PSD3 is coming — here's what's changing
The European Commission's Payment Services Directive 3 (PSD3) represents the most significant overhaul of EU payment regulation since PSD2 launched in 2018. Expected to be fully implemented by late 2026, PSD3 introduces sweeping changes to authentication requirements, open banking frameworks, and consumer protection standards.
For merchants processing European transactions, understanding these changes now is critical to maintaining compliance and avoiding disruption.
Stronger customer authentication (SCA) evolves
PSD3 refines the Strong Customer Authentication requirements introduced under PSD2. Key changes include expanded exemptions for trusted beneficiaries, higher thresholds for low-value transactions, and new provisions for machine-to-machine payments in IoT contexts.
The regulation also introduces performance benchmarks for authentication — issuers must maintain approval rates above certain thresholds when SCA is applied, addressing the decline rate issues that plagued early PSD2 implementation.
For merchants, this means fewer unnecessary authentication challenges for returning customers, which should translate to improved conversion rates on European transactions.
Open banking gets teeth
PSD3's companion regulation, the Payment Services Regulation (PSR), creates a more enforceable open banking framework. Banks will face stricter requirements for API performance, with financial penalties for interfaces that don't meet uptime and latency standards.
New data-sharing requirements expand beyond account information to include insurance products and investment accounts, creating opportunities for more comprehensive financial management tools.
For payment processors and merchants, this means more reliable pay-by-bank options and richer data for credit decisioning and financial product embedding.
Enhanced consumer protection
PSD3 significantly strengthens consumer protections, including mandatory instant refunds for unauthorized transactions (within 24 hours), extended liability coverage for payment fraud, and new provisions for protecting consumers from social engineering scams.
Merchants should review their refund and dispute processes to ensure they can meet the accelerated timelines. Payment processors like Pochipay will handle much of the technical compliance, but merchant-side processes need to keep pace.
How Pochipay is preparing
We've been tracking PSD3 since the initial proposal and have already begun implementing the required changes:
• Our SCA engine is being updated to support the new exemption categories and performance benchmarks
• Pay-by-bank integrations are being enhanced to leverage the improved open banking APIs
• Refund processing workflows are being accelerated to meet the 24-hour mandatory timeline
• Our compliance dashboard will include PSD3-specific reporting for merchants who need to demonstrate adherence
If you're processing European transactions through Pochipay, you'll be PSD3-compliant with zero integration changes required on your end. We'll handle the regulatory complexity so you can focus on growing your business.