The National Pension System (NPS) is set to undergo a significant security upgrade. From April 1, 2024, all users logging into the Central Record-keeping Agency (CRA) system will be required to authenticate their identity through a two-factor process involving Aadhaar. This move aims to bolster the security of NPS transactions and safeguard the interests of subscribers and stakeholders.
The Pension Fund Regulatory and Development Authority (PFRDA) has taken a proactive step to enhance the security measures surrounding the National Pension System (NPS). Effective April 1, 2024, a new layer of protection will be implemented, mandating all password-based users to undergo two-factor authentication involving Aadhaar before gaining access to the Central Record-keeping Agency (CRA) system.
This additional security measure is designed to mitigate the risk of unauthorized access to the CRA system, which serves as the central repository for NPS data and transactions. By integrating Aadhaar-based authentication with the existing user ID and password login process, the PFRDA aims to create a robust two-factor authentication mechanism.
The process of logging into the NPS CRA system with the new two-factor authentication will involve the following steps:
1. Visit the NPS website and navigate to the login section.
2. Enter your user ID and password as usual.
3. Provide the captcha verification.
4. Upon successful entry of credentials, a new window will prompt for Aadhaar authentication.
5. An One-Time Password (OTP) will be sent to your registered mobile number.
6. Enter the received OTP to complete the two-factor authentication process.
Once the Aadhaar-based authentication is successfully completed, users will gain access to their NPS account and can proceed with their desired transactions or activities.
The introduction of this additional security layer is a proactive measure to safeguard the interests of NPS subscribers and stakeholders. By leveraging the unique identification capabilities of Aadhaar, the PFRDA aims to significantly reduce the risk of unauthorized access and ensure the integrity of NPS transactions.
Furthermore, the circular issued by the PFRDA outlines specific guidelines for government and autonomous bodies to implement Aadhaar-based login and authentication in the CRA system for NPS operations. Nodal offices in the government sector will have the option to use Aadhaar OTP for two-factor authentication on the CRA and NPSCAN systems.
To facilitate the implementation of this security enhancement, the PFRDA has provided a roadmap for Aadhaar mapping. Oversight offices (PrAO/DTA) must first link Aadhaar with the corresponding CRA User ID, enabling PAO/DTOs to subsequently link their Aadhaar with their CRA User IDs. This cascading process will allow DDOs (Drawing and Disbursing Officers) to commence Aadhaar linkage and ensure a seamless transition to the new two-factor authentication system.
Q1: Why is the PFRDA introducing two-factor Aadhaar authentication for NPS?
A1: The two-factor Aadhaar authentication aims to enhance the security of NPS transactions and protect the interests of subscribers and stakeholders by reducing the risk of unauthorized access to the CRA system.
Q2: When will the new two-factor authentication process become mandatory?
A2: The new security measure will be implemented from April 1, 2024, for all password-based users logging into the CRA system.
Q3: How will the two-factor authentication process work?
A3: Users will first enter their user ID and password as usual, followed by captcha verification. They will then be prompted for Aadhaar authentication, where an OTP will be sent to their registered mobile number. Entering the OTP will complete the two-factor authentication process.
Q4: What is the role of government and autonomous bodies in implementing this security measure?
A4: Government and autonomous bodies must implement Aadhaar-based login and authentication in the CRA system for NPS operations. Nodal offices in the government sector can use Aadhaar OTP for two-factor authentication on the CRA and NPSCAN systems.
Q5: How will Aadhaar mapping be facilitated for the new authentication process?
A5: Oversight offices (PrAO/DTA) must first link Aadhaar with the corresponding CRA User ID. PAO/DTOs can then link their Aadhaar with their CRA User IDs, enabling DDOs to commence Aadhaar linkage for the two-factor authentication system.