Certification authority
A certification authority (CA) is an organization that creates, issues and maintains certificates of electronic signature verification keys, acting as a trusted party between the signature owner and the systems where it is used.
Contents
- What is a certification authority in simple words
- Main functions of a certification authority
- What signatures does a CA issue
- Non-qualified electronic signature (NES)
- Qualified electronic signature (QES)
- Enhanced qualified electronic signature (EQES)
- How to check the legitimacy of a certification authority
What is a certification authority in simple words
A certification authority (CA) is a specialized organization (government or commercial) that issues certificates of electronic signature (ES) verification keys. It acts as a trusted intermediary between the signature owner and those who will verify signed documents.
In simple words: a certification authority is like a digital notary. It verifies your identity and issues you an “electronic certificate” that confirms that your electronic signature really belongs to you. When you sign a document, anyone can verify this certificate at the CA and make sure that the signature is genuine.
Without certification authorities, electronic document management would be impossible — no one could trust electronic signatures. CAs create a system of trust in the digital world. According to the Ministry of Digital Development, in Russia as of 2025 more than 400 accredited certification authorities operate, which have issued over 10 million electronic signature certificates. Read about how electronic signatures work in the article Electronic signature.
Main functions of a certification authority
A certification authority performs several key functions that ensure trust in electronic document management and digital signatures:
- Identification of the owner: Verifies the identity of a person or organization's data when issuing a signature. This is a mandatory procedure to guarantee that the signature is issued to exactly who it should be. For individuals, a passport, INN, SNILS are checked; for legal entities — founding documents and representative's powers.
- Issuance of certificates: Creates unique electronic certificates that link the owner to their public key. The certificate contains information about the owner (full name, INN, organization), validity period and public key.
- Certificate management: Keeps records of issued certificates, and also suspends or revokes them (for example, upon loss of a token, dismissal of an employee, change of passport data or key compromise).
- Ensuring security: Provides software for encryption (for example, CryptoPro CSP, VipNet CSP) and secure media (tokens, Rutoken, eToken) for storing keys.
- Provision of verification services: Allows verifying the authenticity of electronic signatures through public registries (for example, through the certificate verification service on the CA website or through the government CA infrastructure).
Read more about certificates and their verification in the article Cryptographic information protection.
What signatures does a CA issue
A certification authority can issue different types of electronic signatures depending on the degree of identity verification and requirements for legal force:
Non-qualified electronic signature (NES)
Suitable for internal HR electronic document management or interaction with specific counterparties, if this is agreed in advance in the contract. It confirms the authorship of the document, but does not have the same legal force as a QES. NES does not require CA accreditation and can be issued by any CA or even generated independently by the user.
Qualified electronic signature (QES)
The most reliable type of signature, equated to a handwritten one. Issued only by CAs that have received state accreditation (in particular, the certification authority of the Federal Tax Service of Russia, commercial CAs accredited by the Ministry of Digital Development). QES is needed for interaction with government agencies, participation in procurement under Federal Law 44-FZ and 223-FZ, submitting reports to the Federal Tax Service, Pension Fund, Social Insurance Fund, filing documents in court and other legally significant actions. Read about how to obtain a QES in the article Qualified electronic signature.
Enhanced qualified electronic signature (EQES)
A type of QES used in especially important government systems, for example, in the Electronic Budget GIS or in reporting systems to the Central Bank. Requires the use of certified cryptographic information protection and media with enhanced protection. Read more about EQES in the article Enhanced qualified electronic signature.
How to check the legitimacy of a certification authority
Only organizations that have passed a strict review and are accredited by the Ministry of Digital Development of Russia can issue qualified certificates. To check the legitimacy of a CA, it is recommended to take the following steps:
- Check in the Ministry of Digital Development registry: A complete and current list of all accredited certification authorities is always available on the official portal of the Ministry of Digital Development of Russia. The CA must be included in this registry.
- Check through the Rosakkreditatsiya service: You can check the organization through the Rosakkreditatsiya service by entering the company's INN to make sure there is no suspension of its activities and that there is a valid accreditation.
- Availability of an FSB license: A legal CA must have an FSB license for the right to work with cryptographic means (CIP). This is a mandatory requirement for working with qualified signatures.
Before applying for an electronic signature, always check the legitimacy of the CA. Using certificates from non-accredited centers makes the signature legally void.
Read about how to choose a reliable partner for electronic document management in the article Document flow.
Frequently asked questions
What is a certification authority in simple words?
A certification authority is like a digital notary. It verifies your identity and issues a certificate that confirms that your electronic signature belongs to you. Without a CA, no one could trust electronic signatures, because there would be no way to verify who it belongs to. Read about how electronic signatures work in the article Electronic signature.
What functions does a certification authority perform?
A CA performs five main functions: identifies the signature owner (verifies identity), issues certificates (links the owner to the public key), manages certificates (suspends, revokes), provides software for encryption (cryptographic information protection) and secure media (tokens), and also allows verifying the authenticity of electronic signatures through public registries.
How does QES differ from NES?
QES (qualified electronic signature) has full legal force and is equated to a handwritten signature with a seal. Issued only by accredited CAs included in the Ministry of Digital Development registry. NES (non-qualified) is suitable for internal document management (for example, HR EDM) and interaction with specific counterparties by agreement, but does not have the same force for government agencies and courts. Read about types of signatures in the article Qualified electronic signature.
How to check that a certification authority is legal?
To check the legitimacy of a CA, take three steps: check the organization in the registry of accredited certification authorities of the Ministry of Digital Development of Russia, check the CA through the Rosakkreditatsiya service by INN, make sure there is an FSB license for cryptography. A legal CA must have a valid accreditation and license. Read about choosing a partner in the article Document flow.
Can you get an electronic signature at an MFC?
Yes, you can get an electronic signature at an MFC. To do this, contact the “My Documents” center with a passport, SNILS and INN. An MFC employee will help you submit the application, and after payment the signature will be written to a secure medium (token, for example, Rutoken). This is a convenient way for individuals and individual entrepreneurs. Read about obtaining a signature in the article Electronic signature.
How much does an electronic signature certificate cost?
The cost depends on the type of signature, validity period and level of verification. QES for legal entities and individual entrepreneurs usually costs from 3,000 to 10,000 rubles per year. For individuals — from 1,500 to 5,000 rubles. The price includes the medium (token) and software (CryptoPro CSP). Some CAs offer subscriptions with annual renewal and discounts for corporate clients. Read about choosing a tariff in the article Document flow.
What is a root certification authority?
A root certification authority (root CA) is the top level of the trust system in the electronic signature infrastructure. It confirms that the CA itself is legitimate and trusted. The system works like a chain of trust: the root CA confirms the CA, the CA confirms the signature owner. In Russia, the root CA is the certification authority of the Federal Tax Service of Russia, which confirms all accredited commercial CAs. This ensures a hierarchy of trust in electronic document management. Read about the trust system in the article Electronic signature.
Other terms in «Document flow»
Was this information helpful?
Set up efficient document flow
Set up efficient electronic document flow — automate processes, reduce document processing time and avoid errors.