Every advocate who files a vakalatnama through e-Courts, every chartered accountant who signs a GST return, and every company secretary who uploads an MCA form does so through a small piece of hardware most of them never think about: a USB cryptographic token carrying their Digital Signature Certificate (DSC). On September 21, 2026, the rules governing that hardware changed nationwide — and a day before the change took effect, the Delhi High Court was asking the Central Government why it had built one rule for citizens and a gentler one for itself.
The case is Advocate Ramkishan Saraswat v. Union of India, and on its face it is a narrow dispute about cryptographic standards. Underneath, it is a live Article 14 classification challenge, playing out in real time against a regulatory deadline that has already passed — which makes it a useful lens on both India’s digital-governance infrastructure and the constitutional test that decides whether a government classification is lawful.
The Deadline That Just Passed
The Controller of Certifying Authorities (CCA), the statutory body under the Information Technology Act, 2000 that regulates who may issue Digital Signature Certificates in India, issued an advisory in January 2026 directing Certifying Authorities to stop issuing DSCs on tokens compliant only with the older FIPS 140-2 cryptographic standard, migrating instead to the newer FIPS 140-3 standard. FIPS 140-3 (Federal Information Processing Standard 140-3, aligned with the international ISO/IEC 19790:2012 benchmark) tightens the tamper-resistance and testing requirements for the hardware that stores a signer’s private key, making the key harder to extract or clone.
The CCA fixed September 21, 2026 as the cut-off: from that date, Certifying Authorities may no longer issue fresh DSCs — or process renewals — on FIPS 140-2 tokens. Certificates already downloaded onto a FIPS 140-2 token before the cut-off are not revoked; they continue to work until they expire on their own terms. But every new signer, and every existing signer whose certificate lapses after the deadline, must now buy FIPS 140-3 hardware.
For government organisations, the CCA advisory carved out a different timeline: departments that adopt a formal risk-and-compliance waiver, approved by their parent ministry, may keep using FIPS 140-2 tokens until September 21, 2029 — three years longer than everyone else.
The practical stakes are immediate. The GST Network, anticipating the switch, issued its own Advisory No. 672 on September 19, 2026, rolling out emSigner version 3.3 so that returns and forms signed on the GST portal would recognise the new tokens. Tax professionals who buy a new DSC token after September 21 without the updated signing software risk a return that simply will not upload. The Ministry of Corporate Affairs and the e-Courts filing systems face the same compatibility question, since DSCs are the backbone of authentication for company filings and, increasingly, court e-filing.
What the Petitioner Argued
Ramkishan Saraswat, an advocate who relies on a FIPS-validated token for his own e-filings, made a representation to the government in June 2026 challenging the three-year gap between the private and government deadlines. His central objection, as recorded by the court, was that the CCA’s own advisory acknowledged no known security vulnerability in FIPS 140-2 modules — so the classification wasn’t being driven by a security risk unique to private users. If the standard is safe enough for a government department to keep using for three more years, he argued, there is no rational basis for forcing every advocate, chartered accountant, and small business to replace their tokens immediately.
When the government failed to decide his June representation, Saraswat approached the Delhi High Court. A single judge, on August 31, 2026, directed the Centre to decide the representation within four weeks. When that deadline too passed without a decision, Saraswat filed an intra-court appeal — LPA 738/2026 — which came up before a division bench of Chief Justice D.K. Upadhyaya and Justice Tejas Karia on September 16, 2026, five days before the migration deadline itself.
‘What Is the Intelligible Differentia?’
The bench did not rule on the merits of the classification — it didn’t need to, since the government still hadn’t even decided the representation pending before it. But its oral remarks, reported by LiveLaw, framed the issue precisely in the language of Article 14 doctrine: “Every user of a digital signature should be at same pedestal. The hardships to government employees using it should be the same. What is the rationale? What is the intelligible differentia of these two categories?”
That question invokes a specific, decades-old constitutional test. Article 14 guarantees equality before the law, but it does not outlaw all classification — a law or executive action may validly treat different groups differently, provided the classification clears two hurdles established since State of West Bengal v. Anwar Ali Sarkar, AIR 1952 SC 75: first, the classification must rest on an “intelligible differentia” — a real, identifiable difference separating the groups — and second, that differentia must bear a “rational nexus” to the objective the rule is trying to achieve.
Applied here, the government’s task is to explain what distinguishes a Ministry official’s cryptographic token from a practising advocate’s, for the specific purpose the CCA advisory is meant to serve — namely, upgrading tamper-resistant hardware before older cryptographic modules become a liability. If the honest answer is procurement cost or administrative inertia rather than any security-relevant difference between the two groups of users, the classification is vulnerable on exactly the ground Saraswat has raised and the bench has now voiced.
The division bench declined to interfere with the single judge’s earlier order and simply directed the Centre to decide Saraswat’s representation “latest by September 20” — one day before the migration deadline took effect. Whether that decision has in fact been made, and whether it addresses the constitutional objection or simply reiterates the existing timeline, remained unclear as of the date of this article; no published order or notification reflecting a decision on the representation was available at the time of writing.
Why This Matters Beyond One Advocate’s Token
This dispute sits at an intersection Indian legal practice is going to encounter more often: routine technical compliance mandates issued by a regulator, with real deadlines and real financial cost, that carry an embedded — and sometimes unexamined — classification between citizen and state. The DSC migration is not, by itself, a large controversy; the incremental cost of a new USB token is modest compared to litigation over major legislation. But the doctrinal question the bench raised applies with equal force to bigger stakes: data-localisation rules that exempt government processors, cybersecurity reporting timelines that are shorter for private companies than for public agencies, or compliance grace periods that consistently run longer for the state than for the citizens and businesses the state regulates.
For practitioners, three things follow. First, anyone renewing or acquiring a DSC after September 21, 2026 needs FIPS 140-3-compliant hardware and updated signing software such as GSTN’s emSigner v3.3 — existing certificates are not invalidated, but replacements are not backward-compatible. Second, the pending representation is worth tracking: given the bench’s skepticism, an extension of the private-user deadline is squarely possible, and professionals who haven’t yet migrated may benefit from any relief that follows. Third, the case is a reminder that a technical regulator’s advisory is not immune from constitutional scrutiny merely because it deals with cryptography rather than rights in the conventional sense — differential treatment in any regulatory timeline can be tested against Article 14, and courts are willing to ask the question even at the interim stage.
Frequently Asked Questions
Does my existing Digital Signature Certificate stop working on September 21, 2026?
No. If your DSC was already downloaded onto a FIPS 140-2 token before that date, it continues to function normally until the certificate itself expires. The deadline only stops Certifying Authorities from issuing new DSCs, or processing renewals, on FIPS 140-2 tokens going forward.
What do I need to do if I’m renewing my DSC now?
You will need to purchase a FIPS 140-3-compliant USB token, since Certifying Authorities can no longer issue certificates on the older standard. If you use your DSC on the GST portal, you should also ensure you are running emSigner version 3.3 or later, since GSTN’s Advisory No. 672 confirms older signing software may not recognise the new tokens.
What did the Delhi High Court actually decide?
The division bench did not rule on the legality of the differential deadlines. It disposed of the appeal by directing the Central Government to decide the petitioner’s pending representation by September 20, 2026, while noting its own skepticism about the rational basis for treating government and private users differently.
Why do government organisations get until 2029 to migrate?
The CCA’s advisory permits specified government organisations to continue using FIPS 140-2 modules until September 21, 2029, if their ministry approves a formal risk-and-compliance waiver. The petitioner’s objection — echoed by the bench — is that the advisory does not explain why this extended timeline is available only to the state and not to private professionals facing the same underlying technology.
What is the “intelligible differentia” test the court referred to?
It is the foundational test for permissible classification under Article 14 of the Constitution, established in cases beginning with State of West Bengal v. Anwar Ali Sarkar (1952). A classification survives constitutional scrutiny only if it is based on a real, identifiable difference between the groups, and that difference has a rational connection to the purpose of the law or policy in question.
Is this case likely to change the September 21 deadline?
That is not yet known. The bench’s remarks suggest real doubt about the government’s justification, but the matter currently turns on whether the Centre decides the pending representation — and how — rather than on a final judicial ruling striking down the classification.
Sources
- Delhi High Court Asks Centre To Decide Plea Against Sept 21 Cut-Off For Old Digital Signature Tokens, Questions Different Deadline For Govt Users - LiveLaw’s report on the Delhi High Court’s September 16, 2026 order in LPA 738/2026, including the bench’s oral remarks.
- Advisory on Migration from FIPS 140-2 to FIPS 140-3 - The Controller of Certifying Authorities’ official advisory setting out the migration deadlines.
- GSTN Makes emSigner v3.3 Mandatory for New DSC Tokens from 21 September 2026; Existing DSCs to Remain Valid till Expiry - Coverage of GSTN Advisory No. 672 and its effect on GST-portal DSC users.
- FIPS 140-3 DSC Tokens Mandatory Sept 2026: Complete Guide - Practical explainer on the migration timeline and treatment of existing certificates.
- FIPS 140-3 DSC Token in India: 2026 Guide - Background on the technical differences between FIPS 140-2 and FIPS 140-3 modules.
- FIPS 140-2 to FIPS 140-3 DSC Token Migration in India: 2026 Upgrades & CCA Guidelines - Additional detail on the CCA’s compliance requirements and the government waiver mechanism.
- Doctrine of Reasonable Classification - Explainer on the intelligible-differentia and rational-nexus test under Article 14, tracing it to State of West Bengal v. Anwar Ali Sarkar.
