Explained

What is CCA India? Certifying Authorities & the signature trust chain

Updated June 2026 · 7 min read

What is CCA India? Certifying Authorities & the signature trust chain

Every time a verifier shows a green tick on an Indian document, it's really saying one thing: "I followed this signature's certificate all the way up to a root I trust — and that root belongs to India's CCA." Understanding what the CCA is, and how the chain beneath it works, makes every "Signature Not Verified" message far less mysterious.

The Controller of Certifying Authorities (CCA)

The Controller of Certifying Authorities is a government body set up under the Information Technology Act, 2000. It sits at the very top of India's public-key trust hierarchy and operates the Root Certifying Authority of India (RCAI). In practical terms, the CCA issues and publishes a small set of root certificates (for example the CCA India 2014, 2015 and 2022 roots) that anchor trust for the entire country's digital signatures.

Licensed Certifying Authorities

The CCA doesn't issue individual DSCs to citizens. Instead, it licenses Certifying Authorities (CAs) to do that. These are the names you'll recognise on your certificates: e-Mudhra, (n)Code Solutions, SafeScrypt (Sify), Capricorn, XtraTrust, VSign, IDRBT, C-DAC, Protean (NSDL) and others. Each licensed CA runs its own signing infrastructure, but its certificates chain back up to a CCA root — that's what makes them nationally trusted.

The trust chain, step by step

A digital signature carries a certificate, and that certificate points to whoever issued it. Verifiers follow that trail:

Our verifier bundles every CCA root plus the licensed CA and sub-CA intermediates, so it can build this chain even when your desktop reader can't. That's why a file marked "validity unknown" in Adobe often comes back green here.

Integrity vs trust — two separate questions

It's worth repeating because it clears up so much confusion. Integrity asks: has the document changed since it was signed? Trust asks: do we recognise who signed it? A green result needs both. "Signature Not Verified" in Adobe is almost always a trust gap (the CCA root isn't installed), not an integrity failure. We break this down further in our fix guide.

Why this matters for you

Whether you're checking a GST certificate, an ITR-V, an MCA filing, a DigiLocker document or your e-Aadhaar, the same trust chain decides the outcome. Once you know that a valid Indian signature always ends at a CCA root, verifying any document becomes routine. You can read more about our methodology on the about page, or authoritative details at the official CCA site, cca.gov.in.

Advertisement
Ad space — add your AdSense ID in ads.php

Verify your document now

Free, instant and private — files auto-deleted within 2 hours.

Verify a PDF

Related articles