Core Tools
Infrastructure
Product previews
From zero to regulator-ready
See how ComplyBridge walks you through a full MiCA CASP application — from entity setup to final submission package.
See how it works →The AI that knows your firm
Reasons across the live EU rulebook and your own policies, KYB data, UBOs, and integrations.
Explore Copilot →Coverage · Payment Services
Your payment license, handled.
Applying as a payment institution, registering as an AISP, or already authorised and carrying the ongoing load — your gap analysis, policy suite and application pack are built here, from your own data. And when PSD3 lands, you'll cross with a delta report, not a project.

The framework
What is PSD2?
The Payment Services Directive is the EU's rulebook for moving money — who may execute payments, initiate them, or read account data, and on what terms. It opened banking to non-banks and banks' data to licensed third parties. If you touch a payment or a payment account in Europe, it governs you — and its successor, PSD3, is already agreed.
Four ways in. One of them is yours.
PSD2 isn't one license — it's a family of them. What you owe the regulator depends on which door you're walking through.
You execute payments, acquire, issue instruments or remit money. Full authorisation, €20K–€125K initial capital by service, passportable across the EEA. The main route — and the one detailed below.
You read account data but never touch the money. Registration instead of authorisation — no initial capital, but professional indemnity insurance and most of the conduct rulebook still apply.
Your payment volumes sit under the national threshold. A lighter national regime — faster in, but no passport, and you'll outgrow it. We build the file so the upgrade to full PI is an update, not a restart.
You issue e-money or run wallets — that's an EMI authorisation under EMD2, one page over. Worth knowing now: PSD3 merges EMIs into the PI regime, so the two doors are becoming one.
EMD2 coverage →Not sure which applies? That's the first question the readiness check answers.
Eight services. One authorisation.
Your authorisation is scoped to the services you name in Annex I — and your initial capital follows the heaviest of them.
Initial capital set by PSD2 Art. 7 at the level of the heaviest service you provide; ongoing own funds are calculated separately (Methods A/B/C) and NCAs may require more. AIS-only firms register rather than authorise, but must hold professional indemnity insurance.
The journey hasn't changed. Your side of it has.
From first assessment to authorisation — with months of preparation compressed into weeks, and the regulator's clock kept clean.
Shown for full PI authorisation — the main route. The same machinery runs AISP registrations, small-PI files, and EMI applications under EMD2.
The traditional route
12–18+ MONTHSWith ComplyBridge
Gap analysis, full policy suite, programme of operations and a validated application pack — generated from your data, scoped to the services you name.
Fixed by law, not by us. A complete, validated package means fewer RFIs and fewer clock-stops — we track every deadline and keep the application on course.
Safeguarding reconciliation, SCA and fraud reporting, incident response, passporting notifications. Authorisation is where this page ends — and where most of the platform's life is spent.
Document generation itself takes hours. The pace is set by how ready your inputs are.
What's next
PSD3 is coming. You'll already be compliant.
The successor framework is agreed: PSD3 and the Payment Services Regulation were provisionally agreed in November 2025 and are expected to apply from 2027, after a transition period. The headlines: PIs and EMIs merge into a single regime, fraud liability sharpens, SCA rules tighten, and open banking APIs become mandatory rather than fallback.
Existing licenses carry over — but your authorisation file, governance records and reporting won't update themselves. Because your policies and obligations live in ComplyBridge mapped to the article level, the transition arrives as a delta: what changed, which paragraph of which policy it touches, and what to do about it. Firms still on spreadsheets get a project. You get a task list.
Safeguarding, SCA, incident management and outsourcing policies pre-mapped to PSD2 and the EBA guidelines, populated from your specifics, version-controlled from day one.
License Builder compiles the pack — programme of operations, business plan, security policy — cross-references every requirement, and tells you what's missing before the NCA does.
Fraud reporting, incident classification and templated filings, safeguarding reconciliation checks, passporting notifications — for every year after the license.
Start from the other side — the readiness check maps your current obligations instead of your application. And with PSD3 agreed, your delta starts counting now. See how the ongoing side works →
FAQ
Common questions.
Find out how ready you are.
Two minutes of questions. A gap analysis mapped to PSD2's actual requirements — and PSD3's incoming ones — yours to keep either way.
Already authorised? See how the ongoing side works →