DeFi regulation & security
MiCA review: proposals and current law
The Commission is collecting evidence on MiCA implementation and areas beyond its existing scope. The consultation is open until 30 September 2026; its questions do not create new obligations.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: This guide covers the specified EU rule or assessment program and technical preparation. It does not determine a particular business's legal status or replace national filing instructions.
Track the consultation as a policy process
The Commission's targeted MiCA review consultation opened on . The official page gives an extended deadline of . Its stated purpose is to support assessment of MiCA's implementation and developments in crypto-asset markets.
The Commission connects the work to reports under Articles 140 and 142. A report may be accompanied by a legislative proposal if warranted. The consultation, a possible proposal, an adopted amendment and its application date are separate events. "MiCA v2" is a convenient discussion label, not the title of an adopted replacement act established by these sources.
Use MiCA's current legal text for existing duties. Use the review documents to identify questions under discussion and evidence that might inform a future change.
Read the DeFi questions without turning them into rules
Section 4.1 of the official questionnaire asks about DeFi benefits, risks and possible treatment. Questions 62-65 explore matters including CASP connections to DeFi, possible certification, who might issue it and which activities might be covered. These are options on which the Commission is seeking views.
Section 4.2 addresses staking, lending and borrowing. A reader should not infer from a questionnaire option that every provider must already change its business model to that option. Record the question number and the status of the document when discussing it internally or with clients.
For example, an option concerning certified protocols is not proof that a new EU certification is available today. Nor does discussion of non-custodial wallets establish an adopted certification duty for wallet software developers.
Prepare evidence for a possible change
The useful engineering task is to understand the present system well enough to evaluate alternatives. The following DeFiSec worksheet turns review topics into preparation questions. The proposed artifacts are our editorial method, not new obligations or official consultation answers.
| Discussion area | Question for the product team | Evidence to prepare | Decision trigger |
|---|---|---|---|
| Intermediaries and control | Who operates, upgrades, charges for or restricts the service? | Entity, permission and revenue-flow map. | Published clarification or adopted change affecting the actual role. |
| CASP connections to DeFi | Which protocols can clients reach and what checks precede access? | Integration inventory, selection criteria and incident history. | Confirmed change to applicable due-diligence or access duties. |
| Possible certification | What could an assessor verify about the deployed protocol? | Versioned scope, technical reports, governance and change records. | An actual framework with defined criteria, issuer and legal effect. |
| Staking, lending and borrowing | Who controls the assets, sets terms and bears each operational risk? | Product terms, execution flow and custody/dependency map. | A relevant adopted requirement and confirmed application date. |
| Client communication | Which public claims would change under a new rule? | Inventory of product descriptions, disclosures and contract terms. | Verified change that makes an existing statement inaccurate. |
| Implementation planning | Which components can be changed independently? | Dependency map, effort estimate and migration tests. | A scoped legal requirement rather than an unconfirmed headline. |
Keep unresolved legal questions attached to their affected product decisions. A team can improve version tracking or incident evidence now without claiming that an anticipated policy option already requires it.
Use scenarios for planning, with explicit assumptions
Pharos Production's guide to the possible engineering effects of the MiCA review discusses architecture and reporting implications of potential changes. Use those scenarios to identify affected systems and costs, then confirm the legal status against the Commission's documents. A scenario analysis does not establish a new compliance deadline.
A useful planning record has four fields: the observed policy document, the assumed future requirement, the systems affected and the evidence that would cause the team to act. Keep assumptions visible when estimating work so that a later policy change does not leave an unsupported requirement in the backlog.
For current obligations and other processes, follow the EU regulation overview, French certification research and Data Act Article 36 status guide. Their scope and legal status should remain distinct even when they raise similar technical questions.
The next review point is the consultation deadline and any subsequent official publication. A closed response window establishes that the consultation stage has ended. It does not establish that a proposal or amendment has been adopted.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- Targeted consultation on the review of MiCAEuropean Commission ·
- MiCA Review 2026: What MiCA v2 May ChangePharos Production ·
- MiCA review consultation questionnaireEuropean Commission ·