From the journal

Legal Finality in Pontes: Central Bank Money and Tokenised Securities

Pontes is a Eurosystem service connecting distributed-ledger transactions to euro settlement in central bank money. Its launch raises a legal question: when does payment become final, and what protection reaches the securities delivered against it?

Illia ProkopievCo-Founder and CEO19 min read

Summary

  • The initial service has two legally distinct cash routes. A cash-token transfer precedes central bank money finality through the corresponding T2 movement. The direct route reaches finality in T2, the Eurosystem’s real-time gross settlement service. Parties must identify their route before defining payment completion. (ECB, Pontes Service Description, v1.0, §3.5.6, p. 54.)
  • Cash finality does not establish final securities delivery or ownership. System designation, entry rules, applicable amendments and the instrument’s governing law require separate examination. A technical delivery-versus-payment mechanism cannot supply a missing statutory condition. (Directive 98/26/EC, Articles 2(a), 3 and 5; ECB, Pontes Initial Enhancements URD, v1.0, §1.3.)
  • Pontes access depends on the applicant’s category and admission process. Connection does not establish permission for every securities, custody or payment activity. Each operator’s authorisation and exemptions must cover the proposed transaction. (ECB, “Pontes”, access criteria; Regulation (EU) 2022/858, Articles 4–10; ESMA, Report on the functioning and review of the DLTR, 25 June 2025, §§2.2 and 3.4.)
  • Failed defunding can leave token balances overnight. Recovery and compensation depend on the applicable agreements. German TARGET conditions illustrate limits on liability, but they cannot be imported into a separate Pontes contract without a contractual basis. (ECB, Information Guide, July 2026, §5.2; TARGET-BBk Conditions, effective 15 June 2026, Part I, Articles 21 and 22.)
  • Settlement access and collateral eligibility are separate decisions. The ECB’s announced DLT collateral route requires the existing eligibility criteria and access through eligible, T2S-reachable securities settlement systems. Pontes connectivity alone does not satisfy those conditions. (ECB, collateral announcement, 27 January 2026, eligibility conditions and implementation date.)
  • The published initial pricing phase includes the 2027 enhancements. Its connection charges do not establish the total cost of a transaction. Prices for the enhanced product remain undetermined. (ECB, Pontes Pricing Guide, August 2026, §§1–3.)
  • The 2027 design places tokenised cash finality inside TARGET’s legal arrangements. The 2028 design adds different liquidity and availability objectives. The July specification also excludes direct T2 settlement from the enhanced product’s scope. These are prospective design statements, not present contractual entitlements. (ECB, Initial Enhancements URD, v1.0, §1.1, footnote 4, and §4.1; focus-session timeline, 22 July 2026, PDF p. 7.)
  • The separate own-funds initiative remains preparatory. Its announcement establishes neither completed purchases nor a monetary-policy purchase programme. The initial onboarding roster establishes readiness to start, without demonstrating transaction volumes or market-wide adoption. (ECB, launch release and own-funds release, 21 September 2026.)

Cash finality under the initial service

A payment-completion clause must identify the selected cash route. Under the initial cash-token model, wallet balances change before finality in central bank money. The ECB locates that finality at the corresponding T2 movement during participant-initiated defunding or automatic end-of-day repatriation. Its direct real-time gross settlement (RTGS) model settles in T2 without that deferred conversion step. Submission alone does not establish the necessary T2 event. The ECB’s overview and its 26 August speech corroborate the distinction. (ECB, Service Description, v1.0, §3.5.6, p. 54; “Pontes”, dual settlement model; speech, 26 August 2026, footnote 12.)

The ECB defines a cash token as a proxy for euro central bank money: a claim against the ECB to transfer the amount to the owner’s T2 RTGS account. That definition gives the token an identified issuer and redemption object. It does not make the wallet transfer identical to the later T2 movement. Detailed enforcement and insolvency consequences depend on the executed Pontes terms, which are not verified from the available primary record. Treating those tokens as privately issued money would contradict the ECB’s stated design. (ECB, Service Description, glossary, p. 9; Information Guide, §§1.1 and 5.2; operational and legal presentation, 22 July 2026, PDF pp. 13–14.)

For a German TARGET account, the general rule fixes entry and irrevocability at the relevant account debit. Article 18 prescribes separate rules for specified instant-payment, T2S and ancillary-system procedures. The actual account and procedure must therefore be identified before selecting the timing rule. Those German cash-account terms do not establish the legal effect of a transfer on a separate securities ledger. (TARGET-BBk Conditions, Part I, Article 18(1).)

The ECB’s Hash-Link mechanism coordinates delivery versus payment on an all-or-none basis. That provides technical coordination of the two legs, rather than a legal determination that both transfers are final. Statutory protection against insolvency still depends on the legally defined entry and irrevocability events. Coordinated release therefore cannot substitute for a missing designation or legal timing condition. This deduction preserves the mechanism’s technical function while limiting what it proves about third-party rights. (ECB, “Pontes”, Hash-Link protocol; Directive 98/26/EC, Articles 2(a), 3 and 5.)

Parties could agree that a wallet transfer discharges their bilateral payment obligation, subject to applicable law. That agreement would address contractual performance. It would not itself establish statutory protection against third parties. Under the Settlement Finality Directive, protection depends on the qualifying system and its rules for entry and irrevocability. The counterargument therefore changes the contractual completion test, without proving the statutory conditions. (Directive 98/26/EC, Articles 2(a), 3(1), 3(3) and 5.)

A transaction record should distinguish submission, technical settlement, securities delivery and the relevant cash-finality event. The confirmation should identify the cash route and retain the corresponding account evidence. These are evidential measures inferred from the separate events, rather than a claim that every field is prescribed by statute. A single status labelled “settled” leaves the legal event ambiguous unless the contract defines its meaning. (ECB, Service Description, v1.0, §3.5.6, pp. 52–55.)

Securities finality, title and insolvency

The asset leg requires its own finality analysis. Under the cited Settlement Finality Directive provisions, protection requires qualifying transfer orders and defined timing conditions. For interoperable systems, it preserves separate entry and irrevocability rules, subject to express coordination provisions. A connection between systems does not automatically combine them into a single designated system. The application therefore requires identification of the securities system, its designation and its entry rules. (Directive 98/26/EC, Articles 2(a), 3(1), 3(4) and 5.)

An operator can have regulatory permission without every conventional finality safeguard. ESMA’s June 2025 report records DLT infrastructures operating under exemptions from settlement-finality requirements under the Central Securities Depositories Regulation (CSDR). That historical record defeats the inference that a DLT permission necessarily establishes ordinary system designation. The report also records compensatory controls, so an exemption cannot be equated with an absence of protection. It does not establish the current permission of any Pontes operator. The actual authorisation, conditions and exemptions must be obtained for the proposed venue. Article 5(7) of Regulation (EU) 2022/858 permits the competent authority to grant an exemption from CSDR Article 39, subject to compensatory measures, close-to-real-time or intraday settlement no later than the second business day after the trade, public system rules and mitigation of non-designation risks, particularly insolvency. A DLT settlement system may still be designated where it meets the Settlement Finality Directive’s requirements. (Regulation (EU) 2022/858, Articles 2(7), 5(7), 5(11) and 6; Regulation (EU) No 909/2014, Article 39; ESMA, Report on the functioning and review of the DLTR, §2.4, footnote 3 and §3.4.)

The Eurosystem’s future specification expressly leaves the market-platform leg to the rules applicable to its operator. That allocation also defines the limit of the claimed improvement in cash settlement. Even after tokenised cash acquires finality on the Eurosystem ledger, a securities transfer can still raise an independent question about the constitutive register or the rights transferred. This is a conditional inference from the separate legal treatment of the two legs. It is not a finding that any named operator has defective title arrangements. (ECB, Initial Enhancements URD, v1.0, §1.3, p. 6, and §4.1, requirement PONTES.UR.04.020.)

The title analysis must establish what the buyer acquires: an issuer-facing security, a beneficial interest, or a contractual claim against an intermediary. The supplied materials identify no instrument or ownership structure. An enforceability opinion must therefore locate the legally operative register and the act that transfers the relevant right. It must also address custody segregation and the position if an intermediary fails. Neither an account address nor successful cash settlement supplies those missing premises. (ECB, Service Description, §3.5.6, allocation of responsibility for the asset leg; Directive 98/26/EC, Articles 2(i) and 8.)

Insolvency protection also requires the correct chronology. The Directive protects qualifying orders entered before proceedings open and, conditionally, orders entered afterwards and carried out within the system-defined business day in which proceedings open. For the latter orders, the system operator must prove that, when they became irrevocable, it neither knew nor should have known of the opening. An opinion must map the relevant opening, entry and irrevocability times rather than treat all completed software transactions alike. National implementation and the actual system rules remain necessary before applying that rule to a transaction. (Directive 98/26/EC, Articles 3(1), 5, 6 and 8.)

Admission, permissions and instrument classification

Pontes admission is a service-access decision with category-specific conditions. The ECB’s published criteria distinguish eligible cash participants from market distributed-ledger technology (DLT) operators. Operator routes include central securities depositories (CSDs), DLT settlement infrastructures, payment-system operators and other specified regulated entities. Some routes require particular supervision or a case-by-case national central bank assessment. An applicant must establish the route actually used; regulated status in the abstract does not establish admission. (ECB, “Pontes”, access criteria.)

A separate question concerns permission to conduct the underlying activity. ESMA describes the DLT Pilot Regime as a system of specific permissions and conditional exemptions. An admitted Pontes operator still needs the authorisation or exemption required for each regulated activity. A purely technical provider’s role can differ from that of the operator legally responsible for trading, settlement or custody. The contracts and authorisation record must identify each role before responsibilities can be assigned. (Regulation (EU) 2022/858, Articles 4–10; ESMA, Report on the functioning and review of the DLTR, §§2.1–2.3.)

Admission also requires operational certification. The published testing terms require market participants and operators to complete mandatory tests, with national central banks checking execution. They permit later joining before the next phase, subject to the responsible national central bank’s participation. Completed certification establishes satisfaction of that testing condition; it is not an instrument-specific legal opinion. The applicant still needs the permission and contractual evidence relevant to its proposed activity. (ECB, Testing Terms of Reference, v1.1, §4.3, pp. 22–23.)

The classification of the instrument must also precede analysis under the Markets in Crypto-Assets Regulation (MiCA). The European Supervisory Authorities direct applicants to test the exclusions for financial instruments, deposits and other listed products before classifying a token under MiCA. Their guidance separately recognises the exclusion for the ECB and Member State central banks acting as monetary authorities. The guidance is an official supervisory interpretation, not a substitute for the Regulation or an individual classification decision. (Joint ESA Guidelines JC 2024 28, paragraphs 1–2, 17 and 21–23; Regulation (EU) 2023/1114, Articles 2(2)(c) and 2(4)(a)–(c).)

A securities token, a commercial-bank claim and an e-money token cannot be treated as one product merely because each uses DLT. Where a transaction exchanges central bank money against private money, the private leg retains its own issuer and redemption terms. The inference is conditional on those terms, which have not been supplied. Pontes settlement does not establish that the private issuer’s obligation has become a Eurosystem obligation. (ECB, focus-session timeline, 22 July 2026, PDF p. 8, PvP use case; Joint ESA Guidelines JC 2024 28, paragraphs 21–23.)

The available record does not support an instrument-specific finding on offering documents, trading restrictions, custody permission or applicable Pilot Regime limits. Nor does it establish compliance with anti-money-laundering or sanctions duties for a particular participant. Those questions require the entity, activity, client type and jurisdiction. The limited legal conclusion is that access criteria do not contain a general exemption from those separate obligations. (ECB, “Pontes”, access criteria; TARGET-BBk Conditions, Part I, Articles 4(1), 10(5), 29(1) and 29(3), for German cash participants.)

Instructions, agency and customer rights

A delegated technical instruction can bind a participant even when the delegate breaches their private mandate. The German TARGET conditions expressly attribute designated entities’ orders to the participant despite non-compliance with their separate arrangements. That rule applies to the relevant TARGET account relationship. It does not prove identical wording in the Pontes agreement or an operator’s customer contract. (TARGET-BBk Conditions, Part I, Article 7.)

The practical inference is to reconcile technical permissions with the legal mandate. Operators and participants should identify who may initialise a transaction, release the settlement secret, change reference data and request defunding. An instruction that passes authentication can still exceed an internal approval limit. A valid private mandate also does not establish authority to bypass a system block. The operative agreement must allocate the consequences of each event; the technical design alone does not establish a damages claim. (ECB, Service Description, §§2.1 and 3.5.6; Information Guide, §5.8.)

A customer also needs a defined legal route to the relevant account holder or custodian. The published German TARGET conditions create no rights for outsiders to that bilateral relationship. A customer cannot infer a direct contractual claim against the Bundesbank merely because its intermediary uses TARGET. Other national components and Pontes agreements require their own examination. This conclusion follows from the identified contract’s scope, without deciding any separate statutory or tort claim. (TARGET-BBk Conditions, Part I, Articles 1 and 33(2).)

Liquidity, operating hours and failed defunding

A token balance can remain unavailable for ordinary T2 use during a defunding failure. The ECB’s July operational guide recognises exceptional overnight balances when Pontes or T2 incidents prevent redemption. It assigns the legal consequences to the applicable participation terms. A participant should therefore obtain those terms before assuming automatic compensation, reserve treatment or an unconditional same-day return of funds. The exception is documented; its contractual remedy is not verified from the available primary record. (ECB, Information Guide, §5.2.)

The published operating schedule distinguishes funding from settlement. Its July baseline starts funding at 08:00, settlement at 09:00 and applies a 16:00 settlement cut-off. Times are ECB local time, CET or CEST as applicable. The current production timetable requires confirmation against the participant’s latest national central bank instructions. A general description of daily availability cannot replace the cut-off applicable to a particular function. (ECB, Information Guide, §§1.1 and 2.6, Figure 2.)

A cash-route choice consequently affects liquidity planning as well as finality evidence. Token-funded transactions require the participant to plan funding and redemption. Direct T2 settlement depends on the relevant account liquidity and processing. Neither route supplies an unconditional right to liquidity at the moment the securities contract requires performance. The applicable deadline, available balance and contingency procedure must be tested together before identifying which party caused a failed closing. (ECB, Service Description, §§3.5.4(b) and 3.5.6; TARGET-BBk Conditions, Part I, Article 13.)

The strongest answer to the liquidity concern is that prefunding and coordinated execution can reduce an exchange’s exposure to an unfunded counterparty. That does not establish continuous access to the prefunded balance. A useful failure test assumes the wallet transaction completes but the subsequent T2 interface becomes unavailable. The documented defunding exception means the participant still needs a funding contingency for unrelated obligations. No amount of additional borrowing cost can be established without its funding terms and the actual delay. (ECB, Information Guide, §§5.2 and 5.4.)

Operational duties and available remedies

Using a Eurosystem cash service does not establish discharge of an institution’s own technology duties. Luxembourg’s Commission de Surveillance du Secteur Financier (CSSF) explains the Digital Operational Resilience Act (DORA) through guidance on management responsibility, incidents and information and communication technology (ICT) contracts. That official guidance identifies relevant duties but cannot establish their full application to every Pontes participant. The institution’s scope, service arrangements and competent supervisor must be determined. (Regulation (EU) 2022/2554, Articles 2, 5, 6, 19, 28 and 30; CSSF, “ICT and cyber risk – for DORA entities”, sections on ICT risk management, incident reporting and ICT third-party risk.)

For a proposed deployment, the legal review should distinguish the central-bank service from separately procured nodes, custody software and connectivity services. DORA’s recital 63 states that central banks operating payment or securities settlement systems are outside the intended coverage of ICT third-party service providers. This does not remove a participating financial entity’s own applicable ICT-risk and incident-reporting obligations. The review should then determine which contracts fall within the applicable ICT rules. A failure at a market operator and a failure within the cash service can require different notifications and contractual responses. Neither a successful connection test nor an operator’s regulated status establishes completion of that review. Exact reporting deadlines and any applicable exclusions require the operative rules and the incident facts. (Regulation (EU) 2022/2554, recital 63 and Articles 5, 6, 19 and 28; CSSF, DORA guidance, sections on third-party risk and incident reporting; ECB, Information Guide, §§4 and 5.)

A claim against a service provider must identify breach, causation and recoverable loss. Under the German TARGET conditions, ordinary-negligence recovery covers direct transaction-amount loss and/or loss of interest, excluding consequential loss. Fraud or gross negligence attracts broader liability. Infrastructure-failure exclusions depend on the Bank having taken reasonably necessary protective and remedial measures; participant-caused loss and force majeure receive separate treatment. Those distinctions require incident evidence and do not determine liability under Pontes. (TARGET-BBk Conditions, Part I, Article 22(1)–(4).)

The German terms also contain a specific TARGET malfunction compensation procedure. A Pontes-only incident cannot be assumed to satisfy its trigger. Contractual participation is with the relevant central bank, and the published description of the separate Pontes legal package provides for national-central-bank agreements. A claimant must therefore establish the correct defendant and contractual route before quantifying relief. The ECB’s operational guide expressly confers no legal rights. (TARGET-BBk Conditions, Part I, Articles 10(2) and 21, and Appendix II; ECB, Information Guide, §§1.1 and 5.8; operational and legal presentation, PDF pp. 13–14.)

Forum and governing law require the same discipline. German TARGET terms select German law and exclusive jurisdiction in the competent Frankfurt am Main courts, without prejudice to the Court of Justice’s competence. That clause does not resolve a separate securities-title dispute or a foreign operator contract. No litigation, rejection decision or loss event is identified here. Limitation periods, available interim relief and proof burdens cannot be fixed without that claim and its governing law. (TARGET-BBk Conditions, Part I, Article 34; Directive 98/26/EC, Article 8.)

Collateral eligibility and the financing value of settlement

An asset can settle through Pontes without a demonstrated right to use it for Eurosystem credit. The ECB’s January announcement states that the DLT collateral route effective from 30 March 2026 retains existing eligibility and collateral-management requirements. It includes settlement in eligible CSDR-compliant systems reachable through TARGET2-Securities (T2S). The announcement separately describes further work on assets outside those systems. It cannot be read as blanket acceptance of every token settled through Pontes. (ECB, collateral announcement, 27 January 2026, eligibility conditions and implementation date.)

The deduction concerns different conditions. Cash settlement answers how the purchase price moves. Collateral eligibility requires the asset and settlement arrangements to satisfy the Eurosystem’s criteria. Establishing the first fact does not establish the second. A financing plan must obtain the asset’s eligibility determination and confirm the mobilisation route; the supplied materials identify neither an instrument nor an eligibility decision. No haircut, credit limit or collateral value is assumed. (ECB, collateral announcement, 27 January 2026, eligibility conditions in the opening substantive paragraph.)

Fees and the duration of commercial assumptions

The published tariff charges EUR 2,500.00 once for a market participant and EUR 15,000.00 for a market DLT operator. It imposes no fixed monthly or settlement fees during the defined Initial Launch Phase, which includes the 2027 enhancements. For the enhanced product, the ECB envisages periodic and transaction-related charges, with rates still to be determined. (ECB, Pontes Pricing Guide, §§1–3.)

Those terms support a time-limited Pontes fee assumption, not a zero-cost operating model. Custody, connectivity, operator services and liquidity can have separate prices under their respective agreements. Their amounts are not stated in the available materials. A commercial contract should distinguish pass-through charges, the party bearing a future tariff increase and the right to terminate or migrate. These are proposed contractual responses to the published tariff boundary, rather than existing rights established by the guide. (ECB, Pontes Pricing Guide, §§2–3.)

The 2027 specification targets finality for tokenised central bank money on the Eurosystem ledger through integration into TARGET’s legal arrangements. It also provides for 22.5-hour availability on five days and continued mandatory end-of-day defunding. This addresses the current wallet-to-T2 finality sequence, subject to the implementing legal instruments. A final requirements document is evidence of the approved design, not evidence that the future rules already govern a 2026 transaction. (ECB, Initial Enhancements URD, v1.0, §§1.1, 1.4 and 4.1; focus-session timeline, 22 July 2026, PDF p. 7.)

The enhanced product’s 2028 objectives include overnight liquidity, multicurrency functionality and 24/7 operation. The July initial-enhancements specification expressly places direct T2 RTGS settlement outside that later product’s scope. A participant relying on today’s direct route therefore has a migration question. The specification is not itself a withdrawal notice under that participant’s contract, and later implementation decisions can alter the design. The evidence supports planning for a different service, without asserting an enforceable termination date. (ECB, Initial Enhancements URD, §1.1, footnote 4; focus-session timeline, PDF p. 7; speech, 26 August 2026, section on Pontes.)

Appia has a different deliverable. The ECB expects a blueprint in 2028 for future tokenised financial arrangements. Its August explanation leaves the choice between a common network and connected networks open. A blueprint date cannot establish that a particular architecture will operate by then. Procurement and participation decisions must therefore distinguish the announced Pontes releases from Appia’s exploratory outcome. (ECB, Appia announcement, 11 March 2026; speech, 26 August 2026, section on Appia.)

Launch evidence and the ECB’s own investments

The ECB confirmed the launch on 21 September 2026 and identified an initial group ready to start. That primary announcement establishes an operational launch and onboarding. It does not disclose executed transaction volumes, instrument coverage or a complete record of each participant’s permissions. The announced gradual admission process is therefore consistent with a live service whose actual use still requires transaction-level evidence. (ECB, launch release, 21 September 2026, opening substantive paragraph and footnote 1.)

The ECB’s separate own-funds announcement describes preparatory work for investments in tokenised securities. It identifies a non-monetary-policy portfolio and leaves timing and operational details to the Executive Board after preparation. Planned purchases concentrate initially on specified euro-denominated public-sector and supranational securities. These facts do not establish completed trades, a market-wide purchase commitment or eligibility of an unrelated instrument. The next relevant record is an implementation decision or executed transaction disclosure. (ECB, own-funds release, 21 September 2026, preparatory work and Executive Board implementation decision.)

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.