Important!

Capability of obtaining DS keys by proxy in the CSC excluded

Starting from June 28, 2025, you can receive the registration certificate of the National Certification Authority of the Republic of Kazakhstan (DS keys) only in person and subject to biometric identification.

In case of unsuccessful biometric identification, or in the absence of a photo image of the service recipient in the state database of individuals, the service recipient submits an application for DS keys on his personal computer, after which he contacts the Registration Center (CSC or a foreign institution (list on the pki.gov.kz website) for face-to-face identification and its confirmation.


Why is this important?

A digital signature (DS) has the same legal force as a handwritten signature. Any actions with a DS must be performed exclusively by its owner.

Using biometric identification and waiving powers of attorney when obtaining DS keys significantly reduces the risk of hackers obtaining them. This increases the level of information security and enables more reliable control over the release of DS.


Legal basis

Cancellation of the power of attorney and mandatory biometric identification upon receipt of DS keys are regulated by the Order of the Minister of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan as of June 4, 2025 No. 212/NK “On Amendments to the Order as of November 26, 2015 No. 115/NK “Rules for the issuance, storage, revocation of registration certificates and confirmation of ownership and validity of the public key of the digital signature by the Root Certification Authority of the Republic of Kazakhstan, the Certification Authority of Government Agencies and the National Certification Authority of the Republic of Kazakhstan.

Dear users!

The National Certification Authority of the Republic of Kazakhstan hereby notifies that on June 25, 2025, DS keys issued before April 28, 2024, will not work for authentication and signing in information systems due to the expiration of the root certificates of the National Certificate Authority of the Republic of Kazakhstan based on the algorithms of the State Standard of the Republic of Kazakhstan GOST R 2004 (nca_gost from 08.08.2018 to 25.06.2025) and RSA (nca_rsa from 08/08/2018 to 06/25/2025).

All DS keys issued after April 28, 2024 will remain valid until their expiry date.

Attention!

If the request from your information system to the NCA RK timestamp service specifies the object identifier 1.2.398.3.3.2.6.1 (the policy for signing timestamp receipts based on the GOST 34.310-2004 algorithm with OID 1.2.398.3.10.1.1.1.2), this will make it impossible to generate a timestamp receipt.

In this case, the identifier must be replaced with 1.2.398.3.3.2.6.4 (the policy for signing timestamp receipts based on the GOST R 34.10-2015 algorithm with OID 1.2.398.3.10.1.1.2.3).