PSD3 security and compliance: everything e-commerce merchants need to know


The Payment Services Directive 3 (PSD3) is the next major European regulatory evolution for payments. Following PSD2, which mandated Strong Customer Authentication (SCA) and paved the way for open banking, PSD3 aims to strengthen payment security, improve competition, and clarify liability rules in the event of fraud.
For e-commerce merchants, payment managers, CIOs, and CFOs, this directive is not just another constraint: it is also an opportunity to optimize payment journeys and build greater customer trust.
In this article, we provide an update on PSD3, its new features, its impact on online retail, and best practices for preparation.
The PSD3 (Payment Services Directive 3) is the third European directive governing payment services. It complements and updates PSD2, which has been in effect since 2018.
Its main objectives are:
In short, PSD3 is a regulatory evolution aimed at adapting the legal framework to a market where payments are diversifying and cybercrime is becoming more complex.
PSD2 marked a turning point by mandating Strong Customer Authentication (SCA), which became compulsory for most online payments. It also introduced account aggregation and payment initiation services via APIs, opening the market to new players.
With PSD3, we are moving to the next stage:
New authentication and control requirements may complicate the customer journey. The risk: a drop in conversion rates if payment steps become too cumbersome.
PSD3 compliance requires increased transaction monitoring. Merchants will need to demonstrate that they are working effectively with their PSPs and applying best practices.
👉 According to Deloitte Avocats, this could involve a requirement to implement documented and verifiable anti-fraud plans, with regular audits.
PSD3 consolidates the open banking framework. This opens up prospects for:
In the event of a dispute or fraud, the rules for determining who reimburses the user will be clearer. This may reduce legal risks but will also require increased vigilance on the merchant's side.
PSD3 will not be immediately applicable: like any European directive, it must be transposed into national law. However, waiting would be a strategic mistake.
Preparing for PSD3 compliance requires a comprehensive approach that combines technical, regulatory, and business expertise.
When will PSD3 come into effect?
The directive still needs to be validated and then transposed by each EU member state. It is expected to come into force around 2026.
Does PSD3 replace PSD2?
Yes, PSD3 will gradually supplement and replace PSD2, while building upon its foundations (strong customer authentication, open banking).
What are the main changes in PSD3?
How can e-merchants prepare for PSD3?
By auditing their payment flows, strengthening their anti-fraud tools (particularly with a documented plan), diversifying their payment methods, and relying on a partner like Purse.
PSD3 PSD3 is not just another regulatory burden. For e-merchants and payment managers, it represents an opportunity to enhance security, introduce new payment options, and build customer trust.
By anticipating PSD3 compliance, you can turn this directive into a competitive advantage. And with Purse, you have a partner capable of simplifying regulatory complexity to optimize your payments.
👉 Want to get ahead of PSD3 and optimize your payments?
Deloitte – Revision of the European payment regulatory framework: PSD3 and PSR
Exeis Conseil – PSD3: compliance and a major evolution for open banking
Lemonway – PSD3 and PSR: new payment regulations in Europe
RiskInsight (Wavestone) – Transitioning to PSD3: what are the challenges?