Which one do I actually need?
For almost everything, a Class 3 signature certificate. Add encryption only if you are bidding on e-tender or e-procurement portals, which need the pair, or if you have to decrypt documents that are sent to you encrypted. If you file with DGFT you need the DGFT certificate specifically — nothing else is accepted there.
Individual or organisation — which should I pick?
An organisation certificate carries both your name and the company name, and is what you want when you sign on the company’s behalf: MCA filings, GST, tender bids, EPFO. An individual certificate carries only your name and suits personal income tax filing and court e-filing. They cost the same, so pick by what the portal expects rather than by price.
Is a two or three year certificate better value?
Yes, and the configurator shows you by how much. Three years at ₹2,250 works out under ₹750 a year against ₹1,350 for a single year. The one reason to choose a shorter term is a name, company or role that you expect to change, because a certificate cannot be edited — a change means a new one.
How long does it take?
For an Indian applicant using Aadhaar eKYC, issuance is usually the same working day. The token then takes two to five days to reach you by courier or speed post. Foreign applicants should allow three to five working days for issuance because verification runs on attested documents rather than Aadhaar.
Can I use one certificate on more than one portal?
Yes. One Class 3 certificate registers on MCA21, the income tax portal, GST, EPFO, ICEGATE and the tender portals at the same time. You register the same certificate separately on each, which is a few minutes per portal. You do not need a certificate per portal, whatever anyone selling one per portal tells you.
What happens when it expires?
Renewal is a fresh certificate rather than an extension, and it goes through eKYC again. You can reuse your existing token if it still works. Start about two weeks before expiry — an expired certificate cannot be renewed, only replaced, and anything you signed before expiry stays valid.
Who do I talk to if the download fails?
Us. Email help@sslretail.com with the order number and what the tool told you. The common causes are a token driver that never installed, a browser that has blocked the helper application, or a challenge code that has already been used. None of them require a new certificate.