Digital signature certificates and signing setup

Registrations and licences

·

On demand

A digital signature certificate must match both the person signing and the system on which it will be used. TheTaxCo identifies the required certificate, coordinates the application and issuance through a licensed certifying authority, and handles installation, portal association and signing-error follow-up.

This service covers a new signer, certificate renewal, replacement after compromise or loss, and problems connecting a valid certificate to a portal. We begin with the actual intended use rather than recommending the same certificate for every person.

Certificate, authority and portal access are separate

The certificate connects a public key with the subscriber’s verified identity. A digital signature allows verification of the signer and whether the signed electronic record has changed. Certificates are issued through the licensed certifying-authority framework. The target system determines the certificate attributes and signing method it accepts. Controller of Certifying Authorities FAQ.

A valid certificate does not itself appoint the holder as a company’s authorised signatory. The organisation must separately grant and maintain that authority. Portal association is another step: an otherwise valid certificate may fail if the profile, role or registration has not been updated.

An inactive company can still have filings requiring an authorised signature. Low transaction activity is therefore not a reason, by itself, to let all certificates expire. We check the upcoming filing requirements and the available authorised signers.

What the setup includes

We record the portals and transactions the signer needs, compare their requirements with the proposed certificate, and check identity consistency. Spelling, organisation details and identity-record mismatches should be resolved before issuance where they affect the application.

The subscriber completes the issuer’s identity verification and retains control of the signing credential. We coordinate the installation and test process appropriate to the token or supported signing arrangement, and complete the portal-association steps with the authorised holder. Remote signing and a USB token are not interchangeable on every portal.

You receive a certificate-use checklist, installation and test record, and a register of holder, issuer, expiry and intended use. The register should not contain private keys or access secrets. Each signing request still needs the holder’s authority over the final document.

Handling a departing signatory

When a director or employee leaves, review their organisational authority and portal roles promptly. Separately assess whether a certificate needs revocation because it is compromised, inaccurate or otherwise subject to the issuer’s revocation conditions. A person’s departure does not automatically invalidate every personal certificate they hold.

The replacement signatory needs their own valid certificate and the appropriate appointment or authorisation. Collecting someone else’s token does not transfer their identity or signing power to the replacement. The handover should record completed filings, pending work and updated permissions.

Information needed and delivery time

At first we need the intended signer role, target portals and the next signing deadline. After scoping, we request the issuer’s identity and organisation documents and details of any existing certificate or error message.

Issuance depends on the certifying authority’s identity checks. Setup time also depends on the device, operating system, portal utility and role records. We agree the support scope after checking these items; a fixed same-week completion is not promised without that review.

We also handle renewal, replacement and setup on additional devices. Encryption requirements and the supported signing arrangement are checked against each intended use.

Questions before purchase or renewal

Can a scanned signature serve the same purpose? A signature image does not supply the cryptographic checks required where the portal calls for a DSC. Use the signing route accepted for the particular transaction.

Do we need signing-only or signing with encryption? That depends on the system and use. We check the documented requirement before the certificate is ordered.

Our certificate is valid but signing fails. The cause may be the utility, browser, token driver, certificate association or signer role. The error message and expiry details help narrow the issue before buying a replacement.

Can another director sign while a certificate is renewed? Only if that person is authorised for the transaction and meets the portal’s requirements. A valid certificate alone is insufficient.

See company annual filings, director KYC and incorporation support.

Email TheTaxCo, message us on WhatsApp or book a call. Share the portal name, signer role, next deadline and whether you need a new certificate, renewal or help with an error.