Blog

How to become a payment aggregator

To become a payment aggregator in Russia, you need a Russian legal entity and a contract with a money transfer operator — a bank or a non-bank credit institution; below, for short, we call both a bank. Under Federal Law No. 161-FZ “On the National Payment System”, the aggregator is a bank payment agent of that bank and acts on its behalf. The law’s Article 14.1 (in Russian) does not require the aggregator to hold its own Bank of Russia licence: the bank submits information about it for the Bank of Russia’s list. Then come the legal obligations: a separate special account for the money of merchants (shops and services that accept payments through the aggregator), if the aggregator takes part in the transfer; identification of merchants, if the bank assigns it; the Bank of Russia’s data security requirements.

The provisions are as worded on 2 October 2026: 161-FZ and 115-FZ (on anti-money laundering) as amended on 4 August 2026, 103-FZ (on payment agents) as amended on 9 April 2026, 54-FZ (on cash register equipment) as amended on 24 June 2025, Bank of Russia Regulation No. 821-P with the amendments in force from 1 October 2026. Amendments to 161-FZ that have been adopted but are not yet in force (Laws No. 210-FZ and No. 283-FZ) do not affect the provisions we cite. Prices were collected on the same day, each with its source. The legal part is for reference only: have a lawyer check your launch setup.

Payment agent and aggregator: what is the difference

A payment agent operates under Federal Law No. 103-FZ; a bank payment agent and an aggregator operate under 161-FZ. An aggregator is a special case of a bank payment agent (Part 1 of Article 14.1) that works with electronic means of payment (EMPs, such as bank cards).

Payment agentBank payment agentPayment aggregator
Law103-FZ, Article 2 (in Russian)161-FZ, Article 14161-FZ, Article 14.1
Who can be onea Russian legal entity other than a credit institution, or a sole proprietora legal entity other than a credit institution, or a sole proprietor (Article 3)only a legal entity incorporated under Russian law
Contracta payment acceptance operator — with suppliers of goods and services; a sub-agent — with the operatorwith the bank; the agent acts on its behalfwith the bank; the aggregator acts on its behalf
What it doesaccepts cash payments from individuals; the law does not apply to non-cash settlements (Article 1)accepts and pays out cash, including through ATMs; provides clients with the bank’s EMPsenables merchants to accept EMPs and takes part in transferring money to them
Accountspecial bank account (Article 4)special account for cashseparate special account at the bank that engaged it, if it takes part in transfers

The main differences are cash versus non-cash money and on whose behalf the work is done. The Bank of Russia confirms in its answers to questions on 161-FZ (answer updated 11 August 2023, in Russian) that the aggregator acts on behalf of the bank that engaged it.

What 161-FZ requires of a payment aggregator

The requirements for an aggregator are set out in Articles 14.1 and 14.2 of 161-FZ; some of them depend on what the bank assigns to it.

For any aggregator

  • Form — a legal entity incorporated under Russian law (Clause 1 of Part 2 of Article 14.1).
  • Contract with the bank (Part 1). The aggregator signs contracts with merchants on behalf of the bank and on the bank’s terms (Clause 2 of Part 2). Merchants can also include persons in private practice listed in Part 13 (notaries, lawyers who have set up their own law offices and others) and self-employed people paying the professional income tax.
  • Information for the bank — about merchants and for resolving disputes (Clauses 3–4 of Part 2).
  • Public information. Before starting work, the aggregator discloses at every place where it operates information about itself and the bank, the contract details, ways to file complaints and how they are handled (Clause 5 of Part 2).
  • Bank oversight. The bank checks how the aggregator complies with the terms of its engagement, AML/CFT legislation (anti-money laundering and countering the financing of terrorism) and its contracts with merchants, and may terminate the contract if there are violations (Parts 8–10 of Article 14.2).
  • Bank of Russia list. The bank submits information about the aggregator to it (Parts 11–12 of Article 14.1). The list (in Russian) as of 1 October 2026 contains 85 aggregators.

If the aggregator takes part in transferring money

Buyers’ money goes to the aggregator’s separate special account at the same bank (Part 6). Only five operations are allowed on the account: crediting payments and refunds, transfers to merchants, debiting the aggregator’s fee and debiting in favour of the bank (Parts 7–8). This money cannot be seized or used to recover the aggregator’s own debts, and operations on the account cannot be suspended (Parts 9–10).

Articles 14.1 and 14.2 do not set a deadline for paying out to the merchant: it is usually set by the contract, and the bank monitors timeliness (Part 9 of Article 14.2). Ask a lawyer whether the transfer deadline in Part 5 of Article 5 (up to three business days) applies.

If the aggregator provides merchants with software for accepting payments

In that case the law sets these conditions of engagement: compliance with the Bank of Russia’s data security requirements, sending the bank information about operations, and a ban on transferring information about operations abroad or giving access to it from abroad, except for cross-border transfers (Part 5 of Article 14.1). This leads to a requirement on where the platform is hosted: where the servers are and from where they can be accessed. The data security requirements themselves are mandatory for any bank payment agent, even if the aggregator only takes part in transfers (Part 3 of Article 27).

If the bank assigns the aggregator to check merchants

Under the contract, the bank may assign the aggregator to identify merchants, their representatives, beneficiaries and beneficial owners and to update information about them (paragraph 2 of Clause 1.5 of Article 7 of 115-FZ, in Russian). The aggregator then needs an AML/CFT officer on staff, and that officer, the head and the chief accountant must not have an unexpunged or unspent conviction for economic crimes (Part 4 of Article 14.1). The aggregator passes the information to the bank in full immediately, and no later than three business days from the day it was obtained. It is liable for violations under the contract, and the bank may terminate the contract (Clauses 1.7–1.9 of Article 7 of 115-FZ).

Data security: 821-P, GOST 57580 and EAL 4

Data security requirements for transfers are set by Bank of Russia Regulation No. 821-P of 17 August 2023 (in Russian); from 1 October 2026 the amendments of Directive No. 7220-U of 28 October 2025 (in Russian) apply. From that date the aggregator protects the processes it actually has: enabling payment acceptance and preparing electronic messages when it takes part in transfers (Clause 3.2). The key points for an aggregator:

Requirement821-P provisionWhat it means
Infrastructure protection levelClause 3.5no lower than the minimum, level 3 under GOST R 57580.1-2017 (in Russian)
Compliance assessmentClauses 1.1, 3.6at least once every two years, under GOST R 57580.2-2018 (in Russian), by an organisation licensed for technical protection of confidential information; the report is kept for at least five years
Assessment resultClause 3.7a compliance level no lower than the fourth under clause 6.9 of GOST R 57580.2-2018
Penetration testing (pentest) and vulnerability analysisClauses 1.1, 3.9annually and according to the bank’s criteria
Application softwareClauses 1.2, 3.9, 3.10software for clients and software that receives electronic messages over the internet: FSTEC (Federal Service for Technical and Export Control) certification at trust level 6 or higher, or an assessment at EAL 4 or higher (evaluation assurance level under GOST R ISO/IEC 15408-3-2013, in Russian), which can be carried out in-house; when — according to the bank’s criteria

7220-U added to Clause 1.2: after a change to the source code that implements security measures, the software must be certified or assessed again. Check with the bank and a lawyer how this provision applies to you.

Compliance with 821-P is monitored under the contract by the bank that engaged the aggregator; the same bank decides, according to its risk management system, when and how often penetration testing, compliance assessment and software assessment are needed (Clause 2.11). The Bank of Russia requests information about this monitoring from the bank (Subclause 8.1.2).

The 821-P requirements are addressed to the aggregator: a vendor can hand over software with a certificate or an assessment, but it will not carry out the compliance assessment of your infrastructure or the penetration testing for you. The Payweb platform page says the platform meets Bank of Russia and PCI DSS requirements (821-P, EAL 4); PCI DSS is the payment card data security standard, not a Bank of Russia requirement (more in our guide). Ask any vendor, including us, for an EAL 4 software assessment report or an FSTEC certificate showing the date and the software version, and ask who carries out the reassessment after updates.

What an aggregator platform must do

FeatureWhy, and under which provision
Card payment acceptance (acquiring)software for accepting EMPs (Clause 2 of Part 3 of Article 14.1); data on operations must not be transferred abroad (Part 5)
SBP (the Bank of Russia’s Faster Payments System)accepting QR code payments under the rules of NSPK (National Payment Card System JSC)
Merchant onboarding and checksidentification under 115-FZ, if the bank has assigned it
Payouts to merchants and special account accountingonly the operations listed in Part 7 of Article 14.1
Reports for the bankinformation about merchants and operations (Parts 2 and 5 of Article 14.1)
Action log and protection of electronic messageslogging of actions with protected information and the technological measures of 821-P (Clauses 1.4, 3.11, Appendices 1–⁠2)
Online cash registerreceipts under 54-FZ
Fraud protection (anti-fraud)not mentioned in Article 14.1; the Bank of Russia recommends that banks and aggregators transfer to merchants only amounts from positive authorisations (Clause 3 of Recommendations No. 13-MR of 12 October 2023, in Russian). This is not a statutory rule; discuss the requirements with the bank

SBP. A non-bank organisation signs a payment aggregator engagement contract with a bank that participates in SBP and a contract with the seller, and then itself submits to NSPK an application to join the rules for agents of TSP (trade and service enterprises), signed with a qualified electronic signature. NSPK reviews the documents within up to 30 business days (agent connection procedure; clause 2.2.2 of Rules P.235, version 4.0 of 12 September 2024; both in Russian).

Online cash register. Cash register equipment under 54-FZ is mandatory for non-cash payments too; for payments on the internet the receipt is sent electronically (Clauses 1 and 5 of Article 1.2, in Russian). 54-FZ has no provisions on aggregators, but it does have provisions on receipts of a bank payment agent (Clause 4 of Article 4.7 of 54-FZ, Part 4 of Article 14.2 of 161-FZ). Decide with a lawyer who issues which receipt in your setup.

Launch step by step

  1. Set up a Russian legal entity.
  2. Decide what you do for the bank: provide merchants with software, take part in transferring money, check merchants.
  3. Sign a contract with the bank and, if you take part in transfers, open a special account with it.
  4. Prepare the platform and infrastructure under 821-P without transferring data on operations abroad; get an FSTEC certificate or an EAL 4 software assessment report from the vendor.
  5. Carry out penetration testing and a compliance assessment; check with the bank when the first assessment is needed.
  6. For SBP, submit an application to NSPK.
  7. Disclose information about yourself and the bank, and onboard merchants on the bank’s behalf.

Timeline and cost

According to developer Surf (article of 16 April 2026, in Russian), a simple payment aggregator costs from 15 million roubles and takes at least 6–9 months to build, with 9–12 months being optimal.

Prices for the 821-P checks that the aggregator goes through itself, even on a ready-made platform:

WorkPrice and timeline
Compliance assessment under GOST R 57580.2from 500,000 roubles — LiteraFort (in Russian); from 600,000 roubles, 1–⁠1.5 months — Oreol Security (in Russian)
EAL 4 software assessmentvulnerability analysis — from 315,000 roubles, from 6 weeks, full assessment — on request (LiteraFort); vulnerability analysis — from 512,000 roubles, from 8 weeks, applicant documentation — from 992,000 roubles, from 10 weeks (RTM Group, in Russian)
Penetration testing: external resourcesfrom 200,000 roubles, from 2 weeks — RTM Group; from 350,000 roubles, 2–⁠3 weeks — Oreol Security
Penetration testing: internal resourcesfrom 300,000 roubles remotely, from 4 weeks — RTM Group; from 450,000 roubles, 2–⁠4 weeks — Oreol Security

Prices are the lower bounds from the companies’ websites as of 2 October 2026. The scope of testing, and whether you need your own software assessment when the vendor already has one, is decided by the bank (Clause 3.9 of 821-P).

Payweb’s aggregator software is paid for as a subscription and launches in 30 days. That is the time to launch the software, not to obtain the status: the contract with the bank, NSPK’s review of documents and the compliance assessment run separately. The software includes:

  • card payments and acquiring;
  • payment processing;
  • SBP;
  • mass payouts;
  • subscription payments;
  • anti-fraud tools;
  • online cash register integration.

Merchant checks under 115-FZ, reports for the bank and special account accounting are not on the list — ask about them during the platform demo. Mass payouts, for example to individuals, are not among an aggregator’s operations: it only takes part in transferring money to merchants (Clause 3 of Part 3 of Article 14.1). Agree the payout setup with the bank and a lawyer.

PlanMonthlyHostingSetup and updates
Startfrom 340,000 roubles20,000 roubles—
Businessfrom 560,000 roublesfreefree

The Professional plan is on the platform page. If the aggregator provides merchants with software, the hosting included in the plan is suitable only if information about operations is not transferred abroad and cannot be accessed from abroad, including by our support team (Clause 3 of Part 5 of Article 14.1). Agree where the servers will be and from where they will be accessed before signing the contract.

Payweb builds software and does not provide financial services: we do not obtain licences or aggregator status; your company becomes the aggregator under its own contract with the bank. For how custom development differs from a ready-made platform under your own brand (white label), see Custom development or white label; for the costs of running your own system after launch, see How much does it cost to develop a payment system. If you want to run the numbers for your case, tell us about the project — we will pick a plan and show you the platform.

Contact