DUBAI — If you bank in the UAE, the way you verify your transactions is about to change permanently. By the end of March 2026, every bank, exchange house, and payment provider in the Emirates must complete the full phase-out of SMS and email-based one-time passwords (OTPs) — and the clock has nearly run out.
The mandate comes from the Central Bank of the UAE (CBUAE), which launched the transition phase on July 25, 2025. What started as a gradual rollout is now entering its final chapter, with complete compliance required across all licensed financial institutions.
Why Is the UAE Killing OTPs?
OTPs sent via SMS or email were once considered a reliable security layer, but they have become a prime target for cybercriminals. The weaknesses are well-documented:
- SIM-swapping fraud: Criminals convince telecom providers to transfer your number to their SIM card, intercepting your OTPs in real time.
- Phishing attacks: Fake bank websites and messages trick users into entering their OTPs on spoofed platforms.
- SS7 protocol vulnerabilities: The ageing infrastructure underlying mobile networks can be exploited to intercept text messages.
The UAE's move mirrors similar actions taken globally. Singapore's Monetary Authority banned SMS OTPs for retail banking in 2024, and Malaysia followed suit. The CBUAE is now setting the same gold standard for the Gulf region.
What Replaces OTPs? The 5 New Methods
Rather than a single replacement, UAE banks are deploying a suite of advanced authentication technologies. You may already be using some of them:
| Method | How It Works | Security Level |
|---|---|---|
| In-App Push Notifications | Approve or deny transactions directly in your bank's app | High |
| Biometric Verification | Fingerprint scans, Face ID, or Emirates Face Recognition | Very High |
| Soft Token (In-App) | Time-based codes generated securely within the app itself | High |
| Passkeys | Cryptographic credentials stored on your device, phishing-proof | Very High |
| Device Binding | Your credentials are locked to your registered phone hardware | High |
Major UAE banks have been proactive. Emirates NBD, ADIB, and First Abu Dhabi Bank (FAB) have already rolled out biometric and in-app authentication solutions for the majority of online and in-store transactions. Most customers will notice the change most acutely during large online purchases or QR payments at restaurants.
What Do You Need to Do?
For most users, the transition will be seamless — but only if you take a few proactive steps:
- Update your bank's mobile app to the latest version from the App Store or Google Play immediately.
- Register your device within the app if prompted. This is a one-time setup process.
- Enable biometrics (Face ID or fingerprint) within your banking app's security settings.
- Avoid relying on SMS codes — these will no longer arrive for major transactions after the full rollout.
"The enhanced security measures align with global best practices and are designed to deliver a smoother, faster, and significantly more secure banking experience for all UAE residents." — Central Bank of the UAE directive.
What If You Don't Have a Smartphone?
The CBUAE directive includes provisions ensuring that banks accommodate customers who are unable to use smartphone-based authentication. Physical hardware tokens and in-branch verification remain available as fallback options for those who require them. Contact your bank directly for alternative authentication arrangements.
The Bigger Picture: UAE's Push for Digital Security
This OTP phase-out is part of a broader national strategy to position the UAE as a global leader in digital financial security. The move aligns with the country's increasing vigilance against cyberattacks, which have intensified in recent months. With the UAE processing billions of dirhams in digital transactions daily, the stakes for getting this right have never been higher.
As April begins, the era of waiting for a text message before every transaction is officially over. The future of UAE banking is already in your pocket — you just need to set it up.