Skip to content

BNS 2023 Cyber Provisions and BSA 2023 Electronic Evidence

How BNS 2023 cyber sections and BSA 2023 Section 63 frame electronic evidence in Indian trials, with Anvar PV, Arjun Pandit Rao Khotkar and Shafhi Mohammad mapped onto practice.

Last updated:

Share

Under India's post-July 2024 criminal law framework, the Bharatiya Nyaya Sanhita 2023 (BNS) supplies the substantive offences most commonly charged alongside IT Act sections in a cyber FIR, while the Bharatiya Sakshya Adhiniyam 2023 (BSA) governs how any electronic record is proved at trial. BNS contains no dedicated cyber chapter; instead, existing offence sections such as stalking (Section 78), cheating (Section 318), and forgery (Sections 336 to 338) extend to digital conduct by definition. BSA Section 63 is the gateway test for admissibility of electronic records, requiring a five-element certificate whose substance is identical to the repealed IEA Section 65B, with Arjun Pandit Rao Khotkar (2020) confirming that the certificate is mandatory and cannot be relaxed.

Two statutes carry most of the substantive cyber-relevant work in an Indian trial after 1 July 2024. The Bharatiya Nyaya Sanhita 2023 (BNS) provides the general offences that are routinely added to IT Act charges in a cyber FIR: stalking, cheating, forgery, criminal intimidation, defamation, sexual harassment. The Bharatiya Sakshya Adhiniyam 2023 (BSA) provides the evidence rules under which any electronic record (a screenshot, a CDR, a server log, a forensic image) is produced and proved. The renumbering from IPC and IEA is the easiest part. The hard part is knowing which section to charge in parallel with the IT Act, and how to package an electronic record so that it survives the Section 63 BSA certificate test at trial.

Key takeaways

  • BNS 2023 has no dedicated cyber chapter: cyber offences sit inside general offence sections such as stalking (Section 78), cheating (Section 318), and forgery (Sections 336 to 338), with the digital medium doing the work of attracting each section.
  • Working cyber chargesheets in India follow a dual-charging pattern, combining an IT Act section for the cyber-specific element with a BNS section for the underlying general offence.
  • BSA 2023 Section 63 is the gateway test for electronic records at trial: a screenshot, a CDR, a server log, or a forensic image must be packaged to satisfy its certificate requirement.
  • BNS Section 318 covers OTP fraud and online cheating without requiring a separate cyber provision, because the definition of cheating already extends to digital transactions.
  • The renumbering from IPC and IEA to BNS and BSA is the straightforward part; the harder skill is knowing which BNS section to charge alongside the IT Act for a given cyber fact pattern.

BNS does not have a cyber-only chapter. Cyber offences sit inside the general offence sections, with the medium (computer, mobile, network) determining which section is attracted. Stalking under BNS Section 78 explicitly covers electronic monitoring; cheating under BNS Section 318 covers OTP fraud and online cheating without a separate provision; forgery under BNS Sections 336 to 338 applies to electronic records because BSA expanded the "document" definition. In practice, cyber chargesheets follow a dual-charging pattern: the IT Act section for the cyber-specific offence and the BNS section for the underlying general offence.

By the end of this topic you will be able to:

  • Identify which BNS 2023 sections apply to common cyber fact patterns and explain why BNS carries no standalone cyber chapter.
  • Apply the dual-charging pattern by pairing the correct IT Act provision with the corresponding BNS section for a given fact pattern.
  • State the five mandatory elements of a Section 63 BSA certificate and explain what happens if any element is absent or the certificate is filed late.
  • Trace the electronic evidence certificate jurisprudence from Anvar PV (2014) through Shafhi Mohammad (2018) to Arjun Pandit Rao Khotkar (2020), distinguishing which holdings remain good law.
  • Describe how a forensic examiner builds the hash chain and expert-opinion record that supports a Section 63 BSA certificate and survives cross-examination under Section 39 BSA.
Key terms
BNS 2023
Bharatiya Nyaya Sanhita 2023, the substantive criminal code that replaced the IPC 1860 from 1 July 2024. 358 sections, 20 chapters.
BSA 2023
Bharatiya Sakshya Adhiniyam 2023, the evidence statute that replaced the Indian Evidence Act 1872 from 1 July 2024. 170 sections, 12 chapters.
Section 63 BSA
The statutory certificate required for admissibility of a copy of an electronic record. Successor to IEA Section 65B; substance is materially the same.
Section 39 BSA
Expert opinion provision; covers science, art, handwriting, finger impressions, footprints and electronic evidence. Successor to IEA Section 45.
Dual charging
The Indian cyber FIR practice of adding both an IT Act section and a BNS section for the same act, so each captures a different facet of the offence.
Primary vs secondary electronic evidence
Primary is the original electronic record in the originating computer system; secondary is any copy, output or printout. BSA Sections 60 and 61 govern, with Section 63 supplying the certificate route for secondary.

Why BNS does not have a 'cyber chapter' and how that shapes charging

BNS structures offences by harm, not by medium. There is no chapter titled "Cyber Offences" because the drafters chose to fold cyber-relevant fact patterns into the general offence sections by either expanding the definition or expressly mentioning the electronic mode. Stalking under Section 78 names "monitoring the use by a woman of the internet, email or any other form of electronic communication" as a mode of the offence. Cheating under Section 318 captures any dishonest inducement, which covers OTP fraud, online cheating and pig-butchering without a special section. Forgery under Sections 336 to 338 applies to electronic records because BSA expanded the "document" definition to expressly include electronic records.

BNS 2023 sectionSubject matterCyber fact pattern it picks up
Section 75Sexual harassmentOnline sexual remarks, unwelcome sexually coloured messages, demand for sexual favour through electronic means.
Section 78StalkingPhysical and electronic stalking; expressly covers monitoring of internet, email or electronic communication by a woman.
Section 196Promoting enmity between groupsCommunal hate speech, including online posts; read with Section 197 mob lynching when violence follows.
Section 197Imputations and assertions prejudicial to national integrationOnline incitement, mob-mobilising messages, communally targeted forwards.
Section 318CheatingOTP fraud, fake-investment scam, pig-butchering, online cheating without the personation element; the workhorse with IT Act 66D.
Sections 336 to 338ForgeryElectronic-record forgery, fake screenshots used to defraud, doctored chat logs; BSA's expanded 'document' brings electronic records in.
Section 351Criminal intimidationCyber-bullying, online threats, doxxing-with-threats. Subsections grade the seriousness.
Section 354DefamationOnline defamation, defamatory tweets, defamatory WhatsApp forwards. The medium does not change the section.

The investigative consequence is that an examiner whose work supports a cyber chargesheet should expect questions on both layers. The defence will challenge the IT Act provision on technical grounds (was a computer resource actually used? Was the credential actually impersonated?) and the BNS provision on classical grounds (was there dishonest inducement? Was there intent to cause harm?). The artifact set has to support both attacks.

IT Act versus BNS: who does what

Offences can be sorted into three categories. Some are IT Act only because they require a computer resource by definition (cyber terrorism under Section 66F is the cleanest example). Some are BNS only because the medium is incidental (a defamation on paper and a defamation on Twitter both sit under BNS Section 354). Most cyber FIRs sit in the third bucket where both apply, and the prosecution charges both.

Fact patternIT Act sectionBNS 2023 sectionWhy both
Phishing email that drains a bank account66C, 66D318IT Act captures the credential abuse and the personation through a computer resource; BNS 318 captures the underlying cheating.
Doctored screenshot circulated on WhatsApp to defraud a buyer66D where personation is present318, 336 to 338IT Act for the computer-resource cheating; BNS for forgery of an electronic record.
Online stalking and monitoring of a woman's email67 only if obscene content was sent78BNS 78 expressly covers electronic monitoring; IT Act 67 family only attracts on obscene content.
Ransomware against a hospital66, 66F if critical-care systems threatened318 if extortion is allegedIT Act for the offence; BNS for the underlying cheating or extortion; CERT-In and DPDP layers on top.
Defamatory tweetNo specific IT Act section after 66A struck down354Shreya Singhal struck down 66A; defamation now sits under BNS 354 with no IT Act overlay.
Cyber terrorism (attack on critical infrastructure)66FOften added: BNS terrorism provisions where applicableIT Act 66F is cyber-specific; BNS terrorism captures the broader act if facts support.

The investigative practice is that the IO drafts the FIR with the IT Act sections, the local court (the JMFC for cyber crimes in most states, or a designated cyber court where one exists) takes cognisance, and the FSL or state cyber cell examiner is asked for opinion on both layers in the chargesheet. Section 39 BSA is what authorises the examiner to give expert opinion on the electronic evidence; the underlying offences then sit on a mix of IT Act and BNS sections.

Section 63 BSA: what the certificate must say

Section 63 BSA is the rule that decides whether a screenshot, a CDR printout, a server-log export, or a forensic image is admitted at trial. The substance is materially the same as IEA Section 65B. The provision says that any copy or output of an electronic record produced from a "computer system" is admissible only if it is accompanied by a certificate that identifies the electronic record, describes the manner of its production, particulars of the device involved, and is signed by a person occupying a responsible official position in relation to the operation of the relevant device.

  1. Identify the electronic record
    Name the file, log, message or image. State the format (PDF, CSV, EML, raw forensic image, hash value). Attach the record itself or refer to the exhibit list.
  2. Describe production manner
    Was the record exported from a server, captured from a mobile, imaged from a disk? Name the tool (e.g. FTK Imager 4.7.1, Cellebrite UFED 4PC 7.62, dd 8.32), the command or workflow, and the output path.
  3. Particulars of the device
    Make, model, serial number or unique identifier of the device that produced or stored the record. For server-side records, the hostname, IP and the role of the system.
  4. Operating conditions
    State that the device was operating ordinarily during the relevant period, or where it was not, describe the deviation. The 'computer system' was used regularly to store or process information of that kind.
  5. Person responsible
    Name and designation of a person occupying a responsible official position in relation to the operation of the relevant device. The signatory must be in a position to depose on the device's regular operation.
  6. Sign and date
    Date the certificate to the time of production, not earlier. Late certificates have survived where Anvar PV principles are met; certificates antedated to before the record was produced are routinely rejected.

The "computer system" definition in BSA is broader than the original IEA definition. It includes any data processing device or system, which means a smartphone, a tablet, a network switch, a CCTV DVR and a vehicle telematics unit all qualify. This matters because the certificate is required for any output from any of these devices, not just for outputs from desktop or server machines.

The Indian case law on electronic evidence

Three Supreme Court judgments define the current certificate jurisprudence.

Anvar P V v P K Basheer (2014)

A three-judge bench of the Supreme Court held that any electronic record produced as secondary evidence must be accompanied by a Section 65B IEA certificate. The judgment overruled the earlier State (NCT of Delhi) v Navjot Sandhu line that had treated 65B as one of multiple routes to admit electronic evidence. After Anvar, the certificate became the only route for secondary electronic evidence. The proposition transfers cleanly onto Section 63 BSA.

Shafhi Mohammad v State of HP (2018)

A two-judge bench held that the certificate requirement could be relaxed where the party producing the record was not in possession of the device that produced it. The decision was widely cited for the proposition that a strict certificate rule could defeat justice in cases where the device belonged to a third party (a telecom operator, a social media platform).

Arjun Pandit Rao Khotkar v Kailash Kushanrao Gorantyal (2020)

A three-judge bench of the Supreme Court overruled Shafhi Mohammad and restored Anvar P V as the settled rule. The certificate is mandatory. Where the party producing the record cannot itself sign the certificate (because the device belongs to a third party), the party must apply to the court for production of the certificate from the third party under Section 165 IEA, now Section 168 BSA. The certificate must accompany the electronic record at the time it is produced; a certificate filed later is admissible only if the court permits the late filing on cause shown.

CaseYearHoldingStatus in 2026
Anvar P V v P K Basheer201465B certificate mandatory for secondary electronic evidence; overruled Navjot SandhuGood law; carries over to Section 63 BSA
Shafhi Mohammad v State of HP2018Certificate requirement relaxable where party not in possession of deviceOverruled by Arjun Pandit Rao
Arjun Pandit Rao Khotkar v Kailash Kushanrao Gorantyal2020Overruled Shafhi Mohammad; certificate mandatory; must accompany record at productionGood law; the settled rule under Section 63 BSA
201420182020Anvar P V v P KBasheer, 3-judgebench. Certificatemandatory; NavjotSandhu overruled.Shafhi Mohammad vState of HP,2-judge bench.Certificaterelaxable whenparty lacks deviceaccess.Arjun Pandit RaoKhotkar, 3-judgebench. ShafhiMohammad overruled.Certificatemandatory.Status in 2026Good lawOVERRULEDGood law, settledruleCertificate mandatoryfor secondary evidenceDo not cite as currentauthority in 2026Certificate must accompanyrecord at productionGood law / settled ruleOverruled, do not citeAll three cases apply to Section 63 BSA (successor to IEA Section 65B) for prosecutions from 1 July 2024.
Electronic evidence certificate jurisprudence: Anvar PV (2014) made the Section 65B certificate mandatory; Shafhi Mohammad (2018) relaxed it; Arjun Pandit Rao (2020) overruled Shafhi and restored the mandatory rule, which now applies to Section 63 BSA.

Hash chain, live capture and how the examiner supports the certificate

The Section 63 BSA certificate is a legal document, but its credibility rests on the technical record an examiner builds at the time of acquisition. The standard discipline is to acquire a forensic image with a tool that produces a verified hash, store the source hash and the image hash side by side, and document every subsequent operation against the image (not the original). The hash chain is what tells the trial court that the bit-for-bit copy analysed at the FSL is the bit-for-bit copy seized at the scene.

Hash chain for a digital exhibit. The source device is hashed at acquisition (SHA-256). The image is hashed at write. The ima
Hash chain for a digital exhibit. The source device is hashed at acquisition (SHA-256). The image is hashed at write. The image is verified at intake at the FSL and on every subsequent analysis. Any hash drift between any two points breaks the chain. The Section 63 BSA certificate names the tool, the hash, and the date for each step. Reading order is left to right.

This work overlaps directly with the chain-of-custody discipline covered in Chain of Custody and with the acquisition discipline in Digital First Responder: Volatility, Seizure, Imaging. The hash chain is the technical record; the seizure and forwarding memos are the procedural record; the Section 63 BSA certificate is the courtroom-facing document that pulls both together.

The forensic expert in the witness box

Section 39 BSA is the provision under which the examiner is admitted as an expert and the report is admitted as evidence of the opinion stated. The cross-examination then probes the expert's qualifications, the methods used, the chain of custody, and the limits of the opinion. A digital forensic expert in an Indian trial court should expect a recognisable script.

  • Qualifications. Degree, institution, additional certifications (CHFI, EnCE, GCFA), years of practice, number of similar cases handled. Have a one-page CV ready to be marked as an exhibit.
  • Tool validation. The make, model and version of the tool used, the testing the tool has undergone (NIST CFTT references where relevant), the limits of the tool, the alternative tools considered.
  • Chain of custody. Every link from seizure to analysis. The examiner must be able to identify each handoff, the signatures and the seals, and confirm that the artifact analysed is the artifact seized.
  • Hash chain. The hash at each step. The defence will ask whether any hash differed and what was done about it.
  • Scope of opinion. The expert can speak to what the data shows, not to who put it there. Attribution of an act to a person is for the court to infer from the data combined with other evidence.
  • Limits of the method. What the analysis cannot tell. An examiner who acknowledges limits on direct examination is harder to corner on cross than one who overclaims.

A clean Section 63 BSA certificate, a documented hash chain, and a report that distinguishes observation from inference together provide the foundation for withstanding cross-examination. Section 39 BSA governs expert depositions across forensic disciplines, but electronic evidence is where the documentary record is most explicit and the cross-examination most technically demanding.

Practice
Question 1 of 5· 0 answered

Under BSA 2023, which section governs the admissibility of a copy of an electronic record?

Frequently asked questions

Why are most cyber FIRs in India charged under both IT Act and BNS sections?
The IT Act captures cyber-specific offences (identity theft under 66C, cheating by personation through a computer resource under 66D, cyber terrorism under 66F). The BNS captures the underlying general offence (cheating under 318, forgery under 336 to 338, stalking under 78). The dual-charging pattern is standard practice and lets the prosecution attack the same fact pattern on two layers.
Is Section 65B IEA still cited after 1 July 2024?
Section 65B IEA is the predecessor of Section 63 BSA. Cases pending on 1 July 2024 continue under IEA where relevant transitional rules apply; new prosecutions cite Section 63 BSA. The substance is the same, so the case law on 65B (Anvar PV and Arjun Pandit Rao Khotkar) reads onto Section 63 BSA.
What must a Section 63 BSA certificate state?
Five elements: identification of the electronic record, the manner of production, the particulars of the device, the operating conditions during the relevant period (the device was operating ordinarily, or where it was not, a description of the deviation), and the signature of a person occupying a responsible official position in relation to the operation of the device. The certificate must accompany the record at production.
What did Arjun Pandit Rao Khotkar (2020) settle?
The Supreme Court overruled Shafhi Mohammad and restored Anvar PV as the settled rule. The Section 65B certificate (now Section 63 BSA) is mandatory for secondary electronic evidence and must accompany the electronic record at the time of production. Where the party producing the record cannot sign the certificate itself, it must apply to the court for production of the certificate from the third party.
Can a forensic examiner give expert opinion on electronic evidence under BSA?
Yes, under Section 39 BSA. The section covers opinion of persons specially skilled in foreign law, science, art, handwriting, finger impressions, footprints and electronic evidence. The examiner's report and oral testimony are admitted as evidence of the opinion stated; the weight is for the court.
What happens if the source device hash and the image hash do not match?
The acquisition is invalid and must be redone. A mismatch indicates that the image is not a bit-for-bit copy of the source, which destroys the foundation of the analysis. The examiner must document the mismatch, log the cause (write-blocker failure, source media error, tool fault), and reacquire. Producing an analysis on an image with a mismatched hash invites Section 63 BSA challenge and undermines the expert opinion under Section 39 BSA.
Why is the 'computer system' definition in BSA important for mobile forensics?
BSA's 'computer system' is broad enough to include smartphones, tablets, network switches, CCTV DVRs and vehicle telematics units. Any output from any of these devices is an electronic record that requires a Section 63 BSA certificate when produced as secondary evidence. A WhatsApp chat export from a phone, a call recording from a CDR system, and a CCTV clip from a DVR all need the certificate.

Test yourself on Digital Forensics with free, timed mocks.

Practice Digital Forensics questions

Found this useful? Pass it along.

Share

Spotted an error in this page? Report a correction or read our editorial standards.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.