PSD3, cVRP and the Cloud Core: Why This Summer Is Rewiring Open Banking
- Koen Vanderhoydonk
- 5 hours ago
- 6 min read

As of this week, Europe's payment plumbing is being ripped out and replaced in three places at once. The banks that treat it as a compliance exercise are going to be paying the fintechs that treat it as a growth strategy.
Three regulations, one direction of travel
If you spent June and July on a beach and are only now catching up, here is the compressed version: PSD3 is on the runway, the UK's commercial Variable Recurring Payments scheme is live, and the EU's Financial Data Access framework is inching towards adoption. Together, they will do more to reshape European retail banking over the next 24 months than PSD2 did in the previous eight years.
The direction of travel is unmistakable. API access is becoming a regulated utility. Payment initiation is becoming a real alternative to card rails. And the definition of "your data" is expanding well beyond current accounts.
PSD3: the countdown clock is ticking
According to Morrison Foerster's regulatory update, the European Parliament, Council and Commission agreed the final text of PSD3 and the Payment Services Regulation on 23 April 2026. Publication in the Official Journal of the European Union is expected between June and July 2026, though some industry lawyers have warned the timing could slip to September.
Once publication happens, PSPs across the bloc have 18 months to comply.
What is actually in it? Coverage from Embat and Crassula highlights three material changes for any firm running open banking rails. First, prescriptive requirements for API performance and uptime, with clearer standards for availability and reliability that remove the "unnecessary re-authentication" tricks incumbents used to slow third-party access. Second, expanded fraud-liability rules covering authorised push payment scams. Third, a full merger of the e-money institution regime into the payment institution framework, simplifying licensing but tightening capital and safeguarding expectations.
The 18-month clock is short. Banks that treated PSD2 API compliance as a "build it once and forget it" project are already discovering that PSD3 will require serious platform investment. TechFunnel's 2026 open banking outlook put it plainly: PSD3 turns APIs from a check-box into a graded product.
The UK just went first on cVRP
While Brussels finalises PSD3, London has already shipped. On 3 June 2026, the UK Payments Initiative went live with its commercial Variable Recurring Payments scheme, according to the Financial Conduct Authority's own statement. The founding shareholders read like a Who's Who of British banking: HSBC, Barclays, Lloyds Banking Group, NatWest, Nationwide, Santander, Monzo, Revolut, and Starling.
The Payment Systems Regulator's December 2025 delivery update explained the mechanics. cVRP extends VRPs from "me-to-me" sweeping to paying real businesses: utilities, government, charities, and, in Wave 2, general e-commerce.
Open Banking Expo's coverage called the scheme a "welcome step" for the UK open banking ecosystem, with a broader ecosystem of implementation partners including Token, GoCardless, TrueLayer, and Yapily. Ozone API, according to a separate Open Banking Expo story, launched a cVRP product specifically to bring non-CMA9 UK banks into the scheme so smaller institutions do not get left behind.
Plaid's own blog described cVRP as a "new standard for recurring payments in the UK", positioning it as a genuine alternative to direct debit and card-on-file for merchants who want faster settlement, lower fees, and better user control.
Why cVRP is a bigger deal than it looks
Direct debit has been the backbone of UK recurring payments for decades. cVRP does not just modernise it. It reroutes the value chain around card networks entirely. For a subscription business paying 1.5% to 2.5% on card transactions, that is a materially different unit economics story.
Wave 1 covers regulated and trusted sectors. Wave 2 (general e-commerce) is expected in the second half of 2026. HM Treasury is set to legislate this year to give the FCA new powers to set open banking rules, and the regulator will assess industry-led cVRP growth by the end of 2026, according to the joint FCA and PSR update covered by A&O Shearman.
FiDA: open banking's older, ambitious sibling
The next domino is the EU's Financial Data Access framework. According to Capco's 2026 primer, FiDA is expected to be formally adopted in mid-2026, with implementation starting in late 2027 and provisions phasing in through 2030.
Where PSD2 was limited to payment accounts, FiDA covers savings and investment accounts, pensions, insurance, and credit products. Management Solutions' technical note describes the mechanism: data holders (banks, insurers, investment firms) must make customer data available to authorised data users when the customer permits it, with access organised through Financial Data Sharing Schemes (FDSS). These industry-governed frameworks will set common technical standards, reasonable compensation for data holders, and clear liability rules.
Banking.Vision's analysis notes that the final FiDA text has become "lighter and more consumer-centric" than early drafts, with reduced compliance burden for smaller entities and a clearer opt-in model for consumers. That is arguably the right trade-off. A framework nobody can implement is worth less than a slightly narrower one that actually ships.
For fintechs, FiDA is the strategic prize. Payment data is table stakes. Pension, mortgage, and insurance data is where the differentiated advisory, planning, and cross-selling propositions are built.
Core banking modernisation: the cloud is now the default
None of this works if the underlying core cannot keep up. And here, according to Crassula's 2026 cloud banking guide, the shift is finally complete. Cloud banking is "no longer an edge case" and is now "the default for every new licence in Europe, North America and APAC, and the endpoint of almost every modernisation program at incumbent banks".
The vendor landscape reads like a set of parallel bets. 10x Banking (SuperCore) is the tier-one play, running at Chase UK and Westpac, according to 10x's own 2026 buyer's guide. Its polyglot runtime removes the smart-contract language lock-in that comes with Thought Machine's Vault, and its built-in migration tooling is optimised for legacy book conversion.
Thought Machine's Vault, meanwhile, has genuine Tier-1 credentials with deployments at Lloyds Banking Group and Standard Chartered. Its architecture is microservices-based, its event streaming runs through the Universal Product Engine, and its Smart Contracts (a proprietary Python-based language) define financial products with real precision. The trade-off: language lock-in, and a learning curve for teams new to functional financial modelling.
Mambu, hosted on AWS Marketplace and one of the founding cloud-native cores, remains the go-to for challenger and neobank builds. Its composability model shines for greenfield launches. Its Achilles heel, according to viewpoint analysis pieces, remains complex legacy migration.
Other names in the mix (Finxact, Tuum, and Pismo) round out the vendor list. McKinsey's "next-generation core banking platforms" piece is worth re-reading if you have not looked at it recently. Its "golden ticket" framing still applies, but the risk profile has changed. In 2020, choosing a cloud-native core was a bet. In 2026, choosing to stick with a mainframe is the bet.
The BaaS market grows up too
Gemba's 2026 executive guide describes Banking-as-a-Service as being in its "new era of embedded infrastructure". The estimated global BaaS market sits at $35 billion to $45 billion in 2026, with projections to $75 billion to $90 billion by 2030 to 2031, and annual growth of 16% to 18%. Softjourn's 2026 insight report calls BaaS "the practical way to launch financial products".
But "practical" is doing a lot of work in that sentence. The Financial Brand's "BaaS is Back" piece for 2026 stressed that strong sponsor banking now looks radically different from the light-touch model that dominated 2021 and 2022. The FCA's clarification (that the principal bank owns Consumer Duty outcomes across the entire embedded partner chain) is being echoed by US regulators, per Sumsub's compliance analysis, tightening expectations for KYC, transaction monitoring, and reserve management at every layer.
The bottom line
Open banking has spent nearly a decade in adolescence: real, promising, but not yet load-bearing. This summer is when it starts holding up production traffic.
PSD3 makes APIs a graded utility. cVRP gives the UK a real alternative to card and direct debit rails. FiDA extends the entire model to savings, pensions, insurance, and credit. Cloud-native cores from 10x, Thought Machine, and Mambu are ready to run the workloads. And BaaS is being professionalised, whether the middleware providers like it or not.
The banks and fintechs that treat this as a stack of separate compliance projects will find themselves paying the ones that treat it as a single strategic bet. The wiring is being rebuilt. The question, as of this week, is who is willing to plug in.
.png)