Two interfaces, two jobs
PSD2 solved a different problem. It gave licensed third parties, account information and payment initiation providers, a legal right to access consumer and business accounts through the bank's API, with the customer's consent and strong customer authentication. That opened the door for budgeting apps, pay-by-bank checkouts and accounting integrations. It was never designed for a treasurer who needs to send 20,000 salary payments with dual approval.
Put side by side, the difference is clear:
- Who connects: EBICS connects a company directly with its bank. PSD2 connects a licensed third party with the customer's bank.
- Typical user: EBICS serves corporates, the Mittelstand and service providers acting on their behalf. PSD2 serves consumers, small businesses and the fintechs building for them.
- Legal basis: EBICS is a contract between bank and customer. PSD2 access is a statutory right.
- Volume: EBICS is built for bulk files. PSD2 APIs are built for individual payments and account data.
- Authorisation: EBICS uses bank-issued keys and multi-person signatures. PSD2 relies on strong customer authentication in the bank's own app or website.
EBICS is modernising, not retiring
The next deadline is about content, not transport. From 15 November 2026, the German banking industry will no longer process payment orders in legacy formats such as DTAZV and older pain.001, pain.008 and pain.007 versions, and the new rules on structured addresses apply. The DK notes that this also affects orders submitted earlier with an execution date on or after the cut-off. For many companies, that is a bigger IT project than the protocol switch was.
PSD3 and the PSR fix open banking, but do not widen it
The changes target PSD2's well-known weak spots. Bank APIs will have to perform as well as the bank's own customer channels, measured against harmonised indicators. Customers will get a dashboard to see and revoke third-party access. Name-to-IBAN matching becomes mandatory for credit transfers, and victims of bank impersonation fraud gain stronger refund rights. These are real improvements for consumer open banking. None of them turns a PSD2 interface into a corporate treasury channel. The US is taking a different path: there, banks such as JPMorgan have started charging fintechs for data access.
FiDA was the bridge. It just got shorter.
What this means for builders
- Serving corporates? Plan for EBICS, not instead of APIs but next to them. Treasury, ERP and payroll use cases still depend on it.
- Serving consumers and small businesses? PSD3 and the PSR will make APIs more reliable and fraud rules stricter. Budget for the new dashboard and liability rules now.
- Watch the formats. ISO 20022 changes and structured addresses will cause more failed payments in the coming months than any protocol debate.
This article was researched and written with AI assistance for FinTech Weekly. All facts are linked to their sources in the text.