Standards/en-18184
EN 18184
Overview
EN 18184:2025 ("Financial services — Specification of QR codes for mobile initiated (instant) credit transfers") is a European Standard from the European Committee for Standardization (CEN) that specifies a common QR-code format for initiating mobile (instant) credit transfers (MCTs), in which the payer uses a mobile device to initiate the payment transaction [1]1. The QR code carries the data exchanged between payer and payee to enable initiation of the (instant) credit transfer by the payer, and the document is applicable both to cases where the QR code is presented by the payee and where it is presented by the payer [1]1.
EN 18184 is the formal European standardisation of work originally produced by the European Payments Council (EPC) and its Multi-Stakeholder Group on Mobile Initiated SEPA (Instant) Credit Transfers (MSG MSCT). Its purpose is to enable interoperability across schemes and solutions for SEPA Instant Credit Transfer (SCT Inst)-based and classic SCT-based mobile payments at the point of interaction, so that a single QR-code grammar can be read across borders and across competing wallets [3]3.
It is important to note what EN 18184 does not fix: it defines the structure (the URL-based "envelope") and the coding of routing fields, but it deliberately excludes the detailed technical infrastructure and the detailed payload implementation, which remain at the discretion of the scheme or payload issuer [1][1][2]2.
History
The lineage of EN 18184 runs through more than a decade of EPC QR-code work:
- 2012 — The EPC published "QR-code — Guidelines to enable data capture for the initiation of a SEPA credit transfer", a clear-text format in which all data elements (BIC, name, IBAN, amount, remittance, etc.) reside directly in the QR code [3]3. This is the ancestor of national clear-text schemes such as the Austrian/German EPC QR code (Girocode/Stuzza).
- 2018 — The MSG MSCT originally based its MCT QR-code specification on a similar clear-text format. However, market feedback during public consultation on the MSCT Interoperability Guidance (EPC269-19) rejected the clear-text approach and requested a URL-based QR code for maximum flexibility [3]3.
- November 2021 — The Euro Retail Payments Board (ERPB), chaired by the European Central Bank, issued a statement whose "Recommendation A" tasked the EPC with standardising QR codes for mobile-initiated (instant) credit transfers. The EPC asked the MSG MSCT to execute the work [3]3.
- 2022–2023 — The MSG MSCT generalised the earlier ERPB "QR-codes for IPs at the POI" work (EPC212-21) to cover all payment contexts and both instant and classic SCT, publishing "Standardisation of QR-codes for MSCTs" (EPC024-22) after an eight-week public consultation. A generic, ISO-formatted version (EPC193-22) was submitted to ISO TC 68 / SC 9 (Financial services — Information exchange for financial services) under the fast-track procedure [2][2][3]3.
- 2023 — ISO ballot fails. The ISO TC 68/SC 9 DIS ballot on the document closed on 19 July 2023 with the standardisation proposal rejected by SC 9 [5]5.
- 2024 — pivot to CEN. The EPC opened a liaison process with CEN, finalised in March 2024, and the work was taken up in CEN/TC 225 (AIDC — Automatic Identification and Data Capture) under CEN's fast-track route [5]5.
- 2025 — The standard was finalised and published as EN 18184:2025, adopted nationally as BS EN 18184:2025 (UK), NEN-EN 18184 (Netherlands), SS-EN 18184:2025 (Sweden), I.S. EN 18184:2025 (Ireland) and others [1][1][5][5][7]7.
Technical specification
EN 18184 is built on the URL-based grammar defined in the EPC's ISO-format draft (EPC193-22), which it standardises [2]2.
Two modes. The standard distinguishes [2]2:
- Payee-presented QR codes — the data refers to payee identification data and transaction data (e.g. a merchant POI display or a payee's mobile device, scanned by the payer).
- Payer-presented QR codes — the data refers to payer identification data (e.g. a consumer's wallet showing a code, scanned by the merchant's POI).
URL envelope. The QR code is a valid https:// URL with a recognisable, ordered structure [2]2:
HTTPS://<Domain_name>/<Version>/<Type>/<MCT service provider ID>/<Payload>
- Domain_name — refers to an MCT Interoperability Framework or Scheme (e.g.
qr.INTFRM.org); supports subdomains and a look-up service for cross-scheme interoperability [2]2. - Version —
/1/is the first version; supports future updates [2]2. - Type — for payee-presented codes, indicates the payment context, coded as
/m/mobile payment at the POI,/e/e-commerce/m-commerce,/i/invoice payment,/p/person-to-person,/w/opening a URL in a webview (virtual POI). For payer-presented codes the type is reserved for future use (e.g. refunds) [2]2. - MCT service provider ID — a 3-character alphanumeric identifier assigned by the Interoperability Framework/Scheme for routing [2]2.
- Payload — carried as a URL query string (
?...&...), at the discretion of the payload issuer; must contain the minimum data set [2]2.
Minimum data sets. Rather than always embedding the IBAN and amount in clear text, the spec defines three payee-presented variants [2]2:
- Token —
[Version]+[Type]+[Payee MCT Service Provider ID]+[(payee) token]; the token is de-tokenised by the payee's service provider via an Information/Transaction Information Request over the hub. - Proxy — adds a proxy for the payee data plus a clear-text name/value string; the proxy is resolved by the payee's service provider.
- All data in clear — payee name, trade name, PA-ID (e.g. IBAN), ASPSP-ID, amount, transaction identifier, etc., directly in the payload, enabling immediate initiation.
The payer-presented minimum data set is [Version]+[Type]+[Payer MCT Service Provider ID]+[(payer) token]+[clear-text name/value string] [2]2.
Underlying symbology and references. The QR symbol itself is ISO/IEC 18004; the source draft cites ISO/IEC 18004:2015, ISO 12812-1:2017 (mobile financial services framework) and ISO 9362 (BIC) [2]2.
Security. Because a payee-presented code with data "in clear" can be tampered with (redirecting funds or changing the amount), the spec strongly recommends integrity protection of clear-text payloads, recommends a dynamic token for C2B payments, and notes some countries recommend the PA-ID (IBAN) not appear in clear in a payee-presented code [2]2.
Governance / registration. Routing depends on a registered MCT service provider identifier; the EPC/ERPB framework envisages a Registration Authority issuing these identifiers as part of an overall Interoperability Framework governance [9]9.
Caveat: the full normative text of EN 18184:2025 is paywalled (≈€310). The field grammar above is taken from the EPC's openly published ISO-format draft (EPC193-22) that CEN standardised; details may have changed in the final published standard.
Use cases
EN 18184 targets all mobile-initiated SEPA credit-transfer payment contexts — person-to-person (P2P), consumer-to-business (C2B), business-to-business (B2B) and business-to-consumer (B2C) — and addresses both SCT Inst and classic SCT payments [3]3. Concrete contexts encoded in the Type field include mobile payment at the physical POI, e-commerce/m-commerce, invoice payment, P2P, and virtual-POI/webview flows [2]2.
Strategically, the standard is positioned as the cross-border "glue" allowing instant-payment QR schemes and account-to-account wallets — including the bank-backed European wallet Wero (European Payments Initiative) running on SEPA instant rails — to interoperate at the point of interaction rather than fragmenting into incompatible national QR formats [4]4.
Comparison
- vs national EPC clear-text QR (Girocode / Stuzza / EPC QR code): the classic EPC QR code embeds BIC, name, IBAN, amount, reason and remittance directly as fixed lines of text [8]8. EN 18184 instead defines a URL-based envelope with routing fields and a flexible payload that can be a token, a proxy, or clear-text — chosen for flexibility, privacy and cross-scheme routing [2][2][3]3.
- vs EMVCo Merchant-Presented Mode QR (used by Bizum QR, Wero-style and Asian QR schemes): EMVCo MPM is a TLV (tag-length-value) format. EN 18184's source draft includes an annex mapping its payload onto EMVCo TLV structures, signalling that the two can coexist (a single physical QR can carry multiple payloads for multiple schemes) [3]3.
- vs ISO (TC 68): EN 18184 is the European outcome after the same text failed the ISO TC 68/SC 9 ballot in 2023 — i.e. a regional standard rather than a global ISO standard [5]5.
Status
EN 18184 was published in 2025 and rolled out as national adoptions across CEN members (BS EN, NEN-EN, SS-EN, I.S. EN, etc.), with national catalogue/publication dates in late 2025 / early 2026 [1][1][6][6][7]7. The EPC and trade press framed the January 2026 publication as a milestone toward harmonising mobile-initiated euro payments [5]5. As of mid-2026 the standard is very new; it defines the interoperability grammar but real-world deployments depend on schemes and frameworks (notably Wero/EPI) adopting it, and no public conformant production deployment of EN 18184 specifically is documented in the sources reviewed.
Sources
1 BS EN 18184:2025 — Financial services. Specification of QR codes for mobile initiated (instant) credit transfers — BSI / en-standard.eu, 2025/2026 2 EPC193-22 v1.1 — Specification of QR-codes for mobile (instant) credit transfers in ISO format — European Payments Council, 2022 3 EPC024-22 v2.0 — Standardisation of QR-codes for MSCTs — European Payments Council, 2023 4 SEPA Request-to-Pay / Wero / SEPA Instant — Redbridge market intelligence — Redbridge, 2023 5 EU publishes new European QR code standard for payments — PaymentExpert.com, 2026 6 BS EN 18184:2025 product record — BSI Knowledge, 2025 7 SS-EN 18184:2025 — Specification of QR codes for mobile initiated (instant) credit transfers — Swedish Institute for Standards (SIS), 2025 8 EPC QR code — Wikipedia, 2024 9 Standardisation and governance of QR-codes for Instant Payments at the Point of Interaction (ERPB/2021/017) — European Central Bank / ERPB, 2021
Deployments
No country reports mention this standard by name.
Regions / aggregations not mapped to a single country
- EU