DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Austria

Austria’s FMA expects a structured file with traceable attachments. Establish who controls customer assets before classifying an outsourced service.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Austrian CASP applications and custody-related evidence. Token issuance, individual taxation and a binding licensing decision require separate assessment.

Choose the FMA route

The FMA's CASP application page identifies the Austrian Financial Market Authority as the competent authority under the MiCA-VVG. A new provider applies under Article 62 of MiCA. Eligible existing financial institutions use the service-specific Article 60 route and should contact their existing supervisory unit early.

First map the customer contract, trading interface, wallet controls and deployment permissions to the entity performing each activity. MiCA Recital 22 distinguishes fully decentralized services without an intermediary from activities performed or controlled by a person. Calling an interface DeFi does not settle this assessment.

Prepare the attachment index and language

FMA information letter V.07, dated 22 July 2026, section 3, explains how to organize the file. The application form points to separate PDF evidence. Give the attachments the corresponding form references and explain a provision's non-applicability. Information and documents are submitted through the FMA Incoming Platform, with access instructions obtained before filing.

The default document language is German. The letter allows English for material also used internally, such as policies and standards. This is not an unrestricted English-language filing route. Identify translation needs before assembling the package.

The procedure separates receipt, completeness and substantive assessment. The FMA also describes hearings with management and, where relevant, other key people. Prepare them to explain the actual business and controls. A completeness confirmation is not permission to launch, and assessment periods are not a guaranteed delivery date.

Separate custody control from technical supply

The FMA's publication on outsourcing core CASP services examines whether a supplier can control customer crypto-assets, including through keys, recovery material or signing participation. Outsourced custody requires the relevant authorized provider. A generic IT supplier should not be treated as a custodian without examining its actual access. The CASP retains its own responsibilities under Article 73.

For the technical inventory behind this assessment, Pharos Production discusses smart contract risk in crypto custody. Use the discussion of deployed code and privileged access to describe who can change a transaction path. A code assessment does not establish the supplier's regulatory permission.

Build a reviewable Austrian application package

This DeFiSec worksheet organizes preparation work. It is not an FMA form. Keep the version submitted to the authority separate from subsequent product changes.

Austria: attachment and custody-control worksheet
File decisionSuggested evidenceQuestion to resolve
Form referenceIndex connecting each answer to a PDF and exact pageCan the reviewer locate the evidence without searching a shared drive?
Document languageList of German documents and internally used English policiesWhich documents still need translation?
Custody supplierKey-access diagram, contract and permission scopeCan this supplier sign, recover or redirect customer assets?
Management hearingNamed control owners and one demonstrated failure scenarioCan the accountable person explain how the control works?
Operational changeDated change log and affected attachment identifiersDoes the application still describe the deployed service?

DORA and CASP continuity requirements add work beyond filing. Preserve recovery results and supplier dependencies with the application evidence. The DORA evidence guide explains the continuing register and testing duties.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
  4. Smart contract risk in crypto custodyPharos Production ·
  5. Information for CASP applicantsFMA ·
  6. Information letter for CASP applicants, V.07, 22 July 2026FMA ·
  7. Outsourcing core services by CASPsFMA ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source