On April 23, 2026, the Council of the European Union published final compromise texts for the Third Payment Services Directive (PSD3) and the new Payment Services Regulation (PSR). The texts were approved by national representatives the previous day, marking the last major drafting milestone before formal adoption and publication in the Official Journal of the European Union, which is anticipated for the second half of 2026.
The reforms replace PSD2 with a split structure: PSD3 governs licensing and supervision of payment institutions, while the PSR contains directly applicable operational rules covering strong customer authentication, open banking API performance standards, and fraud liability allocation. The PSR eliminates the implementation variation that plagued PSD2 across member states, as regulations apply uniformly without national transposition.
Key provisions include mandatory fraud reimbursement for authorized push payment scams where the payment service provider failed to meet detection standards, clearer requirements for API reliability and performance that prevent banks from degrading third-party access, and a merger of payment institution and e-money institution licensing categories. The new rules will apply 21 months after publication, placing the effective date in mid-to-late 2028.
For fintechs and payment service providers, the timeline creates a defined preparation window. API-based business models built on PSD2 access rights will benefit from strengthened technical standards that reduce the friction banks can impose. The fraud liability shift, modeled on the UK’s Contingent Reimbursement Model, will require PSPs to invest in transaction monitoring capabilities or face direct financial exposure to scam losses.