- Key Takeaways
- What Problem Does PSD2 Solve That PSD1 Did Not?
- What Are the Two Core Focus Areas of PSD2?
- What Digital Certificates Does Psd2 Require?
- What is Strong Customer Authentication (SCA)?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Meet PSD2's Certificate and Authentication Requirements
The Payment Services Directive 2 (PSD2) is a European Union regulation that requires Strong Customer Authentication for electronic payments, mandates open banking through secure APIs, and requires digital certificates to identify banks and third-party payment providers.
PSD2 is an EU regulation, effective January 2018, that protects electronic payments through Strong Customer Authentication and opens banking data to licensed third-party providers via secure APIs. It requires Qualified Website Authentication Certificates and Qualified Certificates for Electronic Seals to identify and encrypt communication between banks and providers.
Key Takeaways
- PSD2 replaced PSD1 (2007) to address gaps left by the rapid growth of digital payments and third-party payment providers.
- Strong Customer Authentication (SCA) requires two of three factors: knowledge, possession, and inherence, for most electronic payments.
- Payment Initiation Services (PIS) and Account Information Services (AIS) let licensed third parties initiate payments and aggregate account data with the customer’s consent.
- PSD2 requires Qualified Website Authentication Certificates (QWAC) and Qualified Certificates for Electronic Seals (QSealC) to identify and encrypt communication between banks and Third-Party Providers.
- Recurring payments under 30 euros and select low-risk transactions can be exempted from full SCA under the Regulatory Technical Standards.
What Problem Does PSD2 Solve That PSD1 Did Not?
PSD1, introduced in 2007, standardized payment processing across the EU but did not anticipate the rise of digital payment methods and third-party providers. PSD2, approved in 2015 and adopted by January 13, 2018, closes that gap with stronger authentication requirements and a legal framework for open banking.
What Are the Two Core Focus Areas of PSD2?
PSD2 reduces the traditional banking monopoly through two new regulated services, while simultaneously tightening security around customer data.
- Payment Initiation Service (PIS): lets a licensed Payment Initiation Service Provider initiate a payment directly from a customer’s bank account, bypassing card networks.
- Account Information Service (AIS): lets a licensed Account Information Service Provider aggregate a customer’s account data across multiple banks into one view.
What Digital Certificates Does Psd2 Require?
| Certificate type | Purpose |
|---|---|
| Qualified Website Authentication Certificate (QWAC) | Identifies banks and TPPs and secures peer-to-peer API communication using TLS |
| Qualified Certificate for Electronic Seal (QSealC) | Seals data or documents to prove origin from a legal entity, using ETSI standards such as PAdES, CAdES, or XAdES |
A Payment Service Provider obtains these certificates by registering with its National Competent Authority, then requesting a qualified certificate from a Qualified Trust Service Provider, which validates the PSP against the public register before issuing the QWAC or QSealC.
What is Strong Customer Authentication (SCA)?
SCA requires online payment providers to verify a customer’s identity using at least two of three independent factors: something the customer knows, such as a password; something the customer has, such as a phone generating a one-time code; and something the customer is, such as a fingerprint. Dynamic linking ties each authentication token to a specific transaction amount and payee, so a token cannot be reused for a different payment.
How Encryption Consulting Helps
Encryption Consulting’s PKI-as-a-Service and Compliance Advisory Services help payment service providers obtain, deploy, and rotate QWAC and QSealC certificates, and design Strong Customer Authentication flows that satisfy PSD2’s Regulatory Technical Standards. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is the difference between QWAC and QSealC certificates?
A QWAC authenticates the endpoints of a communication channel, such as a bank and a Third-Party Provider, and secures the data in transit using TLS. A QSealC seals a specific document or data block to prove it originated from a legal entity, protecting data at rest and in transit even through an intermediary.
What transactions are exempt from Strong Customer Authentication?
PSD2’s Regulatory Technical Standards exempt recurring payments and transactions under 30 euros, along with higher-value transactions a bank can show fall below a defined fraud-rate threshold, for example up to 100 euros where fraud rates stay below 0.13 percent.
Who needs to comply with PSD2?
Banks, fintech and neobank providers, and any third-party or foreign payment service provider offering services to EU customers must comply with PSD2, regardless of whether the provider itself is based in the EU.
How does PSD2 relate to eIDAS?
PSD2’s Regulatory Technical Standards require QWAC and QSealC certificates, both of which are Qualified certificate types defined under the eIDAS Regulation. A Qualified Trust Service Provider recognized under eIDAS is the entity that issues these certificates to payment service providers.
Meet PSD2’s Certificate and Authentication Requirements
Encryption Consulting helps payment service providers obtain QWAC and QSealC certificates and build Strong Customer Authentication into their payment flows. Explore PKI-as-a-Service to see how it supports PSD2 compliance.
- Key Takeaways
- What Problem Does PSD2 Solve That PSD1 Did Not?
- What Are the Two Core Focus Areas of PSD2?
- What Digital Certificates Does Psd2 Require?
- What is Strong Customer Authentication (SCA)?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Meet PSD2's Certificate and Authentication Requirements
