On the 11th June, Estonia’s central bank cut six supermarket stores, one from each of the country’s biggest chains, off the network for about an hour. This wasn’t down to a technical fault, or worse, an irritated central banker venting after a missed grocery run. It was planned, part of the national defence exercise ILVES 2026. Shoppers in Selver, Coop, Rimi, Maxima, Grossi and Lidl stores paid for their groceries by chip and PIN with no connection to anything. Rainer Olt, who heads Eesti Pank’s payment and settlement systems department, said afterwards that the exercise “gave the confidence that offline card payments work” whilst also revealing “issues that need to be dealt with”. A central bank running a live-fire drill on disconnected card acceptance in a NATO member state in 2026 is not testing out an inclusion initiative. It is a clear signal of civil preparedness.
For most of the last fifteen years, offline payments have been framed as a feature to help cater for the edges of the map. Think of the rural customer with no signal, the festival-goer out in a field in the middle of nowhere, the farmers market stall sitting beyond conventional coverage. In my view, that framing has now been overtaken by something more significant and urgent, and this summer is the evidence of that.
The question the industry is answering has changed from “how do we reach people without connectivity” to “what does an economy do when connectivity fails,” and with that change came something the inclusion case was never able to fully attract: legal instruments, budgets and the urgency only deadlines can muster.
A post by Munish Gupta in my feed got me digging into this properly, and I’ll come back to his framing later, because the way he framed it deserves more credit than the discourse around offline usually gets.
Offline stopped being an inclusion feature and shifted gear to become a resilience requirement
Let’s take stock of what actually happened this summer, aside from the heatwaves bearing down across the UK and Europe. Four payment systems, four offline moves, all in the span of six weeks.
On the 1st July, Sweden’s offline card payment capability went live for essential goods. Seven banks, both global card schemes and four acquirers, working in concert with Sveriges Riksbank (the Swedish central bank), now support card payments that authorise offline.
This is enabled through the shopper’s use of their physical card and PIN, in grocery stores, pharmacies and staffed fuel stations, covering most Visa and Mastercard cards, with the Riksbank encouraging more banks to join.
The design brief tolerates disruptions lasting up to seven days, and Governor Erik Thedéen’s framing on the day was that “a resilient payment system requires all actors within the system to take responsibility”.
On the 13th July, the Digital Euro Regulation, which as proposed would make offline capability a legal requirement from first issuance, entered its trilogue phase. Around the 20th July, the NPCI was reported to be building a fully offline NFC tap-to-pay experience for UPI at the point of sale, with terminal certification expected during 2026. And finally on the 10th August, Brazil’s central bank put offline Pix on its public agenda in the Pix management report. Its own Fórum Pix roadmap still parks the work in a 2027 and later discussion column, so that gap between the announcement and the agenda is worth bearing in mind.
Four systems moved on offline in six weeks
The figure is wider than a phone screen. Scroll it sideways, or use expand.
Sweden’s offline card capability goes live for essential goods
Physical card and PIN, for essential goods, designed for disruptions of up to seven days. The Riksbank memo behind it describes offline authorisation up to a floor of at least SEK 2,000 per transaction at the issuer’s risk, with the chip’s accumulated limit sized to at least a week of a household’s essential purchases.
PRIMARY SOURCE SVERIGES RIKSBANKWhat all four have in common is that none of these are inclusion projects. Take Sweden’s example. It is anchored in the Sveriges Riksbank Act, which requires that payments function “in peacetime crisis situations and states of heightened alert.” Meanwhile, Norway’s BankAxept has quietly operated an offline backup sized to roughly one week of essential purchases since 2021, and Norwegian authorities now want it extended further. Denmark’s Payments Council targets offline card acceptance at supermarkets and pharmacies for at least a week. Finland legislated a statutory reserve payment system in 2022, a backstop for bank-level disruption rather than offline acceptance, but part of the same preparedness family. Sweden, Norway and Denmark have converged, almost without anyone outside the region noticing, on a common standard, which is that a citizen should be able to buy food, medicine and fuel for about a week with the network down.
David Birch has been arguing for years that payment resilience is critical national infrastructure and that engineered offline capability beats cash hoarding as the answer. His Cash and Catastrophe article on Substack makes that case well. Jeremy Light has made the adjacent argument that governed offline payments, cryptographically signed against reserved funds, are the resilient design paradigm to follow. He sets it out in his article I’m Still Standing, from February. What this summer added was not a better argument but regulators acting decisively on it. The question they were asking changed, and the impetus followed.
In April’s blackout, the core held firm but failure materialised at the brittle edge
The empirical hinge for all of this goes back to the 28th April 2025, when the Iberian grid went down for the better part of a day. The key detail that matters is not that payments failed (they do sometimes), but where they failed.
Banco de España’s next-morning monitoring listed TARGET, Iberpay and Redsys as “functioning regularly”. In Portugal, SIBS reported its core systems operational all day. In both cases, the switches and settlement systems ran, but none of that mattered to a shopper standing in a dark store in Valencia because the terminals had no power, telecoms were degraded, and the tills were down.
The ECB’s post-mortem compiled the numbers, drawing on telemetry from Spanish banks. Card spending in affected areas fell by an estimated 41 to 42 per cent against unaffected regions, national e-commerce spending dropped by around 54 per cent, and overall Spanish consumption fell by an estimated 34 per cent in a single day.
This is illustrative of a pattern rather than a one-off incident. The CrowdStrike update of July 2024 took out Windows-based tills at Waterstones, Waitrose and Wetherspoons while Visa’s and Mastercard’s networks ran untroubled. Core systems are engineered for extreme availability, but the edge, where a payment actually happens and is initiated, can be a Windows OS till, a terminal running over a flaky SIM network and a power socket that isn’t backed by a UPS.
And when the core itself fails, the lesson runs the same way in reverse. In June 2018, a partial failure in a single switch in Visa’s primary data centre stopped roughly 5.2 million European transactions in ten hours, and there was no offline fallback waiting at the edge to absorb it. Wherever the single point of failure lies, the payment fails with it, because, by design, nothing in the chain is permitted to proceed unchecked.
Piero Cipollone made exactly this case to the European Parliament last September, citing people in Spain and Portugal who were “unable to pay” because they had no cash on hand, and framing the digital euro’s offline function as the answer. For balance, he has also argued against a purely offline design. But the institutional direction is not in doubt, and it is the same direction the Riksbank, Norges Bank, Danmarks Nationalbank and Eesti Pank are already walking.
Offline has stopped being a feature you add for the disconnected and become an insurance policy you price for the day the connection fails.
Cards solved offline decades ago, and then switched it off
For those not steeped in the arcane arts of card internals, here is the part of this story that the current coverage has largely lost from memory. The card system had already solved offline long ago, and, funnily enough, the solution still sits in the specification.
An EMV chip carries counters and cumulative amount limits, including the Lower and Upper Consecutive Offline Limits (EMV tags 9F14 and 9F23), that track how many times, and for how much, the card has been approved offline since it was last in contact with its issuer. Terminals have their own limits, and neither side can force an offline approval alone. The chip can, however, overrule a terminal that asks for one, forcing the transaction online or declining it outright, and whichever of the two limits is more stringent always wins.
The design insight, and I would go so far as to call it one of the most under-appreciated decisions in payments, is where the control lives. The cap sits in the cardholder’s hand, in tamper-resistant hardware, where neither a broken network nor a compromised terminal can loosen it.
Then the industry switched it off. In the United States, contactless floor limits were set to zero across the networks by 2020, which is the cheapest possible way to manage offline risk, since a floor limit of zero abolishes offline authorisation at the point of sale entirely. Always-on connectivity became cheap, fraud teams preferred real-time decisions on every transaction, and the offline apparatus went dormant outside transit and aviation.
Europe kept the pattern but moved the counter. PSD2’s contactless exemption, in Article 11 of the SCA rules, allows €50 per tap and €150 or five transactions before authentication, and that counter sits at the issuer, inside exactly the infrastructure that disappears in an outage.
This is what makes Sweden’s design historically interesting rather than merely sensible. The Riksbank’s memo describes offline authorisation up to a floor limit of at least SEK 2,000 per transaction, at the issuer’s risk, with an accumulated offline limit in the card’s EMV chip sized to at least a week of a household’s essential purchases. Sweden’s fix is, at its core, an instruction to switch EMV’s dormant machinery back on, with the cap limits re-sized for a national emergency instead of a corner shop.
Instant rails cannot follow suit without becoming something else entirely
If you know me, you’re probably wondering why I’ve just spent ages talking about how cards handle offline payments. Well, let me get back to my preferred subject matter and bring the conversation back to the land of ‘other’ payment methods.
Let’s start by asking ourselves: why can’t Pix, UPI proper, or any of the instant-payment rails that now carry large chunks of the world’s daily commerce simply do what Sweden did?
This is where the architecture bites, and it is the reason the offline story is fragmenting rather than converging.
An account-to-account (A2A) rail settles by moving entries on a central ledger. There is no ledger entry you can make without reaching the ledger, and I could not find a single live A2A scheme outside India that has a genuinely offline mode. But even India’s own exception proves the rule.
UPI Lite X, the genuinely offline variant, works because, under the UPI Lite framework it is built on, the money leaves your account in advance and sits in an “escrow / pool / designated account” at the bank, mirrored on your device. That is not UPI working offline so much as a small bearer instrument riding alongside the rail, under the rail’s brand. The digital euro reaches the same destination by another road, with an offline applet on a secure element where, in the ECB’s own words, final settlement occurs locally between devices.
Both-offline payment exists only where someone has built a bearer instrument, and building a bearer instrument is a monetary design decision, not a rail feature.
Munish Gupta, whose post prompted this piece, framed the underlying pattern well. When you cannot reach the source of truth in time, you move a bounded slice of it closer and reconcile after, the way a cache does, with a spending limit attached. This bounded local-authority pattern is exactly right, and it describes everything from EMV floor limits to transit gates. The one place I would extend his framing is at the point of failure, because the analogy identifies precisely why offline money is hard.
A cache can be invalidated by its source of truth. Money handed to a counterparty offline cannot be, and every control in real offline design exists because that invalidation path is gone.
Once you see that asymmetry, the fragmented landscape of “offline” payments becomes visible and sharpens into focus. Nearly every model in production is offline on one side only, and each one has picked a different side, a different cap and a different loss-bearer.
Alipay’s and WeChat’s payment codes rotate offline on the payer’s phone, but the merchant’s scanner must be online, no-PIN use is capped at ¥1,000 per transaction, and the platforms have publicly pledged to eat code-theft losses.
Apple Pay runs a truly impressive payer-offline design at global scale, with device-bound keys held in a secure element, and its Express transit cards keep working on power reserve for up to a whopping five hours after the battery dies.
Google Wallet meters the same freedom through a stock of limited-use keys that replenish when the device reconnects. Transit gates run the mirror image, payee-offline, waving you through on a deny-list check and carrying first-ride risk until the deferred authorisation lands.
Zettle’s merchant mode caps the queue at $10,000 per device, with 24 hours to reconnect, and states plainly that the merchant assumes the risk on anything declined, expired or disputed. And M-Pesa, so often cited as the offline success story, moves no value offline at all. Its marketed offline mode is store-and-forward and executes on reconnection, while core M-Pesa runs on USSD, which requires a live GSM session. What M-Pesa removed was the smartphone and the data plan, never the network.
Every offline model picks a side, a cap and a loss-bearer.
The models in production, compared on the three decisions of the disconnection budget: who can be disconnected, on what cap, at whose risk.
| Model | Who can be offline | The cap | Who eats the loss | Details |
|---|---|---|---|---|
Cards, offline-enabledEMV · Sweden 2026![]() ![]() | BOTH | Chip counters + floor limits Sweden ≥SEK 2,000 per txn | Issuerby agreement | |
EMV chip counters, including the Lower and Upper Consecutive Offline Limits (tags 9F14 and 9F23), track how many times and for how much the card has been approved offline since it last reached its issuer, and the tighter of chip and terminal limits always wins. Sweden’s fix re-arms this dormant machinery: offline authorisation to a floor of at least SEK 2,000 per transaction at the issuer’s risk, with the chip’s accumulated limit sized to about a week of essentials. RIKSBANK MEMO | ||||
Alipay / WeChat codesrotating payment code![]() ![]() | PAYER | ¥1,000 no-PIN per txn WeChat adds 10 per day | Platformpledged | |
The payment code rotates offline on the payer’s phone, but the merchant’s scanner must be online. No-PIN use is capped at ¥1,000 per transaction, WeChat adds a ten-per-day count, and the platforms have publicly pledged to eat code-theft losses. WECHAT PAY RULES | ||||
Apple Pay / Google Wallettokenised NFC![]() ![]() | PAYER | Terminal carries the online leg Google meters key stock | Issuerscheme rules | |
Device-bound keys in a secure element carry the payer side offline, and the terminal carries the online leg. Apple’s Express transit cards keep working on power reserve for up to five hours after the battery dies; Google Wallet meters spending through a stock of limited-use keys that replenishes when the device reconnects. APPLE PLATFORM SECURITY | ||||
| Transit open-loopdeferred authorisation | PAYEE | Single fare, deny-list check | Agencythen shared | |
The gate waves the rider through on a deny-list check and sends the authorisation later. The agency carries first-ride risk until the deferred authorisation lands, and what bounces is shared under scheme rules. CAL-ITP GUIDE | ||||
Zettle offline modemerchant store-and-forward![]() | PAYEE | $1,000 per txn · $10,000 per device · 24h to reconnect | Merchantentirely | |
Payments queue on the merchant’s device at up to $1,000 per transaction and $10,000 per device, with 24 hours to reconnect. PayPal states plainly that the merchant assumes the risk on anything declined, expired or disputed. PAYPAL HELP | ||||
UPI Lite Xbearer float beside the rail![]() | BOTH | ₹500 per txn · ₹2,000 balance | Account holderRBI rules | |
The money leaves the account in advance and sits in an “escrow / pool / designated account” at the bank, mirrored on the device: a small bearer instrument riding alongside the rail, under the rail’s brand. ₹500 per transaction against a ₹2,000 balance, with lost-device balances refundable via the bank and offline-window fraud under RBI limited-liability rules. NPCI CIRCULAR 138 | ||||
| Digital euro offlineproposed, in trilogue | BOTH | Holding limit undecided | Design not yet settled | |
The proposed design settles offline payments locally between devices, on a secure element, in the ECB’s own words. The holding limit, and who bears which loss, are undecided while the regulation is in trilogue. ECB PROGRESS REPORT | ||||
M-PesaUSSD · store-and-forward app![]() | NEITHER | No value moves offline USSD needs live GSM | — | |
M-Pesa moves no value offline at all. The marketed offline mode is store-and-forward that executes on reconnection, and core M-Pesa runs on USSD, which needs a live GSM session. What it removed was the smartphone and the data plan, never the network. SAFARICOM | ||||
Dashed chip = proposed, in trilogue. NPCI’s reported offline PoS product is press-only and omitted. Scheme and regulator documentation, as of 17 Aug 2026.
Swipe the table sideways, or expand it
Every offline design boils down to the same three key decisions
Put the models side by side, and it appears to me that each one reduces to three key decisions.
- Who is allowed to be disconnected?
- How much value is at risk while they remain disconnected?
- Who eats the fraud losses that get through?
I have started thinking of the answers to these questions as a scheme’s disconnection budget. The bounded authority a payment system extends to a payer or payee at the moments it cannot check is the most useful focal lens I have found for comparing designs that otherwise look nothing alike.
The reason the scheme’s disconnection budget can never be unlimited is not engineering conservatism. The IMF’s analysis, citing underlying research, states that eliminating double spending in a fully offline system is mathematically impossible to achieve. It can only be bounded, and physical cash, incidentally, has always had the same property. Secure elements raise the cost of attack by orders of magnitude, but nothing restores the missing invalidation path. So the residual risk is irreducible, and the cap is essentially a means for each scheme to write down how much of it they will tolerate.
When you interpret the caps that way, they become a ledger of risk and fraud appetite. The UK raised its contactless limit from £30 to £45 in the first weeks of the pandemic and to £100 the following year. In December 2025, the FCA went further and decided to let firms with strong fraud controls set their own limits from March 2026. Note that the UK contactless cap governs authentication rather than offline authorisation, since UK contactless transactions are normally authorised online, whereas Sweden’s chip cap governs offline authorisation and UPI Lite’s balance cap governs a bearer float. These caps sit in different places and control different things, but every time one of them changes, it is because someone has re-priced the same trade-off between convenience, availability and fraud.
Every disconnection budget is a decision about how much fraud a scheme is prepared to tolerate, and every one of them names who pays for the losses that get through.
The caps are decisions, not physics.
Offline, no-PIN and bearer-balance limits across systems, grouped by what the cap actually governs, with who decided each one and where the risk sits.
| Instrument | The cap | Decided by | Risk sits with | |
|---|---|---|---|---|
AUTHENTICATION | UK contactlessSCA exemption | £100 per tap, firm-set from Mar 2026 | FCA | ISSUER |
| EU contactlessPSD2 Art. 11 | €50 per tap · €150 or 5 taps | EU RTS | ISSUER | |
| WeChat payment codeno-PIN ceiling | ¥1,000 per txn · 10/day | Platform | PLATFORM | |
OFFLINE AUTH | Sweden offline cardsEMV chip cap | ≥SEK 2,000 per txn, plus a week+ of essentials on chip | Riksbank pact | ISSUER |
Zettle offline mode merchant queue | $1,000/txn · $10,000/device 24h to reconnect | PayPal | MERCHANT | |
BEARER BALANCE | UPI Lite X on-device float | ₹500 per txn · ₹2,000 balance | RBI / NPCI | ACCOUNT HOLDER* |
| Octopusstored value | HK$3,000 balance, a CDD boundary | HKMA rules | ACCOUNT HOLDER | |
| Suicastored value | ¥20,000 balance, until autumn 2026 | JR East | ACCOUNT HOLDER | |
| Digital euro offlinesecure element | Holding limit undecided | In trilogue | NOT SETTLED |
Digital euro offline limit undecided (design in trilogue). Suica’s balance moves server-side in autumn 2026 to lift its cap.
* UPI Lite X: lost-device balances are refundable via the bank, and fraud in the offline window falls under RBI limited-liability rules.
Swipe the table sideways, or expand it
The direction of travel is a stated offline standard
There is no interoperable offline payment standard today. The BIS came closest with Project Polaris, which is a handbook rather than a specification, and its survey found central banks in near-unison on the fact that offline capability matters. Meanwhile, every serious offline design has converged on the same three controls anyway: a hardware secure element, hard caps on value and velocity, and forced reconciliation with blacklisting. The convergence of architecture and design thinking is already real, with only the standard missing.
I would anticipate that availability follows the same path fraud took a decade ago, moving from an engineering metric buried in operations to a regulated, disclosed, designed-for property of national payment systems. Australia’s central bank already publishes retail payment outage statistics by institution. Sweden has shown what a nationally agreed disconnection budget looks like in production. The digital euro will, if the trilogue holds its course, hardwire one into law.
Three dates will inform us how fast this is moving. The digital euro regulation is expected to be agreed around the end of 2026, with the offline requirement intact or mildly watered down. The NPCI’s offline PoS terminals are reported to be nearing certification in 2026, and NPCI’s circular, when it comes, will show whether India raises its offline caps to match. And the Fórum Pix agenda holds offline Pix in its 2027 view, where Brazil will have to decide whether an instant-payment rail is willing to become, in part, a bearer instrument.
For fifteen years, the payments industry measured itself on speed, and the last five years were a contest over who could settle in fewer seconds. The next contest, in my view, is more consequential. It’s not how fast the system runs when everything works, but in an increasingly cashless society, how much of the economy still functions when it doesn’t.










FCA
EU RTS
Riksbank pact
PayPal
RBI / NPCI
HKMA rules
JR East