Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

EDCA-P07 · Governed by EDCA-STD-08

Payment Services Security Certification

An assessment of an organisation that initiates, processes or settles payments. It examines how a payment order is authenticated, whether client funds are protected and can be reconciled, how merchants are settled, and what happens when a payment is refunded, reversed or disputed.

What this certification is not

This certification is an assessment of security and operational controls. It is not an authorisation as a payment institution or electronic money institution under Directive (EU) 2015/2366 or Directive 2009/110/EC, and it is not a licence, registration or approval by any competent authority. It does not assess prudential capital, governance or fitness and propriety requirements, which are reserved to the competent authority of the organisation's Member State.

Scope of assessment

The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.

  • Named payment services and the flows of funds they cover
  • Authentication and authorisation of payment orders
  • Arrangements for holding, segregating and reconciling client funds
  • Settlement to merchants and payouts to beneficiaries
  • Refund, reversal and dispute handling

What is examined

Each area below is assessed against the requirements of EDCA-STD-08, Payment Services Security, version 1.0.

  • Strong customer authentication and the exemptions relied upon
  • Protection and segregation of client funds
  • Integrity of the payment order from initiation to settlement
  • Merchant onboarding, settlement and reconciliation
  • Refunds, reversals, chargebacks and the records behind them
  • Fraud detection and transaction monitoring
  • Availability of the payment path and its behaviour under partial failure

Programme particulars

Programme code
EDCA-P07
Governing standard
EDCA-STD-08 — Payment Services Security, version 1.0, issued 28 July 2026
Levels available
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology
Typical duration
Ten to sixteen weeks from application to decision.
Surveillance
As required by the level held. See level requirements.

Evidence normally requested

The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.

  1. Authentication design and the exemption policy applied
  2. Safeguarding arrangements and reconciliation of client funds
  3. Ledger design, including evidence that a balance cannot go negative
  4. Merchant settlement records and reconciliation reports
  5. Refund, reversal and dispute logs with outcomes
  6. Fraud rules, their tuning history and their measured effect
  7. Incident records for failed, duplicated or misdirected payments

Apply for Payment Services Security Certification

Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.