PSD2
PSD2 is the EU directive (since 2018) requiring strong customer authentication (SCA) and opening banking APIs to licensed third parties.
PSD2 (the Second Payment Services Directive, Directive (EU) 2015/2366) is the EU payment services directive that opened banking to licensed third parties (account information and payment initiation) and made strong customer authentication (SCA) mandatory for electronic payments - two independent factors, plus dynamic linking of the transaction data for remote payments (PSD2 art. 97(2)). PSD2 has applied since January 2018, and the SCA rules set out in the Regulatory Technical Standards (Commission Delegated Regulation (EU) 2018/389) have applied since September 2019. SCA is not required for every transaction: exemptions exist for low-value payments, contactless payments, trusted beneficiaries and payments cleared through transaction risk analysis. In the Netherlands, PSD2 is implemented through the Wft: account information service providers (AISPs) must register, while payment initiation service providers (PISPs) need authorisation, with DNB and the AFM supervising both.
PSD2 leans directly on eIDAS trust services: banks and third parties identify each other's APIs with QWACs and protect traffic with qualified seals (QSealC), per ETSI TS 119 495. Its successor package (PSD3/PSR) continues this line. Under eIDAS 2, banks are also expected to accept the EUDI Wallet as a means of authentication once the relevant transition period has passed, though this acceptance duty covers authentication rather than SCA compliance as such and is not yet in force.