Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Regulation
Regulation

PSD3 and the Payments Services Regulation: What the Proposed EU Overhaul Changes for Licensing

The Commission's November 2023 proposals are still proposals — and their licensing architecture is the part payment institutions should read closest.

William Elliott, · March 30, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Payment licensing team reviewing EU framework proposal documents

The European Commission's payments package of November 28, 2023 — a revised Payment Services Directive ("PSD3") and a new Payments Services Regulation ("PSR") — remains in negotiation, which makes every element of it proposed rather than final, and its licensing design is the part with the longest implementation tail: the package would fold e-money institutions and payment institutions into a single licensing category, tighten the capital and governance expectations on all of them, and convert cross-border passporting friction into directly applicable Union rules under the regulation. Institutions building 2026 plans should treat PSD2 as the law and the package as a design signal with real weight.

3G Times publishes information, not legal advice. Authorization strategy under EU payments law belongs with European counsel and the relevant national competent authority.

Why merge payment and e-money institutions?

The 2023 diagnosis: two adjacent licenses had drifted into the same economic activity. Payment institutions and e-money institutions both hold customer funds; the boundary between stored value and payment execution blurred with every wallet product shipped; and the supervisory data showed firms choosing the lighter regime for the same risk. The proposal's answer is one institution type with one authorization, one safeguarding framework, and no more license-shopping between categories. For incumbents, the transition question is which bucket's obligations survive into the merged regime — the proposal's answer favors the stricter instrument on safeguarding and redemption, which e-money institutions will feel more than payment institutions.

What changes in capital and governance?

The proposal raises own-funds expectations where the 2023 evaluation found undercapitalization risk, tightens the fit-and-proper expectations for management bodies, and pushes national authorities toward consistent initial capital verification rather than pro-forma checks. Governance reads the same direction: harmonized internal-governance provisions move from guidance into the directive text, with the operational-resilience overlay that DORA already applies to ICT. For licensing strategy, the practical consequence is timing: applications filed in the transition window will be judged under rules that are hardening, and authorizations obtained on thin capital stories may face re-papering when the merged category arrives.

What does moving to a regulation accomplish?

A directive transposes; a regulation applies. The PSR carries the cross-border machinery — the passporting provisions, dispute resolution, and the fraud- and data-sharing duties — so that a payment institution's Union-wide rights no longer depend on twenty-seven national transpositions drifting at different speeds. The package's most operational PSR items read like a fraud-compliance wishlist with statutory teeth: IBAN-name verification at payment initiation, fraud-data sharing between providers, and confirmation-of-payee style services, each converting a current voluntary practice into a compliance expectation with liability allocation behind it.

ElementPSD2 todayPackage (proposed)
Institution categoriesPI and EMI separatelySingle merged category
Cross-border machineryDirective transpositionDirectly applicable regulation
IBAN/name checkingVoluntary overlaysStatutory duty with liability rules
Fraud data sharingLimited, contractualProvider-to-provider duty
Open-banking accessXS2A with exemption fightsAccess tightened; dashboard via FiDA package

For licensed account-information services, the transition economics matter as much as the law: the proposal's tightened access rules reward incumbents holding API infrastructure and raise the marginal cost of aggregation built on tolerance rather than contract. The strategic filing — a passport expansion or a license upgrade sought before the regime hardens — prices differently after the package lands, which is why the negotiation calendar is a licensing document even while the text is a proposal.

What does the package do to open banking's old fights?

PSD2's access-to-account regime produced a decade of litigation over licensing exemptions for account-information services and screen-scraping workarounds. The proposal tightens the perimeter — unlicensed access via customer credentials is squarely targeted — and pairs the directive with the Financial Data Access (FiDA) framework proposal, which extends account-data access to a broader open-finance universe on the consent-dashboard model. For fintechs built on aggregation, the two proposals together mean: the credential-scraping era ends, licensed access becomes the only lane, and the consent architecture becomes its own compliance surface. The licensing answer for aggregators is therefore not whether to authorize, but under which transitional reading to file.

The Treasury-grade reading also matters for fund flows: safeguarding documentation that already distinguishes client money, reconciles it daily, and names the insolvency position is portable across the merger, while commingled operational accounts re-paper under deadline. The gap analysis, done well, is mostly a safeguarding audit with a legislative overlay.

How should institutions read a still-proposed package?

By the civil-engineering rule: build for what is certain, option for what is probable. Certain enough to build for: the merged category's direction on safeguarding strictness, the regulation's direct applicability, the fraud-data-sharing duty's arrival in some form, and the end of credential-based scraping. Probable but negotiable: the capital numbers, the transitional periods, and the exact liability splits on verification services. The negotiation itself is trackable through the Council and Parliament positions, and institutions that mapped their license, products, and data flows against each published amendment were able to comment when comments still mattered — several of the package's 2025 redrafts visibly moved on precisely such filings.

What does this mean in practice?

PSD3's fate will be decided in rooms most fintechs never see. Its direction, though, has been legible since November 2023: one license, stricter funds rules, Union-wide application, and fraud duties with teeth. Reading it as a design constraint rather than a spectator sport is the difference between a transition plan and a scramble.

The final planning artifact is a decision tree: on adoption, which existing authorizations convert, which re-file, and which products pause. Written now against the proposed text and updated per amendment, it converts a regulation-in-motion into a checklist the day the Official Journal publishes — which is the only moment in this process when weeks are cheap.

Should institutions comment on the legislative process?

Where they can, through associations if not directly: the package's amendment history shows movement on transition periods, scope, and fraud-liability splits — precisely the items filings moved. Comment is cheap while the file is open and impossible after; trade bodies have been the effective channel for firms without Brussels desks.

Frequently asked questions

When would PSD3 actually apply?

Not before the legislative process ends and a transition period runs — realistic application dates sit years out from any 2026 adoption. Until then PSD2 governs in full; the package is planning input, not law.

Does the package affect crypto-asset services?

No — MiCA owns the crypto perimeter. The interfaces matter at the edges: stablecoin issuers holding e-money-token balances interact with safeguarding and settlement rules, and payment institutions handling crypto-linked flows keep both regimes' files.

What happens to screen scraping under the proposals?

The package targets it directly: access to payment accounts without the account-servicing institution's involvement, via customer credentials, is brought inside the licensed and regulated perimeter. Aggregators' future is licensed access under the directive-plus-FiDA consent architecture.

Frequently Asked Questions

When would PSD3 actually apply?
Not before the legislative process ends and a transition period runs — application dates sit years out from any 2026 adoption. Until then PSD2 governs in full; the package is planning input, not law.
Does the package affect crypto-asset services?
No — MiCA owns the crypto perimeter. Interfaces matter at the edges: stablecoin issuers and payment institutions handling crypto-linked flows keep both regimes' files.
What happens to screen scraping under the proposals?
It is targeted directly: credential-based access without the account-servicing institution's involvement moves inside the licensed perimeter. Aggregators' future is licensed access under the directive-plus-FiDA consent architecture.