What is PSD2? | Transmit Security

Glossary

What is PSD2?

PSD2 is the EU’s Payment Services Directive 2, mandating strong customer authentication and open banking. Learn what PSD2 requires and its impact.
by Transmit Security

PSD2 (the second Payment Services Directive) is European Union regulation governing payment services that mandates strong customer authentication (SCA) for electronic payments and account access, and requires banks to enable open banking by giving licensed third parties API access to customer accounts (with consent). It reshaped payments and identity in Europe and set a template other regions have followed.

PSD2 pursues two big goals: making electronic payments more secure (via SCA) and fostering competition and innovation (via open banking). Both have had major, lasting effects on how banks handle authentication and data access.

Strong customer authentication under PSD2

PSD2’s most identity-relevant requirement is SCA: for electronic payments and account access, customers must authenticate with at least two independent factors from different categories (knowledge, possession, inherence), with additional "dynamic linking" for payments (tying the authentication to the specific amount and payee). SCA dramatically raised the authentication bar for European financial services, and pushed the industry toward stronger, and increasingly passwordless, authentication.

Exemptions and the friction balance

PSD2/SCA includes exemptions to avoid friction on low-risk transactions: small amounts, recurring payments, trusted beneficiaries, and transactions a provider’s risk analysis deems low-risk (transaction risk analysis). These exemptions are where compliance meets conversion: a bank with strong fraud detection can safely apply more exemptions, reducing checkout friction while staying compliant. This is a concrete example of how a good fraud engine turns a regulatory requirement into a competitive advantage.

The open banking mandate

PSD2 also compelled banks to open access to customer accounts for licensed third-party providers via APIs (with customer consent), catalyzing open banking in Europe. This required banks to build secure, consent-driven API access: driving adoption of security standards like FAPI and putting identity, authentication, and consent at the center of compliance.

PSD2’s impact and legacy

PSD2 significantly reduced certain payment fraud through SCA and sparked a wave of open-banking innovation. It also became a reference point globally, influencing payment-security and open-banking regulation elsewhere, and its successor discussions (PSD3 and related payment-services reforms) continue to evolve the framework. For any business serving European customers with payments or financial services, PSD2 compliance (SCA plus open-banking obligations) is mandatory, and its principles increasingly matter beyond Europe.

Frequently asked questions

What is PSD2?

The EU’s second Payment Services Directive, mandating strong customer authentication for electronic payments and open banking API access.

What does PSD2 require for authentication?

Strong customer authentication (SCA), at least two independent factors, plus dynamic linking tying payment authentication to the amount and payee.

What are SCA exemptions under PSD2?

Allowances to skip SCA for low-risk cases (small amounts, recurring payments, trusted payees, and transaction risk analysis).

How did PSD2 enable open banking?

It required banks to provide consented API access to licensed third parties, catalyzing open banking in Europe.

Does PSD2 apply outside the EU?

It’s EU regulation, but it influenced payment-security and open-banking rules globally, so its principles matter well beyond Europe.

What is PSD3?

The proposed successor framework continuing to evolve EU payment-services regulation, building on PSD2’s SCA and open-banking foundations.

How does PSD2 reduce fraud without hurting checkout?

Strong fraud detection lets banks safely apply SCA exemptions (like transaction risk analysis), waving low-risk payments through while staying compliant.

Who must comply with PSD2?

Payment service providers and banks operating in the EU, plus the licensed third-party providers that access accounts under open banking.

Related: Strong Customer Authentication (SCA) · Open Banking · FAPI 2.0 · Risk-Based Authentication · Multi-Factor Authentication (MFA)

Request a Demo

By clicking the button, you agree to the Terms and Conditions