Insights on Crypto Payments, Infrastructure, and Operations

Payment Services Directive (PSD2)

Abbreviation: PSD2

Pronunciation: PAY-munt SUR-vuh-siz dih-REK-tiv (PEE-ESS-DEE TWO)

Also known as: Payment Services Directive, Payment Services Directive Two (PSD2), Payment Services Directive Two, Payment Services Directive 2 (PSD2), Revised Payment Services Directive, Directive EU 2015/2366, PSD2

Definition

PSD2 is Directive (EU) 2015/2366, the European Union framework governing payment services, payment institutions, user rights, security, strong customer authentication, and access to payment accounts. It remains the applicable directive until successor legislation is formally adopted and becomes applicable. As of June 2026, the proposed PSD3 and directly applicable Payment Services Regulation had reached provisional political agreement and were close to adoption, so implementations should track transition rules without presenting the proposals as already effective law.

Overview

PSD2 is Directive (EU) 2015/2366, the European Union framework governing payment services, payment institutions, user rights, security, strong customer authentication, and access to payment accounts. It remains the applicable directive until successor legislation is formally adopted and becomes applicable. As of June 2026, the proposed PSD3 and directly applicable Payment Services Regulation had reached provisional political agreement and were close to adoption, so implementations should track transition rules without presenting the proposals as already effective law.

PSD2 remains the legal baseline for payment services in the EU while Member States apply their national transpositions and the related regulatory technical standards. The exact obligations depend on the service, actor, customer, authentication flow, account access, exemption, and competent authority.

The proposed PSD3 and Payment Services Regulation reached provisional agreement on 27 November 2025, and the European Parliament’s ECON committee approved the negotiated texts on 5 May 2026. As of June 2026, the package was close to adoption but not yet a replacement law in force. Product documentation should distinguish existing PSD2 duties from planned transition changes.

Its boundary becomes clearer when compared with Payment Service Provider (PSP) and Payment Institution.

The principal failure modes are relying on summaries instead of binding law, applying the wrong jurisdiction, misclassifying a service, missing an exemption condition, outdated authentication rules, weak consent evidence, incomplete incident reporting, and assuming one implementation satisfies every market.

Risk reduction depends on controls that map duties to named owners, retain consent and decision evidence, review changes in law and guidance, and test incident and complaint handling, with the control owner and exception path documented whenever Payment Institution is involved.

Payment Services Directive (PSD2) is an EU legal framework for payment services; it is not a provider role, authentication method, or compliance certificate.

Key Takeaway

PSD2 remains the current EU payment-services directive while PSD3 and the Payment Services Regulation approach adoption; implementations must distinguish effective obligations from proposed transition changes.

Sources

  1. Directive (EU) 2015/2366 on Payment Services — European Union (2026-08-01)
  2. European Parliament Legislative Train: PSD3 Status — European Parliament (2026-08-01)
  3. European Parliament Legislative Train: Payment Services Regulation — European Parliament (2026-08-01)
  4. Directive (EU) 2015/2366 on Payment Services in the Internal Market — European Union (2026-08-03)
  5. Commission Delegated Regulation (EU) 2018/389 on Strong Customer Authentication — European Union (2026-08-03)
  6. Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector — European Union (2026-08-03)