Legal development

When do crypto firms need additional EU licenses for stablecoin transfers? EBA issues guidance on the interplay between PSD2 and MiCA

graph and lights background

    On 10 June 2025 the European Banking Authority (EBA) published an opinion (the Opinion) clarifying the interplay between the second EU Payment Services Directive (PSD2) and the EU Markets in Crypto-Assets Regulation (MiCA) in relation to crypto-asset service providers (CASPs) transacting in electronic money tokens (EMTs), which term includes most stablecoins.1

    The Opinion provides supervisory guidance to EU national competent authorities (NCAs) on the application of PSD2 to CASPs and recommendations for longer-term legislative alignment under the upcoming third EU Payment Services Directive (PSD3) and the accompanying EU Payment Services Regulation (PSR).

    Key takeaways for CASPs

    • Transitional relief: CASPs providing EMT transfer services may, in most cases, operate under their MiCA authorization alone until 1 March 2026. However, they will generally need to obtain authorization under PSD2 to continue providing EMT transfer services beyond that date. 
    • Streamlined PSD2 authorization: Where additional PSD2 authorization is required, NCAs are advised to streamline procedures and leverage information already provided under MiCA.

    • Focused supervision: NCAs are encouraged to focus on strong customer authentication, fraud reporting and own funds requirements under PSD2 while de-prioritizing enforcement of other PSD2 requirements in respect of EMT transfers.

    • Legislative reform: The EBA recommends that PSD3/PSR should clarify the requirements that apply to EMT transfer services and avoid duplicative regulatory authorization requirements, while ensuring robust consumer protection and market integrity. 

    What happens before PSD3/PSR apply?

    PSD3 and the PSR are expected to be published in final form by year-end 2025 and apply 18 months after they are published.2

    During the period before their application, the EBA advises NCAs to:

    • treat the transfer, custody, and administration of EMTs by CASPs on behalf of clients as payment services under PSD2, requiring authorization as a payment service provider (PSP),3 but provide a transition period until 1 March 2026 for compliance;

    • treat as excluded from the scope of PSD2: (i) exchange of crypto-assets for funds or other crypto-assets, and (ii) intermediation of crypto-asset purchases using EMTs;

    • recognize custodial wallets holding EMTs as "payment accounts" under PSD2 if they enable sending and receiving EMTs to/from third parties;

    • streamline the authorization process for CASPs seeking authorization under PSD2 by maximizing reliance on information already submitted for authorization under MiCA.

    Supervisory priorities and de-prioritized areas

    The EBA recommends that NCAs:

    • prioritize enforcement of:
      • strong customer authentication (SCA) requirements for access to custodial wallets and EMT transfers;
      • fraud reporting requirements; 
      • prudential requirements, including cumulative initial capital and own funds requirements for CASPs that are also authorized as PSPs;
    • de-prioritize enforcement of certain PSD2 provisions for EMT transactions, including
      • safeguarding requirements (where MiCA’s safekeeping requirements apply);
      • disclosure of exact charges and maximum execution times (where not technically feasible);
      • unique identifier requirements and SEPA Regulation provisions;
      • open banking account access requirements for operators of custodial wallets. 

    Will PSD3/PSR fix the problem? 

    The Opinion proposes two options to address the overlap between MiCA and PSD2 pathways.

    1. Amend MiCA. Use PSD3/PSR to amend MiCA to prescribe a single set of rules applicable to CASPs providing EMT-related payment services.

    2. Clarify the application of PSD3/PSR. Alternatively, specify in PSD3/PSR: (a) which EMT-related services fall within scope of PSD3/PSR; (b) which PSD3/PSR requirements apply to CASPs that provide such services; and (c) an exclusion for such CASPs from the requirement to obtain authorization under PSD3/PSR. 

    What should firms do?

    • Firms providing EMT-related payment services, such as stablecoin transfer services, in the EU should consider whether they fall within scope of PSD2 authorization requirements
    • Where such authorization requirements apply, firms should start taking steps to:
      • obtain appropriate authorization; 
      • partner with a firm that already has such authorization; or 
      • limit the scope of its stablecoin transfer services in the EU to avoid the authorization requirements.
    • Firms should engage with their NCAs to ensure compliance during the transition period and monitor PSD3/PSR legislative developments for the changes proposed by the EBA. 

    1. MiCA defines an EMT as "a type of crypto-asset that purports to maintain a stable value by referencing the value of one official currency".
    2. PSD3 will need to be transposed in the national laws of EU member states by that date and the PSR will apply directly in all EU member states.
    3. E.g. as a payment institution or an electronic money institution.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.

    Editorial Disclaimer

    Originally published before the Ashurst Perkins Coie combination. See disclaimer.