If your company holds other people's money in Montenegro for even a working day — a marketplace collecting buyer funds before paying sellers, a booking platform settling with hotels, a remittance corridor, a wallet, an app initiating transfers out of a customer's bank account — you are inside a licensing perimeter drawn by the Central Bank of Montenegro (CBCG), and it is drawn by function, not by what you call yourself. Providing payment services without CBCG authorisation is a misdemeanour carrying €10,000 to €40,000 for the company and €2,000 to €4,000 for the responsible person under Articles 182(1)(6a) and 182(2) of the Payment Operations Act.
The statute is the Zakon o platnom prometu, Sl. list CG nos. 062/13, 006/14, 111/22, 007/23, 015/25, 140/25 and 103/26 of 16 July 2026 — the last of those published five weeks before this page was written (25 August 2026), and the one that rewired instant payments. Citations are to the consolidated text published by the CBCG.
The eight payment services
Article 2(1) defines payment services as an exhaustive list of eight activities:
| # | Payment service (Art. 2(1)) | Typical business that falls in |
|---|---|---|
| 1 | Cash placement on a payment account, plus the account-keeping it requires | Cash-in networks, kiosks |
| 2 | Cash withdrawal from a payment account, plus the account-keeping it requires | Cash-out agents |
| 3 | Executing payment transactions: direct debits, card transactions, credit transfers, standing orders | Collection and pay-out platforms |
| 4 | The same transactions where funds come from credit granted to the user | Deferred-payment products |
| 5 | Issuing payment instruments and/or acquiring payment transactions | Card issuers, merchant acquirers |
| 6 | Money remittance | Remittance corridors |
| 7 | Payment initiation services | Pay-by-bank apps |
| 8 | Account information services | Aggregators, PFM apps, lending underwriters |
Montenegro has transposed the open-banking pair at positions 7 and 8 — and, as the capital table shows, treats them very differently.
Who may provide them
Article 4(1) sets a closed list: a bank or other credit institution seated in Montenegro; a payment institution; a registered account information service provider; an electronic money institution; a branch of a third-country credit institution seated in Montenegro; the Central Bank; and the State and municipalities when not acting as public authority. Article 4(2) says plainly that anyone else must not provide payment services here, Article 67(2) repeats the prohibition, and Article 67(3)–(4) lets the CBCG inspect the books of anyone it suspects of operating without authorisation.
Every route on that list requires a Montenegrin seat or branch: there is no inbound passport from an EU licence today, and Articles 177–178 on cross-border provision are written for a future inside the single market. So if you plan to reach Montenegrin customers from abroad without a local entity, the live question is not how to get licensed — it is whether what you do is a payment service at all.
The exclusions that get used, and the duty attached to two of them
Article 3(1) lists fifteen non-payment-services. Three do most of the real-world work:
- Art. 3(1)(10) — technical service providers. Processing, data storage, authentication, ICT and network provision, terminal maintenance — provided the person at no moment holds the funds being transferred. Payment initiation and account information are expressly carved out of it. The line between a payments-adjacent software vendor and a regulated institution is custody of funds, not branding.
- Art. 3(1)(11) — limited networks. Instruments usable only on the issuer's premises or inside a limited network under direct commercial agreement; or for a very limited range of goods or services; or valid in one country and issued at a company's or public body's request for social or tax purposes.
- Art. 3(1)(12) — electronic communications. Operator billing for digital content, voice-based services, charity or tickets, capped at €50 per transaction and €300 per subscriber per month.
The limited-network exclusion carries a reporting duty that is easy to breach silently. Under Article 3a(1), a provider relying on Art. 3(1)(11)(a) or (b) whose payment transactions over the preceding 12 months exceed €1,000,000 must notify the CBCG within one month of crossing that threshold. Article 3a(2)–(3) then lets the CBCG decide whether the exclusion still holds and order a full licence application under Article 72, on a deadline that by law cannot be shorter than 90 days. Missing the notification is itself a misdemeanour at €10,000 to €40,000 under Article 182(1)(1) — a closed-loop gift-card or campus-wallet operator that quietly grew past a million euros is the exact profile it was written for.
Capital: four floors, far apart
| Institution / service | Minimum initial capital | Source |
|---|---|---|
| Payment institution — money remittance only | €20,000 | Art. 70(1) |
| Payment institution — payment initiation only | €50,000 | Art. 70(2) |
| Payment institution — any of services 1 to 5 | €125,000 | Art. 70(3) |
| Electronic money institution | €350,000 | Art. 116(1) |
| Registered account information provider (service 8 only) | No capital floor; indemnity insurance or comparable guarantee instead | Art. 107a(1)–(4) |
Article 70(4) resolves the mixed case: an applicant seeking several services meets only the highest floor, not the sum. Articles 70(5) and 116(2) require it to be paid in cash.
Initial capital is a gate, not a steady state. Article 78(1) requires regulatory capital that at no moment falls below the higher of initial capital or the calculated amount; Article 78(2) requires at least 75% of Tier 1 as common equity and caps Tier 2 at a third of Tier 1; Article 78(3) offers three calculation methods — fixed overheads, payment volume, operating income. For e-money, Article 117(2) sets ongoing capital at at least 2% of average electronic money in circulation.
Firms providing only initiation and account information are exempt from both regulatory capital (Art. 78(6)) and safeguarding (Art. 79(9)) — they never hold funds; Article 72(5) requires professional indemnity insurance instead.
The file, and the 90-day clock
Article 72(2) lists seventeen categories of document. Four are where files stall: the safeguarding plan, including how the representative portion of mixed inflows is estimated (Art. 72(2)(5)); ICT and operational resilience material (Art. 72(2)(6), (7), (9), Art. 72(4)); a security policy with a payment-services risk assessment (Art. 72(2)(11)); and the fitness of the executive director, who under Article 72(2)(15) must hold higher education alongside good repute and experience.
The ICT items are new in substance. The Act cross-refers repeatedly to the law governing digital operational resilience of the financial sector, and that statute exists: the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora, adopted 2 February 2026, Sl. list CG 014/26 of 9 February 2026, in force on the eighth day after publication. It transposes EU Regulation 2022/2554 (DORA), and its Article 2(1) covers credit institutions, payment institutions, registered account information providers, e-money institutions and crypto-asset service providers alike. Article 54 gives 24 months from entry into force to comply.
Under Article 169(1) the CBCG must decide on a payment-services authorisation, an e-money authorisation or a payment-system licence within 90 days — but that runs from the day the file is completed where the original submission was incomplete. An incomplete file does not start the clock. The granted authorisation is published in the Službeni list (Art. 73(4)).
Client money sits outside the insolvency estate
Article 79 is what makes a payment institution structurally different from an ordinary company holding a float. User funds must be held separately from the institution's own funds and from funds received on any other basis (Art. 79(2)), and anything not passed on by the end of the next business day must go to a bank account in Montenegro or abroad, to a permitting member-state central bank, or into liquid low-risk assets (Art. 79(3)).
Then Article 79(4): those funds are not the property of the institution, do not form part of its liquidation or bankruptcy estate, and cannot be the object of enforcement against it. Article 79(5) allows an insurance policy or bank guarantee from outside the group instead; Article 123 extends the same protection to funds received for issued e-money.
The mirror-image limits: a payment institution must not take deposits or other repayable funds (Art. 81(2)), and may lend only as a service ancillary to a payment transaction, repayable within 12 months and not funded from client money (Art. 81(1)). An e-money institution must not take deposits (Art. 120) or lend out funds received for issued e-money (Art. 122), and — a point that catches distribution models — must not issue e-money through an agent at all (Art. 115(1)). Breaches carry €20,000 to €40,000 under Articles 184(1) and 186(1).
What the register actually shows
The CBCG keeps a public register of payment institutions, branches and agents under Article 89, with registered account information providers and Article 3a excluded providers entered separately. Read live on 25 August 2026, it holds seven payment institutions, carrying register numbers between 01 and 08 — the gap is accounted for by the CBCG's separate list of institutions whose authorisation has been withdrawn. Their authorised scopes range from money remittance alone to credit transfers combined with payment initiation and account information, so the open-banking permissions in Article 2(1)(7)–(8) are live here, not theoretical. The separate register of electronic money institutions says, in one sentence, that no electronic money institution is currently entered in it.
Montenegro has a complete e-money regime on the books — a €350,000 capital floor, 2% of e-money in circulation as ongoing capital, segregation, redemption at par under Article 109 — and, as at that date, not one licensed e-money institution. Whether that reads as an open field or a warning about the cost of being first is a commercial judgement, not a legal one — but it should be read before anyone budgets for a Montenegrin e-money licence assuming a peer group exists.
Banking access: there is a rule, and a paper trail
Every payments business here eventually hits the same wall — getting and keeping a bank account. Article 4a(1) obliges banks and other credit institutions to open and maintain transaction accounts for payment and e-money institutions on request, on an objective, non-discriminatory and proportionate basis. A bank may refuse where it judges there are justified reasons — but under Article 4a(2) it must then notify the CBCG with reasons. That converts a silent no into a documented, supervised one. It does not make account-opening easy: our notes on why bank accounts in Montenegro are hard to open and on the banking problem specific to crypto companies describe the other side of that rule.
The two clocks that started in July 2026
On 20 July 2026 the CBCG introduced EU instant payments into domestic payment traffic through the TIPS Clone system, built with the Bank of Italy under the auspices of the European Central Bank and with World Bank support. Four days earlier, on 16 July 2026, amendments to the Act were published as Sl. list CG 103/26.
The obligations sit in Articles 56g–56v. Ten seconds: Article 56g(7) requires the payee's provider to make the amount available and confirm execution within ten seconds of receipt; Article 56g(1) requires any provider offering credit transfers to offer instant ones too, with accounts reachable 24 hours a day, every calendar day; Article 56g(10) requires the payer's account to be restored immediately if no confirmation arrives in time. Verification of payee: Article 56j(1)–(2) requires the payer's provider to run a payee check immediately after the payer supplies the payee's details and before authorisation is offered. Pricing: Article 56u(1) bars charging more for an instant transfer than for an ordinary one of the corresponding type, and Article 56u(2) bars charging anything for payee verification.
The transitional timing is where a compliance calendar has to be built carefully. Article 193g(1) gives credit institutions eight days from the establishment of the instant credit transfer infrastructure to align with Articles 56g–56i, 56t, 56u and 56v; Article 193g(2) gives nine months from the establishment of the payee-verification infrastructure for Articles 56j–56š; Article 193g(3) gives 18 months for bulk orders. Article 193h separately defers Article 56g(5) by nine months, and Articles 56h, 56i, 64(6), parts of 142a and 148(2)(3) by 18 months, from the entry into force of the law.
The 20 July 2026 go-live is the obvious candidate for the Article 193g(1) trigger, but the Act ties that trigger to establishment of infrastructure rather than to a published date, and payee verification is a separate trigger with its own clock. The Article 193h periods, meanwhile, run from the commencement of the amending act, which the consolidated text does not restate. Before diarising any of these dates, read the commencement clause in Sl. list CG 103/26 itself. We would rather flag the gap than publish a date we cannot source.
Before you commit to a structure
The expensive mistakes here are made early and quietly: a marketplace that holds buyer money for a week and meets the licensing question at its Series A; a loyalty programme that crosses €1,000,000 without the Article 3a notification; a founder who budgets €125,000 for what is actually e-money at €350,000. Each is decided by the architecture of the money flow, not the wording of the pitch deck. If you are structuring a business that will touch payments in Montenegro — or being asked to sign an agent agreement, a distribution agreement or a flow-of-funds annex — send us the draft and the flow diagram before you sign, and we will tell you which side of Article 2(1) it falls on and what the Act then requires. This work sits in our fintech and crypto practice. For the crypto-asset side of the same perimeter — a different regulator, a different statute — see the crypto service provider register and what changes when MiCA arrives. If the entity still has to be built, start with company formation in Montenegro; if tax is part of the decision, see how Montenegro taxes crypto and company profits; and if you are comparing jurisdictions, Turkey and Montenegro ask completely different questions — our Turkey fintech and crypto practice covers that side.
Sources: the consolidated texts of both laws as published by the Central Bank of Montenegro, and the CBCG registers and TIPS Clone announcement, read on 25 August 2026. General information on Montenegrin law, not advice on a specific structure.



