DeFi regulation & security
DeFi regulation in Bulgaria
The Bulgarian FSC examines the actual service, local operations and supporting documents. Partial key or recovery access can matter when assessing custody.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Bulgarian CASP application preparation and post-transition service verification. Token issuance, personal taxation and a binding DeFi scope determination are separate matters.
Identify the entity and the Bulgarian authority
The FSC crypto-asset FAQ places ordinary CASP supervision with the Financial Supervision Commission (FSC, КФН). The Bulgarian National Bank has responsibilities for EMT and entities within its assigned supervisory scope. Establish the entity type and service before choosing an application route.
MiCA Article 62 applies to a new CASP application. Article 60 gives specified existing financial institutions a service-dependent notification route. A DeFi interface still needs an activity and control assessment under MiCA: identify who contracts with customers, handles orders and can influence their assets.
Prepare Bulgarian documents and operating evidence
The FAQ describes Bulgarian-language filing, including bilingual declarations where relevant for foreign individuals. Electronic submission requires a qualified electronic signature. Match the current FSC submission instructions to the application and attachments before sending them.
Evidence of local operations, management, resources and contracted suppliers should support the business plan. The FSC does not prescribe one universal minimum headcount in its FAQ. Explain why the proposed staff can perform and oversee the actual activities. Combined policies need an index that makes each required answer easy to locate.
Map access before describing a custody service
Examine signing, recovery and other partial access, not just possession of a complete private key. Pharos Production's analysis of smart contract risk in crypto custody helps document deployed code, privileged roles and changes to customer transaction paths. Technical evidence supports the scope analysis. It does not grant a custody permission.
This DeFiSec worksheet turns the business description into reviewable preparation tasks. It is not an FSC form.
| Decision | Evidence to prepare | Review question |
|---|---|---|
| Service classification | Customer terms and order or asset flow | Which entity performs each regulated activity? |
| Key and recovery access | Signing roles, recovery permissions and supplier access | Can anyone affect assets without holding the whole key? |
| Bulgarian file | Signed documents, translations and policy index | Can the reviewer trace every answer to an attachment? |
| Operating resources | Staff responsibilities and executed supplier arrangements | Can the proposed team deliver and oversee the service? |
Verify permission after the transition
The FSC's 30 June 2026 notice explains the end of the transition on 1 July. Check the precise legal entity and permitted services in current registers, including the applicable EU passport basis. An earlier registration is not continuing MiCA authorization.
Record the date and service scope of that check when evaluating a provider. New features or a changed custody arrangement need a fresh comparison with the permission and application evidence. The self-hosted wallet and Travel Rule guide addresses a separate transfer-data question.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- Smart contract risk in crypto custodyPharos Production ·
- Crypto-asset application FAQFSC Bulgaria ·
- MiCA authorization from 1 July 2026FSC Bulgaria ·