DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Portugal

Portugal’s Law 69/2025 divides MiCA responsibilities between Banco de Portugal and CMVM. CASP applications follow a coordinated process rather than two independent permissions.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Portuguese CASP procedure and evidence under Law 69/2025. A current upload portal, application fee and individual tax treatment are not determined by this guide.

Map the Portuguese supervisory responsibilities

Article 2 of Law 69/2025 of 22 December 2025 allocates MiCA responsibilities between Banco de Portugal and the Comissão do Mercado de Valores Mobiliários (CMVM). Banco de Portugal handles the issuer regimes for ART and EMT and specified provider authorization, prudential and organizational matters. CMVM handles other-token offers, market abuse and specified conduct and service duties.

This split does not turn one CASP application into two independent authorizations. Article 6 sets a coordination procedure: Banco de Portugal communicates the Article 60 notifications and Article 62 applications it receives to CMVM within two working days. That period concerns communication between authorities, not approval of the applicant.

Prepare one consistent description of the service

Choose the relevant Article 63 authorization or eligible Article 60 notification route before preparing the file. The latter depends on the existing financial institution and the crypto service proposed. The law's coordination process does not remove the EU eligibility conditions.

Describe the same contracting entity, service and customer assets in the prudential file, conduct policies and customer terms. Resolve inconsistent custody, execution or complaints descriptions before submission. Obtain the current filing-channel instructions from the receiving authority. The statute does not specify an upload portal or establish a complete filing checklist.

For an interface using DeFi protocols, document who controls the interface, executes orders and can alter deployed contracts. The EU scope analysis depends on those activities and actors. Token issuance and a financial-instrument classification need separate assessment.

Reconcile application and conduct evidence

This DeFiSec worksheet helps a team prepare consistent evidence across the two authorities' areas of responsibility. It is not an official application form.

Portugal: coordinated CASP evidence worksheet
Review areaSuggested evidenceConsistency question
Application routeEntity status, requested services and submission recordHas the authorization or notification route been correctly selected?
Prudential and governance fileSafeguards, accountable managers and outsourcing mapDoes this describe the entity actually serving the customer?
Customer-facing controlsAsset segregation, complaints and execution proceduresDo conduct policies match the operating model?
ICT dependencySupplier contract, service owner and recovery evidenceAre legal and technical supplier identities reconciled?
Advisory staffResponsibility map, qualifications and review recordsCan the provider demonstrate the competence of the people giving advice?

Pharos Production's engineering guide to the DORA information register supports the practical reconciliation of suppliers, contracts and services. Keep this technical register aligned with the application and update it when the provider's arrangements change. It does not determine which authority accepts a filing.

Keep service scope and staff competence current

Article 7 requires publication of the entities authorized or entitled to provide services in Portugal with their service scope. Verify that scope before presenting a provider as authorized for a particular feature.

Article 8 addresses staff giving crypto advice, including responsibilities, competence evidence and at least annual assessment. A one-time training certificate is not the entire ongoing process. Record the review outcome and any remedial action.

The earlier VASP transition in Article 30 ended by July 2026. Use a current permission or other valid MiCA basis rather than treating the old registration as continuing authorization. The DORA evidence guide expands the technical work after the provider's regulatory scope is established.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. DORA Register of InformationPharos Production ·
  4. Law 69/2025 implementing MiCA in PortugalAssembleia da República ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source