Payment
12/9/2025
5 min

PSD3 security and compliance: everything e-commerce merchants need to know

Carte bancaire européenne reliée aux méthodes d'authentification forte : code, empreinte, visage
Table of contents
Section Content 1

The Payment Services Directive 3 (PSD3) is the next major European regulatory evolution for payments. Following PSD2, which mandated Strong Customer Authentication (SCA) and paved the way for open banking, PSD3 aims to strengthen payment security, improve competition, and clarify liability rules in the event of fraud.

For e-commerce merchants, payment managers, CIOs, and CFOs, this directive is not just another constraint: it is also an opportunity to optimize payment journeys and build greater customer trust.

In this article, we provide an update on PSD3, its new features, its impact on online retail, and best practices for preparation.

What is PSD3?

The PSD3 (Payment Services Directive 3) is the third European directive governing payment services. It complements and updates PSD2, which has been in effect since 2018.

Its main objectives are:

  • Strengthen online payment security through stricter regulation of service providers.

  • Improve consumer protection, particularly in cases of fraud or disputes.

  • Further regulate open banking, to ensure fair competition between banks, fintechs, and new market players.

  • Standardize rules across the European Union, to limit discrepancies in implementation between countries.

In short, PSD3 is a regulatory evolution aimed at adapting the legal framework to a market where payments are diversifying and cybercrime is becoming more complex.

PSD3 vs. PSD2: what are the differences?

PSD2 marked a turning point by mandating Strong Customer Authentication (SCA), which became compulsory for most online payments. It also introduced account aggregation and payment initiation services via APIs, opening the market to new players.

With PSD3, we are moving to the next stage:

  • Greater security and control : payment service providers (PSPs, fintechs, banks) will be subject to enhanced oversight, particularly regarding governance and cybersecurity.

  • Greater clarity on responsibilities : in the event of fraud, liability will be more clearly defined between the merchant, the bank, and the provider. For example, the European Commission is considering mandating automatic reimbursement for fraud victims, unless there is proof of gross negligence.

  • Stricter open banking regulations : APIs will need to meet more consistent standards to ensure fair competition between banks and fintechs.

  • Focus on fraud prevention : increased reporting obligations, better cooperation between stakeholders, and a strengthened role for national supervisors.

  • Regulation of card payment fees : PSD3 could cap certain fees charged to merchants to avoid disparities and abusive practices, particularly regarding interbank cards.

The impact of PSD3 on e-commerce merchants

1. Enhanced security = potential for more friction

New authentication and control requirements may complicate the customer journey. The risk: a drop in conversion rates if payment steps become too cumbersome.

2. More demanding fraud prevention

PSD3 compliance requires increased transaction monitoring. Merchants will need to demonstrate that they are working effectively with their PSPs and applying best practices.
👉 According to Deloitte Avocats, this could involve a requirement to implement documented and verifiable anti-fraud plans, with regular audits.

3. New opportunities through open banking

PSD3 consolidates the open banking framework. This opens up prospects for:

  • instant bank transfer initiation,

  • alternative payment solutions to credit cards,

  • more seamless integration of wallets and aggregators.

4. Better-defined responsibilities

In the event of a dispute or fraud, the rules for determining who reimburses the user will be clearer. This may reduce legal risks but will also require increased vigilance on the merchant's side.

How can you prepare for PSD3?

PSD3 will not be immediately applicable: like any European directive, it must be transposed into national law. However, waiting would be a strategic mistake.

Step 1: Audit your payment flows

  • Identify friction points related to strong customer authentication.
  • Measure the potential impact on your conversion rates.

Step 2: Strengthen your anti-fraud measures

  • Verify the effectiveness of your 3DSecure and exemption rules.
  • Add anti-fraud plans 
  • Evaluate your scoring and monitoring solutions.

Step 3: Diversify your payment methods

  • Explore instant bank transfers and open banking solutions.
  • Integrate digital wallets to meet customer expectations.

Step 4: Rely on an expert partner

Preparing for PSD3 compliance requires a comprehensive approach that combines technical, regulatory, and business expertise.

Frequently asked questions

When will PSD3 come into effect?
The directive still needs to be validated and then transposed by each EU member state. It is expected to come into force around 2026.

Does PSD3 replace PSD2?
Yes, PSD3 will gradually supplement and replace PSD2, while building upon its foundations (strong customer authentication, open banking).

What are the main changes in PSD3?

  • Strengthening the fight against fraud (mandatory anti-fraud plans, increased reporting),

  • Clarification of liability in cases of fraud with near-automatic reimbursement for victims,

  • Regulation of card payment fees,

  • Enhanced supervision of open banking and PSPs.

How can e-merchants prepare for PSD3?
By auditing their payment flows, strengthening their anti-fraud tools (particularly with a documented plan), diversifying their payment methods, and relying on a partner like Purse.

Conclusion

PSD3 PSD3 is not just another regulatory burden. For e-merchants and payment managers, it represents an opportunity to enhance security, introduce new payment options, and build customer trust.

By anticipating PSD3 compliance, you can turn this directive into a competitive advantage. And with Purse, you have a partner capable of simplifying regulatory complexity to optimize your payments.

👉 Want to get ahead of PSD3 and optimize your payments?

Sources

Deloitte – Revision of the European payment regulatory framework: PSD3 and PSR

Exeis Conseil – PSD3: compliance and a major evolution for open banking

Lemonway – PSD3 and PSR: new payment regulations in Europe

RiskInsight (Wavestone) – Transitioning to PSD3: what are the challenges?

Daf Mag

Deloitte