From

Ideem

— device-bound passkeys and A2A payment authentication for banks, fintechs, and payment platforms.

Regulatory News
9 min read

PSR3 / PSD3 Implementation Update: Where Europe Stands in Mid-2026

The PSR/PSD3 package is out of trilogue with final compromise texts circulated April 23, 2026, putting EU banks on a roughly two-year runway to substantive application in 2028. The regulation ratifies the phishing-resistant, transaction-bound authentication architecture that was already the right answer on security grounds.
Written by
Toby Rush
Published on
June 16, 2026

TL;DR

  • The European Parliament and Council reached a provisional political agreement on PSD3 and the PSR in late November 2025; final compromise texts were circulated to COREPER on 23 April 2026, with Official Journal publication expected toward the end of Q2 2026.
  • As drafted in the current trilogue text, the PSR applies directly across the EU roughly 21 months after publication (early-to-mid 2028), with verification-of-payee provisions phased in over 27 months and PSD3 transposition required within 18 months — meaning the practical compliance runway for most banks runs through 2027 and into 2028.
  • The joint EBA-ECB 2025 Payment Fraud Report confirmed that SCA continues to reduce fraud in absolute terms even as total EEA payment fraud rose to €4.2bn in 2024, with attacker effort shifting toward exemption flows and social-engineering of legitimate users.
  • The expected PSR brings reimbursement obligations for impersonation fraud, mandatory verification-of-payee for credit transfers, stricter governance of SCA exemptions and TRA, and stronger dynamic linking — all of which raise the bar on phishing-resistant authentication.
  • FIDO-based passkeys remain explicitly recognized by the EBA as compatible with PSD2 SCA when implemented with appropriate possession and verification factors; the same architecture maps cleanly onto the PSR's expected requirements.
  • Ideem's Passkeys+ is built to support the controls the PSR is moving toward: origin binding against phishing, device-bound credentials for high-assurance flows, and transaction binding for dynamic linking on high-value payments.

Europe's payments regulation has reached the part of the cycle every bank executive has been waiting for. After three years of negotiation, the PSR and PSD3 are out of trilogue, into legal-linguistic review, and on track for Official Journal publication before the summer break. The political work is done. The implementation work starts now.

This is the mid-2026 picture from where Ideem sits — talking to European banks, payment institutions, and the vendor ecosystem shipping against the final text. The thesis is simple. The PSR is going to push every EU bank toward the controls that were already the right answer on security grounds, and the institutions that started the journey early will be in a meaningfully different posture by the time the rules apply than the ones still waiting for certainty.

Where the legislative process actually stands

The provisional political agreement between the European Parliament and the Council was announced on 27 November 2025, closing out the active trilogue phase under the Danish Presidency. The Council's General Secretariat circulated final compromise texts to COREPER on 23 April 2026 — documents ST-8222-2026-INIT for PSD3 and ST-8221-2026-INIT for the PSR — and the package is now in legal-linguistic review ahead of formal adoption votes.

The consensus expectation from legal commentary is Official Journal publication toward the end of Q2 2026, with some commentators flagging that the timeline could slip into September. As drafted, the PSR enters application 18–21 months after publication for the substantive obligations — commentators differ on which figure ends up in the final text. PSD3, as a directive, requires national transposition in a similar 18–21 month window. The realistic in-force date for the main body of obligations is therefore late 2027 or 2028, with verification-of-payee provisions phased in over 27 months.

That's the runway. Two years, not five. For banks that haven't begun, the program work starts now — not after the OJ link goes live.

What the joint EBA-ECB 2025 Payment Fraud Report tells us about where SCA stands

The EBA and ECB published the joint 2025 Payment Fraud Report in December 2025. Two findings frame the regulatory thinking that fed into the trilogue.

First, SCA continues to work. The report confirmed that the legal requirement for strong customer authentication, fully phased in from 2020 onward, has measurably reduced the fraud rate on transactions that fall inside the SCA perimeter. The mechanism is doing what it was designed to do.

Second, total reported payment fraud across the EEA still rose — from €3.4bn in 2022 to €3.5bn in 2023 to €4.2bn in 2024. The increase is not a failure of SCA. It's a redistribution of attacker effort toward the surface area that SCA doesn't cover: exemption flows, social engineering of legitimate users to authenticate fraudulent transactions, and authorized push payment scams that defeat possession-and-knowledge factors by manipulating the human.

That diagnosis is the single most important piece of context for understanding the PSR's direction of travel. Regulators are not retreating from SCA. They are tightening the controls around it — exemption governance, dynamic linking, verification-of-payee, impersonation-fraud reimbursement — and pushing the industry toward authentication methods that hold up under the new attacker behaviors. Phishing-resistant credentials, properly bound to the transaction, are the only architecture that addresses all three vectors the report identifies.

The PSR provisions that matter most for authentication strategy

The current trilogue text contains several provisions that bear directly on how banks should be thinking about authentication architecture between now and 2028.

The first is the expected reimbursement obligation for impersonation fraud — the case where a fraudster manipulates a user by posing as their PSP. Under the agreed text, this transaction is treated as unauthorised and reimbursed in full, provided the user reports the fraud to the police and to their PSP. The obligation applies to personal accounts and does not extend across the full APP fraud typology, but it shifts financial exposure for impersonation-driven loss back onto the bank in a way that PSD2 did not. The incentive is to deploy authentication that cannot be replayed by a convincing impersonator. Phishing-resistant credentials qualify. SMS OTP does not.

The second is mandatory verification-of-payee for credit transfers, with liability for misdirected funds shifting to the payer's PSP where a name-identifier mismatch is detected and not surfaced to the customer. SEPA Instant and domestic instant-payment rails all become higher-stakes products. The authentication around the payment matters more, not less, when the bank is now liable for the routing decision.

The third is the strengthening of dynamic linking. As drafted, authentication codes must be dynamically linked to the specific amount and payee, ensuring the code cannot be reused for a different transaction. PSD2 set this expectation. The PSR formalizes it with sharper teeth and lays the groundwork for granular RTS work by the EBA. Transaction-level binding becomes the safer interpretation for any high-value flow.

The fourth is tighter governance of SCA exemptions and Transaction Risk Analysis. The TRA exemption stays available, but with more granular fraud-rate thresholds and stronger evidentiary expectations on the PSP applying it. PSPs that lean heavily on TRA to suppress SCA friction will need provable low-risk conditions and the telemetry to defend exemption decisions to a competent authority.

The fifth, less discussed but operationally significant, is the statutory requirement to connect to shared fraud-intelligence infrastructure and share fraud signals with peers. Banks that have already invested in structured authentication telemetry will be ahead.

How passkeys and FIDO authentication map onto the PSR as drafted

The EBA's position on FIDO and passkeys under PSD2 has been clear in the Q&A responses issued through 2024 and 2025, including recent guidance on SCA application to digital wallets. Passkeys align with the RTS requirements through built-in multi-factor authentication, public-key cryptography, phishing resistance, and hardware-backed security. FIDO2 satisfies SCA when implemented as device-bound passkeys or security keys with appropriate user verification — the device provides possession, and a PIN or biometric provides knowledge or inherence.

The PSR as drafted does not change that mapping. If anything, it strengthens it. The provisions moving from PSD2 to the PSR favor architectures that are bound to the origin, bound to the device, and capable of producing per-transaction signatures. That is precisely what FIDO standards describe.

The honest caveat is that the EBA has flagged classification questions around how synced passkeys interact with the possession factor in some implementations, and that has caused some European banks to wait for additional clarity before deploying at scale. We expect that clarity to arrive in the RTS work the EBA is mandated to do under the PSR. The likely outcome is policy controls that distinguish between synced and device-bound credentials for high-value flows, with both forms viable for the appropriate risk tier — which is exactly how serious financial-services passkey deployments are already being designed.

What forward-leaning EU banks are doing in 2026

The institutions not waiting for the Official Journal are already shipping. ABANCA, the largest bank headquartered in Galicia, became the first Spanish bank to deploy passkeys for mobile banking and published the kind of operational evidence regulators are going to want to see. The FIDO Alliance case study, published in April 2025, reports that more than 42% of ABANCA's roughly 1.2 million monthly mobile customers are using ABANCA Key passkeys, and that more than 11 million high-risk transactions have been authenticated through the passkey path with zero technical or service incidents. Customer-effort scores on the new flow sit at 4.7.

The pattern in the deployments that work is consistent. Passkeys are introduced as the primary authenticator with SMS OTP held as a regulated fallback during the enrollment ramp. Dynamic linking is implemented at the transaction level for high-value flows rather than retrofitted into session tokens. Exemption logic is moved out of bespoke fraud-engine code and into observable, auditable policy. None of this is novel architecture. It is the architecture the PSR is going to ratify.

What this means for European bank security and product leaders

For the bank teams making 2026 and 2027 program decisions, four practical takeaways stand out.

Start the passkey program in 2026 if it hasn't already. The runway to the PSR's substantive application is roughly two years. Enrollment ramps are slow, the operational work is non-trivial, and the institutions reporting strong adoption started before they had to.

Treat dynamic linking as a transaction-level requirement, not a session-level one. The cleanest interpretation of the trilogue text and the EBA's direction is per-transaction signing for high-value flows.

Invest in exemption telemetry now. TRA exemption decisions will need clean, defensible audit trails when the RTS work matures. Building telemetry into the authentication layer is easier than retrofitting it.

Plan the SMS OTP retirement timeline backward from 2028. With impersonation-fraud reimbursement applying under text-replay-vulnerable channels, SMS OTP is on a documented decline curve. The banks that retire it on a deliberate schedule will report better numbers than the ones forced into emergency migration in 2027.

Where Ideem fits

Ideem's Passkeys+ is the bank-grade passkey layer financial services teams use to ship the controls the PSR is moving toward without spending engineering cycles building the supporting infrastructure. The platform supports origin binding against phishing, both synced and device-bound credentials with policy-controlled selection, and transaction binding so each high-value payment carries a fresh passkey signature rather than relying on session-level trust. Each of those properties maps directly onto a PSR provision as drafted.

Passkeys+ plugs into the existing identity stack so an EU rollout doesn't require a re-platform. For the regulator-facing conversation, the telemetry the platform produces — enrollment rates, authentication outcomes, exemption decisions, transaction-binding signatures — gives a bank the evidentiary base to demonstrate compliance with the PSR's expected governance requirements rather than reverse-engineering it from logs after the fact.

The honest read on PSR3 and PSD3 in mid-2026 is that the regulation is doing what good regulation does — ratifying where the security architecture already needed to go and giving the industry a clear two-year window to get there. The forward-looking question for every European bank security leader is no longer whether to retire SMS OTP and adopt phishing-resistant authentication. It's how fast, on what enrollment curve, and with what telemetry behind it.

Sources

How exposed is your auth stack?

Most orgs running OTP-based MFA have 3–4 exploitable gaps they don’t know about. Our Authentication Assessment takes 2 minutes and shows you exactly where you stand — plus a phased migration roadmap.

Take the Assessment →

Built by Ideem

Device-bound passkeys and A2A payment authentication. One SDK. No OTPs, no redirects.

Weekly newsletter
No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Think your MFA is solid? Let's find out.

Our 2-minute assessment scores your authentication setup and shows you exactly where the improvements are.

See Your Score →

See how your stack measures up →

Free Assessment →

Before you go —

Ideem replaces the authentication patterns described in this post. Two minutes to see where your stack stands.

8 questions. 2 minutes. Get a phased migration roadmap.

Take the 2-Min Assessment →No thanks, I’ll skip for now