PSD3 and the EU Payment Services Regulation 2026: What Payment Firms Need to Prepare For
- Jul 3
- 26 min read

PSD3 and the EU Payment Services Regulation 2026: What Payment Firms Need to Prepare For
PSD3 and the new EU Payment Services Regulation will create the most significant restructuring of European payment regulation since PSD2. The reforms will change how Payment Institutions and Electronic Money Institutions are authorised, increase minimum capital requirements for several payment activities, bring electronic money issuance into a single Payment Institution framework, strengthen safeguarding and fraud controls, reform Open Banking and introduce more harmonised conduct requirements across the European Union.
The legislation is not yet in force. The European Parliament and Council reached political agreement on PSD3 and the Payment Services Regulation in November 2025, technical work was completed in March 2026 and the agreed texts were endorsed through COREPER and the European Parliament’s ECON Committee during April and May 2026. As of July 2026, lawyer-linguist work is continuing and final adoption and publication are expected during the fourth quarter of 2026.
Most of the substantive new requirements will not apply immediately after publication. The agreed framework generally provides for PSD3 to be transposed and applied 21 months after entry into force, with most corresponding PSR requirements applying on a similar timetable. Existing authorised PIs and EMIs receive additional transitional arrangements, but firms should not interpret the implementation period as a reason to wait before assessing the impact.
The changes affect regulatory permissions, capital, safeguarding, fraud liability, Strong Customer Authentication, Open Banking, payment account access and the legal status of existing EMIs. Firms applying for a new European licence during 2026 should therefore comply with the current PSD2 and Electronic Money Directive framework while designing their business sufficiently flexibly to transition into PSD3 and the PSR when the new rules apply.
PSD3 and the Payment Services Regulation at a glance
Area | Current framework | Agreed PSD3 / PSR direction |
Core legislation | PSD2 plus national implementing laws | PSD3 for authorisation/supervision plus directly applicable PSR for conduct rules |
Electronic Money Institutions | Separate EMI authorisation under E-Money Directive | EMI category integrated into a single Payment Institution authorisation framework |
E-money issuance | Separate e-money regulatory regime | Electronic money issuance becomes a regulated payment service within PI framework |
Money remittance initial capital | €20,000 | €40,000 under agreed PSD3 text |
PIS initial capital | €50,000 | €50,000 |
Main payment services initial capital | €125,000 | €150,000 |
Electronic money issuance | €350,000 EMI initial capital | €250,000 baseline for e-money issuance under agreed PI framework |
Multiple relevant services | Highest threshold generally determines current PI minimum | Certain PSD3 capital categories are cumulative where several specified services are provided |
Fraud prevention | PSD2/SCA framework | Stronger fraud monitoring, payee verification, information sharing and liability rules |
Open Banking | PSD2 account access framework | Prohibited obstacles, permission dashboards and stronger non-discrimination rules |
Safeguarding | PSD2 and EMD requirements implemented nationally | More harmonised safeguarding rules and future EBA technical standards |
Existing PI/EMI licences | Current national authorisations | Transitional assessment into new PSD3 framework |
Conduct requirements | Primarily national PSD2 implementation | Greater EU-wide harmonisation through directly applicable PSR |
The agreed figures and transitional arrangements remain subject to formal adoption and publication of the final legal texts. Firms should therefore use them for regulatory planning rather than treating them as requirements already in force. Until the new framework applies, existing PSD2, national payment-services legislation and the Electronic Money Directive continue to govern European PI and EMI authorisation and operation.
What is the difference between PSD3 and the Payment Services Regulation?
The European Commission deliberately divided the reform into a Directive and a Regulation because one of the weaknesses identified under PSD2 was inconsistent national implementation. PSD2 is a Directive, meaning each Member State transposed the requirements into its own national law, which created differences in interpretation, authorisation practices and enforcement across Europe.
PSD3 will continue to govern areas that require implementation through national law, particularly authorisation, prudential supervision and the institutional framework for Payment Institutions. The new Payment Services Regulation, usually referred to as the PSR, will place many conduct-of-business requirements directly into an EU Regulation that applies consistently across Member States.
This structure is intended to reduce regulatory fragmentation and forum shopping. A firm authorised in Lithuania, Ireland, Malta or another Member State should increasingly face the same core customer-facing payment rules when providing services across the EEA, rather than navigating materially different national interpretations of the same PSD2 provisions.
For payment firms, PSD3 and the PSR should therefore be treated as one reform package. PSD3 determines much of the regulatory framework around becoming and remaining an authorised Payment Institution, while the PSR governs much of how regulated payment services must be provided to customers.
PSD2 remains the law until the new framework applies
A common misconception is that the political agreement on PSD3 means firms should already be applying under the new rules. That is not the case because PSD3 and the PSR have not yet completed formal adoption, entered into force or reached their application dates.
Businesses applying for a European Payment Institution or Electronic Money Institution licence in 2026 must therefore continue to satisfy the current PSD2 and Electronic Money Directive regimes as implemented in their chosen home Member State. Regulators such as the Bank of Lithuania, Central Bank of Ireland, MFSA, DNB and other national competent authorities continue to authorise applicants under the existing legal framework.
The forthcoming changes are nevertheless relevant to application strategy because a firm authorised during 2026 or 2027 is likely to operate under PSD3 during the early years of its regulated life. A business model built around the absolute minimum current capital, outdated safeguarding architecture or assumptions that depend heavily on current regulatory classifications may require significant change shortly after launch.
The sensible approach is therefore dual-track. Applicants should comply fully with the current rules while assessing how the agreed PSD3 and PSR framework will affect permissions, capital, governance, safeguarding and technology when the transition takes place.
Electronic Money Institutions will be integrated into the Payment Institution framework
One of the most significant structural changes is the removal of the separate EMI authorisation category as it exists today. Under the agreed PSD3 framework, payment services and electronic money issuance will sit within a single Payment Institution authorisation regime, with issuing electronic money becoming a specific regulated payment service.
This does not mean electronic money disappears as a legal concept. Requirements concerning issuance, redeemability, safeguarding, outstanding e-money and own funds remain important because electronic money has characteristics that differ from ordinary payment services.
The change instead removes the need for two separate institutional categories operating under PSD2 and the Electronic Money Directive. A future authorised Payment Institution may hold permission to provide ordinary payment services, issue electronic money or combine several regulated activities within one PI authorisation.
For existing EMIs, this represents an important change in regulatory identity. Firms should expect their current EMI authorisation to transition into the new Payment Institution framework rather than assuming they will continue indefinitely as a legally separate category called an Electronic Money Institution.
Existing EMIs will not simply lose their licences
The transition is designed to avoid forcing every existing EMI to stop operating and submit an entirely new application from scratch on the day PSD3 takes effect. The agreed text allows existing authorised EMIs to continue their activities during a transitional period while their competent authority assesses whether they satisfy the new framework.
Existing EMIs operating before the relevant PSD3 application date can generally continue under their existing authority until 27 months after the Directive enters into force. During the transition, they will need to provide the information required by their regulator so that compliance with the new authorisation requirements can be assessed.
Where the competent authority already has sufficient evidence that an existing EMI complies with PSD3, the agreed framework permits automatic authorisation as a Payment Institution. Where further information or remediation is required, the firm will need to address those requirements within the transition period or risk restrictions on continuing regulated services.
This means firms should not interpret the transition as automatic grandfathering without regulatory review. Existing EMIs should prepare an evidence pack showing how their governance, safeguarding, financial resources, business plan and control environment satisfy the new regime before national regulators begin requesting that information.
Existing Payment Institutions will also undergo a transition assessment
Existing PIs receive a similar transitional mechanism. Payment Institutions authorised under PSD2 before the new framework becomes applicable can continue providing the services for which they are authorised while the competent authority assesses their position under PSD3.
The agreed text provides for continuation until 27 months after entry into force, subject to the firm providing the information required by its competent authority. Where the regulator has evidence that the institution already meets the relevant PSD3 requirements, the firm can be treated as authorised under the new framework without undergoing an entirely new application process.
Firms that fail to demonstrate compliance within the applicable transitional period can ultimately be suspended from providing payment services until the required information has been supplied and verified. An exceptional extension of up to three months can be available in defined circumstances, but firms should not build their transition strategy around obtaining additional time.
Existing PIs should therefore expect a regulatory validation exercise rather than assume their current licence will simply be renamed automatically. The work required will depend on the firm’s present governance, capital, permissions, safeguarding and whether its operating model has changed materially since original authorisation.
PSD3 changes the initial capital requirements
The agreed PSD3 text materially changes several of the initial capital thresholds currently applying under PSD2 and the Electronic Money Directive. These changes are particularly important for new applicants, existing money remitters and firms combining several payment and e-money services.
Under the agreed framework, a Payment Institution providing only money remittance would require at least €40,000 of initial capital, compared with €20,000 under PSD2. Payment initiation services retain a €50,000 minimum, while institutions providing the main payment services covered by the broader category, including payment-account, execution, card and acquiring activities, would generally require €150,000 instead of the current €125,000.
Electronic money issuance would carry a €250,000 initial capital requirement within the new Payment Institution framework. This is lower than the current €350,000 initial capital requirement applicable to a full EMI, reflecting the reform’s narrower treatment of e-money issuance as a particular regulated payment service within the combined PI framework.
The most important point is that these figures are contained in the agreed PSD3 text but are not yet current legal requirements. A firm applying in 2026 remains subject to current capital rules until the new legislation becomes applicable.
Future initial capital can be cumulative for multi-service firms
A significant feature of the agreed PSD3 capital framework is the treatment of institutions providing more than one category of regulated service. Under the current PSD2 structure, an API providing several payment services generally applies the highest relevant initial capital threshold rather than adding each threshold together.
The agreed PSD3 text changes this approach for specified combinations. Where an institution provides services falling into more than one of the relevant capital categories, including payment initiation, mainstream payment services and electronic money issuance, the minimum amounts can be added together.
This could materially affect diversified fintechs. A future institution combining e-money issuance with services that independently fall within the €150,000 category may face a higher initial capital requirement than a business providing only one of those categories.
Applicants planning multi-product European platforms should therefore model capital against the future permission mix rather than focusing only on the current EMI or PI minimum. The exact impact should be confirmed once the final legal text is formally adopted, but the agreed framework already gives firms sufficient direction to begin scenario planning.
Ongoing own-funds requirements remain important
Initial capital is only the entry point. PSD3 retains ongoing own-funds requirements and continues the principle that a Payment Institution must maintain capital at least equal to the higher of its applicable initial capital and the ongoing own-funds amount calculated under the relevant methodology.
The agreed framework retains methods linked to payment volumes, income and other prudential measures, with regulatory authorities able to adjust requirements based on the institution’s risk-management processes and internal controls. Electronic money activity remains subject to a Method D-style requirement based on 2% of average outstanding electronic money.
Where a future Payment Institution both issues electronic money and provides other regulated payment services, the own-funds calculation can therefore require the institution to account separately for the different activities. Diversified firms should expect capital planning to become more granular rather than assuming one simple threshold covers every service.
Financial forecasts should be redesigned accordingly once the final rules are published. Firms that maintain only a narrow buffer above current regulatory capital minimums may be particularly exposed to the transition and should assess whether additional shareholder funding could be required.
Safeguarding becomes more harmonised
PSD3 strengthens and harmonises the safeguarding framework for customer funds. One of the Commission’s concerns under PSD2 was that safeguarding requirements were applied differently between Member States, creating uncertainty for both customers and payment firms operating cross-border.
The agreed framework continues to allow segregation of relevant customer funds or protection through an insurance policy or comparable guarantee, subject to the regulatory conditions. Where customer funds remain held beyond the specified period, segregation can involve appropriate separate accounts with qualifying institutions or investment in secure, liquid, low-risk assets.
PSD3 also introduces clearer requirements around safeguarding concentration risk. The EBA is expected to develop technical standards specifying when institutions should avoid excessive concentration of safeguarded funds with a single credit institution and how safeguarding risk should be managed more consistently.
Firms should therefore review not only whether customer funds are segregated but whether the overall safeguarding structure is resilient. Concentrating almost all safeguarded funds with one bank may become more difficult to justify where credible diversification is available and concentration creates material risk.
Customers will receive more information about safeguarding
The agreed rules also increase transparency around what happens to safeguarded money if a Payment Institution fails. Firms will need to provide customers with clearer information about how their funds are safeguarded, which Member State’s insolvency law applies and where a claim would need to be brought if the institution entered insolvency.
This requirement reflects the cross-border nature of European payments. A customer in France may use a PI authorised in Lithuania whose safeguarding bank is located in another Member State, making it difficult for the customer to understand which insolvency protections actually apply.
Payment firms should therefore review customer terms and safeguarding disclosures as part of PSD3 implementation. Legal accuracy will matter, but the information should also be understandable enough for customers to know the basic protection attached to their funds.
Groups operating several European entities may face additional complexity because different customers can be contracted with different regulated firms. The correct safeguarding disclosure will need to correspond with the legal entity actually providing the regulated service rather than using generic group-wide wording.
Settlement accounts and payment system access become more important
PSD3 recognises the increasing importance of non-bank Payment Institutions having effective access to payment infrastructure. The agreed framework provides additional clarity around how customer funds can be used in settlement accounts connected with designated payment systems while remaining appropriately protected.
This is important because PIs increasingly participate directly or indirectly in payment systems rather than relying entirely on traditional correspondent banking models. Where customer funds are needed to provide liquidity for settlement, the regulatory framework must balance operational efficiency with safeguarding protection.
The agreed text allows specified settlement arrangements to satisfy safeguarding requirements where appropriate conditions are met and the funds are ultimately held within qualifying institutions or central banks. The EBA is expected to develop technical standards covering segregation and reconciliation of customer funds held in relevant settlement accounts.
Payment Institutions considering direct scheme access should therefore assess PSD3 alongside other reforms improving access to payment systems. The future framework may create stronger opportunities for non-bank PSPs to reduce reliance on intermediary banks, but treasury, safeguarding and liquidity controls will need to evolve accordingly.
Bank account access for Payment Institutions should improve
Difficulty obtaining and maintaining bank accounts has been a longstanding problem for non-bank payment firms across Europe. PSD3 and the PSR seek to improve the position by strengthening requirements around non-discriminatory access to payment accounts for authorised Payment Institutions.
Banks will be expected to assess access on a proportionate and objective basis rather than excluding PIs automatically because they operate within the payments sector. Where access is refused or withdrawn, the framework is intended to create greater transparency and accountability around that decision.
This does not mean every bank must accept every Payment Institution. Banks retain their own financial crime, risk appetite and prudential responsibilities and can refuse relationships where objectively justified.
The reform nevertheless strengthens the regulatory principle that authorised non-bank PSPs should not face unjustified barriers simply because of their institutional category. For fintechs, this could gradually improve one of the most persistent operational difficulties associated with building a European payments business.
Fraud prevention is one of the largest areas of reform
Payment fraud is central to the new PSR. The framework responds particularly to the growth of social-engineering scams, impersonation fraud, account takeover and other forms of authorised and unauthorised payment fraud that developed rapidly after PSD2 was introduced.
Payment Service Providers will be expected to operate stronger transaction-monitoring and fraud-prevention systems, with both payer and payee PSPs playing roles in identifying suspicious activity. The agreed framework includes real-time monitoring expectations, information sharing between PSPs and stronger preventive tools such as spending limits and payment-blocking capabilities.
These controls need to operate before losses occur rather than relying solely on reimbursement afterwards. A firm processing high volumes of instant or near-instant payments will therefore need technology capable of assessing suspicious activity quickly enough to intervene without making ordinary payment services unusable.
Payment firms should begin reviewing whether current fraud systems can meet that standard. Transaction monitoring built primarily around AML detection after transactions have completed may not provide the real-time fraud intervention capability required by the future framework.
Payee name and account verification will expand
The new rules extend verification requirements intended to detect situations where the name of the intended payee does not match the relevant payment account identifier. A similar concept already exists through Verification of Payee requirements for euro instant payments, but the agreed PSR extends the protection more broadly to credit transfers within the Union.
Where relevant information does not match, customers will need to be warned or the payment handled in accordance with the future regulatory requirements. The objective is to reduce fraud where criminals persuade victims to send money to an account that does not belong to the person or organisation the victim believes they are paying.
For PSPs, implementation will require more than adding a message to the payment screen. Systems need reliable access to beneficiary information, matching logic, customer warnings, exception handling and evidence that the verification process operated correctly.
Firms entering new European markets should therefore consider whether their payment infrastructure can support payee verification across multiple currencies and account systems. This can become a significant technology and operational project for cross-border platforms.
Impersonation fraud creates new reimbursement exposure
The agreed PSR introduces stronger consumer protection where a fraudster impersonates a customer’s Payment Service Provider and manipulates the customer into authorising a payment. Under specified conditions, the customer can become entitled to reimbursement where the fraud is reported appropriately to the PSP and law-enforcement authorities.
This represents an important extension of liability beyond the traditional distinction between authorised and unauthorised transactions. A payment may technically have been approved by the customer but still generate reimbursement obligations where approval was obtained through defined impersonation fraud.
The legislation also clarifies that authentication does not automatically prove that a payment was genuinely authorised. This matters where criminals obtain credentials or manipulate authentication processes in a way that makes the transaction appear technically valid.
PSPs should therefore review fraud investigation and reimbursement processes alongside authentication technology. The operational challenge will be distinguishing genuine impersonation claims from other payment disputes while meeting required customer-protection standards.
Failure to use fraud prevention tools can increase PSP liability
The new framework links preventive obligations more closely to financial liability. Where a PSP fails to implement required fraud-prevention mechanisms, it can become responsible for customer losses that proper use of those mechanisms was intended to prevent.
This creates a strong incentive to treat fraud controls as regulatory infrastructure rather than optional risk-management enhancements. Payee verification, transaction monitoring, blocking mechanisms and other required tools will need demonstrable governance and testing.
A firm should be able to evidence that the control operated at the relevant time and explain why a transaction was executed, delayed or stopped. Weak logging or inability to reproduce the decision made by an automated fraud model can therefore create both operational and regulatory problems.
Boards should expect fraud management to become a more significant conduct and financial risk. Reimbursement exposure can affect customer outcomes, complaints, operational costs and potentially the economics of high-risk payment products.
Fraud information sharing between PSPs will expand
Payment firms frequently see only one part of a fraudulent transaction. The payer’s PSP may understand how the victim was manipulated, while the receiving PSP can see whether the beneficiary account is connected with multiple suspicious payments.
PSD3 and the PSR strengthen the basis for PSPs to share fraud-related information so that intelligence can be used across the payment chain. This should improve the ability to identify mule accounts, repeated beneficiary patterns and emerging scam typologies before further customers suffer losses.
Information sharing still needs appropriate governance around privacy, security, proportionality and data quality. Firms should not interpret the framework as permission to circulate unverified allegations without control.
The operational opportunity is nevertheless substantial. PSPs that combine internal transaction information with reliable industry fraud intelligence can identify patterns that would be difficult to detect from their own customer base alone.
Strong Customer Authentication will be refined rather than removed
PSD3 does not abandon Strong Customer Authentication. Instead, the PSR updates the framework to address practical weaknesses identified under PSD2 and adapt authentication to evolving fraud risks and technology.
The EBA is expected to develop further technical standards covering SCA, exemptions and related requirements. The agreed framework also strengthens controls around areas such as mobile-app activation and recognises the need to balance security with accessibility and user experience.
Payment firms should therefore avoid major long-term authentication architecture decisions based solely on current PSD2 interpretations. The core requirement for robust authentication remains, but the detailed technical framework will evolve as Level 2 measures are developed.
Firms should also ensure that SCA is integrated with fraud monitoring rather than treated as sufficient protection by itself. A transaction can satisfy technical authentication requirements and still be fraudulent where a customer has been manipulated or credentials have been compromised.
Open Banking should become more consistent across Europe
One of PSD2’s major achievements was creating the legal framework for Payment Initiation Service Providers and Account Information Service Providers. Implementation has nevertheless varied significantly between banks and Member States, with TPPs frequently encountering inconsistent APIs, access barriers and customer journeys.
The new PSR seeks to reduce these obstacles by defining practices that Account Servicing Payment Service Providers cannot use to obstruct authorised Open Banking providers. PISPs and AISPs should have more reliable access to the payment account information and functionality needed to provide their authorised services.
The reform also introduces greater transparency for customers. Payment service users will have access to permission dashboards allowing them to see and manage the data-access permissions they have granted to third-party providers.
For Open Banking firms, this should improve consistency and customer control. Banks and other ASPSPs will need to review API architecture, consent management and the treatment of third-party providers to ensure they do not create prohibited barriers.
Permission dashboards will change consent management
The requirement for customers to manage Open Banking permissions through dashboards has practical implications for both banks and third-party providers. Customers should be able to understand which providers have access, what permissions have been granted and manage those permissions more easily.
This requires accurate data exchange between the organisations involved. If consent information is inconsistent between the bank and TPP, customers can receive misleading information about which permissions remain active.
Firms should therefore treat the dashboard requirement as a data-governance and systems issue as well as a customer-interface change. Consent records, expiry, revocation and API access need to remain aligned.
The wider objective is to increase trust in Open Banking. Customers who can see and control access more easily may be more willing to use third-party services, supporting the competition objectives that originally underpinned PSD2.
Mobile device providers face new access requirements
The agreed framework also addresses dependence on mobile devices and digital platforms. Manufacturers of mobile devices and providers of relevant electronic services can be required to allow payment service front-end providers access to technical functionality needed to store and transfer data for payment processing on fair, reasonable and non-discriminatory terms.
This is relevant to wallets and payment applications that depend on smartphone functionality controlled by major technology companies. Restricted access to hardware or operating-system capabilities can affect competition even where a fintech has the necessary financial-services authorisation.
The reform therefore extends beyond banks and Payment Institutions and recognises that modern payment competition depends partly on access to technology infrastructure. The practical impact will depend on the final rules and how they interact with other EU digital regulation.
Fintechs developing wallet or mobile payment products should monitor this area carefully. Improved technical access could create new commercial opportunities once the framework becomes operational.
Payment fee transparency will increase
The PSR strengthens transparency requirements for charges associated with payment services. Customers should receive clearer information about fees before a transaction is initiated, including relevant currency-conversion charges and charges associated with cash withdrawal.
Merchant acquiring is also affected. Providers of card payment facilities will need to provide clearer information about the fees charged to merchants, improving the ability of businesses to understand the cost of payment acceptance.
Cross-border payments receive additional attention because customers can struggle to understand foreign exchange margins and the timing or cost of payments involving third-country PSPs. The agreed framework includes stronger information requirements around currency conversion and, where relevant, expected transmission times.
Payment firms should therefore review whether current fee disclosures explain the real economic cost of the service. A technically disclosed fee can still create poor transparency where significant revenue is embedded elsewhere in the pricing structure.
Human customer support remains relevant despite automation
The agreed framework recognises that digital financial services increasingly rely on automated customer support, but it also preserves the need for customers to access human assistance. Payment firms should not assume that a chatbot-only service model will satisfy every future customer-support obligation.
This is particularly important in fraud, payment blocking, vulnerable customer and dispute situations. Customers dealing with a suspicious or missing payment may need effective escalation beyond automated scripts.
Technology can continue to automate routine support and improve efficiency, but firms should design escalation paths capable of providing meaningful human intervention where appropriate. The requirement also aligns with the broader European focus on ensuring digital financial services remain accessible and understandable.
Businesses planning highly automated operating models should therefore include customer-support resources within PSD3 implementation planning. Regulatory expectations around support can affect staffing, outsourcing and the economics of the service.
Alternative dispute resolution requirements will strengthen
The PSR also strengthens the framework for payment disputes. PSPs will be expected to participate in appropriate alternative dispute resolution mechanisms for consumer disputes, subject to the final national and EU arrangements.
Customers must receive clear information about available ADR procedures, including in relevant payment-service contracts and communications. This increases the importance of complaint-handling systems capable of identifying, investigating and resolving regulatory complaints effectively before disputes escalate.
Cross-border firms need particular care because customers may be located in several Member States while the institution is supervised from one home jurisdiction. The appropriate dispute mechanism and customer communications should therefore be mapped across the passporting structure.
Complaints data can also provide important regulatory intelligence. Firms should use recurring disputes to identify weaknesses in payment execution, fraud handling, fees or customer communications rather than treating each complaint as an isolated case.
Authorisation should become more harmonised
PSD3 seeks to reduce differences in how national regulators authorise Payment Institutions. The agreed text introduces more harmonised application requirements and maintains the principle that a complete application should be decided within three months once the regulator has received all information needed to assess it.
The EBA will develop technical standards on information required for authorisation and a common assessment methodology. This should reduce some of the national divergence that has historically encouraged applicants to compare jurisdictions based on perceived differences in regulatory difficulty.
Authorisation will still be conducted by national competent authorities, so differences in regulatory interaction and local operating environments will not disappear completely. However, the underlying evidence required from applicants should become increasingly consistent.
Our guide to EU Payment Institution and EMI Licensing 2026 explains why jurisdiction selection should therefore be based on genuine substance and commercial fit rather than searching for the regulator perceived to be easiest.
Wind-down planning becomes an explicit authorisation consideration
The agreed PSD3 framework includes an express requirement for an appropriate winding-up or wind-down plan within the authorisation information. The plan should reflect the size and business model of the applicant and demonstrate how payment services could be terminated in an orderly manner if the institution fails.
This brings payment authorisation closer to the wider European regulatory focus on operational and financial resilience. A firm should understand how it would return customer funds, terminate contracts, maintain critical staff and systems and communicate with customers during an orderly exit.
For existing institutions, wind-down planning should therefore be reviewed before transition. A plan produced several years ago for the original PSD2 application may no longer reflect current customer numbers, group dependencies or payment infrastructure.
Applicants should also integrate wind-down assumptions into financial forecasts. A credible plan needs sufficient financial resources to execute the exit rather than simply describing procedural steps.
DORA now forms part of the wider regulatory architecture
PSD3 operates alongside the Digital Operational Resilience Act, which already applies to relevant financial entities across the EU. Payment Institutions and Electronic Money Institutions therefore need to consider operational resilience, ICT risk, incident management and third-party dependencies through the combined regulatory framework.
The agreed PSD3 authorisation requirements expressly interact with information required under DORA, avoiding unnecessary duplication where relevant material has already been provided. This does not reduce the substantive standard; it reflects the fact that operational resilience is already governed through a specialised EU regulatory regime.
Firms should therefore avoid creating separate regulatory silos for PSD3 and DORA. Governance, outsourcing, cyber security, incident management and business continuity should operate as one coherent control framework.
New applicants should design this architecture from the outset. Retrofitting DORA controls after building a payment platform can create considerably more cost than integrating resilience requirements into technology and outsourcing decisions early.
PSD3 also interacts with MiCA and e-money tokens
The relationship between payments regulation and MiCA has become increasingly important because e-money tokens are both cryptoassets under MiCA and legally linked to electronic money concepts. Certain services involving e-money tokens can also constitute regulated payment services.
The agreed PSD3 framework recognises this interaction and provides for streamlined authorisation treatment in certain circumstances for cryptoasset service providers already authorised under MiCA. The objective is to avoid unnecessary duplication while ensuring that firms providing regulated payment services still meet the relevant payment-services requirements.
Not every cryptoasset transfer is automatically a payment service. The regulatory analysis depends on the asset, the activity and whether the transaction falls within the relevant PSD3 and PSR scope or an applicable exclusion.
Groups combining MiCA activities with payments should therefore map permissions across both regimes. A CASP licence should not be assumed to replace payment authorisation where regulated payment services are also provided.
What should existing PIs do during 2026?
Existing Payment Institutions should begin with a structured PSD3 gap assessment rather than waiting for national regulators to request transition information. The review should compare current permissions, capital, safeguarding, fraud controls, SCA, Open Banking arrangements, customer disclosures, governance and wind-down planning against the agreed framework.
Capital modelling deserves early attention because the future thresholds can materially affect money remitters and multi-service institutions. Firms currently operating with limited capital headroom should understand how the €40,000 and €150,000 thresholds, together with cumulative requirements for certain combinations, could affect their funding needs.
Fraud technology should also be reviewed because real-time monitoring, payee verification and strengthened liability can require substantial systems development. Larger technology projects may take longer to implement than the legislative transition period appears to provide once final technical standards are considered.
Boards should assign clear ownership for the transition. PSD3 affects compliance, finance, product, technology, operations and customer experience, making it unsuitable as a project owned solely by the compliance department.
What should existing EMIs do during 2026?
EMIs face the additional structural issue of moving into the future Payment Institution framework. Management should therefore assess not only compliance gaps but how the firm’s current e-money and payment services will map to the new permission structure.
Capital should be modelled carefully. The agreed €250,000 e-money issuance baseline appears lower than today’s €350,000 EMI minimum, but a diversified EMI providing other payment services can face cumulative initial capital requirements and ongoing own-funds calculations that produce a different overall result.
Safeguarding also remains central. The change in institutional label does not reduce the obligation to protect funds received for electronic money issuance, and firms should expect more harmonised safeguarding and concentration-risk standards.
Existing EMIs should prepare documentation that allows their competent authority to assess transition efficiently. A firm with current governance records, accurate permission mapping, strong prudential calculations and a well-maintained regulatory framework will be better positioned than one attempting to reconstruct evidence only after a formal request arrives.
What should new EU licence applicants do now?
Businesses applying for a PI or EMI licence during 2026 should continue under the current legal framework because PSD3 has not yet replaced PSD2 or the Electronic Money Directive. Delaying a commercially necessary licence solely because PSD3 is coming may therefore be unnecessary, particularly where the business intends to launch before the new framework applies.
The application should nevertheless be future-aware. Financial forecasts can model the likely PSD3 capital impact, safeguarding structures can be designed with concentration risk in mind and governance arrangements can incorporate robust wind-down and operational-resilience standards from the beginning.
Applicants should also avoid over-optimising the business around current institutional labels. A company obtaining an EMI licence today should understand that it is likely to transition into a Payment Institution authorised to issue electronic money under the future framework.
The same principle applies when choosing a licensing jurisdiction. PSD3 aims to reduce differences between Member States, so the long-term value of selecting a jurisdiction purely because of perceived regulatory arbitrage is likely to decline further.
Does PSD3 affect UK Payment Institutions and EMIs?
PSD3 and the EU PSR will not automatically apply to FCA-authorised UK Payment Institutions and Electronic Money Institutions because the United Kingdom is no longer part of the EU regulatory framework. A UK API or AEMI remains subject to the UK Payment Services Regulations, Electronic Money Regulations, FCA Handbook and other applicable UK rules unless domestic legislation changes.
The UK is conducting its own major reform of payment services regulation. HM Treasury’s July 2026 consultation proposes modernising the PSRs and EMRs, reconsidering the organisation of regulated payment activities and addressing developments including stablecoins, Open Banking and agentic payments.
Groups operating in both the UK and EU therefore need to manage two evolving regulatory frameworks. The direction of travel has similarities, including greater focus on fraud, innovation and regulatory modernisation, but the legal structures and implementation timetables are different.
Buckingham Capital Consulting specialises in both UK and European payment and e-money regulation. International groups should therefore assess regulatory change separately for each authorised entity rather than assuming that implementation of PSD3 automatically resolves UK compliance requirements.
A practical PSD3 readiness programme
A strong readiness programme should begin by mapping the current business against the agreed future permission structure. Firms should identify every regulated activity, determine how electronic money issuance and payment services will sit within the future PI framework and assess whether existing passporting, agents and distribution structures remain appropriate.
The second workstream should cover prudential impact. Initial capital, ongoing own funds, projected growth and potential cumulative requirements should be modelled across several scenarios so that shareholders understand whether additional funding may be required before transition.
The third workstream should focus on operational change. Safeguarding, fraud prevention, payee verification, SCA, Open Banking, customer disclosures, complaint handling and technology architecture should be assessed against the agreed reforms, with larger implementation projects prioritised early.
Finally, the firm should prepare for regulatory transition. Governance records, current policies, authorisation information and evidence of compliance should be maintained in a form that can be provided efficiently when the home regulator begins its PSD3 assessment of existing institutions.
Do firms need to implement everything immediately?
No. PSD3 and the PSR were not formally in force as of July 2026, and many detailed requirements will depend on final adoption, publication and Level 2 technical standards developed by the EBA.
Implementing speculative requirements prematurely can waste resources where the final rules or technical standards change. Firms should therefore distinguish between changes that are sufficiently certain to affect strategic planning and detailed implementation that should wait for final legal or technical requirements.
Capital, legal-entity strategy, product architecture and major technology decisions can reasonably be assessed now because they have long lead times. Detailed forms, reporting templates and technical SCA configurations may need to wait until the relevant final standards are available.
The right approach is readiness rather than premature compliance. Firms should know where the likely gaps are, budget for change and ensure that major commercial decisions made in 2026 do not make future compliance unnecessarily difficult.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting advises Payment Institutions, Electronic Money Institutions and fintech businesses on UK and European payment regulation, including authorisation, regulatory change, compliance and cross-border structuring. We can assess how PSD3 and the new Payment Services Regulation affect an existing regulated business or a new applicant preparing to enter the European market.
For existing PIs and EMIs, we can conduct a PSD3 readiness and gap assessment covering permission mapping, capital, safeguarding, governance, fraud controls, Open Banking, operational arrangements, wind-down planning and the transition evidence likely to be required by the home regulator. The output can be converted into a prioritised implementation programme aligned with final adoption and the future application timetable.
For new market entrants, we support the complete EU licensing strategy, including selection of the appropriate jurisdiction, regulatory perimeter analysis, PI or EMI applications, regulatory business plans, financial forecasts, governance, safeguarding, financial crime, outsourcing and supporting policies and procedures. Applications can be designed to comply with the current framework while anticipating material PSD3 changes that are sufficiently certain to affect the long-term operating model.
We also support international groups operating parallel UK and EU regulated businesses, helping distinguish the EU PSD3 transition from the separate reforms now taking place in the United Kingdom. To discuss an EU payment licence, PSD3 readiness review or regulatory change project, contact Buckingham Capital Consulting.
Frequently asked questions
When will PSD3 come into force?
PSD3 and the Payment Services Regulation had not been formally adopted as of July 2026. Political agreement was reached in November 2025, technical work concluded in March 2026 and final adoption and publication are expected in the fourth quarter of 2026. The agreed framework generally provides for most substantive requirements to apply approximately 21 months after entry into force, although exact dates will depend on final publication.
Will existing EMI licences disappear under PSD3?
The separate EMI institutional category will be integrated into the Payment Institution framework, with electronic money issuance becoming a regulated payment service. Existing EMIs will receive transitional arrangements rather than simply losing their authorisation, and competent authorities will assess whether they satisfy the new framework. Firms that meet the requirements can transition into authorisation as Payment Institutions with the appropriate electronic money permissions.
What are the new PSD3 minimum capital requirements?
Under the agreed text, money-remittance-only institutions would require €40,000, payment initiation remains at €50,000, the main payment-services category increases to €150,000 and electronic money issuance carries a €250,000 baseline requirement. Certain combinations of activities can result in the relevant minimum capital amounts being cumulative. These are agreed future requirements and do not replace the current PSD2 and Electronic Money Directive capital rules until the new framework becomes applicable.
What are the biggest changes under PSD3 and the PSR?
Major changes include integrating EMIs into a single Payment Institution framework, revised capital requirements, more harmonised safeguarding, stronger fraud prevention and reimbursement rules, wider payee verification, reforms to Strong Customer Authentication and improved Open Banking access. The PSR also strengthens fee transparency, customer protection, dispute resolution and non-discriminatory access to payment accounts for non-bank Payment Institutions.
Should a fintech wait for PSD3 before applying for an EU PI or EMI licence?
Not necessarily. Applications submitted in 2026 continue under the current PSD2 and Electronic Money Directive framework, and the new regime is not expected to apply immediately after formal adoption. A business with a genuine commercial need to become authorised can proceed now, but the application and operating model should consider material future changes such as capital, safeguarding and the transition from the EMI category into the future Payment Institution framework.



