A digital signature certificate should be selected for a named signatory and an intended use. CCA licenses Certifying Authorities; the issuer handles the applicant's certificate. Check the official issuer records and the intended filing portal's requirements before paying. No particular issuer is endorsed here. [S28] [S29]
Write down the requirement first
- The person who will sign and, where relevant, the organisation represented.
- The exact portal or tender system, not simply “all government work.”
- Whether the requirement is signing, encryption or another supported use.
- The computer, operating system and permitted signing software.
- Any deadline and the time needed for issuer verification, delivery and portal association.
Prepare the applicant's own verification
Ask the issuer for its current checklist for your applicant type. Check name and organisational details against the records before beginning. If an online identity or video-verification route is offered, the actual applicant should complete it. Do not promise that every applicant can avoid a visit, every device will work or every portal accepts the same certificate.
Keep control of the signing key
The subscriber must retain control of signing credentials. Do not send a token PIN, password or OTP in a support chat, or ask a helper to impersonate the signatory. Do not follow generic advice to export or back up a signing private key; follow the issuer's supported storage and recovery instructions. [S28]
Check the handover before a deadline
- Confirm the issuer, subject details, permitted usage and certificate validity.
- Install software only from the issuer or the relevant portal's trusted instructions.
- Complete any required portal registration or association under the signatory's control.
- Use a non-sensitive test or the portal's verification facility where available. Confirm both signing and submission acknowledgements.
- Keep the issuer's support and revocation instructions accessible.
Does expiry invalidate every document signed earlier?
No blanket conclusion follows from present-day expiry. CCA describes how earlier signatures can be verified after certificate expiry using the necessary certificate and validation evidence. A new signing attempt with an expired certificate is a different issue. [S28]
What if a token is lost or a PIN is exposed?
Stop using the affected signing arrangement and contact the issuer through its official support route for revocation or recovery guidance. A forgotten PIN, suspected compromise and certificate expiry are different problems; do not prescribe the same reset or reissue action for all three.
What should a quote show?
Issuer charges, validity, token or supported storage arrangement, taxes, delivery and any separately agreed assistance. An urgent-service charge is not proof that identity checks or portal requirements can be bypassed.
Official references and their limits
- Controller of Certifying Authorities: Digital-signature FAQs ↗
Supports licensed issuers, subscriber key custody and verification of earlier signatures after certificate expiry. Some legacy certificate-class examples remain on the FAQ; obtain current issuer and filing-portal requirements.
- Controller of Certifying Authorities: Licensed Certifying Authorities disclosure records ↗
Official verification destination. The text-only view did not expose the full issuer list, so no particular issuer is endorsed or independently verified here.
Older guidance must be read with subsequent changes. Reachability of a reference is not proof that it answers your particular case.
Prepare your next step
Read the related service guide →
Ask LIQUETAX about your requirement →
Share a short description first. Use an agreed secure channel for identity documents, bank details and tax records. Never send passwords or OTPs in a general enquiry.