Kaamos

Framework reference

PSD2 for EU B2B software companies.

PSD2 applies to EU payment service providers and affects software companies that operate payment services or support regulated payment workflows. It commonly appears in fintech security work alongside DORA, PCI DSS, GDPR, and customer due diligence.

Kaamos support
Information only
Category
Binding EU regulations
Obligation
Binding
Last updated

The obligation, in the act's words

Member States shall ensure that payment service providers establish a framework with appropriate mitigation measures and control mechanisms to manage the operational and security risks, relating to the payment services they provide.

Article 95(1), Directive (EU) 2015/2366 (PSD2)

A framework with control mechanisms, assessed by your competent authority, which means it has to be written down and kept current.

Who it applies to

  • Payment institutions, electronic money institutions, and payment service providers.
  • Open banking and account-information service providers.
  • Software suppliers supporting regulated payment workflows.

What you need to do

  • Strong customer authentication, secure communication, incident reporting, and operational controls.
  • Evidence around access, authentication, resilience, and security governance.
  • Alignment with DORA and PCI DSS where payment and ICT risk overlap.

How to use this entry

  • Use this page to understand the buyer or regulatory pressure before it becomes a deadline.
  • Run the regulation checker to see whether this area is likely to matter for your company now.
  • If it becomes relevant, Kaamos can help you scope the gap and turn it into prioritized security work.

Sources

Company profiles this applies to

Information bank

PSD2 is included as an information-bank entry. Use it to understand the pressure, then run the checker to see whether it should enter your roadmap.