Almost every crypto product eventually touches stablecoins, typically USDT or USDC. Under Regulation (EU) 2023/1114 (MiCA), electronic money tokens (EMTs) have a dual regulatory life: crypto-assets involving CASP authorisation and funds for payment regulation. Providers handling them for clients must therefore consider payment services authorisation under Directive (EU) 2015/2366 (PSD2) alongside MiCA.
Why payment regulation applies
MiCA itself connects the regimes. Article 70(4) allows crypto-asset service providers to provide related payment services themselves or through a third party only where that entity is authorised under Directive (EU) 2015/2366. In Slovakia, Payment Services Act No. 492/2009 Z. z. expressly includes electronic money in funds.
Unofficial English translation:
For the purposes of this Act, funds mean banknotes or coins as cash, funds transferred in non-cash form or electronic money.
EBA’s approach follows the same logic: EMTs are funds for PSD2, so transactions involving them may be payment transactions.
What is not a payment service?
Exchange alone does not trigger payment regulation. In no-action letter EBA/Op/2025/08, EBA recommended that supervisors not treat crypto-to-funds exchange, crypto-to-crypto exchange or intermediation of crypto purchases using EMTs as payment services. An exchange model therefore does not itself require a second authorisation.
What may be a payment service: a wider boundary than expected
The dividing point is transfers. EBA/OP/2026/01, paragraph 15, states that transferring EMTs on clients’ behalf may be a payment service whether or not the provider’s custodial wallet qualifies as a payment account. PSD2 has no exemption for transfers between the same user’s accounts. A transfer to a client’s own address, including withdrawal from custody to their own wallet, may therefore be a payment transaction.
Transferability to third parties, long treated as the dividing line, remains only one criterion for whether a wallet is a payment account, not the boundary of the entire regulatory scope. “Withdrawals only to the client’s verified address” is not automatically outside PSD2. Do not rely on apparently safe closed-loop designs.
The tolerance period has ended
EBA/Op/2025/08 envisaged requiring PSD2 authorisation for EMT transfers from 2 March 2026. The subsequent EBA/OP/2026/01 tolerates after that date only entities that properly submitted payment authorisation applications and meet further conditions, without marketing or onboarding new clients. Others should cease those EMT services. The Article 143(3) MiCA exemption ended on 1 July 2026. New entrants have no transition to invoke and must design authorisation arrangements from the start.
Map every token movement
“Do you allow third-party transfers?” is too broad a question. Map each movement separately: deposit, internal ledger transfer, withdrawal and third-party payment. Identify who instructs and executes it, the source and destination wallets, whose name they are held in and whether sender and recipient are the same. Only that map reveals which product components fall under PSD2. Those components require either your own payment institution or electronic money institution authorisation alongside CASP, or routing through an authorised payment service provider, expressly allowed by Article 70(4) MiCA.
Do not overlook the second layer: only tokens with an EU-authorised issuer may be offered. Check each stablecoin’s status in the ESMA register on the date of listing, not through press releases.
How we help
Assessment of whether a product needs one or two authorisations forms part of MiCA CASP authorisation. The transaction map informs the AML programme, while SaaS agreements and terms reflect findings in customer documentation.
This article provides general legal information as at 5 September 2026. It does not constitute legal services or advice on your specific matter. Laws change and the details of your situation may differ. Check the appropriate course of action or contact us before making a decision.