Lex Browse everything
For developers

Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366

as it stood on 2023-09-12, permalink: /eu-eurlex/32018r0389/2023-09-12--416f01deae5bfb61b66b86ce30373f53044de3f485f01bc199cdcd520690e160

2017-11-272023-09-12
Browse 3 dated versions

3 versions · choose a date to read the law as it stood that day · the one you are reading

Official publisher wording state selected for 2023-09-12. This is the consolidated version dated 2023-09-12. Its interval on Lex's publisher-version axis is publisher version 2023-09-12 → latest held; that is not a claim about entry into force or application.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each displayed provision carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 39 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 10a Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38

CHAPTER I — GENERAL PROVISIONS

Article 1, Subject matter #art_1
Article 2, General authentication requirements #art_2
Article 3, Review of the security measures #art_3

CHAPTER II — SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION

Article 4, Authentication code #art_4
Article 5, Dynamic linking #art_5
Article 6, Requirements of the elements categorised as knowledge #art_6
Article 7, Requirements of the elements categorised as possession #art_7
Article 8, Requirements of devices and software linked to elements categorised as inherence #art_8
Article 9, Independence of the elements #art_9

CHAPTER III — EXEMPTIONS FROM STRONG CUSTOMER AUTHENTICATION

Article 10, Access to the payment account information directly with the account servicing payment service provider #art_10
Article 10a, Access to the payment account information through an account information service provider #art_10a
Article 11, Contactless payments at point of sale #art_11
Article 12, Unattended terminals for transport fares and parking fees #art_12
Article 13, Trusted beneficiaries #art_13
Article 14, Recurring transactions #art_14
Article 15, Credit transfers between accounts held by the same natural or legal person #art_15
Article 16, Low-value transactions #art_16
Article 17, Secure corporate payment processes and protocols #art_17
Article 18, Transaction risk analysis #art_18
Article 19, Calculation of fraud rates #art_19
Article 20, Cessation of exemptions based on transaction risk analysis #art_20
Article 21, Monitoring #art_21

CHAPTER IV — CONFIDENTIALITY AND INTEGRITY OF THE PAYMENT SERVICE USERS' PERSONALISED SECURITY CREDENTIALS

Article 22, General requirements #art_22
Article 23, Creation and transmission of credentials #art_23
Article 24, Association with the payment service user #art_24
Article 25, Delivery of credentials, authentication devices and software #art_25
Article 26, Renewal of personalised security credentials #art_26
Article 27, Destruction, deactivation and revocation #art_27

CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 1 — General requirements for communication

Article 28, Requirements for identification #art_28
Article 29, Traceability #art_29

CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 2 — Specific requirements for the common and secure open standards of communication

Article 30, General obligations for access interfaces #art_30
Article 31, Access interface options #art_31
Article 32, Obligations for a dedicated interface #art_32
Article 33, Contingency measures for a dedicated interface #art_33
Article 34, Certificates #art_34
Article 35, Security of communication session #art_35
Article 36, Data exchanges #art_36

CHAPTER VI — FINAL PROVISIONS

Article 37, Review #art_37
Article 38, Entry into force #art_38
Provenance and validity dates, identifier, hash
as of2023-09-12 → this publisher state was selected
publisher statepublisher version 2023-09-12 → latest held publisher-asserted
typeREG_DEL Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)
languageen
published2023-09-12
lex_ideu-eurlex:32018r0389:2023-09-12--416f01deae5bfb61b66b86ce30373f53044de3f485f01bc199cdcd520690e160
record sha2560b8350f25ab1f084876aa6b8f9fe1f182911b4f53d3e6fb349afcfb79760e03d
New here? What am I looking at?

This is an official consolidated text: the original act with later amendments merged by EUR-Lex for the date shown above.

The consolidation date is not an entry-into-force or application date. It identifies a publisher wording state. The authentic legal acts remain those published in the Official Journal; Lex preserves the consolidated wording, source and hashes as a reading and comparison aid.

Each displayed provision carries its own hash so you can verify that Lex served the indexed text unchanged, here is how.

← previous version (2023-07-25)   what changed?   timeline

tierA, publisher-supplied consolidated wording-state dates
history beginspublisher
index built2026-08-15T09:01:06Z · corpus e9c4df0981c855855a1a28218cf086ddeb5bb691
stamp signaturevalid (ECDSA-P256)