Financial services
Revised Payment Services Directive
Published Reviewed
What is PSD2?
PSD2 governs EU payment services through authorisation, customer-protection, account-access and strong-authentication rules while the proposed PSD3 and PSR reforms advance.
| Jurisdiction | European Union |
|---|---|
| Authority | Directive (EU) 2015/2366 |
| Current status | Applicable through national law since 13 January 2018 |
| Reviewed |
Why it matters operationally
PSD2 is the regime under which every EU payment institution, e-money firm and account-servicing bank operates: authorisation, strong customer authentication, open-banking access and fraud reporting all flow from it. It is also a regime with a named successor — the PSD3/PSR package proposed in June 2023 will replace it, and firms authorised under PSD2 should expect a re-authorisation exercise during the transition. Operating well under PSD2 while tracking its successor is the practical mandate.
Are you aware?
The dates that bind
Strong customer authentication is settled law
Two independent factors from knowledge, possession and inherence — with every exemption you rely on (low-value, transaction-risk analysis, trusted beneficiaries) tied to conditions and fraud-rate thresholds you must keep meeting.
PSD3 and the Payment Services Regulation follow
The June 2023 Commission proposals move much of the rulebook into a directly applicable regulation, tighten fraud liability, and will require existing payment institutions to transition. Firms that track the file early set the terms of their own migration.
Fraud reporting is a standing clock
Payment service providers report fraud data to their authorities on fixed cycles under the EBA guidelines — a recurring evidence obligation, not a one-off filing.
Where to start
- 1
Confirm your regulated role for each service — payment institution, e-money institution, AISP, PISP or agent — and the national permissions behind it.
- 2
Inventory the SCA exemptions you rely on and the conditions attached to each, including reference fraud rates for transaction-risk analysis.
- 3
Track the PSD3/PSR file formally: assign an owner for the transition analysis so re-authorisation does not arrive as a surprise.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Does PSD2 only apply to banks?
No — it created regulated roles for non-banks: payment institutions, account-information providers (AISPs) and payment-initiation providers (PISPs). If you touch payment accounts or initiate payments, you likely hold or need one of these authorisations.
What counts as strong customer authentication?
Authentication using at least two independent elements from knowledge (something you know), possession (something you have) and inherence (something you are), with dynamic linking for remote payments (Article 97 and the SCA RTS).
What changes with PSD3?
The proposals merge the e-money regime into payments law, convert most conduct rules into a directly applicable regulation (PSR), strengthen fraud-liability and IBAN-check requirements, and require existing firms to be re-authorised on a transition timetable set in the final texts.
Key terms in this guide
A quick self-check
Are you ready?
- Could you list, today, every SCA exemption you rely on and evidence that its conditions still hold?
- Do you know your current fraud rates per exemption threshold — and who reports them?
- Is anyone in your organisation formally tracking the PSD3/PSR negotiation and its transition clauses?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.