Controller of Certifying Authorities — powers and functions — Intellectual Property Rights I Notes
Controller of Certifying Authorities — powers and functions
If anyone could set up shop issuing digital “identity certificates”, a signature would be worthless — a forger could simply certify himself. So the IT Act puts one regulator at the top of the trust pyramid: the Controller of Certifying Authorities, who licenses the certifiers and certifies the certifiers’ own keys.
What the Controller is and does
The Controller of Certifying Authorities (CCA) is a statutory authority appointed by the Central Government under s.17 of the IT Act, 2000, to supervise and regulate the Certifying Authorities that issue Digital Signature Certificates. The CCA sits at the apex of India’s public-key infrastructure and operates the Root Certifying Authority of India (RCAI), whose key digitally signs and certifies the keys of all licensed CAs — so trust flows down from a single trusted root.
Functions and powers of the Controller — s.18:
- exercising supervision over the activities of Certifying Authorities;
- certifying the public keys of the Certifying Authorities;
- laying down standards to be maintained by Certifying Authorities;
- specifying the qualifications and experience of employees of CAs;
- specifying the conditions under which CAs must conduct business;
- specifying the form and content of a Digital Signature Certificate and the public key;
- specifying the form and manner of maintenance of accounts by CAs;
- specifying the terms of appointment of auditors and their remuneration;
- resolving conflicts of interest between CAs and subscribers;
- laying down the duties of Certifying Authorities; and
- maintaining a database (repository) of the disclosure record of every CA, accessible to the public.
Further powers. The Controller grants and renews licences to Certifying Authorities (s.21), may suspend or revoke a licence (ss.25, 26), and has power to investigate contraventions (s.28) and to give directions to CAs (s.68).
Information Technology Act, 2000, s.18: “The Controller may perform all or any of the following functions, namely — (a) exercising supervision over the activities of the Certifying Authorities; (b) certifying public keys of the Certifying Authorities; (c) laying down the standards to be maintained by the Certifying Authorities; (d) specifying the qualifications and experience which employees of the Certifying Authorities should possess…”
In Simple Terms: The Controller of Certifying Authorities is the top regulator of digital signatures. It licenses the Certifying Authorities, certifies their public keys, sets their standards, audits them, and can suspend or revoke their licences. It runs the Root Certifying Authority of India, from which all digital-signature trust flows.
🧩 WORKED EXAMPLE — a rogue certifying authority
Facts. A licensed Certifying Authority repeatedly issues certificates without verifying identity, undermining the reliability of digital signatures.
Rule. s.18 gives the Controller supervisory power and power to set standards; ss.25–26 allow suspension/revocation of a CA’s licence for breach of conditions.
Apply. The CA has breached the verification standards the Controller laid down; the Controller may investigate (s.28), direct compliance, and suspend or revoke the licence.
Conclusion. The Controller can discipline and, if necessary, delicense the errant CA — the core of its regulatory role.
flowchart TD
CCA["Controller of Certifying Authorities (s.17)"]:::root
CCA --> SUP["Supervises CAs (s.18(a))"]:::leaf
CCA --> KEY["Certifies CAs' public keys (RCAI)"]:::leaf
CCA --> STD["Sets standards, qualifications, audit terms"]:::leaf
CCA --> LIC["Grants / renews / suspends / revokes licences (ss.21-26)"]:::leaf
CCA --> DB["Maintains public repository / database"]:::leaf
classDef root fill:#FFF8DC,stroke:#000,color:#000;
classDef leaf fill:#E6F3FF,stroke:#1E3A8A,color:#000;
Case Laws
- Shreya Singhal v Union of India (2015) — clarified the regulatory scheme of the Act within which the Controller and CAs function.
- State of Delhi v Mohd. Afzal (2003) — reliability of electronic authentication (the CCA’s domain) was accepted in evidence.
📄 Full notes + Question Bank (₹199) — every topic in depth, model answers to all past KSLU questions, in one printable PDF. Get the bundle · 10 Solved Problems · All Intellectual Property Rights I topics