PSD2 License Explained: Requirements and Business Impact
Learn what a PSD2 license is, who needs it, how to apply, and what PSD2 means for security, competition, and EU payment compliance.

What a PSD2 license is and why it matters
A PSD2 license is EU permission for regulated payment work. It lets Payment Service Providers (PSPs) and Electronic Money Institutions (EMIs) operate lawfully.
It also sets rules for safe access to money services. These rules cover security checks, data use, and customer protection.
PSD2 aims to improve pay safety and enable new services. It also pushes fair competition across the EU market.
For a business, PSD2 affects more than legal papers. It changes your product steps, your tech controls, and your risk setup.

What you need to get a PSD2 license
Getting a PSD2 license takes more than one form. You submit a full package to your National Competent Authority (NCA).
Expect to prove three things in your plan. You must show you can run the business, that you stay financially sound, and that you manage risk well.
Security is usually the hardest part to explain. Regulators want proof that controls work in real life.
- Business capability: clear roles, checks, and trained staff.
- Financial stability: capital, funding, and a real business plan.
- Security norms: strong access checks and solid incident plans.
- Operational readiness: support, complaints, and clear service maps.
If your service touches stored value, you may also need EMI work. That is where people ask, “what is an emi license” and how it fits.
An EMI license is permission under the Electronic Money Directive (EMD2). It covers issuing and managing electronic money.
Even if you start as a smaller service, your plan can grow. So your licensing research should cover your roadmap, not just today.
Which entities typically need a PSD2 license
Not every fintech needs a PSD2 license. The key is what your service does in the pay flow.
PSD2 applies when you offer regulated payment tasks. This can include starting payments, processing payments, or using bank data with consent.
You also may need an authorization if you act as a middle layer. Outsourcing does not remove your legal duties either.
| Entity type | Typical PSD2 scope | Common examples |
|---|---|---|
| Payment Institution (PI) | Offers pay services | Transfers between accounts and payment steps |
| Electronic Money Institution (EMI) | Issues or holds electronic money | Store value and later redeem it |
| Account Information Service Provider (AISP) | Reads account data | Shows balances and past payments across accounts |
| Payment Initiation Service Provider (PISP) | Starts a payment | Begins a bank transfer for a user |
If you act as an AISP, you mainly handle data access. If you act as a PISP, you mainly start a payment.
If you issue or store value, EMI rules may drive your license path. That is why “what is emi license” shows up in many build plans.
To decide your needs, map every user step. Then link each step to the regulated activity behind it.

How PSD2 changes day-to-day payment services
PSD2 shapes real workflows, not just paperwork. It tells you when and how to verify a user.
Strong Customer Authentication (SCA) is central to PSD2. SCA means extra checks before many payment actions.
In practice, SCA affects login steps and payment start steps. It also affects how you handle “step-up” checks when risk rises.
- SCA triggers: require checks at key moments.
- Data and consent: keep clear records of user permission.
- Secure access: use tight API and account controls.
- Fraud checks: monitor signals and act fast.
Consumer protection in payments is also part of PSD2. You must handle consent, correct access, and clear support.
PSD2 also helps competition and drives safer innovation. New players can offer services, but they must meet strict rules.
So you need a build plan that joins law and engineering. That means your app, logs, and checks work together.
Who grants PSD2 licenses: the National Competent Authorities
National Competent Authorities grant PSD2 licenses in each EU state. They also supervise licensed firms within their borders.
The core law is EU-wide, but NCA practice can differ. That can change what you must submit and how you present it.
Your best move is to read your home NCA guidance early. Then tailor your docs and your control story to that view.
In most cases, you apply in your home state. Then you manage cross-border work using the PSD2 framework.
Because each NCA can ask for detail, planning helps. Build a “proof pack” you can reuse across reviews.
This pack should match what you run in production. It should also match how you test and change systems.

Compliance, supervision, and enforcement under PSD2
After you get a PSD2 license, compliance keeps going. You must keep controls strong and show you do it over time.
Supervision can include requests for updates and proof. It can also include limits or formal actions if you fail.
A common issue is a gap between plans and reality. If your controls drift, an NCA may push fixes quickly.
SCA compliance needs ongoing care. You must show that you apply checks at the right moments and keep proof.
- Put control proof into product design from day one.
- Test security on a steady schedule, not once.
- Log SCA events and keep audit-ready records.
- Track changes to code, tools, and vendor links.
- Use support tickets and fraud alerts to find gaps.
PSD2 compliance is an ongoing duty, not a one-time signoff.
If you outsource parts of service, stay accountable. You must still manage vendor risk and verify outcomes.
Also expect routine policy reviews. Regulators want your risk view to stay current as threats change.
What comes next: PSD3 and the direction of EU payments
PSD2 is now a baseline for EU pay work. But tech and fraud patterns move fast.
So the EU is likely to push stronger security and tighter data rules. That may also mean more formal ways to show controls.
Some changes could focus on how systems share data. Others could focus on how firms prove safe behavior.
For your planning, treat PSD2 controls as your core engine. Then design so updates can land with less rework.
If your product could later require EMI work, plan early. That is part of how to get emi license later with less risk.
In short, build a control culture that can grow. Then you stay ready for future rules, not just PSD2.
FAQ
- What is a PSD2 license?
- A PSD2 license is EU permission that lets Payment Service Providers and Electronic Money Institutions offer regulated payment services. It comes with duties for security, reporting, and customer protection.
- How do I get a PSD2 license in the EU?
- You submit documents to your home National Competent Authority. You must show business capability, financial stability, and security controls, including user checks and incident plans.
- What entities need a PSD2 license?
- Common licensed groups include payment institutions, electronic money institutions, and Account Information Service Providers. Payment Initiation Service Providers may also need authorization, based on what they do.
- What is an EMI license and how is it different from PSD2?
- An EMI license allows an Electronic Money Institution under the Electronic Money Directive framework. It focuses on electronic money activity, and it can overlap with PSD2 services.
- How does PSD2 affect Strong Customer Authentication (SCA)?
- PSD2 requires Strong Customer Authentication in many payment and account access steps. You must implement correct triggers, handle allowed exceptions, and keep proof for audits.
- Who enforces PSD2 and can they withdraw a license?
- National Competent Authorities supervise licensed firms. If rules are not met, they can demand fixes, add limits, or take enforcement actions.


