PSD2 will radically alter the EU financial services landscape by mandating stronger security controls while opening bank capabilities to new competitors through standardized, secure APIs. It introduces Third-Party Providers (TPPs)—notably Account Information Service Providers (AISPs) that aggregate account data and Payment Initiation Service Providers (PISPs) that can initiate payments directly between consumers and merchants—functions historically performed by banks. This expands consumer choice and competition, including from non-banking businesses, while increasing operational cost and risk for banks, which still bear capital reserve obligations that AISPs and PISPs do not.
Technically, PSD2 concentrates on two areas: Strong Customer Authentication (SCA) and Secure Communications. SCA follows the two-of-three factor model (something you know/have/are) and is driven by the well-known weaknesses of passwords. The text emphasizes a shift toward more usable, higher-assurance methods—especially mobile-based authenticators and smartphone biometrics—while predicting low consumer acceptance for SmartCards and USB tokens. PSD2’s Regulatory Technical Standards (RTS) also allow limited exceptions to SCA (e.g., transactions under €30, unattended kiosks, or where adequate transactional risk analysis is performed). Risk-adaptive authentication and transactional risk analysis can reduce the need for SCA on every transaction by evaluating user, device, and environmental signals and triggering step-up actions or denials when risk exceeds policy thresholds.
For Secure Communications, banks must expose APIs enabling AISPs and PISPs to retrieve account information and initiate payments, requiring new “TPP-facing” layers protected with defense-in-depth controls such as API gateways/WAFs, certificate-based trust, session authentication, authorization, and monitoring. PSD2 also explicitly requires attention to malware indicators during authentication and transaction sessions, motivating endpoint and server-side detection approaches plus integrated governance, risk, and compliance processes.
See All Locations
See All Locations