EBICS vs. PSD2: Europe Built Two Bank Interfaces. They Were Never Meant to Compete.

EBICS vs. PSD2: Europe Built Two Bank Interfaces. They Were Never Meant to Compete.

Open banking was supposed to make old bank channels obsolete. Eight years after PSD2, corporates still move their money over EBICS, and the next wave of EU rules (PSD3, the PSR and a slimmed-down FiDA) is more likely to cement that split than end it.

Every few months, someone on LinkedIn declares that APIs will kill EBICS. The argument sounds convincing: PSD2 forced every bank in the EU to open an interface to third parties, so why would a treasurer still use a file-based protocol designed in Germany in the mid-2000s? Yet in 2026, EBICS is not shrinking. It has just gone through a major version upgrade, and German banks are now counting down to a format deadline on 15 November 2026. Both standards are alive because they solve different problems.

Two interfaces, two jobs

EBICS (Electronic Banking Internet Communication Standard) is a direct channel between a company and its bank. It is used in Germany, France, Switzerland and Austria, and it carries the heavy lifting of corporate treasury: bulk SEPA payments, direct debit files, account statements in ISO 20022 formats, and distributed electronic signatures, where one person uploads a payment file and two authorised signatories release it later. The company owns the connection. There is no third party in between unless the company chooses one.

PSD2 solved a different problem. It gave licensed third parties, account information and payment initiation providers, a legal right to access consumer and business accounts through the bank's API, with the customer's consent and strong customer authentication. That opened the door for budgeting apps, pay-by-bank checkouts and accounting integrations. It was never designed for a treasurer who needs to send 20,000 salary payments with dual approval.

Put side by side, the difference is clear:
  • Who connects: EBICS connects a company directly with its bank. PSD2 connects a licensed third party with the customer's bank.
  • Typical user: EBICS serves corporates, the Mittelstand and service providers acting on their behalf. PSD2 serves consumers, small businesses and the fintechs building for them.
  • Legal basis: EBICS is a contract between bank and customer. PSD2 access is a statutory right.
  • Volume: EBICS is built for bulk files. PSD2 APIs are built for individual payments and account data.
  • Authorisation: EBICS uses bank-issued keys and multi-person signatures. PSD2 relies on strong customer authentication in the bank's own app or website.

EBICS is modernising, not retiring

EBICS 3.0, available since November 2018, replaced the separate German, French and Swiss variants with a single European standard. It introduced Business Transaction Formats instead of cryptic order types, X.509 certificates with at least 2048-bit keys, and XML-based customer protocols that machines can read reliably. German banks began winding down EBICS 2.5 in late 2025.

The next deadline is about content, not transport. From 15 November 2026, the German banking industry will no longer process payment orders in legacy formats such as DTAZV and older pain.001, pain.008 and pain.007 versions, and the new rules on structured addresses apply. The DK notes that this also affects orders submitted earlier with an execution date on or after the cut-off. For many companies, that is a bigger IT project than the protocol switch was.

PSD3 and the PSR fix open banking, but do not widen it

The EU's next payments package reached a provisional agreement in November 2025, and the final compromise texts were circulated in April 2026. Formal adoption is still pending, and most rules are expected to apply around 2028.

The changes target PSD2's well-known weak spots. Bank APIs will have to perform as well as the bank's own customer channels, measured against harmonised indicators. Customers will get a dashboard to see and revoke third-party access. Name-to-IBAN matching becomes mandatory for credit transfers, and victims of bank impersonation fraud gain stronger refund rights. These are real improvements for consumer open banking. None of them turns a PSD2 interface into a corporate treasury channel.

FiDA was the bridge. It just got shorter.

The one law that could have pushed open data into corporate banking is the Financial Data Access Regulation (FiDA). After negotiations stalled in June 2025, the Commission published a revised proposal in April 2026. The new version is deliberately narrower: large corporates are among the segments carved out, historical data requirements shrink, and the rollout is phased over roughly four years. For corporate banking, the message is clear. There will be no regulatory mandate to replace direct bank channels any time soon.

What this means for builders

  • Serving corporates? Plan for EBICS, not instead of APIs but next to them. Treasury, ERP and payroll use cases still depend on it.
  • Serving consumers and small businesses? PSD3 and the PSR will make APIs more reliable and fraud rules stricter. Budget for the new dashboard and liability rules now.
  • Watch the formats. ISO 20022 changes and structured addresses will cause more failed payments in the coming months than any protocol debate.
EBICS versus PSD2 was always a false duel. Europe has one rail where the customer holds the keys and one where regulated third parties get access on the customer's behalf. That split also matters for a broader question the industry is asking right now: who controls financial data and infrastructure in Europe? We look at that in our piece on data sovereignty in European fintech.

This article was researched and written with AI assistance for FinTech Weekly. All facts are linked to their sources in the text.

Related Articles