Back to Insights
Compliance

Navigating PSD3: what merchants need to know

Pochipay ComplianceJan 20, 2026 5 min read

PSD3 is coming — here's what's changing

The European Commission's Payment Services Directive 3 (PSD3) represents the most significant overhaul of EU payment regulation since PSD2 launched in 2018. Expected to be fully implemented by late 2026, PSD3 introduces sweeping changes to authentication requirements, open banking frameworks, and consumer protection standards.

For merchants processing European transactions, understanding these changes now is critical to maintaining compliance and avoiding disruption.

Stronger customer authentication (SCA) evolves

PSD3 refines the Strong Customer Authentication requirements introduced under PSD2. Key changes include expanded exemptions for trusted beneficiaries, higher thresholds for low-value transactions, and new provisions for machine-to-machine payments in IoT contexts.

The regulation also introduces performance benchmarks for authentication — issuers must maintain approval rates above certain thresholds when SCA is applied, addressing the decline rate issues that plagued early PSD2 implementation.

For merchants, this means fewer unnecessary authentication challenges for returning customers, which should translate to improved conversion rates on European transactions.

Open banking gets teeth

PSD3's companion regulation, the Payment Services Regulation (PSR), creates a more enforceable open banking framework. Banks will face stricter requirements for API performance, with financial penalties for interfaces that don't meet uptime and latency standards.

New data-sharing requirements expand beyond account information to include insurance products and investment accounts, creating opportunities for more comprehensive financial management tools.

For payment processors and merchants, this means more reliable pay-by-bank options and richer data for credit decisioning and financial product embedding.

Enhanced consumer protection

PSD3 significantly strengthens consumer protections, including mandatory instant refunds for unauthorized transactions (within 24 hours), extended liability coverage for payment fraud, and new provisions for protecting consumers from social engineering scams.

Merchants should review their refund and dispute processes to ensure they can meet the accelerated timelines. Payment processors like Pochipay will handle much of the technical compliance, but merchant-side processes need to keep pace.

How Pochipay is preparing

We've been tracking PSD3 since the initial proposal and have already begun implementing the required changes:

• Our SCA engine is being updated to support the new exemption categories and performance benchmarks

• Pay-by-bank integrations are being enhanced to leverage the improved open banking APIs

• Refund processing workflows are being accelerated to meet the 24-hour mandatory timeline

• Our compliance dashboard will include PSD3-specific reporting for merchants who need to demonstrate adherence

If you're processing European transactions through Pochipay, you'll be PSD3-compliant with zero integration changes required on your end. We'll handle the regulatory complexity so you can focus on growing your business.

Ready to get started?

See how Pochipay can power your global payment operations.