How to become a payment aggregator
To become a payment aggregator in Russia, you need a Russian legal entity and a contract with a money transfer operator — a bank or a non-bank credit institution; below, for short, we call both a bank. Under Federal Law No. 161-FZ “On the National Payment System”, the aggregator is a bank payment agent of that bank and acts on its behalf. The law’s Article 14.1 (in Russian) does not require the aggregator to hold its own Bank of Russia licence: the bank submits information about it for the Bank of Russia’s list. Then come the legal obligations: a separate special account for the money of merchants (shops and services that accept payments through the aggregator), if the aggregator takes part in the transfer; identification of merchants, if the bank assigns it; the Bank of Russia’s data security requirements.
The provisions are as worded on 2 October 2026: 161-FZ and 115-FZ (on anti-money laundering) as amended on 4 August 2026, 103-FZ (on payment agents) as amended on 9 April 2026, 54-FZ (on cash register equipment) as amended on 24 June 2025, Bank of Russia Regulation No. 821-P with the amendments in force from 1 October 2026. Amendments to 161-FZ that have been adopted but are not yet in force (Laws No. 210-FZ and No. 283-FZ) do not affect the provisions we cite. Prices were collected on the same day, each with its source. The legal part is for reference only: have a lawyer check your launch setup.
Payment agent and aggregator: what is the difference
A payment agent operates under Federal Law No. 103-FZ; a bank payment agent and an aggregator operate under 161-FZ. An aggregator is a special case of a bank payment agent (Part 1 of Article 14.1) that works with electronic means of payment (EMPs, such as bank cards).
| Payment agent | Bank payment agent | Payment aggregator | |
|---|---|---|---|
| Law | 103-FZ, Article 2 (in Russian) | 161-FZ, Article 14 | 161-FZ, Article 14.1 |
| Who can be one | a Russian legal entity other than a credit institution, or a sole proprietor | a legal entity other than a credit institution, or a sole proprietor (Article 3) | only a legal entity incorporated under Russian law |
| Contract | a payment acceptance operator — with suppliers of goods and services; a sub-agent — with the operator | with the bank; the agent acts on its behalf | with the bank; the aggregator acts on its behalf |
| What it does | accepts cash payments from individuals; the law does not apply to non-cash settlements (Article 1) | accepts and pays out cash, including through ATMs; provides clients with the bank’s EMPs | enables merchants to accept EMPs and takes part in transferring money to them |
| Account | special bank account (Article 4) | special account for cash | separate special account at the bank that engaged it, if it takes part in transfers |
The main differences are cash versus non-cash money and on whose behalf the work is done. The Bank of Russia confirms in its answers to questions on 161-FZ (answer updated 11 August 2023, in Russian) that the aggregator acts on behalf of the bank that engaged it.
What 161-FZ requires of a payment aggregator
The requirements for an aggregator are set out in Articles 14.1 and 14.2 of 161-FZ; some of them depend on what the bank assigns to it.
For any aggregator
- Form — a legal entity incorporated under Russian law (Clause 1 of Part 2 of Article 14.1).
- Contract with the bank (Part 1). The aggregator signs contracts with merchants on behalf of the bank and on the bank’s terms (Clause 2 of Part 2). Merchants can also include persons in private practice listed in Part 13 (notaries, lawyers who have set up their own law offices and others) and self-employed people paying the professional income tax.
- Information for the bank — about merchants and for resolving disputes (Clauses 3–4 of Part 2).
- Public information. Before starting work, the aggregator discloses at every place where it operates information about itself and the bank, the contract details, ways to file complaints and how they are handled (Clause 5 of Part 2).
- Bank oversight. The bank checks how the aggregator complies with the terms of its engagement, AML/CFT legislation (anti-money laundering and countering the financing of terrorism) and its contracts with merchants, and may terminate the contract if there are violations (Parts 8–10 of Article 14.2).
- Bank of Russia list. The bank submits information about the aggregator to it (Parts 11–12 of Article 14.1). The list (in Russian) as of 1 October 2026 contains 85 aggregators.
If the aggregator takes part in transferring money
Buyers’ money goes to the aggregator’s separate special account at the same bank (Part 6). Only five operations are allowed on the account: crediting payments and refunds, transfers to merchants, debiting the aggregator’s fee and debiting in favour of the bank (Parts 7–8). This money cannot be seized or used to recover the aggregator’s own debts, and operations on the account cannot be suspended (Parts 9–10).
Articles 14.1 and 14.2 do not set a deadline for paying out to the merchant: it is usually set by the contract, and the bank monitors timeliness (Part 9 of Article 14.2). Ask a lawyer whether the transfer deadline in Part 5 of Article 5 (up to three business days) applies.
If the aggregator provides merchants with software for accepting payments
In that case the law sets these conditions of engagement: compliance with the Bank of Russia’s data security requirements, sending the bank information about operations, and a ban on transferring information about operations abroad or giving access to it from abroad, except for cross-border transfers (Part 5 of Article 14.1). This leads to a requirement on where the platform is hosted: where the servers are and from where they can be accessed. The data security requirements themselves are mandatory for any bank payment agent, even if the aggregator only takes part in transfers (Part 3 of Article 27).
If the bank assigns the aggregator to check merchants
Under the contract, the bank may assign the aggregator to identify merchants, their representatives, beneficiaries and beneficial owners and to update information about them (paragraph 2 of Clause 1.5 of Article 7 of 115-FZ, in Russian). The aggregator then needs an AML/CFT officer on staff, and that officer, the head and the chief accountant must not have an unexpunged or unspent conviction for economic crimes (Part 4 of Article 14.1). The aggregator passes the information to the bank in full immediately, and no later than three business days from the day it was obtained. It is liable for violations under the contract, and the bank may terminate the contract (Clauses 1.7–1.9 of Article 7 of 115-FZ).
Data security: 821-P, GOST 57580 and EAL 4
Data security requirements for transfers are set by Bank of Russia Regulation No. 821-P of 17 August 2023 (in Russian); from 1 October 2026 the amendments of Directive No. 7220-U of 28 October 2025 (in Russian) apply. From that date the aggregator protects the processes it actually has: enabling payment acceptance and preparing electronic messages when it takes part in transfers (Clause 3.2). The key points for an aggregator:
| Requirement | 821-P provision | What it means |
|---|---|---|
| Infrastructure protection level | Clause 3.5 | no lower than the minimum, level 3 under GOST R 57580.1-2017 (in Russian) |
| Compliance assessment | Clauses 1.1, 3.6 | at least once every two years, under GOST R 57580.2-2018 (in Russian), by an organisation licensed for technical protection of confidential information; the report is kept for at least five years |
| Assessment result | Clause 3.7 | a compliance level no lower than the fourth under clause 6.9 of GOST R 57580.2-2018 |
| Penetration testing (pentest) and vulnerability analysis | Clauses 1.1, 3.9 | annually and according to the bank’s criteria |
| Application software | Clauses 1.2, 3.9, 3.10 | software for clients and software that receives electronic messages over the internet: FSTEC (Federal Service for Technical and Export Control) certification at trust level 6 or higher, or an assessment at EAL 4 or higher (evaluation assurance level under GOST R ISO/IEC 15408-3-2013, in Russian), which can be carried out in-house; when — according to the bank’s criteria |
7220-U added to Clause 1.2: after a change to the source code that implements security measures, the software must be certified or assessed again. Check with the bank and a lawyer how this provision applies to you.
Compliance with 821-P is monitored under the contract by the bank that engaged the aggregator; the same bank decides, according to its risk management system, when and how often penetration testing, compliance assessment and software assessment are needed (Clause 2.11). The Bank of Russia requests information about this monitoring from the bank (Subclause 8.1.2).
The 821-P requirements are addressed to the aggregator: a vendor can hand over software with a certificate or an assessment, but it will not carry out the compliance assessment of your infrastructure or the penetration testing for you. The Payweb platform page says the platform meets Bank of Russia and PCI DSS requirements (821-P, EAL 4); PCI DSS is the payment card data security standard, not a Bank of Russia requirement (more in our guide). Ask any vendor, including us, for an EAL 4 software assessment report or an FSTEC certificate showing the date and the software version, and ask who carries out the reassessment after updates.
What an aggregator platform must do
| Feature | Why, and under which provision |
|---|---|
| Card payment acceptance (acquiring) | software for accepting EMPs (Clause 2 of Part 3 of Article 14.1); data on operations must not be transferred abroad (Part 5) |
| SBP (the Bank of Russia’s Faster Payments System) | accepting QR code payments under the rules of NSPK (National Payment Card System JSC) |
| Merchant onboarding and checks | identification under 115-FZ, if the bank has assigned it |
| Payouts to merchants and special account accounting | only the operations listed in Part 7 of Article 14.1 |
| Reports for the bank | information about merchants and operations (Parts 2 and 5 of Article 14.1) |
| Action log and protection of electronic messages | logging of actions with protected information and the technological measures of 821-P (Clauses 1.4, 3.11, Appendices 1–2) |
| Online cash register | receipts under 54-FZ |
| Fraud protection (anti-fraud) | not mentioned in Article 14.1; the Bank of Russia recommends that banks and aggregators transfer to merchants only amounts from positive authorisations (Clause 3 of Recommendations No. 13-MR of 12 October 2023, in Russian). This is not a statutory rule; discuss the requirements with the bank |
SBP. A non-bank organisation signs a payment aggregator engagement contract with a bank that participates in SBP and a contract with the seller, and then itself submits to NSPK an application to join the rules for agents of TSP (trade and service enterprises), signed with a qualified electronic signature. NSPK reviews the documents within up to 30 business days (agent connection procedure; clause 2.2.2 of Rules P.235, version 4.0 of 12 September 2024; both in Russian).
Online cash register. Cash register equipment under 54-FZ is mandatory for non-cash payments too; for payments on the internet the receipt is sent electronically (Clauses 1 and 5 of Article 1.2, in Russian). 54-FZ has no provisions on aggregators, but it does have provisions on receipts of a bank payment agent (Clause 4 of Article 4.7 of 54-FZ, Part 4 of Article 14.2 of 161-FZ). Decide with a lawyer who issues which receipt in your setup.
Launch step by step
- Set up a Russian legal entity.
- Decide what you do for the bank: provide merchants with software, take part in transferring money, check merchants.
- Sign a contract with the bank and, if you take part in transfers, open a special account with it.
- Prepare the platform and infrastructure under 821-P without transferring data on operations abroad; get an FSTEC certificate or an EAL 4 software assessment report from the vendor.
- Carry out penetration testing and a compliance assessment; check with the bank when the first assessment is needed.
- For SBP, submit an application to NSPK.
- Disclose information about yourself and the bank, and onboard merchants on the bank’s behalf.
Timeline and cost
According to developer Surf (article of 16 April 2026, in Russian), a simple payment aggregator costs from 15 million roubles and takes at least 6–9 months to build, with 9–12 months being optimal.
Prices for the 821-P checks that the aggregator goes through itself, even on a ready-made platform:
| Work | Price and timeline |
|---|---|
| Compliance assessment under GOST R 57580.2 | from 500,000 roubles — LiteraFort (in Russian); from 600,000 roubles, 1–1.5 months — Oreol Security (in Russian) |
| EAL 4 software assessment | vulnerability analysis — from 315,000 roubles, from 6 weeks, full assessment — on request (LiteraFort); vulnerability analysis — from 512,000 roubles, from 8 weeks, applicant documentation — from 992,000 roubles, from 10 weeks (RTM Group, in Russian) |
| Penetration testing: external resources | from 200,000 roubles, from 2 weeks — RTM Group; from 350,000 roubles, 2–3 weeks — Oreol Security |
| Penetration testing: internal resources | from 300,000 roubles remotely, from 4 weeks — RTM Group; from 450,000 roubles, 2–4 weeks — Oreol Security |
Prices are the lower bounds from the companies’ websites as of 2 October 2026. The scope of testing, and whether you need your own software assessment when the vendor already has one, is decided by the bank (Clause 3.9 of 821-P).
Payweb’s aggregator software is paid for as a subscription and launches in 30 days. That is the time to launch the software, not to obtain the status: the contract with the bank, NSPK’s review of documents and the compliance assessment run separately. The software includes:
- card payments and acquiring;
- payment processing;
- SBP;
- mass payouts;
- subscription payments;
- anti-fraud tools;
- online cash register integration.
Merchant checks under 115-FZ, reports for the bank and special account accounting are not on the list — ask about them during the platform demo. Mass payouts, for example to individuals, are not among an aggregator’s operations: it only takes part in transferring money to merchants (Clause 3 of Part 3 of Article 14.1). Agree the payout setup with the bank and a lawyer.
| Plan | Monthly | Hosting | Setup and updates |
|---|---|---|---|
| Start | from 340,000 roubles | 20,000 roubles | — |
| Business | from 560,000 roubles | free | free |
The Professional plan is on the platform page. If the aggregator provides merchants with software, the hosting included in the plan is suitable only if information about operations is not transferred abroad and cannot be accessed from abroad, including by our support team (Clause 3 of Part 5 of Article 14.1). Agree where the servers will be and from where they will be accessed before signing the contract.
Payweb builds software and does not provide financial services: we do not obtain licences or aggregator status; your company becomes the aggregator under its own contract with the bank. For how custom development differs from a ready-made platform under your own brand (white label), see Custom development or white label; for the costs of running your own system after launch, see How much does it cost to develop a payment system. If you want to run the numbers for your case, tell us about the project — we will pick a plan and show you the platform.