{"id":3551,"date":"2026-06-05T18:02:19","date_gmt":"2026-06-05T18:02:19","guid":{"rendered":"https:\/\/idlayr.com\/?p=3551"},"modified":"2026-06-05T18:36:10","modified_gmt":"2026-06-05T18:36:10","slug":"regulators-banning-sms-otp","status":"publish","type":"post","link":"https:\/\/idlayr.com\/it\/blog\/regulators-banning-sms-otp\/","title":{"rendered":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide"},"content":{"rendered":"<h1>Regulators Are Banning SMS OTP \u2014 What You Need to Know<\/h1>\n<p>&nbsp;<\/p>\n<p><b>A Regulator-by-Regulator Guide<\/b><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">How the world&#8217;s financial regulators are forcing SMS one-time passwords out of banking \u2014 what each one has actually mandated, the deadlines that matter, and where to find the primary-source documents.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">For two decades, the six-digit code texted to your phone was the default second factor in digital banking. That era is ending. SMS one-time passwords (OTPs) travel over a channel the bank does not control, can be intercepted through SIM swap, SS7 exploits, phishing and smishing, and increasingly fail against AI-assisted, adversary-in-the-middle attacks. Regulators have noticed \u2014 and over the last three years they have moved from gentle encouragement to hard deadlines and liability shifts.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">This is not a single-market story. <\/span><b>More than 25 regulators worldwide<\/b><span style=\"font-weight: 400;\"> have now moved toward phishing-resistant authentication. Below is a market-by-market briefing on the regulators that matter most, what they have actually required (the detail matters \u2014 &#8220;banned&#8221; and &#8220;expanded the options&#8221; are very different things), and links to the primary instruments so you can verify each claim yourself.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2>At a glance<\/h2>\n<table style=\"width: 100%; border-collapse: collapse; margin: 16px 0;\">\n<thead>\n<tr>\n<th style=\"background-color: #1b2a4e; color: #ffffff; text-align: left; padding: 12px 16px; font-weight: 700; border: none;\">Market<\/th>\n<th style=\"background-color: #1b2a4e; color: #ffffff; text-align: left; padding: 12px 16px; font-weight: 700; border: none;\">Regulator<\/th>\n<th style=\"background-color: #1b2a4e; color: #ffffff; text-align: left; padding: 12px 16px; font-weight: 700; border: none;\">Instrument<\/th>\n<th style=\"background-color: #1b2a4e; color: #ffffff; text-align: left; padding: 12px 16px; font-weight: 700; border: none;\">Key deadline<\/th>\n<th style=\"background-color: #1b2a4e; color: #ffffff; text-align: left; padding: 12px 16px; font-weight: 700; border: none;\">Is SMS OTP &#8220;banned&#8221;?<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">UAE<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">CBUAE<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">June 2025 directive<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">31 Mar 2026<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Yes \u2014 full phase-out for all FIs<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Singapore<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">MAS \/ ABS<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">July 2024 announcement<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">~Oct 2024<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Removed for bank logins (digital-token users)<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Malaysia<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Bank Negara Malaysia<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">RMiT policy (Nov 2025); 2022 directive<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">In force<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Non-compliant as a standalone 2nd factor<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Philippines<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">BSP<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Circular 1213 (AFASA)<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">30 Jun 2026<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Yes, for high-risk transactions<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">India<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">RBI<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Authentication Directions, 2025<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">1 Apr 2026<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">No \u2014 2FA mandated, OTP still permitted<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">UE<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">EBA \/ PSD2 \u2192 PSD3<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">RTS on SCA; PSD3\/PSR<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">~2027\u20132028 (PSD3)<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">No \u2014 restricted, not banned<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">United States<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">NIST (+ FINRA, USPTO, FCC)<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">SP 800-63B-4<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">July 2025<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">No \u2014 formally &#8220;restricted&#8221;<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Vietnam<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">State Bank of Vietnam<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Decision 2345\/Q\u0110-NHNN<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">1 Jul 2024<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Biometric required above thresholds<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Saudi Arabia<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">SAMA<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Cyber Security Framework<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Ongoing<\/span><\/td>\n<td style=\"padding: 12px 16px; border-bottom: 1px solid #e6e8ee; vertical-align: top; text-align: left;\"><span style=\"font-weight: 400;\">Moving beyond OTP to FIDO2 \/ device-bound<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>United Arab Emirates \u2014 the hardest line<\/h2>\n<p><span style=\"font-weight: 400;\">The Central Bank of the UAE (CBUAE) issued a directive in June 2025 requiring all licensed financial institutions \u2014 banks, finance companies, exchange houses, insurers and payment service providers \u2014 to eliminate SMS- and email-based OTPs by 31 March 2026, replacing them with app-based and biometric authentication. Critically, the directive also shifts liability: institutions are now responsible for fraud linked to OTP authentication.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The transition has been visible to consumers. Banks began moving customers to in-app approval from July 2025, and several of the largest banks switched off SMS OTP for online card payments from 6 January 2026. This is the clearest &#8220;ban&#8221; of any major market.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: Central Bank of the UAE \u2014 <\/span><\/i><a href=\"https:\/\/www.centralbank.ae\/\"><i><span style=\"font-weight: 400;\">centralbank.ae<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">. Reporting detail: <\/span><\/i><a href=\"https:\/\/gulfnews.com\/business\/banking\/new-rule-uae-banks-to-stop-sending-otps-via-sms-and-email-from-july-25-1.500209071\"><i><span style=\"font-weight: 400;\">Gulf News<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>Singapore \u2014 OTP removed from the login<\/h2>\n<p><span style=\"font-weight: 400;\">On 9 July 2024, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) announced that major retail banks would progressively stop using OTPs for bank-account login for customers who have activated a digital token. The digital token authenticates the login directly, removing the code that scammers phish for. Note the scope: this targets the login step for digital-token users \u2014 decisive, but narrower than a blanket statutory ban.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: MAS media release \u2014 <\/span><\/i><a href=\"https:\/\/www.mas.gov.sg\/news\/media-releases\/2024\/banks-in-singapore-to-strengthen-resilience-against-phishing-scams\"><i><span style=\"font-weight: 400;\">Banks in Singapore to Strengthen Resilience Against Phishing Scams<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>Malaysia \u2014 among the earliest movers<\/h2>\n<p><span style=\"font-weight: 400;\">Bank Negara Malaysia (BNM) was one of the first central banks anywhere to publicly direct banks off SMS OTP, instructing financial institutions in September 2022 to migrate to more secure authentication for high-risk activities \u2014 account opening, fund transfers, payments and changes to account settings. That direction hardened with BNM&#8217;s updated Risk Management in Technology (RMiT) policy, issued 28 November 2025, under which SMS OTP is no longer compliant as a standalone second factor, device binding defaults to one device per account, and MFA must be interception-resistant.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: Bank Negara Malaysia \u2014 Policy Document on Risk Management in Technology (RMiT) \u2014 <\/span><\/i><a href=\"https:\/\/www.bnm.gov.my\/\"><i><span style=\"font-weight: 400;\">bnm.gov.my<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>Philippines \u2014 a firm 2026 deadline<\/h2>\n<p><span style=\"font-weight: 400;\">The Bangko Sentral ng Pilipinas (BSP) issued Circular No. 1213 in June 2025 to implement Section 6 of the Anti-Financial Account Scamming Act (AFASA). It requires supervised institutions to transition away from interceptable authentication mechanisms \u2014 explicitly SMS and email OTPs \u2014 for high-risk transactions and critical account changes by 30 June 2026. OTPs retain a single permitted use: confirming ownership of a registered mobile number, never authorising a transaction. In January 2026, the BSP publicly confirmed it is not extending the deadline, and under AFASA, institutions without adequate controls bear liability for customer losses.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: Bangko Sentral ng Pilipinas \u2014 Circular No. 1213 \u2014 <\/span><\/i><a href=\"https:\/\/www.bsp.gov.ph\/\"><i><span style=\"font-weight: 400;\">bsp.gov.ph<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>India \u2014 mandate 2FA, but OTP stays<\/h2>\n<p><span style=\"font-weight: 400;\">India is the market most often mischaracterised. On 25 September 2025, the Reserve Bank of India issued the Reserve Bank of India (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025, to be complied with by 1 April 2026 (cross-border card-not-present transactions by 1 October 2026). The Directions require two-factor authentication for all domestic digital payments, with at least one factor dynamically generated per transaction, and they open the door to device-bound passkeys, biometrics and tokens.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">What the RBI did <\/span><i><span style=\"font-weight: 400;\">non<\/span><\/i><span style=\"font-weight: 400;\"> do is ban SMS OTP. The framework states plainly that it &#8220;does not call for discontinuation of SMS based OTP&#8221; \u2014 it expands the menu of acceptable factors rather than removing the old one. The direction of travel is clear; the instrument is principle-based, not prohibitive.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: RBI Press Release 2025-2026\/1165 \u2014 <\/span><\/i><a href=\"https:\/\/rbidocs.rbi.org.in\/rdocs\/PressRelease\/PDFs\/PR1165D250AB0389BE4D3D9E006CECD26F928E.PDF\"><i><span style=\"font-weight: 400;\">rbidocs.rbi.org.in<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>European Union \u2014 restricted, and tightening<\/h2>\n<p><span style=\"font-weight: 400;\">Under PSD2&#8217;s Strong Customer Authentication (SCA) regime and the EBA&#8217;s Regulatory Technical Standards, SMS OTP is not outright banned: it can serve as a possession element where it meets requirements such as dynamic linking. In practice, regulators and the market increasingly treat plain SMS OTP as insufficient. The proposed PSD3 and the Payment Services Regulation (PSR) will tighten SCA further, reduce exemption thresholds and give explicit weight to phishing-resistant methods, with implementation generally expected around 2027\u20132028.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary sources: European Banking Authority \u2014 RTS on SCA \u2014 <\/span><\/i><a href=\"https:\/\/www.eba.europa.eu\/\"><i><span style=\"font-weight: 400;\">eba.europa.eu<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">; European Commission PSD3\/PSR proposals \u2014 <\/span><\/i><a href=\"https:\/\/finance.ec.europa.eu\/\"><i><span style=\"font-weight: 400;\">finance.ec.europa.eu<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>United States \u2014 &#8220;restricted,&#8221; not retired<\/h2>\n<p><span style=\"font-weight: 400;\">There is no single US banking mandate, but the centre of gravity has shifted. In July 2025, NIST published SP 800-63B-4, which for the first time formally classifies SMS\/PSTN OTP as a &#8220;restricted&#8221; authenticator \u2014 still permitted, but only with conditions and risk mitigations, and with a clear expectation that organisations at AAL2 migrate away. Around it, federal practice is moving: the US Patent and Trademark Office discontinued SMS authentication on 1 May 2025, FINRA has been phasing SMS OTP out of its own systems, and the FCC has tightened SIM-swap and port-out protections.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: NIST SP 800-63B-4, Digital Identity Guidelines \u2014 <\/span><\/i><a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63b\/\"><i><span style=\"font-weight: 400;\">pages.nist.gov\/800-63-4<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>Vietnam \u2014 biometrics on top, by value<\/h2>\n<p><span style=\"font-weight: 400;\">The State Bank of Vietnam issued Decision No. 2345\/Q\u0110-NHNN (18 December 2023), in force from 1 July 2024, requiring biometric authentication for individual transfers at or above 10 million VND (or above 20 million VND cumulative per day) and for first-time or new-device transactions, verified against the national population database. The SBV has reported a roughly 50% drop in fraudulent transactions since rollout. SMS OTP persists for lower-value flows, but the high-risk tier now demands biometrics.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Primary source: State Bank of Vietnam \u2014 <\/span><\/i><a href=\"https:\/\/www.sbv.gov.vn\/\"><i><span style=\"font-weight: 400;\">sbv.gov.vn<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>Saudi Arabia \u2014 the framework approach<\/h2>\n<p><span style=\"font-weight: 400;\">The Saudi Central Bank (SAMA) has advanced authentication expectations through its Cyber Security Framework, increasingly steering institutions beyond OTP toward FIDO2 and device-bound credentials. Saudi Arabia is frequently cited as a model of specificity and measurable outcomes in authentication regulation.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Further reading: Ideem, <\/span><\/i><a href=\"https:\/\/www.useideem.com\/post\/sama-authentication-requirements-saudi-arabia-banks-move-beyond-otp\"><i><span style=\"font-weight: 400;\">SAMA Authentication Requirements<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">; primary framework: SAMA \u2014 <\/span><\/i><a href=\"https:\/\/www.sama.gov.sa\/\"><i><span style=\"font-weight: 400;\">sama.gov.sa<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<h2>The common thread<\/h2>\n<p><span style=\"font-weight: 400;\">Read across these markets and a single pattern emerges. The &#8220;ban&#8221; markets (UAE, Philippines), the &#8220;remove it from the risky flows&#8221; markets (Singapore, Malaysia, Vietnam), and the &#8220;raise the bar without banning&#8221; markets (India, EU, US) are all doing the same thing for the same reason: <\/span><b>moving the proof of identity off a shared secret sent over a channel the bank doesn&#8217;t control, and onto something cryptographic, device-bound, and hard to intercept.<\/b><span style=\"font-weight: 400;\"> No major regulator anywhere is moving back toward SMS OTP.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">For any institution operating across borders, the practical conclusion is that an SMS-OTP exit is no longer a question of if but of which deadline hits first. The replacement needs to satisfy a possession factor that regulators recognise, survive SIM swap and porting, and work without adding checkout friction \u2014 which is precisely where network-verified, device-bound mobile trust comes in.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2>Primary sources<\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>UAE \u2014 CBUAE:  <\/b><a href=\"https:\/\/www.centralbank.ae\/\"><span style=\"font-weight: 400;\">centralbank.ae<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Singapore \u2014 MAS:  <\/b><a href=\"https:\/\/www.mas.gov.sg\/news\/media-releases\/2024\/banks-in-singapore-to-strengthen-resilience-against-phishing-scams\"><span style=\"font-weight: 400;\">Banks in Singapore to Strengthen Resilience Against Phishing Scams (9 Jul 2024)<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Malaysia \u2014 BNM:  <\/b><a href=\"https:\/\/www.bnm.gov.my\/\"><span style=\"font-weight: 400;\">Risk Management in Technology (RMiT) policy, bnm.gov.my (28 Nov 2025)<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Philippines \u2014 BSP:  <\/b><a href=\"https:\/\/www.bsp.gov.ph\/\"><span style=\"font-weight: 400;\">Circular No. 1213 \/ AFASA, bsp.gov.ph<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>India \u2014 RBI:  <\/b><a href=\"https:\/\/rbidocs.rbi.org.in\/rdocs\/PressRelease\/PDFs\/PR1165D250AB0389BE4D3D9E006CECD26F928E.PDF\"><span style=\"font-weight: 400;\">Authentication Mechanisms for Digital Payment Transactions Directions, 2025 (25 Sep 2025)<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>EU \u2014 EBA \/ European Commission:  <\/b><a href=\"https:\/\/www.eba.europa.eu\/\"><span style=\"font-weight: 400;\">RTS on SCA<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/finance.ec.europa.eu\/\"><span style=\"font-weight: 400;\">PSD3 &amp; PSR proposals<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>United States \u2014 NIST:  <\/b><a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63b\/\"><span style=\"font-weight: 400;\">SP 800-63B-4, Digital Identity Guidelines (Jul 2025)<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Vietnam \u2014 SBV:  <\/b><a href=\"https:\/\/www.sbv.gov.vn\/\"><span style=\"font-weight: 400;\">Decision 2345\/Q\u0110-NHNN, sbv.gov.vn<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Saudi Arabia \u2014 SAMA:  <\/b><a href=\"https:\/\/www.sama.gov.sa\/\"><span style=\"font-weight: 400;\">sama.gov.sa<\/span><\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Last updated June 2026. Regulatory positions change; verify against the primary instruments before relying on any deadline.<\/span><\/i><\/p>","protected":false},"excerpt":{"rendered":"<p>Regulators Are Banning SMS OTP \u2014 What You Need to Know &nbsp; A Regulator-by-Regulator Guide &nbsp; How the world&#8217;s financial regulators are forcing SMS one-time passwords out of banking \u2014 what each one has actually mandated, the deadlines that matter, and where to find the primary-source documents. &nbsp; For two decades, the six-digit code texted [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":3553,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.6 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Global SMS OTP Ban: A Regulator-by-Regulator Guide - IDlayr<\/title>\n<meta name=\"description\" content=\"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/idlayr.com\/it\/blog\/regulators-banning-sms-otp\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Global SMS OTP Ban: A Regulator-by-Regulator Guide\" \/>\n<meta property=\"og:description\" content=\"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc\" \/>\n<meta property=\"og:url\" content=\"https:\/\/idlayr.com\/it\/blog\/regulators-banning-sms-otp\/\" \/>\n<meta property=\"og:site_name\" content=\"IDlayr\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-05T18:02:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-05T18:36:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1168\" \/>\n\t<meta property=\"og:image:height\" content=\"784\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Paul McGuire\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theidlayr\" \/>\n<meta name=\"twitter:site\" content=\"@theidlayr\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"Paul McGuire\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/\"},\"author\":{\"name\":\"Paul McGuire\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/#\\\/schema\\\/person\\\/2e2005b12b1c34d317856764476870e9\"},\"headline\":\"The Global SMS OTP Ban: A Regulator-by-Regulator Guide\",\"datePublished\":\"2026-06-05T18:02:19+00:00\",\"dateModified\":\"2026-06-05T18:36:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/\"},\"wordCount\":1480,\"publisher\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg\",\"articleSection\":[\"Uncategorized\"],\"inLanguage\":\"it-IT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/\",\"url\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/\",\"name\":\"The Global SMS OTP Ban: A Regulator-by-Regulator Guide - IDlayr\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg\",\"datePublished\":\"2026-06-05T18:02:19+00:00\",\"dateModified\":\"2026-06-05T18:36:10+00:00\",\"description\":\"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#primaryimage\",\"url\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg\",\"contentUrl\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg\",\"width\":1168,\"height\":784,\"caption\":\"Regulators are Banning SMS OTP\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/blog\\\/regulators-banning-sms-otp\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/idlayr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Global SMS OTP Ban: A Regulator-by-Regulator Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/#website\",\"url\":\"https:\\\/\\\/idlayr.com\\\/\",\"name\":\"IDlayr\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/idlayr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/#organization\",\"name\":\"IDlayr\",\"url\":\"https:\\\/\\\/idlayr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/header-device-binding.png\",\"contentUrl\":\"https:\\\/\\\/idlayr.com\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/header-device-binding.png\",\"width\":660,\"height\":524,\"caption\":\"IDlayr\"},\"image\":{\"@id\":\"https:\\\/\\\/idlayr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/theidlayr\"],\"description\":\"IDlayr provides Silent Network Authentication (SNA) to replace SMS OTP for banks, payment platforms, and consumer apps.\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/idlayr.com\\\/#\\\/schema\\\/person\\\/2e2005b12b1c34d317856764476870e9\",\"name\":\"Paul McGuire\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g\",\"caption\":\"Paul McGuire\"},\"description\":\"Paul McGuire is CEO of IDlayr. He has spent over two decades at the intersection of mobile, telecoms, and digital identity. He works directly with banks, payment platforms, and large consumer apps deploying Silent Network Authentication to replace SMS OTP, eliminating ATO and SIM Swap fraud risk. He has held senior leadership roles across mobile and technology businesses in the USA and internationally.\",\"jobTitle\":\"CEO\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide - IDlayr","description":"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/idlayr.com\/it\/blog\/regulators-banning-sms-otp\/","og_locale":"it_IT","og_type":"article","og_title":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide","og_description":"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc","og_url":"https:\/\/idlayr.com\/it\/blog\/regulators-banning-sms-otp\/","og_site_name":"IDlayr","article_published_time":"2026-06-05T18:02:19+00:00","article_modified_time":"2026-06-05T18:36:10+00:00","og_image":[{"width":1168,"height":784,"url":"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg","type":"image\/jpeg"}],"author":"Paul McGuire","twitter_card":"summary_large_image","twitter_creator":"@theidlayr","twitter_site":"@theidlayr","twitter_misc":{"Scritto da":"Paul McGuire","Tempo di lettura stimato":"7 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#article","isPartOf":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/"},"author":{"name":"Paul McGuire","@id":"https:\/\/idlayr.com\/#\/schema\/person\/2e2005b12b1c34d317856764476870e9"},"headline":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide","datePublished":"2026-06-05T18:02:19+00:00","dateModified":"2026-06-05T18:36:10+00:00","mainEntityOfPage":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/"},"wordCount":1480,"publisher":{"@id":"https:\/\/idlayr.com\/#organization"},"image":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#primaryimage"},"thumbnailUrl":"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg","articleSection":["Uncategorized"],"inLanguage":"it-IT"},{"@type":"WebPage","@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/","url":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/","name":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide - IDlayr","isPartOf":{"@id":"https:\/\/idlayr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#primaryimage"},"image":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#primaryimage"},"thumbnailUrl":"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg","datePublished":"2026-06-05T18:02:19+00:00","dateModified":"2026-06-05T18:36:10+00:00","description":"More than 25 regulators are phasing out SMS OTP. A market-by-market guide to every SMS OTP ban, deadline and mandate \u2014 UAE, India, EU, US, etc","breadcrumb":{"@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#primaryimage","url":"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg","contentUrl":"https:\/\/idlayr.com\/wp-content\/uploads\/2026\/06\/0c1002b2-35ed-40a0-a309-9fdd17936710.jpg","width":1168,"height":784,"caption":"Regulators are Banning SMS OTP"},{"@type":"BreadcrumbList","@id":"https:\/\/idlayr.com\/blog\/regulators-banning-sms-otp\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/idlayr.com\/"},{"@type":"ListItem","position":2,"name":"The Global SMS OTP Ban: A Regulator-by-Regulator Guide"}]},{"@type":"WebSite","@id":"https:\/\/idlayr.com\/#website","url":"https:\/\/idlayr.com\/","name":"IDlayr","description":"","publisher":{"@id":"https:\/\/idlayr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/idlayr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Organization","@id":"https:\/\/idlayr.com\/#organization","name":"IDlayr","url":"https:\/\/idlayr.com\/","logo":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/idlayr.com\/#\/schema\/logo\/image\/","url":"https:\/\/idlayr.com\/wp-content\/uploads\/2023\/12\/header-device-binding.png","contentUrl":"https:\/\/idlayr.com\/wp-content\/uploads\/2023\/12\/header-device-binding.png","width":660,"height":524,"caption":"IDlayr"},"image":{"@id":"https:\/\/idlayr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/theidlayr"],"description":"IDlayr provides Silent Network Authentication (SNA) to replace SMS OTP for banks, payment platforms, and consumer apps."},{"@type":"Person","@id":"https:\/\/idlayr.com\/#\/schema\/person\/2e2005b12b1c34d317856764476870e9","name":"Paul McGuire","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/secure.gravatar.com\/avatar\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63110ead4492c8a9236c7f167563cddc19d09704b07b5281905e451a3d326ece?s=96&d=mm&r=g","caption":"Paul McGuire"},"description":"Paul McGuire is CEO of IDlayr. He has spent over two decades at the intersection of mobile, telecoms, and digital identity. He works directly with banks, payment platforms, and large consumer apps deploying Silent Network Authentication to replace SMS OTP, eliminating ATO and SIM Swap fraud risk. He has held senior leadership roles across mobile and technology businesses in the USA and internationally.","jobTitle":"CEO"}]}},"_links":{"self":[{"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/posts\/3551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/comments?post=3551"}],"version-history":[{"count":7,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/posts\/3551\/revisions"}],"predecessor-version":[{"id":3559,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/posts\/3551\/revisions\/3559"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/media\/3553"}],"wp:attachment":[{"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/media?parent=3551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/categories?post=3551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/idlayr.com\/it\/wp-json\/wp\/v2\/tags?post=3551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}