From 1 April 2026, all domestic digital payments—whether made through UPI, cards, wallets, or net banking—will require two-factor authentication (2FA). This change comes under the Reserve Bank of India’s circular RBI/2025-26/79, issued on 25 September 2025.
The move standardises payment security across platforms, ensuring that every transaction is verified using at least two independent authentication factors.
If you already use Bajaj Pay for utility bills, mobile recharges, or FASTag management, you are operating within the Bharat Bill Payment System (BBPS)—a framework that has always followed multi-layered authentication and real-time monitoring. The new rules simply extend similar safeguards across the entire digital payments ecosystem.
Table of Contents
Why is the RBI doing this?
The numbers tell the story plainly.
- processed 186 billion transactions in FY 2024-25 — up 42% from the previous year
- As per NPCI, by January 2026, monthly UPI volumes had hit an all-time high of 21.7 billion transactions worth ₹28.33 lakh crore
- According to the Ministry of Finance, fraud losses stood at ₹485 crore across 6.32 lakh incidents in FY 2024-25 alone
- The most exploited weakness has been the SMS-based OTP — criminals intercept it mid-transit or clone a victim’s SIM card to receive codes meant for someone else
The fraud does not happen because users are careless. It happens because an OTP travelling over a mobile network is only as secure as that network itself. The RBI’s fix is direct — make at least one authentication factor dynamic, meaning it is generated fresh on the user’s device for that specific transaction and is worthless the moment the payment is done.
Why is the RBI making 2FA mandatory?
India’s rapid adoption of digital payments has made security a top priority.
- UPI processed 186 billion transactions in FY 2024–25, a 42% increase year-on-year
- As per NPCI, by January 2026, monthly UPI volumes had hit an all-time high of 21.7 billion transactions worth ₹28.33 lakh crore
- According to the Ministry of Finance, fraud losses stood at ₹485 crore across 6.32 lakh incidents in FY 2024-25 alone
A key vulnerability has been SMS-based OTPs. These can be intercepted or misused through SIM cloning, making them less reliable as a standalone authentication method.
To address this, the RBI now requires at least one authentication factor to be dynamic, meaning it is generated specifically for each transaction and cannot be reused.
Two rules, one goal
The April 2026 change is driven by two separate but connected regulatory documents. Here is what each one does.
RBI Directions (RBI/2025-26/79) — the legal mandate, effective 1 April 2026
- Applies to all domestic digital payment instruments — cards, wallets, net banking, and UPI
- Every transaction must use at least two distinct authentication factors
- The three recognised categories are: something you know (PIN or password), something you have (an OTP on your registered device), and something you are (a biometric)
- For all non-card-present transactions, at least one factor must be dynamic — generated uniquely for that transaction
- Compromising one factor must not affect the security of the other — both must work independently
- Platforms can apply additional verification for high-risk transactions based on location, device, or behaviour — DigiLocker can be used as a secure confirmation channel
- Exemptions apply to: small-value contactless card transactions, FASTag (NETC) transactions, recurring e-mandate payments (after the first), and small-value offline digital payments
NPCI Circular OC-226 (7 October 2025) — the UPI-specific instruction
- Introduces on-device biometric authentication — fingerprint or face recognition — as a genuine alternative to entering your UPI PIN
- Initial cap of ₹5,000 per transaction — subject to review by NPCI after assessing system performance
- Introduces Aadhaar-based Face Authentication for UPI PIN setup and reset — no debit card number or OTP required to get started
- Particularly useful for senior citizens and first-time smartphone users who have found the traditional onboarding process difficult
In short — the RBI Directions set the floor, and NPCI OC-226 tells UPI how to meet it without making things harder for everyday users.
What this means for you on 1 April 2026
For most users, this date will pass without much disruption. Here is what to expect.
- Using a PIN today? Nothing changes — PIN-based UPI stays fully valid
- Want biometric authentication? You must opt in yourself — no app can activate it without your explicit consent
- Once enabled, biometrics switch off automatically if you reset your UPI PIN or go 90 consecutive days without using it — you will need to re-consent after either event
- Rooted or jailbroken phones are excluded — biometric authentication requires a secure, unmodified device
- International card payments have a separate deadline — additional authentication for non-recurring cross-border card-not-present transactions must be in place by 1 October 2026
The single most important step right now is to keep your UPI app updated. Banks are required to roll out the new authentication flows before the deadline, and those updates reach you automatically through your app.
How Bajaj Pay already aligns with these changes
When you pay bills or recharge through Bajaj Pay, transactions are processed via BBPS—a system designed with built-in verification layers and real-time monitoring.
This means:
- Multi-step authentication is already in place
- Transactions are tracked within a regulated ecosystem
- You experience minimal disruption as new rules roll out
The bigger picture
According to ACI Worldwide, 2024 – India now accounts for roughly 49% of all real-time payment transactions globally. At that scale, any gap in authentication architecture has real consequences. The April 2026 mandate does not slow UPI down — it protects a system that hundreds of millions of people rely on daily, and makes it more accessible for those who have always found OTPs the most unreliable part of the process.

