With PSD3 and the new Payment Services Regulation (PSR), the EU is fundamentally reshaping payments in 2026 - and unlike the previous PSD2, much of it acts directly in the checkout of your online shop. After the political agreement in late November 2025 (European Parliament/Council) and confirmation by the member states in April 2026 (Council of the EU), the direction for merchants is becoming clear: strong customer authentication becomes stricter and more accessible, surcharges on payment methods are further removed, an IBAN name check arrives, and fraud liability is reallocated. Anyone who prepares checkout, payment provider and invoice purchase now reduces friction, drop-offs and legal risk. This article explains what changes, when it applies and which steps make sense in the shop.

From PSD2 to PSD3 and PSR: the new framework

The second Payment Services Directive PSD2 has shaped the European checkout since 2018: it made strong customer authentication (SCA) mandatory, opened up open banking and banned extra charges on many card payments. But implementation varied across member states, fraud patterns shifted, and new payment methods such as account-to-account (A2A) transfers outgrew the old framework. The EU is drawing the consequence and replacing PSD2 with a double package: the directive PSD3 and the directly applicable regulation PSR.

This split is more than a formality. A directive must first be transposed into national law and leaves room for interpretation; a regulation applies directly and identically across Europe. That is precisely why the rules affecting the checkout - authentication, transparency, charges, fraud liability - move into the PSR and become uniform across all EU states. This reduces the previous fragmentation and makes cross-border trade more predictable (Herbert Smith Freehills Kramer). For merchants that means: what is handled differently from country to country today will follow a common rulebook.

In substance, the package builds on the weaknesses of PSD2. Mandatory authentication has noticeably curbed card fraud, yet new schemes such as transfer fraud through deception grew in the shadow of the old rules. At the same time, open banking fell short of expectations because bank interfaces were inconsistent and at times unreliable. PSD3 and PSR address exactly this: they modernise fraud defence, strengthen the interfaces and close gaps that have become visible in online commerce over recent years. For shop operators the reform is therefore less a break than a consistent continuation of what already shapes the checkout.

LevelPSD3 (directive)PSR (regulation)
Legal natureTo be transposed into national lawApplies directly across the EU
Mainly governsAuthorisation, supervision, licencesCheckout: SCA, charges, liability
Relevance for shopsIndirect, via the providersDirect, at the payment step
Why PSD3 and PSR matter now

The reform concerns not only banks and payment providers, but every merchant who accepts money online. As soon as the rules for authentication, charges and liability change, conversion, cost and duties in the checkout change too. Anyone who plans the transition early with their payment setup shapes it actively instead of scrambling later under time pressure.

The timeline: when PSD3 and PSR really take effect

In late November 2025, Parliament and Council reached a provisional political agreement on PSD3 and PSR (European Parliament/Council). In April 2026 the member states confirmed the compromise text (Council of the EU); formal adoption and publication in the EU Official Journal follow. Only with that publication do the deadlines start to run - and they are deliberately staggered so that banks, providers and merchants can adapt their systems.

After entry into force, member states have around 18 months to transpose the PSD3 directive, while the PSR regulation becomes directly applicable after a comparable transition period (Herbert Smith Freehills Kramer). Realistically, the core of the new duties therefore takes effect from 2027. Individual building blocks get longer lead times: the mandatory payee verification, for instance, applies for many providers only about 24 months after entry into force (Council of the EU). The horizon to 2027 is thus no reason to wait - payment flows, contracts and checkout can only be adapted cleanly with lead time.

Do not wait until the last day

The transition periods look generous, but changes to checkout, fraud rules and contracts with the payment provider need time to test and coordinate. Experience shows it pays to inventory your own payment process early and agree a roadmap with the provider, rather than reacting shortly before the rules apply.

Strong customer authentication: stricter and more accessible

Strong customer authentication remains the heart of fraud defence - and it works: SCA-authenticated card payments show markedly lower fraud rates than non-authenticated ones, and outside the European Economic Area, where SCA does not legally apply, the fraud rate for card payments is around ten times higher (ECB/EBA). At the same time, the statistics show headroom: in 2024, only about 40 percent of card payments and roughly 38 percent of e-money transactions were actually strongly authenticated (ECB/EBA).

The PSR tightens SCA in several places. First, authentication must work in an accessible way: it may not rely exclusively on a modern smartphone, but must leave a path for people without a smartphone or with a disability. This is also a bridge to the requirements of an accessible checkout. Second, the exemptions from SCA - such as transaction risk analysis for low-risk payments - are framed more clearly so that merchants trigger fewer unnecessary authentication steps. Third, responsibilities between the parties are allocated more precisely.

Effective against fraud

SCA noticeably lowers the fraud rate; outside the EEA without SCA it is around ten times higher (ECB/EBA). The reform builds on this foundation.

Accessible to use

Authentication may not hinge on a smartphone alone - a gain for reach and for the accessible shop.

Less needless friction

Clearer exemptions for low-risk payments aim to reduce drop-offs without lowering security.

For the checkout this means: the 3-D Secure flow in use and the logic for when an exemption is claimed belong on the test bench. A technically clean payment process - coordinated in shop programming - decides whether customers pass through smoothly or abandon in frustration. Because every additional yet avoidable authentication costs conversion. Conversely: anyone who exempts low-risk payments from authentication too aggressively loses the liability protection and bears the chargebacks themselves. The right balance between friction and security is therefore not a pure technical question but a commercial trade-off that belongs under regular review.

Surcharge ban: no extra charges on payment methods

Even under PSD2, surcharges on many card and SEPA payments were not permitted. The PSR widens the scope and explicitly extends the ban to credit transfers and direct debits in all EU currencies, to remove previous differences in interpretation (Herbert Smith Freehills Kramer). In practice that means: an extra charge simply because a customer pays by card, transfer or direct debit becomes even more clearly off-limits in European commerce.

This has consequences for pricing in the shop. Anyone who has so far passed on the cost of certain payment methods via a surcharge must rethink that calculation and either build the fees into the base price or absorb them differently. It is important not to fall into the opposite trap: depending on its design, a blanket discount for a preferred payment method can be treated as a hidden charge on the other methods. Clearly displayed final prices that are uniform across all common options are therefore the safest route - and at the same time the most transparent for your customers.

Price transparency and legal risk

Hidden or after-the-fact payment charges are a classic point of legal challenge. Payment-method-dependent surcharges should disappear from the checkout, and the final price must be shown transparently. Anyone who instead offers free, common payment options meets the requirements and improves the user experience along the way. This article does not replace legal advice in individual cases.

Verification of Payee: the IBAN name check

A visibly new building block is payee verification, the Verification of Payee (VoP). Before a transfer, the payment provider checks whether the given payee name matches the stated IBAN and warns of discrepancies. Originally developed for instant payments, the check is anchored more broadly under the PSR; the corresponding duty and liability apply for many providers around 24 months after entry into force (Council of the EU).

For shops this is relevant wherever customers pay by transfer - for instance with advance payment, invoice purchase or A2A payment methods. If the payee details on the invoice do not exactly match the account holder, a warning can unsettle customers and delay payments. Anyone who outputs company name, account holder and payment references cleanly and consistently from the system - ideally connected via the inventory management integration - avoids needless queries. Especially in B2B commerce with invoice purchase and bulk transfers, clean master data pays off twice over.

Fraud liability is reallocated

Payment fraud in the EU is growing: in 2024 it added up to around 4.2 billion euros, after roughly 3.5 billion euros the year before (ECB/EBA). Of that, about 1.3 billion euros fell on cards issued in the EU/EEA - an increase of around 29 percent compared with 2023 (ECB/EBA). For merchants, fraud is no abstract risk: European online retailers lose, by industry estimates, an average of around 2.8 percent of their revenue to fraud (Sift).

The PSR responds with a newly balanced liability regime. Alongside classic card payments, it addresses authorised push payment fraud - cases where customers, through deception, trigger a transfer themselves. If damage occurs despite a faulty or missing IBAN name check, for example, responsibility shifts more strongly to the payment providers involved. The abuse of a provider's brand name in fraud schemes is also addressed (Worldline).

What this means for your shop

The new allocation of liability relieves customers and puts providers more firmly on the hook - but it does not replace your own fraud prevention. The cleaner your checkout handles SCA and exemptions, the less often you end up in disputes over chargebacks. A well-considered payment process is therefore not only a duty but a lever for margin and trust - because outside the EEA without SCA the fraud rate is around ten times higher (ECB/EBA).

Open banking and A2A: more than just cards

The PSR expands open banking further and improves the data interfaces between banks and licensed services. For commerce this opens the door to account-to-account payments (A2A) that run directly from the customer account to the merchant account - often cheaper than cards and with immediate credit when instant transfers are involved. Key here is the reliable availability of the bank interfaces, which the reform explicitly strengthens (Worldline).

  • More choice in the checkout: alongside card, wallet and invoice purchase, A2A methods gain importance - a reason to review the payment mix regularly.
  • Cheaper transactions: account-to-account payments bypass the card networks and can lower the fee burden.
  • Immediate liquidity: combined with instant transfers, the money is there within seconds - relevant for cash flow and shipping release.
  • Reliable interfaces: the strengthened requirements for bank interfaces aim to reduce outages and friction.

How exactly you integrate these methods into your shop depends on the platform and the provider. A clean technical connection - for instance via a tested Shopware implementation - ensures that new payment methods run stably and are correctly reflected in accounting and inventory management.

Checklist: how to prepare your checkout

There is still time until the rules fully apply - but merchants should use it. The following steps help align the payment process with PSD3 and PSR without last-minute stress:

  • Payment method inventory: which methods are active, and are payment-method-dependent surcharges still applied anywhere?
  • Review the SCA flow: is 3-D Secure running properly, and are exemptions for low-risk payments used sensibly?
  • Test accessibility: does authentication also work without a modern smartphone?
  • Reconcile master data: do company name, account holder and IBAN match exactly (payee verification)?
  • Provider roadmap: clarify transition dates and liability questions with the payment provider and bank.
  • Check price display: final prices transparent, no hidden payment charges in the checkout.

Harden the checkout technically

Implement 3-D Secure, exemption logic and error handling cleanly - coordinated in programming so every payment runs reliably.

Secure data and payments

Payment and customer data belong in a secure, European environment - more in our article on data sovereignty for online shops.

Broaden the payment mix

A2A and wallet payments complement card and invoice purchase - for more reach and lower fees.

Update legal texts

Adapt terms, payment and price information to the new requirements - fitting also with the new product liability from December 2026.

Make your checkout PSD3-ready now

PSD3 and PSR are not a pure banking topic but a modernisation of paying that lands directly in the checkout. Stricter yet more accessible SCA, a broader surcharge ban, the IBAN name check and reallocated fraud liability change how customers pay and who is liable when damage occurs. For merchants this is above all an opportunity: a cleanly set-up payment process reduces drop-offs, saves fees and protects against legal challenges and chargebacks.

Related shifts in B2B commerce - such as customer-specific prices from the ERP - and further deadlines of the year like the upcoming end of the Google Content API show that 2026 is a year of many parallel transitions. Those who tackle the checkout in a structured way now have less to fix later. We analyse your payment process, set up SCA and payment methods for the future and connect them stably to shop and inventory management. Talk to our team to prepare your checkout for PSD3 and PSR in good time.

Sources

This article draws on the provisional political agreement between the European Parliament and Council on PSD3 and PSR (November 2025) and its confirmation by the Council of the EU (April 2026), on the PSD3/PSR analysis by Herbert Smith Freehills Kramer, on the joint payment fraud report by the ECB and EBA (ECB/EBA, 2024 figures) for fraud volume, card fraud and SCA rates, on the payment trends by Worldline, and on industry data on fraud losses in commerce (Sift). Deadlines and details may still change in the further legislative process; the figures cited serve as guidance. This article does not replace individual legal advice. As of August 2026.

PSD3 is a directive that must be transposed into national law by the member states and mainly governs the authorisation and supervision of payment service providers. The PSR is a regulation that applies directly and uniformly across Europe and contains the rules for the payment process itself - such as strong customer authentication, charges and fraud liability. For online shops the PSR is especially relevant because it affects the checkout directly.

Parliament and Council reached a provisional agreement in late November 2025 (European Parliament/Council); in April 2026 the member states confirmed it (Council of the EU). After publication in the Official Journal, staggered transition periods apply; the directive is typically to be transposed within around 18 months, and the regulation becomes applicable after a comparable period (Herbert Smith Freehills Kramer). The core of the new duties therefore realistically takes effect from 2027, with individual building blocks such as payee verification around 24 months after entry into force (Council of the EU).

Yes. SCA remains mandatory but is tightened: it must work in an accessible way and may not rely exclusively on a modern smartphone, the exemptions for low-risk payments are framed more clearly, and responsibilities between the parties are allocated more precisely. SCA is still considered effective: outside the EEA without SCA, the fraud rate for card payments is around ten times higher (ECB/EBA).

The ban on extra charges is being extended: the PSR explicitly prohibits surcharges also on credit transfers and direct debits in all EU currencies in future (Herbert Smith Freehills Kramer). Payment-method-dependent surcharges should therefore disappear from the checkout, and final prices must be shown transparently. Hidden payment charges are a known legal risk.

Before a transfer, the payment provider checks whether the entered payee name matches the IBAN and warns of discrepancies. This protects against mis-transfers and fraud. For shops the check matters above all with advance payment, invoice purchase and A2A payments: company name, account holder and IBAN should match exactly so that no warnings unsettle customers. The duty applies for many providers around 24 months after entry into force (Council of the EU).

We analyse the existing payment process, review the SCA flow, exemption logic and payment mix, and implement the technical changes in the checkout - coordinated with your payment provider. In doing so we pay attention to accessible authentication, transparent price display and a clean connection to inventory management and accounting. This way the checkout can typically be aligned with the new requirements in good time and without time pressure (project experience).