Political agreement on PSD3 and the Payment Services Regulation was reached in late 2025. National transposition is underway across EU member states, with full application expected mid-to-late 2027. For payment institutions already compliant with PSD2, the question is not whether to prepare but how much of PSD2 compliance transfers directly and where new obligations require material work.
The structural change: from directive to regulation
PSD2 was a directive, requiring national transposition and resulting in significant implementation variation across EU member states. The Payment Services Regulation is a directly applicable regulation: meaning a single set of rules applies uniformly across the EU without national discretion on core provisions. For payment institutions operating across multiple EU jurisdictions, this removes a significant compliance overhead: one set of rules replaces the patchwork of national implementations that PSD2 created.
Material changes from PSD2
The fraud provisions are the most operationally significant change. PSD3 and the PSR introduce new requirements for payment service providers to verify payee account details before executing credit transfers: extending the UK's Confirmation of Payee model to the EU. This has material technology and process implications for payment institutions, particularly for faster payment flows where current verification mechanisms are minimal.
The scope of strong customer authentication has been refined. The PSR maintains the SCA obligation for electronic payments while clarifying exemptions and introducing new exemption categories that reduce friction for low-risk transactions. The transaction risk analysis exemption framework is more clearly defined than under PSD2, reducing the ambiguity that drove significant compliance variation across member states.
Open banking provisions are strengthened. PSD3 introduces dedicated interfaces as the mandated access method, with enhanced performance standards and a clearer liability framework for access failures. The practice of screen scraping: which persisted under PSD2 despite the dedicated interface requirement, is addressed more directly.
What stays essentially the same
The core licensing framework for payment institutions and e-money institutions is substantially unchanged. The categories of payment services, capital requirements and safeguarding obligations carry over from PSD2. Institutions with valid PSD2 authorisations will not need to reapply, though updates to regulatory submissions may be required as national competent authorities implement the new framework.
What institutions should be doing now
The transposition period provides time to prepare, but the scope of work should not be underestimated. Payee verification requirements for credit transfers require technology development that cannot be rushed. SCA exemption frameworks may need reconfiguration as the new PSR provisions are transposed. Open banking infrastructure may need enhancement to meet the strengthened performance standards. Institutions should begin gap assessments now against the final legislative text, with particular focus on fraud prevention obligations and the payee verification requirements, which represent the most material operational change.