Written by Moeed Sheikh
Every time someone logs in to JazzCash, tops up Easypaisa, or checks out on Daraz, a one-time code is sent via SMS. That single text costs the sending business somewhere between $0.20 and $0.47 for international traffic & around PKR 3.5 for local traffic, depending on the carrier and the aggregator in the chain. Multiply that by every login, every transfer, every checkout across a subscriber base of roughly 205 million, and you start to see why A2P SMS has been one of the more reliable revenue streams telecom operators in Pakistan can count on.
Then the State Bank stepped in. Under PSD Circular No. 01 of 2024, banks and microfinance banks were told they could replace SMS OTPs with a Transaction PIN or Financial PIN for mobile banking transactions, with transaction alerts moving to push notifications, in-app alerts, and email, free of cost to the customer, starting January 1, 2025.
That shift hasn’t stopped there. Regulatory conversations already underway point to the same push/in-app default extending well past mobile banking apps, to every transaction channel, branch, and over-the-counter included, not just what happens inside an app. What looks set to stay protected is OTP delivery and account-security alerts, which appear likely to keep a free SMS lane even as everyday “you spent X, your balance is Y” notifications move to push and in-app by default, with SMS surviving mainly as a paid opt-in for customers who specifically ask for it. If that’s the direction it lands in, the SMS volume operators actually lose isn’t the OTPs this article opened with; it’s the much bigger, much more frequent stream of transaction alerts that fire on every purchase, everywhere, not only inside a banking app.
Pakistan isn’t an outlier in the broader direction either. The Philippines’ central bank has ordered a similar shift for high-risk transactions; the UAE has told banks to phase out SMS OTP by March 2026, and globally, OTP-related SMS traffic peaked back in 2022 and has been sliding since. Juniper Research puts total A2P SMS volume on a path from 1.9 trillion messages in 2023 down toward 1.5 trillion by 2029.
None of that makes A2P SMS in Pakistan collapse overnight; push notifications need an installed, opened app, and SMS remains the fallback that works on a basic handset with no data plan. But the direction is set by regulation now, not customer preference, and regulation doesn’t reverse once compliance costs are sunk. Telecom operators here are watching the same category international carriers watched play out elsewhere. In some markets, international A2P SMS volume contracted by up to 70% within a few quarters once large accounts moved their traffic. Indonesia is the cautionary case: after operators leaned on inflated pricing, Google and Telegram simply withdrew OTP traffic from the country. Nobody came back.
That’s the part worth sitting with, not because Pakistani operators have been asleep, but because the economics have made caution the safer-looking move. A2P SMS is real, immediate revenue with an existing billing relationship. Building something new means giving up a known number for an unproven one, on a timeline set by someone else’s regulator. That’s a genuinely hard trade to make first.
Except that the “something new” already exists, and Pakistani operators aren’t the ones building it. GSMA’s Open Gateway initiative, the standardized way mobile networks expose functions like SIM Swap detection and Number Verification through a common API layer, now counts 86 operator groups, covering more than 300 networks and roughly 80% of global mobile connections, commercially live on it. A bank in Germany or Uruguay can check whether a customer’s SIM was recently swapped before approving a large transfer, in real time, without an SMS ever being sent. That’s not a pilot. It’s a shipped product, sold by Deutsche Telekom, Vodafone, Telefónica, and dozens of others, built on open specifications from the CAMARA project.
Pakistan has a head start most of those markets don’t: NADRA already biometrically verifies every SIM against a national identity record, and that same biometric link is expected to gate which customers qualify for push and in-app alerts under the next round of rules. The identity layer other countries are bolting onto their networks from scratch is already sitting underneath every Pakistani number; what’s missing is an operator deciding to expose it as an API instead of a customer-service backend. And the one category regulators still seem inclined to leave on SMS is OTP delivery, precisely the use case that Number Verification and SIM Swap already replace elsewhere. That’s a case operators can make to the regulator now, while the volume and the relationship are still theirs to negotiate with, not after both have already moved onto someone else’s platform.
If you’re setting network strategy at an operator right now, this is the trade worth actually running the numbers on, not “how do we defend A2P SMS revenue,” but “who captures the authentication layer that replaces it.” Because that layer is getting built either way. If Jazz, Zong, Ufone, or Telenor don’t build the Number Verification and SIM Swap APIs that Pakistani banks are about to need, a CPaaS aggregator or a hyperscaler’s connectivity platform will build them on top of them instead, the way Microsoft’s Azure Programmable Connectivity and Vonage have already done in markets where local operators moved slowly.
SMS isn’t dying because banks got tired of it. It’s dying because something more secure became available everywhere else. The real question for Pakistani telecoms isn’t whether that shift is coming. It’s whether they own what replaces it or rent it back from someone who built it while they were still counting on the SMS number holding steady.
Author Bio:
Moeed Sheikh is the VP Products & Partnerships at Eocean.