Updated on 14 August 2026 by Héloïse Torreani Payments Reading Time: 5 minutes Interactive table of contents What is PSD3?PSD2 vs PSD3/PSR: what’s changed?PSD3: what does it mean for you?When does PSD3 come into effect?How to start preparing now Key takeaways PSD3 builds on PSD2 to secure and modernise electronic payments across the EU. It strengthens payment security by extending the Strong Customer Authentication (SCA) framework and tightening access to account data. It improves consumer protection (via the new PSR regulation) and drives financial innovation. The EU is finalising PSD3. This new regulation protects your revenue and streamlines your customers' purchase journey, while levelling the playing field across Europe. What is PSD3? How will it affect your checkout flow, and how can you start preparing your business today? Here is what you need to know to turn this regulatory requirement into a growth lever. What is PSD3? The Payment Services Directive 3 (PSD3) is a European reform designed to create a stronger regulatory framework for payment services. It succeeds the previous directives aimed at harmonising the EU payments market — most notably PSD2. PSD3 will strengthen payment security PSD3 provides the legal foundation for the reform, while the Payment Services Regulation (PSR) defines the bulk of the rules — and most of the practical changes that matter to merchants: Strong Customer Authentication (SCA) and its exemptions Data sharing to combat fraud Access to open banking infrastructure Obligations applicable to payment service providers The PSR applies directly across all EU member states. The objectives: a more integrated, secure, and innovative payments market PSD2 has shown its limits: rules applied inconsistently across countries, and fraud continuing to evolve. This fragmentation creates uneven payment experiences for your customers. PSD3 sets a clear goal — harmonise the rules to: Strengthen the security of your transactions Improve protection for your customers Drive innovation in financial services PSD2 vs PSD3/PSR: what’s changed? TopicPSD2PSD3 & PSRMerchant impactRegulationEach member state sets its own implementation rulesA single regulation for the entire EU (PSR)Unified, streamlined paymentsFraudPartially defined liability, limited cooperationStrengthened anti-fraud data sharing, widespread IBAN/Name verification, clarified liabilityFewer fraud-related losses, better dispute traceabilityPayment securitySCA mandatory for most transactionsOptimised SCA with better-defined exemptions and alternative methodsLess friction at checkout, improved conversion rateOpen bankingAPI-based access to bank data, but variable reliabilityHarmonised, reliable open banking — simpler data access and A2A payment initiationAbility to offer A2A and BNPL payments, diversified payment mixActor liabilityBank primarily liable in the event of fraudClarified liability chain between banks, PSPs, and fintechsFaster dispute resolution, greater legal protection for merchants Tackling fraud more effectively Payment fraud continues to rise. According to the Banque de France, it reached €618.4 million across 3.7 million transactions in H1 2025. The most affected payment types are: Card payments (62.3%) Credit transfers (17.2%) PSD3 strengthens prevention — particularly against authorised push payment (APP) fraud, where customers are manipulated into initiating fraudulent payments themselves. This type of scam rose by 37% between H1 2024 and H1 2025 and now accounts for 40% of the total fraud value. (Source: Observatoire de la sécurité des moyens de paiement, H1 2025) Optimising Strong Customer Authentication PSD2 made SCA the norm — but at the cost of friction in some purchase journeys. PSD3 and the PSR preserve this high level of security while optimising the payment experience. They introduce: Better-defined exemptions for low-value amounts, subscriptions, and low-risk transactions Alternative authentication methods, so that payment no longer depends solely on access to a smartphone Advancing open banking Introduced by PSD2, open banking allowed third-party providers to access users' bank data with their consent, enabling the emergence of new financial services. In practice, however, merchants and fintechs still run up against real barriers: API failures, repetitive consent screens, and complex technical integrations. → The PSR requires banks to provide more reliable and standardised interfaces. The goal? Make open banking genuinely operational and accelerate the development of A2A payments. Clarifying the liability chain PSD3 clarifies how responsibility is distributed between banks, payment service providers, and fintechs: Stronger consumer protection, with faster reimbursements in the event of fraud caused by a technical failure or identity theft (such as spoofing) Shared liability between actors when fraud originates from a technical flaw at a third-party provider PSD3: what does it mean for you? For merchants, the regulatory changes touch the payment collection process and commercial performance management. The rise of account-to-account (A2A) payments The development of A2A (Account-to-Account) payments is the standout change brought by PSD3. A2A lets customers pay directly from their bank account, without going through a card scheme. This type of payment builds on the open banking framework introduced by Directive (EU) 2015/2366 — but PSD3 and the PSR are set to make it far easier to deploy in practice. In concrete terms, these payments can take several forms: Pay by bank: the customer authorises a payment directly from their banking interface Instant bank transfers initiated at checkout Payment initiation solutions offered by fintechs or payment service providers For merchants, these methods offer several advantages: Diversify the payment mix at checkout Reduce card-related fraud Accept payments better suited to high-value or international transactions With improved banking APIs and the harmonisation brought by PSD3, A2A payments could progressively become a credible card alternative for certain e-commerce use cases — such as transactions above card limits. A revised payment journey New payment journeys will need to evolve to meet three simultaneous objectives: Integrate the new exchange protocols required by the directive into the payment solution provided by your PSP Reduce the number of steps required to complete a payment, minimising basket abandonment Strengthen security to maintain protection against intrusion and bank data theft SCA becomes invisible. Whether through mobile biometrics or simplified desktop validation, the journey is smoothed out: you stay compliant while removing the friction that slows your sales. Fewer false positives, more sales: boosting your acceptance rate Thanks to better data sharing between banks and providers, PSD3 reduces unjustified payment declines. This approach — fully GDPR-compliant — builds buyer confidence and improves your payment acceptance rate. The result: a more secure business and more sales converted at checkout.In the face of these changes, your choice of payment service provider (PSP) is decisive. At Payplug, we turn regulatory change into concrete growth levers for your business: Continuity: we manage the technical transition to keep your payment collection running without interruption. Performance: we activate new payment methods — including instant bank transfers — to drive your sales. Peace of mind: we ensure the legal compliance of every transaction so you can focus on your business. Stronger protection against disputes and fraud PSD3 clarifies how disputes and fraud-related refunds are handled. It defines responsibilities between banks, PSPs, and merchants. For example, where the SCA protocol has been correctly applied, the Liability Shift towards the customer's bank is reinforced. An end to legal grey areas for commercial agents and marketplaces Previously, certain platforms relied on a derogation to manage payments without a specific licence. PSD3 clarifies these rules to better protect sellers. New embedded financial services Open banking will bring new financial services into the purchase journey. PSD3 provides more reliable, standardised access to bank data — always with the customer's consent. Payment service providers and fintechs will be able to build tools that analyse a user's financial situation in real time. This opens the door to faster, more personalised financial services. The most visible use cases for merchants include: Instant credit, granted at the point of payment Payment optimisation solutions capable of dynamically adapting the payment methods offered to the customer When does PSD3 come into effect? PSD3 is currently moving through the European legislative process. The European Parliament and Council reached agreement on the content of PSD3 in November 2025. The official texts still need to be published. Once finalised, member states will have between 18 and 24 months to transpose the directive into national law. The new standards are expected to take effect in the 2027–2028 timeframe. How to start preparing now Getting ahead of these changes is essential to ensuring your payment operations remain fully functional when the new rules take effect. Audit your payment flows Start by taking stock of your current setup: E-commerce: analyse your payment failures to identify drop-off at the payment step. Marketplaces: check whether you are directly handling your sellers’ funds. If so, you will need to secure that flow to achieve compliance. In-store: ensure your terminals accept the new payment methods (biometrics, QR code-based bank transfers) so you are no longer constrained by card limits. Evolve your anti-fraud strategy Once you have reviewed your payment flows, the next step is to strengthen your defences. PSD3 places greater responsibility on financial actors — use it as an opportunity to protect your revenue: Scoring tools: deploy online fraud detection solutions capable of analysing user behaviour before the payment is initiated. Data sharing: work with your PSP to integrate the data-sharing principles of the directive now, blocking high-risk transactions before they are even initiated. Optimise the user experience and conversion rates Once you have analysed your flows and secured your revenue, the challenge is to make payment invisible: Go frictionless: activate smart exemptions (for low-value amounts or trusted customers) to validate purchases with zero additional steps for the buyer. Remove card ceilings: integrate instant bank transfer. It is a fluid alternative that lets your customers complete high-value purchases where a card might be declined. Choose a partner that anticipates change for you Your payment partner’s role is to absorb this complexity on your behalf. At Payplug, we help you turn new regulations into concrete advantages: A smooth transition: we guide you at every step and adapt your tools — no technical headaches on your end. A technology advantage: our solutions already anticipate forthcoming security standards to guarantee the fluidity of your sales. Get in touch with our team today to discuss your strategy and prepare for PSD3. Share this article
Posted on 14/08/2026 in Payments Secure online payments: protect your transactions and cut fraud Secure online payments: key takeaways A secure online payment: protects banking data, fights fraud, meets...
Posted on 19/03/2026 in Payments Agentic payment: when AI buys on behalf of consumers With agentic payment, artificial intelligence doesn't just recommend products — it advises consumers, personalises their...
Posted on 27/11/2025 in Payments How can you boost your payment performance using the French Cartes Bancaires (CB) scheme ? If you sell in France, part of your payment performance depends on the Cartes Bancaires...