top of page
BQK8LjzL74sMmqpVnPx3svLRbrw.webp

The DLT Pilot Regime, Pontes and Appia: How Europe Built Central Bank Money Rails for Tokenised Finance

Writer: Yiannos Ashiotis
Yiannos Ashiotis
2 hours ago
14 min read

By Yiannos Ashiotis, Pnyx Hill

Regulatory and operational position reviewed: 29 September 2026


Putting a bond on a blockchain is only part of the job. The harder questions are how the buyer pays, when that payment becomes final, and who carries the risk until both sides have delivered. That is where Europe’s tokenisation story becomes interesting.


On 21 September 2026, the Eurosystem launched the initial Pontes service, connecting transactions on market distributed ledger technology (DLT) platforms to settlement in euro central bank money. Europe deserves credit here, without pretending that its approach to innovation is flawless. Institutional adoption needs more than permission to experiment: it needs settlement arrangements that banks, investors and their advisers can understand and trust.


The DLT Pilot Regime provides a framework for eligible market infrastructures, Pontes addresses central-bank settlement, and Appia explores the longer-term design of tokenised wholesale markets. Understanding the distinction is the starting point for deciding what a firm can do today and what still depends on future changes.



Editorial illustration of bronze rails connecting pale stone structures against a navy background, symbolising the infrastructure linking tokenised financial markets and central-bank settlement.


What the DLT Pilot Regime is


The DLT Pilot Regime is Regulation (EU) 2022/858, which entered into force on 22 June 2022 and generally applies from 23 March 2023; it establishes a dedicated framework for certain DLT-based trading and settlement infrastructures, with specified exemptions and safeguards rather than a general exemption from securities law. Its three infrastructure categories are:


  • DLT multilateral trading facility (DLT MTF): A trading venue for DLT financial instruments, operated by an authorised investment firm or market operator with the relevant specific permission.


  • DLT settlement system (DLT SS): A system settling transactions in DLT financial instruments, operated by an authorised central securities depository (CSD) with the relevant specific permission.


  • DLT trading and settlement system (DLT TSS): An infrastructure combining trading and settlement functions, operated by an investment firm, market operator or CSD under the applicable requirements.



Eligible instruments and limits


Under the current framework, eligibility is restricted to specified instruments and thresholds assessed at admission or recording:


  • Shares: The issuer must have a market capitalisation, or tentative market capitalisation, below €500 million.


  • Debt instruments: Bonds, other securitised debt and money-market instruments must generally have an issue size below €1 billion, excluding instruments that embed a derivative or have a structure making their risks difficult for the client to understand.


  • Eligible fund units: Units in undertakings for collective investment in transferable securities (UCITS) covered by Article 25(4)(a)(iv) of the Markets in Financial Instruments Directive (MiFID II) must have assets under management with a market value below €500 million.


Article 3 also excludes corporate bonds issued by issuers whose market capitalisation did not exceed €200 million at issuance from the calculation of the debt-instrument threshold. The share test concerns issuer size, while the debt test generally concerns issue size; the rules therefore do not automatically exclude a large company issuing a smaller bond.


Each DLT market infrastructure also faces an aggregate limit: a new admission or recording cannot take the aggregate market value to or beyond €6 billion, and reaching €9 billion triggers its transition strategy. These are infrastructure-level limits, not a single allowance shared across the EU, and national competent authorities may set lower thresholds.



Targeted exemptions, not a regulatory free pass


DLT MTFs may receive specified exemptions from MiFID II and the Markets in Financial Instruments Regulation (MiFIR), while DLT settlement systems may receive specified exemptions from the Central Securities Depositories Regulation (CSDR), each subject to its own conditions and compensatory measures. For example, the cash-settlement exemption still requires delivery versus payment (DvP), linking delivery of the instrument to payment, and prioritises central bank money, including tokenised central bank money, where practical and available.


ESMA’s register includes examples of all three permission types: CSD Prague’s DLT SS, 21X’s DLT TSS and 360X’s DLT MTF, alongside other authorised infrastructures. 21X’s platform initially used Polygon and added live operation on Stellar in May 2026.


How a financial instrument becomes eligible for DLT trading


A prospectus does not, by itself, make an instrument eligible for the Pilot Regime: instrument eligibility, venue permission and public-offer disclosure are separate questions. A practical admission assessment should work through the following stages.


Classify the instrument and establish the legal rights


A token qualifying as a financial instrument is excluded from the Markets in Crypto-Assets Regulation (MiCA), and Pilot Regime eligibility then depends on the permitted instrument categories and other conditions. A token outside that perimeter requires separate classification; it does not automatically fall within MiCA, which has other exclusions.


Before admission, the issuer should establish how the instrument is validly created and transferred, which record determines ownership and how token movements correspond to investors’ legal rights. This legal work complements the operator’s obligation to document governing law, rights, liabilities, dispute arrangements and insolvency protections.


Check eligibility, capacity and the prospectus position


A DLT MTF, including the trading function of a DLT TSS, is not a regulated market, so admission alone does not trigger the Prospectus Regulation’s regulated-market admission requirement. A public offer must nevertheless be assessed separately: an offer solely to qualified investors may rely on Article 1(4)(a), while smaller offers must be assessed under the amended Article 3 framework and any applicable national disclosure requirements.


Fund units require separate care: units in open-ended collective investment undertakings are excluded from the Prospectus Regulation under Article 1(2)(a), so the applicable fund-disclosure regime must be considered instead.


Complete venue admission and ongoing compliance


Admission must fit the operator’s permission, documented operating rules and relevant DLT arrangements, while the Market Abuse Regulation applies to DLT financial instruments admitted to a DLT MTF or DLT TSS. Technical compatibility therefore sits alongside, rather than replaces, legal and regulatory admission checks.


Ongoing operator duties include monthly threshold reports, six-monthly operational reports and notification of specified material changes, incidents and emerging risks; proposed material business-plan changes require at least four months’ notice, while complaints-handling arrangements are a separate requirement. The result is a securities-law framework with additional DLT-specific requirements, not an unchanged process with a blockchain label.



The 2024 exploratory work: three approaches to the cash leg


Between May and November 2024, 64 participants across nine jurisdictions completed 58 use cases, settling almost €1.6 billion in central bank money through the Eurosystem’s exploratory programme. The programme tested three approaches:


  • Bundesbank Trigger Solution: A technical bridge connected market DLT platforms to T2, the Eurosystem’s real-time gross settlement (RTGS) system.


  • Banca d’Italia TIPS Hash-Link: An interface connected market DLT platforms with a TIPS-like payment platform and linked the transaction legs.


  • Banque de France Full DLT Interoperability, or DL3S: Cash tokens supported settlement on a Eurosystem DLT platform, with underlying central bank money held through an exploratory escrow arrangement.


These were not exclusively laboratory exercises: Siemens issued a €300 million digital bond, and Slovenia issued a digital sovereign bond during the programme. Siemens’ €300 million bond was issued under Germany’s Electronic Securities Act, with DekaBank acting as registrar and settlement using SWIAT’s private permissioned blockchain and the Bundesbank’s Trigger Solution. The example illustrates why national issuance law must not be confused with a Pilot Regime venue permission.


Pontes builds on the programme as a whole rather than being described by the European Central Bank (ECB) as the continuation of one winning design. The historical trials explain its origins, but current operating documents, not trial assumptions, govern the explanation below.



Pontes: how the initial service works


Pontes supports two cash-settlement routes, both linked to market DLT platforms through Hash-Link: direct T2 settlement and cash-token settlement on the Eurosystem DLT. This article calls them Option A and Option B. Their most important practical distinction is when the recipient receives final central bank money.


Question

Option A: direct T2

Option B: cash tokens at launch

Where is liquidity used?

T2 RTGS accounts.

Dedicated Cash Wallets funded from T2.

When is cash final in central bank money?

When the payment settles in T2.

On defunding or the end-of-day sweep into T2.

What additional work is involved?

RTGS liquidity, mandates and payment instructions.

Wallet funding, token balances and defunding, as well as the T2 connection.

Is weekend settlement available?

Not in the initial service.

Not in the initial service.


Option A: direct settlement in T2


The transaction is coordinated with the market DLT, while payment settles through the participating institutions’ T2 RTGS accounts and reaches finality there. Cash need not first be converted into Pontes cash tokens.


In simplified terms, the asset is locked on the market DLT, the buyer’s payment is processed through the direct T2 route, and successful settlement allows the asset to be released under the Hash-Link arrangement. An investor may use an eligible settlement bank rather than hold its own RTGS account, as demonstrated by cash-settlement-agent arrangements in the earlier trials.


Option B: cash tokens on the Eurosystem DLT


At initial launch, a cash token is a proxy for euro central bank money: a contractual claim against the ECB to transfer the corresponding amount to its owner’s T2 RTGS account. It must not be confused with a private stablecoin or with immediate final settlement in central bank money on the Eurosystem ledger.


The funding and settlement cycle is:


  1. A participant requests funding of its Dedicated Cash Wallet; the corresponding money moves from its T2 RTGS account through the ECB’s Technical Interim Account to the ECB’s Token Issuance Account.

  2. Cash tokens are issued and credited to the participant’s wallet, where they can be used for supported transactions.

  3. A cash-token payment debits and credits the relevant wallets, with Hash-Link connecting the payment outcome to the asset leg.

  4. Defunding redeems tokens and returns the corresponding money to T2; it may be requested during the applicable window, while the normal end-of-day process sweeps remaining balances back to T2.


Wallet balances change immediately, but finality in central bank money follows the corresponding T2 settlement on defunding or the end-of-day sweep. That timing should be explicit in client documentation and treasury procedures.


How Hash-Link connects delivery and payment


The seller locks the asset in a contract on the market DLT using information generated by Pontes; successful payment makes an execution key available to the buyer, while the relevant failed-payment or timeout outcome permits a cancellation key to be released to the seller. The buyer can use the execution key to obtain the asset, or the seller can use the cancellation key to recover it under the applicable conditions.


This is an all-or-none control mechanism, not a promise that separate ledgers update at precisely the same instant; the asset-side contract is outside Pontes, and the market DLT operator remains responsible for the asset leg. Technical coordination does not remove the need to understand each leg’s legal finality.


Operating hours and settlement times


At initial launch, start-of-day funding and cash-token transfers run from 08:00–09:00, the full transaction window runs from 09:00–16:00, and end-of-day processing runs from 16:00–18:00 in Frankfurt local time, CET/CEST. Pontes operates on weekdays excluding TARGET euro holidays, so T2’s longer operating day does not extend the initial Pontes transaction window.


The initial documentation describes direct T2 finality and immediate wallet updates, but those descriptions are not an unconditional end-to-end seconds guarantee covering the asset platform, funding and every exception. For planning, distinguish the intended settlement date, the processing time once a valid instruction is submitted, and the legal cash-finality event.



Who can connect, and which settlement route should they choose?


The ECB distinguishes eligible market participants with T2 access from eligible market DLT operators, including qualifying CSDs, DLT SS and DLT TSS operators, overseen payment systems in the EU or European Economic Area, authorised central counterparties and certain other licensed financial institutions meeting additional oversight or assessment criteria. Eligibility is not automatic onboarding, and a MiCA crypto-asset service provider (CASP) licence alone is not a substitute for satisfying the relevant Pontes criteria.


The settlement route is selected when the DvP transaction is initialised and is then fixed for that transaction’s lifecycle. It is a choice to agree in advance, not a switch to make halfway through settlement.


My practical recommendation is to choose by reference to the venue’s supported connection, liquidity arrangements and the recipient’s need for final central bank money. The direct route may suit a bank prioritising immediate T2 finality, while the cash-token route may suit a funded-wallet workflow, provided its documentation recognises the later T2 finality event.


Pontes is institutional settlement infrastructure, but that does not mean every investor in a tokenised instrument must be an institution: the Pilot Regime permits qualifying natural persons to participate under specified conditions. Central-bank access and investor eligibility are different questions.


Diagram comparing two Pontes settlement routes. Direct T2 settlement: lock the asset, settle payment in T2, make the execution key available, then release the asset. Cash-token settlement: fund the wallet, lock the asset, transfer tokens and release the asset, then redeem into T2. Navy boxes mark final cash settlement at the T2 payment step in the first route and the redemption step in the second. Asset-leg legal finality requires separate assessment.
Pontes’ two settlement routes: direct payment in T2, or cash-token transfer on the Eurosystem DLT followed by redemption into T2. In the initial service configuration, final cash settlement occurs in T2; asset-leg finality must be assessed separately.


Practical use cases


The following examples are hypothetical, not claims about named live transactions. The first three assume legally eligible instruments, appropriately authorised and onboarded parties, sufficient liquidity and compatible systems; the fourth illustrates a possible future service.


A €400 million corporate bond through the direct T2 route


A German industrial company plans a five-year, €400 million plain-vanilla bond offered solely to qualified investors. It selects a DLT TSS with the necessary permissions, aggregate capacity and Pontes connectivity.


The assumed issue size is within the general debt threshold, while the qualified-investor-only offer can rely on the relevant prospectus exemption; admission rules, issuance law and any additional listing must still be assessed. In this illustration, the investors’ settlement banks pay through T2 during the Pontes transaction window, and Hash-Link controls release of the bonds against successful payment.


The commercial point is that the investor can participate through a settlement bank rather than becoming a central-bank account holder. Tokenised issuance and central-bank settlement access remain separate parts of the operating model.


An intraday repo between two banks


Bank A wishes to borrow €50 million from Bank B against eligible tokenised securities from 09:30 to 15:00 on the same business day. The banks agree to use the direct T2 route and assume both legs can be processed within the initial Pontes transaction window.


The opening leg transfers collateral against cash, while the closing leg reverses those movements under the agreed repo terms; the assumed times fall within the 09:00–16:00 full transaction window. The earlier HQLAX, Clearstream, Goldman Sachs and Eurex Repo trials provide a real example of intraday triparty repo settlement using central bank money, but do not imply that Pontes removes collateral-management or triparty-agent functions.


A cash-token payment followed by defunding


At 10:00, Bank A funds a Pontes wallet with €10 million to buy an eligible tokenised bond from Bank B. Both banks have selected and support the cash-token route.


In this illustration, payment debits Bank A’s wallet and credits Bank B’s wallet, with Hash-Link controlling release of the bond; Bank B then requests defunding, and finality in central bank money follows the corresponding T2 settlement. The example highlights why receiving cash tokens and receiving final central bank money in T2 are different events at launch.


Future scenario: weekend institutional fund trading


An Asian institution wishes to buy €80 million of eligible tokenised fund units on a Saturday through an appropriately authorised venue. This is a future-service scenario, not an available initial Pontes workflow.


The initial service cannot settle that transaction over the weekend, while the 2028 roadmap targets overnight liquidity and 24/7 opening that could support such activity if implemented alongside the necessary venue, funding and legal arrangements. Its finality would need to follow the future service’s rules, not an assumption that Saturday token transfers simply become final in T2 on Monday.


What changes next?


The proposed expansion of the DLT Pilot Regime


The Commission’s December 2025 package proposes removing product-specific caps, expanding eligible instruments, increasing the regular aggregate admission limit to €100 billion and introducing a simplified regime with a €10 billion limit; the proposed transition triggers are €150 billion and €15 billion respectively. It would also remove automatic expiry of permissions after six years, while retaining a review by 2030 of integration into the permanent securities-law framework.


Certain MiCA-authorised trading-platform operators would also be able to seek DLT permissions subject to specified securities-law requirements. These remain proposals: the Parliament’s procedure record shows the legislation awaiting committee decision, so the expanded scope and limits must not be treated as current law.


Pontes enhancements


Pontes’ launch configuration is not its intended end state: the 2027 requirements envisage settlement finality for tokenised central bank money on the Eurosystem ledger within TARGET’s legal framework, together with 22.5-hour weekday availability. The 2028 roadmap targets overnight balances, multicurrency possibilities and 24/7 opening, all of which must be presented as planned rather than current capabilities.


The July 2026 requirements retain direct T2 settlement for initial launch and the 2027 enhancements, but place it outside the scope of the 2028 Enhanced Product. That is a published design-scope statement to monitor, not an unconditional promise about a future withdrawal date.


Appia and the wider market design


Appia addresses the broader ecosystem rather than simply adding features to Pontes: its roadmap, published on 11 March 2026, explores how European tokenised wholesale markets could be designed, with a blueprint planned for 2028. The questions include shared versus interconnected DLT networks, common standards, governance and the trade-offs between technological, market and broader economic considerations.


The two initiatives are complementary, and Appia’s work is intended to inform Pontes enhancements as well as market-led infrastructure. Appia is therefore not a third settlement route available to a bank today.


The retail digital euro is a separate project, with a 12-month pilot planned from the second half of 2027 and potential first issuance in 2029 conditional on legislation and a subsequent ECB decision. It should not be confused with institutional access to Pontes.



Switzerland shows this is not an EU first


The EU should receive credit without claiming to have invented the approach: the Swiss National Bank has provided wholesale central bank digital currency on SIX Digital Exchange through Project Helvetia since the end of 2023. In June 2025, it extended the pilot until at least mid-2027 and added a production-environment link between BX Digital and Swiss Interbank Clearing for settlement in traditional central bank money, while expressly withholding any commitment to permanent wholesale CBDC provision.


Pontes’ significance lies in creating a common Eurosystem offering for eligible market DLT platforms and participants, rather than in being the first experiment of its kind. My assessment is that the quality of that shared infrastructure, and whether institutions use it, matters more than a contest over who announced tokenisation first.



What this means for regulated firms


My advice is to start with the operating model, not the technology label. The priorities differ by institution:


  • DLT venue operators: Assess settlement connectivity, liquidity providers, onboarding and the cash-finality terms promised to users; a DLT MTF should identify the settlement infrastructure for its trades rather than assume its trading permission also covers settlement.


  • Banks, CSDs and investment firms: Compare the two launch routes against treasury processes, client-account arrangements and operational support, and plan for the documented enhancement path.


  • CASPs: Keep crypto-asset permissions separate from securities activities; MiCA excludes financial instruments, while current Pilot Regime permissions follow the applicable investment-firm, market-operator or CSD framework.


  • Stablecoin issuers: Treat Pontes as an additional institutional settlement alternative, not proof that private settlement assets will disappear; the commercial effect will depend on access, availability, integration costs and user demand.


  • Non-EU groups: Map the required securities and crypto-asset permissions separately, then assess venue access and settlement connectivity rather than treating MiCA, the Pilot Regime and Pontes as one licence.



Five questions before choosing your operating model


Before committing to a venue or settlement design, I would ask the project team to answer five questions in writing. They provide a useful test of whether the proposal is ready to move beyond a technology demonstration:


  1. What legal rights does the token represent?

  2. Which permissions and venue arrangements does the business need?

  3. Who provides the cash-settlement access?

  4. When does each leg become legally final?

  5. What happens if payment, delivery or defunding fails?


If those answers are unclear, a faster ledger will not resolve the underlying design problem. Getting them right is the work that turns an interesting concept into an investable, operable business.



Credit for building, without pretending the work is finished


Europe should not be praised for moving slowly. It should be praised when patient institution-building produces something useful.


Trust in tokenised finance can be built from the top down: through the settlement asset, accountable operators and clear legal rights, before it reaches the end investor. Pontes is an institutional start, not the completion of that process.


Slow and steady is not a defence of unnecessary regulation. It earns its place only when something useful gets built. Europe should be judged on that distinction, and deserves credit for this step.


At Pnyx Hill, we advise regulated institutions on licensing, operating models, governance and market-entry strategy across the EU, the UAE and Central Asia. If your firm is evaluating tokenised financial instruments, we can help map the regulatory perimeter, venue requirements and settlement arrangements into a practical implementation plan.







References


Official regulatory publications, legislation and first-party announcements supporting the article.


  1. European Central Bank — Pontes launch: “Eurosystem brings central bank money to tokenised finance”, 21 September 2026

  2. European Securities and Markets Authority — DLT Pilot Regime overview

  3. European Central Bank — Appia roadmap for Europe’s tokenised finance, 11 March 2026

  4. European Securities and Markets Authority — Register of authorised DLT market infrastructures (PDF)

  5. 21X — Announcement of EU authorisation for its blockchain-based trading venue

  6. 21X — Trading and settlement system goes live on Stellar

  7. European Securities and Markets Authority — Prospectus Regulation, Article 1: subject matter, scope and exemptions

  8. EUR-Lex — Regulation (EU) 2024/2809: Listing Act amendments to the Prospectus Regulation and other market rules

  9. European Central Bank — Report on exploratory work on new technologies for wholesale central bank money settlement, June 2025

  10. Siemens — Digital bond issued on blockchain and settled in central bank money, 4 September 2024

  11. European Central Bank — Pontes: settlement model, design overview and participation criteria

  12. European Central Bank — Pontes Pilot Service Description, version 1.0 (PDF)

  13. European Central Bank — Information Guide for Pontes Pilot participants, July 2026 (PDF)

  14. Deutsche Bundesbank — Trials and experiments conducted with the Trigger Solution

  15. European Central Bank — Pontes timeline, use cases and key milestones, 22 July 2026 (PDF)

  16. Council of the European Union — Presidency discussion paper on the DLT Pilot Regime review, WK 2365/2026 REV 1, 13 February 2026 (PDF)

  17. European Parliament — Legislative procedure 2025/0383(COD): capital market integration and supervision amendments (PDF)

  18. European Central Bank — Digital euro pilot

  19. Swiss National Bank — Extension and expansion of Project Helvetia, 30 June 2025

  20. EUR-Lex — Regulation (EU) 2017/1129: Prospectus Regulation, original Official Journal text (PDF)

  21. EUR-Lex — Regulation (EU) 2023/1114: Markets in Crypto-Assets Regulation (MiCA), original Official Journal text (PDF)

  22. Regulation (EU) 2022/858 — DLT Pilot Regime, original Official Journal text, hosted by the Cyprus Securities and Exchange Commission (PDF)

  23. European Central Bank — Pontes Initial Enhancements: User Requirements Document, final version 1.0, published 22 July 2026 (PDF)

bottom of page