# PSD3 Explained: What SaaS and Digital Sellers Need to Know

> A plain-English PSD3 and PSR guide for SaaS founders: where the legislation stands in 2026, what changes on fraud liability and SCA, and what it means for checkout.
- **Author**: Ayush Agarwal
- **Published**: 2026-08-27
- **Category**: Compliance, Payments, SaaS
- **URL**: https://dodopayments.com/blogs/psd3-explained-saas

---

Most PSD3 explainers are written for banks. If you run a SaaS product or sell digital goods into Europe, you need a different summary: what is actually decided, what is still moving, and which parts change anything at all for you.

The short version is that PSD3 is the biggest overhaul of EU payment rules since PSD2, it is close to final but not yet law, and the parts that will affect your checkout are mostly in its sibling regulation rather than in PSD3 itself.

_Disclaimer: This article is for educational purposes only and does not constitute legal advice. Consult a qualified adviser about how EU payments legislation applies to your business._

## Where PSD3 actually stands in 2026

The timeline matters, because a lot of writing about PSD3 implies it is already in force. It is not.

| Date | Milestone |
| --- | --- |
| 28 June 2023 | European Commission publishes the PSD3 proposal, COM(2023)366, alongside the Payment Services Regulation proposal, COM(2023)367 |
| 14 February 2024 | Parliament's ECON committee adopts its report |
| 23 April 2024 | Parliament adopts its first reading position |
| 21 October 2024 | ECON opens interinstitutional negotiations |
| 27 November 2025 | Parliament and Council reach provisional political agreement on PSD3 and the PSR |
| 23 April 2026 | Council publishes the final compromise texts and refers them to Coreper |
| 5 May 2026 | ECON approves the text agreed at early second reading |
| 14 December 2026 | Indicative plenary sitting date recorded in the Legislative Observatory |

As of this writing the procedure file records the stage as awaiting the Council's first reading position. The negotiated text still needs formal adoption by Parliament and Council, then signature and publication in the Official Journal, before any clock starts running.

The practical read: the direction of travel is settled, the text is stable enough to plan against, and nothing obliges you to change anything today.

## PSD3 and the PSR are two different instruments

This is the detail that causes the most confusion, and it determines who each rule actually binds.

The reform uses a dual structure:

- **PSD3 is a directive.** It covers areas that still need national implementation: authorisation, supervision, and prudential matters for payment institutions. Each member state transposes it into its own law.
- **The PSR is a regulation.** It applies directly across every member state with no transposition, and it carries the conduct rules: transparency, open banking, fraud prevention, and payment execution.

The goal is to cut the national divergence that emerged under PSD2, where the same directive produced meaningfully different rules in different countries.

For a SaaS business, the split has a simple consequence. **PSD3 is mostly about your payment provider's licence. The PSR is where the rules that touch your checkout live.**

```mermaid
flowchart TD
    A["EU payments reform package"] --> B["PSD3 directive: licensing, supervision, prudential"]
    A --> C["PSR regulation: fraud, SCA, transparency, open banking"]
    B --> D["Binds licensed payment institutions"]
    C --> E["Shapes what your checkout must do"]
```

## What PSD3 changes for payment institutions

PSD3 repeals both PSD2 and the second Electronic Money Directive. The most structural change is that **e-money institutions become a sub-category of payment institutions** rather than a separate licence class. It also brings in provisions for cash withdrawal services offered by retailers and by independent ATM deployers.

There are transitional measures for existing licences. Licences held by payment institutions and e-money institutions stay valid until 30 months after the directive enters into force, on condition that an application under the new directive is made no later than 24 months after entry into force.

If you are a SaaS company, none of this applies to you directly. It applies to whoever processes your payments. It is still worth knowing, because a provider that has to re-authorise under a new regime is a provider with a large compliance project ahead of it.

## What the PSR changes that you will actually notice

These are the provisions in the agreed text that reach your customers.

### Fraud liability shifts toward providers

Under the agreed text, a payment service provider is liable for covering a customer's losses where it failed to implement appropriate fraud prevention mechanisms. That is a meaningful reallocation of risk.

There is a specific rule for impersonation fraud, where a scammer poses as a PSP employee and tricks a customer into approving a payment. Where the customer reports it to both the police and the PSP, the PSP is expected to refund the full amount.

### Payee name and identifier matching

PSPs must check that a payee's name and unique identifier match. Where there is a discrepancy, the provider must refuse the payment order and inform the payer.

If you have ever dealt with the support load from a mismatched bank transfer, this one is good news. It also means more payments will be stopped before they complete, so your reconciliation flows should expect a slightly higher rate of refusals rather than failures.

### Strong customer authentication continues, with a risk assessment duty

SCA does not go away. The agreed text requires PSPs to ensure strong customer authentication and to conduct a risk assessment, and to offer customers spending limits and blocking measures to reduce fraud exposure.

If you are still catching up on what SCA means at checkout, [3D Secure and payment authentication](https://dodopayments.com/blogs/3d-secure-3ds-payment-authentication) and [payment compliance for GDPR and PSD2](https://dodopayments.com/blogs/payment-compliance-gdpr-psd2) cover the mechanics that carry over.

### Platform liability for fraudulent content

Where fraudulent content is spread through online platforms and those platforms fail to remove it after being informed, they become liable to the PSPs that reimbursed defrauded customers. Advertisers of financial services will need to demonstrate to very large online platforms and search engines that they are authorised, exempt, or advertising on behalf of someone who is.

### Charges must be disclosed before the payment starts

Customers must be properly informed about all charges before a payment is initiated. The agreed text calls out currency conversion charges and fixed ATM withdrawal fees specifically.

This is the provision most likely to change your checkout copy. If your pricing displays one number and the customer's card is billed a converted amount with an FX margin baked in, that gap needs to be visible up front. Our note on [why localised payment methods raise conversion](https://dodopayments.com/blogs/why-localized-payment-methods-are-important-for-higher-conversions) covers the customer-experience side of the same problem.

### A right to human support

Customers gain the right to reach human customer support rather than only a chatbot. If your billing support is fully automated, that is worth reviewing.

## What this means if you sell software into Europe

Here is the honest assessment: PSD3 and the PSR regulate payment service providers, not software vendors. You will not need a payments licence because you sell a SaaS subscription.

What changes is the environment your payments run in.

**Your provider's compliance burden goes up.** Re-authorisation, stricter fraud controls, and new liability exposure all cost money. Historically those costs surface in pricing or in tightened risk rules that catch legitimate merchants.

**Fraud controls get stricter before they get smarter.** When liability moves to providers, providers respond by declining more aggressively. Expect more friction on marginal transactions, at least initially. If declines are already a problem for you, [reduce payment declines](https://dodopayments.com/blogs/reduce-payment-declines) and [credit card decline codes](https://dodopayments.com/blogs/credit-card-decline-codes) are the practical starting points.

**Fee transparency becomes a checkout design question.** Pre-payment disclosure of conversion charges is not something you can bolt on later. It affects how you present prices in local currency.

**Who is the merchant of record still decides who carries the burden.** If you are the merchant of record, your provider's obligations become your operational reality. If a [Merchant of Record](https://dodopayments.com/blogs/what-is-a-merchant-of-record) is the legal seller, that entity sits between you and most of this. The distinction is covered in [merchant of record vs PSP](https://dodopayments.com/blogs/merchant-of-record-vs-psp).

## A sensible preparation checklist

Nothing here is urgent. All of it is cheap to do early.

1. **Ask your provider for its PSD3 readiness position.** A provider that cannot describe its re-authorisation plan is telling you something.
2. **Audit your checkout for fee disclosure.** Is every charge the customer will see visible before they commit? Adaptive or converted pricing is the usual gap.
3. **Check your support path for a human escalation route.** A chatbot with no handoff will not satisfy the agreed text.
4. **Model a higher decline rate.** Build the dunning and retry logic now. [Subscription dunning and recovery sequences](https://dodopayments.com/blogs/subscription-dunning-recovery-sequence) and [involuntary churn from failed payments](https://dodopayments.com/blogs/involuntary-churn-failed-payments) cover the patterns.
5. **Revisit whether you want to be the merchant of record at all.** For most software businesses selling cross-border, the answer has been trending toward no for several years, and this package does not reverse that trend.
6. **Keep your tax position separate in your head.** PSD3 is payments regulation, not tax law. VAT obligations are unchanged by it, and those are covered in the [EU VAT guide for SaaS](https://dodopayments.com/blogs/eu-vat-saas-guide-2026) and [VAT compliance for digital products](https://dodopayments.com/blogs/vat-compliance-digital-products).

## How Dodo Payments handles this layer

Dodo Payments operates as the Merchant of Record, which means we are the legal seller on the transaction and we carry the payment-side compliance obligations rather than passing them to you. Practically:

- Tax calculation, filing, and reporting are handled across 190+ countries
- Fraud prevention and [dispute handling](https://docs.dodopayments.com/features/transactions/disputes) sit inside the MoR model
- Checkout supports 40+ payment methods, 80+ currencies, and 14+ languages across 220+ countries and territories
- [Tax-inclusive pricing](https://docs.dodopayments.com/features/tax-inclusive-pricing) lets you show customers the final amount before they pay, which is the direction the PSR pushes
- The platform is PCI DSS Level 1 certified and runs at 99.99% uptime

If you want to see how the payment flow is structured, start with the [integration guide](https://docs.dodopayments.com/developer-resources/integration-guide) or the [MoR introduction](https://docs.dodopayments.com/features/mor-introduction).

## FAQ

### Is PSD3 law yet?

No. Parliament and the Council reached provisional political agreement in November 2025, the Council published final compromise texts in April 2026, and ECON approved the agreed text in May 2026. The procedure file still records the file as awaiting the Council's first reading position, and the text must be formally adopted and published in the Official Journal before it takes effect.

### What is the difference between PSD3 and the PSR?

PSD3 is a directive covering authorisation, supervision, and prudential requirements, which each member state transposes into national law. The PSR is a regulation that applies directly across the EU and carries the conduct rules on transparency, fraud prevention, open banking, and payment execution. Most of the rules that affect a merchant's checkout sit in the PSR.

### Does PSD3 apply to SaaS companies?

Not directly. PSD3 and the PSR regulate payment service providers, so a software company selling subscriptions does not need a payments licence because of them. The effects reach you indirectly through your provider's fraud controls, pricing, and the fee-transparency rules that shape checkout.

### Does PSD3 replace PSD2?

Yes. PSD3 repeals PSD2 and also repeals the second Electronic Money Directive, folding e-money institutions into payment institutions as a sub-category. Existing licences remain valid for a transitional period of 30 months after entry into force, provided an application under the new regime is filed within 24 months.

### Will strong customer authentication still be required?

Yes. The agreed text keeps strong customer authentication and adds an explicit duty for providers to run a risk assessment and to offer customers spending limits and blocking measures. SCA is being extended and refined rather than removed.

## Final thoughts

PSD3 is a large piece of legislation that mostly happens to other people. For a SaaS founder the correct response is not a compliance project, it is a short list of questions for your payment provider and a checkout review for fee transparency.

The one strategic question worth revisiting is whether you want to be the merchant of record as European payment rules keep getting denser. If the answer is no, [Dodo Payments](https://dodopayments.com) takes that role along with tax compliance in 190+ countries. Pricing is published in full on the [pricing page](https://dodopayments.com/pricing).
---
- [More Compliance articles](https://dodopayments.com/blogs/category/compliance)
- [All articles](https://dodopayments.com/blogs)