Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
Goods and Services Tax

GSTN Advisory on emSigner v3.3 and FIPS 140-3 Migration

Advertisement

Summary: The GSTN advisory dated September 19, 2026 provides advance information to taxpayers and tax officers using Digital Signature Certificates (DSCs) on the GST Portal regarding the availability of emSigner version 3.3. The new version is intended to provide compatibility with USB dongles issued on or after September 21, 2026. Users whose existing DSCs and tokens continue to work normally may continue using their current emSigner version, while users experiencing signing failures or certificate-selection issues may upgrade to version 3.3, which is stated to be backward compatible with existing tokens. Users receiving newly issued or renewed certificates in new dongles on or after September 21, 2026 are required to upgrade to emSigner v3.3. The advisory also specifies minimum system requirements, including a 64-bit operating system, 8 GB RAM, 64 GB storage and Java 1.8, with Java 9 and above unsupported. It further refers to the CCA advisory concerning migration from FIPS 140-2 to FIPS 140-3. The accompanying migration advisory explains that FIPS 140-3 supersedes FIPS 140-2 and establishes a transition framework for cryptographic modules, including crypto tokens, HSMs and secure elements. It states that DSCs downloaded onto FIPS 140-2 dongles on or before September 21, 2026 may continue until expiry, subject to specified exceptions, while fresh issuance and renewal generally require FIPS 140-3 modules. The migration objective is to retire or replace non-compliant or obsolete cryptographic components by September 21, 2029. The advisory also sets out responsibilities for OEMs, distributors, Certifying Authorities, government organisations and other users, along with an applicability matrix and a model acknowledgement and risk-assessment letter for continued use of FIPS 140-2 modules in permitted circumstances.

Goods and Services Tax
Government of India, States and Union Territories

Advisory on use of version 3.3 of emSigner

Sep 19th, 2026

This is an advance information to the all users – Taxpayers and Tax Officers, of GST System who use Digital Certificate Signature on the GST Portal.

A new version of emSigner (v3.3) is being made available for download for the purpose of providing compatibility with tokens (USB dongles) that are issued on or after 21-September-2026.

A. Users with valid certificates: There is no change for the users having existing valid digital certificates and their existing token (USB Dongle) are working, as of 21-Sep-2026. If your existing DSC works normally, you may continue using your current emSigner version.

If you encounter signing failures or if your certificate does not appear for selection despite correctly installed token drivers, upgrade to the emSigner version 3.3 by following steps given under point-B below. The emSigner version 3.3 is backward compatible to support the existing tokens (USB dongles).

B. Users with newly issued tokens: The users who have been issued a new token (USB Dongle) on or after 21-Sep-2026, either due to issuance of new certificate and dongle, or renewal of certificate in a new dongle, shall have to upgrade to version 3.3 of emSigner by following below steps:

Step-1. Please ensure that your system – desktop / laptop / AIO which on which the DSC is used for the GST System, meets the following minimum system requirements:

1.1 Operating system and hardware

Item Requirement
Operating system Windows 10 or 11 (64-bit); Linux (Ubuntu 18 and above); macOS (10.6 and above)
System type 64-bit operating system
Installed RAM 8 GB and above
Storage 64 GB and above

1.2 Java

Item Requirement
Java runtime Java 1.8 – OpenJDK or Oracle
Availability Java must be pre-installed; it is not bundled with the installer
Higher versions Java 9 and above are not supported

1.3 Browser

Browser Supported version
Internet Explorer 10.0 and above
Firefox 6.0 and above
Chrome 16.0 and above
Safari 6.0 and above
Opera 12.1 and above
Microsoft Edge Since first version

Step-2. Download & install the version 3.3 of emSigner from the GST Portal by navigating to https://www.gst.gov.in/help/docsigner-the older versions of emSigner will not work for such new DSC dongles issued from 21 September 2026 onwards.

C. Validity and future renewal: Under CCA’s advisory, DSCs downloaded onto FIPS 140-2 dongles on or before 21 September 2026 can continue to be used until the DSC expires. That date does not automatically invalidate existing DSCs. Subsequent renewal or fresh issuance generally requires a FIPS 140-3 dongle, subject to CCA’s specified exceptions. The CCA migration advisory may be referred for more details on this aspect by navigating to [https://cca.gov.in/sites/files/pdf/news/Advisory_on_Migration_from_FIPS_140-2_to_FIPS_140-3.pdf](https://cca.gov.in/sites/files/pdf/news/Advisory_on_Migration_from_FIPS_140-2_to_FIPS_140-3.pdf)

Please create a ticket on the GST Helpdesk if you need any assistance while upgrading to the emSigner version 3.3 and our teams shall get in touch for resolution.

Thanks,
Team GSTN

Advisory Note on FIPS 140-2 to FIPS 140-3
Migration

Introduction

This document outlines the certifying authority and organisation-wide strategy to migrate cryptographic modules and dependent systems from FIPS 140-2 to FIPS 140-3. The objective is to ensure continued regulatory compliance, maintain security assurance, minimize operational disruption, and align cryptographic controls with current international standards (ISO/IEC 19790:2012 and ISO/IEC 24759:2017).

FIPS 140-2 validations are being sunset, and new validations are required under FIPS 140-3. This migration document defines scope, governance, timelines and execution phases.

Background and Drivers

FIPS 140-3 supersedes FIPS 140-2 and is mandatory for new cryptographic module validations.

Why FIPS 140-3?

As it aligns with international ISO standards and introduces updated requirements, which would enhance security for:

  • Non-invasive attack mitigation
  • Software module validation
  • Entropy and random bit generation
  • Lifecycle assurance
  • Reduction of compliance and audit risk
  • Improved cryptographic assurance and resilience, Non-proprietary Standards.
  • Alignment with modern platforms (containers, virtualization).

This document is for all stake holders, OEMs, Distributers, Vendors or any other association of persons/company etc operating in India who are being advised to achieve FIPS 140-3 validation for all in-scope cryptographic modules (Crypto Tokens, HSM, Secure elements etc) before 21 September 2026, to ensure uninterrupted service for products and internal systems relying on cryptography.

Objectives

The objective of this exercise is to retire or replace non-compliant or obsolete cryptographic components in use, completely by 21 September 2029 as no further updates for FIPS 140-2 would be available after 21 September 2026.

In addition, the objective is to establish sustainable cryptographic governance for future standards/updates.

Scope

This migration document applies to PKI ecosystem operational under CCA’s jurisdiction and includes:

  • All software, firmware, hardware, and hybrid cryptographic modules.
  • Third-party products and services claiming FIPS compliance.
  • Internal applications, platforms, and infrastructure that rely on FIPS-validated cryptography.

By ensuring, the stockholders first prepare a CBOM for establishing a trusted supply chain.

Ref: TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf by Cert-In

What happened to FIPS 140-2

*Source NIST “Applicability of Validated Modules

FIPS 140-3 validations are currently being accepted. Upon validation, modules will be placed on the Active list for 5 years (or 2 years for Interim Validations) and may be used for new and existing systems.

Modules validated as conforming to FIPS 140-2 can continue to be accepted by the Federal agencies of both countries for the protection of controlled unclassified information (United States) or Designated Information (Canada) through September 21, 2026. After that time CMVP will place the FIPS 140-2 validated modules on the Historical list, allowing agencies to continue using these modules for existing systems only. Agencies should continue to make use of FIPS 140-2 modules until replacement FIPS 140-3 modules become available”.

Path ahead

For enhanced security and compliance CCA advices all Certifying Authorities to adopt the benefit of FIPS 140-3 modules as early as possible for assuring enhanced security within the Indian jurisdiction.

Accordingly, CAs should ensure to stop issuance of DSC in FIPS 140-2 modules by 21 September 2026. The DSC which are downloaded in FIPS 140-2 modules on or before 21 September 2026 will remain in operation till the expiry of the DSC and no longer be used for renewal or fresh download of DSC thereafter.

Exception – in cases, where an active DSC requires reissuance to the same user, by following due process, CA’s may issue DSC on or after 21 September 2026 in FIPS 140-2 module for the remaining validity of the DSC (one time only) without any cost to user.

OEMs/Distributers of Cryptographic modules are advised to publish buy back or exchange policy clearly on their respective website regarding replacement of FIPS 140-2 modules with FIPS 140-3 modules.

CA’s are advised to update their price list for FIPS 140-3 modules and also publish exchange or buy back rates (with information to O/o CCA, by Mar 2026).

CA’s/OEM/relying parties are also advised to widely publicize this advisory along with their exchange policy and price list to relying parties/public at large.

Exception- for specific cases where in the Government organisation only, after considering their security policy choose to continue with FIPS 140-2 modules (but not after 21 September 2029), CA’s may issue DSC to such specific govt organisation in FIPS 140-2 modules. In such cases CA should collect the risk and compliance waiver from relying party authorised officer with the approval from their concerned Ministry (format attached, annexure -2). CAs should inform and provide a written list of such organisations to the office of CCA on quarterly basis for continuation.

It may be noted that,O/o CCA has stopped accepting fresh audit application for FIPS 140-2 modules w.e.f 1st January 2026.

Key Differences: FIPS 140-2 vs FIPS 140-3

Area FIPS 140-2 FIPS 140-3
Basis Proprietary standard ISO/IEC 19790 & 24759
Algorithm Validation CAVP CMVP aligned with ISO
Testing Vendor interpretation Strict lab-driven testing
Security Levels 1–4 1–4 (clarified & stricter)
Software Modules Less Prescriptive Stronger lifecycle & integrity controls
Legacy algorithms Many allowed Deprecated or disallowed
Software integrity Basic Explicit integrity mechanism
Firmware protection Limited Mandatory authenticated updates
Key storage definition Implicit, loosely described Explicitly defined security boundary
Storage location Often vague Must be clearly identified and justified
Boundary enforcement Assumed Formally enforced and validated
Plaintext keys in memory Commonly accepted Strongly restricted
Protection expectation Reasonable Explicit cryptographic protection required
Encryption of stored keys Optional in some cases Mandatory unless justified
Key-wrapping standards Flexible Strict use of approved key-wrapping algorithms
Access controls High-level Role-based and enforceable

Conclusion

Migrating from FIPS 140-2 to FIPS 140-3 is a strategic security compliance. By following a structured, risk-based approach with strong governance and early engagement of certification bodies, the organisation can achieve compliance while strengthening its cryptographic posture and future-proofing its platforms.

Annexure-1

FIPS 140-3 module Applicability matrix

Relying Parties Compliance Activity Exception
OEM/Distributer Mandatory CCAs Audit requirement to be completed by May 2026 for FIPS 140-3 modules No
Certifying Authority Mandatory Integration of FIPS 140-3 and compliance audit by July 2026 No
Government Organisation Optional up to 21 sept 2029 With approval from their concern ministry Risk analysis and acceptance No exception beyond cutoff date
Other User Optional

Annexure -2

[On Organisation Letterhead]

Date: [DD Month YYYY]

Subject: Acknowledgement of CCA Advisory and Risk Assessment for Continued Use of FIPS 140-2 Validated Modules

To

[Certifying Authority / Customer Name]
[Organisation Name]

Subject: Acknowledgement of CCA Advisory and Risk Assessment for Continued Use of FIPS 140-2 Validated Cryptographic Modules

Dear [Sir / Madam / Recipient Name],

This letter is to formally confirm that [Organisation Name] has reviewed and understood the advisory issued by the Controller of Certifying Authorities (CCA) regarding the transition from FIPS 140-2 to FIPS 140-3 validated cryptographic modules which enhance security.

Following receipt and review of the advisory, [Organisation Name] has conducted its own independent risk assessment and impact analysis covering technical, operational, security (Confidentiality, integrity & availability), regulatory, and business considerations associated with the continued use of FIPS 140-2 validated cryptographic modules in our environment.

Based on this assessment, and considering the current scope of usage, threat landscape, compensating controls, vendor roadmaps, and system lifecycle constraints, [Organisation Name] has determined that the continued use of existing FIPS 140-2 validated modules remains appropriate at this time and does not introduce unacceptable risk to confidentiality, integrity, or availability of our systems and data.

This decision has been taken with the following considerations:

  • The cryptographic modules in use remain validly certified under FIPS 140-2 and are operating in approved modes but not after 21 Sept 2029.
  • No known vulnerabilities so far / as on date have been identified that would materially increase risk due to the continued use of FIPS 140-2 modules.
  • Appropriate compensating security controls are in place to mitigate identified risks.
  • A planned and controlled transition strategy towards FIPS 140-3 validated modules is under evaluation in the organisation and will be implemented in alignment with regulatory expectations, vendor availability, and operational feasibility.

[Organisation Name] acknowledges that FIPS 140-3 represents the latest standard, is more secure and confirms its commitment to completely migrate to FIPS 140-3 validated modules within an appropriate and risk-managed timeframe latest by 21 sept 2029, or earlier if there are material changes in regulatory guidance, threat conditions, or system architecture. The current decision shall be periodically reviewed.

This letter is issued as a formal record of our due diligence and risk-based decision-making process.

Should you require any additional information or clarification, please feel free to contact [ Certifying Authority representative name, email and phone].

Yours faithfully,

[Name]
[Designation]
[Organisation Name]
[Contact Information]

Advertisement

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *