DeFi regulation & security
DeFi regulation in Austria
Austria’s FMA expects a structured file with traceable attachments. Establish who controls customer assets before classifying an outsourced service.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Austrian CASP applications and custody-related evidence. Token issuance, individual taxation and a binding licensing decision require separate assessment.
Choose the FMA route
The FMA's CASP application page identifies the Austrian Financial Market Authority as the competent authority under the MiCA-VVG. A new provider applies under Article 62 of MiCA. Eligible existing financial institutions use the service-specific Article 60 route and should contact their existing supervisory unit early.
First map the customer contract, trading interface, wallet controls and deployment permissions to the entity performing each activity. MiCA Recital 22 distinguishes fully decentralized services without an intermediary from activities performed or controlled by a person. Calling an interface DeFi does not settle this assessment.
Prepare the attachment index and language
FMA information letter V.07, dated 22 July 2026, section 3, explains how to organize the file. The application form points to separate PDF evidence. Give the attachments the corresponding form references and explain a provision's non-applicability. Information and documents are submitted through the FMA Incoming Platform, with access instructions obtained before filing.
The default document language is German. The letter allows English for material also used internally, such as policies and standards. This is not an unrestricted English-language filing route. Identify translation needs before assembling the package.
The procedure separates receipt, completeness and substantive assessment. The FMA also describes hearings with management and, where relevant, other key people. Prepare them to explain the actual business and controls. A completeness confirmation is not permission to launch, and assessment periods are not a guaranteed delivery date.
Separate custody control from technical supply
The FMA's publication on outsourcing core CASP services examines whether a supplier can control customer crypto-assets, including through keys, recovery material or signing participation. Outsourced custody requires the relevant authorized provider. A generic IT supplier should not be treated as a custodian without examining its actual access. The CASP retains its own responsibilities under Article 73.
For the technical inventory behind this assessment, Pharos Production discusses smart contract risk in crypto custody. Use the discussion of deployed code and privileged access to describe who can change a transaction path. A code assessment does not establish the supplier's regulatory permission.
Build a reviewable Austrian application package
This DeFiSec worksheet organizes preparation work. It is not an FMA form. Keep the version submitted to the authority separate from subsequent product changes.
| File decision | Suggested evidence | Question to resolve |
|---|---|---|
| Form reference | Index connecting each answer to a PDF and exact page | Can the reviewer locate the evidence without searching a shared drive? |
| Document language | List of German documents and internally used English policies | Which documents still need translation? |
| Custody supplier | Key-access diagram, contract and permission scope | Can this supplier sign, recover or redirect customer assets? |
| Management hearing | Named control owners and one demonstrated failure scenario | Can the accountable person explain how the control works? |
| Operational change | Dated change log and affected attachment identifiers | Does the application still describe the deployed service? |
DORA and CASP continuity requirements add work beyond filing. Preserve recovery results and supplier dependencies with the application evidence. The DORA evidence guide explains the continuing register and testing duties.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
- Smart contract risk in crypto custodyPharos Production ·
- Information for CASP applicantsFMA ·
- Information letter for CASP applicants, V.07, 22 July 2026FMA ·
- Outsourcing core services by CASPsFMA ·