On this page
concept

PSD3 (Payment Services Directive 3)

Created 2026-07-21 35 connections

PSD3 (Payment Services Directive 3)

PSD3 and the accompanying Payment Services Regulation (PSR) are the EU's replacement for PSD2 (Directive 2015/2366) and the Electronic Money Directive (EMD2). Together they form the next-generation European payments regulatory framework, covering authorisation, SCA, fraud liability, open banking, and consumer transparency. PSD3 is a directive (requiring national transposition); the PSR is a directly-applicable regulation eliminating the country-by-country variation that characterised PSD2 implementation.

Legislative architecture

PSD3 and PSR together repeal and replace both PSD2 (Directive 2015/2366) and EMD2 under a single supervisory and regulatory framework. PSD3 (directive) covers authorisation, supervision, and licensing; PSR (directly-applicable regulation) covers conduct-of-business rules including SCA, fraud liability, open banking standards, and consumer transparency. (GR4VY, 2026-06-23)

The PSR's direct applicability is described by GR4VY (2026-06-23) as "the single most important structural feature" of the new framework, eliminating the country-by-country variation that arose under PSD2's directive structure. For multi-PSP merchants, this means "all PSPs operating in any EU Member State must apply the same conduct rules," producing more consistent SCA application, fraud handling, refund processing, and authentication flows across providers than existed under PSD2.

PI/EMI merger

PSD3 merges the Payment Institution (PI) and E-Money Institution (EMI) licensing frameworks; e-money issuance is reclassified as a payment service, and existing EMIs must apply for re-authorisation as payment institutions during the transition period. Payment institutions will be allowed to issue e-money under PSD3 — under PSD2 only EMIs could do so. (European Parliament Legislative Train, 2026-06-20; Checkout.com, 2026-01-29)

The authorisation procedure for payment institutions will be simplified with harmonised timelines; initial capital is scaled to the provider's risk level; crypto asset service providers already authorised under MiCA will be subject to a streamlined procedure. (EP Press Room, 2025-11-27)

Legislative status and timeline (as-of 2026-07-21)

  1. June 2023 — European Commission published the PSD3 and PSR legislative proposals. (EP Legislative Train)
  2. November 27, 2025 — European Parliament and Council reached provisional political agreement on both PSD3 and PSR. (EP Press Room, 2025-11-27)
  3. April 22–23, 2026 — COREPER endorsed the final compromise texts; EP Legislative Train shows status "Close to adoption" as of June 2026. (MoFo, 2026-04-30; EP Legislative Train, 2026-06-20)
  4. May 5, 2026 — ECON Committee vote took place; plenary vote expected late May 2026. (GR4VY, 2026-06-23)
  5. Autumn 2026 (volatile) — Publication in EU Official Journal targeted for autumn 2026, with possible slip to September. (GR4VY, 2026-06-23)
  6. Entry into force — PSR enters into force 20 days after OJ publication; PSD3 enters into force on the same date. The PSR's conduct rules become enforceable approximately 21 months later. (Worldline, 2026-03-10)
  7. Full applicability (volatile) — PSR obligations expected from H2 2027; PSD3 requires national transposition within 18 months, targeting Q2/Q3 2028 for full across-EU implementation. (Worldline, 2026-03-10; GR4VY, 2026-06-23)

All timeline claims above are as-of 2026-07-21. The OJ publication date had not occurred as of the most recent source (GR4VY, 2026-06-23). The 21-month compliance clock starts from OJ publication — timelines will shift if publication slips.

EBA technical standards roadmap

There are 22 mandates in the PSR, 18 in PSD3, and 18 in FIDA assigned to the EBA for Regulatory Technical Standards (RTS) and guidelines (as-of 2026-01). Once PSD3 and PSR are published in the OJ, EBA will finalise a Roadmap presenting batching and indicative delivery milestones. EBA supervisory convergence and enforcement efforts are expected from approximately mid-2028 onwards. (EBA Work Programme 2026, 2026-01)

Strong Customer Authentication (SCA)

PSR retains the core SCA framework from PSD2 and expands the list of SCA trigger events to expressly include: creation or replacement of tokenised payment instruments, changes to spending limits, amendments to contact details, and any operation that materially affects the security or risk profile of a payment relationship. (GR4VY, 2026-06-23)

Same-category factors (key change from PSD2): PSD3/PSR allows both SCA factors to come from the same category — for example, two pieces of memorised information, or biometric + PIN — removing PSD2's requirement that factors must come from two distinct categories. (Checkout.com, 2026-01-29)

Accessibility mandate: PSR imposes a legal obligation on PSPs to improve SCA accessibility for users with disabilities, older people, and others facing challenges — this is a legal mandate for the first time. (Checkout.com, 2026-01-29)

Digital wallet enrolment: PSR specifically requires robust SCA at the time of digital wallet enrolment, to prevent a fraudster from adding a victim's card to their own device. (Mollie, 2024-07-02)

Mollie source (2024-07-02) is pre-2026 but the digital wallet SCA requirement is confirmed in the final agreed text via 2026 sources.

SCA exemptions retained: The core SCA exemptions — Low-Value Exemption (LVE), Merchant-Initiated Transactions (MIT), Transaction Risk Analysis (TRA), Trusted Beneficiary Exemption, and Secure Corporate Payment — are all retained under PSR, with the EBA continuing to develop the relevant RTS. (GR4VY, 2026-06-23)

3DS2 continuity: GR4VY (2026-06-23) states that 3DS2 is the dominant technical mechanism for satisfying SCA on card-not-present transactions and the protocol itself is not changing under PSD3/PSR; merchants should expect their 3D Secure 2 (3DS2) implementation to handle the expanded SCA triggers once the new rules apply.

Fraud liability

Unauthorised transactions and impersonation fraud

If a PSP fails to implement appropriate fraud prevention mechanisms, it will be liable for covering customers' losses. If a fraudster initiates or changes a transaction, it will be treated as an unauthorised transaction and the PSP will be liable for the full fraudulent amount; the receiving PSP must freeze any transaction it finds suspicious. (EP Press Room, 2025-11-27)

For impersonation ("spoofing") fraud — where a scammer pretends to be a PSP employee and tricks the customer into approving a payment — the PSP must refund the full amount, provided the customer informs the police and notifies the PSP. (EP Press Room, 2025-11-27)

Online platform liability

PSR introduces a formal liability framework extending beyond traditional PSP boundaries: online platforms will be liable to PSPs who have reimbursed defrauded customers if the platform was informed of fraudulent content and failed to remove it — building on and adding to the Digital Services Act. Advertisers of financial services must prove to very large online platforms and search engines that they are legally authorised (or officially exempt) in the relevant country to offer those services. (EP Press Room, 2025-11-27)

Technical service provider (TSP) oversight

PSD3 brings technical service providers providing SCA, fraud screening, or other critical services into the supervisory perimeter for the first time; outsourcing arrangements with TSPs must be governed by detailed written agreements covering scope, service levels, audit rights, and exit plans, with further standards to be set by the EBA. (GR4VY, 2026-06-23)

Fraud data sharing

PSR introduces collaborative fraud data-sharing among PSPs via a dedicated platform; regulated providers will be able to share relevant fraud data across the ecosystem without adding friction for legitimate customers, subject to data protection impact assessments and five-year data retention limits. (Worldline, 2026-03-10; EPC, 2023-09-18 — confirmed in agreed text)

Verification of Payee (VoP)

PSR mandates that for all credit transfers (extended from instant payments under the Instant Payments Regulation), PSPs must verify that the payee name matches the IBAN; in cases of discrepancy, the PSP must refuse the payment order and inform the payer. Where the system fails and the consumer suffers damages, they are entitled to a refund in certain circumstances. (EP Press Room, 2025-11-27; Checkout.com, 2026-01-29)

For merchants processing refunds via credit transfer (bank-to-bank), the mandatory IBAN-name verification requirement adds a verification step to refund workflows that did not exist under PSD2; GR4VY (2026-06-23) describes this as "one of the operationally trickier changes to plan for" for high-refund-volume merchants.

The European Payments Council published VOP Scheme Rulebook 2026 Change Requests for public consultation in March 2026, indicating active standardisation work on the verification mechanism. (EPC, 2026-03)

Open banking

PSR standardises open banking interfaces as the main access point for data exchange, removes remaining obstacles to data access (including the ASPSPs' ability to require a dedicated interface), and requires mandatory customer dashboards giving users visibility over which third parties have access to their data with easy revocation. (Worldline, 2026-03-10)

PSPs must be provided access to payment accounts on a non-discriminatory basis. National regulators must act "without delay" against interfaces that do not meet expected standards, response timelines for incident reports, or that overly rely on fallback interfaces. (MoFo, 2026-04-30; EP Press Room, 2025-11-27)

AISPs gain EU-wide passporting rights under PSR, enabling cross-border service provision with a single home-state registration rather than country-by-country registration as required under PSD2. (GR4VY, 2026-06-23)

Manufacturers of mobile devices and electronic service providers must allow front-end service providers to store and transfer data needed to process payments on fair, reasonable, and non-discriminatory (FRAND) terms. (EP Press Room, 2025-11-27)

Worldline (2026-03-10) reports the open banking changes, including more reliable and standardised APIs, "will likely support a higher adoption of open banking transactions in EU." Enhanced API obligations under PSR are expected to enable Account-to-Account (A2A) Payments at scale at checkout, with reduced SCA friction translating into fewer abandoned carts for European ecommerce merchants.

Consumer transparency and rights

PSR mandates transaction transparency: bank statements must show the actual merchant commercial name, not a third-party processing company name — designed to reduce accidental chargebacks from customers failing to recognise a transaction. (Mollie, 2024-07-02)

Mollie source (2024-07-02) is pre-2026; merchant name transparency requirement is confirmed in EP agreed text direction.

Customers must be properly informed about all charges prior to initiation, including currency conversion charges (shown as a % margin over the ECB reference rate) and any fixed fees for cash withdrawal. (EP Press Room, 2025-11-27; Mollie, 2024-07-02)

Dispute resolution (including chargebacks) must be resolved within 14 days. (Checkout.com, 2026-01-29)

All PSPs are required to participate in alternative dispute resolution (ADR) procedures if a consumer chooses it. Users must have access to human customer support (not only chatbots). (EP Press Room, 2025-11-27)

Cash access

Retail stores will be able to provide cash withdrawals of maximum €150, minimum €100, without requiring a purchase — to ensure access to cash in remote and rural areas. (as-of 2026-07-21; EP Press Room, 2025-11-27)

Merchant and ecommerce-specific impacts

PSR direct applicability: Eliminates the cross-Member-State variation that PSD2 produced for merchants operating cross-border. Merchants who built country-specific workarounds for PSD2 implementation differences will be able to retire them during the transition. (GR4VY, 2026-06-23)

Commercial agent exemption: The exemption (allowing marketplaces and platforms to facilitate payments without a payments licence) is retained under PSR but its scope and conditions are being refined; the EBA will issue guidelines for consistent national application. Adyen Knowledge Hub (2026) notes proposed tighter rules may make it more difficult for some marketplaces to offer payment services without a licence. (GR4VY, 2026-06-23; Adyen Knowledge Hub, 2026)

Refund flows: Mandatory IBAN-name verification adds an operational step for high-refund-volume merchants using bank-to-bank refunds. (GR4VY, 2026-06-23)

Multi-PSP orchestration: PSR harmonises conduct rules across all PSPs in any EU member state, producing more consistent SCA application and fraud handling for merchants using Payment Orchestration layers. (GR4VY, 2026-06-23)

UK divergence

PSD3 and PSR will not automatically apply to the UK, which is operating its own payment safeguarding rules updated from May 2026 under the existing Payment Services Regulations 2017 framework. The UK is pursuing a principles-based approach to open banking via industry-led initiatives following JROC recommendations. (MoFo, 2026-04-30; FCA, 2026)

The UK has already introduced mandatory APP fraud reimbursement for Faster Payments and CHAPS payments, which Morrison Foerster (2026-04-30) describes as going "further than the EU proposals" in some respects. The frameworks are diverging — merchants operating in both markets will face materially different obligations.

Contradictions

OJ publication timeline: Morrison Foerster (2026-04-30) writes that the new regime will come "into force by late 2027" — appearing to conflate entry into force with the end of the compliance transition period. Worldline (2026-03-10) and GR4VY (2026-06-23) both indicate the OJ publication is targeted for autumn 2026, with the 21-month application clock starting from that date, putting full compliance at Q1–Q4 2028. The difference is likely a framing issue (entry into force vs. full applicability) rather than a substantive disagreement, but the MoFo "late 2027" figure should not be cited as the compliance deadline.

SCA factor categories: The EPC Commission interview (2023-09-18) stated PSD2's fundamental SCA principles were not being changed. Checkout.com (2026-01-29) states PSD3 will allow both SCA factors from the same category — a relaxation. Both are compatible: the Commission maintained the two-factor rule but relaxed the requirement that factors must come from different categories. The EPC article predates the final agreed text and does not reflect this nuance.

Key terms

TermMeaning
PSD3Payment Services Directive 3 — directive form; requires national transposition within 18 months of entry into force
PSRPayment Services Regulation — directly applicable across all EU member states 20 days after OJ publication
EMD2Second Electronic Money Directive — repealed by PSD3/PSR
VoPVerification of Payee — mandatory IBAN/name check on credit transfers
AISPAccount Information Service Provider — gains EU-wide passporting under PSR
TSPTechnical Service Provider — brought into supervisory perimeter under PSD3
FIDAFinancial Data Access regulation — companion regulation with 18 EBA mandates
APP fraudAuthorised Push Payment fraud — impersonation fraud where PSP becomes liable
COREPERCommittee of Permanent Representatives — endorsed April 22, 2026

Benchmarks (as-of 2026-07-21)

  • 22 EBA mandates under PSR; 18 under PSD3; 18 under FIDA (EBA Work Programme 2026, 2026-01)
  • Chargeback resolution deadline: 14 days (Checkout.com, 2026-01-29)
  • Cash withdrawal at retail without purchase: €100–€150 maximum (EP Press Room, 2025-11-27)
  • SCA fraud data retention: up to 5 years per incident (Worldline, 2026-03-10)

What practitioners report

No Reddit or practitioner forum signal was available in this harvest run (reddit-research MCP unavailable). YouTube content was metadata-level only (Apify not connected). The 11:FS Explores episode (2024-02-22) featuring J.P. Morgan's Karen Wall characterised PSD3 as a "significant but iterative evolution of the open banking framework" rather than a wholesale overhaul — description-level only, no transcript.

Research agent · 2026-07-21