PSD2 / PSD3 — EU Payment Services Directive

PSD2 / PSD3 — EU Payment Services Directive — 98% of in-scope requirements covered.

61 requirements · 61 in scope (59 enforced · 1 designed · 1 advisory). The 98% is weighted over the in-scope base.

Source: Directive (EU) 2015/2366 (PSD2) + Commission Delegated Regulation (EU) 2018/389 (RTS on SCA & CSC) + PSD3 Directive proposal COM(2023)366

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Open-Banking Interfaces (Article 30 RTS)131210096%
Operational and Security Risk (Article 95)66000100%
RTS Strong Customer Authentication (Articles 4-9)2828000100%
Third-Party Provider Access (Articles 32-36, 66-67)141301095%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
psd2.RTS.30RTS Article 30 — General obligations for access interfaces — dedicated interface or modified customer-interfaceenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/16-EDGE-RUNTIME.md, constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.30.1RTS Article 30(1) — Dedicated interface (or modified customer-interface fallback) — equivalent functionality, performance, and availability to the customer interfaceenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/16-EDGE-RUNTIME.md, constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.30.2RTS Article 30(2) — Communication of confidential authentication data shall not be requiredenforcedaudit_events: kye.purpose.admissibility.v1, kye.evidence.tool_call_pin.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.30.3RTS Article 30(3) — Availability and performance — interface KPIs published, downtime alerting, contingency fallbackenforcedaudit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/51-NO-SPOF.md
psd2.RTS.30.4RTS Article 30(4) — Service Level Targets and remediation plans must be publishedenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
psd2.RTS.30.5RTS Article 30(5) — Testing facility for TPPs (sandbox + onboarding) for at least 6 months before go-livedesignedconstitution_refs: constitution/07-SUBDOMAIN.md, constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.31RTS Article 31 — Access interface options — dedicated interface vs. modified customer-interfaceenforcedaudit_events: kye.compliance.attestation.v1, kye.evidence.decision_map.v1
engines: internal
constitution_refs: constitution/16-EDGE-RUNTIME.md
psd2.RTS.32RTS Article 32 — Fallback mechanism — if the dedicated interface fails SLA, TPPs may use the modified customer-interface routeenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/25-EDGE-GOVERNANCE.md
psd2.RTS.32.4RTS Article 32(4) — Conditions for exemption from contingency-interface obligationenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.33RTS Article 33 — Common standards for communication — usage of standardised API specificationsenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/16-EDGE-RUNTIME.md
psd2.RTS.34RTS Article 34 — Certificates — qualified certificates for electronic seals / website authentication under eIDASenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
psd2.RTS.35RTS Article 35 — Security of communication session — TLS 1.2+ with strong cipher suitesenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/16-EDGE-RUNTIME.md
psd2.RTS.36RTS Article 36 — Data exchanges — strong end-to-end encryption protecting PSU credentialsenforcedaudit_events: kye.evidence.tool_call_pin.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/16-EDGE-RUNTIME.md, constitution/25-EDGE-GOVERNANCE.md
psd2.A95.1Article 95(1) — Establish a framework with appropriate mitigation and control mechanisms to manage operational and security risksenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1, kye.signal.drift.detected.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md
psd2.A95.2Article 95(2) — Annual operational and security risk assessment report to the competent authorityenforcedaudit_events: kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
psd2.A95.3Article 95(3) — Customer awareness of operational and security risks + mitigating actionsenforcedaudit_events: kye.comms.dispatched.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
psd2.A96Article 96 — Major operational or security incident — notify competent authority without undue delay; payment-service-user notification when adverseenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.compliance.attestation.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
psd2.A96.1Article 96(1) — Initial notification (≤4 hours) to competent authority + intermediate + final reportsenforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
psd2.A98Article 98 — RTS on SCA + CSC published by EBA — applicable directlyenforcedconstitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.1RTS Article 1 — Subject matter: technical requirements for SCA and CSCenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/40-IMPLEMENTATION-CANONICAL.md
psd2.RTS.2RTS Article 2 — General authentication requirements — robust technical features, monitoring of authentication proceduresenforcedaudit_events: kye.authority.grant.v1, kye.signal.drift.detected.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.3RTS Article 3 — Authentication code review and testing — fraud-rate analysis, security auditenforcedaudit_events: kye.compliance.attestation.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
psd2.RTS.4RTS Article 4 — Apply Strong Customer Authentication (SCA) with at least two independent elements from knowledge, possession, and inherenceenforcedaudit_events: kye.authority.grant.v1, kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.4.bisRTS Article 4 — Authentication code generation — non-replayable, single-use, cryptographically bound to the SCA elementsenforcedaudit_events: kye.authority.grant.v1, kye.payments.proof_bundle.v1, kye.replay.proof.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.5RTS Article 5 — Dynamic linking — every payment authentication code linked to amount + payee, invalidated on tamperenforcedaudit_events: kye.payments.intent.v1, kye.payments.authority.v1, kye.payments.proof_bundle.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.5.1RTS Article 5(1) — Amount of transaction and identity of payee shown to user during SCAenforcedaudit_events: kye.payments.intent.v1, kye.governedui.action_proposal.v1, kye.evidence.decision_map.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/36-GOVERNEDUI.md
psd2.RTS.5.2RTS Article 5(2) — Confidentiality, authenticity, integrity of amount and payee maintained throughout the authentication channelenforcedaudit_events: kye.payments.proof_bundle.v1, kye.evidence.tool_call_pin.v1
engines: internal, internal
constitution_refs: constitution/16-EDGE-RUNTIME.md
psd2.RTS.6RTS Article 6 — Knowledge-element requirements — guess-resistant, non-disclosure measuresenforcedaudit_events: kye.authority.grant.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
psd2.RTS.7RTS Article 7 — Possession-element requirements — uniqueness, replication-resistance, non-disclosureenforcedaudit_events: kye.authority.grant.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.8RTS Article 8 — Inherence-element requirements — false-acceptance + false-rejection rates within toleranceenforcedaudit_events: kye.authority.grant.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.9RTS Article 9 — Independence of the elements — breach of one element does not compromise reliability of the othersenforcedaudit_events: kye.authority.grant.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
psd2.RTS.10RTS Article 10 — Exemption for payment account information (read-only AISP, ≤180 days)enforcedaudit_events: kye.consent.acceptance.v1, kye.purpose.grant.v1, kye.evidence.decision_map.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.11RTS Article 11 — Exemption for contactless payments at POS (≤€50 per transaction, cumulative limits)enforcedaudit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.12RTS Article 12 — Exemption for unattended terminals for transport fares + parking feesenforcedaudit_events: kye.purpose.admissibility.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.13RTS Article 13 — Exemption for trusted beneficiaries — added to ASPSP whitelist via SCAenforcedaudit_events: kye.authority.grant.v1, kye.purpose.admissibility.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.14RTS Article 14 — Exemption for recurring transactions of same amount + same payeeenforcedaudit_events: kye.purpose.admissibility.v1, kye.payments.intent.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.15RTS Article 15 — Exemption for credit transfers between same natural-or-legal-person accountsenforcedaudit_events: kye.purpose.admissibility.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.16RTS Article 16 — Exemption for low-value remote payments (≤€30, cumulative limits)enforcedaudit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.17RTS Article 17 — Exemption for secure corporate payment processes + protocolsenforcedaudit_events: kye.purpose.admissibility.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.RTS.18RTS Article 18 — Transaction Risk Analysis (TRA) — exemption only available below value thresholds and with documented low-fraud-rate evidenceenforcedaudit_events: kye.evidence.decision_map.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
psd2.RTS.19RTS Article 19 — Monitoring of fraud-rate per payment-instrument categoryenforcedaudit_events: kye.signal.drift.detected.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
psd2.RTS.20RTS Article 20 — Cessation of TRA exemption when fraud-rate exceeds reference rateenforcedaudit_events: kye.purpose.admissibility.v1, kye.signal.drift.detected.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/13-RESILIENCE-LOOP.md
psd2.RTS.21RTS Article 21 — Common and Secure Communication (CSC) — general requirements for identification + integrity + confidentialityenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/16-EDGE-RUNTIME.md, constitution/25-EDGE-GOVERNANCE.md
psd2.RTS.22RTS Article 22 — Identification — TPP eIDAS-QWAC bound to the access channelenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
psd2.RTS.23RTS Article 23 — Traceability — TPP requests logged with sufficient detail for auditenforcedaudit_events: kye.audit.event.v1, kye.federation.cross_org_delegation.v1, kye.evidence.tool_call_pin.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
psd2.RTS.24RTS Article 24 — Session — protected; idle session timeout ≤5 minutesenforcedaudit_events: kye.authority.grant.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd3.SCA.evolvedPSD3 — extension of SCA to instant payments, anti-APP-fraud confirmation-of-payee, accessibility carve-outsenforcedaudit_events: kye.payments.intent.v1, kye.evidence.decision_map.v1
engines: internal, internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A32Article 32 — TPP registration and authorisation — only licenced AISP/PISP/CBPII may access payment-account data via the dedicated interfaceenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.authority.grant.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md
psd2.A33Article 33 — TPP identification via eIDAS qualified certificates (QWAC for transport + QSealC for sealing)enforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.evidence.tool_call_pin.v1
engines: internal, internal
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
psd2.A34Article 34 — Information requirements at TPP registration — name, licence number, NCA contact detailsenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A35Article 35 — Account servicing PSP must not impose contractual conditions or charges on TPP accessadvisoryconstitution_refs: constitution/26-COMMERCIAL.md
psd2.A36Article 36 — Customer access to payment-account data — direct + through any AISP, with explicit customer consentenforcedaudit_events: kye.consent.acceptance.v1, kye.purpose.grant.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/31-DATA-GOVERNANCE-PACK.md
psd2.A65Article 65 — Confirmation on availability of funds (CAF) — ASPSP responds yes/no to a CBPII query, consent-boundenforcedaudit_events: kye.consent.acceptance.v1, kye.federation.cross_org_delegation.v1, kye.payments.intent.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A66Article 66 — Right to use a payment-initiation service (PIS) — ASPSP cooperation with the PISP without discriminationenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.payments.intent.v1, kye.payments.proof_bundle.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A66.2Article 66(2) — PISP must not hold payer's funds and must transmit credentials securelyenforcedaudit_events: kye.evidence.tool_call_pin.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A66.3.bArticle 66(3)(b) — PISP shall identify itself towards the ASPSP and communicate securelyenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
psd2.A66.4Article 66(4) — ASPSP shall treat PIS-mediated transactions equally to direct transactions in timing, priority, chargesenforcedaudit_events: kye.purpose.permission.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A67Article 67 — Right to use an account-information service (AIS) — read-only access to designated payment accounts, scoped consentenforcedaudit_events: kye.consent.acceptance.v1, kye.purpose.grant.v1, kye.evidence.tool_call_pin.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/31-DATA-GOVERNANCE-PACK.md
psd2.A67.2Article 67(2) — AISP must access only designated payment accounts + necessary associated informationenforcedaudit_events: kye.purpose.permission.v1, kye.evidence.tool_call_pin.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
psd2.A67.3Article 67(3) — AISP must not request sensitive payment data nor use data for other purposesenforcedaudit_events: kye.purpose.admissibility.v1, kye.evidence.tool_call_pin.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/31-DATA-GOVERNANCE-PACK.md
psd2.A68Article 68 — Refusal of access by ASPSP — objectively justified, documented, reported to NCAenforcedaudit_events: kye.signal.decision.denied.v1, kye.evidence.decision_map.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/13-RESILIENCE-LOOP.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.