The European payments landscape is entering its next major phase. Nearly a decade after PSD2 introduced Open Banking and reshaped digital payments across the EU, lawmakers are preparing a new regulatory package built around PSD3 and PSR.
For FinTech companies, these changes will reshape how payment services are built and delivered, creating both new technical challenges and opportunities for innovation. Read on to learn which areas of your business are likely to be affected and how to start preparing for the new regulatory environment.
What is PSD3?
PSD3 (Third Payment Services Directive) is the European Union's upcoming directive that updates the legal framework for payment services. It rebuilds PSD2 and sets out rules for licensing, supervision, governance, and the operation of payment service providers (PSPs). Unlike a regulation, a directive must be transposed into the national law of each EU Member State before it becomes applicable.
This is what distinguishes PSD3 from the Payment Services Regulation (PSR), which will apply directly across the EU without requiring national implementation. It's a new regulation containing the core rules for providing payment services, from how providers interact with customers to how transactions are processed. By moving these provisions into a regulation, the EU aims to eliminate inconsistencies caused by national implementation of PSD2.
Although PSD3 often receives most of the attention, both acts form a single legislative package. The European Commission proposed them together in June 2023 after concluding that PSD2 had successfully promoted innovation and Open Banking but had not fully delivered consistent implementation across the EU.
PSD3 vs PSD2: What is actually changing?
While PSD2 introduced the legal foundations for secure digital payments and third-party access to bank accounts, PSD3 and PSR strengthen the framework. They aim to make the European payments market more secure, more competitive, and easier to navigate for both providers and consumers.
PSD2 delivered significant progress, but it also exposed practical challenges. Open Banking often fell short of expectations due to poor API performance, while payment fraud became more sophisticated than the original framework anticipated.
This is why the following changes were introduced under PSD3 and PSR:
| Area | PSD2 | PSD3 / PSR |
|---|---|---|
| Fraud prevention | Focus on Strong Customer Authentication | Broader anti-fraud framework, including stronger monitoring, expanded reimbursement rules, and mandatory IBAN-name verification in relevant payment scenarios |
| Open Banking | Introduced account access through APIs | Higher API performance standards, fewer barriers for third-party providers, and stronger customer control over data permissions |
| Licensing | Separate regimes for payment institutions (PIs) and electronic money institutions (EMIs) | Single licensing framework, with EMIs integrated into the PSD3 regime |
| Consumer protection | Basic transparency and refund rules | Stronger consumer rights, enhanced transparency, and additional safeguards against payment fraud |
| Competition | Opened the market to non-bank providers | Further levels the playing field by improving access to payment systems and bank accounts for non-bank PSPs |
What PSD3 means for FinTech companies
PSD3 is designed to modernize the European digital payments landscape. For FinTech companies, this means operating under a new set of rules that will influence both day-to-day operations and long-term strategy. Below, we explore the five changes most likely to affect your business:
1. Better Open Banking creates better products
PSD3 and PSR introduce several changes designed to make Open Banking more reliable for both providers and users. One of the biggest improvements is the removal of technical barriers that have limited third-party access to bank accounts since PSD2.
Banks may be required to meet stricter performance standards for their dedicated APIs and publish quarterly statistics on interface availability and performance. This would give FinTech companies greater transparency when integrating with banking systems and create stronger incentives for banks to maintain reliable Open Banking infrastructure.
The new framework also strengthens business continuity, but on stricter terms than under PSD2. Banks are now required to ensure their dedicated APIs perform on par with their own customer-facing interface, and the old option to rely permanently on the customer interface as a fallback is being phased out. Instead, if a bank's dedicated interface becomes unavailable or fails to meet the required standards, third-party providers may get temporary, supervisor-approved contingency access to the customer interface until the issue is resolved. This reduces service disruptions for applications that rely on account information or payment initiation, while pushing banks toward consistently reliable APIs rather than a permanent workaround.
2. Fraud prevention becomes a core business capability
PSD3 and PSR significantly expand the responsibility of payment service providers for preventing payment fraud. PSPs that fail to implement appropriate security measures may be held liable for customer losses in certain scenarios, particularly in cases of Authorized Push Payment (APP) fraud.
Mandatory Verification of Payee (VoP) checks are also becoming a reality across the EU under the Instant Payments Regulation. PSPs are progressively implementing systems that compare the payee's name with the IBAN before a credit transfer is executed, helping to prevent payments from being sent to fraudulent accounts. PSD3 complements these efforts by embedding stronger payment security requirements into the broader regulatory framework.
In addition, the new rules reinforce Customer Authentication (SCA). Rather than relying solely on traditional authentication factors, PSPs are expected to use a broader range of contextual signals when assessing transaction risk, including:
- Device information
- Transaction history
- Spending patterns
- User location.
PSD3 may also introduce more accessible authentication methods for users who cannot rely on smartphones, making SCA both more effective against emerging fraud techniques and more inclusive.
For FinTech companies, fraud prevention can no longer be treated as a standalone compliance function. Payment platforms will need to combine Verification of Payee, stronger transaction monitoring, and enhanced SCA into a single risk management process capable of detecting suspicious activity before a payment is executed. This will require greater investment in anti-fraud technology, but it should also reduce liability exposure and strengthen customer trust.
3. Direct access to payment systems removes a major barrier
Today, many licensed Payment Institutions (PIs) still depend on commercial banks to connect to core payment infrastructure. As a result, they have less control over how transactions are processed and remain exposed to commercial decisions made by their banking partners.
PSD3 changes this by allowing eligible PIs to participate directly in designated payment systems under the amended Settlement Finality Directive. Instead of routing transactions through a sponsoring bank, qualifying FinTechs will be able to connect directly to the underlying payment infrastructure, provided they meet the applicable risk and operational requirements.
Removing intermediary banks can simplify transactions, reduce operational costs, and shorten the time needed to launch new payment services. It also creates a more level playing field between banks and licensed non-bank providers, making it easier for FinTechs to compete in the European payments market.
4. A unified licensing framework simplifies market entry
PSD3 replaces the separate licensing regimes for Payment Institutions and Electronic Money Institutions (EMIs) with a single framework. The Electronic Money Directive (EMD2) will be repealed, and electronic money issuance will become an activity performed under a PI licence rather than under a separate regulatory regime.
For companies entering the market, this creates a simpler regulatory model. Instead of determining whether a business requires a PI or EMI licence, applicants will follow a single authorization framework with harmonized requirements for governance, risk management, safeguarding, and supervision. Existing EMIs will transition to the new regime through a reauthorization process during the implementation period.
5. Customer consent becomes easier to manage
PSD3 and PSR give consumers greater visibility into how their financial data is shared. Banks may be required to provide permission dashboards that allow customers to see, in real time, which third-party providers have access to their payment account data and what permissions have been granted. They will also be able to withdraw or restore access whenever they choose.
This changes how banks and third-party providers manage customer consent. When a user revokes or re-grants access, both parties must keep permission records synchronized so that access rights remain accurate and up-to-date.
What does it mean for your business? Greater transparency around customer permissions can increase confidence in Open Banking services and encourage more users to connect their bank accounts. At the same time, you will need to ensure that consent changes are reflected accurately and without delay across their services.
How can FinTech companies prepare for PSD3 and PSR?
To prepare for PSD3, FinTech companies need to strengthen fraud controls and update their Open Banking infrastructure before the new requirements take effect. That's why you should focus on the following areas:
PSD3 preparation checklist for FinTech companies
Although PSD3 and PSR are expected to be formally adopted in 2026, most requirements will become applicable after a 21-month transition period. That means FinTech companies should be ready by Q2/Q3 2028 or shortly thereafter.
PSD3 in Finance: Final thoughts
PSD3 creates new opportunities for FinTech companies to deliver more secure and reliable payment services. At the same time, it raises the technical and regulatory bar. Starting early gives you time to implement these changes without disrupting existing operations. Working with an experienced software engineering partner can help you reduce delivery risks and ensure every requirement is built into the platform from the ground up.
Building a PSD3-ready payment platform?
We help FinTech companies design and implement payment infrastructure that meets current and upcoming regulatory requirements — from Open Banking integrations and fraud controls to licensing strategy and SCA.
Talk to our engineers about how to prepare your platform for PSD3 and PSR without disrupting what you've already built.

