If you've been following European digital finance news lately, you've probably noticed: everything is happening at once.
On July 1, MiCA, the EU's landmark crypto-assets regulation, fully took effect. Regulated exchanges began delisting non-compliant stablecoins, while compliant issuers secured licenses to operate across all 27 member states.
Just days later, the European Parliament approved the Single Currency Package, paving the way for trilogue negotiations on the digital euro. The European Central Bank selected 36 payment service providers to join the digital euro pilot, scheduled to start in the second half of 2027. If negotiations stay on track, the digital euro could be available to citizens by 2029.
And from November 2026, just four months away, ISO 20022 becomes the mandatory standard for payment messages, with banks required to use structured, data-rich formats for cross-border payments.
Three major transitions. Three converging timelines. All pointing to one conclusion: Europe is building a new digital payment infrastructure, and we need the standards to make it work.
That's exactly what my StandICT.eu 2029 fellowship is about.
The Challenge: When DLT Meets Traditional Payments
Distributed Ledger Technology (DLT) offers something traditional payment systems struggle with: programmability, near-instant settlement finality, and transparent transaction records. Whether it's a MiCA-compliant stablecoin, a future digital euro, or a tokenised bank deposit, DLT-based assets are becoming real contenders in retail payments.
But there's a problem.
Today's DLT payment systems and traditional financial messaging standards, like ISO 20022, don't speak the same language. A DLT transaction carries metadata that ISO 20022 messages simply don't have a field for. Compliance data (KYC/AML attributes, consent proofs, SCA evidence) is represented inconsistently across platforms. And for European SMEs and Payment Service Providers (PSPs), this fragmentation means higher costs, legal uncertainty, and a competitive disadvantage against non-EU players with proprietary infrastructures.
The EU's Retail Payments Strategy explicitly calls for interoperability, privacy, and competition. The ICT Rolling Plan for Standardisation prioritises action on these fronts. But the technical standards to bridge DLT and traditional payments? They don't exist yet.
That's the gap my fellowship is filling.
The Work: Three Standards Contributions, One Vision
My fellowship project, "Retail Payments Standards for Interoperable, Compliant DLT Integration", is delivering three concrete contributions to international standardisation bodies:
1. Semantic Mapping for Retail Payments
I'm proposing a harmonisation framework to map DLT transaction data directly into ISO 20022 messages (specifically the pacs.008 credit transfer). Using the standard's SupplementaryData element, we can carry DLT-specific metadata, asset type, block hashes, smart contract details, without breaking existing infrastructure. With ISO 20022 becoming mandatory in November 2026, this mapping couldn't be more timely.
2. Privacy-Preserving Compliance Profile
Working with W3C Verifiable Credentials, I'm developing a tailored compliance profile for retail payments. It enables PSPs to share KYC/AML, consent, and regulatory data with selective disclosure, revealing only what's necessary, nothing more. This is GDPR-aligned by design and supports the Strong Customer Authentication requirements of PSD2.
3. Interoperability Test Vectors
Theory is one thing. Practical implementation is another. I'm creating a concrete test suite with baseline scenarios and pass/fail criteria. This gives European SMEs and fintech developers a clear, low-cost path to validate their DLT payment implementations against recognised standards.
These contributions are directed at ISO/TC 307 (Blockchain and DLT), ISO/TC 68 (Financial Services), W3C, and CEN/CENELEC JTC 19, ensuring European priorities are embedded in the global standards of tomorrow.
Technical Profile: Privacy-Preserving Identity & Compliance
Beyond the standardisation contributions, I'm developing a concrete technical specification—a privacy-preserving identity and compliance profile for retail payment flows built on W3C Verifiable Credentials. This profile bridges the gap between DLT-based payment systems and regulatory requirements.
Core Claims Set
The profile defines a minimal set of claims that must be included in a retail payment compliance credential, enabling efficient verification while protecting privacy:
- legalPersonIdentifier - Unique identifier of the legal entity (LEI or national registration number)
- naturalPersonIdentifier - Pseudonymised natural person identifier (one-way hash for privacy)
- subjectRole - Distinguishes the role in the payment flow: payer, payee, intermediary, or escrow
- amlRiskCategory - AML risk score assigned by the issuer: low, medium, or high
- transactionPurposeCode - Purpose of the transaction following ISO 20022 PurposeCode (e.g., CASH, SALA)
- consentProof - Cryptographic proof of user consent for data processing (GDPR Art. 7)
- scaEvidence - Strong Customer Authentication evidence for transactions above PSD2 thresholds
- credentialStatus - Endpoint to check revocation status via W3C Status List 2021
Selective Disclosure with BBS+ Signatures
The profile recommends BBS+ Signatures as the primary proof format, enabling:
- Selective disclosure - Holders can reveal only the claims necessary for a given interaction
- Unlinkable presentations - Each presentation generates a different zero-knowledge proof, preventing correlation
- Blind signature support - Issuers can sign credentials without learning user attributes
This approach balances privacy with regulatory compliance, allowing PSPs to verify required attributes without exposing unnecessary personal data.
ISO 20022 Integration
The profile provides a mapping between VC claims and ISO 20022 elements, leveraging the SupplementaryData extension mechanism to carry compliance evidence without modifying the core schema. To address message size constraints, it introduces a Reference Pattern: the ISO 20022 message includes only a hash (SHA-256) of the full VC, with the full credential stored in a secure, retrievable location and referenced via a DID URL or HTTPS endpoint.
Regulatory Alignment
The profile aligns with key European regulations:
- MiCA - Supports stablecoin requirements through issuer identification and reserve attestation
- PSD2 - Includes dedicated scaEvidence claim for Strong Customer Authentication
- DORA - Enables traceability and incident reporting through unique identification
- GDPR - Designed with data minimisation, purpose limitation, and consent tracking
- FATF Travel Rule - Fulfils requirements for sharing originator/beneficiary information for transfers above 1,000 EUR
Implementation Guidance for SMEs and PSPs
The profile includes concrete implementation guidance covering the full credential lifecycle: issuance, storage, presentation, verification, and revocation via W3C Status List 2021. It provides test vectors for baseline scenarios (P2P stablecoin transfer, CBDC point-of-sale) and conformance criteria to ensure interoperability across diverse national infrastructures.
Relevant Standards
The successful implementation of interoperable DLT-based retail payments relies on adherence to internationally recognized standards that ensure security, privacy, and regulatory compliance:
- ISO 20022 - Financial messaging standard that becomes mandatory for cross-border payments in November 2026, providing the foundation for structured, data-rich payment messages
- ISO/TC 307 - Blockchain and Distributed Ledger Technologies committee developing international standards for blockchain and DLT interoperability
- ISO/TC 68 - Financial Services committee responsible for standards in banking, securities, and other financial services
- W3C Verifiable Credentials Data Model - Standard format for verifiable digital credentials that enables privacy-preserving compliance and selective disclosure
- CEN/CENELEC JTC 19 - European Blockchain and DLT standards committee ensuring European priorities are reflected in global standardisation
- MiCA Regulation - Markets in Crypto-Assets Regulation establishing the EU's comprehensive framework for crypto-assets and stablecoins
- PSD2 - Payment Services Directive 2 governing payment services and Strong Customer Authentication (SCA) requirements in the EU
- eIDAS Regulation - Electronic Identification and Trust Services regulation providing the legal framework for electronic signatures and digital identity
- ISO/IEC 27001 - Information Security Management standard providing the framework for securing payment infrastructure and protecting sensitive data
- ISO/IEC 29115 - Entity Authentication Assurance framework defining Levels of Assurance (LoA) for identity verification in digital transactions
By aligning with these standards, European businesses can ensure their DLT payment implementations are secure, interoperable, and compliant with EU regulations while maintaining competitiveness in the global market.
Why This Matters Right Now
The timing of this work isn't accidental, it's essential.
MiCA is live. Stablecoin payments are entering the European mainstream. But without standardised messaging, every PSP integrating DLT payments will build its own custom solution. That's fragmentation by another name.
The digital euro is coming. The Eurosystem's comprehensive payments strategy, published on 31 March 2026, highlights how the digital euro will foster pan-European private retail payment solutions. But a digital euro that can't interoperate with existing ISO 20022 infrastructure? That's a missed opportunity for seamless integration.
ISO 20022 is the new baseline. From November 2026, unstructured payment data won't cut it anymore. The standards we define now will shape how DLT payments integrate with this new mandatory framework.
Europe has a choice: let DLT payment standards be defined by non-EU actors with different values, or lead the development of standards that reflect European principles, privacy, sovereignty, competition, and SME inclusion.
My fellowship is a small but concrete contribution to the second path.
The Broader Picture: StandICT.eu 2029

This work is made possible by StandICT.eu 2029, the EU's flagship programme for ICT standardisation. With €4.2 million in funding supporting over 300 experts across six open calls, StandICT.eu enables European specialists to represent Europe in major standardisation bodies. In Open Call 1 alone, 75 fellowships were selected, with an average quality score of 8.2 out of 10.
The programme bridges the gap between EU digital policy and the technical standards that make policy real. That's exactly what we need at this moment of rapid transformation.
What's Next
Over the coming months, I'll be:
- Presenting draft contributions at ISO/TC 68 and ISO/TC 307 plenaries
- Conducting interoperability testing with independent implementers
- Finalising ballot-ready submissions
- Publishing a public technical report and hosting a webinar for European SMEs and regulators
The goal is simple: make it easier, cheaper, and safer for European businesses to adopt DLT-based payments,while ensuring those payments are compliant, privacy-preserving, and truly interoperable.
Join the Conversation
If you're working at the intersection of payments, DLT, and standards,or if you're an SME or PSP navigating the MiCA, digital euro, and ISO 20022 transitions, I'd love to hear from you.
The standards we build today will shape Europe's digital payment landscape for a generation. Let's build them together.
References
- [1] StandICT.eu 2029, "Official Website" https://www.standict.eu
- [2] European Commission, "Markets in Crypto-Assets Regulation (MiCA)" https://finance.ec.europa.eu/digital-finance/crypto-assets_en
- [3] European Central Bank, "Digital Euro" https://www.ecb.europa.eu/euro/digital_euro/html/index.en.html
- [4] ISO, "ISO 20022 - Financial Services" https://www.iso20022.org
- [5] ISO/TC 307, "Blockchain and Distributed Ledger Technologies" https://www.iso.org/committee/6266604.html
- [6] ISO/TC 68, "Financial Services" https://www.iso.org/committee/49650.html
- [7] W3C, "Verifiable Credentials Data Model" https://www.w3.org/TR/vc-data-model/
- [8] CEN/CENELEC JTC 19, "Blockchain and Distributed Ledger Technologies" https://www.cencenelec.eu/media/CEN-CENELEC/Areas%20of%20Work/CEN%20sectors/Digital%20Society/Emerging%20technologies/fg-bdlt-white_paper-version1-2.pdf
- [9] European Commission, "Retail Payments Strategy" https://finance.ec.europa.eu/publications/digital-finance-package_en
- [10] European Commission, "ICT Rolling Plan for Standardisation" https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/rolling-plan-2026
- [11] European Commission, "PSD2 - Payment Services Directive" https://finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/implementing-and-delegated-acts/payment-services-directive_en
- [12] European Commission, "Single Currency Package" https://finance.ec.europa.eu/digital-finance/digital-euro_en
- [13] European Commission, "eIDAS Regulation" https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation
- [14] ISO, "ISO/IEC 27001 - Information security management" https://www.iso.org/isoiec-27001-information-security.html
- [15] ISO, "ISO/IEC 29115:2013 - Entity authentication assurance framework" https://www.iso.org/standard/45138.html
- [16] W3C, "Status List 2021" https://www.w3.org/community/reports/credentials/CG-FINAL-vc-status-list-2021-20230102/
- [17] ISO, "ISO 17442:2020 - Legal Entity Identifier (LEI)" https://www.iso.org/standard/78829.html
- [18] European Commission, "DORA - Digital Operational Resilience Act" https://finance.ec.europa.eu/digital-finance/cyber-resilience_en
- [19] FATF, "Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers" https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
Olvis Enrique Gil Ríos is the founder of OG Technologies EU and a StandICT.eu 2029 fellow. His project, "Retail Payments Standards for Interoperable, Compliant DLT Integration" runs from March to September 2026.
#StandICT #DigitalPayments #DLT #ISO20022 #MiCA #DigitalEuro #VerifiableCredentials #EUSovereignty #FintechStandards




