
The Goods and Services Tax Network (GSTN) has issued an important Advisory No. 672 dated September 19, 2026 for taxpayers and tax officers using Digital Signature Certificates (DSCs) on the GST Portal, announcing the availability of emSigner version 3.3. The upgraded version has been introduced to provide compatibility with new DSC tokens/USB dongles issued on or after 21 September 2026.
No Change for Existing Valid DSC Holders
GSTN has clarified that taxpayers and tax officers whose existing Digital Signature Certificates and USB tokens are valid and working normally as on 21 September 2026 are not required to immediately upgrade. Such users may continue using their existing version of emSigner. However, where the DSC fails to sign or the certificate does not appear for selection despite proper installation of token drivers, users should upgrade to emSigner v3.3, which is backward compatible with existing DSC tokens.
emSigner v3.3 Mandatory for New DSC Tokens Issued from 21 September 2026
Where a taxpayer or officer is issued a new USB token on or after 21 September 2026, whether on account of a fresh DSC or renewal of a certificate in a new dongle, GSTN has stated that emSigner version 3.3 must be installed. Older versions of emSigner will not work with such newly issued DSC dongles.
Minimum System Requirements for emSigner v3.3
Before installing the new version, GSTN has advised users to ensure that their desktop, laptop or AIO system meets the prescribed requirements. The supported operating systems include Windows 10 or 11 (64-bit), Ubuntu Linux 18 and above, and macOS 10.6 and above. A 64-bit operating system, minimum 8 GB RAM and 64 GB storage have been prescribed.
Further, Java 1.8 – OpenJDK or Oracle is required and must be pre-installed, as Java is not bundled with the installer. Significantly, Java 9 and above are stated to be unsupported under the advisory.
Existing FIPS 140-2 DSCs Will Not Become Invalid on 21 September 2026
A major clarification is that 21 September 2026 is not an automatic expiry date for existing DSCs. DSCs downloaded onto FIPS 140-2 compliant dongles on or before 21 September 2026 may continue to be used until the respective DSC expires. Thereafter, renewal or fresh issuance would generally require migration to a FIPS 140-3 compliant token, subject to specified exceptions.
CCA Directs Shift from FIPS 140-2 to FIPS 140-3
The transition follows the advisory of the Controller of Certifying Authorities (CCA) for migration of cryptographic modules from FIPS 140-2 to FIPS 140-3. FIPS 140-3 supersedes FIPS 140-2 for new cryptographic module validations and aligns cryptographic controls with the international standards ISO/IEC 19790:2012 and ISO/IEC 24759:2017.
The CCA advisory states that stakeholders, including OEMs, distributors and vendors operating in India, have been advised to move in-scope cryptographic modules, including crypto tokens, HSMs and secure elements, toward FIPS 140-3 so as to ensure uninterrupted functioning of systems dependent on cryptography. The broader objective is to completely retire or replace non-compliant or obsolete cryptographic components by 21 September 2029.
Certifying Authorities to Stop Issuing DSCs on FIPS 140-2 Modules
As part of the migration, the CCA has advised Certifying Authorities (CAs) to stop issuing DSCs in FIPS 140-2 modules by 21 September 2026. However, DSCs downloaded into FIPS 140-2 modules on or before that date will remain operational until their expiry and cannot thereafter ordinarily be used for renewal or fresh DSC download.
One-Time Reissuance Exception for Existing DSCs
The CCA has provided a limited exception where an active DSC needs to be reissued to the same user. In such cases, after following due process, the Certifying Authority may issue the DSC in a FIPS 140-2 module on or after 21 September 2026 for the remaining validity period of the existing DSC, one time only and without charging the user.
Special Relaxation for Government Organisations up to 21 September 2029
A further exception has been provided for specified Government organisations which, after considering their security policy, decide to continue using FIPS 140-2 modules. Such continuation is permissible only up to 21 September 2029, subject to approval of the concerned Ministry and obtaining the prescribed Risk and Compliance Waiver. Certifying Authorities are also required to furnish details of such organisations to the CCA on a quarterly basis.
OEMs and Distributors Asked to Publish Buy-Back/Exchange Policies
The CCA has also advised OEMs and distributors of cryptographic modules to clearly publish on their websites their buy-back or exchange policies for replacement of FIPS 140-2 modules with FIPS 140-3 modules. Certifying Authorities have similarly been advised to update the price lists for FIPS 140-3 modules and publish the applicable exchange/buy-back rates.
What Taxpayers Should Do Now
Accordingly, taxpayers whose existing DSC and dongle are functioning normally need not replace them merely because of the 21 September 2026 transition date. However, taxpayers procuring a new DSC token/dongle from 21 September 2026 onwards should install emSigner v3.3 and ensure that their computer meets the specified system and Java requirements. GSTN has advised users facing difficulty during the upgrade to raise a ticket with the GST Helpdesk.
The Advisory can be accessed at: https://www.gst.gov.in/newsandupdates/read/672


