NPCI's UPI Mobile App Security Framework (MASF) requires UPI apps to check the device isn't rooted, tampered with, hooked, running on an emulator, or being screen-mirrored, and to recognise the device across sessions. The compliance date was 19 May 2025 — and it isn't a one-time gate: certification from a CERT-In empanelled auditor is due every year, by 31 December.
MASF applies to Payment Service Providers and Third-Party App Providers offering a UPI app, and to banks that expose UPI inside their own app.
| The Requirement | What Satisfies It in NonaShield | Instrument |
|---|---|---|
| App integrity (RASP) | Phone health — root, tamper, hook, overlay and debugger detection, live on the device. | NPCI UPI MASF |
| Device binding | Device recognition across sessions and accounts, so a UPI credential doesn't quietly move to a new handset. | NPCI UPI MASF · RBI DPSC |
| Request & channel integrity | API-layer certificate pinning, proxy detection and signed-payload validation on every request. | NPCI UPI API OC-215A · PCI DSS v4.0.1 |
MASF is the app-and-device layer; OC-215A is the API-channel layer. Instruments as published by NPCI and PCI SSC, under circular NPCI2025-26IS003. Compliance certification from a CERT-In empanelled auditor is required annually, by 31 December. Not legal advice; confirm current requirements with your compliance counsel.
The compliance date for MASF's app and device integrity checks, under circular NPCI2025-26IS003. Dates are compliance dates, not issue dates, as published by NPCI.
A UPI Information Security Compliance Framework submission is due annually, with compliance certification from a CERT-In empanelled auditor. This isn't a one-time gate — it repeats every financial year.
reported UPI fraud loss in FY24, across 13.42 lakh cases
reported in FY25, across 12.64 lakh cases
reported in FY26 up to November, across 10.64 lakh cases
Source: Ministry of Finance reply in the Lok Sabha, December 2025, as reported by the press. Reported cases and losses, not NonaShield measurements.
Screen-sharing and remote-access scams pass every check that only looks at the device, because the real customer is using their real phone — the compromise is in who's driving the session, not the hardware. MASF's device checks and NonaShield's behavioural layer answer two different questions; both are part of the same requirement. See the behavioural detection case study.
NPCI UPI MASF is one of seven compliance instruments NonaShield maps to on day one — alongside the RBI Digital Payment Security Controls, RBI Authentication Directions, RBI Digital Lending Directions, PCI DSS v4.0.1, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →
NPCI's UPI Mobile App Security Framework (MASF) requires UPI apps to check that the device isn't rooted, tampered with, hooked, running on an emulator, or being screen-mirrored, and to recognise the device across sessions. The compliance date was 19 May 2025.
Payment Service Providers (PSPs), Third-Party App Providers (TPAPs) and banks that offer a UPI app or UPI functionality inside their own app on the UPI network.
No, they cover different layers. MASF is about the app and device itself — root, tamper and hook detection, device recognition. OC-215A is about the API channel — certificate pinning, proxy detection and signed-payload validation on every request.
NonaShield's RASP layer checks device health — root, tamper, hooking, overlay and debugger detection — and device fingerprinting recognises the device across sessions, both control-mapped to MASF on day one. The API gateway separately satisfies OC-215A's channel-integrity checks.
No. Beyond the initial compliance date, NPCI circular NPCI2025-26IS003 requires a UPI Information Security Compliance Framework submission every financial year, with compliance certification from a CERT-In empanelled auditor, due by 31 December annually.
Twelve controls, mapped to NPCI UPI MASF and OC-215A, for your app.