PSD3 Compliance: What You Need To Know

Date
August 12, 2026
Written by
Toba Ojuri
Industry
Payments

Learn what PSD3 and the Payment Services Regulation mean for payment firms, key compliance changes, the 2028 timeline, and how PIs and EMIs can prepare.

PSD3 is coming, and for payment firms, the countdown to compliance has begun.

The third Payment Services Directive (PSD3) and its companion regulation, the Payment Services Regulation (PSR), are nearing official publication, ushering in the biggest overhaul of the EU payments framework since PSD2 was adopted in 2015.

For payment institutions (PIs) and e-money institutions (EMIs), the implications are significant. Publication in the Official Journal and entry into force are expected in Q3 2026, triggering a 21-month transition period and putting the compliance deadline at around mid-2028.

That may sound far in the future, but the work ahead is substantial. Firms will need to interpret the new requirements, assess their impact across existing operations, implement the necessary changes, track progress, and demonstrate compliance.

This guide explains why the EU is introducing PSD3 and PSR, what is set to change, and what payment firms should be doing now to prepare.

Not sure where to start with PSD3? Vixio helps payments and financial services firms track regulatory change, understand its impact, and manage implementation with our regulatory change management platform. Book a demo today.

What you need to know about PSD3

On April 23, 2026, the Council of the EU published what appears to be the final version of the revised payment services framework: the third Payment Services Directive and the Payment Services Regulation.

The distinction between the two matters for compliance planning:

  • PSR is a regulation, meaning it applies directly across all EU member states and to PIs operating within the bloc.
  • PSD3 is a directive, so each member state will need to transpose its provisions into national law, which means that timing and implementation across jurisdictions could vary.

Both are still moving through the EU legislative process and official publication hasn't happened yet. Still, all likely requirements and obligations have been made public. That makes now a critical time to get the ball rolling on compliance preparations so you can be ready by the time the directive and regulation take effect.

Why the framework is changing

PSD3 and PSR are designed to bring the EU's payment services framework in line with how the retail payments market looks today. The landscape has changed substantially since PSD2 was adopted in 2015: card and digital payment use has grown, and so has the number of non-bank players offering payment services.

Over a decade ago, PSD2 opened the door for non-banking entities to enter the payments space. PSD3 and PSR build on that by aiming to improve the reliability of digital payments and level the playing field between traditional banks and non-bank payment service providers (PSPs) like fintechs and EMIs.

What changes under the PSD3/PSR framework

PSD3 and PSR cover a lot of ground, from licensing and capital requirements to safeguarding rules and fraud liability. Here's a quick rundown of the key changes:

  • Licensing. EMIs will be licensed as a sub-category of PIs, rather than under the second E-Money Directive (EMD2), which is being repealed. Existing EMIs must transition into the PI framework and demonstrate PSD3 compliance.
  • Payment services. The list of payment services covered under PSD3 has been streamlined, and now includes the issuance of electronic money, which was previously governed under EMD2.
  • Initial capital requirements. PSD3 adjusts minimums, though not all in the same direction. Initial capital requirements for money remittance services rise from €20,000 to €40,000, and other payment services from €125,000 to €150,000, while EMI requirements decrease from €350,000 to €250,000. Payment initiation services stay unchanged at €50,000. One key change applies across the board, though: providers offering more than one service must now add the minimums together.
  • Exemptions. The criteria for exemption have shifted slightly to reflect the updated list of payment services and include a revised threshold on business activity.
  • Safeguarding methods. PSD2 required client funds to be safeguarded through deposit at a credit institution, investment in liquid low-risk assets, or by being insured. PSD3 adds two more options: deposit at a central bank (at the bank's discretion) or deposit in a separate account at a post office giro institution that meets prudential requirements comparable to a credit institution. PIs also must disclose to payment service users how their funds are safeguarded and which member state's insolvency law applies.
  • Concentration risk. Payment institutions can no longer hold all safeguarded funds in a single credit institution.
  • Payee verification. Under PSR, PSPs must verify in real time that the IBAN and account name match before executing a transfer.
  • Direct access. Non-bank PSPs can now access central payment systems (like SEPA) directly, without going through a sponsor bank. Access can only be denied if the PSP poses a risk to the system.
  • Strong Customer Authentication (SCA). Core SCA requirements are unchanged from PSD2, but a section in PSD3/PSR clarifies SCA requirements for credit transfers. There are also clarifications for SCA in respect of payment initiation and account information services.
  • Merchant-initiated transactions. PSD3/PSR explicitly exempts merchant-initiated transactions from SCA after the initial setup transaction, a point PSD2 left more ambiguous.
  • Impersonation fraud liability. Under PSD2, liability for authorised push payment fraud sat with the payer if they'd authorised the transaction. Under PSD3/PSR, liability shifts to the PSP, unless it can prove the victim acted with gross negligence or fraudulent intent.

From capital requirements to safeguarding arrangements, PSD3 and PSR introduce plenty of changes firms should start preparing for now. 

For a more detailed breakdown of the requirements and their practical implications, check out our playbook on preparing for PSD3/PSR authorisation.

The timeline for PSD3 compliance

PSR is expected to apply 21 months after entry into force, which will be 20 days after official publication.

PSD3's timeline is less straightforward. Member states have 21 months from entry into force to publish the laws, regulations, and administrative provisions needed for compliance. However, as PSD2's rollout showed, not every member state will meet the deadline, which can affect when PIs and EMIs are able to get authorised or reauthorised.

Adding to the complexity, PSD2 and EMD2 are set to be repealed 21 months after PSD3 enters into force. If a member state hasn't transposed PSD3 into national law by then, PIs and EMIs in that jurisdiction could be left without a clear licensing framework to operate under.

Institutions seeking authorisation for the first time can still apply under the PSD2 framework during the 21-month transition period, but should build toward PSD3 compliance now, because reauthorisation will be required regardless.

What could complicate PSD3/PSR implementation?

Delays in national implementation create a few scenarios worth watching:

  • PSR will apply regardless of whether a given member state has transposed PSD3, which means PIs and EMIs can't assume delays in national implementation will buy them extra time in complying with PSR.
  • If a member state hasn't transposed PSD3 and can't process reauthorisations once PSD2 is repealed, PIs and EMIs risk holding an obsolete PSD2 licence.
  • Passporting could also become complicated; a PI or EMI operating under an untransposed home-state framework may face pushback from other member states arguing it hasn't met PSD3's higher standards.

The takeaway: final legislation doesn't mean the regulatory picture is complete. PIs and EMIs need to keep a close eye on how implementation plays out in each member state, as well as have a reliable way to monitor those developments, assess their impact, and act on them.

How Vixio helps payments and financial services master regulatory change

What we covered above is just the tip of the iceberg. Between parsing the actual legal text, mapping it against your operations, and proving compliance within the transition window, getting authorised (or reauthorised) for PSD3/PSR represents a significant amount of work.

That's where Vixio can help. Vixio is a regulatory change management platform purpose-built to help payments and financial services teams navigate this kind of regulatory complexity, from monitoring regulatory developments as they happen, to impact analysis, through to audit-ready proof of compliance.

Here’s what you can do with the platform:

Turn dense legal text into clear requirements

Reviewing legislation and figuring out what's actually new or relevant is the first hurdle, and it's a time-consuming one, especially when relevant updates are scattered across multiple jurisdictions and sources.

Vixio consolidates regulatory developments into a single place and surfaces them to you in an intelligent triage inbox, so you can stay on top of updates as PSD3 implementation unfolds across member states.

Within the platform, you can view the regulatory text directly, extract requirements highlighted within it, and turn any passage into an obligation in a click. 

You also have access to Vixio's expert-led analyst reports that break down what PSD3 and PSR mean in practice, including a playbook with actionable insights and next steps your team can take.

For quick answers along the way, you can ask natural-language questions to the VIQ assistant, which draws only from Vixio's verified, expert-written content.

Assess the impact on your operations

Once you know what's required, the next step is figuring out where your current processes fall short and what to prioritise first. 

Regulatory mapping lets you link obligations directly to your internal policies, procedures, and controls, giving you a clear view of where your operations already align with PSD3 and PSR and where they don't.

Advanced sorting and filtering also make it easy to isolate the highest-priority obligations, so your team can focus on what matters most first.

Action, track, and prove PSD3 compliance

With a 21-month transition period, managing tasks efficiently is critical. Vixio replaces scattered spreadsheets and email chains with centralised task and action boards, so you can create, assign, and track compliance work with clear ownership and deadlines.

Meanwhile, project tracking gives leadership a real-time view of progress across the organisation, which can help them catch bottlenecks early rather than at the deadline. 

And because regulatory mapping creates an audit-ready record connecting your processes to specific requirements, you'll have the documentation ready when it's time to prove compliance.

How FinteqHub relies on Vixio for real-time insights into regulatory compliance

More than 100 financial services firms rely on Vixio to navigate regulatory change, including FinteqHub, a payment gateway provider known for fast, seamless payment integrations across a range of industries.

According to the company's Head of Legal and Compliance, Tamara Makhatadze, Vixio stands out for its combination of technology and human expertise. Automated tools are useful for surfacing relevant facts and emerging trends quickly, but the decisions that matter most still call for human judgment and context.

Vixio brings together the best of both worlds, with FinteqHub relying on the platform’s AI-driven tools to quickly flag relevant regulatory developments, as well as Vixio's analysts for deeper, scenario-specific guidance when they need it.

Learn why FinteqHub recommends Vixio to legal teams and companies in payments.

Get ahead with PSD3 compliance and authorisation with Vixio

PSD3 and PSR bring meaningful changes to how PIs and EMIs operate. And with national implementation likely to vary across member states, keeping track of what applies where and by when will be an ongoing task.

Getting ahead of the requirements now puts your team in a stronger position to extract what's relevant, assess the impact on your operations, and get compliant and authorised by the time the deadline rolls around.

Vixio can help you get there. Request a call to see how.

FAQs on PSD3 compliance

What is PSD3?

The Payment Services Directive 3 (PSD3) is an EU directive that updates the payment services framework introduced under PSD2. It covers areas such as licensing and authorisation, capital requirements, governance, safeguarding customer funds and consumer protection for payment institutions and e-money institutions.

Because PSD3 is a directive, each EU member state must transpose it into national law before the relevant PSD3 compliance requirements apply locally.

What is the Payment Services Regulation?

The Payment Services Regulation is PSD3’s companion regulation. It covers operational requirements such as Verification of Payee, Strong Customer Authentication, payment fraud prevention, open banking, payment security and fraud liability.

Unlike PSD3, the regulation will apply directly and consistently across EU member states without requiring national transposition. Together, PSD3 and the Payment Services Regulation create the new EU regulatory framework for payment services.

Who must comply with PSD3 and the Payment Services Regulation?

PSD3 and Payment Services Regulation compliance applies to payment institutions, e-money institutions, banks and other payment service providers operating in the EU.

This includes non-bank fintechs and organisations providing regulated payment or electronic money services. The specific PSD3 requirements that apply will depend on the organisation’s regulatory status, business model and the payment services it provides.

When is the PSD3 compliance deadline?

The final PSD3 compliance deadline has not yet been confirmed.

Once the legislation enters into force, payment service providers are expected to have a defined implementation period in which to update their systems, policies and compliance processes. Full compliance is currently expected around 2028, although the exact timing may vary depending on the final legislative timetable and the national implementation of PSD3.

Organisations should begin their PSD3 readiness assessment and implementation planning before the final deadline is announced.

What is the difference between PSD2 and PSD3 compliance?

PSD3 and the Payment Services Regulation build on PSD2 by updating the rules for a more digital, competitive and secure payments market.

The new framework separates the rules into two legal instruments. PSD3 focuses mainly on licensing, authorisation, safeguarding, capital requirements, governance and regulatory supervision. The Payment Services Regulation covers operational requirements, customer rights and consumer protection.

Key areas of change include Verification of Payee, Strong Customer Authentication, fraud prevention, open banking, access to payment systems and fraud liability. Together, the reforms aim to improve payment security and create a more level playing field between banks and non-bank payment service providers.

What are the main PSD3 and Payment Services Regulation requirements?

The main PSD3 requirements are expected to cover the licensing and supervision of payment institutions and e-money institutions, including capital adequacy, governance, risk management and the safeguarding of customer funds.

Payment Services Regulation requirements will focus more heavily on how payment services are delivered. This includes Strong Customer Authentication, Verification of Payee, fraud monitoring, customer reimbursement rights, open banking services and access to payment account data.

The exact compliance obligations will depend on the services a payment service provider offers and where it operates.

How can payment service providers prepare for PSD3 compliance?

Payment service providers can prepare by carrying out a PSD3 readiness assessment to identify gaps between their current PSD2 compliance framework and the new PSD3 and Payment Services Regulation requirements.

A PSD3 implementation plan may include reviewing licensing and authorisation arrangements, safeguarding controls, governance, capital requirements, fraud prevention systems, Strong Customer Authentication and Verification of Payee processes.

Firms should also assess their open banking technology, API performance, customer communications, incident reporting and third-party provider arrangements. Starting early can help reduce regulatory risk and make the transition from PSD2 to PSD3 more manageable.

Turn these insights into your competitive advantage
Navigate complex compliance with our world-class regulatory insights.

Master your next market

Take a closer look at how we track and simplify global regulatory shifts in real-time