DeFi regulation & security
DeFi regulation in Belgium
Belgium divides MiCA supervision by activity and existing institutional status. Identify the legal entity and services before choosing FSMA or NBB instructions.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Belgian CASP routes and the division of supervisory responsibility. Issuance and individual tax questions require their own assessment.
Identify the competent Belgian authority
The National Bank of Belgium's MiCAR overview explains the division established by the law of 11 December 2025. FSMA generally supervises CASPs, while NBB retains competence for relevant entities already under its supervision that offer crypto services. NBB also has the main ART and EMT issuance role, with specified responsibilities for other authorities.
Use the legal entity's institutional status, not the branding of its app, to select the procedure. The FSMA CASP page distinguishes Article 63 authorization from Article 60 notification for eligible financial institutions. Notification is service-specific and is not a general exemption from crypto supervision.
Prepare a file for the correct route
For cases within its competence, FSMA publishes separate contacts for CASP applications and institutional notifications, together with the relevant EU forms. A bank or another NBB-supervised applicant should follow its applicable NBB route instead of assuming the FSMA channel covers every entity.
The FSMA notice on the transition's end sets the national transition in its historical context. It ended by July 2026. Check current permission and the services it covers. A pending application is not permission to continue active business.
Start the evidence file with a service map: who holds customer assets, who executes orders, which entity receives fees and who can change contract code. For a controlled DeFi interface, those facts support the MiCA scope assessment. A fully decentralized arrangement without an intermediary needs a different analysis.
Keep authority, service and evidence aligned
This DeFiSec matrix helps the team maintain one consistent description across the supervisory file, the customer contract and the deployed service.
| Question | Suggested evidence | Review outcome |
|---|---|---|
| Which legal entity? | Institutional license, corporate identifier and customer contract | Select the applicable FSMA or NBB route |
| Which crypto service? | Service list and authorization or notification scope | Separate custody, exchange, advice and transfer permissions |
| Who controls assets? | Key access, recovery powers and contract upgrade roles | Identify discrepancies between legal and technical custody |
| Which supplier? | Contracting parties and operational dependencies | Assign oversight to the entity responsible to customers |
| Which customer disclosure? | Permission statements, complaints route and product terms | Remove claims that exceed the actual regulatory scope |
To examine custody at the code and access-control level, see Pharos Production's analysis of smart contract risk in crypto custody. Use its technical questions to prepare evidence for the responsible entity. A smart contract assessment does not establish FSMA or NBB approval.
Read registers at the level of the service
Check the official national information together with the relevant EU register and cross-border record. A list restricted to FSMA-authorized Belgian providers does not describe every institution under NBB supervision or every EU provider serving Belgium.
Record the permission's legal entity, service categories and current status. Compare them with the customer journey before release and after any group restructuring. For ART or EMT issuance, reopen the issuer-specific route; CASP authorization alone does not resolve the issuer's obligations.
The DORA evidence guide covers continuing ICT responsibilities once the relevant entity and scope have been established.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- Smart contract risk in crypto custodyPharos Production ·
- Crypto-Asset Service Provider authorization and notificationFSMA ·
- Markets in Crypto Assets RegulationNational Bank of Belgium ·
- Crypto service providers: end of the transitionFSMA ·