Event Alert | Join us at 10th International Police Expo, New Delhi | 31st July – 1 August 

Section 63 BSA Certificate: A Practical Guide for Investigators and Legal Teams

Section 63 BSA certificate

A Section 63 BSA certificate is a signed statement that must accompany an electronic record when it is produced in court under the Bharatiya Sakshya Adhiniyam, 2023 (BSA). It follows a fixed format given in the Schedule to the Act. Part A is filled by the party or the person in charge of the device. Part B is filled by an expert. Both parts record the hash value of the record. The BSA replaced the Indian Evidence Act, 1872 on 1 July 2024, and Section 63 took the place of Section 65B.

Key Takeaways

  • Section 63 BSA replaced Section 65B of the Evidence Act from 1 July 2024
  • The certificate now follows a prescribed format in the Schedule, in two parts
  • Part A comes from the party or person in charge of the device
  • Part B comes from an expert
  • Both parts must state the hash value and the algorithm used
  • The Supreme Court has said Part B need not always come from a Section 79A examiner
  • The certificate must go with the record each time it is submitted
  • A short checklist at seizure, extraction and filing keeps the paperwork consistent

What Section 63 of the BSA says

What Section 63 of the BSA says

Every investigation now leaves a digital trail: seized phones, DVR footage, bank logs, chat exports. Section 63 is the rule that decides whether a court will accept that material.

In plain terms, Section 63(1) treats information in an electronic record as a “document” when it is printed on paper, or stored, recorded or copied in optical or magnetic media or semiconductor memory, and produced by a computer or communication device. If the conditions in the section are met, it is admissible without further proof or production of the original. The BSA also adds two companion provisions. Section 61 says a record cannot be denied admissibility only because it is electronic. Section 62 says the contents of electronic records are proved under Section 63.

The four conditions in Section 63(2)

Diagram of four conditions in Section 63(2)

  1. The device was regularly used to create, store or process information for activities regularly carried on by the person with lawful control over it.
  2. Information of that kind was regularly fed into the device in the ordinary course of those activities.
  3. The device was working properly during the material period. If it was not, the fault did not affect the record or its accuracy.
  4. The information in the record reproduces, or comes from, information fed into the device in the ordinary course.

Many devices, one system

Section 63(3) says that where several computers or communication devices did the job, whether standalone, networked, cloud-based or through an intermediary, they are treated as a single device for this section.

The certificate itself

Section 63(4) requires a certificate that:

  1. Identifies the electronic record and describes how it was produced,
  2. Gives particulars of the devices involved, and
  3. Deals with the conditions in Section 63(2).

It must be signed by a person in charge of the device or of the relevant activities, and by an expert. It is enough for a matter to be stated to the best of the signer’s knowledge and belief. And it must be submitted with the record “at each instance” where the record is submitted for admission.

Section 63 BSA vs Section 65B: what changed

Diagram of Section 63 BSA vs Section 65B: what changed

PointSection 65B, Evidence Act, 1872Section 63, BSA, 2023
Certificate formatNo format prescribedPrescribed in the Schedule
Hash valueNot part of the certificateRequired in Part A and Part B
ExpertNot requiredPart B is signed by an expert
Devices coveredComputer outputAlso covers semiconductor memory and “any communication device”
General rule on electronic recordsNo equivalent to Section 61Section 61: electronic records have the same legal effect as other documents, subject to Section 63

The Supreme Court described the shift in its May 2026 order: Part A adds the hash value on top of the declaration that Section 65B already required, and Part B adds a further declaration by an expert.

Do you always need the certificate?

Do you always need the certificate

Under the old law, the answer came from two Supreme Court rulings. In Anvar P.V. v. P.K. Basheer (2014), the Court held that electronic records used as secondary evidence need the Section 65B certificate. In Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (14 July 2020), a three-judge bench confirmed this. It held that the certificate is a condition precedent, that oral evidence cannot take its place, and that it is not needed when the original device itself is produced. It also said that if the person or authority holding the record refuses to give the certificate, the party can apply to the court for a direction.

The BSA adds a twist. Section 57, Explanations 4 to 7, say that electronic records stored in multiple files, records produced from proper custody, simultaneously stored video recordings, and automated storage such as temporary files can each count as primary evidence. Explanation 5 applies only “unless it is disputed”. Courts are still working out how far these explanations reduce the need for a certificate.

The safe approach: treat the certificate as the default for any electronic record you produce, and prepare one even when you plan to argue the record is primary evidence. Explanation 5 falls away the moment the record is disputed.

What goes in the certificate: Part A and Part B

Diagram of What goes in the certificate: Part A and Part B

The Schedule sits at the end of the Act. Both parts open with a solemn affirmation and a tick-box list of the source: computer or storage media, DVR, mobile, flash drive, CD/DVD, server, cloud or other. Both then ask for make and model, colour, serial number, and IMEI, UIN, UID, MAC or cloud ID as applicable.

FieldPart A (party or person in charge)Part B (expert)
Device or source tick-boxYesYes
Make, model, colour, serial number, IMEI/UIN/UID/MAC/Cloud IDYesYes
Device was under lawful control and used regularlyYesNo
Device was working properly, or any fault did not affect the recordYesNo
Owned, maintained, managed or operated by the signerYesNo
Hash value and algorithmYesYes
Hash report enclosedYesYes
Date (DD/MM/YYYY), time in IST (24 hour format), placeYesYes

In short, Part A carries the statement about how the device was used. Part B carries an independent technical confirmation of the source and the hash.

Hash value: the field that trips people up

Hash value: the field that trips people up

A hash value is a fixed-length string produced by running a file through an algorithm. Change even one byte of the file and the hash changes. The Supreme Court equated a hash value with a digital fingerprint of the record, and said requiring it in the certificate has a rational link to the aim of protecting authenticity and integrity.

The Schedule lists SHA1, SHA256, MD5, or another legally acceptable standard, and asks for the hash report to be enclosed.

Which algorithm should you pick?

All three listed algorithms are on the face of the form, so a certificate using MD5 or SHA-1 is not defective just for that. But SHA-256 is the safer choice. NIST has recommended moving away from SHA-1 by 31 December 2030 because of collision attacks, and MD5 and SHA-1 are both known to be open to collision attacks. A collision weakness is exactly what an opposing lawyer can raise.

Good practice (not a legal requirement):

  • Hash the exact file you will produce, not a converted or re-saved copy
  • Record the hash at the moment of extraction or export
  • Copy the hash from the tool’s report instead of retyping it
  • Confirm that Part A and Part B show the same value
  • Verify the hash again after every copy or transfer
  • Note the tool name, version and date in the case file

Who can sign Part B?

Who can sign Part B

Neither Section 63 nor the Schedule defines “expert”. Section 39(2) of the BSA says that where a court must form an opinion on information stored in any electronic form, the opinion of an Examiner of Electronic Evidence under Section 79A of the IT Act, 2000 is relevant, and such an examiner is an expert.

The Madras High Court, in R. v. B & Anr. (2024 SCC OnLine Mad 6084), a matrimonial case instituted in 2019, read this to mean that Part B can be signed only by a notified Section 79A examiner. Very few entities are notified, so this raised a practical worry for litigants.

The Supreme Court addressed this in Pune Bar Association v. Union of India (Writ Petition (Civil) No. 599 of 2026, order dated 22 May 2026, before CJI Surya Kant and Justices Joymalya Bagchi and Vipul M. Pancholi). It did three things:

  1. Rejected the challenge to the hash and expert requirements. It held they have a rational link to the purpose of the law and are not arbitrary. It also noted that AI and deepfake technology add to the challenge of proving authenticity.
  2. Widened who can sign Part B. Reading Section 39(1) and 39(2) together, it said that apart from notified examiners, another person with special skill in computer science and cyber forensics can sign Part B if the court is satisfied on “unimpeachable material”.
  3. Set aside the Madras High Court’s narrow reading as precedent. It said that finding shall not be treated as binding.

Read this with care. This was an order disposing of a petition at the admission stage. The Court declined to issue notice to the Union of India and said it was not giving a conclusive opinion, keeping the question of law open. It is a strong signal, but not the last word.

Practical takeaway: use a notified Section 79A examiner where one is accessible. Where you cannot, keep documented proof of your signer’s expertise ready: qualifications, training, tools used, and prior experience of court work.

From seizure to courtroom: a step-by-step flow

From seizure to courtroom: a step-by-step flow

Record the seizure

Under Section 105 of the BNSS, the search or seizure, including the seizure list and its signing by witnesses, is to be recorded through audio-video electronic means, preferably by mobile phone. The recording is forwarded to the Magistrate without delay. (Law)

Bring in forensics for serious offences

Under Section 176(3) of the BNSS, for offences punishable with seven years or more, a forensic expert is to visit the scene, collect evidence, and the process is to be videographed. This applies from a date notified by each State Government within five years, so check your state’s position. (Law)

Extract or image, and hash straight away

Log the tool, version, date and operator. (Good practice)

Prepare Part A

For audio-video recordings made on a mobile phone, the BPR&D SOP under BNSS describes generating the hash on the device, noting it, and producing a Part A certificate to the officer in charge of the police station. (SOP)

Get Part B from the expert who has examined the source and verified the hash. (Law)

File the certificate with the record and the hash report, every time the record is submitted. (Law)

Keep the custody trail: seizure memo, storage details, transfer log and access log. (Good practice)

For a deeper look at how device data is examined before it reaches this stage, see our guide to device forensics.

Special situations

diagram of Special situations

CCTV and DVR footage

In State of Andhra Pradesh v. Suda Suresh Veera Venkata Naga Raju (2026 INSC 744, decided 27 July 2026), the Supreme Court directed that CCTV footage and videographic recordings be produced in original form, without deletion, overwriting, editing or tampering, together with a Section 63 certificate. Many DVR and NVR systems overwrite older footage automatically, so early preservation matters.

Records held by someone else

For bank statements, call records or platform data, the statute lets the person in charge of the device or the management of the relevant activities sign. If the holder does not respond, the Arjun Panditrao route of applying to the court for a direction was set out under the old law.

Documents built from electronic records

Section 63(1) covers information printed on paper, so a printout of a chat or an email is also computer output and needs the same certificate.

Common mistakes and how to avoid them

Diagram of Common mistakes and how to avoid them

These are process gaps, and most can be closed with a template and a checklist.

GapWhy it causes troubleFix
Hash in Part A differs from Part BIt suggests two different filesCompute once at extraction and copy from the report
One certificate covering many recordsThe statute ties the certificate to the record and to each submissionPrepare per record, or list each record with its own hash
Device identifiers left blankThe Schedule asks for themFill IMEI, serial, MAC or cloud ID wherever applicable
Hash report not enclosedThe Schedule asks for itAttach it to both parts
Part B signer’s expertise not documentedThe court must be satisfied on expertiseKeep a short profile and proof of qualifications ready
Old Section 65B template usedThe format is now prescribedUse the Schedule format
Oral evidence used to fill a missing certificateThe Supreme Court held it cannot take the place of the certificateGet the certificate, or apply for a direction
Hash taken from a converted copyIt will not match the sourceHash and certify the exact file produced, and identify the source device separately

For BFSI and enterprise teams

For BFSI and enterprise teams

Banks, NBFCs and large enterprises often produce system logs, statements, emails and CCTV clips to courts and agencies, and run internal investigations that can end up in litigation. Because the statute lets the person managing the relevant activity sign, it helps to decide in advance who that person is for each system.

A standard procedure for log exports, hashing and custody, agreed with the legal team, saves time when a request arrives.

Where analysis tools fit

Where analysis tools fit

Section 63 is about proving that a record is authentic. Making sense of what the records say is a separate job. Argus, Innefu’s forensic analytics toolkit, works after data has been extracted by commercial forensic tools.

It brings the output from multiple devices into one repository, correlates common contacts, locations, applications and groups across suspects’ phones, and prepares reports that explain technical data in plain language for court use. It does not replace the custodian’s Part A or the expert’s Part B. Those stay with the people who can attest to the device and the hash.

Frequently Asked Questions

1. What is a Section 63 BSA certificate?

It is the signed statement, in the format set out in the Schedule to the Bharatiya Sakshya Adhiniyam, 2023, that accompanies an electronic record produced in court. It has two parts, one by the party or person in charge of the device and one by an expert, and both state the hash value.

2. Is a Section 63 certificate mandatory?

For electronic records produced as computer output, the statute requires a certificate to be submitted with the record. Under the older law, the Supreme Court held it unnecessary only when the original device itself was produced. How far the BSA changes that is still developing, so prepare the certificate as a default.

3. What replaced Section 65B of the Evidence Act?

Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, which came into force on 1 July 2024.

4. Who signs Part A and Part B?

Part A is signed by the party or the person in charge of the device or of the relevant activities. Part B is signed by an expert. In May 2026 the Supreme Court said a person with special skill in computer science and cyber forensics can sign Part B if the court is satisfied, and that Part B need not come only from a Section 79A examiner.

5. Which hash algorithm should I use?

The Schedule lists SHA1, SHA256, MD5 or another legally acceptable standard. SHA-256 is the safer choice because MD5 and SHA-1 have known collision weaknesses.

6. Does Section 63 apply to cases filed before 1 July 2024?

Not automatically. The law that applies depends on the proceeding. In the Pune Bar Association order, the Supreme Court noted that a matrimonial case instituted in 2019 had been held by the Madras High Court to be governed by the old Evidence Act. Check with counsel for older matters.

7. Is a certificate needed for a printout of a chat or email?

Yes. Section 63(1) covers information in an electronic record that is printed on paper, so the printout is treated as computer output.

8. Do I need a fresh certificate every time I submit the record?

The statute says the certificate is to be submitted along with the electronic record at each instance where the record is submitted for admission.

This article is for general information and is not legal advice. Laws and court decisions change. Confirm the current position with qualified counsel before relying on it in a specific matter.

Sources

Related Posts

GST ITC Fraud Detection Software
How Innefu’s Prophecy Eagle I Traced a ₹5,700 Crore Suspected Input Tax Credit (ITC) Fraud Network

They never broke any rule, never missed a filing deadline, never...

criminal profiling software
Criminal Profiling Software: How AI-Driven MO and Pattern Analysis Helps Police Identify Repeat Offenders

Criminal profiling software uses AI to correlate modus operandi, forensic evidence,...

AI-powered GST fraud investigation
How AI Structures a GST Fraud Investigation: From Raw Data to Case-Ready Evidence

Detecting a fraudulent GST claim and proving it are two different...