THE PAYMENTS TRACE SEARCH/
RESILIENCE

The summer offline payments got serious and became a requirement

Sweden switched on offline cards, the digital euro’s offline requirement entered trilogue, NPCI was reported to be building offline UPI at the point of sale and Brazil put offline Pix on its agenda, inside six weeks. Offline payment capability has stopped being an inclusion feature and become a resilience requirement, and who can comply is a question of architecture.

17 AUG 202612 MIN READ Discuss on LinkedIn

Written in a personal capacity. The author is an employee of Global Payments; this article is not written on its behalf.

Highlights

  1. Sweden’s offline card capability went live on the 1st July. The digital euro, UPI and Pix have all made offline moves within six weeks of each other, each at a different stage.
  2. During the Iberian blackout, the core payment systems ran throughout, yet card spending in affected areas still fell by an estimated 41 to 42 per cent.
  3. EMV chips have carried offline spending caps for decades. The US set its contactless floor limits to zero rather than price the risk.
  4. Instant rails settle on a central ledger, so true offline payment requires a bearer instrument built alongside the rail.
  5. Every offline design allocates a disconnection budget, a decision about how much fraud to tolerate and who pays for the losses that get through.
Contents

On the 11th June, Estonia’s central bank cut six supermarket stores, one from each of the country’s biggest chains, off the network for about an hour. This wasn’t down to a technical fault, or worse, an irritated central banker venting after a missed grocery run. It was planned, part of the national defence exercise ILVES 2026. Shoppers in Selver, Coop, Rimi, Maxima, Grossi and Lidl stores paid for their groceries by chip and PIN with no connection to anything. Rainer Olt, who heads Eesti Pank’s payment and systems department, said afterwards that the exercise “gave the confidence that offline card payments work” whilst also revealing “issues that need to be dealt with”. A central bank running a live-fire drill on disconnected card acceptance in a NATO member state in 2026 is not testing out an inclusion initiative. It is a clear signal of civil preparedness.

For most of the last fifteen years, offline payments have been framed as a feature to help cater for the edges of the map. Think of the rural customer with no signal, the festival-goer out in a field in the middle of nowhere, the farmers market stall sitting beyond conventional coverage. In my view, that framing has now been overtaken by something more significant and urgent, and this summer is the evidence of that.

The question the industry is answering has changed from “how do we reach people without connectivity” to “what does an economy do when connectivity fails,” and with that change came something the inclusion case was never able to fully attract: legal instruments, budgets and the urgency only deadlines can muster.

A post by Munish Gupta in my feed got me digging into this properly, and I’ll come back to his framing later, because the way he framed it deserves more credit than the discourse around offline usually gets.

Offline stopped being an inclusion feature and shifted gear to become a resilience requirement

Let’s take stock of what actually happened this summer, aside from the heatwaves bearing down across the UK and Europe. Four payment systems, four offline moves, all in the span of six weeks.

On the 1st July, Sweden’s offline card payment capability went live for essential goods. Seven banks, both global card schemes and four , working in concert with Sveriges Riksbank (the Swedish central bank), now support card payments that authorise offline.

This is enabled through the shopper’s use of their physical card and PIN, in grocery stores, pharmacies and staffed fuel stations, covering most Visa and Mastercard cards, with the Riksbank encouraging more banks to join.

The design brief tolerates disruptions lasting up to seven days, and Governor Erik Thedéen’s framing on the day was that “a resilient payment system requires all actors within the system to take responsibility”.

7 days The disruption tolerance in the design brief behind Sweden’s offline card capability.

On the 13th July, the Digital Euro Regulation, which as proposed would make offline capability a legal requirement from first issuance, entered its trilogue phase. Around the 20th July, the NPCI was reported to be building a fully offline NFC tap-to-pay experience for UPI at the point of sale, with terminal certification expected during 2026. And finally on the 10th August, Brazil’s central bank put offline Pix on its public agenda in the Pix management report. Its own Fórum Pix roadmap still parks the work in a 2027 and later discussion column, so that gap between the announcement and the agenda is worth bearing in mind.

FIG. 1 · SUMMER 2026 AND THE ROAD AHEAD

Four systems moved on offline in six weeks

JUN JUL AUG 2027 2028 2029 AXIS BREAK TODAY 1 JUL 2026 Sweden’s offline card capability goes live for essential goods 13 JUL 2026 Digital euro Regulation, offline requirement included, enters ≈20 JUL 2026 NPCI reported to be building offline UPI tap-to-pay at PoS 10 AUG 2026 Brazil puts offline Pix on the public agenda in the Pix report DURING 2026 Offline UPI terminal certification, as reported END-2026 Digital euro regulation agreed, with a pilot possible mid-2027 2027 AND LATER Offline Pix stays in the Fórum’s discussion column ~2029 Digital euro first issuance targeted

The figure is wider than a phone screen. Scroll it sideways, or use expand.

DOWNLOAD ALL MILESTONES SHOWN1 JUL 2026
1 JUL 2026 LIVE

Sweden’s offline card capability goes live for essential goods

Physical card and PIN, for essential goods, designed for disruptions of up to seven days. The Riksbank memo behind it describes offline authorisation up to a floor of at least SEK 2,000 per transaction at the issuer’s risk, with the chip’s accumulated limit sized to at least a week of a household’s essential purchases.

PRIMARY SOURCE SVERIGES RIKSBANK
The focal move. Sweden’s offline capability, live on 1 July. A regulatory or structural move that has happened.
A reported industry build. Press reporting only, so far. An announced target, which is a softer thing than a date.
Vishwanath Callikan, MBA SOURCED: RIKSBANK · EP TRILOGUE · MEDIANAMA · BCB FÓRUM PIX · AS OF 17 AUG 2026
A static master of this figure is available from the download control. Each event’s detail panel links to its primary source.

What all four have in common is that none of these are inclusion projects. Take Sweden’s example. It is anchored in the Sveriges Riksbank Act, which requires that payments function “in peacetime crisis situations and states of heightened alert.” Meanwhile, Norway’s BankAxept has quietly operated an offline backup sized to roughly one week of essential purchases since 2021, and Norwegian authorities now want it extended further. Denmark’s Payments Council targets offline card acceptance at supermarkets and pharmacies for at least a week. Finland legislated a statutory reserve payment system in 2022, a backstop for bank-level disruption rather than offline acceptance, but part of the same preparedness family. Sweden, Norway and Denmark have converged, almost without anyone outside the region noticing, on a common standard, which is that a citizen should be able to buy food, medicine and fuel for about a week with the network down.

David Birch has been arguing for years that payment resilience is critical national infrastructure and that engineered offline capability beats cash hoarding as the answer. His Cash and Catastrophe article on Substack makes that case well. Jeremy Light has made the adjacent argument that governed offline payments, cryptographically signed against reserved funds, are the resilient design paradigm to follow. He sets it out in his article I’m Still Standing, from February. What this summer added was not a better argument but regulators acting decisively on it. The question they were asking changed, and the impetus followed.

In April’s blackout, the core held firm but failure materialised at the brittle edge

The empirical hinge for all of this goes back to the 28th April 2025, when the Iberian grid went down for the better part of a day. The key detail that matters is not that payments failed (they do sometimes), but where they failed.

Banco de España’s next-morning monitoring listed TARGET, Iberpay and Redsys as “functioning regularly”. In Portugal, SIBS reported its core systems operational all day. In both cases, the switches and settlement systems ran, but none of that mattered to a shopper standing in a dark store in Valencia because the terminals had no power, telecoms were degraded, and the tills were down.

The ECB’s post-mortem compiled the numbers, drawing on telemetry from Spanish banks. Card spending in affected areas fell by an estimated 41 to 42 per cent against unaffected regions, national e-commerce spending dropped by around 54 per cent, and overall Spanish consumption fell by an estimated 34 per cent in a single day.

The core payment systems ran throughout the 28 April 2025 Iberian blackout, and card spending in affected areas still fell by an estimated 41 to 42 per cent. Portrait big-stat graphic with a waffle grid marking the fall, noting TARGET, Iberpay and Redsys listed as functioning regularly, e-commerce down around 54 per cent and Spanish consumption down an estimated 34 per cent in a day.
FIG. 2 · The core systems ran uninterrupted, but spending still collapsed. Click to expand or download.

This is illustrative of a pattern rather than a one-off incident. The CrowdStrike update of July 2024 took out Windows-based tills at Waterstones, Waitrose and Wetherspoons while Visa’s and Mastercard’s networks ran untroubled. Core systems are engineered for extreme availability, but the edge, where a payment actually happens and is initiated, can be a Windows OS till, a terminal running over a flaky SIM network and a power socket that isn’t backed by a UPS.

And when the core itself fails, the lesson runs the same way in reverse. In June 2018, a partial failure in a single switch in Visa’s primary data centre stopped roughly 5.2 million European transactions in ten hours, and there was no offline fallback waiting at the edge to absorb it. Wherever the single point of failure lies, the payment fails with it, because, by design, nothing in the chain is permitted to proceed unchecked.

5.2m European Visa transactions stopped in ten hours in June 2018, with no offline fallback waiting at the edge.

Piero Cipollone made exactly this case to the European Parliament last September, citing people in Spain and Portugal who were “unable to pay” because they had no cash on hand, and framing the digital euro’s offline function as the answer. For balance, he has also argued against a purely offline design. But the institutional direction is not in doubt, and it is the same direction the Riksbank, Norges Bank, Danmarks Nationalbank and Eesti Pank are already walking.

Offline has stopped being a feature you add for the disconnected and become an insurance policy you price for the day the connection fails.

Cards solved offline decades ago, and then switched it off

For those not steeped in the arcane arts of card internals, here is the part of this story that the current coverage has largely lost from memory. The card system had already solved offline long ago, and, funnily enough, the solution still sits in the specification.

An EMV chip carries counters and cumulative amount limits, including the Lower and Upper Consecutive Offline Limits (EMV tags 9F14 and 9F23), that track how many times, and for how much, the card has been approved offline since it was last in contact with its issuer. Terminals have their own limits, and neither side can force an offline approval alone. The chip can, however, overrule a terminal that asks for one, forcing the transaction online or declining it outright, and whichever of the two limits is more stringent always wins.

The design insight, and I would go so far as to call it one of the most under-appreciated decisions in payments, is where the control lives. The cap sits in the cardholder’s hand, in tamper-resistant hardware, where neither a broken network nor a compromised terminal can loosen it.

Then the industry switched it off. In the United States, contactless floor limits were set to zero across the networks by 2020, which is the cheapest possible way to manage offline risk, since a floor limit of zero abolishes offline authorisation at the point of sale entirely. Always-on connectivity became cheap, fraud teams preferred real-time decisions on every transaction, and the offline apparatus went dormant outside transit and aviation.

Europe kept the pattern but moved the counter. PSD2’s contactless exemption, in Article 11 of the SCA rules, allows €50 per tap and €150 or five transactions before authentication, and that counter sits at the issuer, inside exactly the infrastructure that disappears in an outage.

SEK 2,000 Sweden’s per-transaction offline floor limit, authorised at the issuer’s risk.

This is what makes Sweden’s design historically interesting rather than merely sensible. The Riksbank’s memo describes offline authorisation up to a floor limit of at least SEK 2,000 per transaction, at the issuer’s risk, with an accumulated offline limit in the card’s EMV chip sized to at least a week of a household’s essential purchases. Sweden’s fix is, at its core, an instruction to switch EMV’s dormant machinery back on, with the cap limits re-sized for a national emergency instead of a corner shop.

Instant rails cannot follow suit without becoming something else entirely

If you know me, you’re probably wondering why I’ve just spent ages talking about how cards handle offline payments. Well, let me get back to my preferred subject matter and bring the conversation back to the land of ‘other’ payment methods.

Let’s start by asking ourselves: why can’t Pix, UPI proper, or any of the instant-payment rails that now carry large chunks of the world’s daily commerce simply do what Sweden did?

This is where the architecture bites, and it is the reason the offline story is fragmenting rather than converging.

An (A2A) rail settles by moving entries on a central ledger. There is no ledger entry you can make without reaching the ledger, and I could not find a single live A2A outside India that has a genuinely offline mode. But even India’s own exception proves the rule.

UPI Lite X, the genuinely offline variant, works because, under the UPI Lite framework it is built on, the money leaves your account in advance and sits in an “escrow / pool / designated account” at the bank, mirrored on your device. That is not UPI working offline so much as a small bearer instrument riding alongside the rail, under the rail’s brand. The digital euro reaches the same destination by another road, with an offline applet on a where, in the ECB’s own words, final settlement occurs locally between devices.

Both-offline payment exists only where someone has built a bearer instrument, and building a bearer instrument is a monetary design decision, not a rail feature.

Munish Gupta, whose post prompted this piece, framed the underlying pattern well. When you cannot reach the source of truth in time, you move a bounded slice of it closer and reconcile after, the way a cache does, with a spending limit attached. This bounded local-authority pattern is exactly right, and it describes everything from EMV floor limits to transit gates. The one place I would extend his framing is at the point of failure, because the analogy identifies precisely why offline money is hard.

A cache can be invalidated by its source of truth. Money handed to a counterparty offline cannot be, and every control in real offline design exists because that invalidation path is gone.

Once you see that asymmetry, the fragmented landscape of “offline” payments becomes visible and sharpens into focus. Nearly every model in production is offline on one side only, and each one has picked a different side, a different cap and a different loss-bearer.

Alipay’s and WeChat’s payment codes rotate offline on the payer’s phone, but the merchant’s scanner must be online, no-PIN use is capped at ¥1,000 per transaction, and the platforms have publicly pledged to eat code-theft losses.

¥1,000 the no-PIN ceiling on a rotating Alipay or WeChat payment code, per transaction

Apple Pay runs a truly impressive payer-offline design at global scale, with device-bound keys held in a secure element, and its Express transit cards keep working on power reserve for up to a whopping five hours after the battery dies.

Google Wallet meters the same freedom through a stock of limited-use keys that replenish when the device reconnects. Transit gates run the mirror image, payee-offline, waving you through on a deny-list check and carrying first-ride risk until the deferred authorisation lands.

Zettle’s merchant mode caps the queue at $10,000 per device, with 24 hours to reconnect, and states plainly that the merchant assumes the risk on anything declined, expired or disputed. And M-Pesa, so often cited as the offline success story, moves no value offline at all. Its marketed offline mode is store-and-forward and executes on reconnection, while core M-Pesa runs on USSD, which requires a live GSM session. What M-Pesa removed was the smartphone and the data plan, never the network.

FIG. 3 · OFFLINE PAYMENT MODELS

Every offline model picks a side, a cap and a loss-bearer.

TAP ANY MODEL FOR ITS MECHANICS AND PRIMARY SOURCE

The models in production, compared on the three decisions of the disconnection budget: who can be disconnected, on what cap, at whose risk.

Model Who can be offline The cap Who eats the loss Details

Dashed chip = proposed, in trilogue. NPCI’s reported offline PoS product is press-only and omitted. Scheme and regulator documentation, as of 17 Aug 2026.

Swipe the table sideways, or expand it

The one both-offline model in production at issuer risk is cards, and M-Pesa moves no value offlineINTERACTIVE FIGURE · TAP A ROW TO EXPAND IT
DOWNLOAD

Every row opens: the model’s offline mechanics in two sentences, and the primary source the row is built on. The static master from the download control is the version that runs with the LinkedIn post.

Every offline design boils down to the same three key decisions

Put the models side by side, and it appears to me that each one reduces to three key decisions.

  1. Who is allowed to be disconnected?
  2. How much value is at risk while they remain disconnected?
  3. Who eats the fraud losses that get through?

I have started thinking of the answers to these questions as a scheme’s disconnection budget. The bounded authority a payment system extends to a payer or payee at the moments it cannot check is the most useful focal lens I have found for comparing designs that otherwise look nothing alike.

The reason the scheme’s disconnection budget can never be unlimited is not engineering conservatism. The IMF’s analysis, citing underlying research, states that eliminating double spending in a fully offline system is mathematically impossible to achieve. It can only be bounded, and physical cash, incidentally, has always had the same property. Secure elements raise the cost of attack by orders of magnitude, but nothing restores the missing invalidation path. So the residual risk is irreducible, and the cap is essentially a means for each scheme to write down how much of it they will tolerate.

When you interpret the caps that way, they become a ledger of risk and fraud appetite. The UK raised its contactless limit from £30 to £45 in the first weeks of the pandemic and to £100 the following year. In December 2025, the FCA went further and decided to let firms with strong fraud controls set their own limits from March 2026. Note that the UK contactless cap governs authentication rather than offline authorisation, since UK contactless transactions are normally authorised online, whereas Sweden’s chip cap governs offline authorisation and UPI Lite’s balance cap governs a bearer float. These caps sit in different places and control different things, but every time one of them changes, it is because someone has re-priced the same trade-off between convenience, availability and fraud.

Every disconnection budget is a decision about how much fraud a scheme is prepared to tolerate, and every one of them names who pays for the losses that get through.

FIG. 4 · DISCONNECTION BUDGETS

The caps are decisions, not physics.

FILTER THE CAPS BY WHAT EACH ONE ACTUALLY GOVERNS

Offline, no-PIN and bearer-balance limits across systems, grouped by what the cap actually governs, with who decided each one and where the risk sits.

SPECIES All three species shown. Each cap governs a different thing.
Instrument The cap Decided by Risk sits with
AUTHENTICATION
UK contactlessSCA exemption£100 per tap,
firm-set from Mar 2026
FCAISSUER
EU contactlessPSD2 Art. 11€50 per tap ·
€150 or 5 taps
EU RTSISSUER
WeChat payment codeno-PIN ceiling¥1,000 per txn · 10/dayPlatformPLATFORM
OFFLINE AUTH
Sweden offline cardsEMV chip cap≥SEK 2,000 per txn, plus
a week+ of essentials
on chip
Riksbank pactISSUER
Zettle offline mode Zettlemerchant queue$1,000/txn · $10,000/device
24h to reconnect
PayPalMERCHANT
BEARER BALANCE
UPI Lite X UPI Lite Xon-device float₹500 per txn ·
₹2,000 balance
RBI / NPCIACCOUNT HOLDER*
Octopusstored valueHK$3,000 balance,
a CDD boundary
HKMA rulesACCOUNT HOLDER
Suicastored value¥20,000 balance,
until autumn 2026
JR EastACCOUNT HOLDER
Digital euro offlinesecure elementHolding limit undecidedIn trilogueNOT SETTLED

Digital euro offline limit undecided (design in trilogue). Suica’s balance moves server-side in autumn 2026 to lift its cap.
* UPI Lite X: lost-device balances are refundable via the bank, and fraud in the offline window falls under RBI limited-liability rules.

Swipe the table sideways, or expand it

Regulator, scheme and operator documentation · native currencies · as of 17 Aug 2026INTERACTIVE FIGURE · FILTER BY SPECIES
DOWNLOAD

Three species of cap sit in this table, and they are not the same decision: an authentication cap, an offline authorisation cap and a bearer balance cap bound different risks. Filter to one species to compare like with like.

The direction of travel is a stated offline standard

There is no interoperable offline payment standard today. The BIS came closest with Project Polaris, which is a handbook rather than a specification, and its survey found central banks in near-unison on the fact that offline capability matters. Meanwhile, every serious offline design has converged on the same three controls anyway: a hardware secure element, hard caps on value and velocity, and forced reconciliation with blacklisting. The convergence of architecture and design thinking is already real, with only the standard missing.

I would anticipate that availability follows the same path fraud took a decade ago, moving from an engineering metric buried in operations to a regulated, disclosed, designed-for property of national payment systems. Australia’s central bank already publishes retail payment outage statistics by institution. Sweden has shown what a nationally agreed disconnection budget looks like in production. The digital euro will, if the trilogue holds its course, hardwire one into law.

Three dates will inform us how fast this is moving. The digital euro regulation is expected to be agreed around the end of 2026, with the offline requirement intact or mildly watered down. The NPCI’s offline PoS terminals are reported to be nearing certification in 2026, and NPCI’s circular, when it comes, will show whether India raises its offline caps to match. And the Fórum Pix agenda holds offline Pix in its 2027 view, where Brazil will have to decide whether an instant-payment rail is willing to become, in part, a bearer instrument.

For fifteen years, the payments industry measured itself on speed, and the last five years were a contest over who could settle in fewer seconds. The next contest, in my view, is more consequential. It’s not how fast the system runs when everything works, but in an increasingly cashless society, how much of the economy still functions when it doesn’t.