DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in the Netherlands

The Dutch CASP process divides responsibilities between AFM and DNB. Use this guide to connect application topics to specific documents, owners and technical checks.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Provider authorization, token classification and security evidence. Tax, individual legal advice and a complete analysis of every financial-services regime are outside this guide.

Which questions belong to AFM and DNB?

The Dutch process combines conduct and prudential supervision. AFM describes the allocation: it leads on crypto-asset service providers, other crypto-assets and market abuse. DNB leads on ART/EMT issuance and handles CASP prudential supervision and qualifying holdings.

A product team should distinguish the entity providing a service from an issuer whose token the service supports. Providing custody of a stablecoin and issuing that stablecoin are different activities. MiCA's asset classification and service definitions determine the relevant starting point.

For a DeFi product, record the parties controlling the interface, customer relationship, keys and upgrades. Recital 22's treatment of full decentralization does not give every project using smart contracts a general exemption. Use the EU regulation guide to prepare that initial scope description.

Use the AFM documents as the file index

The AFM forms page lists an application form, management letter and checklist. It asks for specific page references to supporting documentation. Its application sections include IT/DORA, continuity, asset segregation and AML/TFR. The page also provides a separate notification package for eligible institutions.

Give each answer a precise reference. "See security policy" leaves a reviewer to find the relevant section; "SEC-04, version 3, section 6, pages 12–14" identifies the evidence. Check that every cited attachment is actually included and that its scope covers the proposed Dutch entity.

Keep the legal explanation distinct from the evidence. The explanation states why a rule applies and how the organization addresses it. The attachment shows the arrangement, decision or test supporting that statement.

Map application topics to testable artifacts

This DeFiSec worksheet proposes an internal review method for the document topics above. It does not reproduce the official form or establish a separate Dutch technical standard.

Netherlands: application topic to supporting artifact
File topicSuggested evidenceConsistency check
IT/DORAArchitecture diagram, ICT contract inventory and risk decisionsCan each critical customer function be traced to its suppliers?
Business continuityRecovery exercise covering ledger and infrastructure interruptionDo observed recovery results support the plan's assumptions?
Asset segregationWallet ownership map and reconciliation recordsCan the team distinguish client assets from its own holdings?
AML/TFRTransfer workflow, missing-data decisions and exception recordsDoes the documented process match production transfers?
Prudential informationVersioned calculation with finance-owner approvalAre the service scope and cost assumptions consistent with the business plan?

For the ICT portion, Pharos Production explains how to connect crypto service dependencies to the DORA information register. This is useful when procurement records and engineering inventories use different names for the same supplier. DORA and its implementing measures remain the source of the register obligation and format.

Keep unresolved findings in the file. A successful backup job says little about whether withdrawals can resume with correct balances after a chain interruption. Test the service outcome and retain the reconciliation result.

Submission and follow-up

AFM describes a pre-scan as optional. Its forms page gives the current secure submission method. Use the latest instructions when sending the application and avoid attaching confidential records through channels copied from an old guide.

After submission, maintain a question log with the regulator's reference, the responsible person, the changed attachment and the response version. Update affected cross-references together. A supplier change can affect the architecture, outsourcing evidence, continuity plan and financial assumptions simultaneously.

For cross-border services, distinguish an actual MiCA permission and Article 65 notification from a historical national registration. Check the legal entity and authorized service scope before integrating a provider into your product.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. CASP business continuity — Delegated Regulation (EU) 2025/299European Commission ·
  4. DORA Register of InformationPharos Production ·
  5. CASP application and notification formsAFM ·
  6. MiCAR supervision: AFM and DNBAFM ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source