What the EU’s PSD3 and PSR Mean for Cross-Border Subscription Billing

TL;DR

  • The EU’s new payments package (PSD3, a directive, and PSR, a directly-applicable regulation) is expected to reach the Official Journal around mid-2026, starting a phased compliance clock of roughly 18 to 24 months.
  • For subscription businesses charging EU cardholders, the changes touch checkout (SCA and surcharging), fraud liability (shifting toward payment providers), and account verification (mandatory payee name matching).
  • The operational weight lands on businesses that bill the EU market by market: the rules attach to local entities, acquiring, and PSP relationships, not to a single cross-border setup.
What actually happened

In late November 2025, the European Parliament and the Council of the EU reached political agreement on the EU’s payments overhaul: the third Payment Services Directive (PSD3) and the new Payment Services Regulation (PSR). After technical finalisation, the texts are generally expected to be published in the Official Journal around the end of the second quarter of 2026.

The two instruments behave differently, and the difference matters for planning.

  • PSR is a regulation. It applies directly in every member state, with no national transposition step. Its core obligations phase in over roughly 18 months after entry into force, with the mandatory payee name verification requirement arriving at the 24-month mark.
  • PSD3 is a directive. Member states have around 18 months to write it into national law, so the licensing and supervisory changes land later and country by country.

The headline changes that touch online and recurring commerce:

  • Strong customer authentication (SCA). SCA is the layered identity check at checkout. It must still use at least two of three elements: something you know, something you have, something you are. PSD3 and PSR tighten the rules for high-risk transactions while widening risk-based exemptions, and require providers to offer at least one authentication method that works for customers without a smartphone or with low digital skills.
  • Surcharging. The ban on adding a checkout surcharge is extended explicitly to credit transfers and direct debits in all EU currencies.
  • Fraud liability. Liability shifts harder onto payment service providers (PSPs, the companies that move the money). Where a fraudster impersonates a customer’s own PSP, the transaction is treated as unauthorised and triggers full reimbursement. Where a payee name and account number (IBAN) do not match, the payer must be warned before authorisation, or liability for misdirected funds can shift to their provider.
  • Outsourced authentication. Where a PSP delegates SCA to a third party such as a wallet or a gateway, that is now explicitly treated as outsourcing, pulling in the EBA outsourcing guidelines and DORA (the EU’s operational-resilience regime).
  • One licensing regime. PSD3 folds e-money institutions into the payment-institution category and repeals the old e-money directive, with existing e-money authorisations valid for a transition period.
Why this changes decisions for subscription businesses

A subscription charge is rarely a one-off checkout. It is a relationship that has to clear, every cycle, against rules set in the cardholder’s market.

That is where PSD3 and PSR land hardest. Most recurring card charges run as merchant-initiated transactions, which lean on SCA exemptions to avoid asking the customer to re-authenticate every month. When the exemption framework moves, the share of renewals that sail through without friction moves with it. Get the new rules wrong and you convert silent renewals into authentication prompts, and authentication prompts into involuntary churn (lost subscribers who wanted to stay but whose payment failed).

The fraud-liability shift changes the contract conversation too. If more liability sits with the PSP, the terms of who carries a misdirected payment or an impersonation claim become a line you negotiate, not a default you inherit. For a business operating across several EU markets through several providers, that negotiation repeats per relationship.

And none of this collapses into one tidy integration. PSD3 and PSR apply where the payment happens. A business billing customers in five EU countries is not managing one compliance clock. It is managing the same clock against five local setups: local acquiring, local PSP contracts, local reporting. The regulation rewards businesses that process locally and treats a thin cross-border arrangement as the harder place to comply from.

How orchestration architecture absorbs this

The instinct is to read PSD3 and PSR as a legal project. The more useful frame is an infrastructure one: the rules attach to the local payment stack, so the cleanest way to carry them is to actually have a local payment stack in each market.

That is the layer payment orchestration is built for, and it maps to the work directly.

  • A local stack per market. SGW Payment stands up the local setup on a client’s behalf when they enter a new market: incorporating an entity where required, opening banking and acquiring relationships, negotiating PSP contracts in the jurisdiction, and running the downstream finance operations (reconciliation, cash flow, reporting, and local tax clearance). When the compliance clock is local, the infrastructure carrying it is local too.
  • Local processing instead of cross-border. Because transactions then process locally in every market rather than as cross-border flows, the business sits inside each regime rather than reaching into it. That posture lifts issuer approval rates on its own, and it is also the posture PSD3 and PSR are written around.
  • One integration, a network of providers. A single SDK and API connect the merchant to a network of payment providers, with each transaction routed to the provider most likely to approve it. When SCA rules or exemptions shift in one market, rebalancing across providers is a routing decision, not a re-integration.

The point is not that the rules disappear. It is that the work of meeting them sits with infrastructure designed to operate locally, market by market, instead of with a product team retrofitting one cross-border setup to five legal regimes at once.

Takeaways to act on this quarter
  • Map your EU exposure by market, not in aggregate. List every EU country you bill in and the acquirer and PSP behind each. The compliance clock runs per setup, not per company.
  • Reopen the liability clauses. With more liability shifting to PSPs, confirm in writing who carries impersonation and misdirected-payment claims in each provider contract before the rules apply.
  • Stress-test your SCA exemption assumptions. Model what happens to renewal success if more recurring charges need authentication, and translate that into an involuntary-churn number your finance team can see.
  • If you are expanding into the EU, price in the lead time. Standing up local processing in a new market otherwise takes 6 to 12 months. Set against a phased PSD3/PSR clock, that lead time is the constraint to plan around, not an afterthought.
  • Decide ownership now. Name whether product, finance, or your payments partner owns PSD3/PSR readiness, so the work has a home before the Official Journal clock starts.
Sources

 


 

About SGW Payment. SGW Payment helps online businesses capture more revenue and reduce processing costs. Through a single SDK and API, SGW connects merchants to a network of payment providers and routes each transaction to the provider most likely to approve it. On top of the technology, SGW acts as the payments infrastructure layer for international expansion, standing up the local payments stack (entity, banking, acquiring, and finance operations) in every new market, so transactions process locally rather than cross-border. Learn more at sgw-payment.com.

Share:

More Posts

The Digital Euro Just Cleared Two Milestones: What a Fragmenting European Rail Mix Means for Subscription Billing

On July 9, 2026 the European Parliament approved its digital euro negotiating mandate and the ECB named 36 providers for a 2027 pilot. For subscription businesses the real story is not the digital euro itself but a fragmenting European rail mix (cards, A2A wallets like Wero, and a coming CBDC), each adding integration and reconciliation work per market. An orchestration layer plus local per-market infrastructure is the structural hedge.

When Your PSP Buys Your Billing Engine: What Adyen’s $335M Orb Acquisition Means for Subscription Merchants

Adyen agreed to acquire enterprise billing platform Orb for $335 million, with the deal closing July 1, 2026. Adyen’s long-term goal is to converge billing and payments into a single platform. For subscription merchants, the structural hedge is an independent routing architecture: multi-provider routing with local acquiring in each market, operating regardless of which vendor runs the billing engine.