By Kristijan Sekereš

SEPA Instant in 2027: What Payment Institutions, E-Money Firms and Non-Euro Providers Must Build

smartphone, laptop and open notebook with a pen on a white desk

The first wave of the Instant Payments Regulation hit euro area banks in 2025. The second wave lands in 2027, on the providers the first wave skipped: payment institutions, e-money institutions, and every payment provider in an EU country that does not use the euro.

The dates are close. Payment and e-money institutions in the euro area must send and receive instant euro transfers by 9 April 2027. Banks in Czechia, Denmark, Hungary, Poland, Romania and Sweden must receive them by 9 January 2027, then send them, with Verification of Payee, by 9 July 2027. Payment and e-money institutions in those six countries get until 9 April 2027 to receive and 9 July 2027 to send.

What the 2025 wave changed for merchants and checkout is in our earlier article on instant payments and Verification of Payee. This one is for the other end of the transfer: the provider that has to build it.

Who Has to Do What, and When

The law is Regulation (EU) 2024/886, which amends the SEPA Regulation and covers credit transfers in euro only. Article numbers below are those of the SEPA Regulation as amended. The dates match the ECB's summary:

ProviderReceive instantSend instantVerification of Payee
Euro area banks9 January 20259 October 20259 October 2025
Euro area payment and e-money institutions9 April 20279 April 20279 October 2025
Non-euro area banks9 January 20279 July 20279 July 2027
Non-euro area payment and e-money institutions9 April 20279 July 20279 July 2027

The non-euro countries, per the EU's list of countries using the euro, are Czechia, Hungary, Poland, Romania and Sweden, plus Denmark, which has an opt-out.

Four details in that table catch people out.

The Verification of Payee date for euro area institutions is not a typo. The 2027 deferral for payment and e-money institutions sits in Article 5a, which covers sending and receiving. Article 5c, on Verification of Payee, has no such carve-out, so it has applied to every euro area provider since 9 October 2025. If you are a euro area institution offering credit transfers and your VoP is not live, that is a gap today.

Charge parity comes first in non-euro countries. Article 5b, which stops you charging more for an instant transfer than for a standard one, applies there from 9 January 2027.

Non-euro providers get extra time on out-of-hours sending. Until 9 June 2028, they need not send instant euro transfers from national-currency accounts during hours when they handle no standard euro transfers for those accounts. A regulator can also allow a per-transaction cap of at least EUR 25 000, based on the provider's access to euro liquidity (Article 5a(2)). Receiving is unaffected.

Bulgaria is now euro area. It adopted the euro on 1 January 2026, and Article 16(9) sets a transition of its own. If you are licensed there, read that paragraph rather than either row above.

What Has to Be Built

The legal text is short. The software underneath it is not.

A ledger that never closes

Every account reachable for credit transfers must be reachable for instant ones "24 hours a day and on any calendar day" (Article 5a(1)). When an order arrives, the payer's provider checks it, checks the funds, reserves or debits the amount and sends it on immediately.

This is usually the expensive part, because the ledger was built around business days. Look for:

  • End-of-day batch jobs that lock accounts or rebuild balances while they run.
  • Fee, interest and FX jobs that assume nothing posts overnight.
  • Safeguarding reconciliation that runs once per business day and now has to absorb credits at 3am on a Sunday.
  • Release practice. Downtime escapes penalties only if it is short, foreseeable planned maintenance (or scheme-wide planned downtime) announced to customers in advance (Article 11(1c)). A four-hour weekend release no longer fits.

Non-euro providers have one more item. An order from an account not held in euro counts as received only once converted into euro, and the conversion must happen immediately (Article 5a(3)(c)). Your rate source now works nights and weekends too.

Connectivity: direct or through a sponsor

The same Regulation amended the Settlement Finality Directive so that payment and e-money institutions can join designated payment systems directly, provided they document their safeguarding, governance and ICT arrangements and keep a winding-up plan (the new Article 35a of PSD2). The ECB states that since October 2025, non-bank providers meeting the TARGET Guideline requirements can access TIPS, the Eurosystem's instant settlement service.

Direct participation removes a dependency but hands you 24/7 liquidity management. Most smaller institutions will keep a sponsor bank, which changes the build less than people expect: you still need the always-open ledger, and the sponsor's API becomes part of your time budget. Before you sign, find out:

  • How inbound credits reach you, and how much of the 10-second window that takes.
  • What their planned downtime looks like and how you hear about it.
  • Whether they route Verification of Payee requests in both directions.
  • What happens when their call to you times out.

The 10-second window

The payee's provider must credit the payee and confirm to the payer's provider within 10 seconds of the payer's provider receiving the order (Article 5a(4)(c)). Without that confirmation, the payer's provider must immediately restore the payer's account and tell the payer (Article 5a(4)(e) and 5a(5)).

Ten seconds sounds generous until you split it across your systems, the sponsor, the clearing mechanism and the other provider:

  • Every synchronous check in the send path (limits, fraud scoring, AML rules) needs a hard time budget and a defined fallback.
  • The transfer needs an explicit state machine: reserved, sent, confirmed, rejected, timed out, reversed. Every transition must be idempotent.
  • A confirmation that arrives after your timer fired goes to an exception queue, never quietly posted.
  • On the receive side, crediting is a direct ledger write with a same-day value date (Article 5a(4)(d)), not a queue entry for the next batch.

Customers can set a maximum per day or per transaction and change it at any time (Article 5a(6)). Bulk files accepted for standard transfers must be accepted for instant ones (Article 5a(7)), and instant must be offered in every channel that offers standard transfers (Article 5a(4)(a)).

Verification of Payee: buy the service, build the integration

VoP is a scheme service. The VoP scheme developed by the European Payments Council defines how providers ask and answer, and the ECB notes that the Eurosystem offers its own VoP service, built on solutions from Banco de Portugal and Latvijas Banka and designed to that scheme. Commercial providers sell the same. Few institutions should write their own matching engine.

What you cannot buy is the integration into your own systems. It has two halves.

Requester side. Before a customer authorises a credit transfer, you check the IBAN against the name they typed, in every channel, and show the result (Article 5c(1)). The ECB lists the results as match, close match, no match and other; on a close match you show the name actually held on the account. The check must never stop the customer from authorising (Article 5c(5)), and business customers sending packages must be able to opt out (Article 5c(6)). Log every result against the payment: your protection from liability for a misdirected transfer depends on having met these requirements (Article 5c(8)).

Responder side. When another provider asks about one of your accounts, you answer from your customer data, and this is where data quality hurts. The payee's name means name and surname for a person and "the commercial or legal name" for a company (Article 2, point (1d)), so your responder needs both for business customers. If a payer supplies a company identifier you hold, such as an LEI or fiscal number, you must verify that too (Article 5c(1)(b)).

One case matters more for e-money institutions than for banks: accounts held on behalf of several payees, such as pooled client accounts and virtual IBANs. You must confirm whether the named payee is one of them (Article 5c(1)(c)), so the responder needs fast read access to your virtual IBAN mapping.

VoP is free to customers (Article 5b(2)), so the provider fee is a cost, not a revenue line.

Sanctions screening moves from the payment to the customer

A provider offering instant transfers must check its whole customer base against EU targeted financial restrictive measures (asset freezes and related prohibitions under Article 215 TFEU) as soon as new or amended measures enter into force, and at least once every calendar day. During an instant transfer, neither provider may screen payer or payee against those measures again.

In software terms:

  • An event-driven rescreen of all customers whenever the EU measures change, plus a full daily run, with hits handled at account level.
  • A documented change to the in-flight screening engine so it skips EU targeted measures on instant transfers.
  • Everything else stays: other restrictive measures and anti-money laundering checks are expressly left untouched (Article 5d(2)).
  • Data for the yearly report on rejections caused by targeted financial restrictive measures (Article 15(3)).

This is the one obligation where the Regulation sets the scale of the penalty: for a legal person, maximum fines of at least 10% of total annual net turnover (Article 11(1b)).

Charges and the app

An instant transfer may not cost more than a standard transfer of the corresponding type (Article 5b(1)). If you sell instant as a paid "express" option, that tariff goes. Put the parity rule in the fee engine, since you report charge levels to your regulator every year (Article 15(3)).

In the app and online banking, the work mostly assembles the pieces above: VoP before every confirm button, a screen for transfer limits, a status that resolves in seconds, and a clear message when a transfer times out and the money comes back.

Who Can Skip Most of This

If your packaged core or e-money platform already supports SEPA Instant and VoP, much of this is an upgrade and testing. Still check that your own batch jobs do not break the 24/7 promise, that the VoP module covers requester, responder and multi-payee accounts, and that screening follows Article 5d.

If you are a fintech on a banking-as-a-service platform where the provider holds the licence, the obligation is theirs and your work is the app and API integration.

This article is most useful if your ledger is in-house, heavily customised, or old enough to have a nightly batch at its heart.

How Ready the Sector Is

In a Celent survey of more than 100 financial institutions, commissioned by ClearBank (a bank that sells euro payment access to these firms, so read it with that in mind), one in five e-money and payment institutions said they already expected to miss the July 2027 deadline by up to six months.

The Regulation provides no general extension. The Commission must report on remaining obstacles to instant payments by 9 April 2027 (Article 15(6)), possibly with a proposal, but that lands on the euro area deadline itself. Plan against the dates in the text.

A Plan Working Back from the Deadline

As of early October 2026, a euro area payment or e-money institution has six months. A non-euro bank has three months to start receiving, with the holidays in the middle.

  1. October 2026: gap assessment. List every job and process that assumes business hours. Map every channel that can start a transfer. Measure how often legal and trading names differ in the data your VoP responder will use.
  2. By the end of November 2026: decide connectivity and providers. Direct or sponsor, a VoP provider chosen, contracts moving. Onboarding runs on other people's timetables, so start it first.
  3. December 2026 to February 2027: build. Real-time posting, the timeout state machine, VoP requester and responder, the screening and tariff changes, the channel screens.
  4. February and March 2027: test as if it were Sunday night. End to end against the sponsor's or clearing test environment, with injected timeouts, load at the hours your batch used to run, and a deployment during live traffic.
  5. Two to four weeks before the date: freeze.

Non-euro banks should compress this for the receive path into what is left of 2026, then repeat it for sending and VoP against 9 July 2027. Non-euro payment and e-money institutions also face two releases: receive by 9 April 2027, then send and VoP by 9 July 2027.

Where This Fits

The PSD3 and Payment Services Regulation guide covers what follows 2027, including the wider reach of Verification of Payee. The Wero integration guide shows what becomes possible once instant rails are everywhere.

We build and change payment software: ledgers and posting engines, sponsor bank and scheme integrations, VoP provider integrations, and the app and back-office screens on top. If you have a 2027 date and a ledger that still closes at night, write to office@c9group.dev.