Skip to content
BaFin · Germany

BaFin licence for a fintech in Germany — which authorisation you actually need

Fintech Passport
August 4, 2026 · 10-min read
BaFin licence for a fintech in Germany — which authorisation you actually need

“We need a BaFin licence” is not a plan — Germany has five separate authorisation regimes for financial activity, and the one you need is decided by what you actually do with customer money, not by what you call the product. A payment institution licence, an e-money licence, a bare registration, a full banking licence and a crypto-asset authorisation all come from the same supervisor, and none substitutes for another. Getting it wrong is expensive in a specific way: firms discover mid-application that their capital is set for the wrong category, or that the feature they treated as an add-on is the one pushing them into banking supervision. This piece maps the decision, with the statutory hooks and the capital figures.

1. The five regimes, and who lands where

German financial supervision is not organised around fintech business models. It is organised around statutes, and each statute has its own gateway:

RegimeStatuteGatewayMinimum capital
Payment institutionZAGErlaubnis, § 10(1)€20,000 / €50,000 / €125,000
E-money institutionZAGErlaubnis, § 11(1)€350,000
Account information serviceZAGRegistrierung, § 34Professional indemnity cover
CRR credit institutionKWGErlaubnis, § 32Set by CRR/KWG
Investment firmWpIGErlaubnisSet by IFR/IFD class
Crypto-asset service providerMiCAR / KMAGAuthorisation or Art 60 notificationSet by MiCAR class

The first filter is therefore not “are we a fintech” but “which statute names our activity” — and a firm sitting in two of them holds two permissions, not a blended one.

2. Start with the ZAG service catalogue, not the pitch deck

Under § 10(1) of the Zahlungsdiensteaufsichtsgesetz (ZAG), written permission from BaFin is required to provide payment services commercially or on a scale requiring a commercially organised business. § 11(1) does the same for issuing e-money. What counts as a payment service is an enumerated list in § 1(1) sentence 2, and the numbering matters because the capital tiers reference it:

  • 1. Einzahlungsgeschäft — enabling cash placement onto a payment account.
  • 2. Auszahlungsgeschäft — enabling cash withdrawal from a payment account.
  • 3. Zahlungsgeschäft — executing payment transactions (direct debits, cards, credit transfers) without an associated credit line.
  • 4. Zahlungsgeschäft mit Kreditgewährung — the same, where the transaction is covered by a credit facility.
  • 5. Akquisitionsgeschäft — issuing payment instruments, or acquiring and settling payment transactions.
  • 6. Finanztransfergeschäft — money remittance, where no payment account is opened in either party’s name.
  • 7. Zahlungsauslösedienste — payment initiation.
  • 8. Kontoinformationsdienste — consolidated account information.

Map every user-facing feature onto that list first. A wallet that stores value and settles at merchants is not one service — it is typically e-money issuance plus an acquiring limb, with different consequences for each.

3. The capital tiers in § 12 ZAG

§ 12 no. 3 ZAG sets initial capital by reference to the catalogue above, and the steps are steep:

  • €20,000 — money remittance only (no. 6 alone).
  • €50,000 — payment initiation only (no. 7 alone).
  • €125,000 — any of the payment services in nos. 1 to 5.
  • €350,000 — e-money issuance.

Two traps sit in that list. First, the €20,000 and €50,000 figures apply only to the pure single-service cases; add one adjacent feature from nos. 1 to 5 and the requirement is €125,000. Second, where the applicant is simultaneously a credit institution or a securities firm, the higher requirement under the banking or securities regime applies instead — you do not get to use the ZAG figure as a ceiling. Initial capital is also only the entry price: ongoing own funds are calculated under the ZAG-Instituts-Eigenmittelverordnung, and that answer is normally larger.

4. Account information: registration, not licence

Pure account information services are the one payments activity Germany handles by Registrierung under § 34 ZAG rather than by Erlaubnis. There is no initial-capital figure; the substitute safeguard is professional indemnity cover. This is a genuinely lighter route, and it is also a trap for scope creep: the moment the product initiates a payment rather than only reading account data, it becomes a § 10 payment service at the €50,000 tier — and a registration does not stretch to cover it.

5. The KWG boundary — where a payments firm becomes a bank

The hardest line to see from inside a product team is the one into the Kreditwesengesetz (KWG). Deposit-taking and lending on own account are banking business requiring an Erlaubnis under § 32 KWG, with capital and governance in a different league. Payment institutions and EMIs may hold customer funds, but they hold them as safeguarded funds against a payment or e-money claim — not as repayable deposits, and they may not on-lend them. Two product ideas cross the line more often than teams expect: paying interest on stored balances, and any facility where the firm advances its own funds beyond the narrow credit permitted under catalogue no. 4. If either is on the roadmap, resolve the KWG question before filing a ZAG application, because the answer determines which application you file.

6. Crypto: MiCAR, the KMAG, and the notification shortcut

Crypto-asset services are now governed by Regulation (EU) 2023/1114 (MiCAR), implemented in Germany principally through the Kryptomärkteaufsichtsgesetz (KMAG). Two points matter for an already-licensed payments firm.

First, there is a shortcut. Article 60 MiCAR lets certain already-authorised financial entities provide crypto-asset services on notification rather than a fresh authorisation, filed at least 40 working days before first providing the service; the competent authority has 20 working days to check completeness, and any request for missing information adds up to a further 20 working days that do not count against the 40. But the scope is narrow and asymmetric: a credit institution can notify across the range, an investment firm only for services equivalent to its MiFID permissions, and an electronic money institution only for custody and administration of crypto-assets and transfer services — and, on the Article 60(4) limb, in relation to e-money tokens it issues itself. An EMI that wants to run an exchange or a trading platform needs full CASP authorisation, not a notification.

Second, Germany’s transitional window closed early. The EU-wide grandfathering backstop runs to 1 July 2026, but Germany shortened its own transitional regime to 31 December 2025 under § 50(2) no. 3 KMAG. Firms relying on the pre-MiCAR German crypto-custody permission under the KWG therefore ran out of runway some six months before peers elsewhere. Verify your position against the current KMAG text, not generic EU timelines.

7. Before you apply: check whether you need to at all

§ 2(1) ZAG carves activities out of the regime entirely, and three exclusions do most of the work in practice:

  • Technical service providers (no. 9) — data processing and infrastructure, where the provider never comes into possession of the transferred funds. Funds flow is the test, not the technology.
  • Commercial agents (no. 2) — payment transactions where an agent negotiates or concludes the sale exclusively on behalf of one side.
  • Limited networks (no. 10) — instruments usable only at the issuer’s own premises or within a restricted network under a commercial agreement.

The limited-network exclusion carries its own duty: where the total value of payment transactions in the preceding twelve months exceeds €1 million, the provider must notify BaFin, which then determines whether the conditions are genuinely met. Treat that as a monitored metric, not a one-off legal opinion — it is a common way for an unlicensed programme to become a supervised one without any change in the product.

8. The application, and what supervision looks like afterwards

BaFin publishes tabular overviews setting out the documents required for a ZAG application, and it expects the file to arrive twice in written form — either both copies to BaFin in Bonn or one each to BaFin and the Deutsche Bundesbank — with electronic copies by e-mail. It also asks applicants to make contact before formal submission to agree the documentation, the application fee under the Financial Services Supervision Fees Regulation, and the ongoing BaFin levy. DORA documentation now forms part of the expected file, so the ICT risk framework cannot be a post-authorisation workstream.

After authorisation, the Bundesbank side of the relationship begins: § 29(1) ZAG requires monthly returns (Monatsausweise), and there is a separate schedule of notification and reporting duties under the ZAG. Firms consistently under-resource this because the licence feels like the finish line.

9. Worked examples

Scenario 1 — the €20,000 illusion. Facts: a remittance start-up capitalises at €25,000, comfortably above the money-remittance floor, then adds a prepaid card so recipients can spend without withdrawing cash. What the rule says: issuing the payment instrument is catalogue no. 5, so the applicable tier is no longer €20,000 but €125,000 — and if the card balance is stored value rather than a pass-through, the firm is issuing e-money and the figure is €350,000. What the practitioner does: freezes the card feature, re-runs the own-funds calculation on projected volumes, and either raises capital before filing or ships the card as a phase two under a separate application. Outcome: the alternative is discovering the gap in BaFin’s completeness review, months in.

Scenario 2 — an EMI that wants to offer crypto. Facts: a German-authorised EMI plans to let customers hold and send bitcoin alongside their euro balance, and also to swap between the two in-app. What the rule says: Article 60 MiCAR covers an EMI only for custody and administration and for transfer services; the in-app swap is an exchange service that the notification route does not reach. What the practitioner does: splits the roadmap — notifies for custody and transfer with the 40-working-day lead time built into the launch plan, and opens a full CASP authorisation track for the exchange limb. Outcome: two thirds of the product ships on the fast route, and nothing ships unlicensed.

Scenario 3 — the loyalty wallet that outgrew its exclusion. Facts: a retail group runs a closed-loop wallet usable only in its own stores, unlicensed under the limited-network exclusion. Volumes grow, and it opens the wallet to a handful of partner brands. What the rule says: the exclusion in § 2(1) no. 10 depends on the network remaining restricted, and once twelve-month transaction value passes €1 million a notification to BaFin is due, after which BaFin decides whether the conditions still hold. What the practitioner does: instruments the twelve-month rolling volume as a compliance metric with a threshold alert, and prepares the notification file before the number is hit rather than after. Outcome: a supervised conversation the firm controls, instead of an enforcement one it does not.

10. FAQ

Which BaFin licence does a fintech in Germany actually need?

It depends on the activity, not the business model. Payment services need an Erlaubnis under § 10(1) ZAG; issuing e-money needs one under § 11(1) ZAG; account information services need only registration under § 34 ZAG; deposit-taking or lending on own account needs a banking Erlaubnis under § 32 KWG; crypto-asset services fall under MiCAR and the KMAG.

How much initial capital does a German payment institution need?

Under § 12 no. 3 ZAG: €20,000 for money remittance alone, €50,000 for payment initiation alone, €125,000 for the other payment services, and €350,000 for e-money issuance. Where the firm is also a credit institution or securities firm, the higher requirement of that regime applies.

Can an existing e-money institution add crypto services without a new licence?

Partly. Article 60 MiCAR allows an EMI to notify rather than apply, but only for custody and administration of crypto-assets and transfer services. Exchange and trading-platform services require full CASP authorisation.

Do I need a licence for a closed-loop or limited-network payment instrument?

Not necessarily — § 2(1) no. 10 ZAG excludes instruments usable only at the issuer’s premises or within a restricted network. But once twelve-month transaction value exceeds €1 million you must notify BaFin, which then assesses whether the exclusion genuinely applies.

Is the Bundesbank involved, or only BaFin?

BaFin grants the authorisation. The Bundesbank is part of the process — the application can be filed one copy each to BaFin and the Bundesbank — and ongoing supervision includes monthly returns under § 29(1) ZAG.

How long does a ZAG application take?

There is no reliable single figure — the clock in practice depends on file completeness. The controllable variable is the pre-submission dialogue BaFin invites: agree the document list, the fee and the DORA expectations before filing.

11. What to do, today

  • Write out every money-touching feature and map each one to a numbered service in § 1(1) sentence 2 ZAG — then read § 12 no. 3 against that list to fix the capital tier.
  • Resolve the KWG question explicitly: does anything on the roadmap pay interest on balances or lend the firm’s own funds? Decide before choosing the application track.
  • If crypto is planned, split it into Article 60-notifiable services and services needing full CASP authorisation, and put the 40-working-day lead time on the launch plan.
  • If you are operating on a § 2(1) exclusion, instrument the twelve-month rolling transaction value and set an alert well below €1 million.
  • Book the pre-application conversation with BaFin, and staff the DORA documentation and the § 29(1) monthly returns as part of the licence project, not after it.

Related: EMI licence in Germany (BaFin, ZAG) · Payment institution licence in Germany · CASP authorisation in Germany under MiCA

Related reads.