A parliamentary panel has warned that delays in notifying a tiered MDR framework for UPI transactions could severely restrict cybersecurity spending across India's digital payment network.

Delay in UPI MDR Framework Threatens Cybersecurity Investments, Warns Parliamentary Panel

The420 Web Correspondent
5 Min Read

In a stern warning regarding the financial health of India’s digital payment ecosystem, a parliamentary panel has cautioned that prolonged delays in notifying a tiered Merchant Discount Rate (MDR) framework could severely undermine investments in cybersecurity and fraud prevention. The Standing Committee on Finance, chaired by senior parliamentarian Bhartruhari Mahtab, presented its 44th report in the Lok Sabha on August 12, highlighting critical vulnerabilities created by a persistent funding gap between operational costs and government subsidies.

The report scrutinised the Union Government’s action taken on recommendations concerning the Department of Financial Services’ Demands for Grants for 2026-27. While India’s Unified Payments Interface (UPI) and RuPay platforms continue to process record transaction volumes, the committee observed that payment service providers and acquiring banks are operating under acute financial strain. This structural deficit, if left unaddressed, risks starving critical digital infrastructure of the capital required to keep pace with evolving cyber threats.

The Massive Fiscal Mismatch in the Zero-MDR Regime

At the heart of the committee’s concern lies a stark disparity between the actual operational expenses incurred by the digital payments industry and the fiscal support allocated by the state. For the financial year 2026-27, the Union Budget earmarked ₹2,000 crore to compensate banks and fintech entities for maintaining the zero-MDR framework on RuPay debit cards and low-value person-to-merchant UPI transactions.

Industry assessments, however, estimate the total operational costs associated with processing, network infrastructure, and real-time transaction maintenance at approximately ₹20,700 crore. The parliamentary panel described this ₹18,700 crore gap as a matter of serious concern, noting that payment service providers remain unviably dependent on inadequate annual subsidies.

Without a predictable and self-sustaining revenue stream, payment processors may be forced to curtail capital expenditure on background network upgrades, server redundancy, and automated threat detection mechanisms. Such capital cuts could compromise the operational resilience of India’s primary retail payment architecture.

Legislative Groundwork and the Tiered Charging Model

The parliamentary warning follows recent legislative action aimed at resolving the zero-MDR deadlock. Parliament passed the Taxation and Other Laws (Amendment) Bill, 2026, which amended Section 10A of the Payment and Settlement Systems Act, 2007. This statutory modification removed the explicit legal prohibition against levying transaction fees on notified electronic payment modes, empowering the Central Government to establish a calibrated pricing structure.

Under the proposed tiered framework, consumer-to-consumer transfers and small merchant transactions will remain entirely free of charge to preserve digital inclusion. However, a limited MDR is slated for notification on high-value merchant transactions exceeding defined turnover thresholds.

The committee urged the Union Ministry of Finance to expedite the formal notification and operationalisation of this tiered mechanism. A predictable fee structure for large commercial entities would allow payment service providers to monetise high-volume enterprise traffic while shielding small vendors and everyday retail users from additional financial burdens.

Fraud Prevention Pressures and Pension Scheme Liabilities

The necessity for sustained cybersecurity spending comes amidst a sophisticated wave of digital financial crimes across the country. Renowned cybercrime expert and former IPS officer Prof. Triveni Singh emphasized that digital payment networks require continuous, capital-intensive upgrades in real-time risk analytics, behavioral threat monitoring, and automated system verification to counter increasingly complex fraud tactics.

Prof. Singh noted that any hesitation in modernising risk infrastructure directly exposes vulnerable demographics to predatory cyber schemes. Maintaining public trust in digital payments requires an equitable balance between low transaction costs and robust, cutting-edge security architecture.

Beyond payment infrastructure, the Standing Committee on Finance also flagged escalating liability concerns regarding central social security programmes. The panel highlighted that subsidy burdens for the Pradhan Mantri Vaya Vandana Yojana (PMVVY) surged dramatically from ₹27.58 crore in FY 2022-23 to ₹597.33 crore in FY 2025-26, while the Atal Pension Yojana (APY) continues to require annual gap funding of over ₹202 crore.

Calling for a comprehensive evaluation of interest rate risk management across public pension vehicles, the committee urged the Department of Financial Services to institute concrete, forward-looking measures. The report underscored that fiscal stability across both digital transaction frameworks and long-term social security schemes remains imperative to safeguard India’s broader financial stability.

Stay Connected