ABDM M1 M2 M3 Certification: NHA Sandbox Exit in 4 Steps
Founder & Lead Developer, Codingclave · 200+ projects since 2017

ABDM M1, M2 and M3 certification takes 4 to 7 months for a hospital with a working HMS, and the NHA sandbox exit is a 4-step process: functional testing by an NHA-empanelled agency, a WASA (Safe-to-Host) security certificate, Health Tech Committee approval with an Exit Form, and production credentials. M1 is ABHA creation and verification, M2 is linking health records to an ABHA address (HIP), and M3 is exchanging records between facilities (HIU).
I'm Ashish Sharma, founder of Codingclave in Lucknow. We have built 6 ABDM-integrated hospital systems since 2024, 2 of which hold NHA production access through M3. I re-checked every step below against the Sandbox Entry & Exit page on sandbox.abdm.gov.in and the ABDM dashboard on 4 October 2026, and I have marked where our own numbers are estimates.
Three things changed since I first wrote this guide:
- V3 APIs only. NHA no longer accepts an M1 built on V1 or V2 APIs for sandbox exit, and warns that V1/V2 credentials will be deactivated.
- Functional testing moved to empanelled agencies. Nine NHA-empanelled FT agencies now run the M1, M2 and M3 test cases, with a 7-working-day cap per engagement.
- Milestone 4 (NHPR) was added for native HFR and HPR flows inside the software.
For the business case rather than the technical path, start with the ABDM compliance pillar guide. If you want us to do the work, the scope and fixed prices are on the ABDM compliance hospital software service page.
WhatsApp me for ABDM certification help
ABDM M1 M2 M3 certification: what each milestone means
NHA's own one-line definitions, from the sandbox home page:
| Milestone | NHA definition | Your role | What it unlocks |
|---|---|---|---|
| M1 | ABHA creation and verification | Register patients with an ABHA | ABHA-linked registration, DHIS registration eligibility |
| M2 | Linking health records with ABHA address | HIP (Health Information Provider) | Records visible in the patient's ABHA app, DHIS per-record incentives, PM-JAY ABDM-HMIS compliance |
| M3 | Health records exchange between health facilities | HIU (Health Information User) | Doctors pull a patient's history from other facilities with consent |
| M4 | NHPR (native HFR and HPR flows) | Facility and professional registry inside your HMS | Required for integrators who onboard facilities and doctors from within the software |
Certification is per software. Once your HMS clears a milestone and exits the sandbox, every hospital that deploys it inherits that status, which is why the ABHA integration service can offer an M1-only path in 4 to 8 weeks for hospitals that only need registration.
NHA sandbox: how to register and what you get
Where: sandbox.abdm.gov.in, then Apply for Sandbox Integration.
What the entry form asks for (per the Sandbox Entry & Exit page): entity name, email address, password, website, and intent to integrate (HIP, HIU, both, or health locker). NHA recommends a designation-based email such as integration@yourcompany.com because every credential, update and the Exit Form login goes only to that address.
NHA's six-step sandbox process, as printed on the portal:
- Send request for sandbox API access
- Get access after Health Tech Committee approval
- Integrate with the sandbox APIs
- Functional testing and WASA
- HTC demo and live access
- Go live (available in all states and union territories)
What you receive after approval: sandbox client-id and secret, the V3 Postman collections, a sandbox ABHA address for testing, the reference ABHA Android app (version 3.3.0 "Godavari", updated 24 November 2025 at the time of writing), and the HIU reference app for raising consent requests.
Timeline: 1 to 3 weeks in our experience. Cost: free. Support: sandboxsupport.abdm.gov.in and the developer forum at devforum.ndhm.gov.in.
ABDM M1 documentation, V3 APIs and the "M1 certificate"
What M1 requires you to build
Using the V3 ABHA APIs only:
| Capability | What the patient experiences |
|---|---|
| ABHA enrolment by Aadhaar OTP | Walk-in with Aadhaar gets an ABHA number in under two minutes |
| ABHA enrolment by mobile number | Walk-in without Aadhaar still gets an ABHA |
| Profile login and verification | Returning patient verifies an existing ABHA by OTP |
| Fetch ABHA by Aadhaar | Front desk finds an existing ABHA without the patient remembering it |
| QR scan | Patient shows the ABHA app QR, desk verifies in one scan |
| Profile fetch and local linkage | ABHA stored against the patient record with an audit trail |
The last two rows (mobile-number access and Aadhaar-based fetch) were added to the Milestone 1 test scenarios in NHA's updated slide deck on the Test Cases page.
M1 test scenarios the FT agency runs
- New patient with Aadhaar, create ABHA via Aadhaar OTP
- New patient without Aadhaar, create ABHA via mobile OTP
- Existing ABHA, verify by OTP
- Existing ABHA, verify by QR scan
- OTP timeout and resend handled without a crash
- Network failure mid-enrolment, safe retry
- Patient cancels mid-flow, no orphan record
- Phone already registered, fetch the existing ABHA instead of duplicating
What an "M1 certificate" actually is
NHA does not issue a document called an M1 certificate. What you get is the FT agency's certificate and report for Milestone 1 in NHA's approved template. That report, plus the WASA certificate, is what you attach to the Exit Form. HTC approval and production credentials are the real outcome.
Common M1 failures we have seen: no mobile fallback when Aadhaar OTP fails, consent text missing at enrolment, incomplete audit trail, QR scan not implemented, and the big one in 2026, an M1 built on V2 APIs that has to be redone on V3.
ABDM M2: linking records to an ABHA address (the hard one)
M2 turns your HMS into a Health Information Provider. Every visit becomes a care context linked to the patient's ABHA address, discoverable through the ABDM gateway and shareable only with consent.
What you build for M2
- FHIR R4 mapping layer. Map your schema to FHIR R4 bundles for the ABDM health information types: Prescription, OP Consultation, Diagnostic Report, Discharge Summary, Immunization Record, Wellness Record, Health Document Record and Invoice. The sandbox validator rejects malformed bundles.
- Care context linking. Create a care context per encounter and link it to the ABHA address, with the patient's OTP-based or token-based confirmation.
- Discovery. Answer patient discovery requests from the gateway using ABHA address, mobile or demographic match.
- Consent handling via the HIE-CM. Receive consent notifications, validate the consent artefact, honour scope and expiry, stop sharing on revoke.
- Encrypted data transfer. ECDH key exchange with the requesting HIU's public key and AES-GCM encryption of the FHIR payload, pushed to the HIU's data-push URL.
- Audit logging. Who requested what, when, under which consent, retained for inspection.
M2 test scenarios the FT agency runs
- HIU raises a consent request, your HMS receives the notification
- Patient grants consent in the ABHA app
- Your HMS encrypts the requested FHIR R4 bundles and transfers them
- HIU receives and decrypts the bundles
- Audit entries verified
- Patient revokes consent, sharing stops immediately
- Expired consent artefact is rejected
- Every bundle passes strict FHIR R4 validation
Realistic M2 timeline: 6 to 8 weeks with clean structured data, 8 to 12 weeks with messy legacy data, 10 to 16 weeks for a first-time vendor. Nine out of ten M2 delays we have been called into were FHIR mapping of legacy data, not the APIs.
What M2 gets you: PM-JAY's ABDM-HMIS compliance condition is met at M2 (see the incentive section below), and DHIS per-record incentives start counting.
ABDM M3 sandbox: what it tests and how to exit
M3 is M2's mirror. After serving records as a HIP, your HMS now requests them as a Health Information User. NHA's current V3 documentation includes new endpoints for both M2 and M3, so build on V3 from day one.
What the M3 sandbox tests
- Doctor clicks "Pull patient history", your HMS raises a consent request to the patient's ABHA address with purpose, health information types and date range
- Patient approves in the ABHA app, your HMS receives the consent artefact
- Your HMS requests health information from the source HIPs through the gateway
- Encrypted FHIR R4 bundles arrive at your data-push URL, you decrypt and display them in the patient's chart, grouped by type
- Audit entries verified for the request and the receipt
- Patient denies or revokes, your HMS handles it without error
How you exit M3
Exactly the same 4 steps as M1 and M2, described in the next section. Because the FT agency can test M1, M2 and M3 together, most vendors finish all three builds first, then book a single FT engagement, which keeps you inside NHA's 7-working-day cap.
Realistic M3 timeline: 2 to 4 weeks. The consent, encryption and FHIR parsing already exist from M2, so most of the effort is making imported records readable for doctors.
What M3 gets you: fewer repeat tests, a complete history on day one of admission, and, under DHIS Corrigendum 7, ₹10 to the HIU for every consent that results in a successful record share.
ABDM sandbox exit process (step by step)
This is the official 4-step exit published on sandbox.abdm.gov.in (Documentation, Sandbox Entry & Exit), checked on 4 October 2026.
Step 1a: functional testing by an NHA-empanelled agency
Approach one of the nine agencies on NHA's list: AKS Information Technology Services, Avasure Technologies, AQM Technologies, Code Decode Labs, ESF Labs, FIME India, Nangia & Co LLP, Oxygen Consulting Services, or Suma Soft. Testing is chargeable, and NHA does not publish fees, so get three quotes. The agency runs the functional and non-functional test cases for your milestones and must file its report, in NHA's standard template, within 7 working days of onboarding you. Grievances about an agency go to integration.support@nha.gov.in.
Step 1b: internal demo by NHA
NHA's integration team reviews the FT report and schedules an internal demo to confirm the agency tested the current scenarios. An M1 done on V1 or V2 APIs is rejected here; only V3 counts.
Step 2: WASA (Safe-to-Host) certificate
Get a Website Application Security Assessment from a CERT-IN or STQC empanelled agency and submit the Safe-to-Host certificate to NHA. Web, Android and iOS builds each need their own WASA. NHA's infrastructure pointers for clearing the audit are linked on the same page, and STQC may validate sample applications itself.
Step 3: Exit Form and Health Tech Committee approval
- Log in to the sandbox with the email and password from your original application
- Open the Exit Form, select the milestones you are exiting, and attach the FT certificate and reports, WASA certificate, signed Undertaking and GSTIN certificate
- Courier the signed hard copy of the Undertaking to the NHA office
- Submit; after review, NHA schedules your demo to the HTC
- Demonstrate the milestones live to the committee
Step 4: production access and the Integrator Testing Lab
NHA emails production client-id and secret to the registered address. Before touching a real hospital, point your production build at NHA's test facility, named "Integrator Testing Lab", facility ID IN0110005723, and confirm record linking works through the multi-HRP construct. Each partner hospital must be on the Health Facility Registry, and its HFR profile must carry your production bridge ID. Production support: abdm.pc13@nha.gov.in.
Where exits fail in our experience: FT report not in NHA's template, WASA done for the web app but not the Android app, Undertaking hard copy never posted, and a demo build that differs from the build the FT agency tested.
PM-JAY incentives inactive due to ABDM non-compliance: how to fix
If your PM-JAY hospital login shows "Hospital incentives are inactive in PMJAY application due to non-compliance with ABDM-HMIS and M1, M2 (or higher) requirements", it means your facility profile does not show an ABDM-compliant HMIS at M1 and M2 or higher. The old portal at hospitals.pmjay.gov.in now redirects empanelment to HEM 2.0, and NHA gates the hospital add-on incentives on ABDM adoption.
Fix it in this order:
- Confirm HFR registration. Your hospital must be a verified facility on the Health Facility Registry and the HFR ID in HEM 2.0 must match.
- Check your vendor's status. Look up your HMS on NHA's partner list (abdm.gov.in/our-partners). It needs production access for M1 and M2, not sandbox access and not M1 alone.
- Link the bridge ID. Ask the vendor to confirm its production bridge ID is linked to your HFR profile; without this, no record you create counts as an ABDM transaction.
- Start creating ABHA-linked records. Capture ABHA at registration for PM-JAY beneficiaries and link the discharge summary and diagnostic reports, because NHA sees compliance through transactions, not paperwork.
- Update HEM 2.0 and escalate. Enter the HMIS details in your HEM 2.0 profile, then raise a ticket with your State Health Agency if the flag does not clear in the next cycle.
If your current vendor is M1-only or still on V2 APIs, the honest answer is that you need an M2-certified HMS. Our PM-JAY empanelment software guide covers the HEM 2.0 side, and the ABDM compliance service covers getting your software to M2 and beyond. I could not read the HEM 2.0 rule text itself because it sits behind the hospital login, so treat the exact incentive percentages as something to confirm with your SHA.
Digital Health Incentive Scheme 2026: what certified software earns you
Verified against abdm.gov.in/dhis on 4 October 2026. Corrigendum 7 runs April to September 2026 and pays only for KYC-verified ABHA-linked records and consent-based sharing, above 100 eligible transactions a month:
| Transaction | Health facility earns | Digital solution company earns |
|---|---|---|
| Diagnostic Report or Discharge Summary linked to a KYC-verified ABHA | ₹10 per record | ₹5 per record |
| Any other health information type linked (Prescription, OP Consultation, Immunization, Wellness, Invoice) | ₹5 per record | ₹2.50 per record |
| Consent-based record share (HIU-initiated or patient-initiated) | ₹10 to the HIU, ₹5 to the source HIP | per API confirmation |
| PM-JAY claim filed in FHIR through NHCX with ABHA | ₹200 per claim or 10% of claim, whichever is lower | ₹10 per claim |
Caps: 1 ABHA per day and 5 per month per category, ₹1 crore for the NHCX category, and up to ₹5 crore overall per registered facility. A hospital registers for DHIS from its HFR profile; a vendor registers from its sandbox profile after going live. None of this is payable until the software has exited the sandbox.
How long does ABDM M1 M2 M3 certification take in 2026
| Stage | Duration (our estimate) | Owner |
|---|---|---|
| Sandbox registration and HTC access | 1-3 weeks | NHA |
| M1 build on V3 APIs | 3-5 weeks | Vendor |
| M2 build (FHIR R4, consent, encryption) | 6-12 weeks | Vendor |
| M3 build | 2-4 weeks (parallel with late M2) | Vendor |
| Functional testing (M1+M2+M3 together) | up to 7 working days (NHA cap) | FT agency |
| NHA internal demo | 1-2 weeks | NHA |
| WASA / Safe-to-Host (can run parallel to M3) | 2-4 weeks | CERT-IN auditor |
| Exit Form review and HTC demo | 2-4 weeks | NHA |
| Production config and Integrator Testing Lab check | 1-2 weeks | Vendor |
| Total with an existing HMS | 4-7 months | |
| Total building the HMS and ABDM together | 8-12 months |
Hospital rollout (data migration, staff training, parallel run) adds 4 to 12 weeks on top, but it starts only after production credentials arrive. The dashboard numbers show why NHA is strict: on 4 October 2026 it reported 98.1 crore ABHAs, 122.7 crore linked records, 5,85,863 verified facilities and 12,30,296 verified professionals, so a badly built HIP can leak a lot of records.
ABDM certification cost in 2026
For a hospital working with a vendor on full certification:
| Component | Cost |
|---|---|
| NHA sandbox registration and production access | Free |
| M1 implementation (vendor) | ₹1.5L-₹3L |
| M2 implementation (vendor, the largest item) | ₹3L-₹7L |
| M3 implementation (vendor) | ₹1.5L-₹3L |
| Functional testing agency | Chargeable, unpublished; get three quotes |
| WASA / Safe-to-Host audit | ₹50K-₹2L |
| HFR and HPR registration | Free |
| Total certification cost | ₹6.5L-₹15L plus FT agency fees |
Add ₹50K-₹2L for staff training, ₹50K-₹3L for data migration, and ₹50K-₹3L a year for maintenance, including re-WASA after major releases. Our ABDM integration cost guide breaks these down by hospital size.
How Codingclave handles ABDM certification
Codingclave Development LLP (Lucknow, since 2017, 200+ projects, 4.9 stars on Google from 76 reviews, Top Rated on Upwork) has built 6 ABDM-integrated hospital systems since 2024, 2 with NHA production access through M3. Fixed-price scopes:
| Scope | Timeline | Cost |
|---|---|---|
| M1 only (ABHA creation and verification) | 4-8 weeks | ₹2L-₹4L |
| M1 + M2 (HIP, records shareable) | 12-18 weeks | ₹5L-₹10L |
| M1 + M2 + M3 (HIP + HIU) | 16-24 weeks | ₹6.5L-₹13L |
| Full certification with WASA coordination | 18-26 weeks | ₹7L-₹15L |
| Hospital training and go-live | +2-4 weeks | +₹1L-₹3L |
Every engagement includes sandbox setup, V3 API implementation, FHIR R4 mapping, HIE-CM consent integration, encryption and audit logging, FT agency and WASA coordination, the Exit Form bundle, the HTC demo, and the Integrator Testing Lab check. Details and FAQs are on the ABDM compliance hospital software and ABHA integration service pages.
If you are stuck mid-certification (failed M2 validation, WASA findings, a rejected Exit Form, or an M1 that has to be redone on V3), we can pick it up from where it stopped.
WhatsApp Ashish for ABDM certification help
About the author
Ashish Sharma is the founder of Codingclave, a Top Rated Upwork agency in Lucknow that has shipped 6 ABDM-integrated hospital management software builds since 2024, including 2 with NHA production access through M3. Reach him on LinkedIn or WhatsApp.
Related reading:
Frequently asked questions
The ABDM sandbox exit is the 4-step process NHA publishes at sandbox.abdm.gov.in under Sandbox Entry & Exit. Step 1: an NHA-empanelled functional testing agency tests your software against the official M1, M2 and M3 test cases and files its report in NHA's template, after which NHA runs an internal demo. Step 2: a CERT-IN or STQC empanelled auditor issues a Safe-to-Host (WASA) certificate. Step 3: you submit the Exit Form on the sandbox portal with the FT report, WASA certificate, signed Undertaking (hard copy posted to NHA) and GSTIN certificate, then demonstrate the milestones to the Health Tech Committee. Step 4: NHA emails production client-id and secret, and you verify record linking against the Integrator Testing Lab facility (IN0110005723) before going live.
M3 in the ABDM sandbox tests your software as a Health Information User, meaning it can request and display a patient's records from other facilities. The M3 test cases cover raising a consent request to the patient's ABHA address, handling grant, deny and revoke from the ABHA app, fetching the encrypted FHIR R4 bundle once consent is granted, decrypting it, showing it in the clinician's view, and writing an audit entry for every request. Because M2 already built the consent and encryption plumbing, M3 usually takes us 2 to 4 weeks. You exit M3 the same way as M1 and M2: FT agency report, WASA certificate, Exit Form and HTC demo. NHA's current V3 documentation includes new endpoints for both M2 and M3.
That message in the PM-JAY hospital portal (now HEM 2.0) means your facility profile does not show an ABDM-compliant HMIS that has cleared at least M1 and M2. NHA ties the hospital add-on incentives to ABDM adoption, so the flag stays on until the facility is on the Health Facility Registry, is using software from NHA's certified partner list with M1 and M2 (or higher) production access, and is creating ABHA-linked records. Fix it in this order: confirm your HFR ID, ask your vendor for proof of M2 production access and that its bridge ID is linked to your HFR profile, start linking records, then update the HMIS details in HEM 2.0 and raise a ticket with your State Health Agency if the flag does not clear.
There is no separate paper certificate called an M1 certificate from NHA. What integrators call the M1 certificate is the functional testing certificate and report issued by one of the nine NHA-empanelled FT agencies after your software passes the Milestone 1 test cases (ABHA creation and verification using V3 APIs). That FT certificate, together with the WASA Safe-to-Host certificate, is what you attach to the Exit Form, and HTC approval is what unlocks production credentials. Since 2025, NHA does not accept M1 implementations built on V1 or V2 APIs, so an older M1 pass on V2 has to be redone on V3 before it counts.
Everything is at sandbox.abdm.gov.in under Documentation. The left menu has Getting Started, Sandbox Entry & Exit, Milestone 1, Milestone 2, Milestone 3, Milestone 4 (NHPR), V3 Documentation, Swagger, Postman Collection, Test Cases and Use Cases. For M1 you need three things: the Milestone 1 page, the V3 Postman collection for M1 (ABHA enrolment by Aadhaar OTP, by mobile, profile login and verification, QR and profile fetch), and the Milestone 1 test scenarios on the Test Cases page, which were extended with mobile-number access and Aadhaar-based ABHA fetch. Developer questions go to devforum.ndhm.gov.in or sandboxsupport.abdm.gov.in.
Plan for 4 to 7 months with an existing digital HMS and 8 to 12 months if you are building the HMS and ABDM layer together. Our working breakdown: sandbox registration and HTC access 1 to 3 weeks, M1 build 3 to 5 weeks, M2 build 6 to 12 weeks (FHIR R4 mapping of legacy data is the bottleneck), M3 build 2 to 4 weeks, functional testing capped by NHA at 7 working days from onboarding with the agency, WASA 2 to 4 weeks, Exit Form review and HTC demo 2 to 4 weeks, production configuration and the Integrator Testing Lab check 1 to 2 weeks. With our pre-built modules we usually land in 16 to 24 weeks.
Yes. Step 2 of the official exit process is a Website Application Security Assessment from a CERT-IN or STQC empanelled agency, and NHA will not schedule the HTC demo without the Safe-to-Host certificate. NHA's sandbox FAQ adds three rules people miss: the web app, Android app and iOS app each need their own WASA, the audit runs on your staging URL and the certificate is licensed to the same build in production, and any major backend change needs a fresh WASA. Budget ₹50,000 to ₹2 lakh depending on application size and auditor, plus 1 to 2 weeks for fixing findings and a re-test. STQC may also validate sample applications itself.
Certification is per software, not per facility. Once a vendor's HMS has cleared M1, M2 and M3 plus WASA and holds production credentials, every hospital that deploys it inherits that status. The hospital still has its own checklist: register on the Health Facility Registry, get each doctor on the Healthcare Professional Registry, have the vendor link its production bridge ID to the hospital's HFR profile, and start creating ABHA-linked records. This is why a pre-certified HMS goes live in 2 to 4 weeks while a custom build needs the full 4 to 7 months first. NHA's dashboard on 4 October 2026 lists 584 successful integrators out of 3,511 active ones.