Regulation 14 min read 2026-04-27

PSD3 and PSR: The End of PSD2 and a New EU Payments Era

What's changing, why, when it takes effect, and what it means for the market.

TL;DR

  • Reallocating fraud liability toward PSPs and online platforms
  • Opening up open banking through a list of prohibited obstacles and a consent dashboard
  • Opening the payments layer in mobile devices for front-end providers
  • Full harmonisation of market rules: PSR as a regulation applies directly, while PSD3 as a directive requires national transposition

Package architecture: why two acts instead of one

ActFormScopeDirect applicability
PSR (Regulation)RegulationMarket conduct: transparency, user rights and obligations, SCA, open banking, access to payment systems, fraudYes, directly applicable across Member States
PSD3 (Directive)DirectiveLicensing, prudential requirements, and supervision of payment institutions and e-money institutionsRequires transposition into national law

Why the reform: the Commission's diagnosis

  • Fraud risk persists: despite SCA, consumers still fall victim to fraud, and many still prefer cash
  • Open banking underperforms: especially with regard to data access interface quality and performance
  • Supervision is inconsistent: national competent authorities have divergent powers and obligations
  • No level playing field: particularly in TPP access to payment systems

Combating fraud: the deepest change in the package

Verification of Payee (VoP): universal IBAN-name check

Liability shift: impersonation and control failures

Online platform liability: a new layer of accountability

Financial-services advertising: control at the source

Fraud-data sharing among PSPs

Transaction monitoring on steroids

Cooling-off period and SCA redefined

Important nuance:

What didn't make it: Parliament tried to extend liability to impersonation of any other public or private entity (e.g. police, tax authorities). That extension was not retained in the final text. The compromise stops at impersonation of the PSP itself.

Open banking: from PSD2 to PSD3

List of prohibited obstacles (PSR Article 44)

Dedicated interface as the standard

Non-discriminatory account access

Consent dashboard

Mobile-device opening: a breakthrough for front-end wallets

Licensing, capital, and CASPs

Streamlined authorisation procedure

Streamlined path for MiCA-authorised CASPs

Account Information Service Providers (AISPs)

Access to payment systems

Transparency and consumer protection

No surprises on fees

Better cash access

Alternative dispute resolution (ADR)

What hasn't changed, what's missing

  • Open finance: broader sharing of financial data beyond payment accounts is regulated by the separate Financial Data Access Regulation (FIDA), still in trilogue
  • UK-style liability cap: there is no upper limit on PSP liability (in the UK, it is £85,000)
  • Full PSP liability for every fraud: Parliament wanted to go further, but the compromise narrowed it to PSP impersonation
  • Full NFC opening: the text speaks of "data necessary for payment execution," not NFC explicitly; details will come in implementing acts

Timeline: when this takes effect

DateStep
28 June 2023Commission publishes the package proposal
23 April 2024Parliament adopts first-reading position
18 June 2025Council adopts negotiating mandate
27 November 2025Provisional political agreement in trilogue
23-24 April 2026Council publishes final compromise texts (ST-8221/8222-2026-INIT)
Q2 2026 (planned)Publication in the Official Journal of the EU
~Q2 2026 + 20 daysEntry into force of PSR and PSD3
Entry into force + 6 monthsApplication of Settlement Finality Directive amendments
Entry into force + 18 monthsDeadline for transposition of PSD3; application of general PSR provisions
Entry into force + 24 monthsApplication of VoP obligation (IBAN-name check)
~Q1/Q2 2028Full operational applicability of the package

What organisations should be doing now

  • Gap analysis: map PSD3/PSR requirements against the current compliance state, with particular focus on fraud liability, VoP, SCA, data access, and licence scope
  • Investment in fraud prevention: transaction monitoring, behavioural analytics, and real-time intervention are no longer optional
  • VoP readiness: if not yet implemented for SEPA Instant, do it now; PSR extends the obligation to all transfer types
  • Platform compliance: e-commerce, marketplaces, and content platforms need to assess exposure under the new fraud-liability regime
  • Budgeting for 2027-2028: the GDPR, PSD2, and DORA stories show that 18-21 months go faster than they look on a slide
  • Plan in concert with other regulations: DORA (already in force), Instant Payments Regulation (already in force), MiCA, FIDA (in trilogue), the PSD3/PSR package does not exist in isolation

The CEE / Polish perspective

MiCA implementation status

Express Elixir and PISP

KNF and supervision

Closing commentary

The devil, as always with EU regulation, is in the delegated acts and RTSs. The next 18-24 months will reveal whether 1:25 a.m. in Strasbourg was indeed a turning point.

Sources

  • European Parliament Press Release, Payment services deal: More protection from online fraud and hidden fees, 27 November 2025
  • Council of the EU Press Release, Payment services: Council and Parliament agree to step up the fight against fraud and increase transparency, 27 November 2025
  • Council of the EU, Final compromise texts ST-8221-2026-INIT (PSR) and ST-8222-2026-INIT (PSD3), 23-24 April 2026
  • EPRS Briefing PE 775.891, Payment services framework, August 2025
  • European Commission, Proposals COM(2023) 367 (PSR) and COM(2023) 366 (PSD3), 28 June 2023
  • ECB Opinion CON/2024/0013, 30 April 2024
  • European Banking Authority, Response to the Call for Advice, 23 June 2023
  • Legislative procedures: 2023/0210(COD) (PSR), 2023/0209(COD) (PSD3)
  • Industry commentary: Hogan Lovells, Norton Rose Fulbright, William Fry, McCann FitzGerald, Taylor Wessing, Linklaters, OneSpan, Capco, Worldline, ClearingPost, iPiD, Projective Group

Need help with regulatory compliance?

Our consultants can guide you through implementation and regulatory requirements.

Talk to a Consultant