You already hold the licence. Build, buy, or use a technology provider?

If you hold an e-money or payment institution licence and you are weighing how to launch a card programme, there is a form you already file with your regulator that asks four of the questions you would otherwise be answering informally. Under DORA Article 28(3) you keep a register of information on every contractual arrangement for ICT services, and where the service supports a critical or important function you fill in template B_07.01 of Commission Implementing Regulation (EU) 2024/2956, which you submit annually and which the European Supervisory Authorities use to decide which providers get designated critical at Union level. Ten of its fields are mandatory, and four of them are the build-versus-buy question in miniature: how substitutable is this provider, is there an exit plan, could the service come back in-house, and what is the impact if it stops. A fifth asks whether you have identified alternative providers at all. For the impact question, one of the four permitted answers is assessment not performed.
I should say where I sit, and say it properly. HOPPA is a technology provider, which makes us one of the three options here and means I am not placed to referee a category we compete in. There is a second disclosure that matters more, and I have not seen anyone else make it: redundancy across multiple financial institutions is what we sell, so the concentration argument later in this piece is an argument for our architecture at the same time as it is an argument against our category. Discount it accordingly. What follows leans on what supervisors have published rather than on my view of which option wins.
The compliance read: what does not move
The simple version is that outsourcing moves work but not responsibility. The European Banking Authority's outsourcing guidelines say outsourcing cannot result in the delegation of the management body's responsibilities, and PSD2 Article 20(2) puts it in harder terms still, providing that a payment institution remains fully liable for the acts of any entity it outsources to.
The deeper version is procedural. PSD2 Article 19(6) requires you to tell your home competent authority when you intend to outsource operational functions of payment services, and DORA Article 28(3) requires notice of a planned arrangement supporting a critical or important function, with no microenterprise carve-out even though the strategy obligation in 28(2) has one, so a small EMI sits inside this whether or not it feels like it should.
That being said, I want to be even-handed about the other side of the ledger, because most writing on this subject is not. A provider absorbs real work as well as creating it — PCI DSS scope, the building and evidencing of ICT controls, certification maintenance, and the scheme mandate cycle that lands every year whether or not you have someone to read it. Nor does building make the regime disappear, since cloud, key management, fulfilment, BIN sponsorship and identity checks all stay third-party arrangements with their own register entries, which means building shrinks the outsourcing surface rather than removing it.
The commercial read, which points the other way
Card economics are capped at the top and squeezed underneath. The Interchange Fee Regulation limits consumer debit interchange to 0.2% and credit to 0.3%, with commercial cards and three-party schemes outside those caps and scheme fees outside them altogether, and the European Commission's 2020 review found issuers lost EUR 2,950 million a year through lower interchange combined with higher scheme fees. The UK's Payment Systems Regulator found in March 2025 that core fees charged to acquirers rose at least 25% in real terms between 2017 and 2023, with little evidence they tracked costs — a UK regulator on UK-related transactions, so directional rather than law here.
The finding I would act on is about bargaining position. The PSR found scheme incentives to issuers that in some cases more than totally offset the core fees charged to them, with incentive ratios varying significantly by the size of the issuing portfolio, which read one way argues for aggregation, since a small book negotiating alone will not reach the terms a large one does. But those incentives are paid to whoever holds the scheme licence and the BIN, so if your programme runs on someone else's BIN they accrue there, and I have found nothing published establishing what is passed through underneath — the PSR redacted every issuer-side figure, so the direction is on the record and the size of it is not. Put that question to every provider you shortlist, us included, because a reluctance to show the calculation is itself an answer.
The technical read: deciding before you are allowed to know
Certification is where building becomes hard to price, and it is the part I see underestimated most often. PCI DSS v4.0.1 is the current standard and the 51 requirements the PCI Security Standards Council originally future-dated took effect on 31 March 2025, while EMVCo publishes approval categories but no durations. I have found no published scheme certification requirements at all, and in my experience they arrive after a licence or a provider agreement is signed, which I offer as an operator observation rather than from a document.
There is a further gate that catches people out, and it is not the software, because holding an EMI licence does not make you a scheme member. Principal membership is a separate application with its own fees, collateral and certification timeline, the terms are not published, and in the programmes I have seen it is the long pole rather than the platform. Consequently the option whose cost is least knowable in advance is the one you build, while the option arriving with a number attached is the one somebody is selling you, which tells you who had to publish a price rather than which is cheaper.
The concentration read: a provider is not a stable end state
The register comes back here, because DORA Article 29 requires you, before signing, to assess whether you are contracting a provider that is not easily substitutable and to weigh the insolvency law that would apply if it failed. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers at Union level, and the fact worth noticing for anyone running cards is what is absent from that list: no card processor, no scheme processor, nobody from the issuing stack. Which cuts against the argument I am about to make, so take the argument with that in mind.
Designation binds you and not only the provider, because under Article 31(12) you may use a designated third-country provider only if it establishes a Union subsidiary within twelve months, and under Article 42(6) a competent authority may, as a last resort, require firms to suspend the use of a critical provider's service and where necessary terminate the contract. No negotiation prevents that, which is why the transition period in Article 30(3)(f) is a clause worth arguing over rather than boilerplate. And the data feeding designation is the register itself: Delegated Regulation (EU) 2024/1502 sets the thresholds at 10% of the entities in a category, computed from the registers firms file, and payment institutions and electronic money institutions are two separate categories under DORA — so a provider serving no banks can cross that threshold on its EMI book alone, on numbers its clients submitted. Crossing it is not designation, since the other sub-criteria and a qualitative assessment apply on top, but it is the door.
Which brings me to the part I think is most under-discussed. Article 28(8) requires an exit plan for ICT services supporting critical or important functions, documented and periodically tested, and Article 30(3)(f) contemplates exit either to another provider or back in-house. ECB Banking Supervision reported in February 2025, on year-end 2023 data, that 82% of critical functions outsourced by significant institutions to external providers are difficult or impossible to substitute, and 95% of those difficult or impossible to reintegrate. Three caveats before anyone quotes that back at me: ICT is 51% of that population, so half sits outside Article 28(8); the sample is banks with decades of core-platform integration rather than EMIs; and the ratings are the institutions' own entries in their own registers, which means a piece arguing for honest self-assessment is resting its headline number on self-assessment of unknown honesty. The shape is still uncomfortable enough to sit with, because the exit you are required to hold may be one you cannot execute, and a firm that has never built any part of the stack has given up one of the two exits the Regulation contemplates.
Where each option wins
I said I would not referee this, so rather than a recommendation, here is where the supervisory material points in each direction, stated the same way for all three.
Building is where the register argument lands hardest: it is the option that keeps reintegration live, and it is indicated where the capability is the product rather than the plumbing under it, where your volume is large enough to hold the scheme relationship directly, and where the honest entry against substitutability would otherwise be "not substitutable". Licensing a platform and running it yourself is the option the PSR's incentive evidence points at, since it keeps the scheme relationship and the BIN with you, which is where the pass-through question resolves, and it keeps your substitutability answer improvable because you can change platform without moving the programme — paid for in certification and the membership application above. Using a provider is where the commercial and technical readings point, because it is the option that absorbs certification and scheme mandates and prices the thing you cannot price yourself, and it suits a programme that is not your differentiator and an exit plan that honestly runs to another provider. It is also the option this article argues against hardest, in the section immediately above, and it is the one we sell.
What I am not sure about
The licensing regime is not final. Neither PSD3 nor the Payment Services Regulation has been adopted, and the European Parliament's file records committee approval of the negotiated text on 5 May 2026 and an indicative plenary date of 14 December 2026, awaiting the Council's first reading position — so anyone quoting firm re-authorisation dates is quoting a proposal rather than law.
The outsourcing guidelines are being replaced. The EBA consulted until October 2025 on draft guidelines for non-ICT arrangements, and I have found no final version, so the framework above is correct today and moving.
The substitutability evidence is not about us. I have found no published figure for EMI card programmes, and EMI programmes do change processors, so the picture may be better than the ECB's banks — which is why the register field matters, because filling it in generates the only number actually about your firm.
And one I would like answered. I have found no case where a competent authority has exercised Article 42(6) and ordered a firm off a critical provider, and since the power is eighteen months old and the designations nine, silence is unsurprising — but until it is tested I would negotiate the transition period as though it will be used.
What I would do this quarter
Complete B_07.01 honestly before you sign rather than after, because it is already mandatory, it already goes to your regulator, and it is among the cheapest diligence available — and if the honest answer to the impact question is assessment not performed, you have learned something useful about the decision in front of you.
I would rather you weighed the argument against our category before signing than after, which is why it is in here twice. The question I would ask in your seat is narrow: if your provider gave you ninety days, do you know what the migration would cost, and has anyone written the number down?
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 2, 28, 29, 30, 31, 42 and 64 — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
Supports: Application from 17 January 2025 and scope covering payment and e-money institutions including exempted ones; that the financial entity remains fully responsible for ICT obligations; the required contractual terms and exit provisions; the concentration assessment; the twelve-month Union subsidiary requirement; and the competent authority's power to require suspension or termination.
- EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), paragraphs 35, 54, 55 and 106–108 — https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-outsourcing-arrangements
Supports: That outsourcing cannot delegate the management body's responsibilities; that the register requires nine fields for every arrangement and eleven more for critical or important ones, including the substitutability rating and the reintegration assessment.
- Directive (EU) 2015/2366 (PSD2), Articles 19(6) and 20(2) — https://eur-lex.europa.eu/eli/dir/2015/2366/oj
Supports: That outsourcing an important operational function shall not delegate senior management's responsibility, and that payment institutions remain fully liable for the acts of entities to which activities are outsourced.
- Regulation (EU) 2015/751 (Interchange Fee Regulation), Articles 1, 3 and 4 — https://eur-lex.europa.eu/eli/reg/2015/751/oj
Supports: The 0.2% debit and 0.3% credit consumer interchange caps, and the exclusion of commercial cards and three-party schemes.
- Commission Delegated Regulation (EU) 2024/1502, Articles 2, 5 and 6 — https://eur-lex.europa.eu/eli/reg_del/2024/1502/oj
Supports: That the criticality thresholds are set at 10% calculated per category of financial entity, and are computed from the registers of information filed by financial entities.
- ESAs, designation of critical ICT third-party service providers, 18 November 2025 — https://www.bankingsupervision.europa.eu/press/supervisory-newsletters/newsletter/2025/html/ssm.nl250219_2.en.html
Supports: That 82% of critical outsourced functions are difficult or impossible to substitute, of which 95% are difficult or impossible to reintegrate.
- European Commission, SWD(2020) 118 final, report on the application of Regulation (EU) 2015/751 — https://competition-policy.ec.europa.eu/system/files/2021-10/IFR_report_card_payment.pdf
Supports: That issuers lost EUR 2,950 million per year from lower interchange combined with higher, unregulated scheme fees.
- UK Payment Systems Regulator, MR22/1.10, market review of card scheme and processing fees, final report, March 2025 — https://www.psr.org.uk/publications/market-reviews/mr22110-market-review-of-card-scheme-and-processing-fees-final-report/
Supports: That average core scheme and processing fees charged to acquirers rose at least 25% in real terms between 2017 and 2023; that issuer incentives in some cases more than offset core fees; that incentive ratios vary with issuing portfolio size; and that issuer-side figures are redacted in the public report.
- PCI Security Standards Council, PCI DSS v4.x future-dated requirements — https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x
Supports: That 51 of the 64 new requirements took effect on 31 March 2025, and that v4.0.1 is the active standard.
- EMVCo, product approval process — https://www.emvco.com/processes-forms/product-approval/
Supports: That EMVCo publishes product approval categories but no durations or timelines.
- EBA consultation on draft Guidelines on the sound management of third-party risk (non-ICT), 8 July 2025 — https://eba.europa.eu/publications-and-media/press-releases/eba-launches-consultation-its-draft-guidelines-third-party-risk-management-regard-non-ict-related
Supports: That the draft guidelines provide for repeal of the 2019 outsourcing guidelines, and that the consultation ran to October 2025
- European Parliament Legislative Observatory, procedures 2023/0209(COD) and 2023/0210(COD) — https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2023%2F0210%28COD%29
Supports: That neither PSD3 nor the PSR has been adopted; committee approval of the negotiated text on 5 May 2026; indicative plenary date 14 December 2026.
