Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM PSD2 Exemption
Identity Beyond IAM

PSD2 Exemption

← Back to Glossary
By NHI Mgmt Group Updated September 19, 2026 Domain: Identity Beyond IAM

A PSD2 exemption is a rule-based exception that allows some transactions to bypass Strong Customer Authentication when they meet specific conditions. Properly used, exemptions can reduce abandonment and improve conversion. Poorly used, they can create compliance risk or allow avoidable fraud through the checkout process.

How PSD2 Exemptions Work

psd2 exemptions are not blanket exceptions, they are specific rule paths inside the Strong Customer Authentication model. They let a payment proceed with reduced friction only when the transaction matches an allowed condition, such as low risk, low value, or a recognised payment pattern.

That matters because the exemption is part of the authentication decision, not a separate convenience feature. The payment journey must still satisfy the rule conditions, and the provider must be able to justify why SCA was not invoked. In practice, the exemption sits at the point where conversion pressure, fraud controls, and regulatory compliance meet.

For the broader control context, the payment authentication expectations align closely with NIST SP 800-63 Digital Identity Guidelines, which help frame how assurance and authenticator strength should be treated when a transaction needs stronger identity proof.

Where Exemptions Are Commonly Used

Most exemption logic appears in checkout, recurring billing, or low-friction consumer payments where the business wants to reduce drop-off without materially increasing abuse. The practical goal is to preserve completion rates while keeping the payment flow inside the allowed regulatory boundaries.

Typical exemption use cases include low-value transactions, recurring payments with established consent, and low-risk transactions assessed by the issuer or acquirer. Each use case depends on the issuer and PSP rules actually supporting the exemption, so implementation is as much about orchestration and message handling as it is about policy.

That operating model is easier to understand when read alongside the payment security controls in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where access control, auditability, and configuration integrity govern transaction handling.

Why Exemptions Matter to Security and Compliance

Used well, exemptions reduce checkout abandonment and keep customer journeys smooth. Used badly, they can become an easy route around authentication, which weakens fraud resistance and can expose the merchant to compliance findings if exemption conditions are stretched or misapplied.

The security issue is not the exemption itself, but the loss of assurance when teams treat it as a default optimisation rather than a conditional control. If transaction-risk scoring is weak, message fields are mis-set, or monitoring is poor, the organisation may create a gap between the intended control design and the actual payment path.

For risk management perspective, NIST Cybersecurity Framework 2.0 provides a useful way to connect governance, risk treatment, and control monitoring around the payment process.

How to Interpret the Term in Practice

PSD2 exemption should be read as a conditional permission, not a guarantee of frictionless payment. The right question is whether the transaction genuinely qualifies, whether the issuer or PSP will accept it, and whether the merchant can evidence that the exemption was applied correctly.

A useful way to think about it is as a control decision with business impact: if you apply exemptions too narrowly, you lose conversion; if you apply them too broadly, you risk avoidable fraud, chargebacks, and regulatory scrutiny. The term therefore sits at the intersection of payment UX, risk governance, and compliance evidence.

Where exemption logic depends on payment authenticity and transaction assurance, NIST SP 800-63 Digital Identity Guidelines is a useful reference point for understanding when stronger authentication is warranted.

Risk and Threat Considerations

PSD2 exemptions can create exposure when teams treat them as a routine shortcut instead of a tightly bounded exception. The main risk is that weak eligibility checks, poor telemetry, or overly aggressive exemption use allow transactions to bypass stronger authentication more often than intended.

Failure mechanism: The exemption is accepted without sufficient control over transaction risk, customer history, or payment context, so the system shifts from a legitimate exception path into an avoidable fraud or compliance weakness.

Impact: Merchants can see higher fraud losses, more chargebacks, weaker dispute positions, and regulatory or scheme scrutiny if exemption decisions cannot be justified or evidenced.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63AAL — Authenticator Assurance LevelsPSD2 exemptions change when stronger authentication is needed for a payment.
Recommendation — Set assurance expectations for payments so exemption use does not weaken required authentication strength.
NIST CSF 2.0GV.RM — Risk Management StrategyPSD2 exemptions require governance over when control exceptions are acceptable.
DE.CM — Continuous MonitoringExemption misuse is only visible when transaction patterns and exception rates are monitored.
Recommendation — Define risk thresholds for exemption use and review them against fraud and compliance outcomes. Monitor exemption frequency, issuer outcomes, and fraud signals to detect drift or abuse.
CIS Controls v86.2 — Establish and Maintain an Inventory of Authorized AssetsPayment flows and decision points need clear ownership and traceability for exemption governance.
8.2 — Audit Log ManagementExemption decisions need evidence of why SCA was bypassed and how the rule was applied.
Recommendation — Document payment exception paths so authorised transaction handling stays accountable and reviewable. Log exemption decisions with enough context to support fraud review and compliance evidence.

Practitioner Guidance

Why practitioners should care: PSD2 exemptions should be governed as a measured control, not a conversion hack. The practical challenge is balancing fewer checkout interruptions with proof that exemption use remains within the rule set and risk appetite.

What to watch for: Watch for unusually high exemption rates, inconsistent acceptance by issuers, and weak logging around why a transaction was exempted. Those are often the first signs that the control is drifting from intended use.

Practitioner takeaway: Treat exemption logic as part of your payment risk decisioning, and make sure the evidence trail is strong enough to explain every bypass of SCA.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org