Token distributors and users must prepare for the critical migration from FIPS 140-2 compliant cryptographic USB tokens to the newer, highly secure FIPS 140-3 compliant cryptographic modules. This shift marks one of the most significant upgrades in the digital signature infrastructure in recent years.
This transition affects DSC issuance, renewal, eTendering, MCA filings, Income Tax filing, GST filing, DGFT transactions, ICEGATE users, banking authentication, and every organization that relies on Digital Signature Certificates for secure digital transactions across India.
What is Happening in India's DSC Ecosystem?
The Controller of Certifying Authorities (CCA), the regulatory body governing digital signatures in India, has officially advised all Certifying Authorities (CAs) to migrate their infrastructure from FIPS 140-2 to FIPS 140-3 compliant modules. This move is designed to offer enhanced security, prevent unauthorized access to sensitive private keys, and ensure future-ready compliance with international cryptography standards.
As per the official advisory released by the CCA:
- Certifying Authorities must strictly stop issuing new DSCs in FIPS 140-2 modules starting from 21 September 2026.
- Existing DSCs downloaded before the deadline will remain valid and continue to function until their natural certificate expiry date.
- All new DSC issuances and renewals will gradually, yet completely, move to FIPS 140-3-compliant tokens.
- Token manufacturers and distributors have been advised to publish clear exchange or buyback policies for older tokens to aid a smooth transition for large organizations.
Official Migration Timeline
Every DSC user, Chartered Accountant, and IT admin must be aware of these critical cut-off dates:
| Event / Milestone | Applicable Date |
|---|---|
| Last practical date to download a DSC into a legacy FIPS 140-2 token | 20 September 2026 |
| Mandatory complete stop of DSC issuance in FIPS 140-2 modules | 21 September 2026 |
| Fresh audit applications for FIPS 140-2 modules accepted by CCA | Stopped from 1 January 2026 |
Will Existing DSC Tokens Stop Working After September 2026?
No, they will not immediately stop working. This is one of the most common concerns among taxpayers and professionals. If your DSC has already been downloaded into a FIPS 140-2 token before 21 September 2026, the certificate and the hardware token will continue functioning normally until the certificate's expiry date.
What Happens When the Existing DSC Expires?
Once your current DSC validity period ends (e.g., in 2027 or 2028), a renewed or newly issued DSC cannot be downloaded into the old FIPS 140-2 token. Renewal will explicitly require the purchase of, and migration to, a new FIPS 140-3-compliant hardware token. Businesses managing hundreds of tokens will need to budget for replacing legacy hardware.
Why is the Government Moving to FIPS 140-3?
The transition is not arbitrary; it is driven by the urgent need for cybersecurity modernization in India's growing digital economy:
- Stronger Protection of Private Keys: FIPS 140-3 strengthens physical and logical protection mechanisms against sophisticated tampering or unauthorized key extraction.
- Improved Cybersecurity & Resistance: Modern cyber threats require significantly stronger cryptographic algorithms and tamper-resistant hardware casings than what was standardized decades ago.
- International Compliance: FIPS 140-3 directly aligns with globally recognized ISO/IEC security standards and validation frameworks, ensuring India's PKI infrastructure remains globally trusted.
Recommended Migration Strategy for Businesses & DSC Partners
To avoid operational bottlenecks, companies should adopt a proactive migration strategy:
- Review Existing Inventory: Assess available FIPS 140-2 token stock and expected utilization before mid-2026. Avoid overstocking legacy FIPS 140-2 tokens.
- Track OEM Announcements: Keep an eye on announcements from token manufacturers (like WatchData or HyperPKI) regarding official buyback, exchange, or hardware upgrade programs.
- Evaluate Early: Begin evaluating FIPS 140-3 certified token options early to test compatibility with your internal enterprise ERPs or signing applications, avoiding last-minute disruptions.