PSD2 Regulatory Technical Standards (RTS) take effect in September 2019, reshaping the European payments landscape by introducing new regulated roles. Payment Initiation Service Providers (PISPs) can initiate payments directly between consumers and merchants, while Account Information Service Providers (AISPs) can aggregate account information for consumers and businesses. Together, AISPs and PISPs are Third-Party Providers (TPPs), competing with banks, which are defined as Account Servicing Payment Service Providers (ASPSPs). As these historically bank-centered functions move into a more open ecosystem, competition is expected to expand significantly, including participation from non-banking firms.
Technically, PSD2 drives changes in two primary areas: Strong Customer Authentication (SCA) and secure, standardized financial APIs. SCA requires “strong authentication” using two of three factors—something you know, have, or are—alongside transactional risk analysis and malware mitigation to protect sessions and transactions. In parallel, banks must open access to account data and payment initiation through APIs, requiring defense-in-depth security across data, network, and API layers, plus a trust framework and robust identity and access management for regulated external providers.
The market opportunity is broad: FinTechs are preparing to enter SCA and account services, while cybersecurity, identity/IAM, and mobile vendors position offerings across API security, anti-malware, threat detection and response, anti-DDoS, CIAM/IDaaS, MFA, biometrics, and secure SDKs. However, risks increase with new attack surfaces: insecure APIs can amplify fraud; poor SCA can harm user experience and drive excessive PII collection; weak risk models can raise false positives and reduce revenue; and aggregator/payment apps become prime targets for account takeover, phishing, credential stuffing, MITM, bots, and mobile malware. Mitigations emphasize hardened infrastructure, secured API gateways, authenticated/authorized calls, ML-assisted detection, anti-DDoS, standards-based authentication (e.g., FIDO), granular risk engines, secure mobile development, and fraud intelligence platforms.
See All Locations
See All Locations