Full News

Co. Law, Sebi, Audit & A/c
Enhanced Security Measures for Accessing the Central Recordkeeping Agency (CRA) System for National Pension System (NPS) Related Tasks

PFRDA Mandates 2-Factor Aadhaar Authentication for CRA System Access

PFRDA Mandates 2-Factor Aadhaar Authentication for CRA System Access

The Pension Fund Regulatory and Development Authority (PFRDA) has issued Circular No: PFRDA 2024/06/Sup-CRA/03, dated 15th March 2024, announcing a significant security enhancement for accessing the Central Recordkeeping Agency (CRA) system for National Pension System (NPS) related tasks. Effective from 1st April 2024, all password-based users logging into the CRA system are required to undergo mandatory 2-Factor Aadhaar Authentication. This proactive step aims to enhance the security posture of the National Pension System by leveraging Aadhaar-based authentication to fortify the integrity of transactions, mitigate risks, and uphold the trust of subscribers and stakeholders in the system. The circular outlines the process for Nodal offices to link their Aadhaar and proceed with functional activities using the CRA system, emphasizing the importance of implementing the necessary framework for the new Aadhaar-based login and authentication to ensure a seamless transition to the enhanced security paradigm.

Key Takeaways:

1. Increased Security: The introduction of mandatory 2-Factor Aadhaar Authentication for CRA system access significantly reduces the risk of unauthorized access and enhances protection for NPS transactions and the interests of subscribers and stakeholders.


2. Additional Security Feature: The Aadhaar-based authentication will be integrated with the current User ID and Password-based login process, enabling 2-Factor Authentication for accessing the CRA system.


3. Aadhaar Mapping: Nodal offices under the Government Sector are required to link their Aadhaar with their respective CRA User ID, enabling underlying users to initiate Aadhaar Mapping.


4. Performance of NPS Activities: All offices under the Government Sector and Autonomous Bodies are required to implement the necessary framework for the additional feature of Aadhaar-based login and authentication in the CRA system to carry out all NPS related activities.


5. Standard Operating Process: The attached document outlines the process for Nodal offices attached with Protean CRA to link their Aadhaar and proceed with functional activities using the CRA system.

Synopsis:

The Pension Fund Regulatory and Development Authority (PFRDA) has recently issued Circular No: PFRDA 2024/06/Sup-CRA/03, dated 15th March 2024, announcing a significant security enhancement for accessing the Central Recordkeeping Agency (CRA) system for National Pension System (NPS) related tasks. This circular mandates the implementation of mandatory 2-Factor Aadhaar Authentication for all password-based users logging into the CRA system, effective from 1st April 2024.

Purpose of 2-Factor Aadhaar Authentication

The introduction of mandatory 2-Factor Aadhaar Authentication for CRA system access signifies a proactive step towards enhancing the security posture of the National Pension System. By leveraging Aadhaar-based authentication, the PFRDA aims to fortify the integrity of transactions, mitigate risks, and uphold the trust of subscribers and stakeholders in the system.

Key Points from the Circular

1. Benefits of 2-Factor Authentication: The circular emphasizes the increased security and enhanced protection provided by the two-factor approach, significantly reducing the risk of unauthorized access to the CRA system and safeguarding NPS transactions.


2. Additional Security Feature: The circular outlines that the current password-based login for Nodal Offices under Central and State Governments, including their underlying Autonomous bodies, will be integrated with Aadhaar-based authentication to enable 2-Factor Authentication for accessing the CRA system.


3. Aadhaar Mapping: It is specified that User IDs of Nodal offices under the Government Sector (Central/State/CAB/SAB) will be permitted to login to the CRA system using 2-Factor Authentication through Aadhaar OTP (One-time password). The Oversight office (PrAO/DTA) and PAO/DTO are required to link their Aadhaar with their respective CRA User IDs to enable underlying users to initiate Aadhaar Mapping.


4. Performance of NPS Activities: All offices under the Government Sector and Autonomous Bodies are mandated to implement the necessary framework for the additional feature of Aadhaar-based login and authentication in the CRA system to carry out all NPS related activities.

Implementation Process

The circular also provides a detailed Standard Operating Process for Nodal offices attached with Protean CRA to link their Aadhaar and proceed with functional activities using the CRA system. This process includes one-time registration of Aadhaar number against Nodal Office User ID, authentication of Aadhaar Mapping to Nodal Office User ID, status view for Aadhaar Mapping, and the procedure for regular (Aadhaar-based) access to the CRA system.

Acronyms and Abbreviations

The circular includes a section detailing the acronyms and abbreviations used in the document, providing a comprehensive reference for the readers.

Overview

The document provides an overview of the current access provided to Government and Corporate Nodal offices to the CRA system for executing NPS related activities and generating/viewing/downloading various reports. It emphasizes the mandatory introduction of 2-Factor Aadhaar based authentication for all password-based users logging into the CRA system, effective from 1st April 2024.

Process for One-Time Linking of Aadhaar with Nodal Office User ID

The circular outlines the step-by-step process for Nodal Office Users to link their Aadhaar with their User ID, including the submission of Aadhaar details, validation, and verification through OTP. It also details the process for the oversight office to authorize the Aadhaar linking transaction for underlying offices.

Conclusion

In conclusion, the circular serves as a comprehensive guide for Government and Corporate Nodal offices, along with Autonomous Bodies, to implement the necessary framework for the new Aadhaar-based login and authentication and ensure seamless execution of all NPS-related activities.

FAQ

Q1: What is the purpose of the circular issued by PFRDA?

A1: The circular aims to enhance the security posture of the National Pension System by mandating 2-Factor Aadhaar Authentication for accessing the Central Recordkeeping Agency (CRA) system for NPS related tasks.


Q2: Who is required to undergo mandatory 2-Factor Aadhaar Authentication?

A2: Effective from 1st April 2024, all password-based users logging into the CRA system are required to undergo mandatory 2-Factor Aadhaar Authentication.


Q3: What are the steps for Nodal offices to link their Aadhaar and proceed with functional activities using the CRA system?

A3: The document outlines the process for Nodal offices to link their Aadhaar and proceed with functional activities using the CRA system, covering one-time registration of Aadhaar number against Nodal Office User ID, authentication of Aadhaar Mapping to Nodal Office User ID, status view for Aadhaar Mapping, and procedure for regular (Aadhaar-based) access to the CRA system.