Glossary
PSD2 (the second Payment Services Directive) is European Union regulation governing payment services that mandates strong customer authentication (SCA) for electronic payments and account access, and requires banks to enable open banking by giving licensed third parties API access to customer accounts (with consent). It reshaped payments and identity in Europe and set a template other regions have followed.
PSD2 pursues two big goals: making electronic payments more secure (via SCA) and fostering competition and innovation (via open banking). Both have had major, lasting effects on how banks handle authentication and data access.
PSD2’s most identity-relevant requirement is SCA: for electronic payments and account access, customers must authenticate with at least two independent factors from different categories (knowledge, possession, inherence), with additional "dynamic linking" for payments (tying the authentication to the specific amount and payee). SCA dramatically raised the authentication bar for European financial services, and pushed the industry toward stronger, and increasingly passwordless, authentication.
PSD2/SCA includes exemptions to avoid friction on low-risk transactions: small amounts, recurring payments, trusted beneficiaries, and transactions a provider’s risk analysis deems low-risk (transaction risk analysis). These exemptions are where compliance meets conversion: a bank with strong fraud detection can safely apply more exemptions, reducing checkout friction while staying compliant. This is a concrete example of how a good fraud engine turns a regulatory requirement into a competitive advantage.
PSD2 also compelled banks to open access to customer accounts for licensed third-party providers via APIs (with customer consent), catalyzing open banking in Europe. This required banks to build secure, consent-driven API access: driving adoption of security standards like FAPI and putting identity, authentication, and consent at the center of compliance.
PSD2 significantly reduced certain payment fraud through SCA and sparked a wave of open-banking innovation. It also became a reference point globally, influencing payment-security and open-banking regulation elsewhere, and its successor discussions (PSD3 and related payment-services reforms) continue to evolve the framework. For any business serving European customers with payments or financial services, PSD2 compliance (SCA plus open-banking obligations) is mandatory, and its principles increasingly matter beyond Europe.
What is PSD2?
The EU’s second Payment Services Directive, mandating strong customer authentication for electronic payments and open banking API access.
What does PSD2 require for authentication?
Strong customer authentication (SCA), at least two independent factors, plus dynamic linking tying payment authentication to the amount and payee.
What are SCA exemptions under PSD2?
Allowances to skip SCA for low-risk cases (small amounts, recurring payments, trusted payees, and transaction risk analysis).
How did PSD2 enable open banking?
It required banks to provide consented API access to licensed third parties, catalyzing open banking in Europe.
Does PSD2 apply outside the EU?
It’s EU regulation, but it influenced payment-security and open-banking rules globally, so its principles matter well beyond Europe.
What is PSD3?
The proposed successor framework continuing to evolve EU payment-services regulation, building on PSD2’s SCA and open-banking foundations.
How does PSD2 reduce fraud without hurting checkout?
Strong fraud detection lets banks safely apply SCA exemptions (like transaction risk analysis), waving low-risk payments through while staying compliant.
Who must comply with PSD2?
Payment service providers and banks operating in the EU, plus the licensed third-party providers that access accounts under open banking.
Related: Strong Customer Authentication (SCA) · Open Banking · FAPI 2.0 · Risk-Based Authentication · Multi-Factor Authentication (MFA)