Zimperium

India Just Raised the Bar on Mobile App Security

Written by Shashank Pathak | Sep 17, 2026
Here is What Every PSP, ASP, TPAP, and Bank Needs to Know

India processes more than 10 billion UPI transactions every month. That scale made one thing inevitable: attackers would follow the money to mobile.

In May 2025, the National Payments Corporation of India responded. NPCI issued circular NPCI/2025-26/IS/003, a comprehensive mobile application security mandate for every PSP, ASP, and TPAP operating on UPI. The deadline for CERT-IN audit compliance is December 31 of this financial year.

This post explains what the regulation requires, why it was necessary, and what it means for your security and compliance program.

What is NPCI and Why Does its Circular Matter?

NPCI was established in 2008 to build and govern India's payment infrastructure. It is funded and governed by India's member banks. It built UPI. When NPCI issues a security circular, it is not guidance. It is the institution that controls the rails telling you what is required to stay on them.

Non-compliance is not a fine. It is an operational risk. PSPs and TPAPs that cannot demonstrate compliance to a CERT-IN auditor by December 31 face potential transaction restrictions and other regulatory consequences.

Why Did NPCI Have to Act? Understanding Regulatory Dysregulation

Regulatory dysregulation happens when the rules fall behind the threats. That is exactly what happened between NPCI's 2020 RASP guidance and today.

The numbers tell the story. In 2024, mobile banking fraud cases surpassed internet banking fraud for the first time. India now has the highest mobile malware attack rate globally, with a 29% increase in banking malware attacks recorded in the past year. Globally, mobile finance app fraud exceeded $2.64 billion between 2022 and 2023. That number has continued to grow since.

Attackers did not wait for regulators to catch up. They built runtime manipulation tools like Frida that inject scripts into running apps. They created screen overlay attacks that intercept transactions without the user knowing. They distributed repackaged banking apps through unofficial stores and the dark web. The 2020 framework was built for a simpler threat landscape.

NPCI's 2025 circular closes that gap. It adds 23 specific controls, organized under Identify, Protect, Detect, and Respond. It covers everything from root detection and anti-debugging to screen mirroring prevention and automated threat response. And it requires annual audit certification, not self-attestation.

This is not regulatory overreach. It is a regulator recognizing that the attack surface evolved and the rules needed to follow. NPCI acted before a major breach forced the issue.

What the 23 Controls Actually Require

The circular is organized across four domains. Here is what each one means in practice.

A. Identify

Root and jailbreak detection is mandatory, including detection of root cloaking techniques. App installation source must be validated to block sideloaded and repackaged apps. Harmful app detection, virtual device detection, and device blacklisting are recommended.

B. Protect

This is the largest section, with 19 controls. Mandatory requirements include runtime code and data integrity protection, anti-debugging, code obfuscation, OWASP Top 10 coverage, screen obfuscation, proxy network detection, SSL pinning, developer option blocking, auto-read OTP security, reverse engineering prevention, and screen mirroring prevention. Recommended controls include VPN detection, application lock, APK locking, permission controls, wireless debugging prevention, keylogger prevention, screen overlay prevention, and dynamic instrumentation prevention.

C. Detect

Tamper detection with customizable automated response actions is mandatory. Unsecured Wi-Fi detection is recommended.

D. Respond

Real-time alerting to monitoring systems with automated response capabilities is mandatory. This requires the app to send detailed threat information including attack type, affected component, and timestamp to backend monitoring infrastructure.

What Gaps Does NPCI Target

Most organizations have basic security measures. But NPCI's framework specifically targets the gaps that basic measures leave open: reliance on signature-based detections, lack of continuous monitoring across the app install base, and inability to deploy security updates without a new app release.

Effective compliance requires two layers working together. Before release, static and dynamic analysis must identify vulnerabilities, insecure dependencies, and code protection gaps. At runtime, on-device protection must detect and respond to threats without depending on a server connection or a new app version.

The organizations that will navigate this smoothly are the ones that treat NPCI compliance not as an audit checklist but as an ongoing security posture. Continuous monitoring across the full install base, over-the-air threat response updates, and audit-ready evidence generation are not nice-to-haves.

Under NPCI's circular, there are specific requirements.

How Zimperium Helps Comply with the NPCI Framework

Zimperium's Mobile Application Protection platform, MAPS, was purpose built for mobile from the ground up. Its on-device AI engine, developed since 2013, detects and stops app threats at the point of execution. No sensitive user data leaves the device to make that call.

NPCI requires UPI apps to detect and stop tampering, device compromise, and runtime attacks like overlay fraud and screen mirroring. This is mandatory, not optional. Auditors need proof it's happening, not just a policy document. MAPS covers this across the full app lifecycle, before release, at the code level, and on the device.

Before release, the Mobile App Security Testing capability assesses protections and app risk on every build. It runs SAST, DAST, protection validation, and OWASP and MASVS assessment, and generates audit-ready reports mapped to NPCI's specific control requirements. Your team walks into the audit with evidence already built.

At the code level, the App Shielding capability hardens the app itself through obfuscation and anti-tampering protection. This directly covers NPCI's APK locking control, which requires preventing unauthorized redistribution and modification of the app. Even if an attacker gets hold of the APK, they can't easily reverse engineer it, extract logic, or repackage a modified version for distribution.

After release, the Advanced Mobile Runtime Protection capability watches the app on the end user's device. Root detection, jailbreak detection, overlay attack detection, and developer option and USB debug detection cover NPCI's mandatory controls. Frida-based instrumentation detection adds a recommended layer on top, catching dynamic tampering that mandatory checks alone can miss. Bots, emulators, and compromised networks are covered too, all at the point of execution.

Overlay and screen mirroring attacks are not theoretical for a Fraud leader in India right now. Screen sharing scams through apps like AnyDesk have already driven real account takeover losses on UPI. MAPS catches these before the fraud completes.

When a new attack shows up, your team doesn't wait for the next app release to respond. Threat responses deploy over the air, in hours instead of weeks.

Every threat and risk across the full app install base reports in real time to one central console.

    • Continuous visibility for compliance, AppSec, and risk teams
    • Evidence ready for your CERT-In auditor at renewal

Ready to assess your NPCI compliance posture? View the Zimperium MAPS NPCI Compliance Brief, or contact us at zimperium.com to schedule a technical review.