MiCA × PSD2 · Compliance, Registers & Licences

Stablecoins in business: when CASP authorisation is not enough and payment authorisation is needed

Electronic money tokens are funds for payment regulation purposes. Exchanging stablecoins is not a payment service, but transferring them for clients can be, including between the same client’s accounts. EBA’s approach defines where CASP ends and PSD2 begins.

Almost every crypto product eventually touches stablecoins, typically USDT or USDC. Under Regulation (EU) 2023/1114 (MiCA), electronic money tokens (EMTs) have a dual regulatory life: crypto-assets involving CASP authorisation and funds for payment regulation. Providers handling them for clients must therefore consider payment services authorisation under Directive (EU) 2015/2366 (PSD2) alongside MiCA.

Why payment regulation applies

MiCA itself connects the regimes. Article 70(4) allows crypto-asset service providers to provide related payment services themselves or through a third party only where that entity is authorised under Directive (EU) 2015/2366. In Slovakia, Payment Services Act No. 492/2009 Z. z. expressly includes electronic money in funds.

Unofficial English translation:

For the purposes of this Act, funds mean banknotes or coins as cash, funds transferred in non-cash form or electronic money.

§ 2(13) of Act No. 492/2009 Z. z.

EBA’s approach follows the same logic: EMTs are funds for PSD2, so transactions involving them may be payment transactions.

What is not a payment service?

Exchange alone does not trigger payment regulation. In no-action letter EBA/Op/2025/08, EBA recommended that supervisors not treat crypto-to-funds exchange, crypto-to-crypto exchange or intermediation of crypto purchases using EMTs as payment services. An exchange model therefore does not itself require a second authorisation.

What may be a payment service: a wider boundary than expected

The dividing point is transfers. EBA/OP/2026/01, paragraph 15, states that transferring EMTs on clients’ behalf may be a payment service whether or not the provider’s custodial wallet qualifies as a payment account. PSD2 has no exemption for transfers between the same user’s accounts. A transfer to a client’s own address, including withdrawal from custody to their own wallet, may therefore be a payment transaction.

Transferability to third parties, long treated as the dividing line, remains only one criterion for whether a wallet is a payment account, not the boundary of the entire regulatory scope. “Withdrawals only to the client’s verified address” is not automatically outside PSD2. Do not rely on apparently safe closed-loop designs.

The tolerance period has ended

EBA/Op/2025/08 envisaged requiring PSD2 authorisation for EMT transfers from 2 March 2026. The subsequent EBA/OP/2026/01 tolerates after that date only entities that properly submitted payment authorisation applications and meet further conditions, without marketing or onboarding new clients. Others should cease those EMT services. The Article 143(3) MiCA exemption ended on 1 July 2026. New entrants have no transition to invoke and must design authorisation arrangements from the start.

Map every token movement

“Do you allow third-party transfers?” is too broad a question. Map each movement separately: deposit, internal ledger transfer, withdrawal and third-party payment. Identify who instructs and executes it, the source and destination wallets, whose name they are held in and whether sender and recipient are the same. Only that map reveals which product components fall under PSD2. Those components require either your own payment institution or electronic money institution authorisation alongside CASP, or routing through an authorised payment service provider, expressly allowed by Article 70(4) MiCA.

Do not overlook the second layer: only tokens with an EU-authorised issuer may be offered. Check each stablecoin’s status in the ESMA register on the date of listing, not through press releases.

How we help

Assessment of whether a product needs one or two authorisations forms part of MiCA CASP authorisation. The transaction map informs the AML programme, while SaaS agreements and terms reflect findings in customer documentation.

This article provides general legal information as at 5 September 2026. It does not constitute legal services or advice on your specific matter. Laws change and the details of your situation may differ. Check the appropriate course of action or contact us before making a decision.

Facing a similar situation?

Tell us what you need help with.

Describe your situation. We will review it and tell you within 24 hours whether and how we can help, including an indicative fee.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.