Home
>
Merchant Communications
>
Strong Customer Authentication in Bosnia and Herzegovina

Strong Customer Authentication in Bosnia and Herzegovina

Sep 10, 2026

Effective April 2027, Visa is revising its response codes to reflect the upcoming adoption of similar requirements to the Payment Service Directive 2 (PSD2) Strong Customer Authentication (SCA) regulatory requirements in Bosnia and Herzegovina.

The enforcement date for these requirements has not been confirmed by the regulator. Once this is published, Visa plans to align its rules with the enforcement date. 

If you’re based in the EEA or UK and process transactions for customers in Bosnia and Herzegovina, transactions between non-EEA countries and acquirers in the EEA or UK will be considered one-leg-out. The PSD SCA requirement is that SCA should be performed on a ‘best effort’ basis, where technically feasible. 

For more information, see our Strong Customer Authentication guide. It includes all the information you’ll need to follow SCA requirements, understand what transactions are out of scope, the exemptions you can use, and impacts on different business scenarios.

Should there be any variance between Bosnia and Herzegovina’s requirements and those implemented in the EEA and UK, we’ll let you know in a following announcement.

Return to Home

Unlock your payments potential today

Contact us