What PSD2 governs, in one paragraph
PSD2 has been the European framework for payment services for a number of years. It governs who may offer payment services and under what supervision, gives consumers stronger rights, and sets security requirements for online payment. For you as a business, that last part is the most tangible, in the form of strong customer authentication.
SCA: two locks on one payment
Strong customer authentication means your customer confirms a payment with at least two of three kinds of proof: something they know (a code), something they have (their phone) and something they are (a fingerprint or face). In practice your customer experiences that as the familiar moment in the bank app: a quick confirm, done. The technology that does this for card payments, 3-D Secure, we explained in its own article; here it is about what the rule means for your checkout.
The exemptions that keep your checkout smooth
The regulator knew an extra step on every payment would be fatal for convenience, and built in exemptions. The main ones: small amounts can go without the extra step, recurring payments only need full verification the first time, customers can add trusted webshops to a list at their bank, and payments with a demonstrably low risk may proceed without the extra step based on a risk analysis. Payments the webshop itself initiates, such as the monthly charge of a subscription the customer set up earlier with verification, also fall outside the standard requirement. The nice thing: you do not have to apply those exemptions yourself. A good payment setup does it automatically, so the extra step only appears where it belongs.
What this concretely means for your checkout
Three things. Make sure strong customer authentication is on by default; without it your payment in Europe simply stalls at your customer's bank. Set up subscriptions properly, with a fully verified first payment and correctly marked follow-up payments, so your recurring charges keep running smoothly. And do not see the verification as the enemy of your conversion. A customer who sees their bank looking on trusts the payment, and fraud that fails at the front door is a chargeback you never have to fight.
fraud that fails at the front door is a chargeback you never have to fight.
What is coming: PSD3
Europe has its successor ready: the PSD3 and PSR package was finalised this year and will apply in the coming years. The broad line: strong customer authentication stays the basis and is extended in places, fraud prevention is turned up, and there will be, among other things, a check that the recipient's name matches the account number before a transfer goes through. For you as a business it all runs through your payment provider; the only thing you have to do is choose a partner that keeps up with these developments, so your checkout keeps complying on its own.