🇪🇺

European Economic Area (EEA)

Updated 7 Jul 2026Schema world-payments-v1Baseline wpm-2026-06-20

Lead Signal

The single most structurally significant development in this EEA baseline is the widening of central-bank settlement access to non-bank payment service providers. Following amendments to the Settlement Finality Directive via the Instant Payments Regulation, authorised non-bank PSPs — payment institutions and electronic money institutions — gained direct access to T2 and TIPS from 6 October 2025 under the amended TARGET Guideline ECB/2025/28, with EBA CLEARING systems access available from that date. This ends the historic exclusivity of banks over central-bank settlement rails and recasts the competitive economics of non-bank operators. The operating-environment shift here is foundational: a PI or EMI no longer needs to route settlement through a sponsor bank, removing a long-standing dependency that shaped pricing, risk and access for the entire non-bank segment. The change is best read alongside, but kept distinct from, the separate client-fund safeguarding option introduced by the IPR, which lets non-bank PSPs safeguard user funds in a central-bank account at the discretion of the relevant national central bank — the Eurosystem itself does not provide such safeguarding accounts. The two mechanisms are different levers: one concerns settlement access, the other concerns where client money may sit.

The second pillar of this cycle is the forward-loaded restructuring of the non-bank authorisation landscape. A provisional political agreement was reached on 27 November 2025 to merge the payment institution and e-money institution regimes into a single 'payment institution authorised to issue e-money', with final Official Journal publication expected in H1 2026. The impact, however, is forward-loaded: the texts are not yet in the Official Journal as of June 2026, and implementation is most likely H2 2027 to early 2028 subject to an 18- or 24-month transposition window, rather than a bare 2027 entry into force. Existing EMIs will need to plan re-authorisation as payment institutions with grandfathering, materially affecting market-access strategy for every EEA payments operator.

Outlook

The near-term horizon is dense. The MiCA national transitional regime expires on 1 July 2026, requiring grandfathered CASPs to hold full MiCA authorisation. PSD3/PSR Official Journal publication is expected in H1 2026, with implementation most likely H2 2027 to early 2028 — the precise window turning on whether the transposition period is set at 18 or 24 months. FIDA remained in trilogue in April 2026 and would extend open-banking-style access to investments, pensions, insurance and mortgages. The digital euro moved to its next phase on 30 October 2025, targeting potential first issuance during 2029 on the assumption co-legislators adopt the establishing Regulation in 2026, with a pilot possibly starting mid-2027. The Eurosystem is also considering moving T2 toward a 24/7 model. Taken together, the EEA regulatory perimeter is consolidating across licensing, settlement access, stablecoins, resilience and supervision simultaneously, against a backdrop of rising enforcement.

Confidence
Confirmed
Forward deadlines
1

Other Developments

Stablecoin supervision reached a live operational pinch-point. MiCA's stablecoin provisions applied from 30 June 2024 and CASP authorisation from 30 December 2024, with national transitional regimes running to 1 July 2026. The EMT–PSD2 interplay is the current pressure point: the EBA No-Action Letter transition period ended on 2 March 2026, and the EBA Opinion of 12 February 2026 clarified — but did not narrow — post-transition supervisory expectations and conditions for CASPs with pending PSD2 applications continuing certain EMT payment services.

Operational resilience has moved from rule-making to enforcement. DORA entered into force on 16 January 2023 and applied in full from 17 January 2025 with no transition period, harmonising ICT risk management, incident reporting, resilience testing and third-party oversight across financial entities including PIs, EMIs and CASPs. First Registers of Information were due 30 April 2025, with national regulators filing to the ESAs by end-March 2026 and non-compliance risking fines up to 10% of annual turnover; several Level 2 measures remain pending.

Consumer-fraud liability is converging on a narrower model than the UK's. Article 59 of the PSR introduces a compensation model obliging PSPs and electronic communications service providers to fully reimburse consumer victims of impersonation ('spoofing') fraud, with online platforms becoming liable if informed of fraudulent content and failing to remove it. This is materially less broad than the UK PSR's Faster-Payments APP scheme. In parallel, all PSPs offering SCT or SCT Inst were required to implement Verification of Payee by 9 October 2025, checking payee name against IBAN before transfer.

Commercial activity rebounded sharply. Marqeta acquired European EMI TransactPay in February 2025 in an issuing-infrastructure consolidation play at undisclosed value; Trade Republic completed a EUR 1.2bn secondary fundraising in December 2025 valuing the company at EUR 12.5bn; and Danish SMB payments fintech Flatpay raised roughly USD 145m. The gateway-acquirer model continues to pressure legacy processor economics across the bloc.

Cross-Monitor Connections

The W11 AML/CFT position in this monitor is carried from the Sentinel feed and is provenance, not original analysis: AMLA began operations in Frankfurt in July 2025, marking the start of direct EU-wide supervision for high-risk entities under the Single Rulebook, and the Transfer of Funds Regulation mandates that PSPs and CASPs include detailed originator and beneficiary information with each transfer. Original illicit-finance analysis, sanctions-evasion and supervisory-gap assessment belong to FIM, as does the illicit-finance use significance of MiCA stablecoin and EMT developments. The intensifying payments AML enforcement picture — over EUR 36m in fines against payments and e-money firms across roughly 30 actions, including the Bank of Lithuania's Foxpay revocation and Estonia's revocation of B2BX Digital Exchange — is framed here as conduct and enforcement, with the financial-crime substance routed to FIM.

View as
Standing baseline position per module · click a card to expand its full sub-brief

Domains

14 regulatory modules · click to expand the full sub-brief
W1a

Licensing, Authorisation & Market Access

High

The EEA non-bank authorisation architecture rests on two routes under PSD2/EMD2 — the payment institution and the e-money institution — alongside the bank-PSP route.

W12

Correspondent Banking, Settlement & Access

Confirmed

The analytical spine of this module is the bank versus non-bank settlement-access asymmetry, and that asymmetry was decisively narrowed this cycle.

W2

Stablecoins & Digital Money

High

MiCA is the governing EEA framework for stablecoins, distinguishing single-currency e-money tokens from asset-referenced tokens.

W13

Commercial Intelligence (M&A, Investment & Product)

High

This module renders discrete commercial events. In M&A, Marqeta acquired European EMI TransactPay in February 2025 — an infrastructure and issuing consolidation play; the deal value is not publicly disclosed.

W1b

Conduct, Safeguarding & Promotions

Confirmed

The conduct layer of the incoming EEA payments rulebook sits in the Payment Services Regulation, a directly-applicable Regulation carrying conduct-of-business rules — strong customer authentication, fraud liability, refunds, IBAN-name verification and open-banking API performance — that require no national transposition.

W3

Operational Resilience & Critical Infrastructure

Confirmed

DORA is the harmonised EEA operational-resilience regime.

+ 8 more domains — W4 Scheme & Network Compliance, W5 Payment Corridor Dynamics, W6 Industry Structure & Commercial, W7 Legal & Litigation, W8 Merchant Acquiring & Risk, W9 Product Innovation & Market Development, W10 Consumer Protection & APP Fraud, W11 AML/CFT & Financial Crime.
Full per-domain detail — all 14 modules

W1aHighLicensing, Authorisation & Market Access

see this theme across all jurisdictions →5 claims

EEA harmonised non-bank PSP licensing under PSD2/EMD2 (PI and EMI routes) plus bank-PSP route, home-state NCA single licence passportable EEA-wide. PSD3/PSR reached provisional political agreement 27 Nov 2025 to merge PI and EMI regimes into a unified 'payment institution authorised to issue e-money'; OJ publication expected H1 2026, implementation likely H2 2027-early 2028.

Periodic update 2026-07-07T15:44:36Z

Licensing, Authorisation & Market Access

The EEA non-bank authorisation architecture rests on two routes under PSD2/EMD2 — the payment institution and the e-money institution — alongside the bank-PSP route. The defining market-access mechanism is the single licence: a home-state national competent authority-issued PI licence is passportable EEA-wide for regulated payment services under PSD2. This passporting is what allows a single authorisation to confer pan-EEA reach without separate licences in each member state, and it remains the structural core distinguishing the non-bank PI/EMI model from bank-based access.

Member-state transposition gives the regime its operational texture. Germany's ZAG transposes PSD2/EMD2: BaFin authorises payment institutions, electronic money institutions and registers account information service providers, with capital requirements ranging from EUR 20k to EUR 350k depending on the service. This exemplifies how a single supranational framework lands as distinct national authorisation procedures, and BaFin's regime is the most-referenced exemplar of the non-bank PI/EMI authorisation path in practice.

The dominant forward development is the PSD3/PSR reform. A provisional political agreement was reached on 27 November 2025 to merge the PI and EMI regimes into a single 'payment institution authorised to issue e-money', with final Official Journal publication expected in H1 2026 and implementation likely H2 2027 to early 2028 subject to an 18- or 24-month transposition window. The earlier framing of a bare 2027 entry into force overstated both finality and timeline: the texts are not yet in the Official Journal as of June 2026. The practical consequence for the non-bank segment is significant — the merger restructures the entire authorisation landscape, and existing EMIs must plan re-authorisation as payment institutions with grandfathering, materially affecting market-access strategy for every EEA operator. The bank-PSP versus non-bank-PI/EMI distinction runs through this module: the reform targets the non-bank perimeter specifically, consolidating two non-bank tracks into one while leaving the bank route as a separate basis for offering payment services.

Outlook

The near-term turn is Official Journal publication in H1 2026, after which the transposition clock starts. The unresolved variable is the transposition-period length — 18 versus 24 months — which is what drives the implementation window between H2 2027 and early 2028 and cannot be fixed until the final text is published. Operators should treat the period to publication as a planning window for re-authorisation and grandfathering, rather than a settled compliance deadline.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Licensing, Authorisation & Market Access

The EEA non-bank authorisation architecture rests on two routes under PSD2/EMD2 — the payment institution and the e-money institution — alongside the bank-PSP route. The defining market-access mechanism is the single licence: a home-state national competent authority-issued PI licence is passportable EEA-wide for regulated payment services under PSD2. This passporting is what allows a single authorisation to confer pan-EEA reach without separate licences in each member state, and it remains the structural core distinguishing the non-bank PI/EMI model from bank-based access.

Member-state transposition gives the regime its operational texture. Germany's ZAG transposes PSD2/EMD2: BaFin authorises payment institutions, electronic money institutions and registers account information service providers, with capital requirements ranging from EUR 20k to EUR 350k depending on the service. This exemplifies how a single supranational framework lands as distinct national authorisation procedures, and BaFin's regime is the most-referenced exemplar of the non-bank PI/EMI authorisation path in practice.

The dominant forward development is the PSD3/PSR reform. A provisional political agreement was reached on 27 November 2025 to merge the PI and EMI regimes into a single 'payment institution authorised to issue e-money', with final Official Journal publication expected in H1 2026 and implementation likely H2 2027 to early 2028 subject to an 18- or 24-month transposition window. The earlier framing of a bare 2027 entry into force overstated both finality and timeline: the texts are not yet in the Official Journal as of June 2026. The practical consequence for the non-bank segment is significant — the merger restructures the entire authorisation landscape, and existing EMIs must plan re-authorisation as payment institutions with grandfathering, materially affecting market-access strategy for every EEA operator. The bank-PSP versus non-bank-PI/EMI distinction runs through this module: the reform targets the non-bank perimeter specifically, consolidating two non-bank tracks into one while leaving the bank route as a separate basis for offering payment services.

Outlook

The near-term turn is Official Journal publication in H1 2026, after which the transposition clock starts. The unresolved variable is the transposition-period length — 18 versus 24 months — which is what drives the implementation window between H2 2027 and early 2028 and cannot be fixed until the final text is published. Operators should treat the period to publication as a planning window for re-authorisation and grandfathering, rather than a settled compliance deadline.

Read the full sub-brief

Licensing, Authorisation & Market Access

The EEA non-bank authorisation architecture rests on two routes under PSD2/EMD2 — the payment institution and the e-money institution — alongside the bank-PSP route. The defining market-access mechanism is the single licence: a home-state national competent authority-issued PI licence is passportable EEA-wide for regulated payment services under PSD2. This passporting is what allows a single authorisation to confer pan-EEA reach without separate licences in each member state, and it remains the structural core distinguishing the non-bank PI/EMI model from bank-based access.

Member-state transposition gives the regime its operational texture. Germany's ZAG transposes PSD2/EMD2: BaFin authorises payment institutions, electronic money institutions and registers account information service providers, with capital requirements ranging from EUR 20k to EUR 350k depending on the service. This exemplifies how a single supranational framework lands as distinct national authorisation procedures, and BaFin's regime is the most-referenced exemplar of the non-bank PI/EMI authorisation path in practice.

The dominant forward development is the PSD3/PSR reform. A provisional political agreement was reached on 27 November 2025 to merge the PI and EMI regimes into a single 'payment institution authorised to issue e-money', with final Official Journal publication expected in H1 2026 and implementation likely H2 2027 to early 2028 subject to an 18- or 24-month transposition window. The earlier framing of a bare 2027 entry into force overstated both finality and timeline: the texts are not yet in the Official Journal as of June 2026. The practical consequence for the non-bank segment is significant — the merger restructures the entire authorisation landscape, and existing EMIs must plan re-authorisation as payment institutions with grandfathering, materially affecting market-access strategy for every EEA operator. The bank-PSP versus non-bank-PI/EMI distinction runs through this module: the reform targets the non-bank perimeter specifically, consolidating two non-bank tracks into one while leaving the bank route as a separate basis for offering payment services.

Outlook

The near-term turn is Official Journal publication in H1 2026, after which the transposition clock starts. The unresolved variable is the transposition-period length — 18 versus 24 months — which is what drives the implementation window between H2 2027 and early 2028 and cannot be fixed until the final text is published. Operators should treat the period to publication as a planning window for re-authorisation and grandfathering, rather than a settled compliance deadline.

W1aLicensing, Authorisation & Market AccessHigh
EEA harmonised non-bank PSP licensing under PSD2/EMD2 (PI and EMI routes) plus bank-PSP route, home-state NCA single licence passportable EEA-wide. PSD3/PSR reached provisional political agreement 27 Nov 2025 to merge PI and EMI regimes into a unified 'payment institution authorised to issue e-money'; OJ publication expected H1 2026, implementation likely H2 2027-early 2028.
all · compliance · analyst · board
Evidence 5 claims ›

W12ConfirmedCorrespondent Banking, Settlement & Access

see this theme across all jurisdictions →4 claims

EEA settlement runs through TARGET Services (T2/TIPS/T2S/ECMS). Following SFD amendments via the IPR, authorised non-bank PSPs (PIs/EMIs) gained direct T2/TIPS access from 6 Oct 2025 under Guideline ECB/2025/28. EBA CLEARING (RT1/STEP2) provides private SEPA clearing; correspondent-banking retrenchment remains a structural pressure.

Periodic update 2026-07-07T15:44:36Z

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank versus non-bank settlement-access asymmetry, and that asymmetry was decisively narrowed this cycle. Following amendments to the Settlement Finality Directive via the Instant Payments Regulation, authorised non-bank PSPs — payment institutions and electronic money institutions — gained direct access to T2 and TIPS from 6 October 2025 under the amended TARGET Guideline ECB/2025/28, a structural widening of central-bank settlement access previously exclusive to banks, with EBA CLEARING systems access available from that date. This ends a defining structural privilege of banks over non-banks and recasts the competitive economics of the non-bank segment, which no longer must depend on a sponsor bank for settlement. It is kept distinct from the client-fund safeguarding option in W1b: settlement access concerns the rails, safeguarding concerns where client money sits.

The underlying infrastructure is TARGET Services, comprising T2 for large-value, T2S for securities, TIPS for instant and ECMS for collateral, forming the backbone of Europe's financial market infrastructure. The Eurosystem is considering moving T2 toward a 24/7 model. Correspondent-banking retrenchment, driven by compliance, geopolitical and operating costs, remains a structural cross-border pressure — the legacy asymmetry against which the non-bank access widening should be read.

Outlook

The trajectory is escalating. The non-bank T2/TIPS access change is the single most structurally significant EEA development of this baseline, and its competitive consequences will play out as PIs and EMIs operationalise direct access. The forward item is the T2 24/7 operating-hours consultation outcome, expected during 2026.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank versus non-bank settlement-access asymmetry, and that asymmetry was decisively narrowed this cycle. Following amendments to the Settlement Finality Directive via the Instant Payments Regulation, authorised non-bank PSPs — payment institutions and electronic money institutions — gained direct access to T2 and TIPS from 6 October 2025 under the amended TARGET Guideline ECB/2025/28, a structural widening of central-bank settlement access previously exclusive to banks, with EBA CLEARING systems access available from that date. This ends a defining structural privilege of banks over non-banks and recasts the competitive economics of the non-bank segment, which no longer must depend on a sponsor bank for settlement. It is kept distinct from the client-fund safeguarding option in W1b: settlement access concerns the rails, safeguarding concerns where client money sits.

The underlying infrastructure is TARGET Services, comprising T2 for large-value, T2S for securities, TIPS for instant and ECMS for collateral, forming the backbone of Europe's financial market infrastructure. The Eurosystem is considering moving T2 toward a 24/7 model. Correspondent-banking retrenchment, driven by compliance, geopolitical and operating costs, remains a structural cross-border pressure — the legacy asymmetry against which the non-bank access widening should be read.

Outlook

The trajectory is escalating. The non-bank T2/TIPS access change is the single most structurally significant EEA development of this baseline, and its competitive consequences will play out as PIs and EMIs operationalise direct access. The forward item is the T2 24/7 operating-hours consultation outcome, expected during 2026.

Read the full sub-brief

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank versus non-bank settlement-access asymmetry, and that asymmetry was decisively narrowed this cycle. Following amendments to the Settlement Finality Directive via the Instant Payments Regulation, authorised non-bank PSPs — payment institutions and electronic money institutions — gained direct access to T2 and TIPS from 6 October 2025 under the amended TARGET Guideline ECB/2025/28, a structural widening of central-bank settlement access previously exclusive to banks, with EBA CLEARING systems access available from that date. This ends a defining structural privilege of banks over non-banks and recasts the competitive economics of the non-bank segment, which no longer must depend on a sponsor bank for settlement. It is kept distinct from the client-fund safeguarding option in W1b: settlement access concerns the rails, safeguarding concerns where client money sits.

The underlying infrastructure is TARGET Services, comprising T2 for large-value, T2S for securities, TIPS for instant and ECMS for collateral, forming the backbone of Europe's financial market infrastructure. The Eurosystem is considering moving T2 toward a 24/7 model. Correspondent-banking retrenchment, driven by compliance, geopolitical and operating costs, remains a structural cross-border pressure — the legacy asymmetry against which the non-bank access widening should be read.

Outlook

The trajectory is escalating. The non-bank T2/TIPS access change is the single most structurally significant EEA development of this baseline, and its competitive consequences will play out as PIs and EMIs operationalise direct access. The forward item is the T2 24/7 operating-hours consultation outcome, expected during 2026.

W12Correspondent Banking, Settlement & AccessConfirmed
EEA settlement runs through TARGET Services (T2/TIPS/T2S/ECMS). Following SFD amendments via the IPR, authorised non-bank PSPs (PIs/EMIs) gained direct T2/TIPS access from 6 Oct 2025 under Guideline ECB/2025/28. EBA CLEARING (RT1/STEP2) provides private SEPA clearing; correspondent-banking retrenchment remains a structural pressure.
all · compliance · analyst · board
Evidence 4 claims ›

W2HighStablecoins & Digital Money

see this theme across all jurisdictions →5 claims

MiCA governs EEA stablecoins (EMT single-currency / ART basket). Transitional regimes run to 1 July 2026. EBA No-Action Letter transition ends 2 March 2026; the Opinion of 12 Feb 2026 clarifies (does not narrow) post-transition supervisory expectations for CASPs with pending PSD2 applications. Significant tokens supervised EBA-coordinated.

Periodic update 2026-07-07T15:44:36Z

Stablecoins & Digital Money

MiCA is the governing EEA framework for stablecoins, distinguishing single-currency e-money tokens from asset-referenced tokens. Its stablecoin provisions applied from 30 June 2024 and CASP authorisation from 30 December 2024, with national transitional regimes running to 1 July 2026. The authorisation logic differs by token type: EMT issuance requires an EMI or credit-institution licence plus white-paper notification, while an ART requires fresh NCA authorisation. This split, corroborated by Tier-1 ESMA and EBA sources, is the structural spine of the module.

Supervision escalates for systemically important tokens. The EBA leads prudential expectations — reserves, liquidity, recovery and wind-down — for significant ART/EMT issuers, with significant tokens triggering direct EBA-coordinated oversight alongside NCAs and ESMA. This is the supranational direct-supervision lever, and it applies to both bank and non-bank issuers.

The live operational pinch-point is the EMT–PSD2 interplay. The EBA No-Action Letter set a transition period ending 2 March 2026 for CASPs to continue certain EMT activities without full PSD2 authorisation. The EBA Opinion of 12 February 2026 clarified supervisory expectations and conditions for continued EMT payment services by CASPs with pending PSD2 applications after the transition ends. Importantly, the Opinion clarified — it did not reduce — the dual-authorisation scope set by the No-Action Letter; an earlier reading that the Opinion narrowed scope was corrected. For issuers, the consequence is that EMT payment activity now requires the full PSD2 authorisation path, with the Opinion governing how pending applicants are treated in the interim.

At the issuer level, Banking Circle SA's EURI is a CSSF-supervised euro EMT, illustrating member-state-distributed MiCA EMT authorisation, with Germany and the Netherlands leading home-state approvals. This single-issuer dashboard item shows the geographic distribution of euro-EMT authorisation across NCAs rather than a single centralised gate.

Outlook

Two dates anchor the horizon: the EBA No-Action Letter transition period ended 2 March 2026, and the MiCA national transitional regime expires on 1 July 2026, after which grandfathered CASPs must hold full MiCA authorisation. The illicit-finance use significance of stablecoin and EMT developments routes to FIM; WPM retains the trust-as-payment-instrument framing. Confidence on the forward EMT-interplay position is held at High given reliance on vendor and law-firm material against limited primary-regulatory anchoring.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Stablecoins & Digital Money

MiCA is the governing EEA framework for stablecoins, distinguishing single-currency e-money tokens from asset-referenced tokens. Its stablecoin provisions applied from 30 June 2024 and CASP authorisation from 30 December 2024, with national transitional regimes running to 1 July 2026. The authorisation logic differs by token type: EMT issuance requires an EMI or credit-institution licence plus white-paper notification, while an ART requires fresh NCA authorisation. This split, corroborated by Tier-1 ESMA and EBA sources, is the structural spine of the module.

Supervision escalates for systemically important tokens. The EBA leads prudential expectations — reserves, liquidity, recovery and wind-down — for significant ART/EMT issuers, with significant tokens triggering direct EBA-coordinated oversight alongside NCAs and ESMA. This is the supranational direct-supervision lever, and it applies to both bank and non-bank issuers.

The live operational pinch-point is the EMT–PSD2 interplay. The EBA No-Action Letter set a transition period ending 2 March 2026 for CASPs to continue certain EMT activities without full PSD2 authorisation. The EBA Opinion of 12 February 2026 clarified supervisory expectations and conditions for continued EMT payment services by CASPs with pending PSD2 applications after the transition ends. Importantly, the Opinion clarified — it did not reduce — the dual-authorisation scope set by the No-Action Letter; an earlier reading that the Opinion narrowed scope was corrected. For issuers, the consequence is that EMT payment activity now requires the full PSD2 authorisation path, with the Opinion governing how pending applicants are treated in the interim.

At the issuer level, Banking Circle SA's EURI is a CSSF-supervised euro EMT, illustrating member-state-distributed MiCA EMT authorisation, with Germany and the Netherlands leading home-state approvals. This single-issuer dashboard item shows the geographic distribution of euro-EMT authorisation across NCAs rather than a single centralised gate.

Outlook

Two dates anchor the horizon: the EBA No-Action Letter transition period ended 2 March 2026, and the MiCA national transitional regime expires on 1 July 2026, after which grandfathered CASPs must hold full MiCA authorisation. The illicit-finance use significance of stablecoin and EMT developments routes to FIM; WPM retains the trust-as-payment-instrument framing. Confidence on the forward EMT-interplay position is held at High given reliance on vendor and law-firm material against limited primary-regulatory anchoring.

Read the full sub-brief

Stablecoins & Digital Money

MiCA is the governing EEA framework for stablecoins, distinguishing single-currency e-money tokens from asset-referenced tokens. Its stablecoin provisions applied from 30 June 2024 and CASP authorisation from 30 December 2024, with national transitional regimes running to 1 July 2026. The authorisation logic differs by token type: EMT issuance requires an EMI or credit-institution licence plus white-paper notification, while an ART requires fresh NCA authorisation. This split, corroborated by Tier-1 ESMA and EBA sources, is the structural spine of the module.

Supervision escalates for systemically important tokens. The EBA leads prudential expectations — reserves, liquidity, recovery and wind-down — for significant ART/EMT issuers, with significant tokens triggering direct EBA-coordinated oversight alongside NCAs and ESMA. This is the supranational direct-supervision lever, and it applies to both bank and non-bank issuers.

The live operational pinch-point is the EMT–PSD2 interplay. The EBA No-Action Letter set a transition period ending 2 March 2026 for CASPs to continue certain EMT activities without full PSD2 authorisation. The EBA Opinion of 12 February 2026 clarified supervisory expectations and conditions for continued EMT payment services by CASPs with pending PSD2 applications after the transition ends. Importantly, the Opinion clarified — it did not reduce — the dual-authorisation scope set by the No-Action Letter; an earlier reading that the Opinion narrowed scope was corrected. For issuers, the consequence is that EMT payment activity now requires the full PSD2 authorisation path, with the Opinion governing how pending applicants are treated in the interim.

At the issuer level, Banking Circle SA's EURI is a CSSF-supervised euro EMT, illustrating member-state-distributed MiCA EMT authorisation, with Germany and the Netherlands leading home-state approvals. This single-issuer dashboard item shows the geographic distribution of euro-EMT authorisation across NCAs rather than a single centralised gate.

Outlook

Two dates anchor the horizon: the EBA No-Action Letter transition period ended 2 March 2026, and the MiCA national transitional regime expires on 1 July 2026, after which grandfathered CASPs must hold full MiCA authorisation. The illicit-finance use significance of stablecoin and EMT developments routes to FIM; WPM retains the trust-as-payment-instrument framing. Confidence on the forward EMT-interplay position is held at High given reliance on vendor and law-firm material against limited primary-regulatory anchoring.

W2Stablecoins & Digital MoneyHigh
MiCA governs EEA stablecoins (EMT single-currency / ART basket). Transitional regimes run to 1 July 2026. EBA No-Action Letter transition ends 2 March 2026; the Opinion of 12 Feb 2026 clarifies (does not narrow) post-transition supervisory expectations for CASPs with pending PSD2 applications. Significant tokens supervised EBA-coordinated.
all · compliance · analyst · board
Evidence 5 claims ›

W13HighCommercial Intelligence (M&A, Investment & Product)

see this theme across all jurisdictions →4 claims

European payments commercial activity rebounded 2025: $100m+ deal value $3.9bn H1 2025 (near double FY2024). Notable: Marqeta/TransactPay (EU EMI), Trade Republic EUR 1.2bn secondary at EUR 12.5bn, Flatpay $145m.

Periodic update 2026-07-07T15:44:36Z

Commercial Intelligence (M&A, Investment & Product)

This module renders discrete commercial events. In M&A, Marqeta acquired European EMI TransactPay in February 2025 — an infrastructure and issuing consolidation play; the deal value is not publicly disclosed. The commercial logic is that acquiring an EU EMI secures Marqeta a passportable European issuing licence, accelerating its EEA market entry without a fresh authorisation, a non-bank PI/EMI play.

In investment, Trade Republic completed a EUR 1.2bn secondary fundraising in December 2025, valuing the company at EUR 12.5bn — a growth-stage round that marks the firm as one of Europe's most valuable neobrokers and reflects capital concentration in profitable consumer fintech. Separately, Danish SMB payments and POS fintech Flatpay raised roughly USD 145m in a Series B, funding expansion of low-cost SMB acquiring against legacy incumbents in Germany and the Benelux and reflecting capital concentration in profitable acquiring-adjacent fintechs. Both are non-bank PI/EMI-segment events.

These discrete events are kept distinct from W6 structural market analysis and W9 thematic product-access regulation: a specific announced deal or product launch belongs here, while a structural M&A trend or regulatory product-access theme does not.

Outlook

The trajectory is escalating. Issuing-infrastructure consolidation (Marqeta/TransactPay) and capital concentration in profitable consumer fintech and SMB acquiring (Trade Republic, Flatpay) are the dominant patterns, with the gateway-acquirer model structurally pressuring legacy processor economics. The TransactPay deal value remains not publicly disclosed.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Commercial Intelligence (M&A, Investment & Product)

This module renders discrete commercial events. In M&A, Marqeta acquired European EMI TransactPay in February 2025 — an infrastructure and issuing consolidation play; the deal value is not publicly disclosed. The commercial logic is that acquiring an EU EMI secures Marqeta a passportable European issuing licence, accelerating its EEA market entry without a fresh authorisation, a non-bank PI/EMI play.

In investment, Trade Republic completed a EUR 1.2bn secondary fundraising in December 2025, valuing the company at EUR 12.5bn — a growth-stage round that marks the firm as one of Europe's most valuable neobrokers and reflects capital concentration in profitable consumer fintech. Separately, Danish SMB payments and POS fintech Flatpay raised roughly USD 145m in a Series B, funding expansion of low-cost SMB acquiring against legacy incumbents in Germany and the Benelux and reflecting capital concentration in profitable acquiring-adjacent fintechs. Both are non-bank PI/EMI-segment events.

These discrete events are kept distinct from W6 structural market analysis and W9 thematic product-access regulation: a specific announced deal or product launch belongs here, while a structural M&A trend or regulatory product-access theme does not.

Outlook

The trajectory is escalating. Issuing-infrastructure consolidation (Marqeta/TransactPay) and capital concentration in profitable consumer fintech and SMB acquiring (Trade Republic, Flatpay) are the dominant patterns, with the gateway-acquirer model structurally pressuring legacy processor economics. The TransactPay deal value remains not publicly disclosed.

Read the full sub-brief

Commercial Intelligence (M&A, Investment & Product)

This module renders discrete commercial events. In M&A, Marqeta acquired European EMI TransactPay in February 2025 — an infrastructure and issuing consolidation play; the deal value is not publicly disclosed. The commercial logic is that acquiring an EU EMI secures Marqeta a passportable European issuing licence, accelerating its EEA market entry without a fresh authorisation, a non-bank PI/EMI play.

In investment, Trade Republic completed a EUR 1.2bn secondary fundraising in December 2025, valuing the company at EUR 12.5bn — a growth-stage round that marks the firm as one of Europe's most valuable neobrokers and reflects capital concentration in profitable consumer fintech. Separately, Danish SMB payments and POS fintech Flatpay raised roughly USD 145m in a Series B, funding expansion of low-cost SMB acquiring against legacy incumbents in Germany and the Benelux and reflecting capital concentration in profitable acquiring-adjacent fintechs. Both are non-bank PI/EMI-segment events.

These discrete events are kept distinct from W6 structural market analysis and W9 thematic product-access regulation: a specific announced deal or product launch belongs here, while a structural M&A trend or regulatory product-access theme does not.

Outlook

The trajectory is escalating. Issuing-infrastructure consolidation (Marqeta/TransactPay) and capital concentration in profitable consumer fintech and SMB acquiring (Trade Republic, Flatpay) are the dominant patterns, with the gateway-acquirer model structurally pressuring legacy processor economics. The TransactPay deal value remains not publicly disclosed.

W13Commercial Intelligence (M&A, Investment & Product)High
European payments commercial activity rebounded 2025: $100m+ deal value $3.9bn H1 2025 (near double FY2024). Notable: Marqeta/TransactPay (EU EMI), Trade Republic EUR 1.2bn secondary at EUR 12.5bn, Flatpay $145m.
all · compliance · analyst · board
Evidence 4 claims ›

W1bConfirmedConduct, Safeguarding & Promotions

see this theme across all jurisdictions →4 claims

Conduct, safeguarding and consumer-facing rules across the EEA derive from PSD2's conduct provisions (transposed nationally) and will shift to the directly-applicable Payment Services Regulation (PSR) once adopted. Safeguarding of user funds is achieved by segregation in a separate account or insurance/guarantee cover; the IPR additionally created an option for non-bank PSPs to safeguard funds at a central bank, at NCB discretion. The November 2025 PSR political agreement materially expands conduct obligations — strong customer authentication, fraud liability, refund rights and mandatory IBAN/name verification.

Periodic update 2026-07-07T15:44:36Z

Conduct, Safeguarding & Promotions

The conduct layer of the incoming EEA payments rulebook sits in the Payment Services Regulation, a directly-applicable Regulation carrying conduct-of-business rules — strong customer authentication, fraud liability, refunds, IBAN-name verification and open-banking API performance — that require no national transposition. Direct applicability is the analytically important feature: it removes the national-transposition divergence that has historically fragmented conduct rules across member states, applying to both bank and non-bank PSPs alike. The PSR carries forward safeguarding through segregation or insurance/guarantee cover for user funds, continuing the PSD2 conduct provisions. This conduct framework is, however, subject to the same PSD3/PSR timeline uncertainty: the texts are not yet in the Official Journal, so the conduct rules are a near-future, not present, state.

The live safeguarding development concerns where non-bank client money may be held. The Instant Payments Regulation amended PSD2 to introduce an option for non-bank PSPs to safeguard user funds in a central-bank account, exercisable at the discretion of the relevant national central bank; the Eurosystem itself does not provide such safeguarding accounts. This is a discretionary, NCB-level mechanism and must be kept distinct from the October 2025 TARGET settlement-access change covered in W12 — safeguarding concerns the location of client funds, settlement access concerns the rails through which payments clear. The distinction is a non-bank-PI/EMI-specific one and matters because conflating the two overstates what the Eurosystem has committed to provide.

On the evidence that the existing conduct regime works, the EBA/ECB joint 2025 report confirms that strong customer authentication, mandated under PSD2 since 2020, remains effective in reducing fraud, particularly for card payments. This Tier-1 joint supervisory finding supports the continuation of the SCA mandate into the incoming PSR and applies across both bank and non-bank PSPs.

Outlook

The conduct trajectory is escalating but timeline-bound. SCA effectiveness is settled supervisory evidence; the open variables are the PSR's entry into force, which tracks the PSD3/PSR Official Journal publication, and the extent to which national central banks actually exercise the discretionary central-bank safeguarding option. The distinction between safeguarding accounts and settlement access is not fully resolved in the underlying evidence — the definitive position that the Eurosystem will not provide safeguarding accounts rests on a pre-October-2025 source — and warrants monitoring as practice develops.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Conduct, Safeguarding & Promotions

The conduct layer of the incoming EEA payments rulebook sits in the Payment Services Regulation, a directly-applicable Regulation carrying conduct-of-business rules — strong customer authentication, fraud liability, refunds, IBAN-name verification and open-banking API performance — that require no national transposition. Direct applicability is the analytically important feature: it removes the national-transposition divergence that has historically fragmented conduct rules across member states, applying to both bank and non-bank PSPs alike. The PSR carries forward safeguarding through segregation or insurance/guarantee cover for user funds, continuing the PSD2 conduct provisions. This conduct framework is, however, subject to the same PSD3/PSR timeline uncertainty: the texts are not yet in the Official Journal, so the conduct rules are a near-future, not present, state.

The live safeguarding development concerns where non-bank client money may be held. The Instant Payments Regulation amended PSD2 to introduce an option for non-bank PSPs to safeguard user funds in a central-bank account, exercisable at the discretion of the relevant national central bank; the Eurosystem itself does not provide such safeguarding accounts. This is a discretionary, NCB-level mechanism and must be kept distinct from the October 2025 TARGET settlement-access change covered in W12 — safeguarding concerns the location of client funds, settlement access concerns the rails through which payments clear. The distinction is a non-bank-PI/EMI-specific one and matters because conflating the two overstates what the Eurosystem has committed to provide.

On the evidence that the existing conduct regime works, the EBA/ECB joint 2025 report confirms that strong customer authentication, mandated under PSD2 since 2020, remains effective in reducing fraud, particularly for card payments. This Tier-1 joint supervisory finding supports the continuation of the SCA mandate into the incoming PSR and applies across both bank and non-bank PSPs.

Outlook

The conduct trajectory is escalating but timeline-bound. SCA effectiveness is settled supervisory evidence; the open variables are the PSR's entry into force, which tracks the PSD3/PSR Official Journal publication, and the extent to which national central banks actually exercise the discretionary central-bank safeguarding option. The distinction between safeguarding accounts and settlement access is not fully resolved in the underlying evidence — the definitive position that the Eurosystem will not provide safeguarding accounts rests on a pre-October-2025 source — and warrants monitoring as practice develops.

Read the full sub-brief

Conduct, Safeguarding & Promotions

The conduct layer of the incoming EEA payments rulebook sits in the Payment Services Regulation, a directly-applicable Regulation carrying conduct-of-business rules — strong customer authentication, fraud liability, refunds, IBAN-name verification and open-banking API performance — that require no national transposition. Direct applicability is the analytically important feature: it removes the national-transposition divergence that has historically fragmented conduct rules across member states, applying to both bank and non-bank PSPs alike. The PSR carries forward safeguarding through segregation or insurance/guarantee cover for user funds, continuing the PSD2 conduct provisions. This conduct framework is, however, subject to the same PSD3/PSR timeline uncertainty: the texts are not yet in the Official Journal, so the conduct rules are a near-future, not present, state.

The live safeguarding development concerns where non-bank client money may be held. The Instant Payments Regulation amended PSD2 to introduce an option for non-bank PSPs to safeguard user funds in a central-bank account, exercisable at the discretion of the relevant national central bank; the Eurosystem itself does not provide such safeguarding accounts. This is a discretionary, NCB-level mechanism and must be kept distinct from the October 2025 TARGET settlement-access change covered in W12 — safeguarding concerns the location of client funds, settlement access concerns the rails through which payments clear. The distinction is a non-bank-PI/EMI-specific one and matters because conflating the two overstates what the Eurosystem has committed to provide.

On the evidence that the existing conduct regime works, the EBA/ECB joint 2025 report confirms that strong customer authentication, mandated under PSD2 since 2020, remains effective in reducing fraud, particularly for card payments. This Tier-1 joint supervisory finding supports the continuation of the SCA mandate into the incoming PSR and applies across both bank and non-bank PSPs.

Outlook

The conduct trajectory is escalating but timeline-bound. SCA effectiveness is settled supervisory evidence; the open variables are the PSR's entry into force, which tracks the PSD3/PSR Official Journal publication, and the extent to which national central banks actually exercise the discretionary central-bank safeguarding option. The distinction between safeguarding accounts and settlement access is not fully resolved in the underlying evidence — the definitive position that the Eurosystem will not provide safeguarding accounts rests on a pre-October-2025 source — and warrants monitoring as practice develops.

W1bConduct, Safeguarding & PromotionsConfirmed
Conduct, safeguarding and consumer-facing rules across the EEA derive from PSD2's conduct provisions (transposed nationally) and will shift to the directly-applicable Payment Services Regulation (PSR) once adopted. Safeguarding of user funds is achieved by segregation in a separate account or insurance/guarantee cover; the IPR additionally created an option for non-bank PSPs to safeguard funds at a central bank, at NCB discretion. The November 2025 PSR political agreement materially expands conduct obligations — strong customer authentication, fraud liability, refund rights and mandatory IBAN/name verification.
all · compliance · analyst · board
Evidence 4 claims ›

W3ConfirmedOperational Resilience & Critical Infrastructure

see this theme across all jurisdictions →4 claims

The EEA operational-resilience regime for payments is the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which entered into force 16 January 2023 and applied in full from 17 January 2025 with no transition period. DORA covers ICT risk management, incident reporting, resilience testing and ICT third-party/critical-third-party oversight, and applies to PIs, EMIs and CASPs among ~21 financial-entity types. The ESAs oversee critical ICT third-party providers (CTPPs); first Registers of Information were collected in 2025-2026.

Periodic update 2026-07-07T15:44:36Z

Operational Resilience & Critical Infrastructure

DORA is the harmonised EEA operational-resilience regime. It entered into force on 16 January 2023 and applied in full from 17 January 2025 with no transition period, harmonising ICT risk management, incident reporting, resilience testing and ICT third-party oversight across financial entities — including payment institutions, electronic money institutions and CASPs. The absence of any transition period is the defining feature: obligations were live in full from day one of application, applying equally to bank and non-bank entities. One scope detail remains unsettled — the count of financial-entity types is disputed across Tier-1 sources, with ESMA stating 21 and EIOPA and secondary sources stating 20. The application dates are Confirmed-grade; the entity-type count is recorded as a gap pending reconciliation.

The oversight architecture for third parties is now the operational frontier. The ESAs with competent authorities oversee critical ICT third-party service providers. First Registers of Information were due 30 April 2025, with national regulators filing to the ESAs by end-March 2026, and non-compliance risks fines of up to 10% of annual turnover. Several Level 2 measures remain pending, which means the framework is still maturing even as enforcement intensifies through 2026.

Outlook

The trajectory is established rather than escalating: the regime is in full force, and the live questions are enforcement intensity and the finalisation of pending Level 2 measures. The end-March 2026 Register of Information filings to the ESAs are the next concrete milestone, with the disputed entity-type count flagged for reconciliation.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Operational Resilience & Critical Infrastructure

DORA is the harmonised EEA operational-resilience regime. It entered into force on 16 January 2023 and applied in full from 17 January 2025 with no transition period, harmonising ICT risk management, incident reporting, resilience testing and ICT third-party oversight across financial entities — including payment institutions, electronic money institutions and CASPs. The absence of any transition period is the defining feature: obligations were live in full from day one of application, applying equally to bank and non-bank entities. One scope detail remains unsettled — the count of financial-entity types is disputed across Tier-1 sources, with ESMA stating 21 and EIOPA and secondary sources stating 20. The application dates are Confirmed-grade; the entity-type count is recorded as a gap pending reconciliation.

The oversight architecture for third parties is now the operational frontier. The ESAs with competent authorities oversee critical ICT third-party service providers. First Registers of Information were due 30 April 2025, with national regulators filing to the ESAs by end-March 2026, and non-compliance risks fines of up to 10% of annual turnover. Several Level 2 measures remain pending, which means the framework is still maturing even as enforcement intensifies through 2026.

Outlook

The trajectory is established rather than escalating: the regime is in full force, and the live questions are enforcement intensity and the finalisation of pending Level 2 measures. The end-March 2026 Register of Information filings to the ESAs are the next concrete milestone, with the disputed entity-type count flagged for reconciliation.

Read the full sub-brief

Operational Resilience & Critical Infrastructure

DORA is the harmonised EEA operational-resilience regime. It entered into force on 16 January 2023 and applied in full from 17 January 2025 with no transition period, harmonising ICT risk management, incident reporting, resilience testing and ICT third-party oversight across financial entities — including payment institutions, electronic money institutions and CASPs. The absence of any transition period is the defining feature: obligations were live in full from day one of application, applying equally to bank and non-bank entities. One scope detail remains unsettled — the count of financial-entity types is disputed across Tier-1 sources, with ESMA stating 21 and EIOPA and secondary sources stating 20. The application dates are Confirmed-grade; the entity-type count is recorded as a gap pending reconciliation.

The oversight architecture for third parties is now the operational frontier. The ESAs with competent authorities oversee critical ICT third-party service providers. First Registers of Information were due 30 April 2025, with national regulators filing to the ESAs by end-March 2026, and non-compliance risks fines of up to 10% of annual turnover. Several Level 2 measures remain pending, which means the framework is still maturing even as enforcement intensifies through 2026.

Outlook

The trajectory is established rather than escalating: the regime is in full force, and the live questions are enforcement intensity and the finalisation of pending Level 2 measures. The end-March 2026 Register of Information filings to the ESAs are the next concrete milestone, with the disputed entity-type count flagged for reconciliation.

W3Operational Resilience & Critical InfrastructureConfirmed
The EEA operational-resilience regime for payments is the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which entered into force 16 January 2023 and applied in full from 17 January 2025 with no transition period. DORA covers ICT risk management, incident reporting, resilience testing and ICT third-party/critical-third-party oversight, and applies to PIs, EMIs and CASPs among ~21 financial-entity types. The ESAs oversee critical ICT third-party providers (CTPPs); first Registers of Information were collected in 2025-2026.
all · compliance · analyst · board
Evidence 4 claims ›

W4ConfirmedScheme & Network Compliance

see this theme across all jurisdictions →4 claims

EEA card-scheme economics are governed by the Interchange Fee Regulation ((EU) 2015/751), capping consumer debit/credit interchange (0.2%/0.3%) while excluding commercial cards. PCI DSS (administered by the PCI SSC) is contractually mandated by Visa/Mastercard for all merchants, with v4.0 future-dated requirements taking effect from 31 March 2025. Surcharging of regulated cards is restricted under PSD2. Visa and Mastercard dominate the four-party scheme layer, with combined European volume growing strongly in 2025.

Periodic update 2026-07-07T15:44:36Z

Scheme & Network Compliance

Scheme and network compliance is anchored by the Interchange Fee Regulation, which caps regulated consumer card interchange at 0.2% for debit and 0.3% for credit, and addresses steering, surcharging, co-badging, domestic debit and cross-border acquiring across the single market. The analytically material carve-out is that commercial and corporate cards are excluded and can carry interchange of 1.5% or more — a distinction that materially raises acquiring costs for commercial-card acceptance and shapes merchant economics across the bloc. The IFR applies to both bank and non-bank participants in the card value chain.

The scheme-mandated security layer is PCI DSS, which is contractually required by Visa and Mastercard for all merchants. PCI DSS 4.0's future-dated requirements took effect from 31 March 2025, moving previously optional controls into mandatory status and raising the compliance baseline for merchants and their acquirers.

On competitive dynamics, combined Visa and Mastercard European payment volume rose 18% in Q2 2025 (12% in euro terms), with Mastercard marginally exceeding Visa in processed European volume for the first time. This Tier-2 public-data signal marks a notable shift in the relative competitive position of the two networks within Europe.

Outlook

The module is stable. The IFR caps and the now-live PCI DSS 4.0 requirements are settled standing positions; the watch item is the evolving Visa–Mastercard competitive balance in European processed volume, where Mastercard's marginal lead is a position to monitor rather than a structural break.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Scheme & Network Compliance

Scheme and network compliance is anchored by the Interchange Fee Regulation, which caps regulated consumer card interchange at 0.2% for debit and 0.3% for credit, and addresses steering, surcharging, co-badging, domestic debit and cross-border acquiring across the single market. The analytically material carve-out is that commercial and corporate cards are excluded and can carry interchange of 1.5% or more — a distinction that materially raises acquiring costs for commercial-card acceptance and shapes merchant economics across the bloc. The IFR applies to both bank and non-bank participants in the card value chain.

The scheme-mandated security layer is PCI DSS, which is contractually required by Visa and Mastercard for all merchants. PCI DSS 4.0's future-dated requirements took effect from 31 March 2025, moving previously optional controls into mandatory status and raising the compliance baseline for merchants and their acquirers.

On competitive dynamics, combined Visa and Mastercard European payment volume rose 18% in Q2 2025 (12% in euro terms), with Mastercard marginally exceeding Visa in processed European volume for the first time. This Tier-2 public-data signal marks a notable shift in the relative competitive position of the two networks within Europe.

Outlook

The module is stable. The IFR caps and the now-live PCI DSS 4.0 requirements are settled standing positions; the watch item is the evolving Visa–Mastercard competitive balance in European processed volume, where Mastercard's marginal lead is a position to monitor rather than a structural break.

Read the full sub-brief

Scheme & Network Compliance

Scheme and network compliance is anchored by the Interchange Fee Regulation, which caps regulated consumer card interchange at 0.2% for debit and 0.3% for credit, and addresses steering, surcharging, co-badging, domestic debit and cross-border acquiring across the single market. The analytically material carve-out is that commercial and corporate cards are excluded and can carry interchange of 1.5% or more — a distinction that materially raises acquiring costs for commercial-card acceptance and shapes merchant economics across the bloc. The IFR applies to both bank and non-bank participants in the card value chain.

The scheme-mandated security layer is PCI DSS, which is contractually required by Visa and Mastercard for all merchants. PCI DSS 4.0's future-dated requirements took effect from 31 March 2025, moving previously optional controls into mandatory status and raising the compliance baseline for merchants and their acquirers.

On competitive dynamics, combined Visa and Mastercard European payment volume rose 18% in Q2 2025 (12% in euro terms), with Mastercard marginally exceeding Visa in processed European volume for the first time. This Tier-2 public-data signal marks a notable shift in the relative competitive position of the two networks within Europe.

Outlook

The module is stable. The IFR caps and the now-live PCI DSS 4.0 requirements are settled standing positions; the watch item is the evolving Visa–Mastercard competitive balance in European processed volume, where Mastercard's marginal lead is a position to monitor rather than a structural break.

W4Scheme & Network ComplianceConfirmed
EEA card-scheme economics are governed by the Interchange Fee Regulation ((EU) 2015/751), capping consumer debit/credit interchange (0.2%/0.3%) while excluding commercial cards. PCI DSS (administered by the PCI SSC) is contractually mandated by Visa/Mastercard for all merchants, with v4.0 future-dated requirements taking effect from 31 March 2025. Surcharging of regulated cards is restricted under PSD2. Visa and Mastercard dominate the four-party scheme layer, with combined European volume growing strongly in 2025.
all · compliance · analyst · board
Evidence 4 claims ›

W5ConfirmedPayment Corridor Dynamics

see this theme across all jurisdictions →4 claims

Intra-EEA euro corridors run over SEPA (SCT, SCT Inst) operated via EBA CLEARING (RT1/STEP2) and the Eurosystem's TIPS; cross-border/cross-currency reach is extended by TIPS' multi-currency capability and the EPC One-Leg-Out (OCT Inst) scheme, plus SWIFT for global correspondent flows. The Instant Payments Regulation amended the SEPA Regulation to mandate 10-second euro instant transfers and verification of payee. Work aligns with G20 cross-border targets, where global KPIs show only slight improvement against the 2027 timetable.

Periodic update 2026-07-07T15:44:36Z

Payment Corridor Dynamics

Corridor dynamics in the EEA are being reshaped by the extension of TIPS reach beyond the euro area. A baseline cross-currency capability was implemented in TIPS in June 2025, based on the EPC One-Leg-Out Instant Credit Transfer scheme, enabling interaction between TIPS and fast payment systems outside the euro area. A cross-currency service available to all participants since October 2025 enables Swedish and Danish consumers to transfer in their domestic currency. This is a structural extension of the euro instant-payment corridor's reach, connecting the euro-area instant rail to neighbouring non-euro currencies.

Against global benchmarks, the FSB's 2025 consolidated progress report found only slight global KPI improvement, with average remittance and retail cross-border cost remaining sticky and the full 2027 Roadmap targets unlikely to be met. This Tier-1 FSB finding is the reference point for measuring corridor cost and speed against the G20 targets, and it tempers expectations that the structural improvements visible in TIPS translate into rapid progress on the global cost metrics.

Outlook

The corridor trajectory is established. The TIPS cross-currency capability is live and extending to Swedish and Danish domestic-currency transfers; the countervailing signal is the FSB's assessment that the 2027 G20 cost and speed targets are unlikely to be met, leaving the gap between regional infrastructure progress and global cost outcomes as the defining tension.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Payment Corridor Dynamics

Corridor dynamics in the EEA are being reshaped by the extension of TIPS reach beyond the euro area. A baseline cross-currency capability was implemented in TIPS in June 2025, based on the EPC One-Leg-Out Instant Credit Transfer scheme, enabling interaction between TIPS and fast payment systems outside the euro area. A cross-currency service available to all participants since October 2025 enables Swedish and Danish consumers to transfer in their domestic currency. This is a structural extension of the euro instant-payment corridor's reach, connecting the euro-area instant rail to neighbouring non-euro currencies.

Against global benchmarks, the FSB's 2025 consolidated progress report found only slight global KPI improvement, with average remittance and retail cross-border cost remaining sticky and the full 2027 Roadmap targets unlikely to be met. This Tier-1 FSB finding is the reference point for measuring corridor cost and speed against the G20 targets, and it tempers expectations that the structural improvements visible in TIPS translate into rapid progress on the global cost metrics.

Outlook

The corridor trajectory is established. The TIPS cross-currency capability is live and extending to Swedish and Danish domestic-currency transfers; the countervailing signal is the FSB's assessment that the 2027 G20 cost and speed targets are unlikely to be met, leaving the gap between regional infrastructure progress and global cost outcomes as the defining tension.

Read the full sub-brief

Payment Corridor Dynamics

Corridor dynamics in the EEA are being reshaped by the extension of TIPS reach beyond the euro area. A baseline cross-currency capability was implemented in TIPS in June 2025, based on the EPC One-Leg-Out Instant Credit Transfer scheme, enabling interaction between TIPS and fast payment systems outside the euro area. A cross-currency service available to all participants since October 2025 enables Swedish and Danish consumers to transfer in their domestic currency. This is a structural extension of the euro instant-payment corridor's reach, connecting the euro-area instant rail to neighbouring non-euro currencies.

Against global benchmarks, the FSB's 2025 consolidated progress report found only slight global KPI improvement, with average remittance and retail cross-border cost remaining sticky and the full 2027 Roadmap targets unlikely to be met. This Tier-1 FSB finding is the reference point for measuring corridor cost and speed against the G20 targets, and it tempers expectations that the structural improvements visible in TIPS translate into rapid progress on the global cost metrics.

Outlook

The corridor trajectory is established. The TIPS cross-currency capability is live and extending to Swedish and Danish domestic-currency transfers; the countervailing signal is the FSB's assessment that the 2027 G20 cost and speed targets are unlikely to be met, leaving the gap between regional infrastructure progress and global cost outcomes as the defining tension.

W5Payment Corridor DynamicsConfirmed
Intra-EEA euro corridors run over SEPA (SCT, SCT Inst) operated via EBA CLEARING (RT1/STEP2) and the Eurosystem's TIPS; cross-border/cross-currency reach is extended by TIPS' multi-currency capability and the EPC One-Leg-Out (OCT Inst) scheme, plus SWIFT for global correspondent flows. The Instant Payments Regulation amended the SEPA Regulation to mandate 10-second euro instant transfers and verification of payee. Work aligns with G20 cross-border targets, where global KPIs show only slight improvement against the 2027 timetable.
all · compliance · analyst · board
Evidence 4 claims ›

W6HighIndustry Structure & Commercial

see this theme across all jurisdictions →4 claims

The EEA acquiring/processing market is concentrated but contested: legacy processors Worldline and Nexi compete with direct-connection 'gateway acquirers' Adyen and Stripe, plus US entrants (Fiserv, Global Payments, Worldpay) and the SMB 'Tap Pack' (SumUp, Viva.com, myPOS, Flatpay). The top five processors command roughly 55% of market value. Sixteen European banks launched the Wero/EPI account-to-account wallet to reclaim sovereign control of P2P and merchant rails.

Periodic update 2026-07-07T15:44:36Z

Industry Structure & Commercial

The European acquiring and processing market is concentrated and contested. The top five processors command roughly 55% of European payments market value, while sixteen leading European banks launched the Wero/EPI account-to-account wallet to reclaim sovereign control of wallet and P2P rails. The structural tension is between incumbent processor concentration and a coordinated bank-led push for sovereign infrastructure. On the commercial side of the structure, Adyen's platform volume rose roughly 80% to EUR 27bn in H1 2025, Nexi reported merchant-solutions revenue up 2% in H2 2025, and BNP Paribas and BPCE formed Estreem to capture issuer-processor economics. These data points describe the competitive landscape; specific announced deals are routed to W13 to keep structural trend distinct from discrete event.

The analytical spine of the module is the contest between concentrated incumbents and the sovereign-rail challenge, with both bank and non-bank players active across the value chain.

Outlook

The trajectory is escalating. Gateway-acquirer growth and the Wero sovereign-rail push are the two vectors to watch, with incumbent processor economics under pressure from both. Confidence is Assessed given reliance on Tier-3 vendor and market-commentary material for the underlying market-structure figures.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Industry Structure & Commercial

The European acquiring and processing market is concentrated and contested. The top five processors command roughly 55% of European payments market value, while sixteen leading European banks launched the Wero/EPI account-to-account wallet to reclaim sovereign control of wallet and P2P rails. The structural tension is between incumbent processor concentration and a coordinated bank-led push for sovereign infrastructure. On the commercial side of the structure, Adyen's platform volume rose roughly 80% to EUR 27bn in H1 2025, Nexi reported merchant-solutions revenue up 2% in H2 2025, and BNP Paribas and BPCE formed Estreem to capture issuer-processor economics. These data points describe the competitive landscape; specific announced deals are routed to W13 to keep structural trend distinct from discrete event.

The analytical spine of the module is the contest between concentrated incumbents and the sovereign-rail challenge, with both bank and non-bank players active across the value chain.

Outlook

The trajectory is escalating. Gateway-acquirer growth and the Wero sovereign-rail push are the two vectors to watch, with incumbent processor economics under pressure from both. Confidence is Assessed given reliance on Tier-3 vendor and market-commentary material for the underlying market-structure figures.

Read the full sub-brief

Industry Structure & Commercial

The European acquiring and processing market is concentrated and contested. The top five processors command roughly 55% of European payments market value, while sixteen leading European banks launched the Wero/EPI account-to-account wallet to reclaim sovereign control of wallet and P2P rails. The structural tension is between incumbent processor concentration and a coordinated bank-led push for sovereign infrastructure. On the commercial side of the structure, Adyen's platform volume rose roughly 80% to EUR 27bn in H1 2025, Nexi reported merchant-solutions revenue up 2% in H2 2025, and BNP Paribas and BPCE formed Estreem to capture issuer-processor economics. These data points describe the competitive landscape; specific announced deals are routed to W13 to keep structural trend distinct from discrete event.

The analytical spine of the module is the contest between concentrated incumbents and the sovereign-rail challenge, with both bank and non-bank players active across the value chain.

Outlook

The trajectory is escalating. Gateway-acquirer growth and the Wero sovereign-rail push are the two vectors to watch, with incumbent processor economics under pressure from both. Confidence is Assessed given reliance on Tier-3 vendor and market-commentary material for the underlying market-structure figures.

W6Industry Structure & CommercialHigh
The EEA acquiring/processing market is concentrated but contested: legacy processors Worldline and Nexi compete with direct-connection 'gateway acquirers' Adyen and Stripe, plus US entrants (Fiserv, Global Payments, Worldpay) and the SMB 'Tap Pack' (SumUp, Viva.com, myPOS, Flatpay). The top five processors command roughly 55% of market value. Sixteen European banks launched the Wero/EPI account-to-account wallet to reclaim sovereign control of P2P and merchant rails.
all · compliance · analyst · board
Evidence 4 claims ›

W7ConfirmedLegal & Litigation

see this theme across all jurisdictions →4 claims

EEA payments enforcement is NCA-led and intensifying. European regulators issued over EUR 36m in AML fines against payments/e-money firms between March 2024 and March 2025 across ~30 enforcement actions, including licence revocations by the Bank of Lithuania (Foxpay) and Estonia's FIU (B2BX). The new EU Anti-Money Laundering Authority (AMLA) began operations in Frankfurt in July 2025, marking the start of direct EU-level supervision of high-risk entities. The European Commission also pursues infringement penalties before the CJEU for non-transposition.

Periodic update 2026-07-07T15:44:36Z

Legal & Litigation

EEA payments enforcement is intensifying. European regulators issued over EUR 36m in AML fines against payments and e-money firms between March 2024 and March 2025 across roughly 30 actions, including the Bank of Lithuania's Foxpay licence revocation in November 2024 and Estonia's FIU revocation of B2BX Digital Exchange in February 2025. AMLA began operations in Frankfurt in July 2025. This module frames the activity as conduct and enforcement; the AML supervisory substance is carried in the W11 Sentinel feed, and the illicit-finance analysis routes to FIM. The enforcement burden falls particularly on the non-bank PI/EMI segment, where the licence revocations cited concentrate.

On the supranational enforcement lever, the European Commission calculates CJEU infringement penalty payments on seriousness, duration and member-state ability to pay, with rulings binding on all member states; the calculation method was updated in March 2025 and March 2026. This non-transposition enforcement mechanism is directly relevant to the PSD3/PSR rollout, where member-state transposition timing will determine exposure.

Outlook

The trajectory is escalating. Licence revocations and rising AML fines against payments and e-money firms signal sustained supervisory pressure, while the updated CJEU infringement-penalty method gives the Commission a sharpened lever as the PSD3/PSR transposition phase approaches. Original financial-crime analysis remains routed to FIM.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Legal & Litigation

EEA payments enforcement is intensifying. European regulators issued over EUR 36m in AML fines against payments and e-money firms between March 2024 and March 2025 across roughly 30 actions, including the Bank of Lithuania's Foxpay licence revocation in November 2024 and Estonia's FIU revocation of B2BX Digital Exchange in February 2025. AMLA began operations in Frankfurt in July 2025. This module frames the activity as conduct and enforcement; the AML supervisory substance is carried in the W11 Sentinel feed, and the illicit-finance analysis routes to FIM. The enforcement burden falls particularly on the non-bank PI/EMI segment, where the licence revocations cited concentrate.

On the supranational enforcement lever, the European Commission calculates CJEU infringement penalty payments on seriousness, duration and member-state ability to pay, with rulings binding on all member states; the calculation method was updated in March 2025 and March 2026. This non-transposition enforcement mechanism is directly relevant to the PSD3/PSR rollout, where member-state transposition timing will determine exposure.

Outlook

The trajectory is escalating. Licence revocations and rising AML fines against payments and e-money firms signal sustained supervisory pressure, while the updated CJEU infringement-penalty method gives the Commission a sharpened lever as the PSD3/PSR transposition phase approaches. Original financial-crime analysis remains routed to FIM.

Read the full sub-brief

Legal & Litigation

EEA payments enforcement is intensifying. European regulators issued over EUR 36m in AML fines against payments and e-money firms between March 2024 and March 2025 across roughly 30 actions, including the Bank of Lithuania's Foxpay licence revocation in November 2024 and Estonia's FIU revocation of B2BX Digital Exchange in February 2025. AMLA began operations in Frankfurt in July 2025. This module frames the activity as conduct and enforcement; the AML supervisory substance is carried in the W11 Sentinel feed, and the illicit-finance analysis routes to FIM. The enforcement burden falls particularly on the non-bank PI/EMI segment, where the licence revocations cited concentrate.

On the supranational enforcement lever, the European Commission calculates CJEU infringement penalty payments on seriousness, duration and member-state ability to pay, with rulings binding on all member states; the calculation method was updated in March 2025 and March 2026. This non-transposition enforcement mechanism is directly relevant to the PSD3/PSR rollout, where member-state transposition timing will determine exposure.

Outlook

The trajectory is escalating. Licence revocations and rising AML fines against payments and e-money firms signal sustained supervisory pressure, while the updated CJEU infringement-penalty method gives the Commission a sharpened lever as the PSD3/PSR transposition phase approaches. Original financial-crime analysis remains routed to FIM.

W7Legal & LitigationConfirmed
EEA payments enforcement is NCA-led and intensifying. European regulators issued over EUR 36m in AML fines against payments/e-money firms between March 2024 and March 2025 across ~30 enforcement actions, including licence revocations by the Bank of Lithuania (Foxpay) and Estonia's FIU (B2BX). The new EU Anti-Money Laundering Authority (AMLA) began operations in Frankfurt in July 2025, marking the start of direct EU-level supervision of high-risk entities. The European Commission also pursues infringement penalties before the CJEU for non-transposition.
all · compliance · analyst · board
Evidence 4 claims ›

W8HighMerchant Acquiring & Risk

see this theme across all jurisdictions →4 claims

EEA merchant acquiring operates within the IFR/PCI DSS framework, with chargeback/dispute mechanics governed by Visa/Mastercard scheme rulebooks and onboarding/KYC under PSD2 and national AML law. The market is roughly half the size of the US by card volume; acceptance is shifting rapidly to 'gateway acquirers' offering integrated single-platform bundles, while incumbents consolidate acquiring platforms to control cost. SMB acquiring is contested by the low-cost 'Tap Pack'.

Periodic update 2026-07-07T15:44:36Z

Merchant Acquiring & Risk

European merchant acquiring is in structural transition. Europe's acquiring market is about half the size of the US by card volume, and acceptance is shifting to gateway acquirers — Stripe, Adyen, Checkout — offering integrated single-platform bundles that pressure legacy acquirer economics. The SMB segment is contested by the 'Tap Pack' of SumUp, Viva.com, myPOS and Flatpay. The largest 2023 acquirers by transactions were Worldpay, Nexi, Barclays, Fiserv, Adyen, Worldline and Global Payments. The defining dynamic is the migration of acceptance toward integrated gateway platforms and the simultaneous low-cost challenge to incumbents in the SMB tier, with both bank and non-bank acquirers active across the segment.

This is an under-indexed operational vector deliberately surfaced in the baseline; the supporting evidence relies on Tier-3 commentary, and merchant-acquiring operational detail and intra-EEA member-state divergence beyond the principal markets are thinly evidenced.

Outlook

The trajectory is escalating. The gateway-acquirer migration and the Tap Pack's SMB challenge in Germany and the Benelux are the two watch vectors, with legacy acquirer economics under structural pressure. Coverage gaps in operational acquiring detail and member-state divergence are flagged for future indexing.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Merchant Acquiring & Risk

European merchant acquiring is in structural transition. Europe's acquiring market is about half the size of the US by card volume, and acceptance is shifting to gateway acquirers — Stripe, Adyen, Checkout — offering integrated single-platform bundles that pressure legacy acquirer economics. The SMB segment is contested by the 'Tap Pack' of SumUp, Viva.com, myPOS and Flatpay. The largest 2023 acquirers by transactions were Worldpay, Nexi, Barclays, Fiserv, Adyen, Worldline and Global Payments. The defining dynamic is the migration of acceptance toward integrated gateway platforms and the simultaneous low-cost challenge to incumbents in the SMB tier, with both bank and non-bank acquirers active across the segment.

This is an under-indexed operational vector deliberately surfaced in the baseline; the supporting evidence relies on Tier-3 commentary, and merchant-acquiring operational detail and intra-EEA member-state divergence beyond the principal markets are thinly evidenced.

Outlook

The trajectory is escalating. The gateway-acquirer migration and the Tap Pack's SMB challenge in Germany and the Benelux are the two watch vectors, with legacy acquirer economics under structural pressure. Coverage gaps in operational acquiring detail and member-state divergence are flagged for future indexing.

Read the full sub-brief

Merchant Acquiring & Risk

European merchant acquiring is in structural transition. Europe's acquiring market is about half the size of the US by card volume, and acceptance is shifting to gateway acquirers — Stripe, Adyen, Checkout — offering integrated single-platform bundles that pressure legacy acquirer economics. The SMB segment is contested by the 'Tap Pack' of SumUp, Viva.com, myPOS and Flatpay. The largest 2023 acquirers by transactions were Worldpay, Nexi, Barclays, Fiserv, Adyen, Worldline and Global Payments. The defining dynamic is the migration of acceptance toward integrated gateway platforms and the simultaneous low-cost challenge to incumbents in the SMB tier, with both bank and non-bank acquirers active across the segment.

This is an under-indexed operational vector deliberately surfaced in the baseline; the supporting evidence relies on Tier-3 commentary, and merchant-acquiring operational detail and intra-EEA member-state divergence beyond the principal markets are thinly evidenced.

Outlook

The trajectory is escalating. The gateway-acquirer migration and the Tap Pack's SMB challenge in Germany and the Benelux are the two watch vectors, with legacy acquirer economics under structural pressure. Coverage gaps in operational acquiring detail and member-state divergence are flagged for future indexing.

W8Merchant Acquiring & RiskHigh
EEA merchant acquiring operates within the IFR/PCI DSS framework, with chargeback/dispute mechanics governed by Visa/Mastercard scheme rulebooks and onboarding/KYC under PSD2 and national AML law. The market is roughly half the size of the US by card volume; acceptance is shifting rapidly to 'gateway acquirers' offering integrated single-platform bundles, while incumbents consolidate acquiring platforms to control cost. SMB acquiring is contested by the low-cost 'Tap Pack'.
all · compliance · analyst · board
Evidence 4 claims ›

W9ConfirmedProduct Innovation & Market Development

see this theme across all jurisdictions →4 claims

EEA product development is led by instant A2A rails and a sovereign-payments agenda. The EPI's Wero wallet (operated since July 2024 across DE/FR/BE) reached 46m+ users and launched an e-commerce solution in November 2025. The ECB concluded the digital euro preparation phase on 29-30 October 2025 and moved to the next phase, targeting potential first issuance in 2029 assuming the Regulation is adopted in 2026. Open-finance access expands via the FIDA proposal (still in trilogue).

Periodic update 2026-07-07T15:44:36Z

Product Innovation & Market Development

Product and market development is led by the digital euro and sovereign A2A rails. On 30 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting potential first issuance during 2029 on the assumption co-legislators adopt the establishing Regulation in 2026, with a pilot possibly starting mid-2027. This is the central CBDC development for the bloc, conditional on the legislative path in 2026.

The sovereign A2A vector is Wero. Wero is an instant account-to-account wallet operated since July 2024 across Germany, France and Belgium and backed by 16 banks and PSPs. It launched an e-commerce solution in Germany in November 2025 with over 46m users; Deutsche Bank and Postbank joined in December 2025, with merchant and POS use cases on the 2025–2026 roadmap. The specific November 2025 e-commerce launch also surfaces as a W13 product release; here it is framed as a sovereign-payments market development. Both bank and non-bank participants back the wallet.

The forward open-finance horizon is FIDA. The Financial Data Access Regulation, proposed alongside PSD3/PSR, remained in trilogue in April 2026 and would extend open-banking-style access to investments, pensions, insurance and mortgages — broadening the data-access perimeter beyond payment accounts. This thematic product-access regulatory view is distinct from the discrete commercial events in W13.

Outlook

The trajectory is escalating. The digital euro's progress hinges on co-legislators adopting the establishing Regulation in 2026, with a pilot possibly mid-2027 and issuance targeted for 2029. Wero's merchant and POS roadmap and FIDA's trilogue conclusion, expected in H2 2026, are the other developments to watch as the open-finance perimeter widens.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Product Innovation & Market Development

Product and market development is led by the digital euro and sovereign A2A rails. On 30 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting potential first issuance during 2029 on the assumption co-legislators adopt the establishing Regulation in 2026, with a pilot possibly starting mid-2027. This is the central CBDC development for the bloc, conditional on the legislative path in 2026.

The sovereign A2A vector is Wero. Wero is an instant account-to-account wallet operated since July 2024 across Germany, France and Belgium and backed by 16 banks and PSPs. It launched an e-commerce solution in Germany in November 2025 with over 46m users; Deutsche Bank and Postbank joined in December 2025, with merchant and POS use cases on the 2025–2026 roadmap. The specific November 2025 e-commerce launch also surfaces as a W13 product release; here it is framed as a sovereign-payments market development. Both bank and non-bank participants back the wallet.

The forward open-finance horizon is FIDA. The Financial Data Access Regulation, proposed alongside PSD3/PSR, remained in trilogue in April 2026 and would extend open-banking-style access to investments, pensions, insurance and mortgages — broadening the data-access perimeter beyond payment accounts. This thematic product-access regulatory view is distinct from the discrete commercial events in W13.

Outlook

The trajectory is escalating. The digital euro's progress hinges on co-legislators adopting the establishing Regulation in 2026, with a pilot possibly mid-2027 and issuance targeted for 2029. Wero's merchant and POS roadmap and FIDA's trilogue conclusion, expected in H2 2026, are the other developments to watch as the open-finance perimeter widens.

Read the full sub-brief

Product Innovation & Market Development

Product and market development is led by the digital euro and sovereign A2A rails. On 30 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting potential first issuance during 2029 on the assumption co-legislators adopt the establishing Regulation in 2026, with a pilot possibly starting mid-2027. This is the central CBDC development for the bloc, conditional on the legislative path in 2026.

The sovereign A2A vector is Wero. Wero is an instant account-to-account wallet operated since July 2024 across Germany, France and Belgium and backed by 16 banks and PSPs. It launched an e-commerce solution in Germany in November 2025 with over 46m users; Deutsche Bank and Postbank joined in December 2025, with merchant and POS use cases on the 2025–2026 roadmap. The specific November 2025 e-commerce launch also surfaces as a W13 product release; here it is framed as a sovereign-payments market development. Both bank and non-bank participants back the wallet.

The forward open-finance horizon is FIDA. The Financial Data Access Regulation, proposed alongside PSD3/PSR, remained in trilogue in April 2026 and would extend open-banking-style access to investments, pensions, insurance and mortgages — broadening the data-access perimeter beyond payment accounts. This thematic product-access regulatory view is distinct from the discrete commercial events in W13.

Outlook

The trajectory is escalating. The digital euro's progress hinges on co-legislators adopting the establishing Regulation in 2026, with a pilot possibly mid-2027 and issuance targeted for 2029. Wero's merchant and POS roadmap and FIDA's trilogue conclusion, expected in H2 2026, are the other developments to watch as the open-finance perimeter widens.

W9Product Innovation & Market DevelopmentConfirmed
EEA product development is led by instant A2A rails and a sovereign-payments agenda. The EPI's Wero wallet (operated since July 2024 across DE/FR/BE) reached 46m+ users and launched an e-commerce solution in November 2025. The ECB concluded the digital euro preparation phase on 29-30 October 2025 and moved to the next phase, targeting potential first issuance in 2029 assuming the Regulation is adopted in 2026. Open-finance access expands via the FIDA proposal (still in trilogue).
all · compliance · analyst · board
Evidence 4 claims ›

W10ConfirmedConsumer Protection & APP Fraud

see this theme across all jurisdictions →4 claims

EEA consumer protection rests on PSD2 (unauthorised/incorrectly executed transaction refunds) and is being expanded by the PSR. The November 2025 PSD3/PSR political agreement introduces mandatory reimbursement for impersonation ('spoofing') fraud, obliging PSPs and electronic communications providers to fully reimburse consumer victims (Article 59 PSR), plus mandatory IBAN-name verification (live via the IPR since October 2025) and online-platform liability building on the DSA. This contrasts with the UK PSR's broader Faster-Payments APP reimbursement model.

Periodic update 2026-07-07T15:44:36Z

Consumer Protection & APP Fraud

EEA consumer-fraud liability is converging on an impersonation-focused model. Article 59 of the PSR introduces a compensation model obliging PSPs and electronic communications service providers to fully reimburse a consumer victim of impersonation ('spoofing') fraud for the full fraudulent amount; online platforms become liable to reimbursing PSPs if informed of fraudulent content and failing to remove it, building on the Digital Services Act. The analytically important point is that this regime is narrower than the UK PSR's Faster-Payments APP model — it targets impersonation specifically rather than the broader authorised push payment category — a divergence relevant to operators working across both jurisdictions. The obligation falls on both bank and non-bank PSPs and is subject to the PSD3/PSR timeline.

The live anti-fraud control complementing this regime is Verification of Payee. All PSPs offering SCT or SCT Inst were required to implement VoP by 9 October 2025 under the Instant Payments Regulation, checking payee name against IBAN before transfer. Unlike the forward-dated PSR reimbursement regime, VoP is already in force, giving the EEA a preventive control already operating ahead of the reimbursement liability framework.

Outlook

The trajectory is escalating. VoP is live; the Article 59 reimbursement regime follows the PSD3/PSR timeline and will sharpen the EEA–UK divergence in fraud-liability scope. The narrower EEA impersonation model versus the broader UK APP scheme is the cross-jurisdiction point operators should track.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

Consumer Protection & APP Fraud

EEA consumer-fraud liability is converging on an impersonation-focused model. Article 59 of the PSR introduces a compensation model obliging PSPs and electronic communications service providers to fully reimburse a consumer victim of impersonation ('spoofing') fraud for the full fraudulent amount; online platforms become liable to reimbursing PSPs if informed of fraudulent content and failing to remove it, building on the Digital Services Act. The analytically important point is that this regime is narrower than the UK PSR's Faster-Payments APP model — it targets impersonation specifically rather than the broader authorised push payment category — a divergence relevant to operators working across both jurisdictions. The obligation falls on both bank and non-bank PSPs and is subject to the PSD3/PSR timeline.

The live anti-fraud control complementing this regime is Verification of Payee. All PSPs offering SCT or SCT Inst were required to implement VoP by 9 October 2025 under the Instant Payments Regulation, checking payee name against IBAN before transfer. Unlike the forward-dated PSR reimbursement regime, VoP is already in force, giving the EEA a preventive control already operating ahead of the reimbursement liability framework.

Outlook

The trajectory is escalating. VoP is live; the Article 59 reimbursement regime follows the PSD3/PSR timeline and will sharpen the EEA–UK divergence in fraud-liability scope. The narrower EEA impersonation model versus the broader UK APP scheme is the cross-jurisdiction point operators should track.

Read the full sub-brief

Consumer Protection & APP Fraud

EEA consumer-fraud liability is converging on an impersonation-focused model. Article 59 of the PSR introduces a compensation model obliging PSPs and electronic communications service providers to fully reimburse a consumer victim of impersonation ('spoofing') fraud for the full fraudulent amount; online platforms become liable to reimbursing PSPs if informed of fraudulent content and failing to remove it, building on the Digital Services Act. The analytically important point is that this regime is narrower than the UK PSR's Faster-Payments APP model — it targets impersonation specifically rather than the broader authorised push payment category — a divergence relevant to operators working across both jurisdictions. The obligation falls on both bank and non-bank PSPs and is subject to the PSD3/PSR timeline.

The live anti-fraud control complementing this regime is Verification of Payee. All PSPs offering SCT or SCT Inst were required to implement VoP by 9 October 2025 under the Instant Payments Regulation, checking payee name against IBAN before transfer. Unlike the forward-dated PSR reimbursement regime, VoP is already in force, giving the EEA a preventive control already operating ahead of the reimbursement liability framework.

Outlook

The trajectory is escalating. VoP is live; the Article 59 reimbursement regime follows the PSD3/PSR timeline and will sharpen the EEA–UK divergence in fraud-liability scope. The narrower EEA impersonation model versus the broader UK APP scheme is the cross-jurisdiction point operators should track.

W10Consumer Protection & APP FraudConfirmed
EEA consumer protection rests on PSD2 (unauthorised/incorrectly executed transaction refunds) and is being expanded by the PSR. The November 2025 PSD3/PSR political agreement introduces mandatory reimbursement for impersonation ('spoofing') fraud, obliging PSPs and electronic communications providers to fully reimburse consumer victims (Article 59 PSR), plus mandatory IBAN-name verification (live via the IPR since October 2025) and online-platform liability building on the DSA. This contrasts with the UK PSR's broader Faster-Payments APP reimbursement model.
all · compliance · analyst · board
Evidence 4 claims ›

W11AssessedAML/CFT & Financial Crime

Sentinelsee this theme across all jurisdictions →7 claims

[SENTINEL.GI FEED] Sentinel payments-context position for the EEA: the AML/CFT perimeter is consolidating under the EU AML package (Single Rulebook + AMLR + AMLD6) with the Anti-Money Laundering Authority (AMLA) operational in Frankfurt from July 2025 assuming direct supervision of high-risk entities. The Transfer of Funds Regulation extends originator/beneficiary information ('travel rule') to PSPs and CASPs. Enforcement of payments/e-money firms is rising (EUR 36m+ in fines March 2024-March 2025). WPM carries the Sentinel position only; no original illicit-finance analysis performed (that is FIM).

Periodic update 2026-07-07T15:44:36Z

AML/CFT & Financial Crime

This module is sourced from the Sentinel feed; the intelligence is attributed to that feed, and original illicit-finance analysis is not conducted here. Per Sentinel, AMLA began operations in Frankfurt in July 2025, marking the start of direct EU-wide supervision for high-risk entities under the EU Single Rulebook. Also per Sentinel, the Transfer of Funds Regulation mandates that PSPs and CASPs include detailed originator and beneficiary information with each transfer. Both positions are carried as payments-context provenance, applying to bank and non-bank PSPs and to CASPs respectively, rather than as WPM-originated conclusions.

The analytical substance of illicit finance — sanctions-evasion, supervisory-gap assessment and the financial-crime use of payment instruments — belongs to FIM, where it is flagged for cross-monitor handling. WPM's role here is limited to recording the payments-perimeter relevance of AMLA's operational start and the travel-rule obligation.

Outlook

The trajectory is escalating per the Sentinel feed, anchored on AMLA's operational start and the travel-rule perimeter on PSPs and CASPs. Readers seeking illicit-finance analysis should consult FIM; this module tracks only the payments-context surface and links out to the Sentinel feed for the underlying intelligence.

1 earlier update
Periodic update 2026-07-07T12:45:19Z

AML/CFT & Financial Crime

This module is sourced from the Sentinel feed; the intelligence is attributed to that feed, and original illicit-finance analysis is not conducted here. Per Sentinel, AMLA began operations in Frankfurt in July 2025, marking the start of direct EU-wide supervision for high-risk entities under the EU Single Rulebook. Also per Sentinel, the Transfer of Funds Regulation mandates that PSPs and CASPs include detailed originator and beneficiary information with each transfer. Both positions are carried as payments-context provenance, applying to bank and non-bank PSPs and to CASPs respectively, rather than as WPM-originated conclusions.

The analytical substance of illicit finance — sanctions-evasion, supervisory-gap assessment and the financial-crime use of payment instruments — belongs to FIM, where it is flagged for cross-monitor handling. WPM's role here is limited to recording the payments-perimeter relevance of AMLA's operational start and the travel-rule obligation.

Outlook

The trajectory is escalating per the Sentinel feed, anchored on AMLA's operational start and the travel-rule perimeter on PSPs and CASPs. Readers seeking illicit-finance analysis should consult FIM; this module tracks only the payments-context surface and links out to the Sentinel feed for the underlying intelligence.

Read the full sub-brief

AML/CFT & Financial Crime

This module is sourced from the Sentinel feed; the intelligence is attributed to that feed, and original illicit-finance analysis is not conducted here. Per Sentinel, AMLA began operations in Frankfurt in July 2025, marking the start of direct EU-wide supervision for high-risk entities under the EU Single Rulebook. Also per Sentinel, the Transfer of Funds Regulation mandates that PSPs and CASPs include detailed originator and beneficiary information with each transfer. Both positions are carried as payments-context provenance, applying to bank and non-bank PSPs and to CASPs respectively, rather than as WPM-originated conclusions.

The analytical substance of illicit finance — sanctions-evasion, supervisory-gap assessment and the financial-crime use of payment instruments — belongs to FIM, where it is flagged for cross-monitor handling. WPM's role here is limited to recording the payments-perimeter relevance of AMLA's operational start and the travel-rule obligation.

Outlook

The trajectory is escalating per the Sentinel feed, anchored on AMLA's operational start and the travel-rule perimeter on PSPs and CASPs. Readers seeking illicit-finance analysis should consult FIM; this module tracks only the payments-context surface and links out to the Sentinel feed for the underlying intelligence.

W11AML/CFT & Financial CrimeAssessed
[SENTINEL.GI FEED] Sentinel payments-context position for the EEA: the AML/CFT perimeter is consolidating under the EU AML package (Single Rulebook + AMLR + AMLD6) with the Anti-Money Laundering Authority (AMLA) operational in Frankfurt from July 2025 assuming direct supervision of high-risk entities. The Transfer of Funds Regulation extends originator/beneficiary information ('travel rule') to PSPs and CASPs. Enforcement of payments/e-money firms is rising (EUR 36m+ in fines March 2024-March 2025). WPM carries the Sentinel position only; no original illicit-finance analysis performed (that is FIM).
all · compliance · analyst · board
Evidence 7 claims ›

Standing watch

1 tracked development
WT6Escalating
ECB Governing Council moved digital euro to next phase 30 Oct 2025; potential first issuance 2029, pilot possibly mid-2027, conditional on 2026 Regulation adoption.

Key judgments

5 judgments
W12Confirmed
The non-bank settlement-access widening (direct T2/TIPS access for PIs and EMIs from 6 October 2025) is the single most structurally significant EEA development this baseline — it ends banks' exclusivity over central-bank settlement and reshapes the competitive economics of non-bank PSPs.
Impact: CRITICAL
1 supporting claim
Evidence 1 claim ›
W1aHigh
PSD3/PSR (provisional agreement 27 Nov 2025) will restructure the entire EEA non-bank authorisation landscape by merging the PI and EMI regimes, but its impact is forward-loaded: texts are not yet in the Official Journal and implementation is most likely H2 2027-early 2028, not 2027 entry into force.
Impact: CRITICAL
3 supporting claims
Evidence 3 claims ›
W2High
MiCA's EMT-PSD2 interplay is the live operational pinch-point for stablecoin issuers: the EBA No-Action Letter transition ends 2 March 2026 and the 12 February 2026 Opinion clarifies (but does not narrow) post-transition supervisory expectations for CASPs with pending PSD2 applications.
Impact: HIGH
2 supporting claims
Evidence 2 claims ›
W10High
EEA consumer-fraud liability is converging on a narrower 'impersonation/spoofing' reimbursement model (Article 59 PSR + platform liability) that is materially less broad than the UK PSR's Faster-Payments APP scheme — a divergence relevant to cross-jurisdiction operators.
Impact: HIGH
2 supporting claims
Evidence 2 claims ›
W13High
European payments commercial activity rebounded sharply in 2025 ($100m+ deal value $3.9bn in H1, near double FY2024), concentrating capital in infrastructure/issuing consolidation (Marqeta/TransactPay) and profitable SMB acquiring (Flatpay), with the gateway-acquirer model structurally pressuring legacy processor economics.
Impact: ELEVATED
4 supporting claims
Evidence 4 claims ›

What changed this cycle

6 changes this cycle
domain W1aNew
W1a baseline established with PSD3/PSR provisional-agreement position and corrected implementation timeline (H2 2027-early 2028).
EEA baseline run; first standing position for licensing/market access.
Detail ›
domain W12New
W12 baseline established with non-bank PSP direct T2/TIPS access (6 Oct 2025, Guideline ECB/2025/28).
EEA baseline run; structural settlement-access widening recorded.
Detail ›
claim wpm-2026-W2-003Updated
EBA Opinion of 12 Feb 2026 characterised as clarifying (not reducing) post-transition supervisory expectations.
Challenger f-003 correction: research conflated NAL/Opinion scope.
Detail ›
claim wpm-2026-W9-001Updated
Digital euro next-phase decision dated 30 October 2025 (official ECB press release).
Challenger f-004 correction: research stated 29 October 2025.
Detail ›
tracker WT7New
WT7 Major M&A baseline: Marqeta/TransactPay; European $100m+ deal value $3.9bn H1 2025.
EEA baseline run; commercial-intelligence trailing-12-month window recorded.
Detail ›
horizon wpm-reg-1New
PSD3/PSR OJ publication H1 2026; implementation H2 2027-early 2028 with year-band uncertainty.
Forward rule-change horizon registered with corrected band per challenger f-001.
Detail ›

Risk posture

4 tracked
EEAEscalating
Regulatory perimeter consolidating (PSD3/PSR, MiCA, DORA, AMLA, non-bank TARGET access) amid rising enforcement.
Risk level: Elevated
Confidence: High
Detail ›
DEStable
BaFin/ZAG authorisation regime; Wero traction; SMB acquiring contested by Tap Pack.
Risk level: Moderate
Confidence: Assessed
Detail ›
LTEscalating
Bank of Lithuania AML enforcement (Foxpay revocation, neobank EUR 3.5m fine).
Risk level: Elevated
Confidence: High
Detail ›
LUStable
CSSF-supervised euro EMT issuance (Banking Circle EURI).
Risk level: Moderate
Confidence: Assessed
Detail ›
World Payments jurisdiction data · European Economic Area (EEA) · schema world-payments-v1 · baseline wpm-2026-06-20. Data-driven from the published jurisdiction contract — all values shown are read directly from the pipeline output (server-rendered).

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.