DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in France

A French CASP authorization and a smart contract assessment answer different questions. The AMF provides the provider route; ACPR–AMF certification work describes a possible approach to evaluating technology.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: France-based crypto-asset service providers, technical teams preparing their evidence and the status of French smart contract certification research.

Two questions: the provider and the contract

Start by identifying the French entity and the crypto-asset services it provides. MiCA Article 59 provides for CASP authorization and, for specified existing financial entities, the Article 60 route. An eligible notification route depends on the entity and service; it is not an exemption available to every startup.

The AMF's July 2026 update confirms that the French national transition has ended. Historical PSAN status alone is no longer a basis for continuing covered services. Check the current authorization and its service scope rather than relying on an old registration screenshot.

Separately, the ACPR and AMF certification publication explicitly says the working group's report is neither a regulatory proposal nor an official authority position. It does not establish a compulsory French certificate for every DeFi contract.

Document the activity before choosing a route

For a France-based business, make a service inventory before preparing the application. Include each client action, the entity contracting with the client, the asset involved and any third party executing the action. A trading interface, custody service and token offer can involve different responsibilities within the same product.

Scope questions for a French DeFi team
ActivityQuestion to resolveDocument to prepare
Publishing codeDoes the contributor also operate a service for clients?A role description separating development, deployment and ongoing operations.
Operating an interface or DAO serviceWho controls access, upgrades, fees and client execution?An interface workflow and a map of actual privileged permissions.
Providing covered crypto-asset servicesAuthorization under Article 63 or an eligible Article 60 notification?Entity status and service-by-service legal analysis.
Issuing a tokenWhich token category and issuance rules apply?Token terms, rights and classification analysis.

Recital 22 concerns services that are fully decentralized without an intermediary. A governance token, a multisignature wallet or the absence of custody is one fact in that assessment. Retain the evidence for who can change the system and what the interface operator actually does.

Turn the AMF application into a document checklist

The AMF application page lists an authorization application form, a management-body declaration and a cybersecurity/DORA self-assessment. Download the current files from that page when preparing the dossier. A completed self-assessment is a statement by the applicant; its supporting evidence still needs to be assembled.

  1. Describe the services and distribution model. Reconcile the application with the website, client terms and features users can access.
  2. Assign responsibility for governance and operational decisions. Show who approves a change and who can act during an incident.
  3. Prepare ICT documentation that links business services to contracts, infrastructure and external dependencies.
  4. Collect the records supporting the cybersecurity answers, including assessment scope, remediation evidence and exercised recovery procedures.
  5. Keep a dated application index so a replacement document can be traced to the question it answers.

MiCA Article 62 specifies the application information. Article 67 treats prudential safeguards separately from a regulator's application fee. Budget capital or insurance arrangements, professional work and technical implementation as distinct items; this guide does not substitute a market estimate for an official French tariff.

Match each security answer to an artifact

The table is a DeFiSec working map for preparing evidence, not an official AMF form. An artifact earns its place when a reviewer can inspect what it covers and what remains outside its scope.

French CASP evidence preparation map
AreaArtifactVerificationLimit
Service scopeOperations program and client workflow.Match the declared service with production features.A technical description does not decide authorization eligibility.
ICT securityArchitecture, permission map and assessment reports.Trace findings to deployed versions and checked fixes.A smart contract review does not cover the entire organization.
ContinuityRecovery plan, exercise results and communication procedure.Test an RPC outage or ledger disruption against the service response.A planned exercise is not evidence that recovery succeeded.
ICT suppliersContracts and DORA Register of Information.Link arrangements to supported functions and accountable owners.A spreadsheet of vendor names is not a complete register.
Custody, where applicableCustody policy, client positions and reconciliation records.Trace client rights and movements through the records.A wallet balance does not establish ownership or legal segregation.

For the register's implementation, Pharos Production explains building and maintaining a DORA Register of Information: connecting contractual arrangements, provider identifiers and supported functions. Use that engineering detail to structure the data behind your application, while keeping the official rules and AMF documents as the requirements baseline.

Delegated Regulation 2025/299 addresses continuity of crypto-asset services, including disruption involving a ledger the provider does not control. The evidence question is how the service responds and communicates when a dependency fails.

Specify what a contract assessment proves

Keep the assessment engagement separate from the provider application. Identify the code version, deployment configuration, roles and dependencies under review. Agree how fixes will be checked and how a later upgrade changes the validity of the assessment.

A report should let the reader reconstruct its scope without interpreting a marketing badge. Record the assessor, method, date, unresolved findings and exclusions. For methodology, continue with the smart contract security standards guide and the MiCA security evidence guide.

Before filing or relying on a provider

Recheck the current AMF documents and the scope of the relevant authorization. An Article 60 notification, a cross-border service notification and a new CASP application are different procedures. Do not reuse an application checklist for another route without checking which information that route requires.

When a contract changes after an audit, preserve the old report and record the change separately. When a provider changes its services, compare the new activity with its permitted scope. Both checks require a current version; neither is answered by the date of a homepage badge.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
  4. Certification des smart contracts : synthèse de la consultationACPR and AMF ·
  5. PSCA : formulaires pour le dossier d’agrément MiCAAMF ·
  6. Fin de la transition entre la loi Pacte et MiCAAMF ·
  7. DORA Register of InformationPharos Production ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source