The European payments landscape is about to undergo its most significant structural realignment since 2018. As the proposed Third Payment Services Directive (PSD3) inches closer to adoption, much of the industry discussion has centered on timelines, technical specifications, and legal terminology.
But as leaders, we need to look past the policy jargon and focus on the operational reality.
PSD3 is not just another compliance update. It represents a fundamental shift in how payment and electronic money institutions (EMIs) will be permitted to exist. By merging the Payment Institution (PI) and EMI license categories and turning e-money issuance into a standard payment service, the regulator is effectively raising the bar for the entire ecosystem.
For many firms, the next two years will decide whether they continue to operate or find their services abruptly suspended.
Turning transition into a commercial moat
While the operational challenge of PSD3 is real, the commercial opportunity is even greater.
For platforms, lenders, e-commerce giants, and incoming verticals like iGaming, the ability to guarantee uninterrupted service during this time frame is a massive differentiator. Merchants and consumers will naturally migrate away from platforms showing regulatory vulnerability and toward those that can guarantee continuous, stable service.
By investing in robust Open Finance Compliance and consent infrastructure today, you achieve two things at once:
- De-risk your own transition: You hand the regulator clean, verifiable, and structured data that makes authorization a formality.
- Build customer trust: You demonstrate to your partners that your operations are resilient, secure, and built for the long term.
The sharpest lever: The risk of service suspension
Under the proposed rules, existing PSD2 and EMD2 license holders will be granted a 27-month transition window for the existing license holders from the moment PSD3 enters into force. During this period, firms can continue operating under their current authorizations.
However, this is not a free pass. To maintain their status, firms must submit comprehensive evidence demonstrating compliance with the new, rigorous Title II framework.
Historically, regulatory transitions have been treated as “paperwork exercises” with a focus on retrospective reporting. PSD3 changes the stakes entirely. If a firm fails to provide the required information, covering capital adequacy, safeguarding measures, and Digital Operational Resilience Act (DORA) compliance, or if the competent authority cannot easily verify it, the regulator has the power to suspend the firm’s services.
In a highly competitive, real-time transaction environment, a suspension is not a slap on the wrist; it is a terminal event for client trust and business operations.
“As many industry leaders have already pointed out, treating PSD3 as a narrow document-production exercise is the single greatest risk facing licensed firms today. The gap between a ‘narrow checklist’ and a ‘full compliance posture’ is where many will falter.”
The gap between a checklist and true compliance
While the competent authority will demand specific documentation around ICT resilience (such as DORA alignment) and safeguarding, they will ultimately assess your firm against the broader, more holistic Title II framework.
This means regulators aren’t just looking for static policy documents; they are looking for verifiable, live operational resilience.
- Dynamic Consent Auditing: Can your consent management system produce clean, real-time, tamper-proof trails that prove consumer data is safeguarded?
- Continuous Risk Visibility: Is your risk framework integrated into your transaction flow, or is it a manual, retrospective review?
- Clean Operational Boundaries: For EMIs losing the ability to bundle auxiliary services under a single e-money umbrella, can you clearly separate, track, and verify acquiring, remittance, and payment execution?
If your compliance evidence is built on manual spreadsheets and disconnected databases, the risk of information being rejected as “unverifiable” skyrockets.
Walking the same path: Qwist’s dual perspective
At Qwist, we do not view this shift from the safety of the sidelines.
As a ZAG-licensed entity regulated by BaFin, we face the exact same transition. We are navigating the same 27-month countdown, mapping our own DORA documentation to the new standards, and ensuring our regulatory posture is completely seamless.
This direct exposure shapes our entire commercial philosophy. We build the infrastructure we use ourselves.
We know that the key to surviving, and thriving through, this transition is to embed compliance directly into your technical architecture. When your technology naturally produces the audit trails, consent histories, and risk profiles that the regulator wants to see, compliance ceases to be a frantic legal project. It becomes a natural byproduct of your day-to-day operations.
The time to prepare is now
The exact date when the 27-month clock starts ticking remains unfixed, pending the final publication of the Directive in the Official Journal. But waiting for the final text to be printed before acting is a luxury no business leader can afford.
Building robust, audit-ready data structures, updating consent frameworks, and aligning your risk infrastructure with Title II expectations takes time.
The firms that lead this transition will be those that treat PSD3 not as a threat to be managed, but as a catalyst to modernize their financial infrastructure. At Qwist, we are already building that future, both for our own regulated operations and for the partners who build on our technology.
Let’s start the preparation today.
Glenn Mac Donald, Qwist CEO
Glenn Mac Donald is Managing Director and Group CEO of Qwist GmbH, a BaFin and ZAG-licensed Open Finance infrastructure provider connecting more than 3,600 banking institutions across Europe. He leads Qwist’s strategy and growth as the company expands its Connect, Assess and Activate platform, delivering solutions for regulated data access, financial intelligence, Pay by Bank and Account Verification. Glenn brings over 20 years of C-level, board, and regulatory leadership experience across payments and RegTech. He previously served as SVP Global Cards Acquiring at Adyen, CEO of Nasdaq-listed RegTech firm ZignSec (leading its sale to G2RS Group), Chief Commercial Officer and Board Member at International Card Services (ICS, part of ABN AMRO), and Non-Executive Chair at payabl., with earlier senior roles at Visa Europe, ING Group, and Deloitte.




