Integration Guides

ABDM Sandbox to Production: Milestones M1, M2 and M3

The steps from ABDM sandbox registration to production keys: building each milestone, functional testing, the WASA security audit, sandbox exit and realistic timelines.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
7 min read
Developer testing software on a laptop

Getting an ABDM integration live is as much a certification process as a development task. You build against the sandbox, prove each milestone works, pass a security audit and only then receive production credentials. Knowing the sequence in advance saves weeks.

01

Step one: sandbox access

Register your organisation and product on the ABDM sandbox portal. On approval you receive a client ID and secret for the sandbox, and you register your bridge: the callback URL where the gateway will send responses. You will also need test facilities in the sandbox Health Facility Registry.

Sandbox credentialsClient ID and secret used to obtain session tokens
Bridge URLA public HTTPS endpoint for callbacks
ServicesYour facilities registered as HIP, HIU or both
Test ABHA accountsCreated in the sandbox for end-to-end tests
02

Step two: build the milestones

Decide which milestones you need. A hospital system usually builds all three; a lab system may need M1 and M2; an insurer or a teleconsultation tool may focus on M1 and M3.

Build an internal test harness early. Clicking through the PHR app by hand for every test does not scale.

M1ABHA creation, verification, profile fetch and scan-and-share
M2Care context linking, discovery, consent notifications and data transfer as HIP
M3Consent requests, artefact handling, data fetch and display as HIU
03

Step three: functional testing

When the build is complete you apply for functional testing. An agency empanelled by NHA runs your product against the test cases for each milestone, usually over screen-share on the sandbox. Expect them to check mandatory flows, error handling and that the user interface shows what the specifications require, such as consent details.

Test case sheet per milestoneDemo environment on sandboxRecorded demoFix and retest cycles
04

Step four: security audit

You then need a web application security assessment, commonly called WASA, by a CERT-In empanelled auditor, resulting in a safe-to-host certificate. The auditor tests the application and its ABDM flows against common vulnerability classes. Findings must be fixed and retested before the certificate is issued, so budget time for at least one round of remediation.

ScopeThe application, APIs and mobile apps that touch ABDM flows
Typical findingsMissing rate limits, weak session handling, verbose errors, insecure storage on mobile
OutputAudit report and safe-to-host certificate
05

Step five: sandbox exit and production

With functional test approval and the security certificate, you submit the sandbox exit application with the required documents. After review, production credentials are issued. You then register real facilities with their HFR IDs, switch endpoints and run a controlled go-live at one facility before rolling out.

06

Timelines and common delays

For a team that already has a working hospital or lab system, the build for all three milestones commonly takes two to four months, with testing, audit and exit adding roughly six to ten weeks. Delays usually come from waiting for test slots, audit remediation, and FHIR mapping that was left late. Starting the audit engagement before development finishes shortens the tail.

2 gates
Functional testing and security audit
6 to 10 weeks
Typical time for testing, audit and exit
One facility
Go live small before rolling out
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact