Croatian Tax Administration's version 2.7, effective July 6, 2026, mandates stronger security for B2C fiscalisation, transitioning to RSA-SHA256 and newer TLS by January 1, 2027.
Croatia Updates Technical Requirements for B2C Fiscalisation
The Croatian Tax Administration published version 2.7 of the Technical Specification for Fiscalisation of Final Consumption Invoices on July 6, 2026.
The update introduces stronger security requirements for Croatia’s B2C fiscalisation system.
Since July 1, 2026, the following changes have applied in the test environment:
- XML messages can no longer be signed using the RSA-SHA1 method, and
- the system no longer supports TLS 1.1
The same changes will apply in the production environment from January 1, 2027.
Until December 31, 2026, businesses may continue signing XML request messages in production using either:
- RSA-SHA1, or
- RSA-SHA256.
From January 1, 2027, businesses and software providers will need to use RSA-SHA256 and a newer supported TLS version when connecting to the production fiscalisation system.
Businesses should review their POS, invoicing and fiscalisation solutions and complete the necessary technical updates before the end of 2026. The change is intended to improve system security and replace older technical standards. A recent industry update also confirms the transition from SHA-1 to the more secure SHA-256 method.
Questions and comments (2)
test
test test