
If you run revenue assurance, wholesale, or API products at a mobile operator, you have probably already noticed it in the numbers: OTP-related A2P SMS traffic to certain banking and fintech accounts has been flattening or declining since late 2024. That is not random churn. It is regulation, and it is happening on a country-by-country basis, on fixed deadlines, with financial penalties attached for the banks that miss them.
This page is the reference tracker. It lists every confirmed SMS OTP ban or phase-out mandate affecting financial services as of June 2026, the regulator behind it, the effective date, and — critically for operators — what each mandate means for your A2P SMS revenue and your opportunity to sell a compliant authentication API in its place. Two of the five deadlines below (India and the run-up to the UAE deadline) have already passed by the time you are reading this, which means the conversation with your enterprise and banking accounts has shifted from "you should prepare" to "are you compliant right now."
We update this tracker quarterly as new mandates are announced and existing ones move from "upcoming" to "in force." Bookmark it, or talk to our team directly if you need a briefing for your wholesale or enterprise sales conversations this quarter.
Why Regulators Are Banning SMS OTP
Every mandate on this page traces back to the same four underlying problems with SMS as an authentication channel. None of them are new — operators have lived with SS7 and SIM-swap risk for years — but 2025 was the year regulators stopped treating them as theoretical and started writing them into law.
SS7 Network Vulnerabilities
The SS7 signalling protocol that routes SMS between networks was never designed with authentication in mind. Attackers with access to SS7 interconnects — whether through compromised carrier credentials or grey-market signalling access — can intercept OTP messages in transit without the subscriber or the bank ever knowing. This is not a hypothetical: SS7-based OTP interception has been documented in fraud cases across multiple markets, and it is one of the specific risks cited by regulators including the Reserve Bank of India when justifying the move away from SMS-only authentication.
SIM Swap Fraud
SIM swap fraud — where an attacker fraudulently ports or reissues a victim's SIM to intercept their OTPs — has grown alongside the value of mobile-linked financial accounts. Because SMS OTP authenticates the SIM, not the legitimate subscriber, a successful SIM swap defeats the entire control. Operators bear an awkward dual exposure here: SIM swap fraud damages subscriber trust in the operator's own channel, even though the actual breach occurs in a third party's authentication flow.
Artificially Inflated Traffic (AIT) Fraud
AIT fraud — where fraudulent actors trigger high volumes of OTP messages to premium or international routes purely to generate termination fees — costs the industry more than $1.2 billion annually, with some routes seeing cost spikes as high as 256%. Because OTP triggers are usually unauthenticated at the application layer (anyone can submit a phone number to a login form), OTP flows are one of the most heavily targeted vectors for AIT. This is direct, measurable revenue leakage that operators absorb today, and it disappears entirely once an enterprise migrates to a non-SMS authentication method.
The NIST Phishing-Resistance Standard
NIST finalised SP 800-63B-4, the latest revision of its Digital Identity Guidelines, in July 2025. The update is explicit that SMS OTP does not meet the bar for phishing-resistant authentication at AAL2 — the assurance level most financial and government services require — because a user can still be tricked into relaying a valid OTP to an attacker in real time. Regulators across multiple jurisdictions, including the RBI in India, cite phishing-resistance requirements similar in spirit to NIST's framework when drafting their own SMS OTP restrictions.
Country-by-Country Regulatory Status (As of June 2026)
The table below summarises every confirmed mandate. "Status" reflects where each market actually stands today, not the original announcement date — two of the five deadlines have already passed.
India — RBI Authentication Mechanisms Directions, 2025
The RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025, notified on 25 September 2025, came into force on 1 April 2026 — meaning it has already been in effect for nearly three months as of this update. Every digital payment now requires two distinct authentication factors, with at least one dynamically generated and tied to the specific transaction, and at least one resistant to phishing. SMS OTP alone no longer satisfies the rule. India's mobile operators — Jio, Airtel, Vodafone Idea, and the regional players — saw this coming: SIM Swap and Number Verification APIs launched under GSMA Open Gateway at India Mobile Congress in October 2025, ahead of the deadline. The gap that remains for most operators is a full silent authentication layer, not just individual point APIs.
UAE — CBUAE Notice 3057
The Central Bank of the UAE's Notice CBUAE/FCMCP/2025/3057 set 31 March 2026 as the hard deadline for licensed financial institutions to eliminate SMS and email OTP as standalone authentication, with penalties of up to AED 250,000 per violation from that date. Banks including Emirates NBD, ADIB, and First Abu Dhabi Bank completed their transition away from SMS OTP before the end of 2025, ahead of the deadline. Etisalat and du, as the UAE's network operators, are the natural infrastructure partners for the entitlement-server and silent-authentication layer those banks now depend on. Our sister brand Message Central has published a
detailed breakdown of the CBUAE phase-out for compliance teams if you need the banking-side view alongside this operator-side tracker.
Singapore — Already Completed
Singapore moved first and fastest. MAS and the Association of Banks in Singapore announced in July 2024 that major retail banks would phase out SMS OTP for digital-token users within three months — a deadline that has now been fully in effect for close to two years. Singapore is the clearest precedent available to operators elsewhere: a market can move from SMS OTP as default to SMS OTP as exception in under a year once a regulator sets a firm date.
Malaysia and Hong Kong — Regional Momentum
Malaysia's Bank Negara issued RMiT (Risk Management in Technology) guidance pushing banks toward app-based verification as early as 2022, and Maybank — the country's largest bank — completed its migration away from SMS OTP by September 2024. Hong Kong's HKMA has taken a softer supervisory-guidance approach rather than a hard mandate, but the direction of travel is identical: SMS OTP is being treated as a legacy fallback, not a primary control, across virtually every regulated market in APAC.
Markets to Watch
The Philippines, Nigeria, Saudi Arabia, and Indonesia have not yet issued formal SMS OTP bans, but each has live regulatory discussion underway and, in the Philippines' case, active commercial momentum: Globe and GCash completed a Phase 1 silent network authentication proof of concept in December 2025, well ahead of any formal mandate. Operators in these markets that move early on authentication infrastructure will be negotiating from commercial leverage rather than regulatory catch-up when a mandate does land.
What This Means for Mobile Operators
Read purely as a compliance story, this tracker is a bank problem. Read as a revenue story, it is an operator opportunity — and the two are connected through your network. Every bank and fintech account that loses SMS OTP as a viable authentication method needs a replacement, and the only entities that can deliver SIM-based, network-verified authentication at carrier grade are mobile operators. The revenue that disappears from your A2P OTP traffic does not have to disappear from your books; it can migrate into a new line item.
The commercial conversation with your wholesale and enterprise accounts has changed in the last twelve months. It is no longer "would you consider an alternative to SMS OTP" — it is "what API can you give us today that keeps us compliant." Operators that already have an entitlement server and a silent authentication offering in market are having that conversation now. Operators that do not are watching the same enterprise accounts go shopping for a replacement, and not finding one in their own network's product catalogue.
This is also a retention story, not just a new-revenue story. Enterprise and banking accounts that cannot get a compliant authentication API from their existing operator relationship will source one from a competing network, an over-the-top identity vendor, or a global aggregator — taking both the authentication revenue and the underlying A2P relationship with them. Revenue assurance and wholesale teams that have historically treated OTP traffic as a passive, low-margin SMS category should treat this tracker as an early warning system: every new country that appears in the table above is a forecast of which accounts on your books are about to start shopping.
Approved Alternatives — What Replaces SMS OTP
Every mandate above points toward the same set of replacement technologies. They are not equivalent, and the differences matter when you are positioning what your network can actually deliver.
App-based push and biometric authentication satisfy the phishing-resistance requirement, but only for the share of users who have installed and activated the bank's app — which is precisely why Singapore's mandate still depends on digital token activation rates, and why regulators elsewhere are wary of an app-only approach that excludes lower-digital-literacy and rural users. Silent network authentication closes that gap: it works through the SIM itself, requires no app, and — when paired with a USSD fallback — extends to 2G and 3G subscribers who app-based methods cannot reach at all. That combination is what SilentAuth+ was built to deliver: TS.43 EAP-AKA authentication with a unique USSD fallback layer, already running across 104+ operator networks.
For operators evaluating a build-versus-partner decision, the calculation is similar to standing up any new network function: an in-house entitlement server and authentication stack typically takes 12 to 24 months to design, test, and certify against OEM and GSMA requirements, while a partner deployment can be live in a fraction of that time because the entitlement server, EAP-AKA integration, and USSD fallback logic already exist and have been proven across more than a hundred live networks. Given that two of the five deadlines on this tracker have already passed, the build timeline is the more expensive choice twice over — once in engineering cost, and once in the enterprise revenue that walks out the door while the build is still in progress.
What Operators Should Do Now
- Audit your A2P OTP traffic by vertical. Identify which banking and fintech accounts are sending OTP volume into the five markets tracked above — they are the accounts most exposed to mandate-driven churn this year.
- Confirm your entitlement server readiness. TS.43-based silent authentication routes through your entitlement server (ECS). If you do not have one in production, this is the infrastructure gap to close first.
- Stand up a USSD fallback path. Regulators are not just asking for phishing resistance — they are implicitly asking for inclusion across 2G/3G subscribers. A pure smartphone-app or biometric story will not reach your full base.
- Package authentication as a billable API, not a courtesy. Number Verification (NV2), SIM Swap detection, and silent authentication are monetisable products under GSMA Open Gateway and CAMARA — price them accordingly.
- Lead the conversation with regulated accounts before they ask. Banks and fintechs facing the UAE and India deadlines are actively sourcing alternatives this quarter. Being first in that conversation is a wholesale sales advantage, not just a compliance courtesy.
- Re-check this tracker quarterly. Hong Kong, the Philippines, Nigeria, and Saudi Arabia are all candidates for a formal mandate within the next 12–18 months — we update this page each quarter as that picture changes.
Frequently Asked Questions
Which countries have banned or restricted SMS OTP for banking as of 2026?
India (RBI, in force since 1 April 2026), the UAE (CBUAE Notice 3057, in force since 31 March 2026), Singapore (MAS/ABS, completed July 2024), and Malaysia (Bank Negara RMiT guidance, largely completed by September 2024) have confirmed mandates. Hong Kong has supervisory guidance moving in the same direction. The Philippines, Nigeria, Saudi Arabia, and Indonesia have active discussion but no formal mandate yet.
Has India's RBI SMS OTP rule actually taken effect, or is it still upcoming?
It is already in force. The RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025 was notified on 25 September 2025 and became effective on 1 April 2026 — meaning Indian banks and payment providers have been required to use two-factor authentication with at least one phishing-resistant or dynamic factor since that date.
Does this mean SMS OTP is banned entirely?
No. Most mandates restrict SMS OTP as a standalone or primary factor rather than banning the channel outright. SMS can often still play a role as one signal within a multi-factor flow, but it can no longer be the only factor, and in several markets it can no longer be the phishing-resistant factor a transaction requires.
What makes an authentication method 'phishing-resistant' under standards like NIST SP 800-63B-4?
A phishing-resistant method cannot be relayed by a user to an attacker in real time, even if the user is deceived. SMS OTP fails this test because a user can read a code aloud or paste it into a fake site. Cryptographic, device-bound, or SIM-based methods — including silent network authentication via TS.43/EAP-AKA — are designed so there is no code for a user to leak in the first place.
How can a mobile operator monetise SMS OTP bans instead of losing the A2P revenue?
By offering the replacement directly: silent network authentication (TS.43, NV2) and SIM Swap detection APIs, sold as per-verification products to the same banking and fintech accounts that previously generated OTP SMS traffic. Operators with an entitlement server and a USSD fallback path can serve smartphone and feature-phone users alike, which most app-only alternatives cannot.
How often is this regulatory tracker updated?
Quarterly, or sooner if a major regulator announces a new mandate. The status column reflects the live position as of the date at the top of this page, not the original announcement date — check back each quarter for changes.
.png)
.png)

