The PSD3 payment services regulation framework is now approaching its final legislative stage, with the European Union’s overhaul of its payments infrastructure set to reshape how payment institutions operate across the bloc. On the 18th of May 2026, the Chair of the European Parliament’s Committee on Economic and Monetary Affairs confirmed that the Committee is prepared to recommend adoption of the PSD3 and the PSR at second reading without amendment, provided the EU Council transmits its current position. A September 2026 adoption target has been set.
For payment institutions, electronic money institutions, and crypto-asset service providers operating from or considering Malta, this development carries immediate strategic relevance, not least because the Malta Financial Services Authority (“MFSA“) has already moved. A Dear CEO Letter setting out the MFSA’s minimum expectations on authorised persons’ preparedness for PSD3 was issued earlier this month, signalling that the supervisory phase has effectively begun.
From Two Directives to a Directive and a Regulation
The existing framework, built around the Second Payment Services Directive (“PSD2“), governed both the licensing of payment firms and the rules governing how they conduct business. That dual function is now being split.
Under the new structure, PSD3 retains responsibility for authorisation, prudential supervision, and the licensing of payment institutions. The PSR, by contrast, takes over the conduct of business rules: transparency obligations, fraud prevention measures, strong customer authentication, and open banking access. Critically, the PSR is a directly applicable regulation rather than a directive. This means its requirements will apply uniformly across EU Member States without the need for national transposition, eliminating the divergence in implementation that characterised the PSD2 era.
A Single Authorisation Framework for Payment Institutions (“PIs”) and Electronic Money Institutions (“EMIs”)
One of the more structurally significant changes under the PSD3 payment services regulation package is the consolidation of PIs and EMIs into a single authorisation category. Electronic money institutions will become a sub-category of payment institutions, and the existing E-Money Directive will be repealed.
For firms currently authorised as either payment institutions or electronic money institutions, this does not mean starting the licensing process from scratch. Existing authorisations will be transitioned into the new regime. However, firms will be required to update their authorisation files and governance documentation to reflect the revised legislative framework. The administrative burden should not be underestimated, and early preparation will be important.
Implications for Crypto-Asset Service Providers
The proposed framework also addresses the intersection between traditional payment services and crypto-asset regulation under Regulation (EU) 2023/1114 on markets in crypto-assets (“MiCA“). This intersection has long been a source of regulatory uncertainty for the sector.
The position under PSD3 and the PSR is now clearer. Electronic money tokens (“EMTs“) that qualify as electronic money remain subject to the PSD3 and PSR framework. Crypto-asset service providers (“CASPs“) that provide transfer services for EMTs where those tokens are used to pay for goods or services will need to hold payment services authorisation. Exchanges by CASPs acting in their own name as buyer or seller fall outside scope.
To reduce duplication, the PSR introduces a notification-based equivalence mechanism allowing an already-authorised payment institution to offer specified EMT-related crypto-asset services. This is a practical step that acknowledges the operational overlap between the two regulatory regimes.
Open Banking: Tighter Standards and Stronger Enforcement
The PSR significantly tightens the open banking regime. Account servicing payment service providers (“ASPSPs“) will be required to rely on dedicated interfaces as the default for third-party access. Screen-scraping will be prohibited, with a conditional derogation available only in defined circumstances at the discretion of competent authorities.
Performance requirements for those interfaces are more demanding. The PSR sets clear presumptions of unavailability, triggered after five consecutive failed requests or 30-second timeouts, requires quarterly performance statistics, and tasks the European Banking Authority (“EBA“) with specifying optimal recovery times through regulatory technical standards. Unjustified downtime will constitute a supervisory breach in its own right.
Third-party providers will enjoy the same level of data access as the ASPSP’s own customers using direct channels. This resolves one of the most persistent complaints under PSD2, where data parity was frequently cited as an obstacle to effective open banking.
Prudential Safeguarding Requirements
On the prudential side, PSD3 aligns and strengthens the safeguarding regimes previously contained in PSD2 and the E-Money Directive. Customer funds must be diversified to avoid concentration risk where appropriate, with the EBA to define the relevant circumstances through regulatory technical standards.
In eligible jurisdictions where the national central bank’s organic law permits, payment institutions will be able to safeguard customer funds directly at the central bank. This option could eliminate single-bank concentration risk for institutions operating in those jurisdictions.
Additional requirements include formal reconciliation obligations, documented evidence obligations for supervisors, and clearer insolvency ring-fencing provisions. Safeguarded funds must be insulated from the claims of other creditors in accordance with national law.
Centralisation and the Continued Importance of National Supervision
The overall direction of the PSD3 payment services regulation package is centralising. By shifting conduct of business rules into a directly applicable regulation and elevating the EBA’s role in technical standard-setting and supervisory convergence, the framework reduces the space in which National Competent Authorities (“NCAs“) have historically shaped the regulatory environment.
This does not, however, diminish the importance of national supervision. If anything, it increases it. As EU-level standards become more uniform, the quality of the NCA, its accessibility, its commercial understanding, and the consistency and speed of its supervisory engagement, becomes a more decisive factor in jurisdiction selection. The legal framework may be harmonised; the supervisory experience will not be.
Malta’s Position in the New Framework
The MFSA continues to position Malta as a credible home for payment institutions, electronic money institutions, and crypto-asset service providers seeking an established EU base. Its track record in payments and fintech supervision, its engagement during the authorisation process, and its approach to novel business models are factors that will carry increased weight as the new framework comes into force.
As PSD3 and the PSR push regulatory authority towards the European Commission, the European Central Bank (“ECB“), the EBA, and the European Securities and Markets Authority (“ESMA“), the NCA will remain the primary point of contact for firms operating at the national level. The quality of that relationship, and the jurisdiction from which it is managed, will continue to matter.
For payment institutions and electronic money institutions assessing their EU licensing strategy ahead of the September 2026 adoption timeline, Malta’s combination of regulatory credibility, NCA quality, and established infrastructure in the payments space warrants close consideration.
PSD3 Readiness: What Firms Should Be Doing Now
The legislative text may not yet be final, but the supervisory clock has already started. The MFSA’s Dear CEO Letter, issued ahead of PSD3’s publication in the EU Official Journal, sets out eight minimum expectations for authorised payment institutions and electronic money institutions. The approach mirrors the preparatory phase firms experienced ahead of the Digital Operational Resilience Act (“DORA“), and the message carries the same underlying tone: do not wait for the final text before beginning your readiness work.
The eight supervisory expectations centre on three core actions: educating internal stakeholders on the implications of PSD3, conducting a structured gap analysis against the incoming requirements, and developing a clear implementation roadmap. While the Dear CEO Letter stops short of prescribing operational detail on the re-authorisation process itself, the MFSA is explicit that re-authorisation is not automatic. Firms should expect increased scrutiny as they demonstrate compliance with the new framework.
An important timing pressure adds urgency to this. The EBA is expected to develop an authorisation regulatory technical standard within 12 months of PSD3’s publication, with firms required to undergo re-authorisation within a relatively short implementation window thereafter. That window, combined with the volume of firms in scope, makes early engagement with the process a practical necessity rather than an option.
The regulatory detail will continue to emerge through EBA technical standards and guidelines over the coming months. The direction of travel, however, is now sufficiently clear for firms to act. Institutions that approach PSD3 readiness with the same rigour applied to DORA will be better placed, both in terms of the re-authorisation process and in their ongoing relationship with their national competent authority.
Promethean Advisory Limited supports financial services firms navigating regulatory change in Malta and across the EU. We work with payment institutions and electronic money institutions on PSD3 readiness initiatives, from stakeholder awareness sessions through to gap analyses and implementation planning. For further information, please contact our team.

