Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025
UR
- Applies toAll regulated entities
- StatusIn force
- ImportanceMUST READ
- IssuedSep 25, 2025
- Amendmentsnone tracked
- Length29 points in 4 sections · 3 min read
The four dates on this rule
- PublishedSep 25, 2025The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actApril 01, 2026The day by which the work this rule asks for must be finished.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
What it says
Must know
1. Two-factor rule for all payments
Every digital payment transaction in India needs two factors of authentication.
2. Comply by April 2026
All payment providers and participants must comply with these rules by April 01, 2026.
3. Covers all payment system players
These rules cover every payment system provider and participant, banks and non-banks.
4. Domestic transactions only, unless exempt
The rules apply to domestic digital payments, unless specifically exempted.
5. Minimum two authentication factors required
Every digital payment must use at least two separate authentication factors, unless exempted.
6. One factor must be dynamic
For most transactions, at least one authentication factor must be created fresh each time.
7. Factors must not depend together
If one factor is broken, the other one must still work on its own.
8. Issuer pays for non-compliance losses
If a loss happens because the issuer broke these rules, it must repay the customer in full.
9. Cross-border card deals excluded
These directions do not apply to cross-border digital payment transactions.
10. A ₹2,000 exemption is repealed
RBI has repealed the old rule letting small card payments under ₹2,000 skip extra checks.
Do it
1. Issuers may offer factor choice
Issuers may let customers choose which authentication factors to use.
2. Open access to authentication tools
Providers must make their authentication or tokenisation service open to every application.
3. Issuers may weigh transaction risk
Issuers may check transactions against risk signals like location and device details.
4. DigiLocker may flag risky payments
Issuers may use DigiLocker to notify and confirm high-risk transactions.
5. Issuer must test its system
The issuer must check its login system is sound before using it.
6. Follow the data protection law
Issuers must follow the Digital Personal Data Protection Act, 2023.
7. Validate cross-border card requests soon
By October 01, 2026, card issuers must set up checks for one-time cross-border card payments.
8. Register card numbers with networks
Card issuers must register their BINs with card networks.
9. Second cross-border risk check
By October 01, 2026, card issuers must also add a risk-based check for cross-border card payments.
Background
1. Legal basis for these rules
RBI issues these rules under Sections 18 and 10(2) of the PSS Act, 2007.
2. What authentication means
RBI says authentication means checking who sent the payment order.
3. What a CNP transaction is
A CNP transaction is one where the card is not physically present.
4. What card-present means
A card-present transaction is done by physically using the card at the transaction point.
5. What cross-border CNP means
A cross-border CNP transaction is an Indian card used to pay an overseas merchant.
6. What a factor is
A factor of authentication is a credential used to confirm the customer.
7. Who counts as issuer
The issuer is the bank or non-bank that holds the customer's account.
8. Undefined terms follow PSS Act
Any word not defined here takes its meaning from the PSS Act, 2007.
9. Extra checks allowed for risk
Riskier transactions may get checks beyond the minimum two-factor authentication.
10. Old card-security circulars are repealed
This rule replaces a list of older card-security circulars listed in Annexure-2.