Industry News

PSD3 and Payment Passkeys: What Actually Changes for Virtual Card Authentication in 2026

The EU's PSD3 regulation is arriving alongside Visa and Mastercard Payment Passkey services that replace SMS OTPs. Here is what virtual card users actually need to know.

PSD3 and Payment Passkeys: What Actually Changes for Virtual Card Authentication in 2026

What PSD3 actually changes

The EU passed PSD3 (the third Payment Services Directive) and its companion Payment Services Regulation (PSR) in November 2025. This is not a minor technical amendment. It is a rewrite of the rulebook for the entire European payments industry, and three things in it matter.

First, payment license approval gets centralized. PSD3 shifts the licensing of payment institutions from individual member-state approval to a unified EU framework, giving the European Banking Authority (EBA) greater supervisory coordination. For virtual card platforms that rely on EU EMI licenses to issue cards or process payments, compliance costs will rise in the short term.

Second, Open Banking becomes mandatory. Under PSD2, open banking was encouraged. Under PSD3, it is required. Banks must expose standardized API interfaces, and third-party payment providers get free access to account data (with user consent). This is directly driving the Pay by Bank surge across Europe. EBA data shows over 600 banks had live open banking APIs by 2025, processing more than 100 million Pay by Bank transactions per month.

Third, and most relevant to virtual card users: Strong Customer Authentication (SCA) rules get tighter. PSD2 already required SCA, but PSD3 sharpens the technical standards for "dynamic linking" and for customer-present versus customer-absent scenarios. In plain terms, when your virtual card gets charged, the issuing bank has to confirm the cardholder is actually authorizing it, and the acceptable methods for doing that are getting stricter.

How Passkeys change the payment experience

Visa and Mastercard both saw this coming. Almost simultaneously, they launched their own Payment Passkey Service.

Here is the technical shift. In a traditional virtual card payment, the merchant triggers 3-D Secure, which redirects to the issuing bank's page, and you type in an SMS OTP to authenticate. That process has real problems: SMS latency, interception risk, and a clunky user experience. Passkeys use the FIDO Alliance standard, binding authentication to the device's biometrics (fingerprint or face). Verification happens locally. No verification code gets sent anywhere.

Mastercard launched its Payment Passkey Service in India in August 2024. By 2026 it had expanded to Singapore, Brazil, the UAE, and Europe. According to Mastercard's own figures, over 80 percent of confirmed data breaches involve passwords. Visa launched a comparable Payment Passkey Service in 2025. The two card networks moving in lockstep is not a coincidence. They are aligning with PSD3's SCA tightening.

One detail worth catching. Corbado's analysis notes that nearly 50 percent of European e-commerce transactions already use tokenization, and Mastercard's stated goal is full passwordless checkout by 2030. That means by the end of this decade, paying online with a virtual card will not involve any SMS codes or 3DS redirect pages.

Are virtual card platforms ready

Frankly, most are not.

The platforms in our directory, including PokePay, FotonCard, and DogPay, vary widely in their support for PSD3 and Passkey services. Most still handle 3DS through SMS OTPs. This is not the platforms' fault. PSD3 primarily affects EU-licensed issuing banks, and these virtual card platforms typically issue through banks outside the EU (Caribbean tax havens, US BINs), so users will not feel the impact immediately.

But if you are using a virtual card issued under a European EMI license, such as those from LianLian Global, PSD3 compliance pressure will hit your payment experience directly: more 3DS challenges, stricter cardholder verification, and outright declines at some high-risk merchants.

Three practical effects on virtual card users

1. You will hit 3DS more often on cross-border payments. PSD3 expands the scope of SCA. Certain low-value cross-border transactions that previously qualified for SCA exemptions (PSD2 allowed exemptions under 30 euros) lose some of those exemptions. Your virtual card will likely trigger 3DS more frequently when paying for Google Ads, Facebook ad spend, or overseas SaaS subscriptions.

2. Pay by Bank starts eating into card payment volume. Some European merchants have already integrated Pay by Bank, letting users pay directly from their bank accounts and bypass the card networks entirely. What does this mean for you? At certain European merchants, you may see Pay by Bank presented as the default payment option, with card payments demoted. That is not necessarily bad since Pay by Bank fees are lower. But for users who rely on virtual cards to manage multiple accounts, it is a structural shift worth tracking.

3. Issuing platform compliance costs go up. PSD3 raises the minimum initial capital for payment institutions (from roughly $50,000 to $75,000 EUR) and tightens anti-fraud and AML obligations. Those costs will eventually pass through to users in the form of higher issuance fees or transaction charges. Grand View Research puts the global prepaid card market at over $3 trillion in 2025, with virtual cards the fastest-growing segment. But rising regulatory overhead will squeeze platform margins.

How this connects to Visa VAMP

There is another regulatory change that needs to be read alongside PSD3. The Visa VAMP program (Visa Acquirer Monitoring Program) went live in April 2026, merging the old VFMP and VDMP frameworks, and set the fraud dispute ratio ceiling for acquirers at 0.7 percent. VAMP governs risk monitoring on the acquiring side. PSD3 governs authentication requirements on the issuing side. Stack the two together and the effect is clear: decline rates for virtual card transactions at EU merchants will rise.

If you have read our analysis of virtual card declines and BIN risk scoring, you already understand the backdrop. BIN sharing is another structural issue. Multiple virtual card platforms use the same BIN range (for example, 531993 is shared by VCard, FotonCard, PrivCards, and at least one other platform). When one platform's transactions trigger risk controls, every platform on that BIN range takes collateral damage.

What users can do now

A few practical steps.

First, figure out which jurisdiction your virtual card's issuing bank sits in. If the issuer is in the EU (a Lithuanian EMI, an Irish payment institution), PSD3 hits more directly. If the issuer is outside the EU (US, Hong Kong, Singapore), short-term impact is smaller, but the card networks' global policies will gradually align.

Second, check whether your card platform supports 3DS version 2.2 or higher. 3DS 2.x supports a smoother cardholder verification flow (frictionless authentication), which matters more once PSD3 tightens SCA. If your platform is still on 3DS 1.0, the experience will get noticeably worse.

Third, for high-frequency use cases like ad spend and SaaS subscriptions, keep redundant virtual cards on different BINs ready. If one card gets declined due to risk controls or authentication friction, you can switch immediately. This is not paranoia. The VAMP 0.7 percent threshold means acquirers will proactively lower authorization pass rates for high-risk merchants.

This is a structural adjustment, not a threat

One final judgment. PSD3, Passkeys, VAMP, and the rest of these changes are pushing the payment industry toward something safer but also more concentrated. Large banks and card networks benefit because they have the resources to meet these requirements. Mid-sized virtual card platforms face pressure because compliance is a fixed cost, and platforms without sufficient scale will get squeezed out.

For users, the short-term feeling is "more verification prompts" and "cards getting declined more often." Long-term, though, Passkeys replacing SMS OTPs is a net improvement. SMS codes were never secure. SIM swap attacks cause hundreds of millions of dollars in losses every year. PSD3 is pushing the whole industry toward authentication methods that are actually safe, even if the transition is bumpy.

If you run into new authentication prompts or declined transactions while using virtual cards, you can compare fee structures and BIN details across platforms like PokePay or Crospay to see how different issuers handle the shift.