DeFi regulation & security
DeFi regulation in Croatia
Hanfa separates an optional preliminary discussion from the formal CASP application. The service map and management evidence must remain consistent between them.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Croatian CASP preparation and register checks. The preliminary meeting is not approval; this guide does not calculate fees or assess personal tax obligations.
Choose the Croatian permission route
Hanfa's 3 July 2026 notice describes domestic CASP authorization, cross-border services by appropriately authorized EU providers, and the eligible existing-financial-institution route. The latter depends on the institution and services under MiCA Article 60.
Compare the legal entity and exact service with the register entry. A familiar trading brand or an old VASP registration is insufficient. For a product using DeFi contracts, document the operator of the interface, the order flow and any customer-asset control before deciding which permissions apply.
Use the preliminary meeting for unresolved service questions
The Hanfa application guide offers an optional introductory process using a business-model questionnaire. This is an informal discussion, outside the formal authorization procedure. Documents discussed there must still be submitted with the application.
Map all planned services before preparing the formal package. Hanfa also describes applications for consent to management appointments. Prepare the people responsible to explain their responsibilities and the operating model. Separate receipt, completeness and substantive review: none is a promised launch date.
Connect the meeting, application and implementation
This DeFiSec worksheet preserves the questions resolved before filing and the evidence supporting each answer. It is not a Hanfa application form.
| Decision | Evidence to prepare | Review question |
|---|---|---|
| Service map | Contract, interface and execution flow | Have all services actually delivered been included? |
| Preliminary discussion | Questionnaire version and outstanding questions | Which answers changed before the formal submission? |
| Management readiness | Roles, appointment documents and operational explanations | Who can explain each control and its limitations? |
| ICT dependencies | Provider contracts, recovery evidence and accountable owners | Do supplier descriptions match the application? |
Pharos Production's DORA register engineering guide helps reconcile supplier, contract and service records. Use it for the technical inventory once regulatory scope is established. Hanfa's application requirements and the applicable law remain the basis for the filing.
Maintain the file when the product changes
The July 2026 notice marks the end of the previous transition. Retain a dated check of the provider's current permission and service scope. Authorization for one service does not establish permission for every feature.
As an internal control, compare each material release with the submitted service description, customer terms and outsourcing map. Assign an owner to any discrepancy and determine the required regulatory action before launch. The DORA evidence guide expands the continuity and supplier work.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- DORA Register of InformationPharos Production ·
- Guide to a CASP authorization applicationHanfa ·
- Crypto services from 1 July 2026Hanfa ·