Europe forced the NFC chip open. The route that uses the secure element is sold in 48 territories — none of them European.
Europa hat den NFC-Chip aufgezwungen bekommen. Den Weg über das gesicherte Chipelement verkauft Apple in 48 Gebieten — keines davon in der EU.
Europe is the only place on earth where a company is legally obliged to let rival payment apps use the NFC chip in an iPhone. It is also, for in-store payments, the only place where Apple does not offer the route that puts a payment credential inside the phone’s secure element. Apple’s own developer support pages document both facts side by side: an entitlement for host card emulation, free of charge, available exclusively in the European Economic Area because the European Commission required it; and a separate NFC & SE Platform, sold under a commercial agreement with fees, listing forty-eight eligible territories, not one of which is an EU or EEA member state. The competition remedy did not merely open a door. It determined which of two doors Europe would be given.
What the Commission actually ordered
On 11 July 2024 the European Commission adopted a decision under Article 9 of Regulation 1/2003 making commitments offered by Apple legally binding. The case, AT.40452, had been open since June 2020. According to the Commission’s press release, its preliminary view was that Apple held a dominant position in the market for in-store mobile wallets on iOS and had abused it by refusing to supply the NFC input to competing developers while reserving that access for Apple Pay — conduct that may breach Article 102 of the Treaty on the Functioning of the European Union.
The commitments, as the Commission describes them, oblige Apple to give third-party wallet providers access to the NFC input free of charge, without having to use Apple Pay or Apple Wallet; to run a fair, objective, transparent and non-discriminatory eligibility procedure; to let users set a rival app as the default for in-store payments and reach it through the same shortcuts Apple Pay uses — Field Detect, which opens the default payment app when a locked iPhone meets a reader, and Double-click on the side button — and to submit to a monitoring trustee and a separate dispute settlement mechanism. After a market test between 19 January and 19 February 2024, Apple widened the offer: SoftPOS acceptance at merchant phones, the right to combine payments with other NFC uses, and the removal of the requirement that a developer hold a payment institution licence. The commitments run for ten years across the EEA. Apple’s developer documentation gives their effective date as 17 July 2024 and names the monitoring trustee as Alcis Advisers GmbH in Berlin.
One sentence in the press release deserves more attention than it gets: the commitments are without prejudice to Apple’s obligations under other regulations, “in particular relating to other use cases and functionalities within the scope of the Digital Markets Act” and the implementation of the digital euro. The antitrust case settled payments; the rest of the chip was left to a different instrument.
That instrument produced its own decision. On 19 March 2025 the Commission adopted an implementing decision under Article 8(2) of Regulation (EU) 2022/1925, case DMA.100203, specifying how Apple must comply with the Article 6(7) interoperability obligation for iOS features used by connected physical devices — iOS having been designated a core platform service on 5 September 2023. The decision records what third parties asked for: two providers wanted to provision the secure element of a wearable with payment tokens; three more wanted the NFC controller in reader/writer mode, the ability to read a bank card to verify possession during strong customer authentication; and in October 2024 two fashion companies told the Commission they were interested in products built on the same feature.
Those are not wallet vendors. They are ring makers, watch makers, and firms that want a phone to read a card the way a terminal does. The DMA opening is broader than the antitrust one, and its constituency is different.
Two doors into the same chip
Apple publishes two support pages. Reading them next to each other is the fastest way to see what Europe received. The first is titled “HCE-based contactless NFC transactions for apps in the European Economic Area.” Host card emulation means the phone imitates a contactless card in software; the credential does not live in the tamper-resistant secure element but is held by the app and its back end, typically as a network token with short-lived keys. Apple’s page states that the APIs arrived in iOS 17.4, that the developer must be established in the EEA, enrolled as an organisation, and committed to PCI DSS, EMVCo and GDPR requirements. It ends with a section headed “EC Commitments – Complaints” linking to the commitment text on the Commission’s case register. Access is free of charge, as ordered.
The second page is titled “NFC & SE Platform for secure contactless transactions.” Here the credential is an applet installed into the secure element itself, and the chain of custody is markedly heavier: the partner’s applet must be validated by an independent accredited laboratory; Apple verifies, signs and hosts the bundle; on provisioning, an Apple server creates a memory partition on the secure element and hands control to the partner’s servers for personalisation. Every transaction requires an authorisation asserted by the Secure Enclave.
To use it, in Apple’s own words from its announcement of 14 August 2024, “developers will need to enter into a commercial agreement with Apple, request the NFC and SE entitlement, and pay the associated fees.” Apple has not published a fee schedule; the terms sit behind a confidentiality agreement that the same page requires.
Now the geography. Apple’s support page lists the territories in which a developer may be established to obtain the entitlement. Counting the list as printed gives forty-eight, among them Australia, Brazil, Canada, Japan, Singapore, the United States — and, in Europe, Switzerland, the United Kingdom, Serbia, Moldova and Montenegro. No member state of the European Union or the wider European Economic Area appears on it, with one carve-out the page makes explicit: for government ID, and only for government ID, eligibility extends to the European Union from iOS 26.4.
So the position, as documented by the vendor, is this. Where a regulator compelled access, the access is free and uses host card emulation. Where no regulator compelled anything, Apple sells access to the secure element under contract. The compelled route is cheaper for the entrant and weaker technically. Nothing in the Commission’s decision required the secure element: the commitments are framed around HCE, and Apple offered them.
The access is keyed to an application identifier
The most revealing line in either document is not a paragraph of prose. It is a configuration key. To ship an HCE app in the EEA, a developer must declare, in the entitlement request and again in the app’s entitlements file, the list of Application Identifiers or Registered Application Provider Identifiers the app will use. Apple’s page prints five examples. Three are infrastructure or access vendors — the proximity payment system environment, MIFARE, HID. The other two are A0000000032020 and A0000000042010 — Visa and Mastercard, labelled as such by Apple.
An application identifier is what a terminal and a card use to agree on which payment application they are speaking, and it is issued within a registered scheme namespace. This is not a restriction Apple invented; it is how EMV contactless works everywhere. But it makes the shape of the opening concrete. If the wallet is a bank’s app in Germany or France, the credential it presents at the terminal is in almost all cases a Visa or Mastercard token, because that is what the bank issues. The wallet changes who owns the interface. It does not change whose network carries the transaction, who sets the scheme fees, or who receives the interchange — and the interchange itself has been capped since 9 December 2015 at 0.2 per cent of the transaction value for consumer debit and 0.3 per cent for consumer credit by Regulation (EU) 2015/751, a ceiling that the decades of litigation over interchange have shifted at the margins and never dismantled.
Put differently: the remedy reallocates the front end of a card transaction. Everything behind the front end is exactly where it was. That is why the arithmetic of acceptance — the part covered when we looked at what an acquirer actually earns per transaction — is untouched by which app the shopper opened.
Germany ran this experiment first
Europe has a control group, and it is six years old. In late 2019 the German Bundestag inserted § 58a into the Zahlungsdiensteaufsichtsgesetz, the Payment Services Supervision Act — a provision the trade press christened the “Lex Apple Pay”. Its operative sentence is unusually direct for a supervisory statute: an undertaking that contributes technical infrastructure services to the provision of payment services domestically must, on request from a payment service provider or e-money issuer, make those services available without undue delay, through a standardised technical interface to all devices, for a fee not exceeding the actual costs of the access, and in a way that guarantees functional equivalence. Refusal requires demonstrating that security and integrity would be concretely endangered. On paper this is stronger than the EU commitments: a statutory right, priced at cost, with functional equivalence written into the text.
What happened next is the finding. According to reporting by the German technology publication heise online in early 2020, the Sparkassen — the savings-bank group that had been the loudest voice demanding Apple open the interface — stated that they no longer sought access, once their own cards had become available in Apple Pay. That report is press, not a regulatory filing; but the observable outcome supports it. No German bank shipped a tap-to-pay wallet of its own on the iPhone in the years the statute was in force, and the demand that produced the law disappeared as soon as the banks’ cards were inside the incumbent wallet.
This is the mechanism the debate keeps understating. A bank whose card sits in Apple Pay earns the interchange on every tap and pays Apple a fee for the privilege. A bank that builds its own wallet earns the same interchange, pays Apple nothing, and takes on the cost of building, certifying and supporting a payments client, plus the marketing cost of moving customers off a default that already works. The saving is real but small; the cost is large and front-loaded; the revenue line is identical either way, because in both cases the transaction is a card transaction. Access rights do not change that calculation. They only make the unattractive option legal.
The first wallet through the door went via a domestic scheme
The exception is instructive. In December 2024 the Nordic wallet Vipps MobilePay launched tap-to-pay on iPhone — by the account of several trade publications and the company’s own announcements, the first non-Apple wallet in the world to do so. The reports state that it went live for customers of more than forty Norwegian banks at terminals accepting BankAxept, Norway’s domestic card scheme, with Visa and Mastercard support planned to follow. These are company statements relayed by the press; no supervisory authority keeps a register of such launches, so the claim of primacy cannot be checked officially.
Note what made it viable. Norway has a domestic scheme with its own terminal acceptance and its own interchange structure, and Vipps arrived with more than forty banks distributing it. Where an entrant can present a credential that is not a Visa or Mastercard token, the NFC opening changes the economics of a tap. Where it cannot — most of the European Union — the entrant is building a nicer front end for someone else’s rails.
The case for the remedy, put as its defenders would put it
The argument for the Commission’s decision is strong, and it is not the argument that the remedy would immediately reshuffle market shares.
Start with what was actually blocked before. It was never only the radio. It was the default: Field Detect and Double-click, the two paths by which a payment app can be reached on a locked phone in under a second, plus biometric authorisation. A wallet the user must unlock the phone for, find, and open cannot compete with one that appears when the phone nears a reader. The commitments cover exactly those functions, and Apple’s HCE page documents them as available to any eligible app the user selects as default. That is the difference between a right of access and a usable one — and it is the difference the mandated payee-verification warning failed to make on the liability side, where the screen changed and the allocation of loss did not.
Second, the eligibility procedure was loosened where it mattered most: dropping the requirement to hold a payment institution licence means the entitlement is not gated on being a bank, which is exactly what a wallet-platform entrant usually is not. Third, the enforcement architecture is real — ten years, a monitoring trustee, a documented complaint procedure with fifteen and twenty business day deadlines, an appeal board, and — the Commission states this in the same press release — the possibility of a fine of up to ten per cent of total annual turnover for breaching commitments, without the Commission having to establish an infringement first. Fourth, the remedy is prospective. A payment instrument that could not reach the NFC chip on iOS would be an instrument that does not work in a shop; the Commission’s press release names the digital euro’s implementation as one of the things the commitments are without prejudice to. Building that access in 2024 for a product that may exist in 2029 is not a failure of the remedy. It is the remedy doing something that only becomes visible later.
What the opening does not touch
Some numbers, all from the European Central Bank’s payments statistics published on 22 July 2026 for the second half of 2025. Euro area non-cash payments totalled 83.5 billion transactions, 6.9 per cent more than a year earlier, worth €117.8 trillion. Card payments were 57 per cent of that count; credit transfers 21 per cent, direct debits 14 per cent, e-money 6 per cent. Contactless card payments alone came to 32.9 billion, up 11.9 per cent. There were 872.7 million payment cards in circulation, at an average of about €39 per card payment, and of 25.7 million point-of-sale terminals, 93 per cent accepted contactless.
The ECB has no commercial stake in these figures; they are collected from payment service providers under an ECB regulation. Read against the remedy, the point is plain. The instrument that the NFC opening makes reachable from a competing app is the one already carrying 57 per cent of European non-cash payments, growing at roughly ten per cent a year on its own. Whichever app wins the default slot on the phone, the schemes collect on almost every tap it produces. An access remedy allocates a channel. It does not decide what travels through it.
The alternatives that would not run on card rails
Two candidates exist, and both are slower than the remedy that would carry them. Wero, the wallet of the European Payments Initiative, runs on instant credit transfers rather than card rails. By the account of EPI and of Société Générale, one of its bank shareholders, it had reached 55 million users for person-to-person payments in Belgium, France and Germany, with Luxembourg joining in 2026 and the Dutch iDEAL scheme migrating to it. These are figures published by the initiative and its owners, who have an obvious interest in a large number; no supervisor publishes an independent count. The date that matters here is the one EPI gives for in-store payments: 2027. The chip was opened in 2024. The European account-to-account alternative reaches the terminal roughly three years later.
The digital euro is further out still. The ECB reports that its preparation phase ran from November 2023 to October 2025 and has closed, that a pilot’s operational phase is planned for the second half of 2027 over twelve months, and that the Eurosystem aims to be ready for a possible first issuance in 2029 — on the working assumption that the co-legislators adopt the regulation during 2026. Every one of those dates sits inside the ten-year life of the commitments, which is presumably the point.
How confident to be
Firmly held: the two access regimes exist as described, with the terms and territory lists as Apple publishes them; the commitments bind for ten years across the EEA; the ECB’s transaction shares are what they are. Held with reasonable confidence: that building an own-brand iOS wallet is unattractive to a bank wherever the credential is a Visa or Mastercard token, and that this, not the technical barrier, is why the German statutory right went unused. Held cautiously: that the pattern persists. If Wero reaches terminals in 2027 with its own application identifier, or a digital euro arrives with a mandated place on the device, the same remedy begins working on rails the schemes do not own. The instrument was built before the payload existed.
What this does not tell you
First, nobody publishes adoption. Apple does not disclose how many HCE entitlements it has granted or how many EEA users have set a non-Apple default; the monitoring trustee reports to the Commission, not to the public; and no supervisor collects wallet-level market share. The claim that the remedy has produced few competing wallets is an inference from the absence of announcements, which is weaker evidence than it feels.
Second, the absence of EU and EEA states from the NFC & SE Platform territory list is a documented fact with an undocumented cause. Apple has not said why. Regulatory sequencing, certification workloads, contracting questions, or a deliberate choice not to sell where a free route is mandated are all consistent with the same list. Treating it as proof of intent would be reading a table as a motive.
Third, the German comparison is not clean. Section 58a covers one member state, was never tested in a published enforcement action that this research found, and coexisted with a European antitrust case that gave banks an obvious reason to wait. That the right went unused is certain; that it went unused because the economics were unattractive is the best available explanation, not a demonstrated one.
The general lesson
Access remedies are written as though the bottleneck were the interface. Usually it is the business model on the far side of it. Open the chip, and what flows through is whatever the entrant already had to sell — and if that was a card, the opening delivers a new distribution channel to the card networks at zero cost to them, paid for by a competition authority’s enforcement budget and a decade of trustee supervision. The banks asked for the door because they resented paying Apple. They will walk through it carrying Visa and Mastercard credentials, because those are the credentials they issue.
None of which makes the remedy a mistake. It makes it an infrastructure decision rather than a competition outcome. The right question about an access mandate is never “who demanded it” but “what will be carried through it, and who is paid per unit carried”. On that test, the July 2024 decision will be judged in 2027 and 2029, when there is finally something in Europe to carry that is not a card — and the chip is already open, which is the only part of the problem a competition authority was ever in a position to solve.
Europa ist der einzige Ort der Welt, an dem ein Hersteller rechtlich verpflichtet ist, fremde Bezahl-Apps an den NFC-Chip eines iPhones zu lassen. Und es ist zugleich der einzige Ort, an dem Apple für Ladenzahlungen den Weg nicht anbietet, bei dem die Zahlungsdaten im gesicherten Chipelement des Geräts liegen. Beides steht nebeneinander in Apples eigenen Entwicklerseiten: eine Berechtigung für Host Card Emulation, kostenlos, ausschließlich im Europäischen Wirtschaftsraum, weil die Europäische Kommission sie verlangt hat — und daneben eine „NFC & SE Platform”, die es nur mit Vertrag und Entgelt gibt, mit einer Liste von achtundvierzig zugelassenen Gebieten, unter denen kein einziger EU- oder EWR-Staat ist. Die kartellrechtliche Abhilfe hat nicht bloß eine Tür geöffnet. Sie hat entschieden, welche von zwei Türen Europa bekommt.
Was die Kommission tatsächlich angeordnet hat
Am 11. Juli 2024 hat die Europäische Kommission eine Entscheidung nach Artikel 9 der Verordnung 1/2003 erlassen und damit Verpflichtungszusagen von Apple für verbindlich erklärt. Das Verfahren AT.40452 lief seit Juni 2020. Nach der Mitteilung der Kommission war ihre vorläufige Einschätzung, dass Apple auf dem Markt für Bezahl-Anwendungen im Laden unter iOS marktbeherrschend ist und diese Stellung missbraucht hat, indem es den Zugang zum NFC-Eingang konkurrierenden Entwicklern verweigerte und ihn Apple Pay vorbehielt — ein Verhalten, das gegen Artikel 102 des Vertrags über die Arbeitsweise der Europäischen Union verstoßen kann.
Die Zusagen verpflichten Apple, wie die Kommission sie beschreibt, Drittanbietern den Zugang zum NFC-Eingang kostenlos zu gewähren, ohne dass sie Apple Pay oder Apple Wallet benutzen müssen; ein faires, objektives, transparentes und diskriminierungsfreies Zulassungsverfahren zu betreiben; Nutzern zu erlauben, eine fremde App als Standard für Ladenzahlungen zu setzen und sie über dieselben Abkürzungen zu erreichen, die Apple Pay hat — „Field Detect”, das die Standard-App öffnet, sobald ein gesperrtes iPhone an ein Lesegerät kommt, und den Doppelklick auf die Seitentaste; und sich einem Überwachungstreuhänder samt eigenem Streitbeilegungsverfahren zu unterwerfen. Nach einem Markttest zwischen dem 19. Januar und dem 19. Februar 2024 hat Apple nachgebessert: Annahme an Händler-Telefonen (SoftPOS), das Recht, Zahlung mit anderen NFC-Anwendungen zu verbinden, und den Wegfall der Anforderung, dass ein Entwickler selbst eine Zahlungsdienstelizenz halten muss. Die Zusagen gelten zehn Jahre im gesamten EWR. Apples Entwicklerdokumentation nennt als Wirksamkeitsdatum den 17. Juli 2024 und als Überwachungstreuhänder die Alcis Advisers GmbH in Berlin.
Ein Satz der Kommissionsmitteilung wird meist überlesen: Die Zusagen gelten unbeschadet anderer Pflichten Apples, „insbesondere in Bezug auf andere Anwendungsfälle und Funktionen im Anwendungsbereich des Digital Markets Act” sowie der Einführung des digitalen Euro. Das Kartellverfahren hat die Zahlungen geregelt; der Rest des Chips blieb einem anderen Instrument überlassen.
Dieses Instrument hat seine eigene Entscheidung hervorgebracht. Am 19. März 2025 erließ die Kommission einen Durchführungsbeschluss nach Artikel 8 Absatz 2 der Verordnung (EU) 2022/1925, Fall DMA.100203, der festlegt, wie Apple die Interoperabilitätspflicht aus Artikel 6 Absatz 7 für iOS-Funktionen erfüllen muss, die vernetzte Geräte benötigen — iOS war am 5. September 2023 als zentraler Plattformdienst benannt worden. Der Beschluss hält fest, was Dritte verlangt hatten: Zwei Anbieter wollten das gesicherte Chipelement eines am Körper getragenen Geräts mit Zahlungsmerkmalen bespielen; drei weitere wollten den NFC-Baustein im Lese-/Schreibmodus, also die Fähigkeit, eine Bankkarte auszulesen, um bei der starken Kundenauthentifizierung den Besitz nachzuweisen; und im Oktober 2024 meldeten sich zwei Modeunternehmen mit Interesse an Produkten auf derselben Grundlage.
Das sind keine Anbieter von Bezahl-Apps. Das sind Ringhersteller, Uhrenhersteller und Firmen, die wollen, dass ein Telefon eine Karte liest wie ein Terminal. Die DMA-Öffnung ist breiter als die kartellrechtliche, und ihre Klientel ist eine andere.
Zwei Türen zum selben Chip
Apple veröffentlicht zwei Hilfeseiten. Sie nebeneinander zu lesen ist der schnellste Weg zu verstehen, was Europa bekommen hat. Die erste heißt „HCE-based contactless NFC transactions for apps in the European Economic Area”. Host Card Emulation bedeutet, dass das Telefon eine kontaktlose Karte in Software nachbildet; die Zahlungsdaten liegen nicht im manipulationsgeschützten Chipelement, sondern bei der App und ihrem Hintergrundsystem, üblicherweise als Netzwerk-Token mit kurzlebigen Schlüsseln. Apples Seite nennt als Voraussetzungen: die Schnittstellen kamen mit iOS 17.4, der Entwickler muss im EWR niedergelassen und als Organisation im Entwicklerprogramm eingeschrieben sein und sich zu den Sicherheitsvorgaben von PCI DSS und EMVCo sowie zur Datenschutz-Grundverordnung verpflichten. Am Ende steht ein Abschnitt „EC Commitments – Complaints”, der auf den Zusagentext im Fallregister der Kommission verweist. Der Zugang ist kostenlos, wie angeordnet.
Die zweite Seite heißt „NFC & SE Platform for secure contactless transactions”. Hier liegt das Zahlungsmerkmal als eigenes Programm im gesicherten Chipelement selbst, und die Kette ist deutlich schwerer: Das Programm des Partners muss von einem unabhängigen akkreditierten Labor geprüft werden; Apple prüft, signiert und hostet das Paket; beim Einrichten legt ein Apple-Server eine eigene Speicherpartition im Chipelement an und übergibt dann an die Server des Partners zur Personalisierung. Jede Transaktion braucht eine Freigabe, die die Secure Enclave bezeugt.
Um das zu nutzen, müssen Entwickler, in Apples eigenen Worten aus der Ankündigung vom 14. August 2024, „einen kommerziellen Vertrag mit Apple schließen, die NFC- und SE-Berechtigung beantragen und die damit verbundenen Entgelte zahlen”. Eine Preisliste hat Apple nicht veröffentlicht; die Konditionen liegen hinter einer Vertraulichkeitsvereinbarung, die dieselbe Seite verlangt.
Nun die Geografie. Apples Hilfeseite listet die Gebiete auf, in denen ein Entwickler niedergelassen sein muss, um die Berechtigung zu bekommen. Abgezählt sind es achtundvierzig, darunter Australien, Brasilien, Kanada, Japan, Singapur, die Vereinigten Staaten — und in Europa die Schweiz, das Vereinigte Königreich, Serbien, Moldau und Montenegro. Kein Mitgliedstaat der Europäischen Union und kein weiterer EWR-Staat steht darauf. Eine Ausnahme benennt die Seite ausdrücklich: für staatliche Ausweise, und nur dafür, gilt die Berechtigung ab iOS 26.4 auch in der Europäischen Union.
Die Lage ist also, nach der Dokumentation des Herstellers selbst: Wo eine Behörde Zugang erzwungen hat, ist der Zugang kostenlos und läuft über Host Card Emulation. Wo niemand etwas erzwungen hat, verkauft Apple den Zugang zum gesicherten Chipelement per Vertrag. Der erzwungene Weg ist der billigere für den Neuling und der technisch schwächere. Nichts in der Entscheidung der Kommission verlangte das Chipelement: Die Zusagen sind um HCE herum formuliert, und Apple hat sie so angeboten.
Der Zugang hängt an einer Anwendungskennung
Die aufschlussreichste Stelle in beiden Dokumenten ist kein Absatz Prosa. Es ist ein Konfigurationsschlüssel. Wer im EWR eine HCE-App ausliefern will, muss im Antrag und noch einmal in der Berechtigungsdatei der App auflisten, welche Anwendungskennungen (AID) beziehungsweise Anbieterkennungen (RID) die App benutzen wird. Apples Seite druckt fünf Beispiele. Drei sind Infrastruktur oder Zutrittstechnik — die Auswahlumgebung für kontaktlose Zahlungen, MIFARE, HID. Die anderen beiden sind A0000000032020 und A0000000042010, von Apple selbst als Visa und Mastercard bezeichnet.
Eine Anwendungskennung ist das, worüber sich Terminal und Karte darauf einigen, welche Zahlungsanwendung sie miteinander sprechen; vergeben wird sie im Namensraum eines eingetragenen Systems. Das hat Apple nicht erfunden, so funktioniert kontaktloses EMV überall. Aber es macht die Form der Öffnung greifbar. Ist die App die einer Bank in Deutschland oder Frankreich, dann legt sie am Terminal fast immer ein Visa- oder Mastercard-Token vor, weil die Bank genau das ausgibt. Die App ändert, wem die Oberfläche gehört. Sie ändert nicht, wessen Netz die Zahlung trägt, wer die Systementgelte festsetzt und wer das Interbankenentgelt bekommt — und dieses Entgelt ist seit dem 9. Dezember 2015 durch die Verordnung (EU) 2015/751 auf 0,2 Prozent des Umsatzes bei Verbraucher-Debitkarten und 0,3 Prozent bei Verbraucher-Kreditkarten gedeckelt, eine Obergrenze, an der der jahrzehntelange Rechtsstreit um das Interbankenentgelt zwar gerüttelt, die er aber nie beseitigt hat.
Anders gesagt: Die Abhilfe verteilt das vordere Ende einer Kartenzahlung neu. Alles dahinter liegt genau dort, wo es lag. Deshalb rührt die Frage, welche App der Kunde geöffnet hat, an der Rechnung der Akzeptanzseite nicht — an dem also, was wir uns angesehen haben, als es darum ging, was ein Acquirer je Transaktion tatsächlich verdient.
Deutschland hat dieses Experiment schon durchgeführt
Europa hat eine Vergleichsgruppe, und sie ist sechs Jahre alt. Ende 2019 fügte der Bundestag den § 58a in das Zahlungsdiensteaufsichtsgesetz ein — eine Vorschrift, die die Fachpresse sofort „Lex Apple Pay” taufte. Ihr Kernsatz ist für ein Aufsichtsgesetz ungewöhnlich direkt: Ein Unternehmen, das durch technische Infrastrukturleistungen zum Erbringen von Zahlungsdiensten im Inland beiträgt, muss diese Leistungen auf Anfrage eines Zahlungsdienstleisters oder E-Geld-Emittenten unverzüglich zur Verfügung stellen, über eine standardisierte technische Schnittstelle zu allen Endgeräten, gegen ein Entgelt, das die tatsächlichen Kosten des Zugriffs nicht übersteigt, und so, dass Funktionsgleichheit gewährleistet ist. Eine Ablehnung setzt voraus, dass die Sicherheit und Integrität der Infrastruktur konkret gefährdet wäre. Auf dem Papier ist das schärfer als die EU-Zusagen: ein gesetzlicher Anspruch, zu Selbstkosten, mit Funktionsgleichheit im Text.
Was danach geschah, ist der Befund. Nach einem Bericht des deutschen Fachmediums heise online von Anfang 2020 erklärten die Sparkassen — jene Gruppe, die am lautesten gefordert hatte, Apple möge die Schnittstelle für Dritte öffnen —, dass sie den Zugang nicht mehr anstrebten, nachdem ihre eigenen Karten in Apple Pay verfügbar geworden waren. Das ist ein Pressebericht, keine Aufsichtsakte; das beobachtbare Ergebnis stützt ihn aber. In den Jahren, in denen die Vorschrift galt, hat keine deutsche Bank eine eigene Bezahl-App mit Kontaktlosfunktion auf dem iPhone ausgeliefert, und die Forderung, die das Gesetz hervorgebracht hatte, verschwand in dem Moment, in dem die Karten der Banken in der etablierten App lagen.
Das ist der Mechanismus, den die Debatte beharrlich unterschätzt. Eine Bank, deren Karte in Apple Pay liegt, verdient bei jeder Zahlung das Interbankenentgelt und zahlt Apple dafür ein Entgelt. Eine Bank, die eine eigene App baut, verdient dasselbe Interbankenentgelt, zahlt Apple nichts und trägt dafür die Kosten für Bau, Zertifizierung und Betrieb einer Bezahlanwendung plus die Werbekosten, um Kunden von einer Voreinstellung wegzubewegen, die bereits funktioniert. Die Ersparnis ist echt, aber klein; die Kosten sind groß und fallen vorn an; und die Erlöszeile ist in beiden Fällen dieselbe, weil es beide Male eine Kartenzahlung ist. Zugangsrechte ändern diese Rechnung nicht. Sie machen die unattraktive Möglichkeit lediglich legal.
Die erste App durch die Tür ging über ein nationales System
Die Ausnahme ist lehrreich. Im Dezember 2024 startete die nordische App Vipps MobilePay das kontaktlose Bezahlen auf dem iPhone — nach Darstellung mehrerer Fachmedien und des Unternehmens selbst als weltweit erste App neben Apple Pay. Den Berichten zufolge ging sie für Kunden von mehr als vierzig norwegischen Banken an Terminals in Betrieb, die BankAxept akzeptieren, Norwegens nationales Kartensystem; Visa und Mastercard sollten folgen. Das sind Unternehmensangaben, weitergegeben von der Presse; keine Aufsichtsbehörde führt ein Verzeichnis solcher Starts, der Anspruch auf den ersten Platz lässt sich amtlich also nicht prüfen.
Entscheidend ist, was das möglich gemacht hat. Norwegen hat ein eigenes Kartensystem mit eigener Terminalakzeptanz und eigener Entgeltstruktur, und Vipps kam mit mehr als vierzig Banken als Vertriebsweg. Wo ein Anbieter ein Merkmal vorlegen kann, das kein Visa- oder Mastercard-Token ist, verändert die NFC-Öffnung die Ökonomie einer Zahlung wirklich. Wo er das nicht kann — und das ist der größte Teil der Europäischen Union —, baut er eine hübschere Oberfläche für fremde Schienen.
Die Gegenseite, so stark wie sie selbst auftreten würde
Das Argument für die Entscheidung der Kommission ist stark, und es lautet nicht, die Abhilfe werde die Marktanteile sofort umverteilen.
Man muss sehen, was vorher tatsächlich versperrt war. Es war nie nur das Funkmodul. Es war die Voreinstellung: „Field Detect” und Doppelklick, die beiden Wege, über die eine Bezahl-App am gesperrten Telefon in unter einer Sekunde erreichbar ist, dazu die biometrische Freigabe. Eine App, für die man das Telefon entsperren, sie suchen und öffnen muss, kann gegen eine App nicht bestehen, die von selbst erscheint, sobald das Telefon an ein Lesegerät kommt. Genau diese Funktionen decken die Zusagen ab, und Apples HCE-Seite führt sie als verfügbar für jede zugelassene App auf, die der Nutzer als Standard wählt. Das ist der Unterschied zwischen einem Zugangsrecht und einem brauchbaren Zugang — und es ist der Unterschied, den die vorgeschriebene Empfängerprüfung auf der Haftungsseite nicht geschafft hat, wo sich der Bildschirm änderte und die Verteilung des Schadens nicht.
Zweitens wurde das Zulassungsverfahren dort gelockert, wo es am meisten zählt: Der Wegfall der eigenen Zahlungsdienstelizenz bedeutet, dass die Berechtigung nicht daran hängt, eine Bank zu sein — und genau das ist ein neuer Anbieter von Bezahl-Oberflächen in aller Regel nicht. Drittens ist der Durchsetzungsapparat real: zehn Jahre, ein Überwachungstreuhänder, ein dokumentiertes Beschwerdeverfahren mit Fristen von fünfzehn und zwanzig Arbeitstagen, eine Beschwerdestelle, und — die Kommission schreibt das in derselben Mitteilung — die Möglichkeit einer Geldbuße von bis zu zehn Prozent des gesamten Jahresumsatzes bei Verstoß gegen die Zusagen, ohne dass die Kommission erst einen Missbrauch feststellen müsste. Viertens wirkt die Abhilfe in die Zukunft. Ein Zahlungsmittel, das den NFC-Chip auf iOS nicht erreichen kann, ist ein Zahlungsmittel, das im Laden nicht funktioniert; die Mitteilung der Kommission nennt die Einführung des digitalen Euro ausdrücklich als etwas, dem die Zusagen nicht vorgreifen. Diesen Zugang 2024 für ein Produkt zu bauen, das 2029 existieren könnte, ist kein Versagen der Abhilfe. Es ist die Abhilfe bei etwas, das erst später sichtbar wird.
Was die Öffnung nicht anrührt
Ein paar Zahlen, alle aus der Zahlungsverkehrsstatistik der Europäischen Zentralbank, veröffentlicht am 22. Juli 2026 für das zweite Halbjahr 2025. Im Euroraum gab es 83,5 Milliarden bargeldlose Zahlungen, 6,9 Prozent mehr als ein Jahr zuvor, im Wert von 117,8 Billionen Euro. Auf Kartenzahlungen entfielen 57 Prozent der Anzahl, auf Überweisungen 21, auf Lastschriften 14, auf E-Geld 6 Prozent. Allein die kontaktlosen Kartenzahlungen kamen auf 32,9 Milliarden, ein Plus von 11,9 Prozent. Im Umlauf waren 872,7 Millionen Zahlungskarten bei durchschnittlich rund 39 Euro je Kartenzahlung, und von 25,7 Millionen Kassenterminals nahmen 93 Prozent kontaktlose Zahlungen an.
Die EZB hat an diesen Zahlen kein geschäftliches Interesse; sie werden nach einer EZB-Verordnung bei den Zahlungsdienstleistern erhoben. Hält man sie gegen die Abhilfe, ist der Punkt offensichtlich. Das Zahlungsmittel, das die NFC-Öffnung aus einer konkurrierenden App heraus erreichbar macht, ist dasselbe, das schon jetzt 57 Prozent der bargeldlosen Zahlungen Europas trägt und aus eigener Kraft um rund zehn Prozent im Jahr wächst. Welche App auch immer den Standardplatz auf dem Telefon gewinnt: Die Kartensysteme kassieren bei nahezu jeder Zahlung, die sie erzeugt. Eine Zugangsauflage verteilt einen Kanal. Sie entscheidet nicht, was durch ihn fließt.
Die Alternativen, die nicht auf Kartenschienen liefen
Zwei Kandidaten gibt es, und beide sind langsamer als die Abhilfe, die sie tragen würde. Wero, die Anwendung der European Payments Initiative, läuft über Echtzeitüberweisungen statt über Kartenschienen. Nach Angaben von EPI und der Société Générale, einer ihrer Eigentümerbanken, hatte sie 55 Millionen Nutzer für Zahlungen zwischen Privatpersonen in Belgien, Frankreich und Deutschland erreicht; Luxemburg kommt 2026 dazu, das niederländische iDEAL wandert hinüber. Das sind Zahlen der Initiative und ihrer Eigentümer, die ein offensichtliches Interesse an einer großen Zahl haben; eine unabhängige Zählung veröffentlicht keine Aufsicht. Wichtig ist hier das Datum, das EPI für Ladenzahlungen nennt: 2027. Der Chip wurde 2024 geöffnet. Die europäische Alternative ohne Karte erreicht das Terminal rund drei Jahre später.
Der digitale Euro liegt noch weiter draußen. Die EZB berichtet, dass die Vorbereitungsphase von November 2023 bis Oktober 2025 lief und abgeschlossen ist, dass die Betriebsphase eines Pilotversuchs für das zweite Halbjahr 2027 über zwölf Monate geplant ist und dass das Eurosystem für eine mögliche erste Ausgabe im Jahr 2029 bereit sein will — unter der Arbeitsannahme, dass die Gesetzgeber die Verordnung im Lauf des Jahres 2026 verabschieden. Jedes dieser Daten liegt innerhalb der zehnjährigen Laufzeit der Zusagen, was vermutlich der Sinn der Sache ist.
Wie sicher das jeweils ist
Fest vertreten: Die beiden Zugangsordnungen bestehen wie beschrieben, mit den Bedingungen und Gebietslisten, die Apple veröffentlicht; die Zusagen binden zehn Jahre im EWR; die Anteilszahlen der EZB sind, was sie sind. Mit vernünftiger Sicherheit: dass eine eigene iOS-Bezahl-App für eine Bank überall dort unattraktiv ist, wo das Merkmal ein Visa- oder Mastercard-Token ist, und dass darin, nicht in der technischen Hürde, der Grund liegt, warum der deutsche Anspruch ungenutzt blieb. Vorsichtig: dass das Muster bleibt. Erreicht Wero 2027 die Terminals mit einer eigenen Anwendungskennung, oder kommt ein digitaler Euro mit einem verbrieften Platz auf dem Gerät, dann wirkt dieselbe Abhilfe plötzlich auf Schienen, die den Kartensystemen nicht gehören. Das Instrument war früher da als die Fracht.
Was daraus nicht folgt
Erstens veröffentlicht niemand die Verbreitung. Apple legt nicht offen, wie viele HCE-Berechtigungen erteilt wurden oder wie viele Nutzer im EWR eine fremde App als Standard gesetzt haben; der Überwachungstreuhänder berichtet der Kommission, nicht der Öffentlichkeit; und keine Aufsicht erhebt Marktanteile einzelner Bezahl-Apps. Die Aussage, die Abhilfe habe wenige konkurrierende Apps hervorgebracht, ist ein Schluss aus fehlenden Ankündigungen — schwächer, als es sich anfühlt.
Zweitens ist das Fehlen der EU- und EWR-Staaten auf der Gebietsliste der „NFC & SE Platform” eine belegte Tatsache mit unbelegter Ursache. Apple hat sich dazu nicht geäußert. Regulatorische Reihenfolge, Zertifizierungsaufwand, Vertragsfragen oder die bewusste Entscheidung, dort nicht zu verkaufen, wo ein kostenloser Weg vorgeschrieben ist, sind mit derselben Liste vereinbar. Die Liste als Beweis einer Absicht zu lesen hieße, aus einer Tabelle ein Motiv zu machen.
Drittens ist der deutsche Vergleich nicht sauber. § 58a gilt für einen Mitgliedstaat, wurde nach dem, was diese Recherche gefunden hat, in keinem veröffentlichten Verfahren durchgesetzt, und bestand neben einem europäischen Kartellverfahren, das den Banken einen guten Grund zum Abwarten gab. Dass der Anspruch ungenutzt blieb, ist sicher; dass er ungenutzt blieb, weil die Rechnung nicht aufging, ist die beste verfügbare Erklärung, kein Nachweis.
Die allgemeine Lehre
Zugangsauflagen werden geschrieben, als läge der Engpass in der Schnittstelle. Meist liegt er im Geschäftsmodell dahinter. Öffnet man den Chip, fließt hindurch, was der Neuling ohnehin zu verkaufen hatte — und war das eine Karte, dann liefert die Öffnung den Kartennetzwerken einen neuen Vertriebsweg zum Nulltarif, bezahlt aus dem Durchsetzungsbudget einer Wettbewerbsbehörde und einem Jahrzehnt treuhänderischer Aufsicht. Die Banken haben die Tür verlangt, weil sie es leid waren, Apple zu bezahlen. Hindurchgehen werden sie mit Visa- und Mastercard-Merkmalen, weil sie genau die ausgeben.
Nichts davon macht die Abhilfe zum Fehler. Es macht sie zu einer Infrastrukturentscheidung statt zu einem Wettbewerbsergebnis. Die richtige Frage an eine Zugangsauflage lautet nie „wer hat sie gefordert”, sondern „was wird hindurchgetragen, und wer wird je getragener Einheit bezahlt”. An diesem Maßstab wird die Entscheidung vom Juli 2024 in den Jahren 2027 und 2029 gemessen werden, wenn es in Europa endlich etwas zu tragen gibt, das keine Karte ist — und der Chip ist dann schon offen, was der einzige Teil des Problems war, den eine Wettbewerbsbehörde je lösen konnte.