DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Bulgaria

The Bulgarian FSC examines the actual service, local operations and supporting documents. Partial key or recovery access can matter when assessing custody.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Bulgarian CASP application preparation and post-transition service verification. Token issuance, personal taxation and a binding DeFi scope determination are separate matters.

Identify the entity and the Bulgarian authority

The FSC crypto-asset FAQ places ordinary CASP supervision with the Financial Supervision Commission (FSC, КФН). The Bulgarian National Bank has responsibilities for EMT and entities within its assigned supervisory scope. Establish the entity type and service before choosing an application route.

MiCA Article 62 applies to a new CASP application. Article 60 gives specified existing financial institutions a service-dependent notification route. A DeFi interface still needs an activity and control assessment under MiCA: identify who contracts with customers, handles orders and can influence their assets.

Prepare Bulgarian documents and operating evidence

The FAQ describes Bulgarian-language filing, including bilingual declarations where relevant for foreign individuals. Electronic submission requires a qualified electronic signature. Match the current FSC submission instructions to the application and attachments before sending them.

Evidence of local operations, management, resources and contracted suppliers should support the business plan. The FSC does not prescribe one universal minimum headcount in its FAQ. Explain why the proposed staff can perform and oversee the actual activities. Combined policies need an index that makes each required answer easy to locate.

Map access before describing a custody service

Examine signing, recovery and other partial access, not just possession of a complete private key. Pharos Production's analysis of smart contract risk in crypto custody helps document deployed code, privileged roles and changes to customer transaction paths. Technical evidence supports the scope analysis. It does not grant a custody permission.

This DeFiSec worksheet turns the business description into reviewable preparation tasks. It is not an FSC form.

Bulgaria: service and application evidence
DecisionEvidence to prepareReview question
Service classificationCustomer terms and order or asset flowWhich entity performs each regulated activity?
Key and recovery accessSigning roles, recovery permissions and supplier accessCan anyone affect assets without holding the whole key?
Bulgarian fileSigned documents, translations and policy indexCan the reviewer trace every answer to an attachment?
Operating resourcesStaff responsibilities and executed supplier arrangementsCan the proposed team deliver and oversee the service?

Verify permission after the transition

The FSC's 30 June 2026 notice explains the end of the transition on 1 July. Check the precise legal entity and permitted services in current registers, including the applicable EU passport basis. An earlier registration is not continuing MiCA authorization.

Record the date and service scope of that check when evaluating a provider. New features or a changed custody arrangement need a fresh comparison with the permission and application evidence. The self-hosted wallet and Travel Rule guide addresses a separate transfer-data question.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. Smart contract risk in crypto custodyPharos Production ·
  3. Crypto-asset application FAQFSC Bulgaria ·
  4. MiCA authorization from 1 July 2026FSC Bulgaria ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source