PSD3 Regulation: What the New EU Payments Framework Means for EMIs and PSPs

PSD3 Regulation

On 23 April 2026, the Council of the European Union published the final compromise texts for PSD3 regulation and its companion Payment Services Regulation, bringing nearly three years of negotiation close to conclusion. The reform began with the European Commission’s proposal in June 2023. With COREPER endorsing the texts on 22 April 2026 and the European Parliament’s ECON committee adopting both instruments on 5 May 2026, PSD3 regulation is no longer a future hypothesis for EMIs and PSPs. What remains – a plenary vote, formal Council adoption, and publication in the Official Journal, expected around mid-2026 – is procedural rather than substantive. It is a regulatory certainty with a defined, if still shifting, timeline.

The most consequential element of PSD3 regulation is structural. The directive will repeal both the Second Payment Services Directive and the E-Money Directive, folding electronic money institutions into a single payment institution licensing regime. Every EMI currently operating under the E-Money Directive will need to assess whether, and how, it qualifies for re-authorisation under the new framework.

This article examines what PSD3 regulation actually requires, what the PSD3 regulation timeline looks like from here to entry into force, and what EMIs and PSPs need to do operationally, not just legally, to prepare for a licensing regime that, for the first time, treats e-money issuance and redemption as one capability within a broader payment institution licence rather than a standalone category. The scale of the change is worth pausing on: this is the most significant restructuring of EU payments law since the original Payment Services Directive took effect in 2009, and the institutions best placed to absorb it are the ones that start the gap analysis now rather than waiting for the Official Journal publication.

What Is PSD3 Regulation and Why Does It Restructure the EU Payments Framework?

What is the structural difference between PSD3 regulation and the directive it replaces?

PSD3 regulation is built on a fundamentally different architecture than its predecessor. The previous framework required transposition into national law across all twenty-seven member states, a process that generated meaningful divergence in how identical rules were applied from one jurisdiction to the next. PSD3 regulation corrects this by splitting the subject matter into two distinct legal instruments. The directive itself remains a directive, governing authorisation, governance, capital requirements, safeguarding, and supervision of payment institutions. The Payment Services Regulation, by contrast, is directly applicable across all member states without national transposition, and it carries the conduct-of-business rules: customer information, transaction execution, strong customer authentication, fraud liability, and the open banking interface.

The European Commission’s reasoning is that fragmented national implementation undermined the single market that the previous directive was meant to create, and that this hybrid structure is the correction. For an EMI operating across more than one member state today, this split is not academic. It determines whether a future compliance gap is a national supervisory matter or a directly enforceable EU-wide standard.

What does PSD3 regulation mean for EMIs specifically?

The single most significant operational consequence of PSD3 regulation is the merger of the e-money institution regime into the payment institution licence. There will no longer be a separate E-Money Directive. Under the new framework, EMIs become a sub-category of payment institutions, and e-money issuance and redemption become a specific activity that a payment institution can be authorised to perform, rather than a standalone licensing category with its own rulebook.

psd3_regulation_emi_merger

Existing EMIs are not required to start the licensing process from zero. Transitional provisions allow currently authorised institutions to continue operating for up to twenty-seven months after PSD3 regulation enters into force, provided they supply their competent authority with the information needed to assess compliance with the new requirements within that window. If an EMI can demonstrate compliance, it is deemed authorised under the new regime without a fresh application. That said, “deemed authorised” still requires producing updated governance documentation, capital evidence, and safeguarding arrangements mapped to PSD3 regulation’s specific requirements, which is a substantive compliance exercise even without a full re-application.

How does PSD3 regulation address the overlap with crypto-asset regulation?

PSD3 regulation includes a specific carve-out for institutions already operating under MiCA. Issuers of e-money tokens who are already authorised as crypto-asset service providers under MiCA are not required to obtain separate authorisation under the new framework, unless they also provide payment services beyond e-money token issuance. For Baseella’s audience of crypto-asset service providers and EMIs operating adjacent to digital assets, this is a meaningful simplification, though it requires a precise legal assessment of which activities fall inside the MiCA authorisation and which trigger a separate obligation under PSD3 regulation.

What PSD3 regulation Changes for Day-to-Day Compliance and Operations

What new fraud liability does PSD3 regulation introduce?

The Payment Services Regulation that accompanies PSD3 regulation introduces the most consequential liability changes in the package. Verification of Payee, previously required only for instant credit transfers under the EU Instant Payments Regulation, is extended under the new rules to standard credit transfers as well, with failure to verify linked directly to refund and compensation outcomes.

PSD3 regulation also introduces a new refund right for victims of payment service provider impersonation fraud, the increasingly common scenario in which a fraudster spoofs a bank’s caller ID, email domain, or verified phone number to manipulate a customer into authorising a transfer. Under the agreed text, the payment service provider must reimburse the victim unless it can prove the customer acted with gross negligence or in collusion with the fraudster, and falling for a convincing spoof does not, on its own, meet that bar.

The existing refund obligation for unauthorised transactions is retained, with a modified procedure that permits the payer’s provider to defer the refund for up to fifteen business days where there are objectively justified suspicions of payer fraud, subject to a written explanation and a subsequent investigation.

What does PSD3 regulation require for open banking interfaces?

The new framework introduces considerably more prescriptive requirements for the dedicated interfaces that account-servicing payment institutions must maintain for account information and payment initiation providers. National regulators are now expected to act without delay against interfaces that fail to meet functionality standards, miss incident reporting timelines, or rely excessively on fallback interfaces when a dedicated interface is unavailable. Account information service providers, which under the previous regime were only required to register, gain passporting rights under PSD3 regulation, enabling them to operate cross-border on the strength of a single home-state registration rather than separate registrations in each member state.

What does PSD3 regulation mean for outsourcing and technical service providers?

PSD3 regulation tightens the requirements governing outsourcing arrangements, particularly for technical service providers that deliver strong customer authentication on behalf of a payment institution. These arrangements must now be governed by detailed written agreements, with the new rules requiring institutions to demonstrate that outsourcing does not impair operational resilience, that responsibilities are clearly allocated between the institution and the provider, and that audit rights, access rights, and contingency plans, including exit strategies, are documented in advance. This sits alongside, and in some respects anticipates, the operational resilience expectations already established under the Digital Operational Resilience Act.

The PSD3 regulation Timeline and What EMIs Should Do Now

What is the realistic PSD3 regulation timeline from here?

The PSD3 regulation timeline has moved from provisional political agreement to near-final text in a relatively short window. Parliament plenary vote expected to follow mid-summer 2026.

After that, the texts undergo legal-linguistic review before publication in the Official Journal of the European Union, though publication could slip to September. The Payment Services Regulation is expected to apply roughly twenty-one months after that publication, with the Verification of Payee provisions phased in over twenty-seven months. Transposition of PSD3 regulation into national law by member states is expected to follow a broadly similar timetable. In practical terms, this places general application of the new framework somewhere in the second half of 2027 to early 2028, with the twenty-seven-month transitional window for existing EMIs running from whenever PSD3 regulation formally enters into force.

psd3_regulation_timeline

What should EMIs and PIs do before PSD3 regulation applies?

Although the timeline gives institutions some runway, the gap analysis required is substantial enough that waiting for the Official Journal publication is not a sound strategy. EMIs should begin mapping their current governance documentation, capital structure, and safeguarding arrangements against the unified payment institution requirements now, while the final compromise texts are stable enough to work from. PIs more broadly should assess whether their fraud detection capability can support the impersonation fraud refund standard PSD3 regulation introduces, whether their account interfaces meet the uptime and incident reporting expectations the new rules set out, and whether their outsourcing contracts for SCA and other technical services include the audit and exit-strategy provisions now required.

How Baseella Supports PSD3 regulation Readiness

The infrastructure questions raised by PSD3 regulation are not abstract legal questions. They are platform design questions. Verification of Payee extended across all credit transfers, not just instant ones, requires the same always-on lookup and audit trail infrastructure that EMIs have already had to build for SEPA Instant Payments, now applied to a far larger share of transaction volume. The impersonation fraud refund standard under PSD3 regulation requires a transaction monitoring and case management capability that can demonstrate, after the fact, that reasonable detection standards were applied, which depends on having a complete and timestamped audit trail rather than fragmented logs across multiple systems.

Baseella’s core platform addresses these requirements as native capabilities rather than bolt-on modules. The account registry that supports Baseella’s Verification of Payee functionality extends without modification to standard credit transfers, satisfying the broadened scope PSD3 regulation introduces. The Risk Scoring and Block lists modules that drive real-time risk evaluation and sanctions screening generate the same complete, timestamped audit trail that PSD3 regulation’s fraud liability standard requires institutions to produce in a dispute or regulatory review. For EMIs working through the licensing transition PSD3 regulation introduces, Baseella’s reporting module supports the kind of granular, exportable transaction data that updated governance and prudential documentation will require under the new regime.

For EMIs and PIs assessing their readiness today, the practical questions are these: can your current platform extend Verification of Payee to your full credit transfer volume without a separate integration project, can your fraud detection and case management workflow produce the documented audit trail that the impersonation fraud standard under PSD3 regulation will demand, and does your governance and reporting documentation map cleanly onto a unified payment institution licence rather than a standalone e-money framework. The PSD3 regulation timeline still allows time to answer these questions properly. It does not allow time to ignore them.

Baseella is a core banking and payments platform built for electronic money institutions, payment institutions, neobanks, money service businesses, and crypto-asset service providers. To see how Baseella supports PSD3 regulation readiness, Verification of Payee, and fraud liability compliance, visit Baseella online or schedule a demo.