DeFi regulation & security
DeFi regulation in Italy
The applicant’s existing status and intended services determine the Italian procedure. Map the entity, activity and evidence before choosing an authorization or notification route.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Provider authorization, token classification and security evidence. Tax, individual legal advice and a complete analysis of every financial-services regime are outside this guide.
Choose the route for the applicant entity
Italy's CASP process involves Consob and Banca d'Italia. The applicant's existing regulatory status and proposed services determine the route. The Banca d'Italia CASP guide explains the allocation under MiCA and Legislative Decree 129/2024.
For specialized CASPs, Consob authorizes after consulting Banca d'Italia. Banca d'Italia receives Article 60 notifications from banks, electronic money institutions and asset managers for eligible services. Consob receives them from investment firms, central securities depositories and market operators. Other authorization cases depend on the institution and service; consult the authority's detailed matrix.
Prepare a one-page scope statement listing the legal entity, existing permissions, planned activities and customer groups. For each activity, record whether it is already covered, potentially eligible for notification or requires a new authorization. Resolve uncertainty before assigning a submission deadline.
Build an entity-to-procedure map
This DeFiSec matrix is a preparation tool. It separates the initial decision from the documents needed to explain it, without deciding the legal outcome for a particular applicant.
| Applicant situation | Question to resolve | Working document |
|---|---|---|
| New specialized CASP | Which services are included in the authorization request? | Service list linked to customer journeys and system boundaries |
| Existing financial institution | Which proposed services qualify for the Article 60 route? | Permission-to-service comparison with the applicable provision |
| Mixed service model | Do different activities require different procedures? | Activity map with a separate decision and responsible authority for each |
| Group technology provider | Who contracts, operates and remains responsible for the service? | Entity diagram, intragroup agreements and control ownership |
| EU cross-border expansion | Does the permission and notification cover the destination service? | Country and service inventory linked to the Article 65 record |
A shared brand can hide several legal entities and different permissions. Use the exact legal name throughout the application, supplier agreements and customer terms. If a group company provides the wallet infrastructure, explain the applicant's ability to supervise that arrangement and recover the service.
Document the service's operational dependencies
DORA applies to MiCA-authorized CASPs within its scope. A useful evidence package connects each customer function to the systems, people and contractual arrangements on which it depends. A custody diagram should identify signing authority, key recovery, reconciliation and the response when a provider becomes unavailable.
Pharos Production's practical guide to the DORA ICT contract register for crypto services discusses the engineering work behind those records. Use it when connecting an infrastructure inventory to contractual information; the legal basis is DORA and the applicable technical measures.
For business continuity, Delegated Regulation 2025/299 includes risks associated with distributed ledgers. An internal exercise can trace a failed withdrawal from detection through customer communication, recovery and balance reconciliation. Record the actual result and who accepted any remaining limitation.
Filing and service changes
The Italian guide provides current forms and PEC contact instructions. It also offers preliminary discussions before formal filing. Use those discussions to clarify the proposed entity and procedure; they do not constitute authorization.
Keep application preparation time separate from the legal assessment period. Article 63 distinguishes completeness review from assessment of a complete application and provides for requests for further information. A project calendar should include time to repair evidence gaps instead of treating an assessment period as a guaranteed launch date.
After permission is obtained, compare it with the production service. Add a release check for changes to custody, order routing, asset support and the contracting entity. The smart contract audit checklist can support the code-review portion; operational and regulatory evidence still require their own owners.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
- DORA Register of InformationPharos Production ·
- Prestatori di servizi per le cripto-attività (CASP)Banca d’Italia ·