Open finance APIs for what's law now, not just what's coming
PSD2's dedicated-interface APIs are binding today. Verification of Payee has been mandatory for euro-area PSPs since October 2025. PSD3/PSR is provisionally agreed but not yet in force. FIDA is still being negotiated. Build accordingly — not as if all four sit on the same legal footing.
Four instruments, four different legal stages
Open finance coverage tends to blur these together as one "PSD3/FIDA is coming" story. They're not the same thing, and treating them as equally binding leads to either wasted effort or missed obligations.
| Instrument | Legal status on review date | What it covers |
|---|---|---|
| PSD2 + RTS SCA | In force — dedicated-interface Open Banking APIs are a live requirement | Account information (AIS) and payment initiation (PIS) access for licensed third-party providers |
| Instant Payments Regulation | In force — Verification of Payee mandatory for euro-area PSPs since 9 October 2025 | Instant euro credit transfers and payee name/IBAN matching before execution |
| PSD3 / PSR | Provisionally agreed (27 Nov 2025); final texts published (23 Apr 2026); not yet in the Official Journal on the review date | Replaces PSD2/RTS SCA — mandatory dedicated interfaces, permission dashboards, generalized Verification of Payee, revised fraud liability |
| FIDA | Still in trilogue — not politically agreed, no adopted text | Broader financial data beyond payments — mortgages, loans, savings, investments, insurance, pensions, crypto |
Track each instrument's status independently — a provisional political agreement, a published compromise text, and an adopted regulation in the Official Journal are three different things, not synonyms. Council press release, 27 November 2025.
What PSD2 actually requires, today
This is the baseline an auditor or a national competent authority checks against right now — not a future-state aspiration.
Dedicated interface
Account-servicing PSPs must expose a dedicated API for account information and payment initiation access, distinct from their customer-facing channel.
Performance parity
The dedicated interface must offer the same level of availability and performance as the interface the ASPSP offers its own customers.
Strong Customer Authentication
Multi-factor authentication for electronic payments, with defined exemptions for low-risk or low-value transactions under RTS SCA.
TPP identification
Third-party providers authenticate using qualified certificates for electronic seals or website authentication (QWACs/QSealCs) under eIDAS.
Fallback interface conditions
A fallback (contingency) interface is only exempted from live testing when the dedicated interface meets specific, monitored conditions — this exemption is disappearing under PSR.
Consent scope and duration
AISPs must operate within the explicit consent scope and renewal cycle the customer granted, not an open-ended standing permission.
If your dedicated interface doesn't meet these today, that's the compliance gap worth closing first — before spending effort on PSD3 or FIDA readiness. Directive (EU) 2015/2366 and the RTS on SCA and CSC.
Verification of Payee: already live, and expanding
This is the one item on this page with a real, binding, near-term deadline for organizations that haven't implemented it yet — not a "prepare for the future" item.
Euro-area PSPs
Verification of Payee has been mandatory since 9 October 2025 — already in force for close to a year on this page's review date.
Non-euro-area PSPs
Deadline is 9 July 2027 — real, but no longer distant. Build it now rather than treating it as a later-phase item.
What it checks
The payee's name against the account identifier before a transfer executes, returning a match, close-match, no-match, or other result to the payer.
No extra charge
The Instant Payments Regulation requires this check be provided to the payer without additional cost.
PSR is expected to generalize payee-matching across all credit transfers, not just instant euro ones — building a solid VoP integration now under the IPR gives you a head start on that broader requirement. Regulation (EU) 2024/886.
PSD3/PSR: the direction is confirmed, the clock hasn't started
Provisional agreement and published compromise texts mean the substance is very unlikely to change dramatically — worth designing for now — but the compliance deadline itself hasn't started running yet.
What's changing
- Fallback (screen-scraping-adjacent) interface exemption abolished — dedicated interfaces become mandatory with no backstop
- Mandatory permission dashboards for customers to view and revoke third-party access
- Verification of Payee generalized across all credit transfers, not just instant euro ones
- Revised fraud-liability rules, including for authorized push-payment scenarios
- PSR applies directly across Member States as a regulation — less national variance than PSD2's directive-based conduct rules
What's still moving
Official Journal publication timing (anticipated mid-2026, possibly slipping into September 2026) and the exact application date, expected roughly 18–21 months after entry into force. Track the actual OJ publication date directly rather than an estimate. EC payment services page.
FIDA: real momentum, still not a law
FIDA gets discussed as if it were the next confirmed step after PSD3. It isn't there yet — the negotiation is genuinely unresolved on the point that matters most economically.
Still in trilogue
As of this page's review date, Parliament, Council and Commission have not reached political agreement — the process stalled in mid-2025 and resumed through 2026.
The compensation fight
How much a data user owes a data holder for shared access is the most contested open item, and it directly shapes whether an open-finance product built on FIDA data is economically viable.
Broader data scope
As proposed, FIDA extends well past payment accounts into mortgages, loans, savings, investments, insurance, pensions, and crypto/digital assets.
Financial Data Sharing Schemes
As proposed, data holders and users would need to participate in designated schemes governing technical standards and — eventually — compensation.
A permission dashboard, again
As proposed, FIDA mirrors PSR's dashboard concept — customers see and control who has access to which financial data category.
A realistic timeline
Best-case estimates put political agreement in 2026, Official Journal publication in 2027, and application roughly 24 months later — meaning genuine FIDA compliance work is still years out.
Watch the Commission's own tracking page for the actual trilogue status rather than relying on a fixed date from any single article — the timeline has already slipped once. EC framework for financial data access.
Build the data model once, extend it as each instrument lands
The same mistake shows up across every EU compliance deadline on this site: building narrowly for today's exact requirement and rebuilding from scratch when the next instrument arrives. Open finance is a clean case for avoiding that.
Build now
- A dedicated-interface API layer that already meets PSD2/RTS SCA performance-parity requirements
- Verification of Payee integration, ready for the July 2027 non-euro-area deadline if not already required
- A consent/permission model that isn't hardcoded to payment-account scope alone
Design for, don't build yet
- A permission dashboard architecture that can extend from PSR's confirmed shape to FIDA's broader scope
- A data model with a category dimension (payments, savings, insurance, pensions, ...) that FIDA's scope would map onto
- A pluggable compensation/settlement layer for data-sharing arrangements, since that mechanism is still unresolved
Don't let uncertainty become an excuse
FIDA's uncertainty is a reason for architectural caution, not for ignoring open finance. Your PSD2 baseline and Verification of Payee obligations are real today regardless of how FIDA ultimately lands.
Controls that keep pace with a moving legal target
An open-finance API layer needs controls that survive both a regulator audit today and a legal-basis change in 18 months.
Performance-parity monitoring
Continuously monitor dedicated-interface availability and latency against your own customer-facing channel, with alerting on drift.
TPP certificate validation
Validate eIDAS qualified certificates on every third-party provider request, not just at onboarding.
Consent-scope enforcement
Enforce the exact scope and expiry a customer granted — reject requests outside it rather than silently widening access.
VoP result logging
Retain Verification of Payee match/no-match results and the payer's decision for each affected transfer.
Regulatory-status tracking
Track PSD3/PSR and FIDA's actual legislative status on a schedule, not as a one-time reading of this page.
Fallback-retirement readiness
Have a plan to retire any fallback-interface dependency before PSR's abolition of that exemption takes effect.
Close today's gaps before building for tomorrow's rules
Fix what's actually enforceable first. Everything about PSD3 and FIDA readiness matters more once your PSD2 baseline is solid.
Audit your PSD2 baseline
Check dedicated-interface performance parity, SCA exemption logic, and TPP certificate validation against what's actually in force today.
Close any Verification of Payee gap
If you handle euro instant transfers, confirm VoP is live; if not, plan for the 9 July 2027 non-euro-area deadline now.
Model consent and data categories broadly
Build the permission/consent layer with a category dimension that can extend past payment accounts.
Track PSD3/PSR's Official Journal status
Set a recurring check on actual publication, not an estimated date from this or any other article.
Prototype, don't productionize, for FIDA
Sketch how your architecture would extend to FIDA's scope without committing production resources to an unagreed text.
Revisit as each instrument's status changes
Treat this as a living architecture decision, re-evaluated at each legislative milestone, not a one-time build.
Acceptance criteria for the API layer
PSD2-compliant now
Dedicated-interface performance parity, SCA exemption logic and TPP certificate validation all pass today, not conditionally.
VoP-integrated
Verification of Payee is live for euro instant transfers, or explicitly scheduled ahead of the July 2027 non-euro-area deadline.
Status-aware
The system (or the team operating it) tracks PSD3/PSR and FIDA's actual legislative status, not a fixed assumption.
Extensible data model
Consent and data-category structures can extend toward PSR's and FIDA's broader scope without a schema rebuild.
Fallback-independent
The dedicated interface is reliable enough to not depend on a fallback exemption that PSR is expected to abolish.
Not over-built for FIDA
No production compliance investment is locked to FIDA-specific mechanics — like compensation — that remain legislatively unresolved.
FIDA & PSD3 FAQ
Is FIDA law yet? Should we be building for it right now?
No, not as law. As of this page's 2 September 2026 review, FIDA is still in trilogue negotiation between Parliament, Council and Commission — it has not been politically agreed, let alone published in the Official Journal. The compensation mechanism between data holders and data users remains the most contested open issue. Design your data model to be extensible toward FIDA's broader scope, but don't build a production compliance program against a text that could still change.
Is PSD3/PSR further along than FIDA?
Yes, meaningfully. Parliament and Council reached provisional political agreement on 27 November 2025, and final compromise texts were published 23 April 2026. Publication in the Official Journal was anticipated for mid-2026, with some estimates pointing to a slip into September 2026 — potentially right around this page's review date. Even once published, the PSR's core conduct-of-business rules are expected to apply roughly 18–21 months later, realistically not before late 2027.
What do we actually have to comply with today, right now?
PSD2 (Directive (EU) 2015/2366) and its RTS on Strong Customer Authentication (Commission Delegated Regulation (EU) 2018/389) are fully in force — dedicated-interface Open Banking APIs for account information and payment initiation are a live legal requirement, not a future one. If your organization processes euro-denominated instant credit transfers, Verification of Payee under the Instant Payments Regulation has also been mandatory since 9 October 2025. Those are the two things an auditor can actually check you against today.
Is screen-scraping still a legal fallback if our dedicated API has problems?
Under PSD2, a fallback interface (which could permit screen-scraping-style access) was allowed when an account-servicing PSP's dedicated interface met specific exemption conditions. PSR, once it applies, is expected to abolish that fallback exemption entirely, making a compliant dedicated interface mandatory with no screen-scraping backstop. Build your dedicated interface to be reliable enough that you're not depending on a fallback that's disappearing.
What's actually being fought over in the FIDA negotiations?
The compensation mechanism — how much, if anything, a data user (like a fintech building on shared data) must pay a data holder (like a bank) for access — is reported as the single most contested item. Until that's resolved, the economics of building an open-finance product on top of FIDA-shared data remain genuinely uncertain, which is a real reason to treat FIDA-specific investment cautiously right now.
What data would FIDA actually cover, if adopted as proposed?
Beyond PSD2/PSR's payment-account scope, FIDA's proposal extends to a much wider range of customer financial data — mortgages, loans, savings, investments, insurance, pensions, and crypto/digital assets. That breadth is exactly why the data model matters: an architecture built narrowly around payment-account XS2A won't extend cleanly to that scope without rework.
Do existing PSD2 third-party provider licenses carry over to PSD3?
PSD3, as a directive, will require national transposition and is expected to bring authorization and supervision rules for payment institutions largely forward with updates rather than a clean-slate relicensing regime, but the final transposed text in each Member State will govern the actual transition mechanics. Track your national regulator's transposition guidance directly rather than assuming automatic continuity once PSD3 is adopted.
Primary sources and status
Reviewed 2 September 2026. PSD2 and the RTS on SCA and CSC are in force. The Instant Payments Regulation is in force, with Verification of Payee mandatory for euro-area PSPs since 9 October 2025 and for non-euro-area PSPs from 9 July 2027. PSD3/PSR was provisionally agreed with compromise texts published, but not yet published in the Official Journal, on the review date. FIDA remained in trilogue negotiation, with no adopted text, on the review date. Yarify's architecture recommendations are engineering guidance, not legal or regulatory advice — confirm your obligations and licensing status with qualified counsel and your national competent authority.
- Directive (EU) 2015/2366 — PSD2Currently binding directive requiring account-servicing PSPs to give third-party providers dedicated API access to payment accounts
- Commission Delegated Regulation (EU) 2018/389 — RTS on SCA and CSCIn-force technical standard defining strong customer authentication and the dedicated-interface requirements behind today's Open Banking APIs
- Regulation (EU) 2024/886 — Instant Payments RegulationIn-force regulation requiring Verification of Payee; mandatory for euro-area PSPs since 9 October 2025, non-euro-area PSPs from 9 July 2027
- Council of the EU — press release, 27 November 2025Official announcement of the provisional political agreement between Parliament and Council on PSD3 and the Payment Services Regulation
- European Commission — Payment servicesOfficial Commission page tracking the PSD3/PSR legislative package and its status
- European Commission — Framework for financial data access (FIDA)Official Commission page for the FIDA proposal, its scope and legislative progress
