The Centre for Development of Advanced Computing’s Pune campus has issued a conformance schedule for AePS micro-ATM firmware builds that must clear hardware security module checks before the Kisan Mela circuit sends business correspondents into high-volume cash-withdrawal weeks. The calendar, circulated to OEMs and sponsor banks this month, links PIN-entry devices on Luna-class HSMs to the authentication controls UIDAI reinforced in 2025 and to NPCI’s micro-ATM 1.5.1 baseline.

HSM bench and firmware slots

C-DAC maintains Gemalto Luna modules and backup HSMs across Pune, Chennai, and national data-centre sites under long-running comprehensive maintenance contracts. For AePS terminals, Pune’s lab is allocating back-to-back windows in late September and early October for firmware images that handle biometric capture, ISO 8583 messaging, and encrypted PIN blocks. Vendors must demonstrate that keys never leave tamper-evident hardware and that remote patch channels are signed—requirements that mirror both C-DAC’s own tender annexures and UIDAI’s mandate that cryptographic operations run inside certified modules.

Lab engineers said the Kisan Mela deadline is driven by sponsor banks, not a new NPCI circular. Agricultural credit societies and primary cooperative banks deploy fresh micro-ATMs before melas to capture subsidy withdrawals and KCC repayments. A failed conformance slot in October can strand terminals in warehouses while fields are busiest.

AePS stack under scrutiny

Industry documentation from certified switches describes the expected stack: RuPay and Aadhaar acceptance, e-KYC account opening, and routing through FI gateways with UIDAI acting as authentication service agency. Micro-ATMs must comply with IBA, IDRBT, NPCI, and UIDAI formulations, including EMV chip-and-PIN where card rails run alongside biometric AePS. C-DAC’s schedule adds a Pune-specific emphasis on firmware that survives power flicker on generator-backed counters—common at mela grounds—and on thermal printers that do not stall mid-receipt when humidity spikes.

Banks told InfoHandle that the conformance list separates “field trial” builds from “mela-certified” builds. Only the latter receive sponsor-bank BIN whitelisting for AePS on-us and off-us transactions during the festival window. That split is new this season after last year’s reports of terminals accepting biometrics while HSM session keys failed to rotate nightly.

Rural correspondent pressure

Business correspondents operating from melas see AePS as the fallback when ATM vans cannot reach taluka markets. Withdrawal limits and BC commissions rise with foot traffic, which increases the payoff for attackers probing weak PIN pads. UIDAI’s 2025 circular on Aadhaar Data Vaults and HSM hosting is cited in Pune’s invitation letters as the reason sponsor banks cannot rely on software-only keystores on low-cost Android micro-ATMs.

State cooperative federations are urging OEMs to book Pune slots before Navratri, when logistics teams shift to urban card campaigns. Two regional rural banks said they will pause new BC onboarding until conformance stickers are issued—stickers that list firmware hash, HSM serial, and expiry aligned to C-DAC’s published calendar.

What vendors must deliver

OEMs need traceable patch logs, spare PED devices under AMC terms C-DAC itself uses for Luna maintenance, and test evidence that biometric liveness checks do not downgrade when networks switch from 4G to satellite backhaul. NPCI’s AePS switching rules still require sponsor-bank liability for sub-members; a firmware gap at Pune becomes a settlement risk, not merely a hardware ticket.

For farmers lining up at melas, the visible change will be minor: slightly longer boot checks while terminals verify HSM health. Behind the counter, the stakes are larger—without Pune’s sign-off, banks would rather keep cash in strong rooms than push untested firmware into the busiest withdrawal weeks of the year.

Pune engineers noted that backup HSM failover drills are now part of the conformance checklist after a Chennai lab incident last quarter left terminals in authentication-only mode for nearly an hour. Sponsor banks want written attestation that firmware rollback images are stored offline at district offices, not only on vendor clouds that mela grounds cannot reach when mobile towers congest.

NPCI’s public AePS materials still describe the network as cardless and biometric-first; C-DAC’s contribution is to prove that the cryptography underneath those marketing lines survives rural power and monsoon humidity. Until stickers appear on terminal bezels, correspondents said they will keep dual-sim routers in their kits—another small cost of taking HSM rules seriously outside city cores.