DeFi regulation & security
DeFi regulation in the EU
Start with the activity and the people who control it. Use this guide to separate provider authorization, operational resilience and the assessment of a smart contract.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: EU crypto-asset services and security evidence. The country guides cover their stated national procedures; individual tax positions and an authorization decision are outside this guide.
Start with the activity, token and control
A protocol name does not identify the regulated activity. Record who offers the service, who receives a fee, who controls the interface and who can move or restrict assets. Then classify the token and the service separately. A tokenized financial instrument needs a different analysis from a crypto-asset within MiCA.
MiCA Recital 22 distinguishes services provided in a fully decentralized manner without an intermediary from activities performed or controlled by persons, even where part of the system is decentralized. A DAO label or a self-custody wallet alone does not settle that distinction.
| Scenario | First question | Evidence to assemble |
|---|---|---|
| Open-source contributor | Does the person also operate or professionally provide a client service? | Repository responsibilities, deployment role and any client-facing agreements. |
| DAO or managed interface | Who controls upgrades, fees, access and execution? | Permission map, governance rules and the actual interface workflow. |
| Crypto-asset service provider | Which services and which home-state authorization or eligible notification route? | Service inventory, legal entity and national application documents. |
| Issuer or tokenization operator | What rights does the asset confer, and is it a financial instrument? | Token terms, legal rights, issuance process and classification analysis. |
This is a sequence for gathering facts. The answers must be assessed together; the table does not issue a legal classification.
Separate authorization from technical evidence
Provider authorization, an audit report and a technology assessment have different subjects. Authorization concerns a person and specified services. A code audit examines a defined technical scope. A technology recognition program has its own assessment rules and issuer. Record the subject and scope before treating any document as evidence.
| Source | Relevant scope | What to examine |
|---|---|---|
| MiCA | Covered crypto-assets, issuers and crypto-asset services. | Service permissions, governance, safeguards, ICT documentation and custody where applicable. |
| DORA | Financial entities in its scope, including MiCA-authorized CASPs under Article 2(1)(f). | ICT risk, incidents, testing, continuity and contractual arrangements with ICT providers. |
| Delegated Regulation 2025/299 | Continuity and regularity of crypto-asset services. | Service disruption scenarios, recovery measures and communication when a distributed ledger fails. |
Read the MiCA security obligations guide for the security evidence problem and the smart contract standards guide for technical assessment methods. National guides below explain the local route and documents.
Other questions, including transfer information, tax reporting, privacy and payment services, need their own scope analysis. A MiCA authorization does not resolve every obligation attached to the business model.
Build an evidence inventory before commissioning work
The worksheet below is an editorial preparation tool. Give each artifact an owner, a version and a specific question it answers. Separate an observation made during a technical review from a legal conclusion that requires a different assessment.
| Question | Artifact | Check | Limit |
|---|---|---|---|
| Who controls the service? | Entity and permissions map. | Trace deployed roles to the people responsible. | A diagram alone does not establish legal status. |
| What did the audit cover? | Report, commit and deployed addresses. | Match the reviewed version to production and record changes. | A clean report does not establish complete compliance. |
| Can the service recover? | Recovery procedure and exercise record. | Check dependency failures and client communication. | A written plan does not demonstrate a successful exercise. |
| Which providers support the service? | Contracts and ICT provider inventory. | Connect providers to functions, owners and exit arrangements. | A vendor list omits the contractual and dependency details. |
Keep current law and proposals on separate timelines
The European Commission's MiCA review consultation is open until . A consultation asks for evidence and views; it does not amend the regulation when its response window closes.
For planning the systems affected by potential changes, Pharos Production discusses the engineering implications of the MiCA review, including reporting and product classification. Treat those scenarios as architecture planning inputs, then check the status of any legal proposal against the official source.
Record the date a requirement starts applying separately from the date an article was checked. When a source changes, review the affected claim and every translation that contains it.
Country guides
Choose a jurisdiction for its supervisory process, local documents and security evidence. Each guide distinguishes provider authorization from an assessment of the technology.
Austria
Prepare an Austrian CASP file: FMA submission, document languages, custody outsourcing and a worksheet linking application answers to evidence.
English ·Belgium
Identify FSMA or NBB competence, distinguish CASP authorization from notification and map the Belgian procedure to customer and technical evidence.
English ·Czechia
Separate CNB CASP applications, institutional notifications and token classification. Examine liquidation rights and prepare a Czech regulatory evidence map.
English ·Estonia
Use Estonia’s CASP application portal, check document languages and distinguish the processing fee from capital. Prepare a submission evidence worksheet.
English ·France
Distinguish AMF provider authorization from smart contract certification research. Map French application documents to security and operational evidence.
English ·Germany
Prepare a German CASP application: BaFin, KMAG, authorization or notification, DORA evidence and cross-border service checks.
English ·Hungary
Check MNB authorization, ERA submissions and the 2026 repeal of Hungary’s exchange-validation regime. Build a dated control and permission record.
English ·Ireland
Prepare an Irish CASP file: Central Bank Portal, KFD, local accountability, ICT dependencies and operational readiness evidence.
English ·Italy
Choose an Italian CASP procedure by entity and service. Review Consob and Banca d’Italia roles, notification, application evidence and operational controls.
English ·Lithuania
Distinguish Lithuanian CASP licensing from former VASP registration. Review governance, funding and outsourced controls with a readiness worksheet.
English ·Luxembourg
Separate Luxembourg CASP and issuer procedures. Review token classification, CSSF eDesk white paper notification and technical evidence.
English ·Malta
Separate the MFSA crypto-asset provider route from MDIA technology assessment. Compare their scope and prepare an evidence inventory for the relevant process.
English ·Netherlands
Understand AFM and DNB responsibilities, CASP application documents and the technical evidence behind IT/DORA, continuity and asset segregation.
English ·Poland
Read the KNF authority-gap position, distinguish Polish applications from EU cross-border services and verify the permission behind a provider’s offer.
English ·Portugal
Map Portugal’s MiCA responsibilities between Banco de Portugal and CMVM. Prepare CASP application, conduct and security evidence for a coordinated review.
English ·Spain
Verify a crypto provider in Spain: current permission, legal entity, authorized services, white papers and technical integration evidence.
English ·
Regulatory topics
Follow a specific question across the EU framework and the evidence a security team can prepare.
DAC8 reporting
DAC8 starts with 2026 activity. Map tax residence and transactions; distinguish domestic filing from the 30 September 2027 exchange between authorities.
English ·Data Act smart contracts
Article 36 covers data-sharing agreements. Check the proposed Digital Omnibus deletion and map current requirements to control evidence and responsible parties.
English ·DORA evidence
Map DORA governance, testing, incidents and ICT supplier arrangements to evidence. Download a preparation worksheet and distinguish routine tests from TLPT.
English ·French certification research
ACPR-AMF working-group research: understand proposed principles, audit methods and certification scenarios. Prepare evidence with a scope worksheet.
English ·Malta TARF assessment
Compare TARF levels 0-3, assessors and recognition outcomes. Prepare an IDPS blueprint and distinguish MDIA technology assessment from CASP authorization.
English ·MiCA review
The consultation closes 30 September 2026. Read the DeFi certification questions and prepare a product impact worksheet while tracking the legal status.
English ·RWA classification
Classify token rights before choosing a regulatory route. Compare securities, pooled investments and MiCA assets, then map the outcome to technical controls.
English ·Travel Rule and wallets
Regulation 2023/1113: distinguish CASP transfer information, identity checks and self-hosted address-control assessment. Includes a scenario worksheet.
English ·
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
- Targeted consultation on the review of MiCAEuropean Commission ·
- MiCA Review 2026: What MiCA v2 May ChangePharos Production ·