RBI Mandates Two-Factor Authentication For Digital Payments

RBI Mandates Two-Factor Authentication For Digital Payments

SUMMARY

RBI has made two-factor authentication (2FA) mandatory for all digital transactions from April 1, 2026

The new framework aims to strengthen digital payment security while enabling smoother and more flexible processes in a rapidly digitising environment

All payment service providers and partners are required to adhere to the new directions for domestic payments

A year after proposing alternate methods of additional factor of authentication (AFA) for digital transactions, the Reserve Bank of India (RBI) has released new directions, making two-factor authentication (2FA) mandatory for all digital transactions from April 1, 2026.

An AFA requires the use of more than one factor for authentication of a payment instruction. The new framework aims to strengthen digital payment security while enabling smoother and more flexible processes in a rapidly digitising environment.

“The factors of authentication can be from “something the user has”, “something the user knows” or “something the user is” and may comprise, inter-alia, password, SMS based OTP, passphrase, PIN, card hardware, software token, fingerprint, or any other form of biometrics (device native or Aadhaar based),” the RBI said in a notification. 

As no specific factor was mandated for authentication, the digital payments ecosystem has been using SMS-based OTP as the additional factor for authentication for digital transactions till now. The new norms aim to facilitate the use of innovative authentication mechanisms that have emerged over the past few years.

“Issuers may also explore using DigiLocker as a platform for notification and confirmation for high-risk transactions,” the notification added.

All payment service providers and partners are required to adhere to the new directions for domestic payments. 

However, the new rules won’t apply to cross-border transactions. But card issuers will be required to set up systems that check and confirm international online card payments when foreign merchants or payment companies request authentication by October 1, 2026.

The new rules don’t call for discontinuation of SMS-based OTP as an authentication factor, the RBI added. 

The central bank said that at least one of the factors of authentication should be dynamically created or proven, which means it should be unique for that transaction, for all digital payment transactions except those which are carried out through the physical use of a card at the point of transaction.

The development comes at a time when financial frauds and cyber frauds are on the rise in the country. Indians lost INR 107.21 Cr to cyber frauds in the first nine months of FY25. 

Note: We at Inc42 take our ethics very seriously. More information about it can be found here.

You have reached your limit of free stories
Join Us In Celebrating 5 Years Of Inc42 Plus!

Unlock special offers and join 10,000+ founders, investors & operators staying ahead in India’s startup economy.

2 YEAR PLAN
₹19999
₹5999
₹249/Month
UNLOCK 70% OFF
Cancel Anytime
1 YEAR PLAN
₹9999
₹3499
₹291/Month
UNLOCK 65% OFF
Cancel Anytime
Already A Member?
Discover Startups & Business Models

Unleash your potential by exploring unlimited articles, trackers, and playbooks. Identify the hottest startup deals, supercharge your innovation projects, and stay updated with expert curation.

RBI Mandates Two-Factor Authentication For Digital Payments-Inc42 Media
How-To’s on Starting & Scaling Up

Empower yourself with comprehensive playbooks, expert analysis, and invaluable insights. Learn to validate ideas, acquire customers, secure funding, and navigate the journey to startup success.

RBI Mandates Two-Factor Authentication For Digital Payments-Inc42 Media
Identify Trends & New Markets

Access 75+ in-depth reports on frontier industries. Gain exclusive market intelligence, understand market landscapes, and decode emerging trends to make informed decisions.

RBI Mandates Two-Factor Authentication For Digital Payments-Inc42 Media
Track & Decode the Investment Landscape

Stay ahead with startup and funding trackers. Analyse investment strategies, profile successful investors, and keep track of upcoming funds, accelerators, and more.

RBI Mandates Two-Factor Authentication For Digital Payments-Inc42 Media
RBI Mandates Two-Factor Authentication For Digital Payments-Inc42 Media
You’re in Good company