DeFi regulation & security
DeFi regulation in Latvia
Latvijas Banka distinguishes free preparation support from the formal application and ongoing supervision. A complete document file is only one stage of the process.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Latvian CASP preparation, fee categories and operational evidence. Figures refer to the cited regulator page; this guide does not calculate a provider’s capital or annual assessment.
Use the consultation before the formal application
Latvijas Banka's CASP page, updated 28 July 2026 describes a free preliminary consultation that can begin before incorporation. This helps clarify the business model and required material. It does not authorize operations or start a guaranteed approval timetable.
A new CASP applies under MiCA Article 62. An existing financial institution must establish eligibility for the specific Article 60 notification route. For a DeFi interface, map the operator, contracts, order flow and asset control before describing the service in either process.
Separate review cost, safeguards and annual supervision
The cited page states a EUR 2,500 application-document review fee. This is distinct from prudential safeguards and the annual supervisory charge. The latter is described as up to 0.6% of gross crypto-service income, with a EUR 3,000 minimum. The applicable annual rate is set separately.
Completeness review and substantive assessment are separate stages, and additional information can affect timing. Budget preparation and remediation work without treating a statutory assessment period as a promised launch date.
Prepare operational records alongside the policies
The Latvian checklist includes continuity and recovery tests, ICT documentation, customer-asset segregation and outsourcing oversight. This DeFiSec worksheet organizes practical evidence. It is not an official form.
| Decision | Evidence to prepare | Review question |
|---|---|---|
| Consultation outcome | Business-model questions and resolved assumptions | Which issues remain open before formal filing? |
| Cost category | Review payment, safeguard calculation and annual-rate reference | Have different obligations been budgeted separately? |
| Continuity | Recovery test result, owner and unresolved defects | Can the service recover under the proposed arrangements? |
| Supplier oversight | Contracts, technical dependencies and exit responsibilities | Can the CASP explain and oversee each critical dependency? |
Pharos Production's DORA register engineering resource explains how to connect suppliers, contracts and services. Use the inventory to reconcile the application with the system operated in production. The regulator's checklist and applicable law determine the filing duties.
Assign responsibility for changes and reporting
Latvijas Banka describes access to its data-reporting system after authorization and continuing reporting and change obligations. Assign responsible users and escalation owners when establishing the operating model.
As an internal readiness measure, review a material product or supplier change against the application, continuity tests and customer terms. Keep the current permission scope with the evidence record. The DORA evidence guide expands the ongoing ICT work.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- DORA Register of InformationPharos Production ·
- Crypto-asset service provider authorizationLatvijas Banka ·