Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

Preparing for PSD3/PSR: the changes that matter

An overview of what financial institutions must do now to be ready for PSD3/PSR

The EU is modernising its payment rules through PSD3 and the new PSR. Framed as an evolution of PSD2, the impact is far from limited. Discover the six themes that will most affect payment institutions, from fraud liability to open banking, and learn what your organisation should start doing now.

What this blog series covers

Here is what is ahead

What must financial institutions do to be ready for PSD3/PSR?

The European payments landscape is set for a significant update. With the proposals for a third Payment Services Directive (PSD3) and a new Payment Services Regulation (PSR), the European Commission aims to modernise the rules first established under PSD2.

The Commission itself describes the proposals as an evolution of the existing framework rather than a revolution. Yet you should not mistake this for limited impact. The proposed changes are expected to require substantial implementation efforts. They affect Compliance, Risk, Technology and Operations functions, with challenges spanning governance, customer journeys, fraud prevention, operational processes and technology. 

The changes are coming, but they will not happen overnight. The legislative process is nearing its conclusion, though the final steps are taking longer than expected.

Both the Council and the European Parliament have adopted the texts at "technical level". What remains is formal adoption. Publication in the Official Journal of the EU was originally expected before summer 2026, but has been delayed; it is now anticipated around September/October 2026. Importantly, the substance of the agreed texts is not expected to change materially.

Once the final texts are published and enter into force — on the twentieth day after publication — the countdown begins. The PSD3/PSR package will generally apply 21 months after entry into force, meaning in 2028. For a few specific articles, notably those on liability for the IBAN/name matching verification service, a longer 27-month implementation period applies, meaning early 2029. 

While 2028 may feel distant, the governance, technology and process changes involved take time to design, test and embed. Organisations that begin scoping their gaps early will face far less pressure as the deadlines approach.

Rest assured, we will help you navigate with our PSD3 blog series

To help you navigate what lies ahead, we are publishing a blog series of eight instalments. A new blog goes live every two weeks, moving beyond the legislative intent to examine what these changes mean in practice. We explore the six themes that we believe will have the greatest impact on financial institutions, before concluding with a practical guide on how to prepare.

How can Deloitte help?

Deloitte's Regulatory Legal and Compliance experts combine deep legal analysis with strategic and practical (risk) insights to give you a more complete implementation picture. We are happy to guide you through the entire transition, including:

  • Readiness and impact assessment: a strategic gap analysis mapping your current state against PSD3/PSR requirements, identifying deltas in licenses, governance, contracts and processes.
  • Licensing and re-assessment: end-to-end management of the license re-assessment, including information provision to your regulator.
  • Implementation and remediation: closing gaps through policy drafting, updates to customer terms and conditions, and redesign of operational processes and governance.
  • Strategic and interpretive advice: clear answers on complex scoping questions and strategic implications, including the interaction with MiCAR.

Ready to prepare? Contact us to discuss what PSD3/PSR means for your organisation and stay tuned for the next blog in this series.