DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Slovenia

Slovenia’s ZIUTK allocates CASP and token responsibilities by activity and institution. The electronic-money-institution exception needs a separate check.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Slovenian authority allocation under ZIUTK Articles 3–4 and evidence preparation. Current application-form fields, portal instructions and a complete fee schedule were not verified.

Apply the ZIUTK authority allocation

Article 3 of Slovenia's MiCA implementation act, ZIUTK allocates responsibilities between the Securities Market Agency (ATVP) and Banka Slovenije. ATVP handles ordinary CASP authorization and specified existing-institution notifications, subject to the act's exceptions.

The allocation also distinguishes token and issuer categories. It cannot be reduced to one authority for every crypto activity. Map the applicant's existing status and requested services before choosing the authorization or notification route.

Check the electronic-money and banking exceptions

Banka Slovenije handles the specified EMT white-paper notifications and the limited Article 60(4) services of electronic money institutions: custody and transfers relating to their own issued EMT. That provision does not grant every electronic money institution permission for all crypto services.

ZIUTK also provides for cooperation between authorities in specified bank-related cases. An inter-authority opinion or coordination step should not be described as two independent CASP licenses. Keep the entity, issuer and service facts consistent across the file.

Keep outsourced-process evidence accessible

Article 4 gives ATVP powers to obtain relevant records and inspect specified outsourced business processes under the statutory conditions. A provider should be able to explain where its evidence resides and who can supply it.

Pharos Production's DORA information-register guide supports the mapping of suppliers, contracts and ICT services. This DeFiSec worksheet organizes preparation work. It is not an ATVP or Banka Slovenije form.

Slovenia: authority and outsourced-process evidence
DecisionEvidence to prepareReview question
Competent authorityInstitution type, token category and service mapWhich ZIUTK allocation covers the actual activity?
EMI exceptionOwn-issued EMT and proposed custody or transfer scopeDoes the limited Article 60(4) route cover this feature?
Outsourced processProvider identity, contract and records locationCan the required process evidence be obtained?
Operational changeUpdated responsibilities and affected documentsDoes the changed service still match the recorded route?

Use current permissions after the transition

The Slovenian government's 10 July 2026 explanation confirms the end of the previous transition on 1 July. Verify the provider's current entitlement and the precise service scope rather than relying on an earlier registration.

A DeFi product requires an assessment of the actors controlling its interface and activities. Once scope is established, obtain the receiving authority's current filing instructions. The Croatian Hanfa guide provides a neighboring procedural comparison. The DORA guide expands operational evidence.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. DORA Register of InformationPharos Production ·
  4. Act implementing MiCA (ZIUTK), Official Gazette 95/2024Republic of Slovenia ·
  5. European regulation of crypto-asset marketsGovernment of Slovenia ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source