AcademyApproachFAQContact Request an assessment
AREN

Visa is back in Syria: is your company ready to take electronic payments securely?

16 September 2026

It is happening now, in stages. Security and data protection sit in the official framework — not as a later add-on. The service does not yet cover every region.

Visa and Mastercard are not only “back” in theory

On 14 September 2026 — two days before this article — the Central Bank of Syria, with QNB Syria and Mastercard, launched the first locally issued, internationally accepted electronic payment card. That is not a statement of intent. It is a product on the same timeline that began with a May decision and an August live test.

This is a direct follow-up to what we wrote when the website opened and the service still did not work: the page loads, then the process stops at the company’s policy or at a legal constraint that had not yet been lifted. The stage has changed. Visa and Mastercard have started operating in Syria in stages. The question has moved from “does the service exist at all?” to “is the company ready to take an electronic payment securely when it arrives?”

How we got here — by date

The sequence is public, and close together:

  • 4 May 2026: the Central Bank of Syria issued a decision allowing licensed banks and electronic-payment companies to deal with global payment networks such as Visa and Mastercard.
  • 5 May 2026: QNB Syria announced the launch of international card-acceptance services — the first bank in the Syrian market to support that.
  • 7 May 2026: Mastercard announced it had completed its technical readiness to process international bank-card transactions inside Syria — for the first time in more than 15 years, after a memorandum of understanding with the central bank signed on 23 September 2025.
  • 24 August 2026: the US Treasury formally removed Syria from the list of “state sponsors of terrorism” — lifting the last major legal obstacle that had stopped international banks and financial institutions from transferring funds and dealing with the Syrian interior.
  • Around 27 August 2026 — days after the delisting: Visa and Mastercard executed the first actual international card transactions inside Syria. QNB completed the first end-to-end international payment via Mastercard. Visa ran a separate test of a live international transaction with Lebanon’s Fransabank and the Syrian e-payment firm Bemira — the test included a real Visa purchase at a restaurant in Damascus.
  • 14 September 2026: the first locally issued, internationally accepted electronic payment card, with an accompanying regulatory framework that names licensing, compliance, settlement, cybersecurity and data protection, and allows dealing with other qualifying global and regional payment networks that meet the conditions.

This is not a theoretical future possibility. It is happening now, in stages, and gradually by geography. The accompanying regulatory frameworks put cybersecurity and data protection inside the official compliance requirements from the start, not as an optional later add-on.

Still incomplete — and that matters

The governor of the central bank stated explicitly, alongside the August transactions, that the service is still in its early stages and has not yet covered all Syrian regions. That is not a side note. It means a company should not assume Visa “is back” in the sense that it will be on the counter tomorrow in every city. Check the specific position — the bank, the payment firm, the region — before building a sales plan or wiring a payment page.

The geographic rollout itself is a reason to prepare, not to wait: whoever receives acceptance later pays the cost of a rushed connection if they wait until day one.

Security is part of the official framework — not a later idea

The new Syrian regulatory framework for accepting international payments, announced with the 14 September card, names cybersecurity and data protection explicitly as compliance requirements — alongside licensing and settlement. Any Syrian company that wants to take an international electronic payment in future needs to take that side seriously from the start. It is not “we harden security after the card works”. It is a condition stated in the regulatory text itself.

What security readiness means in practice

The following are known principles in the payments industry. They are not statistics, and they are not a claim that your company has been breached:

  • Do not store raw card data in your own systems. Use an approved payment gateway that passes the number and does not leave it with you.
  • Secure the connection between your site or point-of-sale system and the payment gateway: the update, the password, and who can reach the integration keys.
  • Watch for suspicious transactions — repeated failures, amounts outside the shop’s pattern — rather than waiting for a customer complaint.
  • If you will handle card data directly, compliance with the industry standard (PCI DSS) is not a marketing slogan. It is the accepted floor for whoever holds the number themselves.

We do not claim Visa or Mastercard is available across all of Syria today. The governor himself ruled out completeness. The message is narrower: this is the better time to prepare the security, before the service is available in your area in full — not after, when the connection has already been made in a hurry.

Abdulrahman

Abdulrahman

Founder & General Manager

Related

Contact

Is the connection ready before the service reaches your area?

We do not claim Visa and Mastercard are available across all of Syria today. Describe how you take payment, or how you plan to. We help prepare the security before geographic coverage is complete — not after.

Request an assessment
Hours
Sunday — Thursday · 9:00 — 17:00