2026-07-03

Added

Regulation on technical standards for strong customer authentication and common and secure open standards of communication

The Central Bank of the Republic of Kosovo requires payment service providers to implement strong customer authentication based on two or more independent elements of knowledge, possession, and inherence. The regulation establishes specific exemptions from this requirement, including contactless payments capped at EUR 50 per transaction with a cumulative limit of EUR 150 or five transactions, and remote transactions under EUR 30 with a cumulative limit of EUR 100 or five transactions. Providers must maintain transaction monitoring mechanisms to detect fraud and conduct periodic audits, with annual audits required for those utilizing the transaction risk analysis exemption. The document also mandates dynamic linking for certain transactions and sets strict limits on failed authentication attempts and session inactivity.

Central Bank of the Republic of Kosovo logo

Kosovo

Central Bank of the Republic of Kosovo

Click to view full text