UPI, Wallets & Real-Time Payments · Compliance

NPCI UPI MASF: what it requires of your app's mobile security.

NPCI's UPI Mobile App Security Framework (MASF) requires UPI apps to check the device isn't rooted, tampered with, hooked, running on an emulator, or being screen-mirrored, and to recognise the device across sessions. The compliance date was 19 May 2025 — and it isn't a one-time gate: certification from a CERT-In empanelled auditor is due every year, by 31 December.

Who This Binds

PSPs, TPAPs, and Banks on the UPI Network.

MASF applies to Payment Service Providers and Third-Party App Providers offering a UPI app, and to banks that expose UPI inside their own app.

The RequirementWhat Satisfies It in NonaShieldInstrument
App integrity (RASP) Phone health — root, tamper, hook, overlay and debugger detection, live on the device. NPCI UPI MASF
Device binding Device recognition across sessions and accounts, so a UPI credential doesn't quietly move to a new handset. NPCI UPI MASF · RBI DPSC
Request & channel integrity API-layer certificate pinning, proxy detection and signed-payload validation on every request. NPCI UPI API OC-215A · PCI DSS v4.0.1

MASF is the app-and-device layer; OC-215A is the API-channel layer. Instruments as published by NPCI and PCI SSC, under circular NPCI2025-26IS003. Compliance certification from a CERT-In empanelled auditor is required annually, by 31 December. Not legal advice; confirm current requirements with your compliance counsel.

The Deadlines

One Compliance Date. One That Repeats Every Year.

19 May 2025

The compliance date for MASF's app and device integrity checks, under circular NPCI2025-26IS003. Dates are compliance dates, not issue dates, as published by NPCI.

31 December, Every Year

A UPI Information Security Compliance Framework submission is due annually, with compliance certification from a CERT-In empanelled auditor. This isn't a one-time gate — it repeats every financial year.

Why It Matters

Set It Against What UPI Fraud Costs.

₹1,087 cr

reported UPI fraud loss in FY24, across 13.42 lakh cases

₹981 cr

reported in FY25, across 12.64 lakh cases

₹805 cr

reported in FY26 up to November, across 10.64 lakh cases

Source: Ministry of Finance reply in the Lok Sabha, December 2025, as reported by the press. Reported cases and losses, not NonaShield measurements.

Common Mistake

Root Detection Alone Isn't MASF Compliance.

What teams treat as "done"

  • A basic root-check library that a hooking framework can defeat.
  • Checking device health at login, then never again in the session.
  • No signed record of what the check actually found.

What MASF is actually asking for

  • Detection that survives Frida and Xposed-style hooking, not just root-flag checks.
  • Continuous device-health checks, not a one-time gate at login.
  • Device recognition tied to a hardware-backed identity, not a soft device ID.
  • A signed record of the check, for when a transaction is disputed.

Screen-sharing and remote-access scams pass every check that only looks at the device, because the real customer is using their real phone — the compromise is in who's driving the session, not the hardware. MASF's device checks and NonaShield's behavioural layer answer two different questions; both are part of the same requirement. See the behavioural detection case study.

The Full Picture

One Platform, Twelve Controls, Every Sector.

NPCI UPI MASF is one of seven compliance instruments NonaShield maps to on day one — alongside the RBI Digital Payment Security Controls, RBI Authentication Directions, RBI Digital Lending Directions, PCI DSS v4.0.1, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →

Questions People Ask

NPCI UPI MASF, Answered.

What does NPCI's UPI MASF require of a mobile app?

NPCI's UPI Mobile App Security Framework (MASF) requires UPI apps to check that the device isn't rooted, tampered with, hooked, running on an emulator, or being screen-mirrored, and to recognise the device across sessions. The compliance date was 19 May 2025.

Who does NPCI UPI MASF apply to?

Payment Service Providers (PSPs), Third-Party App Providers (TPAPs) and banks that offer a UPI app or UPI functionality inside their own app on the UPI network.

Is NPCI UPI MASF the same as the UPI API OC-215A circular?

No, they cover different layers. MASF is about the app and device itself — root, tamper and hook detection, device recognition. OC-215A is about the API channel — certificate pinning, proxy detection and signed-payload validation on every request.

How does NonaShield map to NPCI UPI MASF?

NonaShield's RASP layer checks device health — root, tamper, hooking, overlay and debugger detection — and device fingerprinting recognises the device across sessions, both control-mapped to MASF on day one. The API gateway separately satisfies OC-215A's channel-integrity checks.

Is NPCI UPI MASF compliance a one-time requirement?

No. Beyond the initial compliance date, NPCI circular NPCI2025-26IS003 requires a UPI Information Security Compliance Framework submission every financial year, with compliance certification from a CERT-In empanelled auditor, due by 31 December annually.

Ask Us for the Coverage Report.

Twelve controls, mapped to NPCI UPI MASF and OC-215A, for your app.