DPI Brief — August 28, 2026

UPI Turns 10: Payment Aggregators Demand Seat at the MDR Table

Layer: L2 — Payments

UPI completed a decade on August 25, and the anniversary arrived with fresh friction over how the upcoming merchant discount rate pie will be sliced. Payment aggregators (PAs) including Razorpay, PayU, and PhonePe are pushing for a fixed, direct share of UPI MDR — bypassing the sponsor banks that currently intermediate their fee flow. The demand, reported by Business Standard on August 27, is likely to meet resistance: PAs are not direct members of the NPCI-run UPI network and sit outside the formal fee-splitting structure that names only issuing banks, acquiring banks, and PSP banks.

The backdrop matters. Parliament passed the Taxation and Other Laws (Amendment) Bill, 2026 last month, amending Section 10A of the Payment and Settlement Systems Act to permit MDR on UPI for a limited category of high-threshold merchant transactions. P2P transactions stay free. The RBI and DFS are now deliberating the MDR slab and participant-level splits. PAs argue that their experience with the existing UPI/RuPay subsidy programme — where banks delayed or under-remitted their share — justifies a direct allocation.

The milestone stats: annual UPI transaction value jumped from ₹0.07 lakh crore in FY17 to ~₹314 lakh crore in FY26 (4,000x), while volumes surged from 1.78 crore to over 24,162 crore (13,000x). July 2026 set a new monthly record at 2,366 crore transactions worth ₹29.88 lakh crore. India now accounts for 49% of global real-time payment volumes. Banks live on UPI rose from 21 at launch to 741 as of July 2026.

CERT-In Joins APCERT Cyber Drill on RMM Compromise

Layer: L7 — Trust

CERT-In participated in the APCERT Cyber Drill 2026 on August 26, themed around “Incident Response: RMM-related Compromise.” The exercise simulated SQL Injection, Kerberoasting, and other techniques used to weaponise Remote Monitoring and Management solutions — a growing attack vector as enterprises adopt RMM tools for endpoint management. Twenty-three CSIRTs from 18 Asia-Pacific economies participated, with two additional teams from OIC-CERT and AfricaCERT. CERT-In flagged the drill on its homepage on August 27.

RMM abuse is particularly relevant for India’s DPI stack: Aadhaar authentication endpoints, UPI switch infrastructure, and ABDM health facility gateways all rely on managed IT environments where compromised RMM access could provide lateral movement into critical systems. The drill underscores that CERT-In’s 12-hour patch mandate for known exploited vulnerabilities (issued May 25) remains the operative compliance deadline for entities managing DPI-adjacent infrastructure.

GeM’s Womaniya Crosses 2.1 Lakh Women MSE Registrations

Layer: L4 — Commerce

The Womaniya initiative on the Government e-Marketplace (GeM) crossed 2.1 lakh women-owned MSE registrations in FY 2025-26, DD News reported on August 28. Operating under the broader SWAYATT framework launched in 2019, Womaniya reduces entry barriers for women entrepreneurs and self-help groups to sell directly to government buyers. GeM’s overall procurement from MSMEs crossed ₹2.37 lakh crore in FY26.

The milestone is part of a wider GeM expansion: cumulative gross merchandise value has surpassed ₹18.4 lakh crore, with ₹5 lakh crore transacted in the current financial year alone. The platform also continues to serve as a procurement channel for digital infrastructure — NIC’s August 26 and 27 bid notices for Redis Enterprise Software and professional hiring were floated through GeM.

JANANI Reaches 1.34 Crore Registrations; Ranchi Mandates ABDM Compliance

Layer: L5 — Sectoral (Health)

Two developments on the ABDM front. The JANANI maternal healthcare platform has recorded 1.34 crore registrations, DD News reported on August 27. The platform supports interoperable digital health records and accepts ABHA, Aadhaar-linked OTP, and other identifiers for registration — making it a live demonstration of the ABDM stack’s integration potential at the point of care.

Separately, the Jharkhand government has issued a directive requiring all private hospitals in Ranchi to achieve 100% ABDM-based HMIS compliance by August 30, 2026, with legal action threatened for non-compliance. The move signals that state governments are beginning to enforce ABDM adoption through regulatory mandates rather than incentives alone. Over 93 crore ABHA accounts have been created nationally, and 1.59 lakh facilities are using ABDM-enabled software.