DeFi regulation & security
DeFi regulation in Denmark
Finanstilsynet’s DeFi principles examine both technical autonomy and control by people or entities. Future decentralisation promises do not describe the service available today.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Danish DeFi scope analysis and CASP filing preparation. The 2024 principles are supervisory guidance, not a binding DeFi certification or an automatic exemption.
Assess technical autonomy and organizational control
Finanstilsynet's 2024 principles for assessing decentralization distinguish the technical operation of a service from control by people or organizations. MiCA Recital 22 addresses fully decentralized services without intermediaries. A project's DeFi label does not establish that condition.
Assess the service when it is made available. A roadmap to relinquish control is different from relinquished control. An interface operator can require its own assessment even where the underlying protocol is not controlled by that operator.
Document the powers that can change the service
The Danish principles discuss self-execution, privileged changes and the ability to influence relevant functions. Describe upgrade permissions, access restrictions, oracle dependencies and economically significant privileges. Distinguish powers affecting the activity from a cosmetic website change. The principles are non-exhaustive guidance, not a certification checklist.
Pharos Production's smart contract security audit services can support a technical examination of deployed code and permissions. An audit finding should identify the code, version and control tested. A technical audit does not establish a MiCA exemption or substitute for an authority's scope assessment.
Build a present-control evidence map
This DeFiSec worksheet is an original preparation tool. Record both the current state and the evidence needed to verify a proposed change.
| Decision | Evidence to prepare | Review question |
|---|---|---|
| Protocol changes | Upgrade roles, timelocks and deployed addresses | Who can change economically relevant behavior today? |
| Interface operation | Hosting, routing, terms and operator identity | Does a separate person provide a service through the interface? |
| External dependencies | Oracle, sequencer and administrator permissions | Which dependency can alter or prevent execution? |
| Governance reality | Executable decisions and control-holder records | Do actual powers match the decentralization claim? |
| Control removal | Transaction evidence and post-change verification | Has the power been removed or only scheduled for removal? |
Use Virk if the activity needs a CASP filing
The Virk application and notification service lists MitID access, CVR and LEI information, domains and relevant business, ICT and customer-asset documents. Its instructions reference the adopted EU application and notification standards.
A new CASP application and an eligible institution's Article 60 notification are distinct routes. Preserve the reasoning connecting the control map to the service classification and filing choice. The Data Act smart contract guide addresses a different legal scope. Its requirements should not be treated as a general DeFi license.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- Smart contract security audits and gas optimizationPharos Production ·
- Principles for assessing crypto-asset decentralisationFinanstilsynet ·
- Application or notification to provide crypto-asset servicesFinanstilsynet / Virk ·