PSD3 and PSR: final texts agreed. New obligations for payment institutions
On 23 April 2026, the Council of the EU published the agreed final texts (documents 8221/26 and 8222/26) of the Third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR), the package that will replace PSD2.
After the provisional political agreement of late November 2025 and the Council’s (COREPER) endorsement on 22 April 2026, the substance of the EU’s new payments rulebook is now settled, ahead of formal adoption and publication in the Official Journal expected around mid–2026.
This guide walks through what the agreed texts actually contain – the new structure, the re–authorisation of existing licences, safeguarding, fraud liability and open banking – and what it means for payment and e–money institutions in or into Poland, including UK and US groups.
What do the final provisions of PSD3 and PSR mean for the payments market?
The payments package was proposed by the Commission on 28 June 2023 as two instruments: PSD3 (a directive) and the PSR (a regulation). After lengthy trilogue negotiations, the European Parliament and the Council reached a provisional political agreement on 27 November 2025. The Council’s Permanent Representatives Committee (COREPER) endorsed the trilogue texts on 22 April 2026, and the agreed final texts were published on 23 April 2026.

What remains is largely procedural: a legal–linguistic review, adoption of the Council’s position at first reading and the Parliament’s approval at second reading (the ECON committee has recommended approval without amendments and has urged adoption by September 2026 at the latest), and publication in the Official Journal of the European Union, expected in the second half of 2026.
The PSR will then apply 21 months after its entry into force – with the payee-verification provisions (Articles 50 and 57 PSR) applying after 27 months – while PSD3 must be transposed into national law within the same 21-month period, which realistically points to application in 2028. The headline for the market is that the content of the rules is now effectively fixed, so firms can plan against it.
PSD3 and PSR instead of PSD2: the new regulatory framework for payment services in the EU
The most fundamental change in the agreed texts is structural. PSD2 (Directive (EU) 2015/2366) is a directive that each Member State transposed into national law – in Poland, the Payment Services Act of 19 August 2011 – which produced divergent rules across the EU. The new package splits the subject matter in two.
The PSR is a regulation: it applies directly in every Member State, without transposition, and governs the conduct of business – information duties, the rights and liabilities of users and providers, strong customer authentication (SCA), open banking, fraud prevention and access to payment systems.
PSD3 remains a directive: it governs authorisation, capital, safeguarding, governance and supervision of payment institutions, and must be transposed into Polish law. The effect is far greater harmonisation of conduct rules across the EU, with national discretion largely limited to authorisation and supervision.
How Will PSD3 Affect Electronic Money Institutions After EMD2?
One of the most structural points in the texts is the integration of e–money. The package repeals the Second E–Money Directive (EMD2, Directive 2009/110/EC) and folds electronic money institutions into the payment institution regime as a sub–category.
In practice, EMIs will be subject to the same authorisation, prudential and conduct framework as payment institutions, with specific rules for issuing and redeeming electronic money. Existing EMIs should map the differences between their current EMD2–based permissions and the new PSD3 requirements early.
Re-authorisation of PSD2 and EMD2 licences – new obligations for payment institutions
This is the point that most directly affects firms already on the market. Under the transitional regime in the texts, authorisations granted under PSD2 and EMD2 will not simply roll over indefinitely.
Payment institutions and e–money institutions will be required, within a transitional window of up to 27 months from PSD3’s entry into force, to review their authorisation and either re–apply or demonstrate compliance with the new PSD3 standards to the KNF; firms that do not complete the process risk losing the right to provide regulated services.
New applicants will need to meet the PSD3 requirements from the outset. For groups operating across the EU, this is also an opportunity to rationalise licensing and passporting.
Client Funds, Capital and Governance – Key KNF Review Areas
The texts tighten the prudential side. Expect enhanced own–funds and initial–capital expectations, a more detailed programme of operations, and stricter governance and outsourcing requirements aligned with the Digital Operational Resilience Act (DORA).
Safeguarding of client funds is a particular focus: the rules diversify and tighten how client funds must be protected (including segregation, permitted safeguarding accounts and an insurance or guarantee option), address concentration risk, and require winding–down plans.
For e–money and incoming–funds flows, tighter timing rules are expected. These are exactly the areas the KNF scrutinises on authorisation.
PSR and payment fraud: new rules on liability for spoofing and fraud
The PSR significantly strengthens anti–fraud rules and shifts liability. SCA is refined, with attention to accessibility and outsourcing. A payee–verification mechanism (an “IBAN/name check”) – already introduced for euro credit transfers (both standard and instant) by the Instant Payments Regulation (applicable in the euro area since 9 October 2025 and, for providers in non-euro Member States such as Poland, from 9 July 2027) – is extended to all credit transfers , so that providers must warn users of a mismatch before a transfer.
Crucially, the texts introduce new liability for “spoofing” or impersonation fraud: where a fraudster impersonates the provider (for example, by spoofing its name or number) and the conditions are met, the provider may have to refund the customer. Providers will also be liable where they fail to put adequate fraud–prevention measures in place, and fraud–related data sharing between providers is facilitated.

The agreed texts also settled some contested scope questions. They require very large online platforms and search engines (as defined under the Digital Services Act) to verify that advertisers of financial services hold the required authorisation, and give providers a right of recourse against online platforms which, once notified of fraudulent content, fail to remove it – while the broader new liability for technical service providers sought during the negotiations was ultimately not introduced.
The PSR is changing open banking. What’s next for FiDA and open finance?
The PSR upgrades open banking. Providers that hold payment accounts must offer reliable data–access interfaces, remove obstacles to access, and give users a “permission dashboard” to manage the access they have granted.
The aim is to make open banking work in practice. The broader move to “open finance” – access to a wider range of financial data – sits in the third element of the original package, the Financial Data Access Regulation (FiDA), which is still in negotiation and expected to follow separately.
PSD3 and PSR narrow the scope of the exemption for limited networks and trading agents
The texts tighten two exclusions that many businesses rely on. The limited network exclusion – used by gift–card and closed–loop schemes – is narrowed: an instrument must be usable only within a “single limited network,” a stricter test than before, and the rules harmonise how the notification threshold is calculated.
The commercial agent exemption, relied on by some marketplaces and platforms, is clarified, with the European Banking Authority mandated to issue guidelines. Firms that currently sit outside the regime on these grounds should re–test whether they still qualify.
New payment regulations: PSD3 and PSR in the context of MiCA and DORA
The package is designed to dovetail with the Markets in Crypto–Assets Regulation (MiCA): the rules coordinate the treatment of e–money tokens (EMTs) so that the same activity is not regulated twice, and a provider authorised under PSD3 may provide certain EMT–related services, subject to conditions and a notification procedure, without a separate licence, while crypto-asset service providers already authorised under MiCA will benefit from a streamlined PSD3 authorisation procedure.
DORA continues to govern ICT and operational resilience for the same institutions. Direct participation of payment institutions and e–money institutions in designated payment systems was already opened by the Instant Payments Regulation’s amendment of the Settlement Finality Directive; the PSR builds on this by harmonising the conditions of access to payment systems and by requiring non-discriminatory access to credit–institution accounts – a meaningful competitive shift relative to banks.
How can a payment institution prepare for PSD3 and PSR? Key steps
Even with application around 2028, preparation should start now.
In practice you should:
- map your current authorisation (payment institution, small payment institution, e–money institution) and prepare for re–confirmation under PSD3;
- run a gap analysis across capital, safeguarding, SCA, fraud–prevention and liability, governance and open–banking interfaces;
- re–test reliance on the limited network exclusion or the commercial agent exemption, both of which the texts narrow;
- update user terms, agent and technical–service–provider contracts, and the IT behind SCA, payee verification and open banking;
- if you are an e–money institution, plan your transition into the payment–institution regime.
Re-authorisation of payment institutions in the EU – when should you consult a lawyer?
Re–authorisation strategy, safeguarding structures, fraud–liability allocation and passporting decisions all carry real legal and commercial consequences, and the transitional rules are detailed. Legal support is worthwhile when you assess whether a re–application or a compliance demonstration is the better route, when you restructure safeguarding or contracts, or when you plan EU–wide expansion under the new passport.

For the current Polish licensing framework, see our guides to the Electronic Money Institution, Small Payment Institutions in Poland and DORA for Financial Entities in Poland; for the wider picture, see our guide to FinTech in Poland.
Frequently asked questions about PSD3 and PSR: deadlines, licences and obligations
What exactly was published on 23 April 2026?
The agreed final texts of PSD3 and the PSR – the version settled in trilogue (Council documents 8221/26 for the PSR and 8222/26 for PSD3). They still require a legal–linguistic review, formal adoption (the Council’s first-reading position followed by the Parliament’s second reading) and Official Journal publication (expected in the second half of 2026), but their content is now effectively fixed.
When do PSD3 and PSR start to apply?
After Official Journal publication (expected in the second half of 2026), the PSR applies 21 months after entry into force (verification of payee: 27 months) and PSD3 after national transposition within the same 21-month deadline – realistically in 2028.
Do existing payment institutions need a new licence under PSD3?
Not necessarily a brand–new licence, but they will have to review and re–confirm their authorisation within a transitional window of up to 27 months – either by re–applying or by demonstrating compliance with the new PSD3 standards. Firms that do nothing risk losing the right to operate.
Our FinTech team supports payment institutions, electronic money institutions and fintech companies in their comprehensive preparations for PSD3 and PSR – from gap analysis and re-authorisation strategies, through funds protection, SCA, open banking and liability for fraud, to the adaptation of contracts and IT systems.
We also regularly advise groups from the UK and the US that operate or plan to launch operations on the Polish and EU markets.
Contact us to assess the impact of the new regulations on your business and plan your compliance process.