DISPATCH ·

PSD3 + PSR: the 21-month transition that reshapes every broker's payment vendor selection

The EU Payment Services Directive 3 (PSD3) and Payment Services Regulation (PSR) reached provisional political agreement on 2025-11-27. The agreed texts were...

tags · psd3 · psr · eu · regulation · broker-payments · emi · psp · compliance

The EU Payment Services Directive 3 (PSD3) and Payment Services Regulation (PSR) reached provisional political agreement on 2025-11-27. The agreed texts were published on 2026-04-23. Official Journal of the European Union (OJEU) publication is anticipated June-September 2026, with the new rules generally applying 21 months after OJEU publication - meaning full compliance is expected by late 2027.

For Brokerage Atlas’s payments-EU chapter, this is the single most consequential regulatory transition of the decade for broker procurement. Three changes reshape every vendor relationship a broker holds today.

Change 1 - EMIs become a sub-category of PIs. Existing EMI authorisations will remain valid for 24 months from entry into force, after which PIs and EMIs must submit new applications to demonstrate compliance with the consolidated framework. Every e-wallet vendor in the universe (Paysafe Skrill+Neteller via Paysafe Group’s EMI authorisations), every payment-institution vendor (Truevo, Trustly, Volt, CoinGate), every crypto gateway with EMI components (B2BinPay) faces a re-authorization gate. Brokers using a vendor that fails the re-authorisation timeline face mid-cycle PSP migration. The chapter recommends operators run vendor-by-vendor authorisation-status reviews by Q4 2026.

Change 2 - mandatory payee-name verification. PSPs must verify that the payee’s name matches the account identifier before any transfer is processed. PSPs that fail to implement adequate fraud risk controls assume liability for customer losses. This is a structural advantage for open banking vendors (Trustly, Volt) - they already have account-holder identity from bank login. E-wallet vendors face the largest technical lift because account names + identifiers are not natively reconciled at the wallet layer. Crypto gateways (B2BinPay, Match2Pay, CoinGate) face the most ambiguous adaptation path - crypto addresses don’t carry names. Operators with crypto-heavy payment stacks should engage their gateway vendor about PSD3 architecture readiness now.

Change 3 - mandatory PSP fraud-data-sharing platform. PSPs must share fraud-related data with each other via a dedicated platform (subject to data protection impact assessment); stored data limited to 5-year maximum. This favors vendors with mature fraud + AML infrastructure - Truevo’s PCI-DSS Level 1 certification, Paysafe Group’s established compliance team, established high-risk acquirers like Fibonatix. Newer entrants face larger compliance-team build-out. Brokers selecting a vendor for new deployments in 2026 H2 should weight the vendor’s data-sharing-platform readiness as a procurement criterion.

The Brokerage Atlas position. Vendors should be scored explicitly on PSD3 + PSR readiness for any procurement decision finalising before late 2026. The chapter introduces a new scorecard dimension - PSD3 readiness - alongside the existing six methodology dimensions for the payments-EU universe. Operators considering a vendor that hasn’t publicly addressed payee-verification or fraud-data-sharing should treat that silence as a procurement red flag.

Implementation timeline guidance. The compliance specialists converge on this trajectory: gap analysis by Q3 2026 (the next 90 days), vendor PSD3-readiness assessment by Q4 2026, contract renegotiation or migration triggers by Q2 2027, full transition by Q4 2027. Operators on the bubble should be running vendor-readiness conversations in the next 90 days, not the next 12 months.


Source: https://www.nortonrosefulbright.com/en/knowledge/publications/cedd39c6/psd3-and-psr-from-provisional-agreement-to-2026-readiness

Full chapter: Payments