DEEP IDDEEP ID
Back
August 27, 2026

DoT SIM Binding Mandate Explained: Compliance Guide for Communication Apps (2026)

T

Team

DoT SIM Binding Mandate Explained

Summarize this article with

Cybercriminals misuse mobile numbers via communication apps to carry out phishing, impersonation, investment scams, and digital arrest fraud. To prevent the misuse of telecom identifiers, the Department of Telecommunications (DoT) introduced the DoT SIM Binding Mandate under the Telecom Cyber Security (TCS) Rules, 2024. According to this mandate, OTT communication apps are required to use SIM Binding and ensure that all apps work on the device where the SIM is present. It helps prevent account misuse and improve detection and tracing.

What is SIM Binding?

SIM Binding is a security mechanism that cryptographically links a user’s app account to the SIM card installed in their mobile device. Instead of relying on a one-time mobile number verification during registration, the app continuously verifies that the registered SIM remains present in the device during login or other sensitive actions.


The verification is performed using telecom identifiers linked with the SIM, such as the International Mobile Subscriber Identity (IMSI), along with device-level checks. If the expected SIM is missing, replaced, or moved to another device, the app can block access or require re-verification.


It prevents SIM swap fraud, account takeover, remote account misuse, and automated abuse.

What is the DoT SIM Binding Mandate?

DoT SIM Binding Mandate is the set of directions the Department of Telecommunications (DoT) issued on 28 November 2025 under the Telecom Cyber Security Rules 2024.


The main objective of this mandate is to prevent misuse of Indian mobile numbers for fraud.


This mandate makes it mandatory for OTT and app-based communication services that use mobile numbers for identification to keep the account linked with the active SIM card present in the user’s device.


The apps should also automatically log out web sessions within 6 hours (periodic logout) and allow users to reconnect through QR code-based device linking.

Why Did DoT Introduce SIM Binding?

DoT has introduced SIM Binding for the following reasons:

Close the SIM removal loophole

Some communication apps continued to work even when the SIM was removed or unavailable on the device.

Reduce Cyber Fraud

SIM Binding helps prevent phishing, digital arrest scams, impersonation fraud, investment scams, and account misuse.

Increase Traceability

SIM binding confirms that accounts remain linked to an active SIM and authorized device.

Reduce Rising Fraud Losses

Cyber fraud losses in India reached approximately ₹22,845 crore in 2024. It highlights the need for stronger telecom security measures.

Who Must Comply with DoT SIM Binding Directions?

The directions apply to Telecommunication Identifier User Entities (TIUEs) — app-based communication services that use Indian mobile numbers for user identification, verification, or service delivery.

WhatsApp

Telegram

Signal

Arratai

Snapchat

Sharechat

Jiochat

Josh

What are the Key Requirements Under the DoT SIM Binding Mandate?

The DoT direction introduces two major security requirements for app-based communication services using Indian mobile numbers:

Continuous SIM Binding

Communication apps must maintain a continuous connection between the user’s registered mobile number, active SIM Card, and the device running the application.

Key requirements

App must verify the linked SIM is present in the device

Registered mobile number must remain linked with the active SIM

Removing or changing the SIM should prevent unauthorized continued access to the account

It helps stop misuse of Indian mobile numbers for remote fraud and impersonation

Service continuity is preserved during international travel as long as the registered SIM remains physically present and active in the device on roaming.

Periodic Web Session Logout

Prevent misuse of long-running web sessions. DoT requires communication platforms offering web access to implement periodic logout and re-linking.

Key requirements:

Web and desktop sessions must automatically log out within 6 hours

Users must re-link the device through a QR code-based verification process

Periodic verification ensures that only users with access to the registered device and SIM can continue the session

It applies to web access instances, not only the mobile application.


How the DoT SIM Binding Mandate fit into India’s Digital Security Framework?

The DoT SIM Binding Mandate is part of India’s broader effort to increase digital security. The RBI (Reserve Bank of India) has long required mobile banking and payment apps to use device and SIM Binding to protect customer accounts. For example, State Bank of India introduced SIM Binding for its mobile banking app in 2021 to reduce fraud.


The SEBI (Securities and Exchange Board of India) proposed using SIM binding and biometric verification to enhance the security of trading and demat accounts. This shows that financial regulators are making SIM and device binding a standard security requirement for apps and digital services.

How Does DeepID Help Apps Achieve Binding Compliance?

DeepID simplifies DoT SIM Binding compliance by providing continuous SIM Binding, device intelligence, and real-time risk detection in a single SDK. It helps communication apps verify that the registered SIM remains active on the user’s device, detect SIM changes, and identify untrusted devices.

Conclusion

DoT SIM Binding Mandate makes SIM binding and periodic logout mandatory for application communication services. It ensures that the genuine user can access the services with the device having a registered SIM. It reduces SIM swap, account takeover, and other SIM-related fraud.


All article tags

Share this post

Identify your web and
mobile traffic in minutes

Collect visitor IDs and signals instantly for free,
or reach out to our team for a demo.

250+

countries and territories where we identified devices_

4 Billion +

unique browsers and mobile devices identified_

50 Million +

real-time device intelligence API events per day processed_