EDCA-P07 · Governed by EDCA-STD-08
Payment Services Security Certification
An assessment of an organisation that initiates, processes or settles payments. It examines how a payment order is authenticated, whether client funds are protected and can be reconciled, how merchants are settled, and what happens when a payment is refunded, reversed or disputed.
This certification is an assessment of security and operational controls. It is not an authorisation as a payment institution or electronic money institution under Directive (EU) 2015/2366 or Directive 2009/110/EC, and it is not a licence, registration or approval by any competent authority. It does not assess prudential capital, governance or fitness and propriety requirements, which are reserved to the competent authority of the organisation's Member State.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- Named payment services and the flows of funds they cover
- Authentication and authorisation of payment orders
- Arrangements for holding, segregating and reconciling client funds
- Settlement to merchants and payouts to beneficiaries
- Refund, reversal and dispute handling
What is examined
Each area below is assessed against the requirements of EDCA-STD-08, Payment Services Security, version 1.0.
- Strong customer authentication and the exemptions relied upon
- Protection and segregation of client funds
- Integrity of the payment order from initiation to settlement
- Merchant onboarding, settlement and reconciliation
- Refunds, reversals, chargebacks and the records behind them
- Fraud detection and transaction monitoring
- Availability of the payment path and its behaviour under partial failure
Programme particulars
- Programme code
- EDCA-P07
- Governing standard
- EDCA-STD-08 — Payment Services Security, version 1.0, issued 28 July 2026
- Levels available
-
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology - Typical duration
- Ten to sixteen weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Authentication design and the exemption policy applied
- Safeguarding arrangements and reconciliation of client funds
- Ledger design, including evidence that a balance cannot go negative
- Merchant settlement records and reconciliation reports
- Refund, reversal and dispute logs with outcomes
- Fraud rules, their tuning history and their measured effect
- Incident records for failed, duplicated or misdirected payments
Apply for Payment Services Security Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.