2026-07-03
Added · Updated
The Central Bank of the Republic of Kosovo requires payment service providers to implement strong customer authentication based on two or more independent elements of knowledge, possession, and inherence. The regulation establishes specific exemptions from this requirement, including contactless payments capped at EUR 50 per transaction with a cumulative limit of EUR 150 or five transactions, and remote transactions under EUR 30 with a cumulative limit of EUR 100 or five transactions. Providers must maintain transaction monitoring mechanisms to detect fraud and conduct periodic audits, with annual audits required for those utilizing the transaction risk analysis exemption. The document also mandates dynamic linking for certain transactions and sets strict limits on failed authentication attempts and session inactivity.
CBK published 3 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 35, paragraph 1 subparagraph 1.1 and Article 65 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No.77 / 16 August 2010), amended and supplemented by Law No. 05/L –150 (Official Gazette of the Republic of Kosovo / No. 10 / 03 April 2017) and pursuant to Article 98, paragraph 1 and Article 136 of the Law No.10/L-026 on Payment Services (Official Gazette of the Republic of Kosovo,No.10 / 14 May 2026), the Board of the Central Bank of the Republic of Kosovo, at its meeting held on June 29, 2026, approved the following:
REGULATION ON TECHNICAL STANDARDS FOR STRONG CUSTOMER AUTHENTICATION AND COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION
CHAPTER I
GENERAL PROVISIONS
Article 1
Purpose and Scope
Article 2
Definitions
Article 4
Review of the security measures
The implementation of the security measures referred to in Article 1 of this regulation shall be
documented, periodically tested, evaluated and audited in accordance with the applicable legal framework of the PSP by auditors with expertise in ICT (Information technology and communication) security and payments and operationally independent within or from the PSP.
The period between the audits referred to in paragraph 1 shall of this article be determined taking
into account the relevant accounting and statutory audit framework applicable to the PSP.
2.1. however, PSPs that make use of the exemption referred to in Article 18 of this regulation shall
be subject to an audit of the methodology, the model and the reported fraud rates at a minimum on a yearly basis. The auditor performing this audit shall have expertise in ICT security and payments and be operationally independent within or from the PSP. During the first year of making use of the exemption under Article 18 of this regulation and at least every 3 years thereafter, or more frequently at the CBK’s request, this audit shall be carried out by an independent and qualified external auditor.
This audit shall present an evaluation and report on the compliance of the PSP's security measures
with the requirements set out in this Regulation. Report shall be made available to the CBK upon request.
CHAPTER II
SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION
Article 5
Authentication code
Where PSPs apply strong customer authentication in accordance with Article 97 paragraph 1 of
the Law on Payment Services, the authentication shall be based on two or more elements which are categorized as knowledge, possession and inherence and shall result in the generation of an authentication code.
1.1. the authentication code shall be only accepted once by the PSP when the payer uses the
authentication code to access its payment account online, to initiate an electronic payment transaction or to carry out any action through a remote channel which may imply a risk of payment fraud or other abuses.
For the purpose of paragraph 1 of this article, PSPs shall adopt security measures ensuring that
each of the following requirements is met:
2.1. no information on any of the elements referred to in paragraph 1 can be derived from the
disclosure of the authentication code;
2.2. it is not possible to generate a new authentication code based on the knowledge of any other
authentication code previously generated;
2.3. the authentication code cannot be forged.
PSPs shall ensure that the authentication by means of generating an authentication code includes
each of the following measures:
3.1. where the authentication for remote access, remote electronic payments and any other actions
through a remote channel which may imply a risk of payment fraud or other abuses has failed to generate an authentication code for the purposes of paragraph 1 of this article, it shall not be possible to identify which of the elements referred to in that paragraph was incorrect;
3.2. the number of failed authentications attempts that can take place consecutively, after which
the actions referred to in Article 97 paragraph 1 of the Law on Payment Services shall be temporarily or permanently blocked, shall not exceed five within a given period of time;
3.3. the communication sessions are protected against the capture of authentication data
transmitted during the authentication and against manipulation by unauthorized parties in accordance with the requirements in Chapter V of this regulation;
3.4. the maximum time without activity by the payer after being authenticated for accessing its
payment account online shall not exceed 5 (five) minutes.
Where the block referred to in subparagraph 3.2 of this article is temporary, the duration of that
block and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred to in Article 3 paragraph 2 of this regulation.
4.1. the payer shall be alerted before the block is made permanent;
4.2. where the block has been made permanent, a secure procedure shall be established allowing
the payer to regain use of the blocked electronic payment instruments.
Article 6
Dynamic linking
Where PSPs apply strong customer authentication in accordance with Article 97 paragraph 2 of
the Law on Payment Services, in addition to the requirements of Article 5 of this Regulation, they shall also adopt security measures that meet each of the following requirements:
1.1. the payer is made aware of the amount of the payment transaction and of the payee;
1.2. the authentication code generated is specific to the amount of the payment transaction and
the payee agreed to by the payer when initiating the transaction;
1.3. the authentication code accepted by the PSP corresponds to the original specific amount of
the payment transaction and to the identity of the payee agreed to by the payer;
1.4. any change to the amount or the payee results in the invalidation of the authentication code
generated.
For the purpose of paragraph 1 of this article, PSPs shall adopt security measures which ensure the
confidentiality, authenticity and integrity of each of the following:
2.1. the amount of the transaction and the payee throughout all of the phases of the authentication;
2.2. the information displayed to the payer throughout all of the phases of the authentication
including the generation, transmission and use of the authentication code.
For the purpose of subparagraph 1.2 and where PSPs apply strong customer authentication in
accordance with Article 97 paragraph 2 of the Law on Payment Services the following requirements for the authentication code shall apply:
3.1. in relation to a card-based payment transaction for which the payer has given consent to the
exact amount of the funds to be blocked pursuant to Article 75 paragraph 1 of the Law on Payment Services, the authentication code shall be specific to the amount that the payer has given consent to be blocked and agreed to by the payer when initiating the transaction;
3.2. in relation to payment transactions for which the payer has given consent to execute a batch
of remote electronic payment transactions to one or several payees, the authentication code shall be specific to the total amount of the batch of payment transactions and to the specified payees.
Article 7
Requirements of the elements categorized as knowledge
PSPs shall adopt measures to mitigate the risk that the elements of strong customer authentication
categorized as knowledge are uncovered by, or disclosed to, unauthorized parties.
The use by the payer of those elements shall be subject to mitigation measures in order to prevent
their disclosure to unauthorized parties.
Article 8
Requirements of the elements categorized as possession
PSPs shall adopt measures to mitigate the risk that the elements of strong customer authentication
categorized as possession are used by unauthorized parties.
The use by the payer of those elements shall be subject to measures designed to prevent replication
of the elements.
Article 9
Requirements of devices and software linked to elements categorized as inherence
PSPs shall adopt measures to mitigate the risk that the authentication elements categorized as
inherence and read by access devices and software provided to the payer are uncovered by unauthorized parties. At a minimum, the PSPs shall ensure that those access devices and software have a very low probability of an unauthorized party being authenticated as the payer.
The use by the payer of those elements shall be subject to measures ensuring that those devices
and the software guarantee resistance against unauthorized use of the elements through access to the devices and the software.
Article 10
Independence of the elements
3.2. the payment transactions executed in the last 90 days through one or more designated
payment accounts.
4. By way of derogation from paragraph 3, PSPs shall apply strong customer authentication where
one of the following conditions is met:
4.1. the PSU is accessing online the information specified in paragraph 3 of this article for the
first time through the AISP;
4.2. more than 180 days have elapsed since the last time the PSU accessed online the information
specified in paragraph 3 of this article through the AISP and strong customer authentication was applied.
5. By way of derogation from paragraph 3 of this article, PSPs shall be allowed to apply strong
customer authentication where a PSU is accessing its payment account online through an AISP and the PSP has objectively justified and duly evidenced reasons relating to unauthorized or fraudulent access to the payment account. In such a case, the PSP shall document and duly justify to the CBK, upon request, the reasons for applying strong customer authentication.
6. ASPSPs that offer a dedicated interface as referred to in Article 32 shall not be required to
implement the exemption laid down in paragraph 3 of this Article for the purpose of the contingency mechanism referred to in Article 34 paragraph 4, where they do not apply the exemption laid down in paragraphs 1 and 2 of this Article in the direct interface used for authentication and communication with their PSUs.
Article 12
Contactless payments at point of sale
Article 14
Trusted beneficiaries
only made available to payers who are not consumers, where the CBK is satisfied that those processes or protocols guarantee at least equivalent levels of security to those provided for by the Law on Payment Services.
Article 19
Transaction risk analysis
Article 20
Calculation of fraud rates
Article 22
Monitoring
Article 24
Creation and transmission of credentials
2.3.2. the delivered personalized security credentials, authentication devices or software
require activation before usage;
2.4. arrangements ensuring that, in cases where the personalized security credentials, the
authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in Article 25 of this regulation.
Article 27
Renewal of personalized security credentials
PSPs shall ensure that the renewal or re-activation of personalized security credentials adhere to the procedures for the creation, association and delivery of the credentials and of the authentication devices in accordance with Articles 24, 25 and 26 of this Regulation.
Article 28
Destruction, deactivation and revocation
Article 30
Traceability
PSPs shall have processes in place which ensure that all payment transactions and other
interactions with the PSU, with other PSPs and with other entities, including merchants, in the context of the provision of the payment service are traceable, ensuring knowledge ex post of all events relevant to the electronic transaction in all the various stages.
For the purpose of paragraph 1, PSPs shall ensure that any communication session established with
the PSU, other PSPs and other entities, including merchants, relies on each of the following:
2.1. a unique identifier of the session;
2.2. security mechanisms for the detailed logging of the transaction, including transaction number,
timestamps and all relevant transaction data;
2.3. timestamps which shall be based on a unified time-reference system and which shall be
synchronized according to an official time signal.
Subchapter II
Specific requirements for the common and secure open standards of communication
Article 31
General obligations for access interfaces
ASPSPs that offer to a payer a payment account that is accessible online shall have in place at least
one interface which meets each of the following requirements:
1.1. AISPs, PISPs and PSPs issuing card-based payment instruments are able to identify
themselves towards the ASPSP;
1.2. AISPs are able to communicate securely to request and receive information on one or more
designated payment accounts and associated payment transactions;
1.3. PISPs are able to communicate securely to initiate a payment order from the payer's payment
account and receive all information on the initiation of the payment transaction and all information accessible to the ASPSP regarding the execution of the payment transaction.
For the purposes of authentication of the PSU, the interface referred to in paragraph 1 of this article,
shall allow AISPs and PISPs to rely on all the authentication procedures provided by the ASPSP to the PSU.
The interface referred to in paragraph 1 of this article, shall at least meet all of the following
requirements:
3.1. a PISP or an AISP shall be able to instruct the ASPSP to start the authentication based on the
consent of the PSU;
3.2. communication sessions between the ASPSP, the AISP, the PISP and any PSU concerned
shall be established and maintained throughout the authentication;
3.3. the integrity and confidentiality of the personalized security credentials and of authentication
codes transmitted by or through the PISP or the AISP shall be ensured.
ASPSPs shall ensure that their interfaces follow standards of communication which are issued by
international standardization organizations.
4.1. ASPSPs shall also ensure that the technical specification of any of the interfaces is
documented specifying a set of routines, protocols, and tools needed by PISPs, AISPs and PSPs issuing card-based payment instruments for allowing their software and applications to interoperate with the systems of the ASPSP;
4.2. ASPSPs shall at a minimum, and no less than 6 months before the end of the transitional
period referred to in Article 40, or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 40, make the documentation available, at no charge, upon request by authorized PISPs, AISPs and PSPs issuing card-based payment instruments or PSPs that have applied to the CBK for the relevant authorization, and shall make a summary of the documentation publicly available on their website.
In addition to paragraph 4, ASPSPs shall ensure that, except for emergency situations, any change
to the technical specification of their interface is made available to authorized PISPs, AISPs and PSPs issuing card-based payment instruments, or PSPs that have applied to the CBK for the relevant authorization, in advance as soon as possible and not less than 3 months before the change is implemented.
5.1. PSPs shall document emergency situations where changes were implemented and make the
documentation available to the CBK on request.
By way of derogation from paragraph 5 of this article, ASPSPs shall make available to the PSPs
referred to in this Article the changes made to the technical specifications of their interfaces in order to comply with Article 11 paragraphs 3 to 6, not less than 2 months before such changes are implemented.
ASPSPs shall make available a testing facility, including support, for connection and functional
testing to enable authorized PISPs, PSPs issuing card-based payment instruments and AISPs, or PSPs that have applied for the relevant authorization, to test their software and applications used for offering a payment service to users. This testing facility should be made available no later than 6 months before the application date referred to in Article 40 or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 40.
7.1. however, no sensitive information shall be shared through the testing facility.
The CBK shall ensure that ASPSPs comply at all times with the obligations included in this
Regulation in relation to the interface(s) that they put in place. In the event that an ASPSP provider fails to comply with the requirements for interfaces laid down in this Regulation, the CBK shall ensure that the provision of PISs and AISs is not prevented or disrupted to the extent that the respective providers of such services comply with the conditions defined under Article 34 paragraph 5.
Article 32
Access interface options
ASPSPs shall establish the interface(s) referred to in Article 31 of this regulation by means of a dedicated interface or by allowing the use by the PSPs referred to in Article 31 paragraph 1 of this regulation of the interfaces used for authentication and communication with the ASPSP's PSUs.
Article 33
Obligations for a dedicated interface
Subject to compliance with Articles 31 and 32 of this regulation, ASPSPs that have put in place a
dedicated interface shall ensure that the dedicated interface offers at all times the same level of availability and performance, including support, as the interfaces made available to the PSU for directly accessing its payment account online.
ASPSPs that have put in place a dedicated interface shall define transparent key performance
indicators and service level targets, at least as stringent as those set for the interface used by their PSUs both in terms of availability and of data provided in accordance with Article 37. Those interfaces, indicators and targets shall be monitored by the CBK and stress-tested.
ASPSPs that have put in place a dedicated interface shall ensure that this interface does not create
obstacles to the provision of PISs and AISs. Such obstacles, may include, among others, preventing the use by PSPs referred to in Article 31 paragraph 1 of the credentials issued by ASPSPs to their customers, imposing redirection to the ASPSP's authentication or other functions, requiring additional authorizations and registrations in addition to those provided for in Articles 15 and 19 of the Law on Payment Services, or requiring additional checks of the consent given by PSUs to providers of PIS and AISs.
For the purpose of paragraphs 1 and 2 of this article, ASPSPs shall monitor the availability and
performance of the dedicated interface. ASPSPs shall publish on their website quarterly statistics on the availability and performance of the dedicated interface and of the interface used by its PSUs.
Article 34
Contingency measures for a dedicated interface
ASPSPs shall include, in the design of the dedicated interface, a strategy and plans for contingency
measures for the event that the interface does not perform in compliance with Article 33 of this regulation, that there is unplanned unavailability of the interface and that there is a systems breakdown. Unplanned unavailability or a systems breakdown may be presumed to have arisen when five consecutive requests for access to information for the provision of PISs or AISs are not replied to within 30 seconds.
Contingency measures shall include communication plans to inform PSPs making use of the
dedicated interface of measures to restore the system and a description of the immediately available alternative options PSPs may have during this time.
Both the ASPSP and the PSPs referred to in Article 31 paragraph 1 shall report problems with
dedicated interfaces as described in paragraph 1 of this article to the CBK without delay.
As part of a contingency mechanism, PSPs referred to in Article 31 paragraph 1 shall be allowed
to make use of the interfaces made available to the PSUs for the authentication and communication with their ASPSPs, until the dedicated interface is restored to the level of availability and performance provided for in Article 33 of this regulation.
For this purpose, ASPSPs shall ensure that the PSPs referred to in Article 31 paragraph 1 of this
regulation can be identified and can rely on the authentication procedures provided by the ASPSP to the PSU. Where the PSPs referred to in Article 31 paragraph 1 of this regulation make use of the interface referred to in paragraph 4 of this article they shall:
5.1. take the necessary measures to ensure that they do not access, store or process data for
purposes other than for the provision of the service as requested by the PSU;
5.2. continue to comply with the obligations following from Article 66 paragraph 3 and Article
67 paragraph 2 of the Law on Payment Services respectively;
5.3. log the data that are accessed through the interface operated by the ASPSP for its PSUs, and
provide, upon request and without undue delay, the log files to the CBK;
5.4. duly justify to the CBK, upon request and without undue delay, the use of the interface made
available to the PSUs for directly accessing its payment account online;
5.5. inform the ASPSP accordingly.
The CBK shall, after having given due consideration to guidance and guidelines from the EBA or
other European Union institutions as applicable to ensure a consistent application of the following conditions, exempt the ASPSPs that have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph 4 where the dedicated interface meets all of the following conditions:
6.1. it complies with all the obligations for dedicated interfaces as set out in Article 33 of this
regulation;
6.2. it has been designed and tested in accordance with Article 31 paragraph 7 of this regulation
to the satisfaction of the PSPs referred to therein;
6.3. it has been widely used for at least 3 months by PSPs to offer AISs, PISs and to provide
confirmation on the availability of funds for card-based payments;
6.4. any problem related to the dedicated interface has been resolved without undue delay.
The CBK shall revoke the exemption referred to in paragraph 6 of this article where the conditions
in subparagraphs 6.1 and 6.4 are not met by the ASPSPs for more than 2 consecutive calendar weeks. The CBK shall ensure that the ASPSP establishes, within the shortest possible time and at the latest within 2 months, the contingency mechanism referred to in paragraph 4 of this article.
Article 35
Certificates
For the purpose of identification, as referred to in Article 31 paragraph 1 subparagraph 1.1 of this
regulation, PSPs shall rely on qualified certificates for electronic seals and signatures or qualified certificates for authentication of websites, according to the provisions in the legislation on electronic identification and trusted services on electronic transactions (Law No. 08/L – 022).
For the purpose of this Regulation, unique identification number or registration number as referred
to in the official records in accordance with legislation on electronic identification and trusted services on electronic transactions (Law No. 08/L–022), shall be the authorization number of the PSP issuing card-based payment instruments, the AISPs and PISPs, including ASPSPs providing such services, available in the public register pursuant to Article 19 of the Law on Payment Services or resulting from the license or authorization framework and rules applicable to other applicable PSPs, such as banks.
For the purposes of this Regulation, qualified certificates for electronic seals or for website
authentication referred to in paragraph 1 shall include, in a language customary in the sphere of international finance, additional specific attributes in relation to each of the following:
3.1. the role of the PSP, which may be one or more of the following:
3.1.1. account servicing;
3.1.2. payment initiation;
3.1.3. account information;
3.1.4. issuing of card-based payment instruments;
3.2. Central Bank of Kosovo, where the PSP is registered.
The attributes referred to in paragraph 3 of this article shall not affect the interoperability and
recognition of qualified certificates for electronic seals or website authentication.
Article 36
Security of communication session
ASPSPs, PSPs issuing card-based payment instruments, AISPs and PISPs shall ensure that, when
exchanging data by means of the internet, secure encryption is applied between the communicating parties throughout the respective communication session in order to safeguard the confidentiality and the integrity of the data, using strong and widely recognized encryption techniques.
PSPs issuing card-based payment instruments, AISPs and PISPs shall keep the access sessions
offered by ASPSPs as short as possible and they shall actively terminate any such session as soon as the requested action has been completed.
When maintaining parallel network sessions with the ASPSP, AISPs and PISPs shall ensure that
those sessions are securely linked to relevant sessions established with the PSU(s) in order to prevent the possibility that any message or information communicated between them could be misrouted.
AISPs, PISPs and PSPs issuing card-based payment instruments with the ASPSP shall contain
unambiguous references to each of the following items:
4.1. the PSU or users and the corresponding communication session in order to distinguish several
requests from the same PSU or users;
4.2. for PISs, the uniquely identified payment transaction initiated;
4.3. for confirmation on the availability of funds, the uniquely identified request related to the
amount necessary for the execution of the card-based payment transaction.
ASPSPs, AISPs, PISPs and PSPs issuing card-based payment instruments shall ensure that where
they communicate personalized security credentials and authentication codes, these are not readable, directly or indirectly, by any staff at any time.
In case of loss of confidentiality of personalized security credentials under their sphere of
competence, those providers shall inform without undue delay the PSU associated with them and the issuer of the personalized security credentials.
Article 37
Data exchanges
ASPSPs shall comply with each of the following requirements:
1.1. they shall provide AISPs with the same information from designated payment accounts and
associated payment transactions made available to the PSU when directly requesting access to the account information, provided that this information does not include sensitive payment data;
1.2. they shall, immediately after receipt of the payment order, provide PISPs with the same
information on the initiation and execution of the payment transaction provided or made available to the PSU when the transaction is initiated directly by the latter;
1.3. they shall, upon request, immediately provide PSPs with a confirmation in a simple ‘yes’ or
‘no’ format, whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer.
In case of an unexpected event or error occurring during the process of identification,
authentication, or the exchange of the data elements, the ASPSP shall send a notification message to the PISP or the AISP and the PSP issuing card-based payment instruments which explains the reason for the unexpected event or error.
2.1. where the ASPSP offers a dedicated interface in accordance with Article 33 of this regulation,
the interface shall provide for notification messages concerning unexpected events or errors to be communicated by any PSP that detects the event or error to the other PSPs participating in the communication session.
AISPs shall have in place suitable and effective mechanisms that prevent access to information
other than from designated payment accounts and associated payment transactions, in accordance with the user's explicit consent.
PISPs shall provide ASPSPs with the same information as requested from the PSU when initiating
the payment transaction directly.
AISPs shall be able to access information from designated payment accounts and associated
payment transactions held by ASPSPs for the purposes of performing the AIS in either of the following circumstances:
5.1. whenever the PSU is actively requesting such information;
5.2. where the PSU does not actively request such information, no more than four times in a 24-
hour period, unless a higher frequency is agreed between the AISP and the ASPSP, with the PSU's consent.
Article 38
Annex
This regulation is comprised of Annex 1 Reference fraud rate.
CHAPTER VI
FINAL PROVISIONS
Article 39
Enforcement, Improvement Measures and Penalties Any violation of the provisions of this Regulation shall be subject to corrective measures and/or administrative and civil penalties as defined within article 67 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo, as amended and supplemented by Law No. 05/L –150 and article 125 of the Law No.10/L-026 on Payment Services.
Article 40
Transitional Period
PSPs subject to this Regulation shall adapt their activities and operations to the provisions of this Regulation no later than the maximum period of 18 months, which corresponds to the transitional period set out in Article 138 of Law No.10/L-026 on Payment Services.
Article 41
Entry into force
This Regulation shall enter into force 15 days from the date of its approval. Dr.sc. Bashkim Nurboja Chairperson of the Board of Central Bank of the Republic of Kosovo
ANNEX 1
Reference fraud rate (%) for:
ETV Remote electronic card-based payments Remote electronic credit transfers EUR 500 0,01 0,005 EUR 250 0,06 0,01 EUR 100 0,13 0,015
Read the rest free
Source: Central Bank of the Republic of Kosovo — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works