PSD3: Europe's new payments regulation

Héloïse Torreani
Updated on 14 August 2026 by Héloïse Torreani
Reading Time: 5 minutes

Key takeaways

  • PSD3 builds on PSD2 to secure and modernise electronic payments across the EU.
  • It strengthens payment security by extending the Strong Customer Authentication (SCA) framework and tightening access to account data.
  • It improves consumer protection (via the new PSR regulation) and drives financial innovation.

The EU is finalising PSD3. This new regulation protects your revenue and streamlines your customers' purchase journey, while levelling the playing field across Europe.

What is PSD3? How will it affect your checkout flow, and how can you start preparing your business today? Here is what you need to know to turn this regulatory requirement into a growth lever.

Homme qui tape sur son téléphone affichant un drapeau européen

What is PSD3?

The Payment Services Directive 3 (PSD3) is a European reform designed to create a stronger regulatory framework for payment services. It succeeds the previous directives aimed at harmonising the EU payments market — most notably PSD2.


PSD3 will strengthen payment security

PSD3 provides the legal foundation for the reform, while the Payment Services Regulation (PSR) defines the bulk of the rules — and most of the practical changes that matter to merchants:

  • Strong Customer Authentication (SCA) and its exemptions
  • Data sharing to combat fraud
  • Access to open banking infrastructure
  • Obligations applicable to payment service providers

The PSR applies directly across all EU member states.


The objectives: a more integrated, secure, and innovative payments market

PSD2 has shown its limits: rules applied inconsistently across countries, and fraud continuing to evolve. This fragmentation creates uneven payment experiences for your customers.

PSD3 sets a clear goal — harmonise the rules to:

  • Strengthen the security of your transactions
  • Improve protection for your customers
  • Drive innovation in financial services

PSD2 vs PSD3/PSR: what’s changed?

TopicPSD2PSD3 & PSRMerchant impact
RegulationEach member state sets its own implementation rulesA single regulation for the entire EU (PSR)Unified, streamlined payments
FraudPartially defined liability, limited cooperationStrengthened anti-fraud data sharing, widespread IBAN/Name verification, clarified liabilityFewer fraud-related losses, better dispute traceability
Payment securitySCA mandatory for most transactionsOptimised SCA with better-defined exemptions and alternative methodsLess friction at checkout, improved conversion rate
Open bankingAPI-based access to bank data, but variable reliabilityHarmonised, reliable open banking — simpler data access and A2A payment initiationAbility to offer A2A and BNPL payments, diversified payment mix
Actor liabilityBank primarily liable in the event of fraudClarified liability chain between banks, PSPs, and fintechsFaster dispute resolution, greater legal protection for merchants

Tackling fraud more effectively

Payment fraud continues to rise. According to the Banque de France, it reached €618.4 million across 3.7 million transactions in H1 2025. The most affected payment types are:

  • Card payments (62.3%)
  • Credit transfers (17.2%)

PSD3 strengthens prevention — particularly against authorised push payment (APP) fraud, where customers are manipulated into initiating fraudulent payments themselves. This type of scam rose by 37% between H1 2024 and H1 2025 and now accounts for 40% of the total fraud value.

(Source: Observatoire de la sécurité des moyens de paiement, H1 2025)


Optimising Strong Customer Authentication

PSD2 made SCA the norm — but at the cost of friction in some purchase journeys. PSD3 and the PSR preserve this high level of security while optimising the payment experience. They introduce:

  • Better-defined exemptions for low-value amounts, subscriptions, and low-risk transactions
  • Alternative authentication methods, so that payment no longer depends solely on access to a smartphone


Advancing open banking

Introduced by PSD2, open banking allowed third-party providers to access users' bank data with their consent, enabling the emergence of new financial services.

In practice, however, merchants and fintechs still run up against real barriers: API failures, repetitive consent screens, and complex technical integrations.

→ The PSR requires banks to provide more reliable and standardised interfaces. The goal? Make open banking genuinely operational and accelerate the development of A2A payments.


Clarifying the liability chain

PSD3 clarifies how responsibility is distributed between banks, payment service providers, and fintechs:

  • Stronger consumer protection, with faster reimbursements in the event of fraud caused by a technical failure or identity theft (such as spoofing)
  • Shared liability between actors when fraud originates from a technical flaw at a third-party provider

PSD3: what does it mean for you?

Vues de main en close up d'un ordinateur portable

For merchants, the regulatory changes touch the payment collection process and commercial performance management.


The rise of account-to-account (A2A) payments

The development of A2A (Account-to-Account) payments is the standout change brought by PSD3.

A2A lets customers pay directly from their bank account, without going through a card scheme. This type of payment builds on the open banking framework introduced by Directive (EU) 2015/2366 — but PSD3 and the PSR are set to make it far easier to deploy in practice.

In concrete terms, these payments can take several forms:

  • Pay by bank: the customer authorises a payment directly from their banking interface
  • Instant bank transfers initiated at checkout
  • Payment initiation solutions offered by fintechs or payment service providers

For merchants, these methods offer several advantages:

  • Diversify the payment mix at checkout
  • Reduce card-related fraud
  • Accept payments better suited to high-value or international transactions

With improved banking APIs and the harmonisation brought by PSD3, A2A payments could progressively become a credible card alternative for certain e-commerce use cases — such as transactions above card limits.


A revised payment journey

New payment journeys will need to evolve to meet three simultaneous objectives:

  • Integrate the new exchange protocols required by the directive into the payment solution provided by your PSP
  • Reduce the number of steps required to complete a payment, minimising basket abandonment
  • Strengthen security to maintain protection against intrusion and bank data theft

SCA becomes invisible. Whether through mobile biometrics or simplified desktop validation, the journey is smoothed out: you stay compliant while removing the friction that slows your sales.


Fewer false positives, more sales: boosting your acceptance rate

Thanks to better data sharing between banks and providers, PSD3 reduces unjustified payment declines. This approach — fully GDPR-compliant — builds buyer confidence and improves your payment acceptance rate. The result: a more secure business and more sales converted at checkout.

In the face of these changes, your choice of payment service provider (PSP) is decisive. At Payplug, we turn regulatory change into concrete growth levers for your business:

  • Continuity: we manage the technical transition to keep your payment collection running without interruption.
  • Performance: we activate new payment methods — including instant bank transfers — to drive your sales.
  • Peace of mind: we ensure the legal compliance of every transaction so you can focus on your business.


Stronger protection against disputes and fraud

PSD3 clarifies how disputes and fraud-related refunds are handled. It defines responsibilities between banks, PSPs, and merchants. For example, where the SCA protocol has been correctly applied, the Liability Shift towards the customer's bank is reinforced.


An end to legal grey areas for commercial agents and marketplaces

Previously, certain platforms relied on a derogation to manage payments without a specific licence. PSD3 clarifies these rules to better protect sellers.


New embedded financial services

Open banking will bring new financial services into the purchase journey.

PSD3 provides more reliable, standardised access to bank data — always with the customer's consent. Payment service providers and fintechs will be able to build tools that analyse a user's financial situation in real time. This opens the door to faster, more personalised financial services.

The most visible use cases for merchants include:

  • Instant credit, granted at the point of payment
  • Payment optimisation solutions capable of dynamically adapting the payment methods offered to the customer

When does PSD3 come into effect?

PSD3 is currently moving through the European legislative process. The European Parliament and Council reached agreement on the content of PSD3 in November 2025.

The official texts still need to be published. Once finalised, member states will have between 18 and 24 months to transpose the directive into national law. The new standards are expected to take effect in the 2027–2028 timeframe.

How to start preparing now

Getting ahead of these changes is essential to ensuring your payment operations remain fully functional when the new rules take effect.


Audit your payment flows

Start by taking stock of your current setup:

  • E-commerce: analyse your payment failures to identify drop-off at the payment step.
  • Marketplaces: check whether you are directly handling your sellers’ funds. If so, you will need to secure that flow to achieve compliance.
  • In-store: ensure your terminals accept the new payment methods (biometrics, QR code-based bank transfers) so you are no longer constrained by card limits.


Evolve your anti-fraud strategy

Once you have reviewed your payment flows, the next step is to strengthen your defences. PSD3 places greater responsibility on financial actors — use it as an opportunity to protect your revenue:

  • Scoring tools: deploy online fraud detection solutions capable of analysing user behaviour before the payment is initiated.
  • Data sharing: work with your PSP to integrate the data-sharing principles of the directive now, blocking high-risk transactions before they are even initiated.


Optimise the user experience and conversion rates

Once you have analysed your flows and secured your revenue, the challenge is to make payment invisible:

  • Go frictionless: activate smart exemptions (for low-value amounts or trusted customers) to validate purchases with zero additional steps for the buyer.
  • Remove card ceilings: integrate instant bank transfer. It is a fluid alternative that lets your customers complete high-value purchases where a card might be declined.


Choose a partner that anticipates change for you

Your payment partner’s role is to absorb this complexity on your behalf. At Payplug, we help you turn new regulations into concrete advantages:

  • A smooth transition: we guide you at every step and adapt your tools — no technical headaches on your end.
  • A technology advantage: our solutions already anticipate forthcoming security standards to guarantee the fluidity of your sales.

Get in touch with our team today to discuss your strategy and prepare for PSD3.

Share this article
TwitterFacebookLinkedInCopy Link

Other posts that might
interest you