What the EU’s PSD3 and PSR Mean for Cross-Border Subscription Billing

TL;DR

  • The EU’s new payments package (PSD3, a directive, and PSR, a directly-applicable regulation) is expected to reach the Official Journal around mid-2026, starting a phased compliance clock of roughly 18 to 24 months.
  • For subscription businesses charging EU cardholders, the changes touch checkout (SCA and surcharging), fraud liability (shifting toward payment providers), and account verification (mandatory payee name matching).
  • The operational weight lands on businesses that bill the EU market by market: the rules attach to local entities, acquiring, and PSP relationships, not to a single cross-border setup.
What actually happened

In late November 2025, the European Parliament and the Council of the EU reached political agreement on the EU’s payments overhaul: the third Payment Services Directive (PSD3) and the new Payment Services Regulation (PSR). After technical finalisation, the texts are generally expected to be published in the Official Journal around the end of the second quarter of 2026.

The two instruments behave differently, and the difference matters for planning.

  • PSR is a regulation. It applies directly in every member state, with no national transposition step. Its core obligations phase in over roughly 18 months after entry into force, with the mandatory payee name verification requirement arriving at the 24-month mark.
  • PSD3 is a directive. Member states have around 18 months to write it into national law, so the licensing and supervisory changes land later and country by country.

The headline changes that touch online and recurring commerce:

  • Strong customer authentication (SCA). SCA is the layered identity check at checkout. It must still use at least two of three elements: something you know, something you have, something you are. PSD3 and PSR tighten the rules for high-risk transactions while widening risk-based exemptions, and require providers to offer at least one authentication method that works for customers without a smartphone or with low digital skills.
  • Surcharging. The ban on adding a checkout surcharge is extended explicitly to credit transfers and direct debits in all EU currencies.
  • Fraud liability. Liability shifts harder onto payment service providers (PSPs, the companies that move the money). Where a fraudster impersonates a customer’s own PSP, the transaction is treated as unauthorised and triggers full reimbursement. Where a payee name and account number (IBAN) do not match, the payer must be warned before authorisation, or liability for misdirected funds can shift to their provider.
  • Outsourced authentication. Where a PSP delegates SCA to a third party such as a wallet or a gateway, that is now explicitly treated as outsourcing, pulling in the EBA outsourcing guidelines and DORA (the EU’s operational-resilience regime).
  • One licensing regime. PSD3 folds e-money institutions into the payment-institution category and repeals the old e-money directive, with existing e-money authorisations valid for a transition period.
Why this changes decisions for subscription businesses

A subscription charge is rarely a one-off checkout. It is a relationship that has to clear, every cycle, against rules set in the cardholder’s market.

That is where PSD3 and PSR land hardest. Most recurring card charges run as merchant-initiated transactions, which lean on SCA exemptions to avoid asking the customer to re-authenticate every month. When the exemption framework moves, the share of renewals that sail through without friction moves with it. Get the new rules wrong and you convert silent renewals into authentication prompts, and authentication prompts into involuntary churn (lost subscribers who wanted to stay but whose payment failed).

The fraud-liability shift changes the contract conversation too. If more liability sits with the PSP, the terms of who carries a misdirected payment or an impersonation claim become a line you negotiate, not a default you inherit. For a business operating across several EU markets through several providers, that negotiation repeats per relationship.

And none of this collapses into one tidy integration. PSD3 and PSR apply where the payment happens. A business billing customers in five EU countries is not managing one compliance clock. It is managing the same clock against five local setups: local acquiring, local PSP contracts, local reporting. The regulation rewards businesses that process locally and treats a thin cross-border arrangement as the harder place to comply from.

How orchestration architecture absorbs this

The instinct is to read PSD3 and PSR as a legal project. The more useful frame is an infrastructure one: the rules attach to the local payment stack, so the cleanest way to carry them is to actually have a local payment stack in each market.

That is the layer payment orchestration is built for, and it maps to the work directly.

  • A local stack per market. SGW Payment stands up the local setup on a client’s behalf when they enter a new market: incorporating an entity where required, opening banking and acquiring relationships, negotiating PSP contracts in the jurisdiction, and running the downstream finance operations (reconciliation, cash flow, reporting, and local tax clearance). When the compliance clock is local, the infrastructure carrying it is local too.
  • Local processing instead of cross-border. Because transactions then process locally in every market rather than as cross-border flows, the business sits inside each regime rather than reaching into it. That posture lifts issuer approval rates on its own, and it is also the posture PSD3 and PSR are written around.
  • One integration, a network of providers. A single SDK and API connect the merchant to a network of payment providers, with each transaction routed to the provider most likely to approve it. When SCA rules or exemptions shift in one market, rebalancing across providers is a routing decision, not a re-integration.

The point is not that the rules disappear. It is that the work of meeting them sits with infrastructure designed to operate locally, market by market, instead of with a product team retrofitting one cross-border setup to five legal regimes at once.

Takeaways to act on this quarter
  • Map your EU exposure by market, not in aggregate. List every EU country you bill in and the acquirer and PSP behind each. The compliance clock runs per setup, not per company.
  • Reopen the liability clauses. With more liability shifting to PSPs, confirm in writing who carries impersonation and misdirected-payment claims in each provider contract before the rules apply.
  • Stress-test your SCA exemption assumptions. Model what happens to renewal success if more recurring charges need authentication, and translate that into an involuntary-churn number your finance team can see.
  • If you are expanding into the EU, price in the lead time. Standing up local processing in a new market otherwise takes 6 to 12 months. Set against a phased PSD3/PSR clock, that lead time is the constraint to plan around, not an afterthought.
  • Decide ownership now. Name whether product, finance, or your payments partner owns PSD3/PSR readiness, so the work has a home before the Official Journal clock starts.
Sources

 


 

About SGW Payment. SGW Payment helps online businesses capture more revenue and reduce processing costs. Through a single SDK and API, SGW connects merchants to a network of payment providers and routes each transaction to the provider most likely to approve it. On top of the technology, SGW acts as the payments infrastructure layer for international expansion, standing up the local payments stack (entity, banking, acquiring, and finance operations) in every new market, so transactions process locally rather than cross-border. Learn more at sgw-payment.com.

Share:

More Posts

A Payments Processor Just Bought a Bank: What Vertical Integration Fixes for Subscription Billing, and What It Doesn’t

On September 2, 2026, TabaPay closed $155 million led by FTV Capital and announced plans to buy Transact Bank, N.A., an OCC-chartered, FDIC-insured bank in Denver. It would become TabaBank, N.A., with closing expected in Q4 2026 subject to regulatory approval. Owning a charter removes a processor’s dependence on sponsor banks, opens direct access to Federal Reserve rails, and replaces state-by-state licensing with one federal framework. It is a rational move for the processor. For a subscription business, that vertical integration deepens one provider path. It does not create a second one, and a US charter does nothing for the approval odds of a renewal on a card issued in another country.

What the Fed’s FedNow Cross-Border Proposal Fixes, and Doesn’t, for Subscription Billing

On April 10, 2026, the Federal Reserve proposed amending Regulation J to let FedNow participants route transfers through intermediary banks, including non-U.S. correspondent banks, extending real-time settlement to the U.S. leg of cross-border payments for the first time. On August 10, Stripe, Visa, Wise and a coalition of banking and fintech trade groups formally backed the proposal, though the Fed has not set a timeline for a final rule. The change only fixes settlement speed on the domestic leg. It does nothing for authorization, where a cross-border card transaction still clears at lower approval odds than one processed locally, which is the problem orchestration and local-market infrastructure actually address.

What Mastercard’s August 2026 Outage Means for Subscription Renewal Resilience

On August 15, 2026, a scheduled Mastercard system update took transactions offline across Australia, Singapore and parts of Europe for close to two hours, with Commonwealth Bank, NAB, ANZ and Macquarie all confirming the fault sat with Mastercard. For subscription billers, a scheme-level outage isn’t a retail glitch, it’s a wave of renewal failures dunning systems can’t distinguish from ordinary card declines unless routing already spans more than one provider.

UK Card Fee Transparency Rules: What the PSR’s Visa and Mastercard Directions Mean for Subscription Billing

On July 30, 2026, the UK’s Payment Systems Regulator finalized two binding directions ordering Visa and Mastercard to disclose how they set scheme fees charged to acquirers, with compliance deadlines running from November 2026 through July 2027. For subscription businesses, undocumented scheme fees repeat on every renewal, compounding against MRR long before UK acquirers get full transparency.