2024-12-27
The Executive Board of the National Bank of Serbia issued this Decision to establish technical standards for strong customer authentication and secure communication protocols for payment service providers in Serbia. The regulation mandates the use of multi-factor authentication based on knowledge, possession, and inherence elements, while defining specific exemptions for low-value transactions, contactless payments, and trusted beneficiaries. It further requires providers to implement robust transaction monitoring mechanisms, conduct regular security audits, and ensure the dynamic linking of authentication codes to transaction amounts and payees.