PSD3 & PSR: Strong Customer Authentication – new duties, old challenges | ALLES LEGAL #109

🎧 This episode of Alles Legal – Fintech-Recht kompakt focuses on strong customer authentication (SCA) in the context of PSD3 and PSR. What are the new obligations for payment service providers? Which pain points remain? – Tune in now!

Podcast: https://paymentandbanking.podigee.io/741-alles-legal-108-psd3-psr-starke-kundenauthentifizierung-neue-pflichten-alte-baustellen/

New rules, new tech, new questions – In episode #109 of Alles Legal, Dana Wondra and Peter Frey take a deep dive into strong customer authentication (SCA) – a topic familiar from PSD2 that is gaining complexity under PSD3 and PSR.

One key change

SCA will soon be governed directly by the PSR as an EU regulation – making it immediately applicable across all member states. A new obligation requires providers to offer accessible alternatives for vulnerable user groups, such as those without smartphones or with limited digital skills.

From a technical angle, passkeys are increasingly recognised as SCA-compliant and could replace traditional passwords. Delegated authentication will still be allowed but will now be considered an outsourcing arrangement – bringing DORA into play.

Telecommunications providers are also entering the picture

They will be required to actively support fraud prevention by implementing protective technical measures.

Peter Frey explains what all this means in practice and where open issues remain.

About this podcast

Alles Legal – Fintech Recht Kompakt delivers sharp, weekly insights into legal and compliance matters in the world of banking. (in German only)
This podcast is a collaboration between Payment & Banking and PayTechLaw.
Each Wednesday, we unpack the legal developments shaping the financial world – clearly, concisely, and without the legal jargon.
Since 2021, PayTechLaw authors and Annerton attorneys have brought depth and clarity to complex topics.
Whether it’s PSD3, DORA, or FiDA – we provide the legal context you need.
In 20 minutes. No detours.



By continuing, you accept our privacy policy.
You May Also Like
MiCAR trifft PSD2: Warum E-Geld-Token plötzlich doppelt reguliert werden | ALLES LEGAL #138
Read More

MiCAR meets PSD2: Why e-money tokens are suddenly subject to dual regulation | ALLES LEGAL #138

Since the end of the EBA transitional period in March 2026, many crypto-asset service providers have had to assess whether, in addition to MiCAR, they also require a PSD2 or national payment services licence. In this episode, Kemal Ahmedi explains why crypto regulation and payment services law overlap and what this means for business models and licensing strategies.
Read More
AMLA konsultiert Leitlinien zur laufenden Überwachung von Geschäftsbeziehungen – Was auf Verpflichtete zukommt AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect
Read More

AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect

Continuous monitoring is already one of the core obligations in anti-money laundering compliance today. However, the AMLR elevates this principle to a new level. Obliged entities must not only review individual transactions but continuously analyse and assess the entire business relationship throughout its lifecycle.
Read More
MiCAR erklärt: Was die neue Krypto-Regulierung für Unternehmen verändert | ALLES LEGAL #137 MiCAR explained: How the new crypto regulation is changing the market | ALLES LEGAL #137
Read More

MiCAR explained: How the new crypto regulation is changing the market | ALLES LEGAL #137

With MiCAR, the EU is introducing its first harmonised regulatory framework for crypto-assets. In the latest episode of “Alles Legal – Fintech-Recht kompakt”, Kemal Ahmedi from Annerton explains which companies will require a MiCAR licence, why stablecoins are subject to stricter regulation and how the EU passport could reshape the European crypto market.
Read More