Major DSC Token Upgrade from 21September 2026: FIPS 140-3 Level 3 Compliance

Important Update for Digital Signature Certificate Users
A major security upgrade is being introduced for Digital Signature Certificate (DSC) tokens
from 21 September 2026.
Existing DSC tokens currently available in the market are generally based on FIPS 140-2
Level 2 compliance. With the new upgrade, the token version will move to FIPS 140-3 Level 3 compliance, providing a higher level of security for storing and protecting digital certificates.

DSC Token upgrade

Important: Existing FIPS 140-2 Tokens
Users who are currently using FIPS 140-2 Level 2 compliant tokens should take note of
the transition date.
According to the announced change, existing FIPS 140-2 tokens can be used for
downloading certificates only up to 21 September 2026. After this date, new Digital Signature Certificates may not be downloadable using the older FIPS 140-2 Level 2 tokens.
Therefore, users who need to obtain or renew a DSC should plan their token requirements in
advance.

What Is FIPS 140?

FIPS 140 is a security standard used to evaluate cryptographic modules and hardware devices that protect sensitive cryptographic information.
DSC tokens use secure hardware to store digital certificates and private keys. Compliance
with FIPS standards helps establish security requirements for protecting this sensitive
information.
The transition from FIPS 140-2 Level 2 to FIPS 140-3 Level 3 represents an important step
toward stronger hardware-based security.

FIPS 140-2 Level 2 vs FIPS 140-3 Level 3

The new token generation is designed to provide a higher level of physical and security
protection.

The exact features and certification of individual token models may vary by manufacturer, so
users should confirm the compliance details of the token being supplied.

What Does This Mean for Existing DSC Users?

If you already have a DSC token based on FIPS 140-2 Level 2, you should not assume that
the token will continue to support downloading new certificates after the transition date.
Existing users should consider the following situations:

1. Your DSC is currently working
If your existing DSC is valid and you are using it for activities such as GST filing, income tax
filing, EPFO, tenders or other online services, you can continue using it according to the
applicable certificate validity and service requirements.
However, if you need to download a new certificate or renew/replace your DSC, the new
token requirements should be considered.
2. Your DSC is going to expire
If your DSC is approaching expiry, it is advisable to check your renewal requirements before
the transition.
Planning ahead can help avoid delays in obtaining a new certificate.
3. You need a new DSC
If you are applying for a new Digital Signature Certificate after the effective date, you may
need a FIPS 140-3 Level 3 compliant token, depending on the certificate provider and
applicable requirements.
4. You have multiple DSCs
Businesses that maintain several DSCs for directors, partners, employees, authorised
signatories or tender users should review their existing tokens and plan the transition
accordingly.

Why Is the Token Upgrade Important?

Digital Signature Certificates are used for many important online activities. The private key
stored inside the DSC token must be protected against unauthorised access.
The move toward FIPS 140-3 Level 3 is intended to provide stronger security controls for
cryptographic hardware.
This is particularly relevant for organisations that use DSCs for:

  • GST return filing
  • Income Tax filing
  • EPFO-related activities
  • Government tenders
  • Railway tenders
  • e-Procurement
  • MCA filings
  • Digital document signing
  • Company and organisation-related filings
  • DGFT services
  • Other government and business portals

Who Should Pay Attention to This Update?

This update is particularly important for :

  • Companies
  • Directors
  • Proprietors
  • Partnership firms
  • Chartered Accountants
  • Tax professionals
  • Company Secretaries
  • Advocates
  • Government contractors
  • Tender participants
  • Importers and exporters
  • HR and payroll professionals
  • Accounts departments
  • Organisations using multiple DSCs

If your business depends on digital signatures for regular compliance or tender activities, it is
better to review your DSC token requirements before the transition.

What Should You Do Before 21 September 2026?

Users with existing FIPS 140-2 tokens should review their DSC requirements and take appropriate action.
Recommended checklist
1. Check your existing token
Find out whether your current DSC token is FIPS 140-2 Level 2 compliant.
2. Check DSC expiry
Verify the expiry date of your Digital Signature Certificate.
3. Check upcoming requirements
If you have GST, income tax, EPFO, tender, DGFT or other filings coming up, plan your DSC
requirements accordingly.
4. Consider the new token
If you need a new certificate after the transition, check whether a FIPS 140-3 Level 3 compliant token is required.
5. Avoid last-minute renewal
Businesses should avoid waiting until the certificate expires or an urgent tender submission is due.

Will My Existing DSC Stop Working?

Not necessarily.
The transition should not be interpreted as meaning that every existing FIPS 140-2 token will
immediately stop functioning.
The key issue is the ability to download new certificates using the older FIPS 140-2 Level
2 token after the specified transition date.
Existing certificates may continue to work according to their validity and the requirements of
the relevant application or service.
Users should therefore distinguish between :
Using an existing certificate and Downloading a new certificate onto the token.
For a specific certificate or token, users should confirm the applicable requirements with their
DSC service provider.

Upgrade to the New Generation of DSC Tokens

The transition to FIPS 140-3 Level 3 compliant tokens is an important development in Digital Signature Certificate security.
If you are using an older FIPS 140-2 Level 2 token and expect to obtain a new DSC, renew an existing DSC or manage multiple digital signatures, planning the token upgrade in advance can help prevent unnecessary delays.
At Digital Signature Kerala, we help individuals, businesses and organisations with Digital
Signature Certificate requirements across Kerala.
Our services include :

  •  Class 3 Digital Signature Certificate
  • Organisation DSC
  • DGFT DSC
  • DSC for GST and Income Tax
  • DSC for Government Tenders
  • DSC for Railway Tenders
  • DSC for EPFO
  • DSC for foreign nationals
  • DSC token-related assistance
  • Digital signature renewal and support

Need Help With Your DSC Token Upgrade?

If you are currently using an FIPS 140-2 Level 2 token and are unsure whether you need to upgrade, contact a DSC service provider and verify your certificate and token requirements before applying for a new certificate.
Plan your DSC requirements early and be prepared for the transition to FIPS 140-3
Level 3 compliant tokens.

Frequently Asked Questions

The token version is being upgraded from the existing FIPS 140-2 Level 2 generation toward
FIPS 140-3 Level 3 compliant tokens.

Existing tokens may continue to be used for existing certificates, subject to the applicable
certificate and software requirements. However, new certificate downloads using FIPS 140-2
Level 2 tokens may not be supported after 21 September 2026.

Not necessarily. The need to replace the token depends on whether you need to download a
new certificate and the requirements applicable to your certificate provider.

FIPS 140-3 Level 3 is a higher security level under the FIPS 140 standard for cryptographic
modules, with stronger security requirements than Level 2.

Businesses should review all their DSC tokens, check certificate expiry dates and identify
certificates that may need renewal or replacement.

Yes. Organisations and individuals who regularly use DSCs for government and railway
tenders should plan ahead because delays in obtaining a required certificate can affect
time-sensitive submissions.

Leave a Comment

Your email address will not be published. Required fields are marked *