DeFi regulation & security
DeFi regulation in Portugal
Portugal’s Law 69/2025 divides MiCA responsibilities between Banco de Portugal and CMVM. CASP applications follow a coordinated process rather than two independent permissions.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Portuguese CASP procedure and evidence under Law 69/2025. A current upload portal, application fee and individual tax treatment are not determined by this guide.
Map the Portuguese supervisory responsibilities
Article 2 of Law 69/2025 of 22 December 2025 allocates MiCA responsibilities between Banco de Portugal and the Comissão do Mercado de Valores Mobiliários (CMVM). Banco de Portugal handles the issuer regimes for ART and EMT and specified provider authorization, prudential and organizational matters. CMVM handles other-token offers, market abuse and specified conduct and service duties.
This split does not turn one CASP application into two independent authorizations. Article 6 sets a coordination procedure: Banco de Portugal communicates the Article 60 notifications and Article 62 applications it receives to CMVM within two working days. That period concerns communication between authorities, not approval of the applicant.
Prepare one consistent description of the service
Choose the relevant Article 63 authorization or eligible Article 60 notification route before preparing the file. The latter depends on the existing financial institution and the crypto service proposed. The law's coordination process does not remove the EU eligibility conditions.
Describe the same contracting entity, service and customer assets in the prudential file, conduct policies and customer terms. Resolve inconsistent custody, execution or complaints descriptions before submission. Obtain the current filing-channel instructions from the receiving authority. The statute does not specify an upload portal or establish a complete filing checklist.
For an interface using DeFi protocols, document who controls the interface, executes orders and can alter deployed contracts. The EU scope analysis depends on those activities and actors. Token issuance and a financial-instrument classification need separate assessment.
Reconcile application and conduct evidence
This DeFiSec worksheet helps a team prepare consistent evidence across the two authorities' areas of responsibility. It is not an official application form.
| Review area | Suggested evidence | Consistency question |
|---|---|---|
| Application route | Entity status, requested services and submission record | Has the authorization or notification route been correctly selected? |
| Prudential and governance file | Safeguards, accountable managers and outsourcing map | Does this describe the entity actually serving the customer? |
| Customer-facing controls | Asset segregation, complaints and execution procedures | Do conduct policies match the operating model? |
| ICT dependency | Supplier contract, service owner and recovery evidence | Are legal and technical supplier identities reconciled? |
| Advisory staff | Responsibility map, qualifications and review records | Can the provider demonstrate the competence of the people giving advice? |
Pharos Production's engineering guide to the DORA information register supports the practical reconciliation of suppliers, contracts and services. Keep this technical register aligned with the application and update it when the provider's arrangements change. It does not determine which authority accepts a filing.
Keep service scope and staff competence current
Article 7 requires publication of the entities authorized or entitled to provide services in Portugal with their service scope. Verify that scope before presenting a provider as authorized for a particular feature.
Article 8 addresses staff giving crypto advice, including responsibilities, competence evidence and at least annual assessment. A one-time training certificate is not the entire ongoing process. Record the review outcome and any remedial action.
The earlier VASP transition in Article 30 ended by July 2026. Use a current permission or other valid MiCA basis rather than treating the old registration as continuing authorization. The DORA evidence guide expands the technical work after the provider's regulatory scope is established.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- DORA Register of InformationPharos Production ·
- Law 69/2025 implementing MiCA in PortugalAssembleia da República ·