DeFi regulation & security
DeFi regulation in Ireland
Ireland’s CASP process tests the operating model behind the application. Connect the Key Facts Document to accountable people, group dependencies and evidence of service recovery.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Provider authorization, token classification and security evidence. Tax, individual legal advice and a complete analysis of every financial-services regime are outside this guide.
The Central Bank application route
Ireland's Central Bank supervises the MiCA authorization process. Its current CASP application guidance describes initial engagement, a Key Facts Document (KFD) stage and formal application. Since , applicants must submit application-related documents through the Central Bank Portal.
The KFD supports pre-application assessment. Prepare the proposed services, customer groups, legal entity and operating model before building the submission. A DeFi product needs the same factual description of who controls the interface, customer relationship, assets and changes to deployed software.
MiCA Articles 59 and 60 distinguish authorization from the service-specific route for eligible existing financial institutions. Determine the applicant's position before treating the CASP application process as the right route for every group entity.
Show who can make and execute decisions
The Central Bank's authorization and supervision expectations address Irish substance, local autonomy, competent leadership and oversight of outsourced activity. They are supervisory guidance to read with the legislation.
An organization chart is a starting document. To make it useful for an operational review, connect each role to a decision it can actually take. Who authorizes emergency key rotation? Who can require a group supplier to restore a service? Who tells customers that withdrawals are delayed? Record substitutes when the primary owner is unavailable.
The following DeFiSec worksheet proposes evidence that a team can use to test those responsibilities. It does not set minimum staffing numbers or predict the Central Bank's decision.
| Responsibility | Suggested evidence | Question for the exercise |
|---|---|---|
| Local management | Decision authority, escalation rules and recorded approvals | Can the local entity act when a group instruction conflicts with its risk decision? |
| Security operations | Incident roster, access permissions and key-rotation exercise | Can an available authorized person execute the recovery action? |
| Supplier oversight | Contract owner, service dependencies and escalation test | Who can obtain evidence and enforce a recovery commitment? |
| Client asset operations | Wallet map, reconciliation ownership and exception queue | Who resolves an asset discrepancy after a disrupted transfer? |
| Financial resilience | Approved funding assumptions and a stress scenario | Which costs remain payable while the service is unavailable? |
Make group and ICT dependencies reviewable
A shared infrastructure platform can support several legal entities. Give each entity's service a traceable relationship to the relevant contracts, systems and responsible people. Avoid presenting the entire group's controls as evidence that automatically covers the applicant.
For the contract inventory, Pharos Production's DORA register guide for crypto service infrastructure explains how technical dependencies can be represented in the supporting records. Review the resulting information against DORA Article 28 and the applicable register requirements.
Use a customer-impact scenario to test the map. Suppose a signing provider becomes unavailable while transfers are pending. Trace detection, escalation, transaction state, customer communication, restoration and reconciliation. Retain the actual timestamps and unresolved dependencies. The CASP continuity framework in Delegated Regulation 2025/299 supplies the regulatory context for the relevant continuity assessment.
Maintain one version of the submission
Use the current Portal guidance for submission mechanics. Maintain an internal record connecting each uploaded document to its owner, version and the question it answers. Keep a log of missing information and proposed remediation rather than allowing assumptions to appear as completed controls.
Before an engagement meeting, rehearse the customer journey using the diagrams and evidence in the file. Ask the business, security and finance owners to describe the same scenario. Differences in their answers often reveal a scope or responsibility gap worth resolving before formal review.
For the technical audit portion, compare providers using the auditor directory and the evidence behind their relevant work. An audit report should identify its code scope and remaining findings; it cannot establish the applicant's governance or local substance.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
- DORA Register of InformationPharos Production ·
- Markets in Crypto Assets Regulation: CASP processCentral Bank of Ireland ·
- MiCAR Authorisation and Supervision ExpectationsCentral Bank of Ireland ·