Commission publishes regulatory technical standards for strong customer authentication and secure communication

Original title: Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance. )

Commission Delegated Regulation (EU) 2018/389 entered into force on 14 March 2018 to supplement PSD2 with regulatory technical standards for strong customer authentication (SCA) and common secure open standards of communication. The regulation sets out specific requirements for authentication mechanisms and communication protocols that payment service providers must implement. This establishes the technical framework for SCA requirements under PSD2, with phased implementation deadlines extending to September 2019.

What changed

  • Commission Delegated Regulation (EU) 2018/389 establishes mandatory regulatory technical standards for strong customer authentication (SCA) under PSD2, specifying technical requirements for authentication mechanisms and protocols that payment service providers must comply with.
  • Regulation introduces common and secure open standards of communication to ensure standardized, interoperable communication frameworks between payment service providers and other market participants.
  • Multiple entry-into-force dates are set: 14 March 2018 for initial implementation, 14 March 2019 for full SCA application, and 14 September 2019 for additional requirements, allowing phased compliance.

Who is affected

Payment service providers operating in the EU; financial institutions offering payment services; third-party providers accessing payment accounts; organizations handling customer authentication and communication in payment transactions across the EEA.

Summary generated by a language model; the official text prevails. Not legal advice.