DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Denmark

Finanstilsynet’s DeFi principles examine both technical autonomy and control by people or entities. Future decentralisation promises do not describe the service available today.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Danish DeFi scope analysis and CASP filing preparation. The 2024 principles are supervisory guidance, not a binding DeFi certification or an automatic exemption.

Assess technical autonomy and organizational control

Finanstilsynet's 2024 principles for assessing decentralization distinguish the technical operation of a service from control by people or organizations. MiCA Recital 22 addresses fully decentralized services without intermediaries. A project's DeFi label does not establish that condition.

Assess the service when it is made available. A roadmap to relinquish control is different from relinquished control. An interface operator can require its own assessment even where the underlying protocol is not controlled by that operator.

Document the powers that can change the service

The Danish principles discuss self-execution, privileged changes and the ability to influence relevant functions. Describe upgrade permissions, access restrictions, oracle dependencies and economically significant privileges. Distinguish powers affecting the activity from a cosmetic website change. The principles are non-exhaustive guidance, not a certification checklist.

Pharos Production's smart contract security audit services can support a technical examination of deployed code and permissions. An audit finding should identify the code, version and control tested. A technical audit does not establish a MiCA exemption or substitute for an authority's scope assessment.

Build a present-control evidence map

This DeFiSec worksheet is an original preparation tool. Record both the current state and the evidence needed to verify a proposed change.

Denmark: DeFi control and autonomy worksheet
DecisionEvidence to prepareReview question
Protocol changesUpgrade roles, timelocks and deployed addressesWho can change economically relevant behavior today?
Interface operationHosting, routing, terms and operator identityDoes a separate person provide a service through the interface?
External dependenciesOracle, sequencer and administrator permissionsWhich dependency can alter or prevent execution?
Governance realityExecutable decisions and control-holder recordsDo actual powers match the decentralization claim?
Control removalTransaction evidence and post-change verificationHas the power been removed or only scheduled for removal?

Use Virk if the activity needs a CASP filing

The Virk application and notification service lists MitID access, CVR and LEI information, domains and relevant business, ICT and customer-asset documents. Its instructions reference the adopted EU application and notification standards.

A new CASP application and an eligible institution's Article 60 notification are distinct routes. Preserve the reasoning connecting the control map to the service classification and filing choice. The Data Act smart contract guide addresses a different legal scope. Its requirements should not be treated as a general DeFi license.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. Smart contract security audits and gas optimizationPharos Production ·
  3. Principles for assessing crypto-asset decentralisationFinanstilsynet ·
  4. Application or notification to provide crypto-asset servicesFinanstilsynet / Virk ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source