DeFi regulation & security
Malta MDIA TARF: levels and evidence
MDIA TARF assesses a defined innovative digital product or service. Its levels produce different recognition outcomes, and the assessed scope matters as much as the level.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: This guide covers the specified EU rule or assessment program and technical preparation. It does not determine a particular business's legal status or replace national filing instructions.
Define the product or service being assessed
Malta's Technology Assessment Recognition Framework concerns an innovative digital product or service, described as an IDPS. The MDIA guidelines, G-SPG-012 Rev. 2, organize assessment by level, technology domain and control type.
Recognition concerns the aspects identified in its scope. It does not certify the applicant's fitness and propriety or guarantee that a system cannot fail. A statement that a company is "MDIA certified" is incomplete unless the underlying document identifies the product, assessed aspects, level and validity.
The MFSA crypto-asset framework has a different purpose. TARF recognition is not a replacement for the authorization or notification required for the relevant financial service. Use the Malta country guide to separate the two decisions.
Compare levels by method and outcome
The framework distinguishes participation, technical review and assurance. Select the level against the product's maturity and assessment objective, then confirm suitability with MDIA. The authority can require changes to the proposed scope.
| Level | Method and assessor | Recognition type |
|---|---|---|
| 0 | Applicant self-assessment under the relevant initiative. | Acknowledgement. |
| 1 | Sandbox program involving a Technical Expert. | Mark of credit. |
| 2 | IDPS review by an independent Technical Expert. | Mark of credit. |
| 3 | ISAE 3000 reasonable assurance by an MDIA-approved Systems Auditor. | Certification, subject to MDIA's decision. |
For the relevant level 2/3 assessments, the guidelines distinguish Type 1 control-design assessment from Type 2 assessment that adds operating effectiveness over a specified period. Check the actual engagement's type and period before treating a result as evidence of sustained operation.
A public document should preserve the difference between these outcomes. A level 0 acknowledgement should not be described as a level 3 certification, and a review of one control domain should not imply that every product and service of the applicant was examined.
Prepare the application and IDPS blueprint
Section 3 addresses eligibility, including rights in the IDPS and a reasonable connection to Malta. It also sets out the application and blueprint process. MDIA reviews the proposed level, domains and controls and can request changes. Confirm current forms and program availability before commissioning the assessment.
Use the following DeFiSec worksheet to organize technical preparation. It supplements the official application. It does not reproduce all required due-diligence documents, administrative requirements or the authority's submission format.
| Preparation item | What to document | Cross-check | Unresolved issue to record |
|---|---|---|---|
| Applicant and IDPS | Applicant's rights, Malta connection and exact product/service. | Names and scope match application documents. | Shared ownership, operating rights or external operators. |
| Assessment scope | Selected level, domains, control types and assessment type. | Scope matches the result the applicant intends to describe publicly. | Excluded domains and why exclusion is appropriate. |
| Blueprint | Architecture, dependencies, data flows, roles and lifecycle. | Blueprint reflects the deployed version and operating process. | Unverified third-party components. |
| Control design | Control objective, implementation and responsible person. | Tests evaluate the actual control rather than only a policy statement. | Controls implemented outside the reviewed system. |
| Operating effectiveness | Period, sampled operations and failures or exceptions. | Evidence covers the period and scope of the Type 2 engagement. | Missing records or controls introduced partway through the period. |
| Outcome and changes | Recognition document, validity, conditions and version changes. | Public claims match the current issued document. | Changes requiring review or affecting continued recognition. |
Before engaging an assessor, confirm their eligibility for the required role and the selected subject matter. An experienced smart contract reviewer is not automatically an MDIA-approved Systems Auditor.
Tie technical evidence to the assessment scope
Pharos Production's article on deployed smart contract risk and custody controls helps teams examine version changes, operational privileges and the limits of an audit report. Those are useful preparation questions for a DLT-related IDPS. The article does not establish Pharos's eligibility as a TARF assessor or confer MDIA recognition.
Choose a service action, identify the contracts and operators involved, and compare them with the blueprint and engagement scope. If the production path includes an unreviewed upgrade or external dependency, record the gap before drawing conclusions from the assessment.
Keep the issued recognition, its scope and any conditions accessible to the people making public claims. The separate French certification research describes possible policy models, while TARF has its own published assessment process. Neither should be used as a synonym for a general guarantee of DeFi safety.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- Technology Assessment Recognition FrameworkMalta Digital Innovation Authority ·
- Crypto-assets: rules, guidance and application formsMalta Financial Services Authority ·
- Technology Assessment Recognition Framework: G-SPG-012 Rev. 2Malta Digital Innovation Authority ·
- Smart contract risk in crypto custodyPharos Production ·