GSTHow to verify DSC-signed MCA / ROC documents
Updated June 2026 · 6 min read
Company law paperwork in India runs on digital signatures. Directors, company secretaries and chartered accountants sign MCA21 forms, board resolutions, ROC filings and audited financials with a Class 3 Digital Signature Certificate (DSC). If you receive one of these signed PDFs — say a certified incorporation document or a signed board resolution — you'll want to confirm the signature belongs to a valid, unexpired certificate before you rely on it.
Which certificates you'll encounter
MCA-related DSCs are issued by CCA-licensed Certifying Authorities such as e-Mudhra, (n)Code Solutions, Capricorn, SafeScrypt (Sify), XtraTrust and VSign. Each of these chains up to a CCA India root, which is exactly what a trustworthy verifier checks. To understand that chain, see our explainer on what CCA and Certifying Authorities are.
Verify a signed MCA/ROC PDF
- Get the signed PDF (a downloaded MCA form, a certified true copy, or a signed resolution).
- Upload it to our verifier.
- Read the verdict, the signer's name (usually the director or professional), the issuing CA and the validity dates of the certificate.
Watch for expired or revoked certificates
DSCs are typically valid for one to three years. A document signed while the certificate was valid remains valid afterwards, but if a file was signed after the certificate expired, that's a genuine problem. Our tool surfaces the certificate's validity window so you can sanity-check the signing date against it. A structurally sound signature whose chain can't be trusted (for example, an expired intermediate) shows as an amber verdict rather than green — a useful early warning.
Integrity is the headline check
The most important thing a signature guarantees is that the document hasn't changed since it was signed. For company filings, where a single altered figure or date can have serious consequences, this is invaluable. If anyone re-saves or edits a signed MCA PDF, the signature breaks and you'll see a red "modified" result. Our full verification guide explains how that integrity check works under the hood.
Why not just trust Adobe's warning?
Adobe often labels these signatures "validity unknown" because it doesn't ship trusting Indian CCA roots. That's a trust-store gap, not evidence of forgery — our fix guide shows how to resolve it. For a quick, no-setup answer, uploading the file here is the simplest route.
ads.phpVerify your document now
Free, instant and private — files auto-deleted within 2 hours.

