PSD3 updates 2026: What's confirmed so far, and what to prepare for now
Industry
Updated 20 Aug 2026
4 min

PSD3 isn't law yet, but it's close. Here's what to know before the final text lands.
As of July 2026, PSD3 is close to adoption but not yet law. The Third Payment Services Directive (PSD3) and its companion regulation, the Payment Services Regulation (PSR), have cleared political agreement and committee approval – but formal adoption and Official Journal publication .
The rules are stable enough to act on now, even though the compliance clock hasn't started. Here's what's confirmed, and what to actually do about it.
Key PSD3 changes at a glance
- Status: Political agreement reached (November 2025), ECON approved the text (May 2026) – formal adoption and Official Journal publication still pending.
- Timeline: Most provisions are expected to land in 2027–2028, though the exact dates depend on when the final text is published.
- Stronger customer authentication (SCA): Firmer accessibility requirements for customers with disabilities, older customers, and others facing barriers.
- Fraud liability: become liable for losses tied to poor fraud controls, plus new mandatory reimbursement for impersonation ("spoofing") fraud specifically.
- : Stricter requirements for API reliability and performance, and a dedicated dashboard for managing account information and payment initiation permissions.
- Transparency and consumer protection: Clearer upfront currency-conversion fees, plus mandatory human customer support and alternative dispute resolution (ADR).
Where PSD3 and PSR stand now
(a directive, transposed into national law) and the (a regulation, applying directly EU-wide) together replace – updating licensing rules for payment institutions, fraud liability, authentication, and transparency.
Here's where the legislative process stands, and what's still ahead:

Most PSR and PSD3 rules apply 21 months after entry into force. Verification of Payee gets extra runway – 27 months – since providers need that time to build the account-matching checks it requires.
PSD3 vs. PSD2 vs. PSR
Here's how the three instruments differ:
| PSD2 (current) | PSD3 | PSR | |
| Type | Directive | Directive | Regulation |
| How it applies | Transposed into national law by each EU member state, with some variation | Transposed into national law – amends/recasts the licensing and supervisory parts of PSD2 | Directly applicable EU-wide, no national transposition – covers conduct-of-business rules like SCA, fraud liability, open banking |
| What it covers | Licensing, supervision, conduct rules – all in one instrument | Licensing, authorization, supervision of payment institutions | SCA, fraud liability, open banking access, transparency |
Core insight: The substance of PSD3/PSR has been locked in since November 2025 – only the calendar keeps moving. Prepare for the substance now, and don't wait for an exact date.
What actually changes
Stronger customer authentication
SCA under PSD2 requires at least two authentication factors from three different categories: knowledge (something only the user knows), possession (something only the user has), and inherence (something the user is).
PSD3 keeps SCA in place but strengthens accessibility: providers must improve authentication for customers with disabilities, older customers, and others facing barriers, backing it with better fraud-mitigation tools.
PSD3 also clarifies merchant-initiated transactions (MITs): SCA is required once, at mandate setup, not on every subsequent renewal.
At the same time, MOTO transactions (mail or phone orders) remain outside SCA's scope. PSR formalizes this for the first time – only the order's placement needs to be non-digital, not its authentication or execution.
Expanded fraud liability
PSD3 and the PSR raise the stakes on fraud prevention. Providers must verify that a payment's payee name matches its account identifier, refuse the payment on a mismatch, and notify the payer. Providers that skip this or don't properly monitor transactions become liable if a customer loses money.
Worth noting: verification of Payee isn't brand new – it's already mandatory for instant payments under the separate , free of charge for euro-area providers since October 9, 2025. PSD3/PSR's version reaches further, so confirm with your provider which rules apply to which transaction types.
There's also mandatory reimbursement for impersonation ("spoofing") fraud, where a scammer poses as a bank or provider to trick a customer into authorizing a payment. That's a meaningful shift from today's rules, where this kind of fraud often left the customer holding the loss.
Open banking, standardized
PSD3 raises the bar on bank API reliability and security for third-party providers, and adds a dashboard requirement. So customers can see who has access to their payment data and cut it off in one place.
That reliability push reaches account-to-account like Pay by Bank, which run on these same APIs.
Transparency, customer support & ADR
PSD3/PSR tightens transparency and strengthens consumer protection on several fronts.
Providers should disclose currency-conversion costs upfront – including exchange rate margins and estimated transfer times – rather than burying them, with similar disclosure rules extending to ATM withdrawals.
Consumer protection extends beyond pricing too. Today, many providers handle disputes through chatbots alone, which can leave customers stuck without real help. PSD3/PSR requires a human support option, and mandatory participation in alternative dispute resolution (ADR) schemes whenever a customer asks for one.
Core insight: PSD3/PSR brings accessible authentication, clearer fraud liability, more reliable open banking with a permissions dashboard, and stronger transparency on fees, support, and dispute resolution.
How to prepare for PSD3 today
Since the substance of PSD3/PSR is already locked in, the most useful moves are the ones that pay off regardless of when the final text publishes:
- Confirm how your provider handles MITs. SCA should only trigger once, at mandate setup – not on every renewal. Mechanisms like already work this way.
- Check your and Verification of Payee coverage – since fraud liability under PSD3/PSR is shifting to PSPs, choosing a reliable one matters more than ever.
- Review how currency-conversion costs are disclosed in your flow, and confirm your provider offers human support and participates in ADR schemes rather than relying on chatbots alone.
Solidgate is paying close attention to how PSD3 unfolds, and stands ready to support merchants as these changes take shape.
Frequently asked questions
PSD3, the third Payment Services Directive, is the EU's update to its payment services rulebook. Alongside its companion Payment Services Regulation (PSR), it replaces PSD2 and covers licensing, authentication, fraud liability, open banking, and cross-border payment rules across the EU.
PSD3 itself is a directive, transposed into national law by each EU member state. Its companion instrument, the PSR, is a regulation that applies directly across the EU. The two together replace PSD2.
PSD3 is a directive – EU member states transpose it into national law, with some room for local variation. The PSR is a regulation – it applies directly and uniformly across the EU with no national transposition step.
Together, they split what PSD2 handled as a single instrument: PSD3 covers licensing and supervision, while the PSR covers conduct-of-business rules like SCA, fraud liability, and open banking access.
As of mid-2026, PSD3 and the PSR have a provisional political agreement (reached November 27, 2025) and ECON Committee approval (May 5, 2026), but haven't been formally adopted.
The numbers get specific once the text is out: PSD3's national rollout and the PSR's EU-wide start both land 21 months after entry into force. Verification of Payee gets extra runway – 27 months – since providers need that much time to actually build the system checks it requires.
PSD3 keeps SCA in place but strengthens accessibility requirements, so providers must improve authentication for customers with disabilities, older customers, and others facing barriers. It also clarifies merchant-initiated transactions (MITs): SCA is required once, at mandate setup, not on every renewal.
PSD3 tightens requirements on API reliability and performance for banks providing open banking access. It also requires a dashboard – built into the account provider's own interface – giving users direct control to monitor and manage which third parties have access to their account information and payment initiation permissions.
PSD3 and the PSR expand liability for providers that fail to properly use tools like Verification of Payee or active transaction monitoring. Providers must also reimburse customers for impersonation ("spoofing") fraud.
PSD3 and the PSR are EU legislation, so they don't apply directly to UK or other non-EU merchants. But if you serve EU customers or route payments through EU-licensed providers, the practical requirements – SCA, fraud liability standards, transparency rules – will still shape what your provider asks of you.


