CESOP reporting requirements
The framework page: population, obligations and supervisory route.
Read the requirements →CESOP is a counting exercise before it is a reporting one. Scope turns on where payer and payee are located, and on a threshold applied per payee, per provider, per quarter — not per transaction.
The obligation attaches to payment service providers as defined in the payment services framework: credit institutions, electronic money institutions, payment institutions and post office giro institutions. The definition is functional rather than reputational — a business that holds funds in its own name before allocating them to a beneficiary can be a payment service provider for these purposes even if it does not describe itself as one.
That catches marketplaces and platform businesses that operate their own settlement layer. It is the first scope question to settle, because everything after it depends on the answer.
A payment is cross-border where the payer is located in one member state and the payee is located in another member state or outside the Union. Location is determined from the identifiers the payment instruction already carries — the account identifier for the payer, and for the payee the account identifier or, where the payee holds no account with the provider, another identifier such as a business identifier code.
Reporting is triggered where a provider makes more than twenty-five cross-border payments to the same payee in a calendar quarter. Four properties of that count cause most of the disputes:
| Group | Content |
|---|---|
| Reporting provider | Identifier of the payment service provider making the report, and the member state to which it is submitted. |
| Payee identity | Name, any value added tax or other tax identification number held, account identifier and address as recorded. |
| Payee location | The member state or third country derived from the identifier, with the basis on which it was derived. |
| Transaction | Date and time, amount and currency, whether the payment is a refund, the payment method, and the member state of origin. |
| Initiation | Whether the payment was initiated at the physical premises of the merchant, which changes how the record is read. |
Refunds are reported and are linked to the payment they reverse rather than netted against it. Personal data on the payer is not reported — the framework is built around the payee.
A provider reports to the member state where it is a home provider, and separately to each member state where it operates as a host provider. A provider passporting into several member states therefore produces several files from one dataset, on the same quarterly cycle, each carrying only that member state’s payments. Building one file and filtering it per member state is the pattern that scales; building each independently is not.
Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.
For that provider, yes. The count is per payee, per provider, per calendar quarter, so a payee spreading activity across several providers can stay below the threshold with each. The provider only assesses what passes through its own books.
Refunds are reportable records in their own right and are identified as refunds rather than netted against the original payment. Treat the counting question as a scope decision to document, and confirm the treatment against the current guidelines rather than inferring it.
The reporting duty runs with the payee side where the payee is located in the Union. A provider acting only for the payer keeps records but does not carry the same reporting obligation for that payment. Systems must therefore derive the role before applying scope.
The framework allows location to be derived from another identifier the instruction carries, such as a business identifier code. Record which identifier was used for each determination, because location is the field most likely to be questioned later.
REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.
More on this framework, and the module that produces the filing.
The framework page: population, obligations and supervisory route.
Read the requirements →The adjacent platform-economy obligation, and where the two overlap.
Read the questions →Apply the scope tests, validate and produce the member state files.
See the module →Load a quarter, see which payees cross the threshold and which member state files result, before you commit to anything.