NCMS - OTP based Two Factor Authentication and upgradation of NCMS version
- Issued
- Effective
- Compliance deadline
- Published
What changed
NSE Clearing Limited, vide Circular No. NCL/CMPT/75369 dated July 23, 2026, has announced an important update regarding implementation of OTP-based Two Factor Authentication (2FA) and upgradation of the NCMS-CM version.
Key Details of the Update –
• NSE Clearing Limited has introduced OTP-based Two Factor Authentication (2FA) to enhance the security of user login for the NCMS-CM application.
• Applicability: All Members using NCMS-CM, including Admin users and Sub-users.
• OTP-based 2FA will be mandatory for all user logins to NCMS-CM.
• On first login after implementation, users will be required to register a valid mobile number and email ID. OTPs will thereafter be sent to the registered mobile number and email ID for authentication.
• Members are required to upgrade to NCMS EXE Version 4.2.3, which will be made available from the implementation date.
• The user manual provides the login process, OTP verification workflow, OTP regeneration after 30 seconds in case of an invalid OTP, and user ID disablement after four invalid OTP attempts.
• Effective Date: OTP-based Two Factor Authentication (2FA) and NCMS EXE Version 4.2.3 shall be implemented with effect from July 25, 2026.
• Penalty/Consequence: In case four invalid OTPs are entered, the user ID will be disabled and the member will be required to contact NSE Clearing Limited for reactivation.
Actions if Any –
• Members shall upgrade to NCMS EXE Version 4.2.3 before using NCMS-CM from July 25, 2026.
• Members shall register a valid mobile number and email ID during the first login to enable OTP-based authentication.
• Members shall use OTP-based Two Factor Authentication for every NCMS-CM login from the effective date.
Compliance Deadline –
• OTP-based Two Factor Authentication (2FA) and NCMS EXE Version 4.2.3 shall be implemented with effect from July 25, 2026.
Need deeper implementation context?
Read the legal update above, then use CompliSense for deeper applicability review, workflow interpretation, ownership tracking, and evidence-ready compliance execution.