The Malta Independent 23 July 2026, Thursday
View E-Paper

Law report: Navigating the regulatory overlap between MiCA and PSD2

Ganado Advocates Wednesday, 3 September 2025, 10:02 Last update: about 12 months ago

Emma Attard Bondi

One 10 June 2025, the European Banking Authority (EBA) issued an opinion addressing the complex regulatory overlap between Regulation (EU) 2023/1114 on Markets in Crypto-Assets Regulation (MiCA) and Directive (EU) 2015/2366 on payment services in the internal market (PSD2). The EBA Opinion provides essential guidance for national competent authorities (NCAs) on how to address the dual classification of electronic money tokens (EMTs) during the transitional period leading up to the coming into force of the proposed Third Payment Services Directive (PSD3) amending Directive 98/26/EC and repealing Directives 2015/2366/EU and 2009/110/EC and the new Payment Services Regulation (PSD3/PSR).

The interplay between MiCA and PSD2 stems from the fact that EMTs, defined under MiCA as "electronic money", also fall under the broader definition of "funds" under PSD2. This dual classification means that Crypto Asset Service Providers (CASPs) offering services related to EMTs may need to obtain two separate authorisations to perform what is essentially a single financial activity. The EBA Opinion seeks to clarify these issues, proposing both immediate transitional measures and long-term legislative solutions.

 

Classification of payment services

To reduce regulatory ambiguity, the EBA provides clear guidance to NCAs on which EMT-related activities fall under PSD2 and which do not.

The EBA advises NCAs to consider (i) transfers of crypto assets (which refers to the transfer of crypto assets refers to the facilitation of a transfer of EMTs from one digital address to another on behalf of a client) and (ii) custody and administration of EMTs (which refers to the holding of EMTs in a custodial wallet, or, as regarded under PSD2 as a payment account, that allows transfers to and from third parties) as payment services.

The EBA clarifies that certain activities should not be classified as payment services, preventing unnecessary licensing requirements. These services include the (i) exchange of crypto assets and (ii) the intermediation of purchase, meaning facilitating the purchase of any crypto asset using EMTs. Also, whilst this is not addressed in the EBA Opinion, it is understood that transfers of an EMT, which constitute a consideration of the exchange, should also not be regarded as a payment service.

 

 

Priority and non-priority considerations for compliance

The EBA advises NCAs to prioritize enforcing specific PSD2 provisions for licensed entities, specifically relating to capital and own funds requirements, the implementation of security measures and fraud reporting. In relation to the former, the EBA is of the opinion that a CASP's capital requirements under MiCA and PSD2 must be applied cumulatively, ensuring that the CASP has enough financial resources to cover their risks. With regards to the latter, the EBA stresses the importance of robust security measures, giving particular importance to Strong Customer Authentication (SCA) and the reporting of payment fraud. However, the EBA advises NCAs not to prioritise the supervision and enforcement of these requirements on SCA and fraud reporting until 2 March 2026.

Conversely, the EBA also advises NCAs not to prioritise enforcing certain PSD2 provisions during the transition period. In particular, with respect to consumer protection, NCAs should not prioritize enforcing rules on disclosing exact charges (e.g., gas fees) or maximum execution times, as these are often unpredictable with crypto assets. The use of unique identifiers (such as an IBAN) and open banking provisions are also non-priority areas. Further, the EBA advises against prioritizing PSD2's safeguarding rules for EMTs. This is because MiCA already has its own specific safekeeping requirements for CASPs, making PSD2's rules redundant and unnecessary.

 

Authorisation and transitional period

The EBA has established a transitional period until 1 March 2026, for CASPs to work toward obtaining the necessary PSD2 authorisation if they provide EMT-related payment services. After this date, NCAs are instructed to prevent entities without a PSD2 license or a partnership with a Payment Service Provider (PSP) from offering these services. This gives CASPs a two-fold approach authorisation: either obtain their own PSD2 license or partner with a licensed PSP, each option having their own advantages and disadvantages.

While the partnership option may seem like a faster route, in practice, it is not straightforward to identify a legally sound arrangement to fit squarely within both the MICA and PSD2 frameworks, considering the services are inextricably linked. A single service involving an EMT will indivisibly and concurrently comprise both a crypto asset service and a payment service, making it difficult to separate the two.

Whilst the EBA Opinion recommends that NCAs streamline the application process by reusing information already submitted during a CASPs MiCA authorisation and applying, where appropriate, existing PSD2 exemptions, CASPs will still be expected to strengthen their governance framework and internal controls and address any gaps in documents or information already submitted.

 

Strengthening governance and way forward

Drawing from the suggestions and recommendations made by the EBA it is anticipated that a CASP would need to review and amend several key documents and information previously submitted to their NCAs when obtaining their MiCA authorisation, to now align with PSD2. It is our understanding that a CASP would potentially need to:

  • update its programme of operations to detail how EMT-related payment services will be conducted, ensuring PSD2 operational standards are met;
  • strengthen governance frameworks and internal controls to cover both MiCA and PSD2 obligations. This involves maintaining a robust Compliance Monitoring Plan and an Enterprise Risk Framework to manage risks associated with EMT-related payment services and prevent fraud;
  • update and reassess the organisational structure and internal management of the CASP and ensuring that the experience and suitability of key personnel. Potentially, the CASP might also need to strengthen its Board of Directors and appoint new members holding specific knowledge and experience in relation to payment services.

Beyond updates, CASPs must prepare and submit entirely new information to fill regulatory gaps which arise between the different authorisation requirements under MiCA and PSD2. Understandably, taking into account PSD2 requirements, we would assume that, apart from being required to provide clear evidence that they meet the cumulative capital requirements under both MiCA and PSD2, the CASP would be expected to:  

  • implement enhanced security monitoring systems and policies. It should be noted that while MiCA addresses general ICT risks, PSD2 has specific requirements for monitoring and reporting security incidents related to payment services;
  • establish and document robust policies for the secure collection, processing, and storage of this data to be aligned with the strict requirements for handling sensitive payment data under PSD2;
  • implement systems to accurately collect and report statistical data on payment transactions and fraud, as mandated by PSD2;
  • establish a comprehensive Security Policy specifically for PSD2 requirements. This policy would potentially need to detail technical and organisational security measures, including SCA and fraud reporting. This policy would possibly need to also outline the CASP's strategy to apply SCA when users access wallets or initiate EMT transfers.

 

Long-Term legislative suggestions

The EBA explicitly recommends that the future PSD3/PSR frameworks should be adapted to prevent the administrative burden of dual authorization. It proposes two long-term solutions. The first option is to amend MiCA to explicitly state that crypto-asset services fall solely under its purview, ensuring that a CASP offering EMT-related payment services only needs a MiCA license. This would require strengthening MiCA's provisions to meet the same level of consumer protection and security as PSD2. An alternative is to create a specific regime within PSD3/PSR for already-licensed CASPs, allowing them to provide EMT-related services through a streamlined notification process rather than a second, full authorization.

 

Conclusion

The EBA Opinion serves as a crucial guide for managing the complex regulatory overlap between MiCA and PSD2. It addresses legal uncertainties by providing a clear transitional period and clarifying the classification of payment services. This represents a crucial first towards creating a coherent regulatory environment which supports innovation, consumer protection and market integrity.

 It is clear that CASPs face a significant and immediate obligation to strengthen their governance and operational frameworks. This includes the need to demonstrate cumulative capital and implement robust security measures, However, the EBA's guidance given to NCAs on the authorisation process and its prioritisation of specific clauses, aims to ensure a smoother, less burdensome, transition.

 

Emma Attard Bondi is a Legal Trainee at Ganado Advocates


  • don't miss