# The PSD2 deadline extension: why you need it and how best to use your additional time
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-09-17
Category: BANKING
Category URL: https://financedigest.com/category/banking
Meta Title: PSD2 SCA Deadline Extension Impact on E-commerce Industry
Meta Description: Learn why the 18-month deadline extension for the implementation of SCA regulations under PSD2 is providing temporary relief for the e-commerce industry in the
URL: https://financedigest.com/the-psd2-deadline-extension-why-you-need-it-and-how-best-to-use-your-additional-timehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd031018-5-1736838994466-compressed.jpg)

By **Ramesh Ramani**, Head of Banking & Financial Services Europe, Cognizant

The UK’s Financial Conduct Authority (FCA) has confirmed an 18-month deadline extension for the introduction of Secure Customer Authentication (SCA) regulations, in an attempt to give firms more time to prepare for the impending Second European Payment Services Directive (PSD2) deadline. With the new rules for cashless payments originally due to come into force on 14th September 2019, this has given cause for a temporary sigh of relief amongst many in the e-commerce industry.

![Ramesh Ramani](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/ramesh-ramanicognizant-1736838994544-compressed.jpg)

Ramesh Ramani

This is because, as part of PSD2, the SCA requirement stipulates stronger payment security standards for [higher value](https://www.financedigest.com/delivery-hero-sees-higher-gross-merchandise-value-in-third-quarter.html "Delivery Hero sees higher gross merchandise value in third quarter") transactions based on multifactor authentication, increasing the security of electronic payments. This comes as FCA data reported that cyber incidents at financial services firms increased by 1,000 per cent in 2018, and this figure is only [expected to rise with the growth in mobile](https://www.financedigest.com/t-mobile-sells-wireline-business-to-cogent-for-1-expects-hefty-charge.html "T-Mobile sells wireline business to Cogent for , expects hefty charge") payments.

The delay to the implementation of the directive is intended to prevent [disruptions](https://www.financedigest.com/unfolding-the-great-payments-disruption-how-consumers-can-navigate-this-new-financial-world-and-how-financial-institutions-can-rise-to-the-challenge.html "Unfolding the Great Payments Disruption – how consumers can navigate this new financial world and how financial institutions can rise to the challenge") to online payment processes and facilitate the smooth transition to the new requirements put in place to make cashless payments safer. But why has the deadline been extended, and what can [businesses do to make sure they are ready for the revised implementation date](https://www.financedigest.com/date-palm-market-detailed-survey-on-key-trends-leading-players-business-opportunities-2026.html "Date Palm Market – Detailed Survey On Key Trends, Leading Players & Business Opportunities 2026")?

**The basics: what you [need to know](https://www.financedigest.com/ukraine-and-russia-what-you-need-to-know-right-now-3.html "Ukraine and Russia: What you need to know right now")**

Applicable across the whole of the EU including the European Economic Area (EEA), the directive will provide better customer data [protection](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks") and ensure that data transmission over the internet is more secure.Simply put, only [payment services that are PSD2-compliant can be used for online purchases using cards](https://www.financedigest.com/fingerprints-supports-two-more-biometric-payment-card-launches-in-the-mena-region.html "FINGERPRINTS’ SUPPORTS TWO MORE BIOMETRIC PAYMENT CARD LAUNCHES IN THE MENA REGION").

Another important element of the directive is that those who accept [payments online will have to demand a two-factor authentication](https://www.financedigest.com/why-latin-america-chose-biometric-authentication-for-payment-cards.html "Why Latin America Chose Biometric Authentication for Payment Cards"). Customers will no longer be able to order with just one click or by [credit card](https://www.financedigest.com/what-happens-to-credit-card-debt-when-you-die.html "What happens to credit card debt when you die") number, but will instead have to confirm their purchase with two security features.

According to the directive, the security features [must](https://www.financedigest.com/the-three-must-haves-of-cyber-security-that-you-need-to-stay-cyber-safe.html "The three “must haves” of cyber security that you need to stay cyber safe") combine two out of the three following security criteria:

1. **Knowledge features** – information that only the customer knows, such as a password or PIN;
2. **Possession features** -a physical entity that the customer has access to, such as a credit card, [mobile phone or TAN generator(the device issued by banks](https://www.financedigest.com/why-you-should-use-a-mobile-banking-app-and-how-to-make-the-most-of-it.html "Why You Should Use a Mobile Banking App – and How to Make the Most of It") to enable customers to generate security codes when undertaking home banking);
3. **Inherence features** -biometrics coming from unique personal characteristics, such as the customer’s voice, iris or fingerprint.

This [means that the traditional combination of a PIN and password is no longer](https://www.financedigest.com/why-fundraising-no-longer-means-kissing-a-lot-of-frogs.html "Why fundraising no longer means kissing a lot of frogs") sufficient, as both entries will come under the “knowledge features” category.

**What could have happened without an extension?**

While banks and third-party providers like Fintechs – such as as Monzo and Revolut– are already well prepared to meet the deadline, many organisations that offer [online payments and even entire markets](https://www.financedigest.com/online-payment-gateway-market-to-witness-a-cagr-of-10-3.html "Online Payment Gateway Market to witness a CAGR of 10.3%") are not. In fact, levels of [readiness for implementing a PSD2-compliant process in time](https://www.financedigest.com/the-spritz-gets-a-shake-up-something-nothing-launches-new-ready-to-drink-spritz-in-time-for-summer.html "The Spritz gets a shake up! Something & Nothing launches new ready-to-drink Spritz in time for summer") for 14th September are now extremely varied. But as SCA comes into effect, all parties in the [payments chain](https://www.financedigest.com/eliminating-payment-barriers-the-future-of-supply-chain-payments-is-digitization.html "Eliminating Payment Barriers: The Future of Supply Chain Payments is Digitization") will need to be ready at the same time to avoid challenges. An extended deadline will therefore provide regulators with more time to consult, engage and work with relevant [market participants](https://www.financedigest.com/powder-dispenser-market-market-2019-2029-where-should-participant-focus-to-gain-maximum-roi.html "Powder Dispenser Market Market (2019 – 2029) | Where Should Participant Focus To Gain Maximum ROI "), industry representatives and financial institutions. It will also provide the opportunity to educate [customers of the impending security measures](https://www.financedigest.com/the-problem-with-measuring-customer-loyalty-and-how-to-overcome-it.html "The problem with measuring customer loyalty; and how to overcome it") as many still remain blissfully unware of the upcoming changes.

Without an extended deadline, a significant number of transactions could have been abandoned, resulting in a loss of revenue as [well as disgruntled customers](https://www.financedigest.com/why-late-payments-are-hurting-your-customer-as-well-as-your-business.html "Why late payments are hurting your customer, as well as your business").According to an [EU-wide study](https://stripe.com/reports/451-research-sca) by the payment platform Stripe and 451 Research, revenues would have fallen by €57 billion in the first year after the directive came into force.

Needless to say, this could have impacted the retail industry and have had an adverse effect in terms of what the EU wants to achieve with the new directive: more security and protection against fraud; more innovation by registered third parties; and, above all, a better, frictionless, convenient [customer experience](https://www.financedigest.com/the-next-generation-of-customer-experience-in-banking.html "The next generation of customer experience in banking").

**Three [tips for ensuring](https://www.financedigest.com/why-companies-need-to-rethink-retirement-tips-for-ensuring-a-happy-life-in-later-years.html "Why companies need to rethink retirement – Tips for ensuring a happy life in later years") a smooth transition to PSD2 compliance**

This extension may now be in place, but it is not a time for retailers to rest on their laurels. It is time for retailers to [act](https://www.financedigest.com/time-to-act-as-cybercriminals-hot-on-the-heels-of-finance-sector.html "Time to act as cybercriminals hot on the heels of finance sector") and take advantage of the increased time they have been given to prepare for PSD2. But how should they best use the time? Here are three of the most important considerations merchants should take into account:

1. **Start (or continue) with 3DSv2 and create a migration plan:** select a service provider for payment processes and pay particular attention to the extent to which it will enable the smoothest possible shopping experience with [strong authentication](https://www.financedigest.com/strong-customer-authentication-must-be-adopted-to-make-open-banking-a-success.html "Strong Customer Authentication must be adopted to make open banking a Success"). If the [business and/or the service](https://www.financedigest.com/more-companies-investing-heavily-in-business-services-software.html "More Companies Investing Heavily In Business Services Software") provider already rely on 3DS technology, then it would be best to continue working with them, rely on the upcoming version, 3DSv2, and create the migration path from there. If still dependent on standards such as one-time password (OTP), it is still advisable to switch to 3DSv2, as this is the best [technology to ensure a smooth customer](https://www.financedigest.com/verasity-joins-the-brightcove-marketplace-to-provide-customers-with-proprietary-ad-tech-technology.html "Verasity Joins the Brightcove Marketplace to Provide Customers With Proprietary Ad-Tech Technology") experience and comply with the new directive.
2. **Include exceptions to improve the customer experience:** small transactions could be exempt from a two-factor authentication: subscription payments are a good example. It is also possible to white list a trader as a ‘trusted trader’with the [company’s respective credit provider](https://www.financedigest.com/is-it-important-to-provide-media-coverage-for-your-company.html "Is it Important To Provide Media Coverage For Your Company?"), and merchants should be making the most of these opportunities.

**3.Become familiar with the opportunities brought by PSD2:** the new directive aims to create benefits for all involved. This includes more security, lower costs, increased flexibility and more innovation. [Businesses should be thinking about how these benefits](https://www.financedigest.com/how-choosing-the-right-mtd-for-vat-software-can-maximise-business-benefits.html "How choosing the right MTD for VAT software can maximise business benefits") can be best maximised and incorporating such considerations into any migration plan.

The 18-month deadline extension in the UK is considerable, but as with anything, it will [come around soon](https://www.financedigest.com/stocks-shed-gains-treasury-yields-jump-as-fed-signals-rate-hikes-could-come-soon.html "Stocks shed gains, Treasury yields jump as Fed signals rate hikes could come ‘soon’") enough and the time table that businesses not yet ready to meet the [directive](https://www.financedigest.com/britain-aims-for-global-leadership-role-with-ai-safety-summit-2.html) will need to stick to will be tight. Merchants should therefore seize the [opportunity](https://www.financedigest.com/surgical-equipment-market-high-trend-opportunities-offers-future-business-growth-by-2030.html "Surgical Equipment Market High Trend Opportunities Offers Future Business Growth by 2030") offered by the extension and ensure they are offering customers a seamless experience as they make the transition to being PSD2-compliant.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

