PSD3 Explained: Key Changes, Compliance Requirements, and How to Prepare

PSD3 Explained - Key Changes, Compliance Requirements, and How to Prepare with Secfense

What is PSD3?

PSD3 (Payment Services Directive 3) is the third iteration of the European Union directive regulating the payments services market. The main objective of PSD3 is to enhance the security of payment transactions, improve consumer protection, and align regulatory frameworks with evolving payment technologies and new business models.

Like its predecessor, PSD2, PSD3 focuses on increasing the security of online transactions, regulating the electronic payments market, and setting standards to protect consumers from financial fraud. However, PSD3 introduces more detailed requirements for Strong Customer Authentication (SCA) and imposes stricter liability on payment service providers for unauthorized transactions.

How is PSD3 different from PSD2?

PSD2 (Payment Services Directive 2) introduced significant changes, such as Strong Customer Authentication and Open Banking. PSD3 builds upon these foundations by tightening existing rules and introducing new ones that focus on security, service provider liability, and data protection in payment transactions.

Key differences between PSD3 and PSD2 include:

  • Stricter rules for Strong Customer Authentication (SCA): PSD3 may introduce more rigorous guidelines for when and how SCA must be applied, particularly in contactless payments.
  • More precise regulations on unauthorized transactions: PSD3 will define more clearly who is responsible for fraudulent transactions, especially in cases of phishing attacks.
  • Enhanced fraud monitoring requirements: PSD3 will set new rules for processing transaction data to detect and prevent fraud, requiring financial institutions to implement more advanced transaction monitoring systems.

Who does PSD3 apply to?

PSD3 will affect a broad range of entities within the financial services sector, including:

  • Financial institutions: Banks, payment service providers (PSPs), and credit institutions.
  • Fintech companies: Any company involved in payments services, such as new payment technology providers and transaction platforms.
  • Payment Service Providers (PSPs): Any entity that facilitates payment transactions, including digital wallet providers, online payment platforms, and card processing companies.

Who needs to implement PSD3?

All entities that provide payment services in the European Union will be required to comply with PSD3. This means that both banks and fintech companies as well as payment service providers will need to adapt their systems to meet the new requirements.

These companies will need to ensure that their systems adhere to the PSD3 regulations on Strong Customer Authentication (SCA), fraud prevention, and liability for unauthorized transactions.

Who is responsible for implementing PSD3?

Responsibility for implementing PSD3 falls on several key stakeholders within an organization:

  • Executive management in financial institutions: Responsible for ensuring their firms comply with the new regulations.
  • IT and security teams: Charged with implementing the technological solutions that ensure compliance with PSD3, particularly in terms of security and authentication.
  • Payment technology providers: Must update their solutions to meet PSD3 requirements related to consumer protection and transaction security.

What is the timeline for PSD3 implementation?

PSD3 is currently under development, and the final version of the regulation and its implementation timeline are still subject to change. However, as of now:

  • Legislative work on PSD3 is expected to be completed in 2024.
  • Full implementation by EU member states and financial institutions is expected over the following years, with specific deadlines for various compliance requirements.

Financial institutions should start preparing for these changes now by reviewing their systems and processes in light of PSD3 compliance.

How can Secfense help with PSD3 compliance?

Secfense provides solutions that can greatly simplify the implementation of PSD3 requirements, particularly in areas related to Strong Customer Authentication (SCA).

Here’s how Secfense can assist:

  1. User Access Security Broker: Secfense offers a technology that enables the rapid deployment of Strong Customer Authentication (MFA, passwordless authentication) to existing applications without requiring any changes to the application code. This is an ideal solution for businesses needing to comply with PSD3’s SCA requirements.
  2. Protection against phishing and fraud: Secfense helps organizations protect their customers from unauthorized transactions resulting from phishing attacks. With advanced authentication technologies, the risk of fraud can be significantly reduced.
  3. Regulatory compliance: Secfense supports financial institutions in meeting PSD3 compliance requirements. Our solutions ensure secure transaction processing, protect customer data, and minimize the risk of liability for unauthorized transactions.

Download Our Report on DORA and NIS2

To better understand how PSD3 fits into the broader context of digital security regulations, we invite you to download our report on DORA and NIS2. This report explains how new regulations on digital operational resilience and risk management will impact your business and how you can prepare for these upcoming changes.

[Download the DORA and NIS2 Report]

Download-report-about-Digital-Operational-Resilience-Act-DORA-and-The-NIS2-Network-and-Information-Security-Directive

Get in Touch with Our Specialists

Are you wondering how to meet PSD3 requirements and secure your company from emerging threats? Contact our specialists who can help you implement the right solutions to comply with PSD3, DORA, and other regulations governing digital security.

Prepare your business for PSD3 changes Schedule a call with Secfense to learn more

[Contact Us]

Conclusion

PSD3 is a critical regulation that will impact all payment service providers operating in the European Union. With heightened requirements for Strong Customer Authentication, data protection, and liability for unauthorized transactions, financial institutions and fintech companies face significant challenges. Secfense offers solutions that help businesses swiftly and efficiently implement these requirements, protecting them from the risks of non-compliance and financial fraud.

You can find the official information and updates about PSD3 on the European Commission’s website. For the latest details regarding the legislative process and documents related to PSD3, visit the European Commission’s Payment Services page:

European Commission – Payment Services

This page includes updates on the development of PSD3, as well as links to official documents and resources.

Antoni takes care of all the marketing content that comes from Secfense. Read More

Testimonials

We are faced with new challenges every day. We must always be one step ahead of the attackers and know what they are going to do before they do it. We are convinced that the User Access Security Broker will bring security to a new level, both for those working at the office and from home. For us, working with Secfense is an opportunity to exchange experience with developers who put great value on out-of-the-box thinking.

Krzysztof Słotwiński

Business Continuity and Computer Security Officer

BNP Paribas Bank Poland

As part of the pre-implementation analysis, we verified that users utilize a wide range of client platforms: desktop computers, laptops, tablets, smartphones, and traditional mobile phones. Each of these devices differs in technological advancement, features, and level of security. Because of this, and also due to the recommendation of the Polish Financial Supervision Authority (UKNF), we decided to introduce additional protection in the form of multi-factor authentication mechanisms based on FIDO. As a result, users of our applications can log in safely, avoiding common cyber threats such as phishing, account takeover, and theft of their own and their clients’ data.

Marcin Bobruk

CEO

Sandis

We are excited to partner with Secfense to enhance our user access security for our web apps. By integrating their User Access Security Broker, we ensure seamless and secure protection for our applications and systems, delivering superior security and convenience to our customers.

Charm Abeywardana

IT & Infrastructure

Visium Networks

Before investing in Secfense, we had the opportunity to talk to its existing clients. Their reactions were unanimous: wow, it’s so easy to use. We were particularly impressed by the fact that implementing their solution does not require the involvement of IT developers. It gives Secfense a huge advantage over the competition, and at the same time opens the door to potential customers who so far were afraid of changes related to the implementation of multi-factor authentication solutions.

Mateusz Bodio

Managing Director

RKKVC

Even when the network and infrastructure are secured enough, social engineering and passwords can be used to gain control of the system by attackers. Multifactor authentication is the current trend. Secfense addresses this and allows you to build zero trust security and upgrade your current systems to passwordless applications within minutes, solving this problem right away,” said Eduard Kučera, Partner at Presto Ventures and cybersecurity expert – former Director in hugely successful Czech multinational cyber security firm Avast.

Eduard Kučera

Partner

Presto Ventures

One of the biggest challenges the world is facing today is securing our identity online. That’s why we were so keen to have Secfense in our portfolio. They make it possible to introduce strong authentication in an automated way. Until now, organizations had to selectively protect applications because the deployment of new technology was very hard, or even impossible. With Secfense, the implementation of multi-factor authentication is no longer a problem, and all organizations can use the highest standards of authentication security.

Stanislav Ivanov

Founding Partner

Tera Ventures

Two-factor authentication is known to be one of the best ways to protect against phishing; however, its implementation has always been difficult. Secfense helped us solve that problem. With their security broker, we were able to introduce various 2FA methods on our web applications at once.

Dariusz Pitala

Head of IT

MPEC S.A.