Solidgate logo in black and white.

What is PSD2?

Payment Services Directive 2 (PSD2) is the European Union directive that governs electronic payments and account-access services across the European Economic Area (EEA). It replaced the original Payment Services Directive to raise security standards, open the payments market to non-bank providers, and strengthen consumer protection. The first directive dated from 2007, before app-based banking and most fintech business models existed, so PSD2 rewrote the rules for a market where non-bank providers now sit between customers and their banks.
Adopted as Directive (EU) 2015/2366 and applied from 2018, PSD2 reshaped how banks, , and fintechs handle customer money and data. Two changes define it: mandatory for most electronic payments, and rules that let licensed third parties reach bank accounts, which became the legal basis for . For merchants, PSD2 is why European customers now confirm card payments through a banking app or one-time code, and why licensed fintechs can offer account-based payments without holding a full banking license.

Key facts

  • Also known as: the revised Payment Services Directive, Directive (EU) 2015/2366
  • Applies in: the European Economic Area (EU member states plus Iceland, Liechtenstein, and Norway)
  • In force since: 2018, with SCA enforcement phased in from 2019
  • Core pillars: Strong Customer Authentication and third-party account access (open banking)
  • Regulated by: national competent authorities in each member state

Key requirements

PSD2 sets obligations that fall mainly on banks and payment providers, though the effects reach every merchant selling into the region:
  • Strong Customer Authentication. (PSD2 Article 97) requires at least two independent factors, drawn from something the customer knows, has, or is, for most electronic and remote card payments. is how card payments meet this in practice.
  • Authentication exemptions. Low-value payments and the let providers skip an SCA challenge when fraud rates stay low, so genuine customers face fewer interruptions at checkout.
  • Access to accounts. Banks must give licensed third-party providers a secure channel, typically an API, to reach customer account data and initiate payments once the customer consents.
  • Consumer protection. The directive tightens refund rights, caps a customer's liability for unauthorized transactions, and bans surcharges on most consumer card payments, so a customer disputing a fraudulent charge carries far less of the loss.

Who it applies to

PSD2 binds any provider that touches electronic payments in the EEA:
  • Banks and that hold customer accounts
  • and payment processors that move funds for merchants
  • Account information service providers (AISPs) and payment initiation service providers (PISPs) built on open banking
  • Merchants selling to EEA customers, who inherit SCA at checkout even when the compliance obligation sits with their provider
Firms handling account access must also meet licensing, safeguarding, and obligations before a national regulator lets them operate. Card schemes and gateways sit outside these licensing rules, but they still build SCA and open-banking support into their products so their customers stay compliant.

Penalties for non-compliance

PSD2 doesn't set a single EU-wide fine. Each member state's national regulator defines and enforces penalties, so the consequences vary by country. In practice, non-compliance leads to:
  • Financial penalties imposed by the national competent authority
  • Loss or suspension of the payment-institution license needed to operate
  • Higher fraud losses and more declined transactions when SCA isn't implemented correctly
  • Lost merchant relationships when a provider can't support a compliant checkout flow
Because SCA acceptance runs through the , skipping it triggers declined payments on top of any regulatory action, which pushes providers toward compliant setups regardless of how strictly a given country enforces the rules.

Related terms