Industry Analysis

PSD3 & PSR: What Every Payment Provider Needs to Know (2026 Compliance Guide)

The complete guide to PSD3 and PSR for payment providers. Timeline, SCA changes, fraud liability shift, Verification of Payee, open banking APIs, and a practical readiness checklist — based on the November 2025 provisional agreement.

PaymentProviders Team April 5, 2026·18 min read

PSD3 is the most significant overhaul of European payment regulation since PSD2 launched Strong Customer Authentication and Open Banking in 2018. If you process payments in the EU — or serve EU customers from anywhere in the world — the new rules will affect your business.

On 27 November 2025, the European Parliament and Council reached provisional political agreement on both PSD3 and its companion regulation, the Payment Services Regulation (PSR). Publication in the EU Official Journal is expected by summer 2026, which starts an 18-month countdown to compliance. That puts the first hard deadline around early 2028 — closer than most teams realize.

This guide breaks down what's actually changing, who's affected, and what payment providers need to do now. We've focused on practical impact rather than legal abstractions, with links to relevant providers in our directory of 1,100+ payment processors.

PSD3 vs PSR: Why There Are Two Regulations

The first thing to understand is that PSD3 is not a single regulation — it's a package of two:

PSD3 (Directive) covers licensing, supervision, and the authorization framework for payment institutions. As a directive, each EU member state must transpose it into national law within 18 months of entry into force. This means implementation may vary slightly between countries.

PSR (Payment Services Regulation) covers the operational rules: Strong Customer Authentication, fraud prevention, liability, open banking APIs, and consumer protections. As a regulation, it applies directly and uniformly across all 27 EU member states — no transposition needed, no national variation.

This split is deliberate. PSD2's biggest weakness was inconsistent implementation across member states. By putting the most critical operational rules into a directly-applicable regulation, the EU eliminates the patchwork enforcement that frustrated payment providers for years.

Timeline: Key Dates for Payment Providers

Milestone Expected Date What Happens
Provisional political agreement 27 November 2025 Done — texts agreed between Parliament and Council
Official Journal publication Summer 2026 Final texts published; compliance clock starts
PSR applies + PSD3 transposition deadline ~Early 2028 (18 months after publication) Core operational rules become enforceable
IBAN/Name verification obligation ~Mid 2028 (24 months after publication) All credit transfers require Verification of Payee
EMI re-authorization deadline 24–30 months after publication Existing e-money institutions must re-apply under PSD3

The 6-month gap between general PSR application and the Verification of Payee deadline is worth noting — it creates a sequencing challenge where most rules are live but the full verification infrastructure has an extra grace period.

What this means in practice: If you're a payment provider, 2026 is your planning year, 2027 is your implementation year, and early 2028 is when regulators start checking your homework.

The 6 Biggest Changes That Affect Payment Providers

1. Strong Customer Authentication Gets Smarter

PSD2's SCA requirements were a blunt instrument — two-factor authentication for almost everything, with limited exemptions that were inconsistently applied. PSD3 keeps the security foundation but makes it significantly more flexible.

Behavioral biometrics are now officially recognized. The PSR formally expands the definition of "inherence" (the biometric authentication factor) to include behavioral and environmental characteristics: typing cadence, device handling patterns, geolocation, spending behavior, and session context. This means a combination of fingerprint plus behavioral pattern analysis counts as valid two-factor authentication — no SMS codes required.

New flexibility in factor combinations. Under PSD3, payment providers can use up to two authentication elements from the inherence category (for example, fingerprint plus behavioral biometrics), but cannot double up on possession or knowledge factors. This opens the door to frictionless authentication that's actually more secure than the password-plus-SMS approach most providers use today.

Transaction Risk Analysis gets teeth. The TRA exemption — which lets low-risk transactions skip SCA — is reinforced and expanded. Payment providers with consistently low fraud rates may qualify for additional exemptions, but the monitoring requirements are stricter. Your fraud detection systems need to analyze environmental and behavioral characteristics of the payer, not just transaction history.

The delegation model changes. When payment providers delegate SCA to third parties (digital wallets, payment gateways, authentication vendors), PSD3 now classifies this as formal outsourcing. That triggers compliance with EBA outsourcing guidelines and DORA requirements, including detailed written agreements, SLAs, exit plans, and unrestricted audit rights for regulators. If you use a third-party 3DS provider, this affects you.

Providers like Checkout.com are already investing heavily here — their Fraud Detection Pro uses network-wide machine learning to power real-time risk scoring that can authenticate transactions in milliseconds using device biometrics and behavioral signals.

2. Verification of Payee Becomes Mandatory for All Transfers

Under PSD2, you could send money to any IBAN without the system checking whether the account name matched. This made misdirected payments and fraud trivially easy. PSD3 fixes this with mandatory Verification of Payee (VoP) for all credit transfers across the EU.

How it works: Before a transfer executes, the payer's PSP must verify that the payee's name matches the IBAN. The system returns one of four results:

  • Match — Name and IBAN align, transfer proceeds
  • Close Match — Minor discrepancy (typo, abbreviation), payer is warned but can proceed
  • No Match — Significant mismatch, payer receives a clear warning
  • Unable to Verify — System can't confirm, payer is informed

Scope expansion from IPR: The EU Instant Payments Regulation (which entered into force in April 2024) already mandated VoP for euro-denominated instant credit transfers. PSD3 extends this to all credit transfers — instant or standard, any currency. This is a massive expansion that requires every PSP to implement verification infrastructure, not just those offering instant payments.

The liability hook: If a PSP fails to flag a name/IBAN mismatch and the payer sends money to the wrong account, the PSP bears liability for misdirected funds. This makes VoP implementation a financial risk issue, not just a compliance checkbox.

VoP services must be free for consumers and operate within seconds. The technical burden falls entirely on payment providers.

3. Fraud Liability Shifts Toward Payment Providers

This is arguably the most impactful change for payment processors. PSD3 fundamentally resets who bears the cost when fraud happens.

Impersonation fraud (spoofing) gets a new liability rule. For the first time, EU regulation mandates that PSPs must reimburse customers who fall victim to impersonation fraud — where a scammer poses as the bank or payment provider to trick the customer into authorizing a payment. Victims receive full refunds if they report to police and notify their PSP. The PSP can only refuse if it proves the customer acted with gross negligence — a deliberately high bar.

Authorized Push Payment (APP) fraud is directly addressed. Under PSD2, SCA did little to prevent APP scams because the customer was properly authenticated — they were just tricked. PSD3 explicitly tackles this gap with new refund rights and monitoring obligations.

The SCA liability hook: If a PSP fails to properly apply Strong Customer Authentication and fraud occurs, the PSP bears the full loss. This isn't new in principle, but PSD3 expands the scope and makes enforcement more consistent through the PSR's direct applicability.

14-day response window. When a customer reports fraud, the PSP must either issue a refund or provide a reasoned refusal with redress information within 14 business days.

Cross-ecosystem liability. PSD3 opens the door for regulators to hold telecom networks and messaging platforms accountable if they enabled fraud through, for example, number spoofing used in phishing attacks.

For payment processors, the message is clear: invest in fraud prevention now, or pay for fraud losses later. Providers with strong real-time monitoring — like Adyen with its revenue-protect suite and Stripe with Radar — have a structural advantage here.

4. Open Banking APIs Get Standardized (For Real This Time)

PSD2's promise of open banking was undermined by inconsistent API implementations across banks. Some banks built dedicated interfaces that barely worked, others added friction like mandatory re-authentication every 90 days, and the "fallback" mechanism that allowed screen scraping created security concerns. PSD3 takes a harder line.

Dedicated interfaces with performance parity are now mandatory. Banks must provide APIs that perform as well as their own customer-facing interfaces. The fallback mechanism from PSD2 is removed and replaced with structured contingency and supervisory mechanisms — if a bank's API goes down, third-party providers can use alternative interfaces, and regulators get involved faster.

Quarterly performance reporting. Banks must publish reports on API availability, uptime, and performance metrics every quarter. This creates public accountability that was entirely absent under PSD2.

Permission dashboards for consumers. Banks must offer customers a dashboard to monitor which third-party providers have access to their data and revoke access in real time. This improves on PSD2's relatively opaque consent model.

Anti-obstruction rules are strengthened. Banks are explicitly prohibited from adding friction like mandatory redirect flows or excessive re-authentication to third-party access. The supervisory response to non-compliance is faster.

For providers operating in the open banking space, this is a significant improvement. Mollie has already published detailed guides on PSD3's implications for platforms and marketplaces, and their Mollie Connect product is designed for compliant fund routing under the new rules.

5. EMI and PI Licensing Merges Into One Framework

PSD3 merges the Electronic Money Directive (EMD2) into the payment services framework, creating a single licensing regime. Electronic Money Institutions (EMIs) become a sub-category of payment institutions rather than a separate regulatory species.

What this means practically:

  • Existing EMIs must re-apply for authorization under PSD3 within 24 months of entry into force (extendable to 30 months at member state discretion)
  • The re-application requires updated governance, DORA-compliant ICT frameworks, revised safeguarding policies, and updated capital requirements
  • New applicants only need one license instead of choosing between PI and EMI authorization

For established providers like Adyen, Mollie, and Checkout.com — all of which hold various EU licenses — this means a re-authorization process that requires dedicated compliance resources. For smaller fintechs, the cost of re-authorization could accelerate market consolidation.

6. DORA Creates an Operational Resilience Layer

The Digital Operational Resilience Act (DORA) isn't part of PSD3, but the two regulations are designed to work together. DORA covers ICT risk management, incident reporting, and third-party service provider oversight for all financial entities — including payment institutions.

Key interaction: PSD2's incident reporting rules cease to apply for entities now subject to DORA. Payment providers need a single, unified approach to operational resilience rather than patching together PSD3 and DORA compliance separately.

Third-party oversight matters. If your payment infrastructure depends on cloud providers, authentication vendors, or fraud detection services, DORA requires formal due diligence, written agreements, and unrestricted audit rights. This aligns directly with PSD3's new outsourcing classification for delegated SCA.

How Major Providers Are Preparing

The largest payment processors have already published their PSD3 readiness strategies. Here's what they're doing:

Stripe has published guidance specifically for platforms and marketplaces, highlighting the need to audit use of the commercial agent exemption — a PSD2 workaround that PSD3 narrows significantly. Their existing SCA and Open Banking tooling is being aligned with PSD3 requirements.

Adyen is investing in Confirmation of Payee (their VoP implementation), with pilot programs showing significant fraud reduction. Their single-platform approach — one integration for online, mobile, and in-store — positions them well for unified compliance.

Checkout.com is emphasizing the balance between compliance and customer experience. Their approach combines real-time multi-layered risk scoring (ML-powered), device biometrics for faster authentication, and dynamic routing to maintain high approval rates while meeting stricter SCA requirements.

Mollie has published the most detailed merchant-facing compliance content, including step-by-step checklists and specific guidance on auditing commercial agent exemptions and updating bank statement descriptors. Their platform compliance tooling through Mollie Connect is explicitly designed for PSD3 readiness.

Impact by Business Type

E-Commerce Merchants

Most of the compliance burden falls on your payment provider, not on you directly. But you'll feel the effects:

  • Checkout friction may decrease. Behavioral biometrics means fewer SMS codes and app switches during authentication. Your conversion rates could actually improve.
  • Fraud chargebacks shift. If your PSP implements SCA correctly, they bear more liability for fraud. This could reduce your chargeback costs.
  • VoP for bank transfers. If you accept SEPA credit transfers, your customers will go through name verification. Make sure your business name matches what's on your bank account.

SaaS and Subscription Businesses

  • Merchant-initiated transactions (MITs) under PSD3 require SCA only at mandate setup, not for subsequent recurring charges. This is largely unchanged from PSD2 but is now clarified in the directly-applicable PSR.
  • Platform exemptions narrow. If you're a marketplace or platform using the commercial agent exemption to avoid PSD2 licensing, PSD3 tightens the criteria. Audit your setup now — providers like Stripe and Paddle have published specific guidance on this.

High-Risk Industries (Gambling, Crypto, Adult)

PSD3 hits high-risk sectors hardest:

  • Enhanced fraud monitoring requirements increase compliance costs. The adult industry already faces chargeback rates 5-7x higher than standard e-commerce, and PSD3's fraud prevention mandates add operational complexity.
  • Crypto faces a dual licensing challenge. Crypto asset service providers managing stablecoin custody and transfers may need both a MiCA license and a PSD3 payment services license. The combined capital requirements total approximately EUR 250,000. The EBA issued a No-Action Letter addressing this overlap, but the long-term solution requires legislative amendment.
  • Market consolidation is likely. Smaller high-risk processors may exit the EU market due to compliance costs, concentrating volume among larger, specialized providers.

Non-EU Businesses Serving EU Customers

You're not exempt. If you process payments for EU consumers, you need to either comply with PSD3 requirements directly or partner with EU-regulated payment service providers. The practical options: adopt EU-compliant security measures and authentication processes, or work exclusively through EU-licensed intermediaries like Adyen, Stripe, or Checkout.com.

The UK Divergence Factor

Post-Brexit, the UK retained its onshored version of PSD2 and is conducting its own independent review. In February 2026, HM Treasury, the FCA, PSR, and Bank of England published a Payments Forward Plan covering 2026-2028.

The substantive rules are converging — fraud liability, SCA flexibility, and open banking access are heading in similar directions. But the structural frameworks are diverging — different licensing categories, prudential requirements, and supervisory architecture.

For providers operating in both markets, this means maintaining compliance with two increasingly separate regulatory regimes. Budget accordingly.

What's Coming Next: FIDA and Open Finance

PSD3 modernizes payment services. The Financial Data Access Regulation (FIDA) extends the same principles to the entire financial ecosystem — insurance, investments, pensions, and lending.

FIDA trilogue negotiations began in April 2025, with adoption expected in the first half of 2026 and full implementation 24 months later. The regulation requires financial institutions to share customer data through standardized APIs upon customer request, with real-time monitoring dashboards and strict consent controls.

For payment providers, FIDA represents both a regulatory expansion and a business opportunity. The data-sharing infrastructure you build for PSD3 compliance becomes the foundation for offering services across the broader financial data ecosystem.

Your PSD3 Readiness Checklist

Now (2026) — Plan and Assess:

  • Map your current PSD2 compliance posture against PSD3/PSR requirements
  • Identify which of your services require re-authorization (especially if you hold an EMI license)
  • Audit your use of exemptions — particularly the commercial agent and limited network exemptions that PSD3 narrows
  • Evaluate your SCA implementation and identify gaps in behavioral biometrics and TRA capabilities
  • Review your fraud detection and monitoring infrastructure against the new liability framework

Early 2027 — Build and Test:

  • Implement Verification of Payee infrastructure for all credit transfers (not just instant payments)
  • Upgrade fraud monitoring to include environmental and behavioral analysis
  • Update customer consent and permission management dashboards for open banking
  • If delegating SCA, formalize outsourcing agreements per DORA and EBA guidelines
  • Train customer support teams on new fraud refund obligations and the 14-day response window

Late 2027 / Early 2028 — Go Live:

  • Complete re-authorization applications (EMIs)
  • Activate VoP on all credit transfer flows
  • Ensure quarterly API performance reporting is operational
  • Run final testing of fraud liability workflows

FAQ

Does PSD3 apply to businesses outside the EU?

Not directly — PSD3 is EU legislation. But if you serve EU customers, your payment flows must comply. In practice, most non-EU businesses handle this by using EU-licensed payment providers like Stripe, Adyen, or Mollie that handle compliance on their behalf.

Will PSD3 increase payment processing costs?

For large providers, compliance investment will be significant — potentially millions of euros for infrastructure upgrades, re-authorization, and staffing. Whether those costs get passed through to merchants depends on the provider. Smaller providers face disproportionate costs, which may accelerate consolidation.

For merchants, the net effect could be neutral or positive: stricter fraud prevention should reduce chargeback costs, and behavioral biometrics should reduce checkout friction.

What's the difference between PSD3 and PSR?

PSD3 is a directive covering licensing and supervision — it needs to be transposed into national law by each member state. PSR is a regulation covering operational rules (SCA, fraud, liability, APIs) — it applies directly and uniformly across the EU. Together, they replace PSD2 and the Electronic Money Directive.

How does PSD3 affect open banking?

PSD3 strengthens open banking by mandating standardized APIs with performance parity, removing the PSD2 fallback mechanism, requiring quarterly performance reporting, and giving consumers real-time dashboards to manage third-party access. The intent is to deliver on the promise PSD2 made but couldn't fully execute.

Is the UK following PSD3?

No — the UK is developing its own payment services modernization through the Payments Forward Plan (2026-2028). The substantive rules are converging with PSD3 on fraud liability and SCA, but the regulatory structures are diverging. Providers serving both markets need separate compliance strategies.


This article reflects the PSD3/PSR provisional agreement text as of April 2026. Final texts are expected in the Official Journal by summer 2026, and specific requirements may be refined through EBA Regulatory Technical Standards. We'll update this guide as milestones are reached. For provider-specific compliance details, see each provider's profile in our directory of 1,100+ payment providers.

Written by
PaymentProviders Team

The research desk behind the directory — we track fees, coverage and licensing across 1,200+ payment providers.

View all articles →

Ready to compare providers?

Use our directory to compare payment providers side by side.

PaymentProviders.io

The open directory of payment providers, gateways and processors. Helping merchants find, platforms integrate, and providers grow.

© 2026 EJ Tech AB · Arboga, Sweden · Org.nr 559470-0154

PaymentProviders.io is operated by EJ Tech AB and is not affiliated with or endorsed by any listed provider; third-party logos and trademarks belong to their respective owners.

Disclaimer: provider information is compiled from public sources and automated research, and only listings marked as claimed are maintained by the provider itself. We work hard to keep this data complete, accurate and useful, but we cannot verify every detail and accept no liability for errors or omissions. Always confirm terms directly with the provider. Spotted something wrong? Tell us — providers can claim their listing.