OB-SCA-001PSR 86(2)Strong customer authentication

TPPs rely on the ASPSP's authentication

What the text fixes

The ASPSP lets PISPs and AISPs rely on the authentication procedures it provides to its customers.

Article
PSR 86(2)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
Who is bound
ASPSP
Who it is for
API
Application
21 months after entry into force, the general application date (Article 112).
Level 2
RTS under Article PSR 89(1)(a), draft due at T + 12 months.Link suggested by this site; the text does not say so.
Origin
PSD2, Art. 97(5)

STET 1.6.3

Covered

STET's three approaches, redirect, decoupled and one-factor embedded, all rely on the bank's authentication.

Handbook pages

Sources

Checked on October 4, 2026

The entry as JSON
{
  "id": "OB-SCA-001",
  "article": "PSR 86(2)",
  "alsoIn": [],
  "articleFinal": null,
  "actors": [
    "aspsp"
  ],
  "roles": [
    "api"
  ],
  "appliesAt": "T+21",
  "title": {
    "fr": "Les TPP s'appuient sur l'authentification de l'ASPSP",
    "en": "TPPs rely on the ASPSP's authentication",
    "es": "Los TPP se apoyan en la autenticación del ASPSP",
    "pt-br": "Os TPPs usam a autenticação do ASPSP"
  },
  "level1": {
    "fr": "L'ASPSP laisse les PISP et les AISP s'appuyer sur les procédures d'authentification qu'il fournit à ses clients.",
    "en": "The ASPSP lets PISPs and AISPs rely on the authentication procedures it provides to its customers.",
    "es": "El ASPSP permite que los PISP y los AISP se apoyen en los procedimientos de autenticación que ofrece a sus clientes.",
    "pt-br": "O ASPSP permite que PISPs e AISPs usem os procedimentos de autenticação que oferece a seus clientes."
  },
  "level2": {
    "mandate": "PSR 89(1)(a)",
    "instrument": "rts",
    "deadline": "T+12",
    "link": "reading"
  },
  "origin": [
    {
      "act": "psd2",
      "articles": "97(5)"
    }
  ],
  "stet": {
    "1.6.3": {
      "status": "present",
      "note": {
        "fr": "Les trois approches de STET, redirection, découplé et embedded à un facteur, reposent toutes sur l'authentification de la banque.",
        "en": "STET's three approaches, redirect, decoupled and one-factor embedded, all rely on the bank's authentication.",
        "es": "Los tres enfoques de STET, redirección, desacoplado y embedded de un factor, se basan todos en la autenticación del banco.",
        "pt-br": "As três abordagens do STET, redirecionamento, desacoplado e embedded de um fator, se baseiam todas na autenticação do banco."
      },
      "pages": [
        "framework/3-prerequisites-and-technical-details"
      ]
    }
  },
  "verification": null,
  "sources": [
    {
      "document": "8221/26",
      "page": 362
    }
  ],
  "verifiedAt": "2026-10-04"
}