ESMIG

Published on

01/10/2026

Updated on

01/10/2026

Reading time

2 min

As of 1 October 2026

Definition

ESMIG (Eurosystem Single Market Infrastructure Gateway) is the common entrance to the Eurosystem’s TARGET Services. The documentation calls it the “single access point for the external communication to all market infrastructure services”: one way in instead of a separate connection per service.

Behind it lie CLM and RTGS as components of T2, along with T2S, TIPS, the collateral management system ECMS and the contingency solution ECONS II, as well as the common components for reference data and reporting.

The ancillary systems that settle in RTGS – the Bundesbank’s SEPA Clearer and the systems operated by EBA CLEARING – are directly connected actors too and take the same route.

Distinction

ESMIG is not a network. The line is provided by the network service providers (NSPs); ESMIG is the gate behind it. Nor is it a payment system: it does not check whether a payment is correct in substance – the respective service does that. And it is no substitute for access rights management; who may do what is held in the reference data of the service.

The role of the network service providers

Connectivity to ESMIG does not run over the open internet but through licensed network operators. Two providers were awarded the concession in a Eurosystem tender: Swift and Nexi together with Colt – the award originally went to SIA, which has since been absorbed into Nexi.

The connectivity contract is between the actor and the network service provider, not with the Eurosystem. The provider encrypts the connection, issues the certificates and maintains a Closed Group of Users for each service and each environment, against which it checks the right of access at network level already. Only what passes that check reaches ESMIG.

An actor may use more than one network service provider. Each individual and each application then needs a separate certificate per provider – a point regularly underestimated when switching provider or building a second connection.

What ESMIG itself does

ESMIG authenticates the sender, checks the entitlement for the service addressed and routes the message there; in the opposite direction it delivers the responses through the network service provider. Added to that are signature handling for non-repudiation, acceptance of compressed data and monitoring of the traffic. Validation against the XML schema is performed by ESMIG itself for TIPS; for the other services the service does it.

Two access modes are available: U2A, access through the graphical interface for individual users, and A2A, the exchange of ISO 20022 messages and files between applications.

TARGET ServicesCLMRTGSTIPST2SECMSECONS IIParticipantNSPESMIGU2A · A2AThe participant works through the interface or between applications.The network service provider opens the connection and checks certificate and group.ESMIG authenticates, checks the entitlement and routes to the right service.Behind it lie all TARGET Services – one way in instead of one link per service.

What it means for banks and payment service providers

ESMIG changes the shape of connectivity: instead of operating a separate line per service, one route leads to all of them. The price is that this one route has to be kept in good order. Three things drive the effort in house: managing the certificates across their whole life cycle, maintaining users and access rights in the reference data of each service, and the decision on a second network service provider as a fallback route – together with the second set of certificates it brings with it.

Sources