electronic signature
Aadhaar eSign vs Digital Signature (DSC) vs Click-to-Sign in India
Three different things get called "e-signature" in India, and mixing them up causes real problems: a signed vendor contract you cannot rely on in a dispute, an MCA filing that gets rejected, or a POA a bank refuses to accept. This guide compares the three methods Indian law actually recognises or accepts: the Digital Signature Certificate (DSC), Aadhaar eSign, and plain click-to-sign (typed name, drawn signature, or an "I Accept" button). Adira, which publishes this guide, makes contract lifecycle management software, so we have a commercial interest in you signing contracts well, but the comparison stands on its own, whichever tool you use. Short version: DSC and Aadhaar eSign are both legally defined "electronic signatures" that carry a court presumption of authenticity. Click-to-sign forms a valid contract too, but without that presumption, so if the other side denies signing, you carry the burden of proving it was them.
The legal architecture in one paragraph
The IT Act, 2000 recognises two techniques as legally an "electronic signature": a Digital Signature under Section 3 (asymmetric cryptography plus a hash function, tied to a CA-issued certificate) and, more broadly, any Electronic Signature under Section 3A using a technique notified as reliable in the Second Schedule. Aadhaar eSign is one such notified technique, added by government notification in January 2015. A typed name, a scanned signature pasted into a PDF, or a "Click to Accept" button is not on that list. It still creates a binding contract under Section 10A, but it is not, in the Act's own vocabulary, an "electronic signature" at all, just evidence of intent to contract. That distinction is the one thing most people get wrong when comparing these three methods.
Method 1: Digital Signature Certificate (DSC)
A DSC is issued by a Certifying Authority (CA) licensed by the Controller of Certifying Authorities (CCA), the body under the Ministry of Electronics and IT that regulates this space (see the CCA's official site). Licensed CAs include eMudhra, (n)Code Solutions, Capricorn Identity Services, and Sify. The certificate binds a public-private key pair to your identity after in-person or video-based verification, and you sign using a USB crypto token or a cloud-based HSM. Since 1 January 2021 the CCA discontinued the lower-assurance Class 2 category; every DSC issued today is Class 3, the highest identity-assurance class, valid for one to three years and renewable.
Section 3 of the IT Act describes the mechanism:
"Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature. ... The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record." Source: Section 3, Information Technology Act, 2000, Indian Kanoon
Where a DSC is mandatory: MCA filings (incorporation, annual returns, DIN, charge registration), GST registration and returns above certain thresholds, income-tax filings for companies and audited firms, and government e-procurement portals (GeM, CPPP, e-tenders, EPFO, customs). No other method substitutes when a government portal requires it, the requirement is baked into the portal's own rules.
Method 2: Aadhaar eSign
Aadhaar eSign lets you sign electronically using your Aadhaar number and either an OTP sent to your linked mobile or biometric authentication, through the UIDAI's e-KYC system. There is no token to buy or carry. Two intermediaries sit behind the scenes: an eSign Service Provider (ESP), a "trusted third party" integrated with a CCA-licensed CA that generates a one-time key pair and a short-lived certificate for that single transaction, and an Application Service Provider (ASP), the platform where you actually view and sign the document. Currently NSDL e-Governance and CDAC are the entities licensed to issue certificates for Aadhaar eSign.
An Aadhaar eSign is, legally, a Digital Signature under the hood, generated fresh for that one document and then discarded, not reused. That is why it counts as a Section 3A "electronic signature" backed by a real certificate, even though you never see a token.
Section 3A sets the reliability bar a technique must clear to be notified in the Second Schedule:
"A subscriber may authenticate any electronic record by such electronic signature or electronic authentication technique which: (a) is considered reliable; and (b) may be specified in the Second Schedule." Source: Section 3A, Information Technology Act, 2000, Indian Kanoon
Where Aadhaar eSign fits: high-volume, consumer-facing signing, loans, insurance, HR onboarding, SaaS orders, where you need per-transaction identity assurance without asking every signer to buy a DSC token. It is faster and cheaper at scale, but each signer needs Aadhaar linked to a live mobile or biometric enrolment, a real limitation for foreign signatories and NRIs without Aadhaar.
Method 3: Click-to-sign, typed name, drawn signature
This covers everything else: clicking "I Agree," typing your name into a signature field, drawing a signature, or pasting a scanned wet-ink signature into a PDF. None of it uses the Section 3A mechanism, and none gets special status from the IT Act as a "signature." What it does get is contract validity. Section 10A protects the underlying agreement:
"Where in a contract formation, the communication of proposals, the acceptance of proposals, the revocation of proposals and acceptances, as the case may be, are expressed in electronic form or by means of an electronic record, such contract shall not be deemed to be unenforceable solely on the ground that such electronic form or means was used for that purpose." Source: Section 10A, Information Technology Act, 2000, Indian Kanoon
The Supreme Court applied this logic in Trimex International FZE Ltd v Vedanta Aluminium Ltd (2010) 3 SCC 1, where a binding contract for the sale of bauxite was formed entirely through a chain of emails, with no signed document at all, once an unequivocal offer met an unequivocal acceptance; the Court upheld the resulting arbitration clause (see the full judgment on Indian Kanoon). That case is about emails, not click-to-sign, but the principle carries over: Indian courts require evidence of agreement, not a formal signature. A typed name or a click button is exactly that kind of evidence.
What click-to-sign does not get is a presumption of authenticity if the other side later denies it. That gap is the real, practical difference between the three methods, and it shows up in the Evidence Act, not the IT Act.
The evidentiary difference (the part most comparisons skip)
Section 67A of the Indian Evidence Act, 1872 sets the default rule for proving any electronic signature:
"Except in the case of a secure electronic signature, if the electronic signature of any subscriber is alleged to have been affixed to an electronic record the fact that such electronic signature is the electronic signature of the subscriber must be proved."
In plain terms: if you rely on a signature and the signer denies it, you must prove it was them, unless it is a secure electronic signature. Section 85B then flips that burden for secure signatures:
"(1) In any proceedings involving a secure electronic record, the Court shall presume unless contrary is proved, that the secure electronic record has not been altered since the specific point of time to which the secure status relates. (2) In any proceedings, involving secure electronic signature, the Court shall presume unless the contrary is proved that (a) the secure electronic signature is affixed by subscriber with the intention of signing or approving the electronic record ..." Source: Section 85B, Indian Evidence Act, 1872, bare act text (Devgan.in)
A "secure" electronic signature (Section 14 of the IT Act: unique to the signatory, under their sole control, tamper-evident, procedurally certified under Sections 15-16) is what both a DSC and an Aadhaar eSign qualify as. A typed name or click does not, since there is no cryptographic binding to a verified identity behind it.
The test you can run: if the signature came through a CCA-licensed CA's certificate, DSC or Aadhaar eSign, the burden of disproving it sits with whoever challenges it. If it is a typed name, a drawn signature, or a click, the burden of proving it belongs to the signer sits with you, using IP logs, timestamps, OTP records, a platform audit trail, or corroborating conduct like payment made or goods delivered.
Comparison table
| Method | Legal basis | s.85B presumption? | Identity assurance | Typical cost | Best for |
|---|---|---|---|---|---|
| DSC (Class 3) | IT Act s.3, CCA-licensed CA | Yes, if "secure" per s.14-16 | High: in-person/video KYC, tied to a token or HSM, valid 1-3 years | Roughly Rs 1,000-2,500, market rate; verify with the CA | MCA/GST/income-tax filings, e-tenders, GeM, repeat corporate signing |
| Aadhaar eSign | IT Act s.3A, Second Schedule, via ESP/ASP | Yes, if "secure" per s.14-16 | High per transaction: OTP or biometric e-KYC, no reusable token | Per-transaction, billed to the platform/ASP; varies by contract | High-volume consumer signing (loans, insurance, HR, SaaS orders) |
| Click-to-sign / typed / drawn | IT Act s.10A (contract validity only) | No | Low by default; depends on your platform's audit trail | Usually free or bundled into any tool | Low-stakes internal documents, NDAs, quick approvals |
You can mark up which signature method a contract actually needs, clause by clause, for free using Weave, before you commit to a paid e-signing workflow.
When each is required vs merely sufficient
Required, not a choice: MCA/ROC filings, GST portal actions, income-tax e-filing for audited entities, government e-tenders and GeM, and any First Schedule document (a negotiable instrument other than a cheque, a power of attorney, a trust deed, a will, or a sale/conveyance of immovable property) cannot be validly e-signed by any of these three methods, they need wet ink regardless.
Legally sufficient but a judgment call: most commercial contracts, an NDA, a SaaS order, a vendor agreement, do not legally require a DSC or Aadhaar eSign; click-to-sign forms a valid contract under Section 10A. The real question is not "is this legal" but "what happens if the other side later denies signing." For a low-value agreement between parties who already trust each other, click-to-sign with a decent audit trail is fine. For a high-value or new-counterparty deal, or one likely to reach arbitration, the s.85B presumption is worth the extra step, since it removes an entire evidentiary fight before it starts.
Cross-border acceptance
None of India's three methods automatically travels abroad, and no foreign e-signature automatically gets Indian secure-signature status either. A DSC or Aadhaar eSign is recognised inside India, but a US or EU counterparty generally will not treat it as their own jurisdiction's "qualified" signature (for example under eIDAS) absent a mutual-recognition arrangement, which India does not broadly have. Conversely, a foreign click-wrap or a "Standard" DocuSign signature is treated in India the same way an Indian click-to-sign is: valid under Section 10A, without the s.85B presumption, since it was never issued through a CCA-licensed CA. Most Indian companies either accept click-to-sign on both sides with a strong audit trail and a clear arbitration clause, or route only the Indian-facing copy through DSC/Aadhaar eSign.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| Platform logs signer identity, timestamp, and IP address, even for click-to-sign | No audit trail, just a typed name in an emailed document | No evidence to displace the s.67A default burden on you |
| High-value or first-time-counterparty contract uses DSC or Aadhaar eSign | High-value contract signed by a plain click when a dispute is foreseeable | You lose the s.85B presumption exactly when you need it most |
| MCA/GST/government filing uses a valid, current Class 3 DSC | Filing attempted with an expired DSC or a borrowed token | Can invalidate the filing and, for misuse, create personal liability |
| Aadhaar eSign used only where the signer has Aadhaar linked to a live mobile or biometric enrolment | Aadhaar eSign forced on a foreign signer or NRI without Aadhaar | The transaction cannot complete, or the platform silently falls back to click-to-sign, losing the presumption |
| Signature method matches document stakes (DSC/Aadhaar eSign for filings and high-value deals, click-to-sign for low-stakes approvals) | Same low-assurance method used everywhere | Uniform under-signing on high-value documents is an avoidable risk |
| Vendor is transparent about which CA issues the certificate behind their "eSign" feature | Vendor is vague about the CA behind their "eSign" branding | Some "eSign" branding is unauthenticated click-to-sign dressed up to look secure |
A worked example: fixing a weak signature clause
Bad (common in template NDAs and vendor MSAs): "This Agreement may be executed electronically and such execution shall be deemed valid and binding on the parties."
What is wrong: it says electronic execution is fine, which is already true under Section 10A and adds nothing, but it does not specify which method, so there is no way to tell later whether the signature carries the s.85B presumption or not, and no audit-trail requirement at all.
Better: "This Agreement may be executed and delivered electronically. For Agreements exceeding INR [X] in value, or where either party reasonably anticipates dispute, execution shall be by Digital Signature Certificate (Class 3, IT Act s.3) or Aadhaar eSign (IT Act s.3A), each a secure electronic signature under s.14 of the IT Act for purposes of s.85B of the Evidence Act, 1872. For all other Agreements, execution by electronic acceptance (click-to-sign) via [named platform] is sufficient, provided the platform's audit trail (signer identity, IP address, timestamp) is retained for the Agreement's record-retention period."
What changed and why: it names the actual mechanism instead of a vague "electronic execution," ties the choice of method to value or dispute risk, and requires an audit trail when click-to-sign is used, since that trail is your only evidence if the signature is ever challenged.
How this interacts with related pages
Read this alongside Are Electronic Signatures Legally Valid in India (the full IT Act framework this page assumes, Sections 5, 10A, and the First Schedule exclusions) and Is DocuSign Legally Valid in India, which applies this same distinction to a foreign platform used by an Indian company. Whichever method you use, stamp duty on the underlying instrument still applies separately.
FAQ
Do I need a DSC to sign a normal business contract in India? No. A DSC is required for specific filings, MCA, GST, income tax, e-tenders, not private commercial contracts. For a contract, click-to-sign or Aadhaar eSign is legally sufficient; the choice is about evidentiary strength, not permission.
Is Aadhaar eSign the same as a Digital Signature Certificate? Functionally yes, at the moment of signing. Aadhaar eSign generates a one-time certificate through a CCA-licensed CA, tied to that single document, rather than a reusable token you buy and hold. Both qualify as electronic signatures capable of being "secure" under the IT Act.
What happens if I sign with just a typed name and the other party denies it later? The contract is not automatically invalid, Section 10A protects that. But under Section 67A of the Evidence Act, you carry the burden of proving the signature was theirs, using an audit trail or conduct consistent with the contract.
Can a foreign counterparty use Aadhaar eSign or a DSC? Aadhaar eSign needs Aadhaar linked to a live mobile or biometric enrolment, which rules out most foreign signatories. A DSC can technically be issued to a foreign national through some Indian CAs, but it is uncommon. Most Indian companies instead accept the foreign party's own e-signature method with a strong audit trail and a clear dispute-resolution clause.
Does using a DSC or Aadhaar eSign remove the need to pay stamp duty? No. Stamp duty attaches to the instrument itself under the Stamp Act and state stamp Acts, regardless of how it was signed. Signature method and stamping are separate questions.
If my platform says "eSign," is that legally an Aadhaar eSign or DSC? Not necessarily. Many platforms market any electronic signing feature as "eSign" loosely. Check whether it integrates with a CCA-licensed CA; if not, you are getting click-to-sign, not the legally defined Section 3A signature, whatever the button says.
This guide explains how the three signature methods differ under Indian law and when each is required or merely sufficient. It does not tell you which method is right for a specific contract in your specific situation, that depends on the counterparty, the stakes, and your risk tolerance, and is not legal advice. Talk to a lawyer before finalising a signing policy for high-value or high-risk agreements.
Frequently asked questions
- Do I need a DSC to sign a normal business contract in India?
- No. A DSC is required for specific filings, MCA, GST, income tax, e-tenders, not for private commercial contracts. For a contract, click-to-sign or Aadhaar eSign is legally sufficient; the choice is about evidentiary strength, not legal permission.
- Is Aadhaar eSign the same as a Digital Signature Certificate?
- Functionally yes, at the moment of signing. Aadhaar eSign generates a one-time certificate through a CCA-licensed Certifying Authority, tied to that single document, rather than a reusable token you buy and hold. Both qualify as electronic signatures capable of being 'secure' under the IT Act, 2000.
- What happens if I sign a contract with just a typed name and the other party denies it later?
- The contract itself is not automatically invalid, Section 10A of the IT Act protects that. But under Section 67A of the Indian Evidence Act, you carry the burden of proving the signature was theirs, using an audit trail (IP address, timestamp, an OTP-verified click) or conduct consistent with the contract, such as payment or delivery.
- Can a foreign counterparty use Aadhaar eSign or a DSC?
- Aadhaar eSign needs the signer to have an Aadhaar number linked to a live mobile number or biometric enrolment, which rules out most foreign signatories. A DSC can technically be issued to a foreign national through some Indian Certifying Authorities, but it is uncommon. Most Indian companies instead accept the foreign party's own e-signature method with a strong audit trail and a clear dispute-resolution clause.
- Does using a DSC or Aadhaar eSign remove the need to pay stamp duty?
- No. Stamp duty attaches to the instrument itself under the Indian Stamp Act and state stamp Acts, regardless of how it was signed. The signature method and the stamping obligation are entirely separate legal questions.
- If my contract platform's button says 'eSign,' does that mean it is legally an Aadhaar eSign or DSC?
- Not necessarily. Many platforms market any electronic signing feature, including plain click-to-sign, as 'eSign' in everyday language. Check whether the platform integrates with a CCA-licensed Certifying Authority for that signature; if it does not, you are almost certainly getting click-to-sign, not the legally defined Section 3A electronic signature.
Sources
- Section 3, Information Technology Act, 2000 (Digital Signature, asymmetric crypto system)
- Section 3A, Information Technology Act, 2000 (Electronic Signature, Second Schedule)
- Section 10A, Information Technology Act, 2000 (Validity of contracts formed through electronic means)
- Section 85B, Indian Evidence Act, 1872 (Presumption as to secure electronic records and electronic signatures)
- Section 67A, Indian Evidence Act, 1872 (Proof as to electronic signature)
- Controller of Certifying Authorities (CCA), Government of India, official site
- Trimex International FZE Ltd, Dubai vs Vedanta Aluminium Ltd, India, Supreme Court of India, 22 January 2010, (2010) 3 SCC 1
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroom