DeFi regulation & security
DeFi regulation in Greece
The Greek route depends on the provider’s existing financial status and the activity. EMT custody or transfers can raise a separate payment-services question.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Greek authority allocation, MiCA route selection and EMT payment-service boundaries. Current HCMC form fields, submission channels and fees were not verified for this guide.
Map the institution before selecting the authority
ESMA's competent-authority table dated 7 July 2026 lists the Hellenic Capital Market Commission (HCMC) and explains the Bank of Greece's role for specified supervised institutions under Law 5193/2025. A provider's legal and supervisory status matters alongside the service.
Start with the contracting entity, its existing permissions and the crypto activities it proposes. MiCA Article 62 applications and Article 60 notifications are different routes. The latter is available only for the institutions and services the regulation specifies.
Distinguish banks, electronic money and payment institutions
The Bank of Greece's notification and authorization instructions distinguish credit institutions, electronic money institutions and payment institutions. Banks have specified notification routes. An electronic money institution's Article 60(4) route is limited. Broader services require separate assessment. An existing payment-institution permission does not itself give the Article 60 CASP route.
The same instructions ask CASPs providing relevant EMT custody or client transfers to examine the interaction with payment-services rules. Route the question to the appropriate Bank of Greece supervisory department before assuming that MiCA permission covers it.
Prepare a consistent authority and service map
This DeFiSec worksheet is a preparation document, not a Greek regulatory form. Keep one factual description of the product across legal and technical reviews.
| Decision | Evidence to prepare | Review question |
|---|---|---|
| Existing status | Corporate identity and current financial permissions | Which institution category applies to this entity? |
| Proposed service | Customer contract and end-to-end transaction flow | Is the selected notification or application route available? |
| EMT functionality | Beneficiary flow and wallet payment capabilities | Does a separate payment-services assessment apply? |
| Control over assets | Signing, recovery, upgrade and supplier permissions | Can the legal description be verified against deployed controls? |
Pharos Production's smart contract custody risk analysis helps describe the asset-control evidence. Use deployed addresses, role assignments and recovery procedures to support the classification discussion. Technical testing does not allocate supervisory competence or authorize a service.
Resolve the filing details before submission
The authority map is not a complete application checklist. Obtain the current receiving authority's form and submission instructions for the identified entity and service. Preserve the instructions and the date obtained with the application record.
A DeFi interface requires the same factual analysis of who provides or controls the activity. A decentralized underlying protocol does not settle the interface operator's position. Compare the Cyprus authority and EMT guide for a neighboring jurisdiction, and the EU Travel Rule guide for transfer-data obligations.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- Smart contract risk in crypto custodyPharos Production ·
- MiCA knowledge and competence guidelines: compliance tableESMA ·
- MiCA notifications and authorizationsBank of Greece ·