← All posts

ROC filing software: what to check before you buy

OnCompliance3 September 20268 min readclaims checked 3 September 2026

The last company e-forms moved to MCA V3 on 14 July 2025, and V3 signs with a DSC token on a local machine. Those two facts bound what any tool can do.

The question that settles most of a software evaluation is not what the product does, it is whether it matches how MCA V3 actually works. Since 14 July 2025 the final set of 38 company e-forms has been filed only on Version 3 of the MCA portal, and a V3 filing is a web form completed in the browser and signed with a digital signature certificate that has been associated to a business user login. (Checked against MCA, 3 September 2026.)

No product changes that. What a good one does is everything around it: knowing what is due for which client and when, holding the working papers, and leaving a record you can produce two years later.

What V3 compatibility actually means

MCA's own FAQ on the final lot lists the 38 forms and states that from 14 July 2025 all of them must be filed through Version 3. It covers most of what a practice files in a year: AOC-4 and its whole family, MGT-7, MGT-7A, MGT-15, the ADT forms, CRA-2 and CRA-4, GNL-1, INC-22A and CSR-1. Read it in MCA's FAQ on the final set of 38 forms (PDF).

The same FAQ is blunt about what changed. In V2 a form was downloaded, filled offline and uploaded. In V3 forms are filled online, with pre-filling from linked records and validation applied as you go. There is still an offline route for annual filings, but it is not the old one: you enter basic details in the web form, the portal generates an Excel set, you fill that offline and upload it back into the same web form, one file at a time, each validated before the next is enabled. MCA sets out that sequence in its FAQ on offline filings of annual forms.

Two things worth putting in front of a salesperson:

Linked filings. Six forms arrived with the migration that had no V2 equivalent: AOC-1, AOC-2, the three Extract forms (Auditor's Report standalone and consolidated, and Board's Report) and ADT-4. All but ADT-4 are filed as linked filings to AOC-4, in an order MCA prescribes: AOC-4 CFS, AOC-1, AOC-2, CSR-2, Extract of Auditor's Report (standalone), Extract of Auditor's Report (consolidated), Extract of Board's Report. Ask which of those the tool knows about, and whether it knows the order.

Where the data ends up. A tool that prepares a pack you then retype into a web form has saved you the thinking and none of the typing. Watch someone move a real client's AOC-4 from the tool to the portal, and count the keystrokes.

Deadline tracking is per client, and it hangs off the AGM

This is where multi-client software either earns its keep or quietly misleads you, because the statute does not give a date. It gives a clock, and the clock starts at each client's own annual general meeting.

Filing The clock Source
Financial statements (AOC-4) Within thirty days of the AGM Section 137(1)
Annual return (MGT-7 / MGT-7A) Within sixty days from the date the AGM is held Section 92(4)
Financial statements of a One Person Company Within one hundred eighty days from the closure of the financial year Section 137(1), third proviso

(All three checked against the Companies Act 2013 as published by MCA (PDF), 3 September 2026.)

One event, and for an OPC no event at all, produce three different answers. A client that holds its AGM in August is not on the same date as one that holds it on the last permitted day, and a client with an extension is on neither.

So the test is simple: find the field the tool derives the due date from. If a per-client AGM date drives it, the tracker is real. If the dates are identical for every client on the list, they are decoration, and the first extension or early AGM will prove it.

The dates and fees for the year you are actually filing sit on the MGT-7 hub and the AOC-4 hub, with the wider sequence on the annual filing page. What a delay costs is on the MCA late fee calculator.

DSC handling is the part with a real downside

MCA's process notes for DSC registration are specific, and they constrain every product in this category equally. From MCA's DSC registration FAQ:

Download EMSIGNER and EMBRIDGE BOTH for DSC registration.

For Professionals, Directors, Designated Partners, Manager, Secretary, Authorized Representatives, Professional Staff Members, registration as a "BUSINESS USER" is MUST for completion of DSC Registration.

One person can have one DSC role only. For Ex: He can register DSC either as a director or authorized representative of the company.

DSC registration on MCA 21-V3 portal is MUST even if the DSC under the particular category has already been registered under MCA 21-V2 portal.

MCA's separate DSC association FAQ (PDF) adds that only business users may associate a DSC at all, and that anyone who signs and files must associate theirs before filing. (Both checked 3 September 2026.)

Three consequences follow, and none of them are a vendor's fault.

The signature happens where the token is. Selecting the token and entering its PIN, with emSigner and emBridge running, is a local act on a specific machine. A tool can assemble the form, chase the attachments and tell you it is ready; it cannot press the button for a director sitting in another city. Judge a product on how well it manages that handoff, not on whether it claims to remove it.

"One person, one DSC role" is a firm-level problem. A partner who is also a director of a client cannot hold both roles on one DSC. Work out who in the practice signs in which capacity before you buy, because the software has to model your actual signatories, not an idealised one.

Custody is a policy question, not a feature. Some workflows end with client tokens in a drawer at the firm. Whether that is acceptable is for the firm and its clients to settle, and it is worth settling before a tool's workflow assumes an answer.

The record you keep, and whose login it sits under

MCA generates a service request number (SRN) on submission, and it is what you quote in any later correspondence. V3 also added "My Application", which shows a user every form they have filed and its current status: pending for DSC upload, under processing, pay fees, resubmission.

Read that carefully. MCA's own history is organised per login, not per firm. When an associate leaves, the portal-side trail of what they filed goes with their login. Your copy of that record is the one you control, which makes it the thing a filing tool is genuinely for.

So ask whether the tool stores, against the client rather than against a person, the SRN, the challan, the form as submitted and the attachments that went with it, and whether every change is attributable to a named user with a timestamp. Then ask for an export and look at what comes out. A record you cannot take with you is not a record, it is a subscription.

What matters less than the demo suggests

"Supports 200+ forms." Almost every practice files a small, repeating set. Depth on AOC-4, MGT-7 and MGT-7A, ADT-1, DIR-3 KYC and the charge forms beats breadth on forms nobody has opened.

"One-click filing." Bounded by the DSC flow above. Treat the claim as a description of the preparation step, and ask what specifically becomes one click.

A long changelog. V3 forms change by notification. What matters is how fast the vendor tracks a change and how you find out, not how many entries the list has.

Disclosure: this site is published by OnCompliance, which builds software in this category. The criteria above are the ones we would want to be judged on, and two of them, the DSC handoff and V3's own validation, are limits no vendor here can design away.

What to do next

  1. Take one client's most recent annual filing and reproduce it in a trial, end to end, including the linked forms. A pack that is right for one real client tells you more than any feature list.
  2. Find the AGM date field and change it. Watch whether every downstream due date moves.
  3. Map the DSC roles of everyone in the firm who signs, against MCA's one-person-one-role rule, before you commit to a workflow.
  4. Ask what happens when MCA marks a form "Resubmission required", because someone has to act on that state inside the tool.
  5. Request a full export of a client's file and open it without the vendor's software.

What this does not cover

This post does not rank products, and it does not compare what vendors charge. It is the set of questions that survive contact with MCA V3, which is the part that does not change between vendors.

Two things we could not verify and are not asserting. First, we found no MCA rule requiring filing software itself to keep an audit trail; the reason to want one is evidentiary rather than statutory, and a claim that MCA mandates it is worth asking a vendor to cite. Second, we could not find an MCA-published interface that lets third-party software submit a company e-form directly. Every route MCA documents ends at a web form signed by an associated DSC, which is what we could confirm rather than proof that nothing else exists.

For the statutory text behind the two annual deadlines, read section 137 on this site. What any particular tool should be trusted with in a particular practice is that practice's own judgement.

roc-filingmca-v3practitionersdsc

This explains a rule; it is not advice for your company. For the authoritative text, follow the sections cited above to the MCA.

More articles

All posts →