Part 3 showed that stablecoin payments remove several of the protections that ordinary payments rely on. This is exactly why the activity is heavily regulated. Several different rules apply, and each one covers a different piece of the picture. Together they form a perimeter around the business.
This part explains the key terms in plain words first, because the regulation is easier to follow once the words are clear. Then it walks through the main rules and what each one does. This is the set of rules that matters for stablecoin payments. It is not the whole of crypto law, and it is written here at the level of what each rule is for, rather than article by article.
The terms you need first
E-money token, or EMT
An e-money token is a stablecoin that keeps its value by tracking one official currency, such as the euro or the dollar. In European law it is treated as a form of electronic money. The stablecoins used for payments are usually e-money tokens, so this is the term that matters most for this series.
Electronic Money Institution, or EMI
An Electronic Money Institution is a licensed firm that is allowed to issue electronic money and to hold customer funds for that purpose. On the money side of the business, a firm needs this kind of authorisation, or a banking licence, to issue an e-money token and to safeguard the money behind it.
Crypto-Asset Service Provider, or CASP
A Crypto-Asset Service Provider is a firm authorised to provide crypto services, such as holding crypto-assets for customers, exchanging between crypto and money, and transferring crypto-assets. On the crypto side of the business, a firm needs this authorisation to custody, exchange and move stablecoins.
Gas
Gas is the fee paid to the blockchain network to process and record a transaction. It pays for the computing work that adds the payment to the shared ledger. On some networks the amount rises and falls with how busy the network is.
The licences, and who grants them
To run stablecoin payments in the European Union, a firm usually needs authorisation on both sides. It needs to be an Electronic Money Institution or a bank for the money side, and a Crypto-Asset Service Provider for the crypto side. In Luxembourg these authorisations are granted by the Commission de Surveillance du Secteur Financier, known as the CSSF, which is the national financial regulator. Once granted, they can be passported across all European Union member states, which means the firm can operate in the whole Union on the strength of one authorisation.
MiCA, the core framework
MiCA is the Markets in Crypto-Assets Regulation, formally Regulation (EU) 2023/1114. It is the European Union law that brings crypto-assets and crypto services into a single framework across all member states. For stablecoin payments, two parts of it matter most.
The first part is the rules for e-money tokens. The issuer of an e-money token has to hold a full reserve behind it, has to let holders redeem their tokens at any time at face value, and has to meet clear disclosure and conduct rules. These are the rules that protect the peg and the promise from Part 3.
The second part is the rules for crypto-asset service providers. A service provider has to be authorised, has to protect the assets it holds for customers, has to have proper governance and controls, and is answerable if it fails. These are the rules that govern the firm doing the custody, the exchange and the transfers.
MiCA also contains rules against market abuse for crypto-assets that are traded on a platform. For payments these matter less, and they are mentioned here only so the picture is complete.
The e-money rules underneath
Because an e-money token is treated as electronic money, the older European rules on electronic money still apply to how it is issued and how customer funds are kept safe. This is the Second Electronic Money Directive, Directive 2009/110/EC, usually shortened to EMD2. MiCA sits on top of these rules rather than replacing them, so the safeguarding of customer money follows the established e-money approach.
The payment services rules
Moving money for customers is a payment service, so the European payment services framework applies to the payment side of the business. This is the Second Payment Services Directive, Directive (EU) 2015/2366, usually shortened to PSD2. It governs how payments are made securely and how customers are protected when they pay.
The Travel Rule, following the money
Part 3 noted that a public blockchain can let value move without anyone knowing who is behind it. The Travel Rule closes that gap. When crypto value is transferred, information about who is sending it and who is receiving it has to travel with the transfer. In the European Union this is set by the Transfer of Funds Regulation, Regulation (EU) 2023/1113. Its purpose is to make crypto transfers traceable for anti-money-laundering and sanctions checks, in the same way that bank transfers already are. It rebuilds one of the protections that a public ledger would otherwise remove.
DORA, keeping the technology resilient
All of this runs on technology, and much of that technology comes from outside providers such as custody platforms and cloud services. DORA, the Digital Operational Resilience Act, formally Regulation (EU) 2022/2554, requires financial firms to manage their technology risk properly. They have to control their own systems, oversee the providers they depend on, report serious incidents to the regulator, and test that they can keep running when something goes wrong. DORA is the rule that keeps the machinery behind the payments dependable.
Where each rule lands
No single rule covers stablecoin payments on its own. Each one closes a different gap. The e-money token rules protect the token and its reserve. The service provider rules govern the firm doing the work. The e-money directive governs how customer money is issued and safeguarded. The payment services directive governs the payment itself. The Transfer of Funds Regulation follows the money for anti-money-laundering purposes. DORA keeps the technology resilient. Placed side by side, they form the perimeter around the business.
| Rule | What it covers | Where it lands |
|---|---|---|
| MiCA, e-money token rules | The reserve, redemption at face value, and disclosure | The stablecoin itself |
| MiCA, service provider rules | Authorisation, protection of client assets, governance | The firm doing custody, exchange and transfers |
| EMD2 | Issuing electronic money and safeguarding customer funds | The money side beneath the token |
| PSD2 | Making payments securely and protecting customers | The payment service |
| Transfer of Funds Regulation | Sender and receiver information travelling with transfers | Every stablecoin transfer, for AML |
| DORA | Technology risk, provider oversight, incidents, testing | The technology and providers behind everything |
No single rule covers stablecoin payments. The protection comes from several rules working together, each one closing a different gap that the technology opened.
Where this goes next
These rules set out what a firm has to achieve. They say the reserve must be full, the client assets must be protected, the transfers must be traceable, and the technology must be resilient. What they do not do is run the business day to day. That is the job of governance, which turns these rules into a working operation with clear owners and real controls. Part 5 looks at how a firm actually does that.
Key takeaways
A short glossary for this part
| Term | Plain meaning |
|---|---|
| MiCA | The Markets in Crypto-Assets Regulation, the main European law for crypto-assets and crypto services. |
| E-money token (EMT) | A stablecoin that tracks one official currency and is treated as electronic money. |
| EMI | An Electronic Money Institution, licensed to issue electronic money and hold customer funds. |
| CASP | A Crypto-Asset Service Provider, authorised to custody, exchange and transfer crypto-assets. |
| Gas | The fee paid to the blockchain network to process a transaction. |
| Passporting | Using one authorisation from one member state to operate across the whole European Union. |
| Travel Rule | The requirement that sender and receiver information travels with a transfer. |
| DORA | The Digital Operational Resilience Act, the European rule on technology resilience in finance. |
| CSSF | The Commission de Surveillance du Secteur Financier, the financial regulator in Luxembourg. |