Chat on WhatsApp

RBI 2FA Mandate 2026: Payment Gateway Compliance Checklist for Razorpay, Cashfree, PayU & Stripe

From 1 April 2026 every digital payment needs two factors. Get a PSP-by-PSP compliance checklist for Razorpay, Cashfree, PayU, Stripe India, Easebuzz, Instamojo. Bulk-payout ERP audit for SAP, Tally, Zoho. Checkout abandonment benchmarks and the 30-day action plan.

18 May 2026 13 min read
Key Takeaways
  • From 1 April 2026 every digital payment needs two factors. Get a PSP-by-PSP compliance checklist for Razorpay, Cashfree, PayU, Stripe India, Easebuzz, Instamojo. Bulk-payout ERP audit for SAP, Tally, Zoho. Checkout abandonment benchmarks and the 30-day action plan.
  • Use this as a gst & finance updates checklist for rbi 2fa mandate 2026, not as a substitute for checking current official or platform rules.
  • Confirm thresholds, filing dates, forms, documents, and portal guidance against the source links before filing, buying software, changing campaigns, or changing a workflow.
GST registration document checklist illustration for RBI 2FA Mandate 2026 Payment Gateway

The RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025 (effective 1 April 2026) shifted full liability for fraudulent transactions to the issuer if 2FA isn't in place. For Indian businesses accepting online payments, this changes one thing operationally — you need written 2FA compliance confirmation from your payment aggregator — and two things commercially: checkout abandonment may rise 3-6 percentage points on first measurement, and bulk-payment APIs that authenticate with a single token are now non-compliant. This guide gives you a PSP-by-PSP checklist for Razorpay, Cashfree, PayU, Stripe India, Easebuzz, and Instamojo, plus an ERP-side audit for SAP, Tally Prime, Zoho Books, and Vyapar bulk payment integrations.

Key Takeaways
  • Every digital payment from 1 April 2026 needs two independent authentication factors— OTP alone is no longer compliant.
  • Liability for non-compliant authentication shifts to the issuer (payment platform / bank). The merchant doesn't absorb the fraud directly but inherits the operational cost of failed transactions and customer disputes.
  • PCI DSS v4.0.1 enforcement (since 31 March 2025) layers on top — merchants must monitor client-side scripts to prevent digital skimming. Major PSPs handle this if you use their hosted checkout.
  • Recurring debits above ₹15,000 trigger per-transaction AFA. SaaS plans, EMI businesses, and high-ticket subscriptions face renewed friction at every renewal cycle.
  • Bulk-payment APIs using a single static token are non-compliant. Treasury teams running payouts through SAP, Oracle, Tally, or Zoho must verify session-level + transaction-level AFA in their ERP-to-bank integration.
  • Paytm Payments Bank's licence was cancelled 24 April 2026 — Paytm-rail merchants must migrate to alternative PSPs before the next settlement cycle.
  • Audit deadline: get written 2FA compliance confirmation from your PSP before the next quarterly settlement closure. Non-confirmation = liability gap.

What the 2FA Mandate Actually Requires

The Directions categorise authentication into three "factors of identity":

  • Knowledge — something you know (PIN, password, secret phrase).
  • Possession — something you have (registered device, hardware token, SIM-bound mobile).
  • Inherence — something you are (fingerprint, face, voice biometric).

A compliant transaction must use at least two factors from two different categories. OTP is a knowledge factor; it cannot count as two factors. Card + OTP, device + PIN, biometric + OTP — all valid. Card + OTP + CVV is still one knowledge category — not enough on its own anymore. One of the two factors must be uniquely generated per transaction (rules out reusable PINs as the only token).

Risk-based authentication: the silent change

The Directions allow issuers to apply risk-based authentication: unusual device, new IP geolocation, or anomalous amount triggers additional verification on top of the standard 2FA. For merchants, this means a small percentage of customers will see extra steps mid-checkouton their first transaction with a new device — even though your gateway is configured correctly. Plan customer-service messaging around this. The number to brief CX on: roughly 3-6% of first-time- device transactions trigger an additional step in the first six months of the framework.

PSP-by-PSP Compliance Checklist

Don't assume compliance. Get it in writing — on your PSP's letterhead, addressed to your business — before the next quarterly settlement closes. Here's what to ask each major Indian aggregator.

1. Razorpay

Razorpay is RBI-authorised as a Payment Aggregator and holds PCI DSS Level 1 certification. Built-in tokenisation, automated merchant KYC under the 2025 Master Directions, and AFA-compliant checkout flows are part of their default stack.

ConfirmWhy
Razorpay Standard Checkout uses 2FA on cards, UPI, net-banking, walletsDefault UI handles this; verify if you have custom checkout
Razorpay Subscriptions sends 24-hour pre-debit alert on every recurring debitE-mandate Framework 2026 requirement
Tokenisation replaces raw card data at point of collectionPCI DSS scope reduction
RazorpayX corporate payouts use 2FA per batch, not per sessionTreasury bulk-payout compliance
Card-on-file mandates carry over through card reissuanceReduces involuntary churn

2. Cashfree Payments

Cashfree is RBI-authorised, PCI DSS Level 1 certified. Strong on bulk payouts and fast settlement — Instant Settlement product credits funds within minutes. Cashfree Recurring handles e-mandates with AFA registration and 24-hour pre-debit alerts.

ConfirmWhy
Cashfree Payouts API uses per-payout AFA, not single-token batch authenticationBulk-payment compliance
Cashfree Recurring sends pre-debit + post-debit alerts on every mandateE-mandate Framework 2026
Webhook-based payment confirmation is signed and authenticatedPrevents callback tampering
Instant Settlement settlement instructions are AFA-protectedTreasury operations
Vendor master onboarding for payouts requires PAN + bank-verificationRBI 2025 Master Directions on merchant due diligence

3. PayU India

PayU is RBI-authorised PA. Known for strong fraud-prevention (PayU Hermes) and enterprise scale. Confirm:

  • PayU Biz checkout uses 2FA on all card-not-present transactions.
  • PayU Money recurring mandates use AFA at registration + 24-hour alerts.
  • Fraud-screening (Hermes) is layered, not replacing 2FA.
  • Refund and chargeback flow conforms to RBI's revised digital-fraud compensation framework (April 2026).

4. Stripe India

Stripe operates in India through PA licence. Particularly relevant for B2B SaaS and cross-border SaaS billing. Confirm:

  • Stripe Payments uses 3D Secure 2 (3DS2) for card 2FA — globally compliant and AFA-equivalent.
  • Stripe Billing recurring debits comply with the E-mandate Framework 2026.
  • Cross-border CNP transactions are 2FA-compliant before the 1 October 2026 deadline.
  • BIN registration with international networks (Visa, Mastercard, Amex) is current.

5. Easebuzz and Instamojo (SMB-focused)

For smaller merchants and direct-to-consumer brands, Easebuzz and Instamojo are common choices. Both are RBI-authorised PAs. The compliance bar is the same — but smaller PSPs may have slower product-update cycles, so verify:

  • Standard checkout 2FA flow is live on all channels (not "coming soon").
  • Recurring/subscription products are E-mandate Framework 2026 compliant.
  • Settlement reports include the AFA verification status per transaction (for audit trail).

6. Paytm — migrate immediately

On 24 April 2026, the RBI cancelled Paytm Payments Bank Limited's banking licence under Section 22(4) of the Banking Regulation Act for persistent compliance failures. Consumer-facing apps and merchant QRs continue via partner banks, but settlement infrastructure is disrupted and partner- bank coverage is uneven. Merchants currently routing through Paytm rails should migrate to an alternative PA before the next settlement cycle. Maintain dual rails until confidence is restored.

The PSP Confirmation Letter: What to Demand

Send your aggregator's account manager an email requesting written confirmation of the following. Copy your CFO and the head of finance. Get it on letterhead, dated post-April 2026.

Template confirmation letter

"We confirm that, as of [date], all merchant accounts of [Your Business] under our PA licence comply with: (a) RBI Authentication Mechanisms for Digital Payment Transactions Directions, 2025 for all card, UPI, net-banking, wallet, and PPI transactions; (b) RBI Digital Payments – E-mandate Framework, 2026 for all recurring mandates including pre-debit and post-debit notifications; (c) PCI DSS v4.0.1 client-side script monitoring; (d) RBI Master Directions for Payment Aggregators, 2025 including data localisation. We assume issuer-side liability for non-compliant authentication in accordance with these directions."

Checkout Abandonment: What to Expect and How to Measure

Pre-April 2026, Indian e-commerce cart abandonment averaged 65-75% with payment-step drop-off contributing 15-25% of that. The 2FA mandate adds a second authentication step on some transactions — particularly first-device transactions and amounts that trigger risk-based extra verification.

CohortPre-April 2026 abandonmentExpected post-April 2026Levers to recover
Returning customer, saved card15-25%18-28%Card tokenisation, device fingerprint trust
First-time customer, new device30-45%35-52%UPI default, trust badges, prefilled forms
High-ticket (above ₹15,000) recurring5-10% per cycle8-15% per cycleConcierge billing, AFA-prompt timing
Cross-border CNP cards40-60%45-68% (after 1 Oct 2026)Local-currency presentment, alternative rails

To measure properly: capture checkout funnel events in GA4 (or your analytics tool) at three steps — payment-method-selected, authentication-prompt-shown, payment-success. The middle step is new. Comparing pre- and post-April cohorts on this funnel quantifies the AFA-friction cost.

UX patterns that reduce 2FA drop-off

  1. Default to UPI for amounts under ₹1 lakh. UPI's PIN-plus-device 2FA is faster than card OTP. UPI checkout conversion in India typically beats card by 8-15 percentage points.
  2. Tokenise cards via your PSP's token vault. Tokenised cards skip the CVV re-entry on returning purchases and use device-bound authentication — fewer false-positive risk triggers.
  3. Show the bank's 2FA prompt inline if your PSP supports it. The pop-up-redirect- return pattern loses customers; the modal-overlay pattern keeps them in the funnel.
  4. Communicate the extra step — a one-line "Your bank will ask to confirm; this is normal" reduces panic abandonment on first-encountering customers.
  5. Don't force 3DS2 on low-risk transactions — if your PSP supports merchant-initiated risk scoring, low-risk transactions can be exempted from the second factor (frictionless flow under 3DS2).

Bulk Payment APIs: The Hidden Compliance Failure

The 2FA mandate covers customer-initiated digital payment transactions. For B2B bulk payouts — vendor payments, salary disbursement, refunds, marketplace seller settlements — the framework is interpreted by RBI to require AFA at the transaction initiation point, not just at user login. Single-token batch authentication, where one OTP authorises a batch of 500 payments, is non-compliant from April 2026.

ERP-to-bank integration: what to audit

IntegrationCommon patternCompliance statusFix
SAP S/4HANA → bank H2HSFTP file drop with single signing keyNon-compliantMove to API-based with per-batch AFA + treasury maker-checker
Tally Prime → bank APISingle API token in Tally configurationLikely non-compliantUse connector that surfaces AFA per batch; manual confirm before submit
Zoho Books → ICICI/HDFC/SBI direct integrationOAuth-based; per-batch authorisationCompliant in newer connectorsConfirm last connector update; require AFA on payouts > ₹1L
Vyapar → UPI corporateUPI Lite / corporate UPI with per-txn approvalCompliant by designMaintain device-level lock and biometric on approver phone
Custom NodeJS/Python → bank APIService-account tokenNon-compliant unless renewed per sessionImplement session-bound AFA token rotation; treasury maker-checker UI

Treasury maker-checker is the cheapest fix: one person prepares the batch in the ERP, a second person logs into the bank's corporate portal with their own AFA, reviews the batch summary, and releases it. This adds 5-10 minutes per batch but converts a non-compliant flow into a fully auditable one. Most enterprise CFOs adopt this even when not strictly required.

Liability Math: Who Pays When 2FA Fails

The Directions assign liability based on the failure mode:

  • Issuer (bank/PSP) didn't implement 2FA properly — issuer absorbs the fraud loss and is statutorily required to compensate the customer.
  • Customer disclosed credentials (phishing, social engineering) — RBI's revised digital-fraud compensation framework limits customer liability if the customer reports within the prescribed window (typically 3 working days for zero liability, 4-7 days for limited liability).
  • Merchant systems compromised — merchant absorbs the chargeback (and faces potential PCI DSS non-compliance penalties). This is why PCI DSS v4.0.1 enforcement matters as much as 2FA itself.

For most merchants using a fully-managed PSP like Razorpay, Cashfree, or PayU, the PSP's PA licence makes them the issuer for compliance purposes — and the merchant escapes direct fraud liability. But the operational cost of failed transactions and customer-service overhead is still yours. The cleanest way to manage this is to choose a PSP whose merchant-side dashboard provides per-transaction AFA verification status as an audit-ready field.

The 30-Day Action Plan

  1. Week 1. Email PSP account manager — request 2FA compliance confirmation letter. Run checkout funnel measurement in GA4 to establish baseline.
  2. Week 2. Audit ERP-to-bank integration. Identify single-token batch flows. Brief treasury team on maker-checker requirement.
  3. Week 3. Update checkout UX: default-to-UPI, inline 2FA prompt where supported, customer-facing copy on "your bank may ask to confirm".
  4. Week 4. Reconcile baseline funnel data against first month under new framework. Identify highest drop-off step and prioritise the next intervention.

How Bizeract Can Help

  • Payment gateway integration audit for your checkout — Razorpay, Cashfree, PayU, Stripe, Easebuzz, Instamojo configurations reviewed against the 2026 framework.
  • Bulk-payout workflow upgrade — replace single-token batch flows with per-batch AFA + treasury maker-checker, integrated with Tally, Zoho, or Vyapar.
  • Checkout funnel measurement setup in GA4/GTM with AFA-friction attribution.
  • Migration support if you're currently on Paytm rails and need to move to an RBI-compliant alternative before next settlement cycle.

Frequently Asked Questions

Q: Is my Razorpay/Cashfree/PayU integration automatically 2FA-compliant?

The PSP's default Standard Checkout is generally compliant for cards, UPI, net-banking, wallets, and recurring mandates from April 2026 onwards. However, if you use Custom Checkout, server-side payment APIs, or integrations built before 2024, manual verification is required. Always request a written compliance confirmation letter from the PSP's account team.

Q: Does the 2FA mandate apply to my QR-code receipt at the counter?

Static merchant QR (P2M) transactions are typically authenticated by the payer's UPI PIN + device — already meeting the two-factor standard. Dynamic QR (per-transaction) with risk-based authentication is the cleaner pattern. Confirm with your PSP that QR transactions are flagged in their AFA verification logs.

Q: My checkout converts at 35%. Will the 2FA mandate drop me to 30%?

Possibly, but the headline number is misleading. The drop concentrates in specific cohorts (first-device, cross-border CNP, high-ticket recurring). Segment your funnel before optimising — blanket discount or trust-badge interventions waste budget. Measure per-cohort drop-off first, then apply targeted UX patterns.

Q: We pay 200 vendors every month via Tally + bank API. Are we compliant?

If the integration uses a single static API token that authorises the entire 200-vendor batch in one call, almost certainly not. Move to a flow where Tally generates the payment file but a designated maker/checker logs into the bank's corporate portal, reviews the file, and releases the batch with their own AFA. The audit trail is also cleaner.

Q: What about international card payments on my SaaS billing?

Cross-border CNP card transactions need 2FA from 1 October 2026 — a later deadline than domestic. Card issuers must register their BINs with international networks (Visa, Mastercard) for the new authentication flow to work. If you bill foreign customers via Stripe, Razorpay International, or similar, confirm 3DS2 is active on the cross-border rails and that BIN registration is up to date well before 1 October 2026.

Q: We use Paytm currently. What's the migration urgency?

High. RBI cancelled Paytm Payments Bank's licence on 24 April 2026. Consumer-facing apps continue via partner banks, but settlement infrastructure has been disrupted and partner-bank coverage is uneven. Migrate to Razorpay, Cashfree, PayU, or Stripe before your next settlement cycle. Maintain a dual-rail setup (Paytm + alternative) for 90 days while customer payment habits adjust.

Q: How often should we re-verify PSP compliance?

Quarterly. Get a fresh confirmation letter from the PSP at the start of each financial quarter, after any major PSP product update, and immediately after any regulatory change (new RBI direction, PCI DSS update). For listed companies, attach the confirmation to the quarterly compliance certificate.

The Bottom Line

The RBI 2FA mandate doesn't change much for merchants who use a well-managed Indian payment aggregator — Razorpay, Cashfree, PayU, Stripe India, Easebuzz, and Instamojo all handle the authentication burden in their default checkout. What changes is the documentation discipline (get the compliance letter), the funnel measurement (track AFA-induced drop-off cohort by cohort), and the bulk-payout workflow (replace single-token batches with per-batch AFA or treasury maker- checker). Do these three things before the next quarterly close and you're operating cleanly under the new framework. Skip them, and a single high-value chargeback or a treasury audit finding will cost more than the work would have.

Sources: RBI Authentication Mechanisms for Digital Payment Transactions Directions, 2025; RBI Master Directions for Payment Aggregators, 2025; RBI Digital Payments — E-mandate Framework, 2026; PCI DSS v4.0.1 (enforced 31 March 2025); RBI cancellation order on Paytm Payments Bank Limited (24 April 2026); industry coverage by Razorpay, Cashfree, PayU, Stripe India, and Chargebee on RBI compliance.

What should you verify before using this GST & Finance Updates guide?

Before acting on rbi 2fa mandate 2026, verify the current rules or platform behavior with the GST Portal. The practical answer depends on your business model, state, turnover, documents, software stack, and whether the decision affects tax, customer data, paid media spend, or a production workflow.

Use this article as a working checklist, then confirm thresholds, registration status, return forms, document rules, and portal notices. In our audits, most expensive mistakes do not come from ignoring the whole process. They come from one stale assumption, one mismatched address, one missing event, or one automation path that nobody tested after launch.

CheckpointWhy it mattersWhere to confirm
Current rule or platform statusLimits, forms, policies, and APIs can change after a blog update.GST Portal
Your exact business caseA local shop, freelancer, D2C store, agency, and SaaS team rarely need the same next step.Documents, invoices, campaign data, analytics setup, or workflow logs
Implementation evidenceThe safest GST decision is backed by proof, not memory or screenshots from an old setup.Portal acknowledgement, dashboard export, invoice sample, test lead, or error log

How do we apply this in real business work?

We start with the smallest decision that can be verified. For compliance work, that means matching PAN, address, bank, invoices, and portal status before filing. For websites, marketing, analytics, and automation, it means testing the real user path from first click to final record. The boring checks catch the costly failures.

A useful rule: if a claim changes money, tax, reporting, or customer communication, keep evidence for it. Save the acknowledgement, export the report, test the form, and note the date you verified the source. That gives you a clean trail when a client, officer, platform, or internal team asks why the setup was done that way.

When should you get expert review?

Get expert review when the next action can create tax exposure, lost reporting data, ad waste, broken customer communication, or production downtime. A simple self-check is enough for low-risk learning. A filed return, new registration, tracking migration, paid campaign restructure, or live automation deserves a second set of eyes before it affects customers or records.

How often should this be rechecked?

Recheck the decision whenever your turnover, state, product mix, campaign budget, website stack, analytics property, or workflow ownership changes. Also recheck it after major portal updates, platform policy changes, annual filing deadlines, and vendor migrations. The guide is useful today only if the facts behind it still match your business.

What is the fastest safe way to decide?

Write the decision in one sentence, list the proof needed for that sentence, and verify only those items first. This keeps the work focused. If the proof confirms the decision, proceed. If one item is unclear, pause and resolve that point before changing filings, campaigns, tracking, website code, or automation logic.

What can go wrong if you skip verification?

The usual failure is not dramatic at first. It looks like a rejected application, a wrong tax invoice, a missing conversion, a duplicate lead, a broken report, or a workflow that silently stops. Those small failures become expensive when nobody notices them until month-end reporting, filing day, or a customer escalation.

What evidence should you keep after making the change?

Keep enough evidence to reconstruct the decision later. For a compliance topic, that usually means the application reference number, registration certificate, invoice sample, return acknowledgement, payment challan, notice reply, or source link checked on the day of filing. For a website, campaign, analytics setup, or automation, keep the before-and-after screenshot, test submission, dashboard export, webhook log, and the exact setting that changed.

This matters because most business fixes are revisited months later, when nobody remembers the original reason. A short evidence trail makes audits faster, handovers cleaner, and vendor conversations more precise. It also keeps the advice in this guide tied to your real operating context instead of becoming a generic checklist that gets copied without review.

  • Date checked: record when the official source, dashboard, or portal screen was reviewed.
  • Business context: note the entity, state, product, campaign, property, or workflow affected.
  • Proof of action: save the acknowledgement, report export, test result, or live URL.
  • Owner: assign one person to re-check the item when rules, tools, or business volume change.
Verification workflowUse this loop before changing money, tax, reporting, or customer communication.1234Check sourceMatch recordsTest actionSave proof
Repeat this check whenever rules, platform settings, business volume, or ownership changes.

Which next step should you take after reading this?

Turn the article into one action list. Mark what is already true, what needs proof, and what needs expert review. If you want to go deeper, compare this guide with RBI New Rules April 2026: 2FA Mandate, NBFC TDS & Cash Reporting — A Business Guide, RBI E-mandate Framework 2026: SaaS & Subscription Churn Playbook for India, and E-commerce Workflow Automation for Indian Businesses: Razorpay → Invoice → WhatsApp → CRM (2026). Then update the decision only after the official source and your own records agree.

Frequently asked questions

Is Razorpay automatically 2FA-compliant after April 2026?

Razorpay's Standard Checkout and Subscriptions products are 2FA-compliant by default for cards, UPI, net-banking, wallets, and recurring mandates under the RBI Authentication Mechanisms for Digital Payment Transactions Directions, 2025. Custom Checkout, server-side payment APIs, or integrations built before 2024 require manual verification. Always request a written compliance confirmation letter from the Razorpay account team.

Does the RBI 2FA mandate apply to bulk payment APIs?

Yes. RBI interprets the framework to require AFA at the transaction-initiation point — not just at user login. Single-token batch authentication where one OTP authorises a batch of 500 payments is non-compliant from April 2026. ERP-to-bank integrations must either implement per-batch AFA or use treasury maker-checker workflow where a second person logs into the bank portal to release each batch.

What is OTP considered under the new 2FA framework?

OTP is a single authentication factor in the "knowledge" category (something you know). To meet the 2FA standard, OTP must be combined with a second factor from a different category — possession (device binding, hardware token) or inherence (fingerprint, face biometric). One of the two factors must be uniquely generated per transaction.

How much will checkout abandonment rise after the 2FA mandate?

Effect varies by cohort. Returning customers with saved tokenised cards see modest 3-5 percentage point rise. First-time customers on new devices may see 5-7 point rise due to risk-based extra verification. High-ticket recurring transactions above ₹15,000 face renewed AFA friction every cycle. Cross-border CNP card transactions face the steepest impact after the 1 October 2026 deadline.

Which Indian payment aggregators are RBI-authorised under the 2025 Master Directions?

Major RBI-authorised Payment Aggregators include Razorpay, Cashfree, PayU India, Stripe India, Easebuzz, Instamojo, and several others. Each holds PCI DSS Level 1 certification and operates under the 2025 RBI Master Directions for Payment Aggregators with 100% data localisation, 24-hour foreign-data purge, and merchant due diligence requirements.

Should I migrate from Paytm to another payment gateway?

Yes, with urgency. RBI cancelled Paytm Payments Bank Limited's banking licence on 24 April 2026 under Section 22(4) of the Banking Regulation Act for persistent compliance failures. Consumer-facing apps continue via partner banks, but settlement infrastructure is disrupted. Migrate to Razorpay, Cashfree, PayU, or Stripe before the next settlement cycle and maintain dual rails for 90 days.

When do cross-border card transactions need to be 2FA-compliant?

Cross-border Card-Not-Present (CNP) transactions must implement 2FA by 1 October 2026 — a later deadline than the 1 April 2026 domestic mandate. Card issuers must register their Bank Identification Numbers (BINs) with international networks (Visa, Mastercard, Amex) before this date. SaaS businesses billing foreign customers must verify 3DS2 is active on cross-border rails.

Let's Talk

Let's talk about your business.

Tell us what you're working on and where you want to go. We'll put together a plan. No obligation, no sales pitch.

  • Free 30-minute call
  • A plan built around your goals
  • No obligation, no pressure
  • Your own account manager

By submitting, you agree to our privacy policy. We'll never spam you.