Everyone in payments is bracing for PSD3. Most people aren’t reading the right document.
The European Commission published its payments overhaul on 28 June 2023 and it arrived in two parts: a Directive, COM(2023) 366 and a Regulation, COM(2023) 367. The Directive lends the package its nickname. The Regulation — the Payment Services Regulation, or PSR — is the instrument that will actually change how your business runs. That distinction is not pedantry. It is the most useful thing to understand about this reform, and it is missing from most of the coverage.
The short version, for anyone who wants the answer and not the tour: PSD3 is not law yet. Negotiators reached a provisional political agreement on 27 November 2025, Parliament’s ECON committee approved the text on 5 May 2026, but formal adoption has not happened as of now — so PSD2 still governs everything you do today. When the package does land, the rules that bite live in the directly applicable PSR, while licensing and supervision sit in the transposable Directive. Plan around the Regulation.
Now the longer version, because the details are where the money is.

The Distinction That Reframes Everything
PSD2 was a Directive. That word did a lot of quiet damage. A directive sets the goal and leaves each member state to write its own law to reach it, which is how «one» European rulebook became twenty-seven slightly different ones, with twenty-seven regulators reading them slightly differently. Anyone who tried to passport a payments product across the bloc has the scar tissue.
The Commission’s structural fix is the interesting part. It split the old rulebook in two. The conduct-of-business rules — how you treat customers, handle fraud, expose data — move into the PSR, a Regulation that applies directly in every member state with no national transposition in between. Authorisation and supervision of payment institutions stay in the PSD3 Directive, which each country still transposes. The Commission’s own framing is that this is the route to stronger harmonisation and enforcement, and for once the framing is right: a Regulation is far harder to dilute on the way to national statute books.
So when a vendor tells you to «get ready for PSD3», ask which half. The licensing half will change your legal entity and your supervisor relationship. The PSR half will change your product, your fraud operations and your APIs. They land differently, and they do not even share a start date — more on that below.
What the PSR Actually Changes
This is the half that touches customers, and it is built around one theme: fraud.
The headline is a liability shift. A large share of fraud losses moves off consumers and onto banks and payment providers, and the categories those providers answer for widen to include social engineering and unauthorised or unwanted payments. In plain terms, the perimeter of «your problem» expands.
The most concrete new duty is name-checking. Every PSP — banks, payment institutions, e-money firms — must run a Verification of Payee check that matches the beneficiary’s name against the IBAN before a credit transfer goes through. On a mismatch, the PSP has to refuse the instruction and warn the payer, and liability attaches when it fails to. The Instant Payments Regulation already imposed this for instant transfers; the PSR stretches it to all of them. If you have ever fat-fingered an account number, you will understand instantly why this matters. If you run the systems that must perform that check in real time, you already know why it frightens people.
The genuinely new ground is the impersonation refund. Where a scammer poses as the customer’s own bank and talks them into approving a payment, the PSR requires the provider to reimburse the full amount, provided the victim reports it to the police and notifies the PSP. This is the line that breaks PSD2’s old wall between «unauthorised» transactions, which were refundable, and «authorised» ones, which were not. It extends reimbursement into exactly the grey zone where modern fraud lives.
The plumbing under all this is a pair of duties most summaries skip. The PSR makes transaction monitoring an express obligation and lets providers share fraud data with each other, and it tells them to warn users about emerging scams — Articles 83 and 84. Worth knowing where the compromise bit: BEUC points out that sharing information about known fraudulent accounts was not, in the end, made mandatory.
Here is the counterintuitive part, and it is the sort of thing that separates someone who read the text from someone who read the webinar. Strong customer authentication — the rule everyone assumes is being rewritten — is barely touched. The core definition of SCA does not change from PSD2; the delta is more detailed obligations and some new exemptions, plus an accessibility requirement that a provider offer more than one authentication method, free, for customers without a smartphone or with a disability. If you were bracing for an SCA overhaul, relax and reallocate the budget.
There is a consumer-rights layer too — clearer treatment when funds are temporarily blocked, better statement transparency, plainer information on ATM charges — the sort of thing that rarely makes headlines and reliably generates complaints when it goes wrong.
Open banking gets its long-promised tightening, and here the drafting is unusually specific. Banks, as account-servicing providers, must run at least one dedicated data-access interface under Article 35. The PSD2 fallback interface — the permanent parallel channel that consumed years of industry argument — is gone; in its place, if the dedicated interface fails, a competent authority may let third parties use the bank’s own customer interface as a contingency, under Article 38(4). Customers get a permission dashboard to see and revoke the access they have granted, and the PSR writes an explicit list of «prohibited obstacles» that banks may not put in a third party’s way. Account-information and payment-initiation providers, in other words, get lower barriers by statute rather than by negotiation.
What PSD3, the Directive, Actually Changes
The Directive is quieter, but not empty. Two changes matter.
First, a merger. PSD3 folds the payment-institution and e-money-institution regimes into one and repeals the E-Money Directive outright; electronic-money firms become a sub-category of payment institution, with their specific requirements — higher initial capital, for instance — preserved. There is a runway: existing licences are grandfathered, with re-authorisation applications due within twenty-four months. If you hold an EMI licence, this is a licensing project, not a product tweak, and it belongs on its own track and its own clock.
Second, access. Non-bank payment providers get the right to reach all EU payment systems, with safeguards, and a secured right to hold a bank account. The mechanism is precise: PSD3 amends the Settlement Finality Directive so that non-bank PSPs can be admitted to designated payment systems directly, closing the exclusion PSD2 left in place. It even loosens safeguarding — providers gain the option, at the central bank’s discretion, to safeguard client funds in a central-bank account under Article 9. This reads as technical and is in fact one of the more consequential lines in the package: a fintech that plugs directly into the rails, instead of renting access from a sponsor bank, has a different cost base and a different strategic position. Banks have spent years as the gatekeepers here. The Directive prises the gate open.
Where It Stands, and When It Bites
Treat every date you read about PSD3 as provisional, including these.
As of Parliament’s 20 June 2026 update, the package is «close to adoption» but not adopted: the November 2025 political agreement and the May 2026 ECON vote are milestones, not the finish line, and until Parliament and Council formally adopt the texts, PSD2 remains the law in force. The commonly cited timeline has Official Journal publication only «towards the end of Q2 2026», the PSR applying eighteen months after entry into force, and the payee-name verification duty and its liability applying twenty-four months after — which realistically pushes full compliance into 2027 and 2028. The application-date estimates are the softest claims in this whole picture; the official sources give no fixed date.
The staggered start gives teams time to plan, but many are not using it well. You do not have to do everything at once. The name-check-and-liability rules, which are the hardest part technically, have a longer 24-month timeline, so the work should be done in that order.
The Fights Worth Watching
If the package were as balanced as the Commission’s press release, nobody would be arguing. Everybody is arguing, and the argument runs along a single axis: does the fraud-liability shift go too far, or not far enough?
The banks say too far. Germany’s banking associations single out the identity-fraud liability rules as the most controversial element of the whole package, on the grounds that they load banks with a risk they cannot control and invite customers to treat their account like all-risk insurance. It is a serious objection, not special pleading: a bank genuinely cannot stop a customer from being talked into authorising a payment.
The lawmakers say that is the point. Parliament’s PSR rapporteur, René Repasi, defends the rebalancing as deliberate — banks should absorb more of the loss precisely when they fall short on fraud prevention. The disagreement is real and clean: one side calls it uncontrollable risk, the other calls it an overdue incentive.
Then consumer advocates say it does not go nearly far enough. BEUC, the EU consumer body, argues that even with the new safeguards, victims will stay liable in most phishing and spoofing cases, and wants the burden of proving fraud or gross negligence moved onto the provider. So the «too far» complaint and the «not far enough» complaint are aimed at the same rule from opposite directions — which is usually the sign of a compromise that will hold.
There is a second, quieter fight over open banking. The Open Finance Association, speaking for the third-party providers, warns that the PSR’s access rules under-deliver: its «latency parity» requirement in Article 36 could even produce performance downgrades versus today’s PSD2 APIs, and critical data such as the account holder’s name is still not reliably exposed. Read that alongside the banks’ complaints and a pattern emerges — nobody thinks the drafting is finished, which is worth remembering before you build too confidently against a text that is still moving.
Where do I land? The structural bet is sound and the fraud shift is defensible; the incentives sit closer to the right place than PSD2’s did. But BEUC has identified the real gap, and the API friction the fintechs describe is not noise. This is a better law than PSD2 with an unfinished edge, not a finished settlement.
One clarification that saves a lot of confusion: none of this is open finance. PSD3 and the PSR govern payment-account data — open banking. The broader regime that would extend data-sharing to savings, mortgages and insurance is a separate, third instrument in the same June 2023 package, FIDA, and it is not part of PSD3 or the PSR. Conflating the two is the most common mistake in this area, and it is worth refusing on principle.
What To Do Now
You cannot comply with a text that is not final, but you can prepare for the parts that will not change in substance.
Map your exposure to the two clocks — the PSR’s eighteen months and the verification duty’s twenty-four — and sequence the work, hardest and latest-dated last. If you run legacy core systems, start there: the law-firm consensus is that the pinch point is technical, not legal, because old cores struggle with the PSR’s real-time obligations like instant name checks and rapid fraud response. If you hold an EMI licence, treat the regime merger as a distinct workstream on the licensing track. If you are a third-party provider, the access gains are real but read Article 36 closely before you assume the APIs will improve. And watch the Official Journal, because the moment of entry into force is the moment both clocks start .
The mistake to avoid is the one this piece opened with: reading PSD3 as «PSD2 with extra fraud rules» and waiting for a directive to trickle through national law. The rules that will reshape your operations are in a Regulation, they apply directly, and the crowd is looking the other way.
FAQ
Is PSD3 law yet?
No. There was a provisional political agreement on 27 November 2025 and an ECON committee approval on 5 May 2026, but the texts haven’t been formally adopted as of now, so PSD2 still applies.
Is there a difference between PSD3 and the PSR?
PSD3 is a Directive (COM(2023) 366) covering licensing and supervision, transposed by each member state; the PSR is a directly-applicable Regulation (COM(2023) 367) carrying the conduct rules — fraud, authentication, open banking.
Does PSD3 replace PSD2?
Yes. The PSD3 Directive would replace PSD2 and also the E-Money Directive, merging the payment-institution and e-money regimes into one.
When Will PSD3 and the PSR Apply?
The dates are not fixed. Commentary expects Official Journal publication towards the end of Q2 2026, with the PSR applying eighteen months later and the payee-verification duty twenty-four months later — so roughly 2027 to 2028.
Is PSD3 the Same As Open Finance / FIDA?
No. Open finance is a separate regulation, FIDA. PSD3 and the PSR cover payment services; do not conflate them.
Sources:
Official EU Legislative Documents
-
European Parliament’s Legislative Train Schedule for the PSR
-
European Parliament’s Legislative Train Schedule for PSD3 (Directive)
ECON Committee Vote Results
-
ECON committee vote on PSD3, 5 May 2026 — passed 50 votes in favour, 3 against, 5 abstentions, under rapporteur Morten Løkkegaard
-
ECON committee vote on the PSR, 5 May 2026 — passed 50 votes in favour, 2 against, 2 abstentions, under rapporteur René Repasi



