India's Supreme Court Widened Who Can Sign an Electronic Evidence Certificate. It Didn't Fix Why They Take Months.
Pune Bar Association v. Union of India settled a constitutional question about digital evidence and opened a procedural one.
What the Bharatiya Sakshya Adhiniyam actually changed
On 1 July 2024, the Bharatiya Sakshya Adhiniyam (BSA) replaced the Indian Evidence Act, 1872, the statute that had governed what counts as admissible proof in an Indian court for a century and a half. Most of the Act's structure survived the rename intact. Section 65B, the clause deciding whether printouts, emails, and database records could be used as evidence, became Section 63, and the electronic evidence certificate it requires got noticeably harder to produce. The substance carried over almost line for line, with one significant addition that took nearly two years to reach the Supreme Court.
Section 65B existed because electronic records aren't self-authenticating the way an original paper document is. A PDF, a chat export, or a server log can be edited without leaving an obvious trace, so the law requires someone to vouch for it: that the record came from a device operating normally, that it accurately reflects what was fed into it, and that nobody altered it afterward. Since 2000, that vouching has taken the form of a certificate. Since July 2024, that certificate has gotten harder to produce.
The two-part electronic evidence certificate nobody reads until they need one
Under the old Section 65B, one person, anyone occupying "a responsible official position in relation to the operation of the device," could sign a single certificate and the electronic record was in. There was no prescribed form, no hash value, no named technical expert. Courts spent two decades litigating what a valid 65B certificate looked like, and defects in that one signature were a routine way for otherwise solid evidence to get thrown out.
Section 63(4) of the BSA replaced that with a two-part certificate laid out in a statutory Schedule. Part A is completed by whoever controls the device or system the record came from, and it now has to disclose the record's hash value, a cryptographic fingerprint that changes if a single byte is altered. Part B has to be signed separately by an "expert" who verifies that fingerprint and the integrity of the record. One signature became two, a discretionary description became a fixed form, and a document that used to need no cryptography now needs a hash value attached before anyone examines it.
Why courts already had zero tolerance for a bad certificate
Section 65B's certificate requirement was contested territory long before the BSA existed. In Anvar P.V. v. P.K. Basheer (2014), a three-judge bench of the Supreme Court held that Section 65B operates as a complete, mandatory code for electronic evidence: without a valid certificate, a court could not even weigh a WhatsApp message, a call record, or a CCTV export, no matter how relevant it looked. Lower courts spent the next few years testing how strictly that rule applied, including a brief window where a party without control over the source device could argue the certificate wasn't required at all.
That window closed in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020), where a larger three-judge bench reaffirmed the mandatory reading and shut down the exceptions lower courts had been carving out. By the time the BSA arrived in 2024, Indian courts had already spent a decade treating a missing or defective certificate as fatal to a case, not a technicality to be waived. That is the backdrop against which Section 63(4) added a second signature and a hash requirement: a regime with no tolerance for paperwork errors just made the paperwork harder to get right.
Pune Bar Association's challenge, and what the Supreme Court actually ruled
The Pune Bar Association took Section 63(4) to the Supreme Court, arguing that the provision, read with its Schedule, was unconstitutional on a practical basis: finding a qualified "expert" to sign Part B was genuinely difficult, because the government had notified only a small number of laboratories as Examiners of Electronic Evidence under Section 79A of the IT Act, 2000. India has 27 state forensic science laboratories and 7 central ones; only a fraction of that combined total carries the Section 79A notification that, on one reading of the law, made them the sole source of a valid expert signature. For a litigant outside a handful of cities, the association argued, that requirement functioned less like a safeguard and more like a bottleneck.
On 22 May 2026, a Supreme Court bench rejected the constitutional challenge. The Court found no manifest arbitrariness in requiring a hash value and an expert signature: authenticity checks on digital evidence are a legitimate legislative objective, the bench reasoned, not an undue burden. Section 63(4) stayed exactly as written.
The "expert" question the Court answered, and the one it didn't
The more consequential part of the ruling wasn't the constitutional holding. It was what the Court said about who Part B's "expert" actually has to be. Reading Sections 39(1) and 39(2) of the BSA together, the bench held that the certifying expert isn't confined to the list of Section 79A-notified examiners: any other person with demonstrable special skill and expertise in computer science can sign Part B, provided the trial court is satisfied of that expertise. In one ruling, the pool of people who can legally certify electronic evidence in India went from a short government list to, in principle, anyone a judge is willing to accept.
What the Court did not do is say how a trial judge should decide that question. It explicitly declined to rule on whether Part B still requires a Section 79A-notified examiner in particular kinds of cases, or what counts as demonstrable expertise when the person offering it isn't on any official list. That determination now happens case by case, in front of whichever judge hears the matter, which means the same in-house engineer who qualifies as an expert witness in one courtroom could be rejected in another, and nobody finds out until the certificate is already filed.
| Dimension | Section 65B, IEA | Section 63 BSA |
|---|---|---|
| Signatories required | One | Two: device custodian (Part A) and expert (Part B) |
| Hash value disclosure | Not required | Required in Part A |
| Certificate format | No prescribed form | Fixed statutory Schedule |
| Who can sign the expert part | Not specified | Any person with demonstrable computer-science expertise, per the court's satisfaction |
| Main litigation risk | Defective single signature | Same risk, doubled across two signatures and a hash mismatch |
Why the examiner shortage is the real bottleneck, not the statute
The ruling reads as a win for practicality: more people can now sign Part B, which should mean shorter queues. But it doesn't change the underlying supply problem the Pune Bar Association was actually pointing at. The government kept adding to the Section 79A list through 2026, including several new labs notified in the middle of the year, one of them the Border Security Force's Special Instruments Wing, covering drone forensics. Even with those additions, the formally notified list remains a small subset of India's roughly three dozen government forensic laboratories, against a rapidly growing volume of digital-evidence disputes every year.
Widening the definition of "expert" doesn't add capacity. It moves the bottleneck from "is this lab on the government list" to "will this specific judge accept my witness." A company with an in-house forensics function or a digital-forensics vendor on retainer can absorb that uncertainty. A smaller litigant, or a company that only discovers it needs a Part B signature after a dispute has already started, is now negotiating expert credibility in open court instead of checking a published list, a different kind of friction, not necessarily a smaller one.
What this means for how companies keep records today
The practical lesson from Pune Bar Association has less to do with courtroom strategy and more to do with logging. A hash value disclosed after the fact, once litigation has already started, is weaker evidence than one generated the moment the record was created. Systems that timestamp, hash, and store an audit trail as records are made, rather than reconstructing one under deadline pressure, give Part A's custodian something they can actually stand behind. Any platform that produces electronic records as part of normal operation, from HR software to accounting systems to document and e-signature platforms such as FlowVerify, is effectively generating that Part A material continuously, whether or not it is ever pulled into a courtroom.
The Part B half is harder to prepare for in advance, because it now depends on one judge's comfort with one witness rather than a name on a government list. The closest thing to a hedge is knowing, before a dispute starts, whether the internal staff who understand a system well enough to testify to its integrity have any documented credentials to point to: a certification, a forensics background, anything beyond having administrator access. That's a cheap thing to establish ahead of time and an expensive thing to improvise during a hearing.
The open question
Pune Bar Association settled the constitutional question and opened a procedural one. It follows a decade in which Anvar P.V. and Arjun Panditrao already taught Indian litigants that a missing certificate kills a case outright, whatever else the evidence shows. Every company that keeps electronic records, which is every company, now has a wider set of people who can vouch for those records in court, and a less certain answer for which of those people any given judge will actually accept until the next round of cases works through the trial courts.
Until that happens, the safest position is the boring one: capture the hash when the record is made, document who had custody of it, and identify a credible technical witness before a dispute forces the question. None of that requires a Section 79A notification. It just requires doing before litigation what the certificate used to let people improvise during it.
Frequently asked questions
Related reading
Chardet's AI Clean-Room Rewrite Didn't Just Change a License. It Broke How Copyleft Gets Enforced.
Chardet moved from LGPL to MIT after an AI-assisted "clean room" rewrite. The plagiarism argument is a distraction from the actual break: AI has collapsed the cost that made copyleft enforceable.
India's DSC Rules Changed Again in 2026. The Headline Everyone's Repeating Is Five Years Old.
Most 2026 DSC explainers repeat a 2021 policy. The genuine change is video-based identity verification and cloud-hosted Class 3 certificates, and it breaks a quiet assumption inside a lot of signing integrations.
The AI Notetaker Lawsuits Aren't About Recording. They're About Who Gets Told.
A 2026 wave of lawsuits against AI meeting notetakers turns on two design choices, not on recording itself: whether the bot visibly joins the call, and whether transcripts train models afterwards.