Frameworks / PSD2 SCA / PSDTWO-3 PSD2 SCA
Open Banking APIs
PSD2 SCA PSDTWO-3: Common and Secure Communication, API Access for AISPs and PISPs Per PSD2 RTS Articles 19-36: common and secure communication. Requirements include (a) implement dedicated Account Information Services (AIS) + Payment Initiation Services (PIS) interface (API) for Third Party Providers (TPPs) + (b) maintain TPP authentication using eIDAS qualified certificates (QWAC + QSealC) + (c) ensure API availability + performance + (d) maintain fallback mechanism in case of API unavailability + (e) implement consent management for AIS + PIS + (f) maintain audit trail for TPP access + (g) cooperate with TPPs + competent authorities.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 190 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
IS.AR.215 Information Security Incident Response IS.D.OR.210 Information Security Risk Treatment IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.210 Information Security Risk Treatment IS.I.OR.220 Information Security Risk Management IS.I.OR.225 External Reporting FFIEC-03 Risk appetite and tolerance for IT risk FFIEC-18 Ongoing monitoring and assessment FFIEC-20 Exit strategy and transition planning FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared PCI-P2PE-16 Due diligence and onboarding PCI-P2PE-18 Ongoing monitoring and assessment PCI-P2PE-19 Concentration risk management PCI-P2PE-21 Incident detection and classification PCI-P2PE-22 Incident response and containment PCI-P2PE-25 Post-incident review and improvement PCI-PIN-16 Due diligence and onboarding PCI-PIN-18 Ongoing monitoring and assessment PCI-PIN-19 Concentration risk management PCI-PIN-23 Regulatory reporting requirements PCI-PIN-24 Customer notification procedures PCI-PIN-25 Post-incident review and improvement PCI-SSF-03 Risk appetite and tolerance for IT risk PCI-SSF-16 Due diligence and onboarding PCI-SSF-17 Contractual security requirements PCI-SSF-21 Incident detection and classification PCI-SSF-24 Customer notification procedures PCI-SSF-25 Post-incident review and improvement 27557-1 Scope 27557-3 Terms and definitions 27557-6.4 Privacy risk treatment 27557-6.6 Recording and reporting 27557-7.3 Risk-based privacy program implementation API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface API1164-21 TSA Pipeline Security Directive Alignment CPS230-13 Board Accountability for Operational Risk Management CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-37 Service Provider Management Policy CPS230-46 Ongoing Risk Management of Each Material Arrangement CPS234-16 Assessment of Related Party and Third Party Capability CPS234-20 Information Asset Classification CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents IEC62443-21 Supply chain risk management for critical components ISO-22320-4.3 Risk-based approach ISO-22320-5.2 Incident management process ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27019-21 Supply chain risk management for critical components BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities CAT-D1-2 Risk management CAT-D5-1 Incident planning and strategy CAT-ML-2 Evolving 60601-1.4.1 General requirements 60601-1.4.2 Risk management process 60601-1.5.1 General requirements for testing IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62304-7.4 Risk Management of Software Changes ISO23894-5.1 Leadership and Commitment ISO23894-5.2 AI Risk Management Integration ISO23894-5.5 Framework Evaluation PICERL-C2 System Backup PICERL-C3 Long-Term Containment PICERL-L3 Plan Improvement D.1 Incident Response Planning D.2 Incident Reporting UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) BS65000-RM-01 Resilience Journey BS65000-RM-02 Integrated Approach UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) ICP-16 Enterprise Risk Management for Solvency Purposes ICP-8 Risk Management and Internal Controls ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-SA-04 Security Risk Treatment Planning ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.3 Information security risk treatment 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team QATAR-5 Security of Processing QATAR-8 Breach Notification, Compliance, Enforcement IM8-RES.3 Incident Response IM8-TPM.4 Supply Chain Risk Management ISMSP-MS-02 Risk Management ISMSP-SYS-05 Incident Response CYB-5 Cyber Incident Response Plan USMTSA-2 Cybersecurity Assessment and CSO Designation PMF-M.4 Privacy Incident Management AMLCTF-82 Part A Compliance AS9100D-8.1 Operational Planning and Control 4.4.7 Emergency and Incident Response P1-S2 Risk-Management Systems BB-DPA-20 Sections 50-60 - Registration and Responsibilities CA-12 Deploys Through Policies and Procedures CA-ITSG33-SC-01 Security Control Catalogue CJIS-19 Supply Chain Risk Management FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO-15189-5.6 Risk management ISO-20400-4.5 Key considerations for sustainable procurement ISO20000-11 Incident management 27010-16.1 Continuity of Sharing 27400-6.5 Security monitoring and incident response ITIL4-11 Incident management NFPA1600-6.3 Emergency Response Operations NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation PSPF24-1 Security Culture, Governance, Risk Management AIGF-1.1 Risk Management and Internal Controls SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights CRM-3 Risk Management Framework OB-OPS.4 Incident Management USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMPDP-2 Consent and Notice VPSHR-3 Implementation Guidance and Reporting Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 190 it maps to, and the evidence behind each claim, over MCP and REST.