News
FIPS 140-3 DSC Tokens Mandatory from 21 September 2026
Published August 9, 2026 · By DSCKart
The Controller of Certifying Authorities (CCA) has issued an advisory moving India's Digital Signature ecosystem from FIPS 140-2 to FIPS 140-3 compliant cryptographic USB tokens, with a key deadline of 21 September 2026. If you are buying a new DSC or renewing an existing one, this decides which USB token your certificate can be downloaded onto.
What Is FIPS 140-3, in Plain Terms
Your DSC's private key never leaves the USB token it is stored on — that hardware is what keeps your signature yours. FIPS is the security standard those cryptographic modules are certified against. FIPS 140-3 is the newer version replacing FIPS 140-2, aligned with the international ISO/IEC standards 19790 and 24759, and it tightens the requirements for key storage, integrity checks and tamper protection.
For a normal user nothing about signing changes. You still plug the token in, enter your PIN and sign. The difference is in how rigorously the hardware itself has been certified.
What the CCA Advisory Actually Says
- Certifying Authorities must stop issuing DSCs on FIPS 140-2 modules by 21 September 2026.
- A DSC downloaded on a FIPS 140-2 token on or before 21 September 2026 stays valid until that certificate expires — but that token cannot be used for a renewal or a fresh download after the date.
- From 1 January 2026, the CCA stopped accepting fresh audit applications for FIPS 140-2 modules.
- A limited exception applies: where an active DSC has to be reissued to the same user, a CA may issue it on a FIPS 140-2 module for the certificate's remaining validity — one time only, at no extra cost.
- 21 September 2029 is the final cutoff for retiring legacy FIPS 140-2 modules, relevant mainly to specific government organisations operating under an approved risk waiver.
What This Means for Your Existing Token
If your DSC is already sitting on a FIPS 140-2 token, it keeps working. The certificate remains valid on MCA21, Income Tax, GST, EPFO, DGFT and e-tender portals until its own expiry date, and there is no need to replace working hardware early.
The change applies to your next certificate. From 21 September 2026, a new DSC or a renewal must be downloaded onto a FIPS 140-3 compliant token. If the token you own is already FIPS 140-3 certified, you can keep reusing it and pay only for the certificate.
Who Is Affected
- Anyone buying a new DSC or renewing an existing certificate
- GST, MCA/ROC and Income Tax filers
- DGFT and ICEGATE users handling import/export filings
- e-tender and GeM bidders
- Chartered Accountants, Company Secretaries and company directors
- Enterprises running bulk or automated document signing
Will FIPS 140-3 Tokens Cost More?
The CCA has directed token manufacturers and Certifying Authorities to publish exchange or buy-back policies and updated price lists for FIPS 140-3 modules. Newer secure hardware can carry a higher cost than older 140-2 tokens, so it is worth checking current rates before your renewal falls due. Ours are always listed on the pricing page.
What You Should Do Now
- Check whether your current USB token is FIPS 140-3 or FIPS 140-2 certified.
- If you will be renewing on or after 21 September 2026 with a 140-2 token, plan for a FIPS 140-3 token.
- Don't replace a working token unnecessarily before your renewal is due.
- Choose a FIPS 140-3 token for any new certificate you buy from here on.
Not sure which token you hold? Message DSCKart on WhatsApp (or call +91 9741033832) with your token model and we will confirm it for you.
Frequently Asked Questions
What changes on 21 September 2026?
From that date, Certifying Authorities must stop issuing Digital Signature Certificates on FIPS 140-2 cryptographic modules. Every fresh certificate and every renewal has to be downloaded onto a FIPS 140-3 compliant USB token.
Does my existing DSC stop working on 21 September 2026?
No. A certificate downloaded on a FIPS 140-2 token on or before that date stays valid until the certificate itself expires. What you cannot do after the date is use that older token for a renewal or a fresh download.
Do I need to replace my USB token right now?
Not if your current token holds a working certificate and your renewal is not yet due. Replace it when you next renew or buy a certificate, unless your existing token is already FIPS 140-3 certified, in which case it can continue to be used.
How do I know whether my token is FIPS 140-2 or FIPS 140-3?
The certification level is published by the token manufacturer for each model. If you are unsure, send us the token model on WhatsApp at +91 9741033832 and we will help you check before your renewal is due.
Will a FIPS 140-3 token cost more?
The CCA has directed token manufacturers and Certifying Authorities to publish exchange or buy-back policies and updated price lists for FIPS 140-3 modules. Newer secure hardware can cost more than older 140-2 tokens; current DSCKart rates are always shown on the pricing page.
Is there any exception to the 21 September 2026 date?
The advisory allows a limited exception: where an active certificate has to be reissued to the same user, a Certifying Authority may issue it on a FIPS 140-2 module for the remaining validity of that certificate — one time only and at no additional cost.
Ready for the FIPS 140-3 Switch
DSCKart issues Digital Signature Certificates and renewals on FIPS 140-3 compliant USB tokens — approved in about 15 minutes, with free pan-India shipping.
This article summarises the CCA advisory for general guidance; for the authoritative text, refer to the official advisory published by the Controller of Certifying Authorities.
