This No Action letter from the EBA clarifies the interplay between the MiCA regulation on crypto-assets and the PSD2 directive on payment services, particularly for crypto-asset service providers dealing with electronic money tokens. It provides guidance to national regulatory authorities on which electronic money token transactions should not be considered payment services and the associated authorization…
This document is an Opinion (No Action letter) published by the European Banking Authority (EBA) on 10 June 2025. It addresses the interaction between Directive (EU) 2015/2366 (PSD2) and Regulation (EU) 2023/1114 (MiCA) concerning crypto-asset service providers (CASPs) conducting transactions with electronic money tokens (EMTs). The scope covers regulatory, authorization, consumer protection, security, and supervisory aspects applicable to CASPs in the European Union, for the transitional period until the future entry into force of PSD3 and the Payment Services Regulation (PSR). The document comprises 33 pages, approximately 30 of which are provided here.
The EBA responds to a request from the European Commission dated 6 December 2024 aiming to clarify the articulation between MiCA and PSD2 for CASPs handling EMTs. The document aims to advise: (i) European institutions on a sustainable solution via PSD3/PSR legislation, and (ii) national competent authorities (NCAs) on transitional management (2-3 years) before PSD3/PSR comes into force. The EBA recommends that NCAs consider as payment services under PSD2 the transfers and custody of EMTs performed by CASPs for their clients, as well as custodial wallets as payment accounts. PSD2 authorization must be required through simplified procedures, with a transition period until 1 March 2026. After this date, only entities holding a PSP license or in partnership with a PSP may provide these services. Certain PSD2 provisions (e.g., fee disclosure, execution time, unique identifier, open banking) should not be prioritized in supervision, while others (strong authentication, fraud reporting, own funds) must be applied. Exchanges of crypto-assets for funds or other crypto-assets are not payment services and do not fall under PSD2. The EBA highlights that dual MiCA and PSD2 authorization is undesirable due to disproportionate burden, overlaps, and complexity for authorities. It advocates that a financial activity be regulated by a single legal framework. In the long term, it recommends strengthening MiCA via PSD3/PSR to integrate key PSD2 requirements adapted to DLT specifics, thus avoiding dual authorization. Excluding EMTs from the scope of PSD3/PSR without strengthening MiCA is deemed unacceptable as it causes confusion, consumer risks, and regulatory arbitrage. The opinion applies to all entities providing services related to EMTs, whether already licensed CASPs or PSPs, or under MiCA transitional regime.
MiCA regulates services related to crypto-assets and the authorization of CASPs, while PSD2 regulates payment services in the EU. EMTs have a dual nature: crypto-assets under MiCA and electronic money/funds under PSD2. This duality creates regulatory overlap, notably for EMT transfer and custody services, raising the issue of dual MiCA and PSD2 authorization. The European Commission identified interpretation divergences among Member States, risks of regulatory arbitrage, and consumer harm. It requested the EBA, in coordination with ESMA, to issue an Opinion to clarify the situation, notably regarding the application of PSD2 authorization requirements to CASPs handling EMTs. The objective is to ensure security, trust, and competitiveness of the payment market while avoiding disproportionate burden for actors and authorities. The opinion aims to guide NCAs during the transitional period before PSD3/PSR entry into force and to propose long-term legislative solutions.
- Definition and scope: EMTs are considered electronic money under MiCA and funds under PSD2. Transfers of EMTs carried out by CASPs for their clients are payment services within the meaning of PSD2. Custodial wallets are treated as payment accounts. Conversely, exchanges of crypto-assets for funds or other crypto-assets, conducted on own account by CASPs, are not payment services and do not fall under PSD2 (p. 1-2, 8-9, 18-22).
- Authorization: CASPs must obtain MiCA authorization. Payment services related to EMTs require PSD2 authorization, which may lead to dual authorization. The EBA recommends avoiding this dual requirement by strengthening MiCA via PSD3/PSR or, failing that, by adapting PSD3/PSR to integrate requirements without requiring new authorization. During the transitional period, NCAs must apply simplified procedures and grant a deadline until 1 March 2026 (p. 2-3, 9-11, 22-26).
- Capital and own funds: Initial capital and own funds requirements of MiCA and PSD2 apply cumulatively to hybrid entities. NCAs must ensure CASPs are informed of eligible elements and apply rules proportionately, without unjustified increase or decrease related to hybridity. The EBA proposes granting NCAs leeway to adjust requirements based on risks (p. 11-13, 24-25).
- Consumer protection: PSD2 imposes strict rules on transparency, rights and obligations, error management, and liability. MiCA is less detailed on these aspects. The EBA recommends strengthening MiCA by integrating key PSD2 provisions adapted to DLT specifics, notably on fee communication, execution times, unique identifier, and dispute management. Some PSD2 requirements are difficult to apply to on-chain transactions (e.g., exact fees, execution time); a pragmatic approach is advocated (p. 13-15, 26-28).
- Security and strong customer authentication (SCA): PSD2 requires SCA to secure electronic payments. MiCA does not provide equivalent requirements. The EBA highlights high fraud risks on EMTs (e.g., private key compromise, sophisticated attacks such as the Bybit hack in 2025). It recommends applying SCA to access to custodial wallets and EMT transfers, with a transitional period until 1 March 2026 to allow compliance. Fraud reporting must also be applied (p. 14-16, 28-30).
- Safeguarding/Safekeeping: MiCA imposes specific EMT custody requirements for CASPs. The EBA advises not to prioritize PSD2 safeguarding supervision to avoid duplication. It recommends clarifying precise obligations in MiCA and excluding EMTs from PSD3 safeguarding requirements, while maintaining obligations for EMT issuers (p. 16-17).
- Open Banking: The EBA advises not to prioritize PSD2 Open Banking supervision for CASPs providing EMT-related services. It recommends clarifying in MiCA or PSD3/PSR whether these provisions apply to CASPs and custodial wallets, consistent with the future Financial Data Access Regulation (FIDA) (p. 17).
- Long-term legislative approach: The EBA advocates strengthening MiCA via PSD3/PSR to integrate PSD2 requirements adapted to EMTs, thus avoiding dual authorization. If not possible, PSD3/PSR must clarify scope and applicable requirements for CASPs without requiring new authorization. Total exclusion of EMTs from PSD3/PSR scope without strengthening MiCA is rejected (p. 2-3, 6-7, 13-14, 25-26).
- Established facts: EMTs have a dual legal qualification under MiCA and PSD2, creating regulatory overlap. Transfers of EMTs by CASPs for their clients are payment services subject to PSD2. Own-account crypto-asset exchanges are not payment services. Dual MiCA and PSD2 authorization is a reality but causes disproportionate burden. Capital requirements apply cumulatively. SCA significantly reduces fraud, which is high in the crypto sector. Some PSD2 requirements are technically difficult to apply to DLT.
- Assumptions: Strict application of PSD2 to all EMT services without technical adaptation is unrealistic. Strengthening MiCA via PSD3/PSR is possible and desirable. NCAs can manage the transitional period with adapted prioritizations.
- Interpretations: The EBA considers regulation must be unified to avoid confusion and regulatory arbitrage. It believes MiCA must be strengthened to cover EMT risks as PSD2 does for traditional payments. The transitional period should allow gradual adaptation.
- Uncertainties: The precise evolution of PSD3/PSR and the capacity to integrate PSD2 requirements into MiCA remain to be defined. Application of rules to custodial wallets and qualification of unique identifiers on DLT require legislative clarifications.
- The EBA recommends European institutions use the PSD3/PSR legislative process to strengthen MiCA by integrating key PSD2 requirements adapted to EMTs and DLT specifics, to avoid dual authorization and ensure a comparable level of user protection.
- Failing that, PSD3/PSR must clarify scope and provide a specific regime for CASPs without requiring new authorization, with enhanced cooperation among NCAs.
- Excluding EMTs from PSD3/PSR scope without strengthening MiCA is rejected.
- For the transitional period until 1 March 2026, NCAs must apply EBA advice: require simplified PSD2 authorization for EMT transfer and custody services, grant a transition period, not prioritize certain PSD2 requirements difficult to apply, apply SCA and fraud reporting with a tolerance period.
- NCAs must cooperate closely and streamline authorization procedures.
- The EBA emphasizes the need for coherent, clear, and proportionate regulation to guarantee trust, security, and competitiveness of the payment market integrating crypto-assets.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.