Learn what PSD3 and the Payment Services Regulation mean for payment firms, key compliance changes, the 2028 timeline, and how PIs and EMIs can prepare.
PSD3 is coming, and for payment firms, the countdown to compliance has begun.
The third Payment Services Directive (PSD3) and its companion regulation, the Payment Services Regulation (PSR), are nearing official publication, ushering in the biggest overhaul of the EU payments framework since PSD2 was adopted in 2015.
For payment institutions (PIs) and e-money institutions (EMIs), the implications are significant. Publication in the Official Journal and entry into force are expected in Q3 2026, triggering a 21-month transition period and putting the compliance deadline at around mid-2028.
That may sound far in the future, but the work ahead is substantial. Firms will need to interpret the new requirements, assess their impact across existing operations, implement the necessary changes, track progress, and demonstrate compliance.
This guide explains why the EU is introducing PSD3 and PSR, what is set to change, and what payment firms should be doing now to prepare.
Not sure where to start with PSD3? Vixio helps payments and financial services firms track regulatory change, understand its impact, and manage implementation with our regulatory change management platform. Book a demo today.
On April 23, 2026, the Council of the EU published what appears to be the final version of the revised payment services framework: the third Payment Services Directive and the Payment Services Regulation.
The distinction between the two matters for compliance planning:
Both are still moving through the EU legislative process and official publication hasn't happened yet. Still, all likely requirements and obligations have been made public. That makes now a critical time to get the ball rolling on compliance preparations so you can be ready by the time the directive and regulation take effect.
PSD3 and PSR are designed to bring the EU's payment services framework in line with how the retail payments market looks today. The landscape has changed substantially since PSD2 was adopted in 2015: card and digital payment use has grown, and so has the number of non-bank players offering payment services.
Over a decade ago, PSD2 opened the door for non-banking entities to enter the payments space. PSD3 and PSR build on that by aiming to improve the reliability of digital payments and level the playing field between traditional banks and non-bank payment service providers (PSPs) like fintechs and EMIs.
PSD3 and PSR cover a lot of ground, from licensing and capital requirements to safeguarding rules and fraud liability. Here's a quick rundown of the key changes:
From capital requirements to safeguarding arrangements, PSD3 and PSR introduce plenty of changes firms should start preparing for now.
For a more detailed breakdown of the requirements and their practical implications, check out our playbook on preparing for PSD3/PSR authorisation.
PSR is expected to apply 21 months after entry into force, which will be 20 days after official publication.
PSD3's timeline is less straightforward. Member states have 21 months from entry into force to publish the laws, regulations, and administrative provisions needed for compliance. However, as PSD2's rollout showed, not every member state will meet the deadline, which can affect when PIs and EMIs are able to get authorised or reauthorised.
Adding to the complexity, PSD2 and EMD2 are set to be repealed 21 months after PSD3 enters into force. If a member state hasn't transposed PSD3 into national law by then, PIs and EMIs in that jurisdiction could be left without a clear licensing framework to operate under.
Institutions seeking authorisation for the first time can still apply under the PSD2 framework during the 21-month transition period, but should build toward PSD3 compliance now, because reauthorisation will be required regardless.
Delays in national implementation create a few scenarios worth watching:
The takeaway: final legislation doesn't mean the regulatory picture is complete. PIs and EMIs need to keep a close eye on how implementation plays out in each member state, as well as have a reliable way to monitor those developments, assess their impact, and act on them.
What we covered above is just the tip of the iceberg. Between parsing the actual legal text, mapping it against your operations, and proving compliance within the transition window, getting authorised (or reauthorised) for PSD3/PSR represents a significant amount of work.
That's where Vixio can help. Vixio is a regulatory change management platform purpose-built to help payments and financial services teams navigate this kind of regulatory complexity, from monitoring regulatory developments as they happen, to impact analysis, through to audit-ready proof of compliance.
Here’s what you can do with the platform:
Reviewing legislation and figuring out what's actually new or relevant is the first hurdle, and it's a time-consuming one, especially when relevant updates are scattered across multiple jurisdictions and sources.
Vixio consolidates regulatory developments into a single place and surfaces them to you in an intelligent triage inbox, so you can stay on top of updates as PSD3 implementation unfolds across member states.

Within the platform, you can view the regulatory text directly, extract requirements highlighted within it, and turn any passage into an obligation in a click.

You also have access to Vixio's expert-led analyst reports that break down what PSD3 and PSR mean in practice, including a playbook with actionable insights and next steps your team can take.
For quick answers along the way, you can ask natural-language questions to the VIQ assistant, which draws only from Vixio's verified, expert-written content.
Once you know what's required, the next step is figuring out where your current processes fall short and what to prioritise first.
Regulatory mapping lets you link obligations directly to your internal policies, procedures, and controls, giving you a clear view of where your operations already align with PSD3 and PSR and where they don't.

Advanced sorting and filtering also make it easy to isolate the highest-priority obligations, so your team can focus on what matters most first.
With a 21-month transition period, managing tasks efficiently is critical. Vixio replaces scattered spreadsheets and email chains with centralised task and action boards, so you can create, assign, and track compliance work with clear ownership and deadlines.

Meanwhile, project tracking gives leadership a real-time view of progress across the organisation, which can help them catch bottlenecks early rather than at the deadline.

And because regulatory mapping creates an audit-ready record connecting your processes to specific requirements, you'll have the documentation ready when it's time to prove compliance.

More than 100 financial services firms rely on Vixio to navigate regulatory change, including FinteqHub, a payment gateway provider known for fast, seamless payment integrations across a range of industries.
According to the company's Head of Legal and Compliance, Tamara Makhatadze, Vixio stands out for its combination of technology and human expertise. Automated tools are useful for surfacing relevant facts and emerging trends quickly, but the decisions that matter most still call for human judgment and context.
Vixio brings together the best of both worlds, with FinteqHub relying on the platform’s AI-driven tools to quickly flag relevant regulatory developments, as well as Vixio's analysts for deeper, scenario-specific guidance when they need it.
Learn why FinteqHub recommends Vixio to legal teams and companies in payments.
PSD3 and PSR bring meaningful changes to how PIs and EMIs operate. And with national implementation likely to vary across member states, keeping track of what applies where and by when will be an ongoing task.
Getting ahead of the requirements now puts your team in a stronger position to extract what's relevant, assess the impact on your operations, and get compliant and authorised by the time the deadline rolls around.
Vixio can help you get there. Request a call to see how.
The Payment Services Directive 3 (PSD3) is an EU directive that updates the payment services framework introduced under PSD2. It covers areas such as licensing and authorisation, capital requirements, governance, safeguarding customer funds and consumer protection for payment institutions and e-money institutions.
Because PSD3 is a directive, each EU member state must transpose it into national law before the relevant PSD3 compliance requirements apply locally.
The Payment Services Regulation is PSD3’s companion regulation. It covers operational requirements such as Verification of Payee, Strong Customer Authentication, payment fraud prevention, open banking, payment security and fraud liability.
Unlike PSD3, the regulation will apply directly and consistently across EU member states without requiring national transposition. Together, PSD3 and the Payment Services Regulation create the new EU regulatory framework for payment services.
PSD3 and Payment Services Regulation compliance applies to payment institutions, e-money institutions, banks and other payment service providers operating in the EU.
This includes non-bank fintechs and organisations providing regulated payment or electronic money services. The specific PSD3 requirements that apply will depend on the organisation’s regulatory status, business model and the payment services it provides.
The final PSD3 compliance deadline has not yet been confirmed.
Once the legislation enters into force, payment service providers are expected to have a defined implementation period in which to update their systems, policies and compliance processes. Full compliance is currently expected around 2028, although the exact timing may vary depending on the final legislative timetable and the national implementation of PSD3.
Organisations should begin their PSD3 readiness assessment and implementation planning before the final deadline is announced.
PSD3 and the Payment Services Regulation build on PSD2 by updating the rules for a more digital, competitive and secure payments market.
The new framework separates the rules into two legal instruments. PSD3 focuses mainly on licensing, authorisation, safeguarding, capital requirements, governance and regulatory supervision. The Payment Services Regulation covers operational requirements, customer rights and consumer protection.
Key areas of change include Verification of Payee, Strong Customer Authentication, fraud prevention, open banking, access to payment systems and fraud liability. Together, the reforms aim to improve payment security and create a more level playing field between banks and non-bank payment service providers.
The main PSD3 requirements are expected to cover the licensing and supervision of payment institutions and e-money institutions, including capital adequacy, governance, risk management and the safeguarding of customer funds.
Payment Services Regulation requirements will focus more heavily on how payment services are delivered. This includes Strong Customer Authentication, Verification of Payee, fraud monitoring, customer reimbursement rights, open banking services and access to payment account data.
The exact compliance obligations will depend on the services a payment service provider offers and where it operates.
Payment service providers can prepare by carrying out a PSD3 readiness assessment to identify gaps between their current PSD2 compliance framework and the new PSD3 and Payment Services Regulation requirements.
A PSD3 implementation plan may include reviewing licensing and authorisation arrangements, safeguarding controls, governance, capital requirements, fraud prevention systems, Strong Customer Authentication and Verification of Payee processes.
Firms should also assess their open banking technology, API performance, customer communications, incident reporting and third-party provider arrangements. Starting early can help reduce regulatory risk and make the transition from PSD2 to PSD3 more manageable.