Mobile banking apps cost €300k+ to build, and that is just the start

ConnectPay and Baltic Amadeus break down the true cost of launching a compliant mobile banking app in 2026.

A long data center aisle is lined with black server racks displaying blinking green and blue indicator lights, illuminated by bright overhead rectangular lights.

ConnectPay, one of Lithuania's largest Electronic Money Institutions (EMIs), has published a cost breakdown of building a mobile banking application from scratch, co-authored with Baltic Amadeus, the Baltic software development firm behind the FinCell white-label banking platform. The analysis puts initial development spend at €120,000 to €300,000, but argues the more consequential figure is the 15–25% of that sum required every year simply to keep the product secure and regulatorily compliant.

The release is framed as an industry corrective: too many fintech entrants, the authors contend, budget for the launch and then discover that the ongoing cost of operation is structurally built into European financial regulation in ways that have no direct analogue in consumer app development.

The regulatory premium

European financial applications carry a compliance overhead that is absent from most other software categories. PSD2 (the EU's open-banking directive), GDPR, AML/KYC obligations, and DORA (the Digital Operational Resilience Act, which took effect in January 2025) collectively increase a fintech app's development budget by 20–40% compared with a functionally similar non-financial application, according to Simas Simanauskas, Chief Commercial Officer at ConnectPay.

"Compliance isn't an add-on feature you can bolt on later, it's a mandatory part of the infrastructure," Simanauskas said. "Security and compliance requirements typically increase a fintech app's development budget by 20–40%, so players who plan for this in advance avoid unpleasant surprises later."

Beyond development, PCI DSS certification alone runs €15,000–€50,000 annually. Transaction-level fees add a further layer: the Bank of Lithuania, for instance, applies a fee of €0.003–€0.0012 per SEPA payment record to licensed institutions. The payments business is a volume game, the per-transaction cost falls as throughput rises, regardless of whether infrastructure is built in-house or licensed from a partner.

The build-versus-buy inflection

The deeper strategic argument in the analysis concerns market positioning rather than cost accounting. A decade ago, Revolut and Wise entered a market dominated by slow incumbents with limited digital capability. In 2026, a new entrant competes from day one against mature, heavily funded neobanks that update their products monthly.

The implication for capital allocation is direct: attempting to build payments infrastructure, compliance tooling, and user experience simultaneously is, the authors argue, both too slow and too expensive for most challengers. The recommended alternative is a niche-first approach, identifying an underserved customer segment and deploying pre-built, licensed infrastructure (such as a Banking-as-a-Service layer or a white-label platform) to reach market in months rather than years.

This build-versus-buy calculus has broader resonance beyond the Baltic fintech corridor. Across Europe, the convergence of tighter regulation (DORA, PSD3 currently in legislative passage) and rising user-experience expectations from incumbent neobanks is compressing the window in which new entrants can differentiate on product alone. The competitive moat is shifting from feature novelty to operational efficiency, specifically, the ability to manage volume, risk, and infrastructure cost per transaction at scale.

For investors watching the European fintech mid-market, the analysis signals a quiet consolidation dynamic. Challengers who cannot fund the compliance overhead are likely acquisition targets for larger EMIs or Banking-as-a-Service platforms seeking to expand their licensed footprint. ConnectPay's decision to publish this cost framework, effectively advertising the complexity of going it alone, is itself a commercial signal about where the company sees its growth: in providing the infrastructure that smaller entrants cannot afford to build themselves.

The broader cross-sector read is that regulatory complexity is becoming a structural moat in financial services, one that increasingly advantages platforms over point solutions and incumbents over greenfield builds. That dynamic is not unique to fintech: analogous patterns are visible in health-data compliance (HIPAA, EU AI Act obligations for medical devices) and defence procurement, where the compliance burden of entering regulated markets is itself a competitive filter.