EPS

Austria · www.eps-ueberweisung.at · 20 vendors

EPS (Electronic Payment Standard), also known as eps-Überweisung, is an online payment method developed jointly by Austrian banks and the Austrian government. It enables consumers to make secure online payments directly through their familiar online banking system. This standard is widely used for e-commerce and e-government services in Austria.

Resilience scores

Disruption prediction

EPS has an estimated 21% probability of disruption in the next 6 months.

6 of EPS's 20 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 5 categories; runs on 20 sub-vendors.

Insights

Last updated 2026-04-15 · revision 13

20 direct vendors, 230 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

EPS exhibits medium migration readiness. The company's internal tech stack, particularly the website's reliance on Joomla, suggests a more traditional infrastructure rather than a cloud-native, containerized, or microservices-based architecture, which would complicate migration to modern cloud platforms. The core payment system, while functionally rich, lacks explicit architectural details that would indicate high cloud readiness. The regulatory environment poses significant challenges, with high-risk 'Assessment Required' statuses for GDPR, NIS2, PCI DSS, and ZaDiG 2018. Migrating a critical payment system requires meticulous planning to maintain continuous compliance with these stringent regulations, especially PCI DSS and data protection requirements. Strict GDPR data residency requirements, explicitly acknowledged by EPS through their Matomo choice, further limit cloud provider options and necessitate careful architectural design to ensure data remains within the EU/EEA. The 'Total Vendors: 0' data is contradictory; however, if interpreted as a lack of direct IT infrastructure vendors, it could imply high internal dependency or lock-in to a specific, potentially monolithic, in-house system. Conversely, the diversity of PSP partners (9 countries) suggests a complex web of integrations (29 services), which, while offering flexibility in partnerships, can increase the complexity of migrating the underlying core system and its numerous interfaces. The absence of financial stability data also prevents an assessment of the company's capacity to fund a significant migration effort.

Compliance

5 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

As an Austrian company operating payment services in the EU, PSA processes personal data of EU residents including customer transaction data, merchant data, and employee data. GDPR compliance is mandatory with severe penalties up to 4% of annual turnover or €20M. The company explicitly references GDPR Article 28 (data processor) and Article 24 (data controller) in their privacy policy, indicating awareness but requiring verification of full compliance implementation.

Evidence: https://eps-ueberweisung.at/de/datenschutzhinweis

PSD2 — Assessment Required

As a payment service provider operating in Austria/EU, PSA likely falls under PSD2 requirements. The company provides payment initiation services through eps-Überweisung system. PSD2 compliance is mandatory for payment services with significant penalties for non-compliance including operational restrictions and fines.

Evidence: https://eps-ueberweisung.at

ISO 27001 (source) — Assessment Required

ISO 27001 is highly recommended for payment service providers handling sensitive financial data. While not legally mandatory, it demonstrates information security management system implementation. Risk is moderate as major bank partners and regulatory authorities may expect ISO 27001 certification for critical payment infrastructure providers.

Financials

Three-year financials

Financial Resilience Score: 7/10

EPS / Payment Services Austria GmbH (PSA) demonstrates strong structural financial resilience despite complete opacity in its published financials. The company is owned by a consortium of virtually all major Austrian banks — including UniCredit Bank Austria, BAWAG, Erste Bank, Raiffeisen Bank International, Volksbank, and 20+ others — providing exceptional institutional backing and making liquidity or solvency risk extremely unlikely. This ownership structure effectively functions as an implicit guarantee of operational continuity. The company holds a monopoly-like position as the dominant Austrian online bank-transfer payment method, integrated into over 11,000 merchant checkouts and embedded in Austrian e-Government digital services. This dual commercial and public-sector revenue base provides meaningful non-cyclical stability and very high switching costs across its network. As a payment scheme operator rather than a credit provider, PSA carries no credit or default risk on its balance sheet, further reducing financial vulnerability. However, the complete absence of publicly available financial statements — no revenue, EBIT, equity, or net profit figures are disclosed — makes independent quantitative verification of financial health impossible. The resilience score is therefore based entirely on structural and qualitative factors. Geographic concentration exclusively in Austria (population ~9 million) caps growth potential and creates exposure to domestic economic conditions and shifting consumer payment preferences. Competitive risks from pan-European A2A payment schemes (e.g., Wero, SCT Inst expansion), global digital wallets (PayPal, Apple Pay, Google Pay), and EU open banking initiatives represent medium-term threats to eps's domestic market share. The dependency on member bank fee structures also introduces renegotiation risk if the Austrian banking sector consolidates further.

Key strengths: Bank-consortium ownership by all major Austrian banks provides exceptional institutional stability, Monopoly-like domestic position with 11,000+ merchant integrations and deep network effects, e-Government integration provides stable, non-cyclical revenue base, No credit or default risk — operates as a payment routing scheme, not a lender, PSD2-compliant A2A payment rail aligned with EU regulatory direction, Coverage across 27+ Austrian banks creates high switching costs and entrenched network

Risk factors: Complete financial opacity — no public revenue, EBIT, or equity data available for independent verification, Geographic concentration exclusively in Austria limits addressable market (~9 million population), Competition from pan-European A2A schemes (Wero, SCT Inst, iDEAL expansion) threatens domestic dominance, Fintech and digital wallet competition (PayPal, Klarna, Apple Pay, Google Pay) may erode transaction volumes, Revenue model dependent on member bank fee structures subject to renegotiation risk, No known international expansion strategy limits long-term growth prospects

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report