← Back to News
Regulation

PSD3 and PSR near the finish line as EU publication looms

With the final compromise text agreed in April, the PSD3/PSR package now awaits publication in the EU’s Official Journal, likely this summer. Banks, PSPs and merchants face new fraud, open banking and cash rules by 2028.

The EU’s new payment services rulebook is now locked in on substance. The political deal struck in trilogue on November 27, 2025 became a final compromise text on April 22, 2026, when the PSD3 directive and the Payment Services Regulation (PSR) cleared Coreper, the committee of member states’ ambassadors to the EU. What remains is procedure: formal adoption, legal-linguistic review and signature. Most law firms consider publication in the Official Journal of the EU realistic for summer 2026. For compliance teams, the countdown has already started.

A directive for licensing, a regulation for conduct

The package splits today’s PSD2 into two instruments. PSD3 keeps the rules on licensing and supervising payment institutions and e-money institutions. It also absorbs the second E-Money Directive (EMD2), which ceases to exist as a separate law. The PSR applies directly in all 27 member states, with no national transposition, and takes over most of the conduct rules: strong customer authentication, user rights and obligations, open banking, fee transparency and fraud prevention. That is a structural shift. The divergent national readings that undermined PSD2 will no longer be legally possible on the operational core.

TopicInstrumentLegal effect
Authorization, capital and supervision of PIs and EMIsPSD3 (directive)National transposition
SCA, exemptions, liabilityPSR (regulation)Directly applicable
Open banking (interfaces, dashboards)PSR (regulation)Directly applicable
Refunds for manipulation fraudPSR (regulation)Directly applicable
E-money (formerly EMD2)PSD3 (directive)Folded into the payment institution regime
How topics are split between PSD3 and the PSR

Fraud rules make up the bulk of the new obligations

  • Refunds for spoofing victims: when a fraudster impersonates the bank, using its phone number, name or email, to trick a customer into a credit transfer, the PSP will have to refund the customer, provided the victim has filed a police report and was not grossly negligent.
  • Payee name checks against the IBAN extend to all credit transfers, building on the Verification of Payee (VoP) already required under the Instant Payments Regulation.
  • Fraud data sharing between PSPs: a legal basis to exchange fraudulent IBANs and risk signals through shared arrangements.
  • Customer awareness and staff training requirements, with supervisors tracking fraud indicators.
⚠️
The spoofing refund is not unconditional
The refund covers impersonation of the PSP itself, not every manipulation scam. Romance scams and fake investment schemes, where victims initiate the payment without anyone posing as their bank, remain largely out of scope. Where the line falls on gross negligence, and who has to prove it, will generate a lot of litigation.
Close-up of a hand holding a mobile phone to someone’s ear
Victims of spoofing, where a fraudster poses as the bank to obtain a credit transfer, will be entitled to a refund if they have filed a police report and were not grossly negligent.

Open banking loses its workarounds

  • Dedicated interfaces (APIs) become mandatory for account information and payment initiation providers, with published performance and availability requirements.
  • Permission dashboards in the customer’s online banking, where users can see and revoke the access they have granted to third parties.
  • An explicit ban on the obstacles that dogged PSD2, such as unnecessary re-authentication and degraded user journeys.
  • The general requirement for a fallback interface goes away, replaced by remedial measures when an API fails.

Wider access to payment systems, bank accounts and cash

The package gives non-bank payment institutions the right to join designated payment systems directly, through an amendment to the Settlement Finality Directive (SFD). It also sets rules for their access to safeguarding accounts at banks, which will have to give reasons for any refusal. On cash, merchants will be able to offer cash withdrawals without a purchase, capped at €150 per transaction, and independent ATM operators get a lighter regime. Both measures aim to keep cash available outside major cities.

2007
PSD1
Creates the payment institution license.
2015
PSD2
SCA and open banking, applicable from 2018.
June 28, 2023
Commission proposes PSD3 and the PSR
November 27, 2025
Provisional trilogue agreement
April 22, 2026
Final compromise text released (Coreper)
Summer 2026
Official Journal publication expected
2028
PSR applies
Most obligations apply about 18 months after entry into force. PSD3 transposition follows a similar timetable.
🔑
What PSPs should start now
Run a fraud gap analysis covering spoofing, data sharing and VoP on all transfers. Draw up a roadmap for open banking APIs and dashboards. Review framework contracts and fee disclosures, and prepare for reauthorization: existing institutions will have to bring their license applications up to date with their national regulator. Eighteen months is not long for a payments IT stack.

Eight years after PSD2, the PSD3/PSR package is less a conceptual overhaul than a demanding consolidation: fewer gray areas, more measurable obligations and a clear tilt toward protecting the payer. Firms that treated PSD2 as a compliance chore will see more of the same. Those that used it as a competitive edge will finally get a harmonized playing field.

Provenance

Published July 9, 2026

3 sources, 3 distinct domains

↗ Racine · Parliament and Council reach agreement on the PSD3/PSR package (in French) · racine.eu↗ Norton Rose Fulbright · PSD3 and PSR: From provisional agreement to 2026 readiness · nortonrosefulbright.com↗ Morrison Foerster · PSD3 and the Payment Services Regulation: key developments · mofo.com
← All news