DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Belgium

Belgium divides MiCA supervision by activity and existing institutional status. Identify the legal entity and services before choosing FSMA or NBB instructions.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Belgian CASP routes and the division of supervisory responsibility. Issuance and individual tax questions require their own assessment.

Identify the competent Belgian authority

The National Bank of Belgium's MiCAR overview explains the division established by the law of 11 December 2025. FSMA generally supervises CASPs, while NBB retains competence for relevant entities already under its supervision that offer crypto services. NBB also has the main ART and EMT issuance role, with specified responsibilities for other authorities.

Use the legal entity's institutional status, not the branding of its app, to select the procedure. The FSMA CASP page distinguishes Article 63 authorization from Article 60 notification for eligible financial institutions. Notification is service-specific and is not a general exemption from crypto supervision.

Prepare a file for the correct route

For cases within its competence, FSMA publishes separate contacts for CASP applications and institutional notifications, together with the relevant EU forms. A bank or another NBB-supervised applicant should follow its applicable NBB route instead of assuming the FSMA channel covers every entity.

The FSMA notice on the transition's end sets the national transition in its historical context. It ended by July 2026. Check current permission and the services it covers. A pending application is not permission to continue active business.

Start the evidence file with a service map: who holds customer assets, who executes orders, which entity receives fees and who can change contract code. For a controlled DeFi interface, those facts support the MiCA scope assessment. A fully decentralized arrangement without an intermediary needs a different analysis.

Keep authority, service and evidence aligned

This DeFiSec matrix helps the team maintain one consistent description across the supervisory file, the customer contract and the deployed service.

Belgium: supervisory-route evidence matrix
QuestionSuggested evidenceReview outcome
Which legal entity?Institutional license, corporate identifier and customer contractSelect the applicable FSMA or NBB route
Which crypto service?Service list and authorization or notification scopeSeparate custody, exchange, advice and transfer permissions
Who controls assets?Key access, recovery powers and contract upgrade rolesIdentify discrepancies between legal and technical custody
Which supplier?Contracting parties and operational dependenciesAssign oversight to the entity responsible to customers
Which customer disclosure?Permission statements, complaints route and product termsRemove claims that exceed the actual regulatory scope

To examine custody at the code and access-control level, see Pharos Production's analysis of smart contract risk in crypto custody. Use its technical questions to prepare evidence for the responsible entity. A smart contract assessment does not establish FSMA or NBB approval.

Read registers at the level of the service

Check the official national information together with the relevant EU register and cross-border record. A list restricted to FSMA-authorized Belgian providers does not describe every institution under NBB supervision or every EU provider serving Belgium.

Record the permission's legal entity, service categories and current status. Compare them with the customer journey before release and after any group restructuring. For ART or EMT issuance, reopen the issuer-specific route; CASP authorization alone does not resolve the issuer's obligations.

The DORA evidence guide covers continuing ICT responsibilities once the relevant entity and scope have been established.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. Smart contract risk in crypto custodyPharos Production ·
  4. Crypto-Asset Service Provider authorization and notificationFSMA ·
  5. Markets in Crypto Assets RegulationNational Bank of Belgium ·
  6. Crypto service providers: end of the transitionFSMA ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source