed by the issuing officer using a DSC, so they can be verified online.
- Internal file approvals: officers approving notes and orders often use DSC, or eSign where the office system supports it.
- Tenders and procurement: vendors typically sign and encrypt bids with Class 3 DSC on e-procurement portals.
- Agreements with contractors and vendors: either method can be used, subject to departmental rules and stamp duty requirements.
- Bulk outputs: for high-volume documents such as notices or certificates, server-side signing with an organisational certificate stored in a hardware security module may be appropriate, subject to policy approval.
Building Signing Into a Government Portal
For departments and their IT teams, adding signing to a portal involves more than a button. Plan these steps:
- Map the workflows. List every document that needs a signature, who signs it, how often, and whether legal rules require a particular method.
- Choose the method per document. eSign for citizens and low-volume signers, DSC for officers and vendors, server-side signing for approved bulk outputs.
- Select an ESP or aggregator for eSign, and confirm the integration approach, pricing model and supported authentication modes.
- Handle DSC on the client side. Browser signing needs a signing utility or component that works with USB tokens across operating systems. Test with the token types your officers actually use.
- Use a standard signed format. PDF signatures with visible signature blocks help users; the embedded cryptographic signature is what gives validity.
- Add verification. Provide a way for recipients to check signed documents, such as a verification page or QR code linked to the portal.
- Log everything. Record who signed, when, the certificate used and the document hash, and keep logs secure and tamper-evident.
Our e-governance solutions team builds these integrations into citizen portals and internal workflow systems, keeping the user experience simple for both officers and citizens.
Preparing Officers and Citizens for the Change
Technology is rarely the hardest part. Adoption is. Officers used to wet signatures may worry about accountability, and citizens may be unsure whether a digitally signed certificate will be accepted elsewhere. Plan for this early:
- Issue a clear office order stating which documents will be signed electronically and by which method.
- Run short, hands-on training sessions for officers on token use, PIN safety and what to do if signing fails.
- Set up a helpdesk contact for token, driver and browser issues during the first few weeks.
- Print a short note on digitally signed certificates explaining how recipients can verify them online.
- Pilot with one office or one service before expanding across the district or state.
Security and Governance Checklist
- Keep DSC tokens under the officer's personal control. Never share tokens or PINs among staff.
- Maintain a register of DSC expiry dates and renew before expiry to avoid stalled approvals.
- Revoke certificates promptly when officers transfer or retire, or when a token is lost.
- Protect server-side signing keys in hardware security modules with strict access control.
- Validate certificate chains and revocation status when accepting signed documents.
- Protect the portal itself with secure coding, security testing and monitoring. A signed document is only as trustworthy as the system that produced it.
Our cybersecurity services can review key management, portal security and audit logging for signing workflows.
Frequently Asked Questions
Is eSign legally valid for government documents?
Yes. eSign is an electronic signature technique recognised under Section 3A and the Second Schedule of the IT Act, 2000, except for document types excluded by the First Schedule or by specific departmental rules.
What is the difference between eSign and a DSC?
eSign is an online service using Aadhaar or other e-KYC to create a one-time signature, with no token needed. A DSC is a certificate issued for a fixed period, usually stored on a USB token and used repeatedly.
Which DSC class is used for government work?
Class 3 DSC is the standard since Class 2 certificates were discontinued from January 2021. It is widely used for e-tendering and official filings.
Can a scanned signature replace a digital signature?
No. A scanned signature image does not verify identity or protect document integrity, and it is not an electronic signature under the IT Act.
How Affix Center Can Help
We help government departments, PSUs and agencies add eSign and DSC-based signing to portals and internal systems, from workflow mapping and ESP integration to verification pages, logging and security review.
To discuss digital signing for your department's workflows, contact Affix Center.