Initial meeting

Feb 23, 2026

European CASP Supervision – Will ESMA Replace BaFin in MiCAR Supervision?

The supervision of crypto service providers (CASP) has become a day-to-day issue for financial supervisory authorities in European member states over the last few years, and especially since MiCAR came into force. Hardly any self-respecting institution can avoid the question of whether its own business areas should be expanded to include crypto assets or whether blockchain technology could be used to improve the technical efficiency of existing business models. The German BaFin, in particular, which was already required to supervise crypto-related business models under national law before MiCAR came into force, has built up considerable expertise in this area in relation to the functioning of crypto assets and the markets in which they are traded. However, the EU Commission is considering withdrawing the supervisory mandate for providers of crypto-asset services from BaFin and, in general, all national financial supervisory authorities in the future and having supervision carried out directly by ESMA, based in Paris. ESMA would then be directly responsible for license applications from crypto asset service providers in accordance with Art. 62 MiCAR. After successfully completing the MiCAR licensing process, ESMA would also take over the ongoing supervision of CASPs from the national supervisory authorities.

ESMA’s Jurisdiction Would Apply to All Pure CASPs – Distinction for Entities Notified Under Article 60 MiCAR

According to the current draft of the EU Commission for the planned amendments to MiCAR, ESMA would be the competent authority for all companies that have applied for or received authorization under Article 62 MiCAR. With regard to credit institutions, investment firms, or other companies supervised under other regimes that are authorized to offer crypto asset services in addition to their traditional business after successfully completing a notification procedure in accordance with Article 60 MiCAR, the current jurisdiction of BaFin and the Deutsche Bundesbank would remain in place for the time being. However, under the current draft regulation, such companies would have to submit information on their total annual turnover to ESMA on an annual basis, specifying the percentage of turnover attributable to crypto-asset services. As soon as crypto asset services became the company’s main business according to these figures, the supervisory mandate with regard to the supervision of obligations under MiCAR would be transferred from the nationally competent authority to ESMA. The last available annual financial statements approved by the management body of the notified company would be decisive in each case.

EU Passporting to be Integrated Directly into Authorization

Another change planned by the EU Commission concerns the MiCAR passporting regime. In future, crypto-asset service providers will be allowed to provide the crypto-asset services for which they are authorized by ESMA throughout the European Union. This approach seems sensible and understandable, especially since ESMA would be responsible for supervising all crypto-related business anyway. However, it remains to be seen whether the planned changes would actually lead to simplifications. It seems questionable whether the supervision of small and medium-sized CASPs by the Paris-based ESMA in particular can prove to be practicable. Correspondence and supervisory discussions would probably take place largely in English, which could cause difficulties for smaller CASPs. With regard to investor protection, internationalization could also create hurdles for customers of supervised CASPs if they have to turn to an international institution with their concerns instead of being able to contact German-speaking representatives at BaFin and the Bundesbank. One positive effect would certainly be that the already very granular interpretation of MiCAR by ESMA would be further harmonized and differences in the supervisory rigor of national supervisory authorities could be counteracted. However, it remains to be seen whether the EU Commission’s proposals will actually be implemented in this form, as the consultation period for comments from market participants and associations on the proposed amendments has only recently expired and the evaluation of the comments received is still pending. In addition, the proposals would still have to go through the entire EU legislative process, which is rarely, if ever, completed without significant changes.

Attorney Dr. Lutz Auffenberg, LL.M. (London)

I. https://fin-law.de

E. info@fin-law.de

subscribe to Newsletter

This Blog Article as Podcast?

The Gist of It:

Presentation

    Contact

    info@fin-law.de

    Feb 16, 2026

    Utility Tokens in Transition – Legal Nature Under the German Banking Act (KWG) and MiCAR

    Since the launch of Ethereum in 2015 and the associated emergence of the smart contract economy, issuing proprietary tokens has become an interesting alternative to corporate financing, especially for startups and tech companies. In the past, issuers of crypto tokens generally attempted to design their tokens as utility tokens. The background to this was the legal situation in Germany at the time, according to which utility tokens were not necessarily classified as financial instruments within the meaning of the German Banking Act (KWG) or the Securities Trading Act (WpIG). BaFin took the view that utility tokens were a subtype of crypto tokens that essentially enabled the purchase of goods or services from their issuer and were therefore conceptually limited to the issuer’s network. Based on this understanding, synonyms for utility tokens were app tokens, usage tokens, or consumption tokens. If the legal requirements were met, crypto tokens could qualify as financial instruments until MiCAR replaced national crypto regulation at the end of 2024. At that time, crypto assets were financial instruments pursuant to Section 1 (11) sentence 1 no. 10, sentences 4 and 5 of the previous version of the KWG and Section 2 (5) no. 10 of the WpIG and were therefore potentially subject to financial services or investment services requiring a license. The definition required that the token in question be accepted as a medium of exchange or payment or serve investment purposes. In the case of utility tokens, these conditions could not be met in individual cases. In such cases, utility tokens were not regulated financial instruments and services relating to them were therefore not activities subject to authorization.

    Under MiCAR, Utility Tokens are a Clearly Defined Subtype of Crypto Assets

    Since MiCAR came into force, crypto assets have been defined in Article 3(1)(5) MiCAR as digital representations of a value or right that can be electronically transferred and stored using distributed ledger technology or similar technology. The EU regulation also provides an explicit definition for utility tokens in Article 3(1)(9) MiCAR. According to this, utility tokens are crypto assets that are exclusively intended to provide access to a good or service provided by their issuer. Since the definition requires that it be a crypto asset, these tokens can no longer be considered unregulated items since MiCAR came into force. In any case, they are crypto assets that can potentially be the subject of crypto asset services. Commercial handling of them may therefore trigger licensing requirements under Art. 59 ff. MiCAR. The issuance of these tokens also entails obligations for their issuers and offerors, in particular the fundamental obligation to prepare and publish a crypto asset white paper, with MiCAR regulating specific details in this regard.

    What are the Advantages for Issuers and Offerors of Such Tokens under MiCAR?

    Utility tokens are now regulated crypto assets under MiCAR regulations. However, for public offerings of utility tokens, the EU regulation provides for very attractive privileges for issuers and offerors in certain circumstances. For example, Article 4(3)(c) MiCAR stipulates that the provisions of the entire Title II of MiCAR do not apply to public offerings of utility tokens that provide access to goods or services that already exist or are already being provided. Issuers and offerors of such utility tokens therefore have the advantage that they are not required to prepare and publish a crypto asset white paper. Furthermore, they are not required to comply with the strict requirements for marketing communications under Article 7 MiCAR, they are not subject to the transparency requirements under Article 10 MiCAR, and purchasers of the utility tokens are not entitled to the right of withdrawal under Article 13 MiCAR. However, these advantages only apply if the goods or services made accessible via the tokens actually already exist and are available. If, for example, their development or availability is to be financed by the proceeds from the utility token sale, the privileges do not apply. Issuers and providers of tokens that have additional relevant functions besides providing access also do not enjoy these advantages. The definition of utility tokens in Art. 3 (1) No. 9 MiCAR clearly stipulates that utility tokens only exist in the case of crypto assets that exclusively provide access to goods and services of their issuer.

    Attorney Dr. Lutz Auffenberg, LL.M. (London)

    I. https://fin-law.de

    E. info@fin-law.de

    subscribe to Newsletter

    This Blog Article as Podcast?

    The Gist of It:

    Presentation

      Contact

      info@fin-law.de

      Feb 09, 2026

      Notification Procedure as a Fast Track for Existing Institutions to Obtain a MiCAR License

      Crypto assets are not financial instruments within the meaning of MiFID2 regulation. This is explicitly clarified in Art. 2 (4a) MiCAR in conjunction with Art. 3 (1) No. 49 MiCAR. Nevertheless, credit institutions and investment firms, particularly in the Federal Republic of Germany, are showing growing interest in trading digital assets. For existing institutions, crypto assets open up new target groups and markets as well as innovative modern product types that attractively expand the product portfolio alongside or in conjunction with traditional MiFID business. In fact, the opportunities to seize these chances are within reach for already licensed credit institutions and investment firms, but also for e-money institutions, UCITS management companies, or alternative investment fund managers, as they can benefit from the notification procedure fundamentally regulated in Art. 60 MiCAR. Article 59(1) MiCAR provides for two options for obtaining authorization to provide crypto-asset services. First, pursuant to Article 59(1a) MiCAR, a company may provide crypto-asset services if it has previously been authorized as a crypto asset service provider. The significantly simpler route is the notification procedure for existing institutions set out in Article 59(1b) MiCAR and regulated in Article 60 MiCAR. According to this, credit institutions, investment firms, e-money institutions, UCITS management companies, and alternative investment fund managers can obtain authorization as providers of crypto asset services by submitting certain information about their planned crypto asset transactions to BaFin without having to go through a full authorization process.

      Who Can Benefit from a MiCAR Notification?

      Article 60(1) MiCAR grants authorized credit institutions the option of providing all crypto asset services after submitting a complete notification. For investment firms, the notification option is restricted in that, after successful notification, they may only provide those crypto asset services that correspond to the investment services for which they hold a corresponding license in accordance with MiFID regulations. Article 60(3) subparagraph 2 regulates which MiFID investment services correspond to which crypto asset services. In contrast, pursuant to Art. 60(4) MiCAR, e-money institutions are only permitted to provide custody, administration, and transfer services in relation to the e-money tokens they issue after successful notification. If an e-money institution wishes to offer additional crypto asset services, it must obtain the necessary authorization by submitting an application for authorization in accordance with Article 62 MiCAR. UCITS management companies or alternative investment fund managers may notify crypto asset services for the acceptance and transmission of orders in crypto assets for clients, advice on crypto assets, and portfolio management of crypto assets, provided that they hold the relevant authorizations under the UCITS Directive (2009/65/EC) or the AIFM Directive (2011/61/EC). Finally, market operators authorized under MiFID2 also have the option of taking advantage of the notification procedure. If their notification is successful, they can operate a trading platform for crypto assets.

      What Requirements Must Be Met and How Long Does the Notification Take?

      The notification procedure under Article 60 MiCAR is significantly less complex than a full application for authorization under Article 62 MiCAR. In particular, the notifying institution must present a viable business plan outlining how crypto asset services are to be marketed and offered in the future. In addition, it must provide a detailed and complete description of how the institution will adapt its strategies, procedures, and internal controls in relation to the planned provision of crypto asset services. This includes adapting internal procedures for risk management and money laundering prevention, IT security, emergency and business continuity planning, outsourcing management, and all other procedures relevant to regulatory compliance. Specific details are regulated by Delegated Regulation (EU) 2025/303. With regard to the duration of notification procedures, Article 60 MiCAR stipulates somewhat ambiguously for all types of eligible institutions that crypto asset services to be notified may only be provided once the information to be submitted has been transmitted to the competent authority at least 40 working days prior to the initial provision. According to Article 60(8) MiCAR, the competent authority – in Germany, BaFin – must check within 20 working days of receiving the notification whether the information in the notification is complete. If any information is missing, BaFin shall set a deadline for the applicant to provide the missing information, which may not exceed a further 20 working days from the date of the request. It should be noted that the request period does not count towards the 40 working days specified in Article 60(1) to (6) MiCAR. This means that the notification procedure can actually take 60 working days.

      Attorney Dr. Lutz Auffenberg, LL.M. (London)

      I.  https://fin-law.de

      E. info@fin-law.de

      subscribe to Newsletter

      This Blog Article as Podcast?

      The Gist of It:

      Presentation

        Contact

        info@fin-law.de

        Dec 15, 2025

        The Tokenization of Real World Assets – Can Real Estate Be Tokenized Using RWA Tokens?

        The tokenization of so-called real-world assets (RWA tokens) is currently one of the hot topics in the blockchain scene. In this context, the term tokenization refers to the technical and, as far as possible, legal connection of a digital token, usually existing on a blockchain, with a specific tangible object, such, as for example, real estate or a wind turbine, or with a specific intangible object, such, as for example, a right. The tokenization of rights continues to enjoy unbroken popularity in the financial sector. The issuance of security tokens, i.e., the public offering of financial products that are linked to a token in such a way that they qualify as securities within the meaning of securities regulation, has become a very popular form of corporate financing. BaFin qualifies such products, which in terms of content often constitute an investment under the German Investment Act, as sui generis securities due to their tokenization. This is the case if the products meet certain requirements in terms of transferability, tradability on the financial market, and the granting of securities-like rights. When issuing an electronic security under the German Electronic Securities Act (eWpG), the qualification of the products as securities has already been carried out by the legislator, so that products issued under the eWpG unproblematically constitute securities. But how can physical objects such as real estate be tokenized?

        Possible Concepts for Tokenizing Real Estate

        In principle, the complete tokenization of real estate via RWA tokens, i.e., of land ownership, is not yet provided for in the German legal system. This is primarily because in Germany, the land register is the sole and decisive legal document for assigning land ownership to individuals, and it does not yet allow for digitization, let alone tokenization via RWA tokens. Ultimately, this means that, in general, the person entered in the land register is also the owner of the property in question. However, there are various ways of approaching the tokenization of real estate. One example is the KG model, and another is the subordinated bond model. In both models, the initiator/issuer acquires the property in question and then allows interested investors to participate in it. In the KG model, the initiator would typically establish another company, a trust limited partner. This company would then establish a GmbH & Co KG with the initiator, provided that the latter is a GmbH, whereby the initiator would act as the personally liable partner and the trust company as the (trust) limited partner. Interested investors can then conclude tokenized trust agreements with the trust limited partner, which would transfer the rights of the trust limited partner in the GmbH & Co KG to the investors, i.e., both the rights to profit sharing, as specified in the partnership agreement, and the other corporate rights of a limited partner. In this model, the GmbH & Co KG would be the owner of the property as entered in the land register. The issuance of a subordinated bond is another option for tokenizing real estate. In this case, the issuer usually issues subordinated bonds that are registered in the name of the investor – mostly subordinated loans or subordinated profit participation rights – and tokenizes them. These products grant investors, for example, a share in the profits of the property in question or in the issuer’s corporate profits. In both models, however, the investor does not legally acquire ownership of the properties in question.

        What Documentation is Required for the Distribution of the Tokens?  

        As a rule, and if structured appropriately, tokenized products created according to one of the two models mentioned above will qualify as investments under the German Asset Investment Act (Vermögensanlagengesetz). As explained above, BaFin considers these tokenized investments to be securities for regulatory purposes if structured appropriately. In this respect, the regulatory regime for securities applies to their distribution. The volume of the planned issue is a decisive factor here. For issues with volumes of up to EUR 8,000,000, a securities information sheet of no more than four A4 pages is required or, in the case of a product packaged in accordance with the PRIIPs Regulation and provided that the product is offered to retail investors, a key information document (KID). Furthermore, in the case of issuances using a securities information sheet, distribution to non-qualified investors is only permitted if it is carried out by way of investment advice or investment brokerage through an investment services company. For issuances of up to EUR 20,000,000, a so-called EU growth prospectus  could be prepared, approved, and published; for issuances with a volume of more than EUR 20,000,000, a securities prospectus must be prepared by the issuer, approved by BaFin, and published, unless a statutory exemption applies.

        Attorney Dr. Lutz Auffenberg LL.M. (London)

        I.  https://fin-law.de

        E. info@fin-law.de

        subscribe to Newsletter

        This Blog Article as Podcast?

          Contact

          info@fin-law.de

          Dec 01, 2025

          Do Issuers of Crypto Assets Require a PRIIPs KID in Addition to the MiCAR White Paper?

          For more than a decade, EU Regulation No. 1286/2014 (PRIIPs Regulation) has required issuers and providers of packaged retail investment products and insurance-based investment products to prepare, publish, and make available key information documents (PRIIPs KIDs). The key information document is intended to provide retail investors with a clear and easily understandable overview of the underlying investment product. It must therefore not exceed three A4 pages in length and must contain the essential key information and warnings required by the PRIIPs Regulation. The legal form of the investment product is generally irrelevant, which is why a PRIIPs KID may have to be prepared for issues of both securities and, for example, units in investment funds or asset investments in accordance with the German Asset Investment Act (VermAnlG), as long as the product is to be offered to retail investors. Even fundamentally unregulated investment products may fall under the PRIIPs Regulation if the product meets its requirements for a packaged investment product or insurance-based investment product. In this context, the question arises as to whether issuers of crypto assets may also be required to prepare a key information document for a token issue, especially since the regulator of the PRIIPs Regulation in 2014 certainly did not have MiCAR, which will not apply until the end of 2024, in mind.

          Prospectus Requirements Under Other Regulations Are Irrelevant for the Applicability of the PRIIPs Regulation

          The fact that issuers and providers of investment products may be required by other regulations, such as the Prospectus Regulation, the KAGB or the VermAnlG, to prepare and publish prospectuses or other documentation relating to their products is fundamentally irrelevant to the question of the applicability of the PRIIPs Regulation. The obligation to prepare and publish a key information document may therefore exist in addition to the obligation to prepare a prospectus, provided that the investment product in question meets the requirements of the PRIIPs Regulation. According to Article 4 (1) of the PRIIPs Regulation, the existence of a packaged retail investment product within the meaning of the PRIIPs Regulation requires, in particular, that the amount to be repaid to the retail investor is subject to fluctuations resulting from the performance of reference values that are not directly acquired by the retail investor. According to BaFin’s administrative practice, only external reference values such as the value of precious metals, investment products from third-party providers, or crypto assets are relevant here. Internal reference values such as issuer- or group-related profit figures such as profit after tax or EBITDA, on the other hand, do not constitute a PRIIP. According to these principles, crypto assets within the meaning of Art. 3 (1) No. 5 MiCAR can also qualify as PRIIPs if they are to be distributed to retail investors and provide for a repayment to the investor whose amount depends on an external reference value. In this context, it is important to note that a repayment within the meaning of the PRIIPs Regulation can be not only genuine repayment claims at the end of a term, but also interest or other returns from the investment product during the period of ownership.

          PRIIPs KID and Crypto-Asset White Paper Conceivable for Certain Crypto Assets

          In cases where a crypto asset meets the requirements outlined above, the issuer and also the persons who advise on or sell the crypto asset may be required to prepare a PRIIPs KID, publish it, and make it available to investors in good time before subscription. The obligations under the PRIIPs Regulation then apply in addition to the obligations under MiCAR, meaning that, in addition to creating the PRIIPs KID, it may also be necessary to create and publish a crypto-asset white paper. The issuer of a crypto asset must therefore take both EU regulations into account when planning its token issuance. In this context, it is also important to note the further obligations under the PRIIPs Regulation and MiCAR, which impose strict requirements on issuers and providers in the area of advertising and marketing communications for the offering of investment products or crypto assets. No advertising statement may relativize or contradict the information contained in the PRIIPs KID or the crypto-asset white paper. It is therefore of considerable importance to ensure that, in the event of the applicability of the PRIIPs Regulation to a token issuance, the crypto-asset white paper in accordance with MiCAR and the key information document in accordance with the PRIIPs Regulation are consistent.

          Attorney Dr. Lutz Auffenberg, LL.M. (London)

          I.  https://fin-law.de

          E. info@fin-law.de

          subscribe to Newsletter

          This Blog Article as Podcast?

          The Gist of It:

          Presentation

            Contact

            info@fin-law.de

            Nov 17, 2025

            From Basic Tests to TLPT: DORA Redefines Resilience Testing Requirements

            Since January 17, 2025, financial companies have been required to comply with the requirements of Regulation (EU) 2022/2554, better known as DORA. This regulation creates a harmonized legal framework to strengthen digital operational resilience across the EU financial sector and address the growing risks posed by cyberattacks and ICT operational disruptions. To achieve this goal, DORA establishes a complex set of rules, supplemented by detailed technical regulatory standards (RTS) from the European Supervisory Authorities (ESAs). A key pillar for ensuring this resilience is the way companies test their systems. Overall, DORA introduces more far-reaching, uniform, and specific testing requirements for financial companies than previously existed. While earlier requirements were often fragmented or left room for interpretation, DORA now requires a structured and comprehensive testing program. This ranges from regular basic tests to sophisticated, threat-led penetration tests (TLPTs) for systemically important institutions. These new obligations require a detailed examination of the regulation and the associated RTS. The following section therefore outlines the general requirements for the testing program and what needs to be considered for the extended tests, known as TLPTs.

            General DORA Requirements for Stress Tests

            Financial institutions that are not micro-enterprises must establish, maintain, and review a robust and comprehensive program for testing digital operational resilience. This program is an integral part of the ICT risk management framework (in accordance with Art. 6 DORA). The main objective of the testing program is to assess preparedness for handling ICT-related incidents, identify weaknesses, deficiencies, and gaps in digital operational resilience, and implement corrective measures promptly. Financial firms must take a risk-based approach when executing the testing program. In doing so, they must give due consideration to the evolving ICT risk landscapes, specific risks to which the firm is exposed, and the criticality of information assets and services provided. The program must include a range of assessments, tests, methods, procedures, and tools, including vulnerability assessments and scans, open-source analysis, network security assessments, gap analyses, physical security reviews, scenario-based testing, compatibility testing, performance testing, end-to-end testing, and penetration testing. Appropriate testing must be performed at least once a year on all ICT systems and applications that support critical or important functions. The tests should be performed by independent internal staff or external personnel. The findings and challenges arising from the digital operational resilience tests must be continuously and properly incorporated into the ICT risk assessment process. They serve as the basis for appropriate reviews of the relevant components of the ICT risk management framework.

            Advanced Testing: Threat-Led Penetration Testing (TLPT)

            Beyond general testing, DORA requires certain financial companies to perform advanced testing known as threat-led penetration testing (TLPT). The legal basis for this can be found in Articles 26 and 27 of DORA. TLPT is another tool for strengthening operational resilience. DORA is guided by international standards such as the G7 Fundamental Elements and frameworks such as TIBER-EU, and defines TLPT in Article 3(17) DORA as a framework that replicates the tactics, techniques, and procedures of real attackers who are perceived as genuine cyber threats and enables a controlled, tailored, knowledge-based (red team) test of the financial company’s critical live production systems. The requirements of Articles 26 and 27 DORA are supplemented and specified in detail by Delegated Regulation (EU) 025/1190 (RTS on TLTP). Which companies must carry out TLTPs is determined by BaFin as the competent supervisory authority or, in the case of significant credit institutions, by the ECB. The criteria for classification are set out in Article 28(8), subparagraph 3, DORA. The impact of the financial company in question, its systemic nature, and its ICT risk profile based on the criteria set out in Article 2 of the RTS on TLPT are taken into account. Micro-enterprises are exempt from the obligation to perform TLPTs.

            FIN LAW

            I.  https://fin-law.de

            E. info@fin-law.de

            subscribe to Newsletter

            This Blog Article as Podcast?

              Contact

              info@fin-law.de

              Nov 10, 2025

              Threats, Incidents, and Attacks Under DORA – What Financial Companies Need to Know

              Since January 17, 2025, Regulation (EU) 2022/2554 – better known as DORA – has been compulsory for financial companies. A key objective of the regulation is to strengthen the digital operational resilience of the financial sector and create clear structures for dealing with ICT risks. But not all risks are the same: DORA makes a precise distinction between threats, incidents, and attacks – and attaches different obligations to each category. While threats as potential sources of danger are primarily to be analyzed internally, actual incidents and attacks trigger specific reporting and action obligations. This distinction becomes particularly relevant when it comes to the question of when financial companies are obliged to inform authorities or affected parties. The regulation not only defines what constitutes a cyber threat, an ICT-related incident, or a cyber-attack, but also specifies the steps that companies must take in each case. Precise classification is of central importance not only for compliance, but also for the strategic orientation of ICT risk management.

              What Are Threats, Incidents, and Attacks Under DORA

              DORA uses a number of different terms for attacks and incidents. These terms can be broadly divided into two categories: threats (which have the potential to cause damage) and incidents/attacks (the actual events that have caused or are causing damage). Threats refer to possible circumstances or actions that could affect network and information systems (ICT). According to Art. 3 No. 12 DORA, a cyber threat refers to a possible circumstance, event, or action that could harm, disrupt, or otherwise affect network and information systems, users of these systems, and other persons. According to Art. 3 No. 13 DORA, a significant cyber threat is a cyber threat whose technical characteristics indicate that it could have the potential to cause a serious ICT-related incident or a serious payment-related operational or security incident. An ICT-related incident is the most general category of a negative event in the ICT sector. It is defined in Article 3(8) of DORA as an unplanned event or a series of related events that compromises the security of network and information systems and has an adverse impact on the availability, authenticity, integrity, or confidentiality of data or on the services provided by the financial institution. ICT-related incidents are further subdivided into serious ICT-related incidents and serious payment-related operational or security incidents within the meaning of Article 3(10) and (11) DORA. In contrast, a cyberattack within the meaning of Article 3(14) DORA refers to a malicious ICT-related incident resulting from an attacker’s attempt to destroy, expose, alter, disable, steal, or gain unauthorized access to or use of an asset.

              What Obligations Are Associated With Each Category?

              DORA attaches different legal consequences and obligations to threats, incidents, and attacks. There is no external reporting obligation for cyber threats as a general threat category. The information is primarily used for internal analysis and further development of digital operational resilience. Reporting a significant cyber threat to the competent authorities is voluntary under Article 19(2) DORA. Financial companies may share this information if they consider the threat to be relevant to the financial system, service users, or customers. Both ICT-related incidents and cyberattacks only trigger an external reporting obligation if they reach a certain level of severity, i.e., if they are classified as serious. According to Art. 19 (1) DORA, financial companies must therefore report serious ICT-related incidents to the competent authority. Credit institutions, e-money institutions, payment institutions, and account information service providers must also report serious payment-related operational or security incidents in accordance with Article 23 of DORA. It follows from recitals 23 and 54 of DORA that this specific reporting obligation replaces the corresponding reporting obligations under PSD2 in order to avoid duplication of requirements. However, the obligations of financial companies are not limited to reporting requirements. Following disruptions to their main activities as a result of serious ICT-related incidents, financial companies must provide for subsequent reviews of the ICT-related incident. These reviews should investigate the causes and identify improvements to ICT processes or the ICT business continuity policy. In addition, financial companies that are not micro-enterprises must, upon request, notify the competent authorities of the changes made following the review of ICT-related incidents in accordance with Article 13 of DORA. Consequently, DORA focuses on proactive integration into risk management and voluntary information sharing in the event of threats, while clear reactive obligations such as reporting, damage limitation, recovery, and root cause analysis are at the forefront in the event of incidents/attacks.

              FIN LAW

              I.  https://fin-law.de

              E. info@fin-law.de

              subscribe to Newsletter

              This Blog Article as Podcast?

              The Gist of It:

              Presentation

                Contact

                info@fin-law.de

                Oct 27, 2025

                Contract Drafting in the Context of the DORA Regulation – What Do Financial Companies Need to Observe?

                Since January 17, 2025, Regulation (EU) 2022/2554 – better known as DORA – has been binding for financial companies and third-party ICT service providers. The regulation not only sets high requirements for digital operational resilience, but also has a direct impact on contract drafting. A key question that arises in practice is: When is a service considered an ICT service within the meaning of DORA? This distinction is crucial because, according to Article 30 DORA, contracts for ICT services must contain certain minimum content. This includes, among other things, clear provisions on risk management, incident reporting, audit rights, and exit strategies. The classification of a service as an ICT service therefore has far-reaching consequences for contract negotiations between financial companies and their service providers. If services are incorrectly not classified as ICT services, this not only poses compliance risks, but also contractual gaps that can lead to liability issues in serious cases. At the same time, DORA shifts the balance of power in contract negotiations: financial companies are now obliged to impose strict requirements on their service providers – which redefines the scope for negotiation for both sides. But how can ICT services be clearly identified, and which contractual clauses are absolutely necessary to meet DORA requirements? These questions are the focus of current discussions and show that DORA represents not only a regulatory challenge, but also a contractual one.

                What are ICT Services?

                According to Article 3(21) of DORA, ICT services are digital services and data services that are provided on a permanent basis to one or more internal or external users via ICT systems, including hardware as a service and hardware services, which also includes technical support provided by the hardware supplier by means of software or firmware updates, with the exception of traditional analog telephone services. The definition is very broad in order to cover as many ICT services as possible and effectively implement the objectives of DORA. A key limitation of the scope of application, as set out in the definition, is that only digital services and data services that are provided on a permanent basis are to be covered. This means that only continuing obligations are regularly covered, while one-off services are not. Annex III of Commission Implementing Regulation (EU) 2024/2956 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the information register (ITS on register of information). This contains a list of categories of ICT services, each with a brief description. This list can be used as an aid for initial classification. The services mentioned include: ICT project management, ICT development, ICT helpdesk and first-level support, ICT security management services, data provision, data analysis, ICT operating resources and hosting services (excluding cloud services), computing power, data storage outside the cloud, telecommunications providers, network infrastructure, hardware and physical devices, software licensing (excluding SaaS), ICT operations management (including maintenance), ICT consulting, ICT risk management, IaaS, PaaS and SaaS.

                Article 30 DORA Defines Clear Minimum Standards for ICT Contracts – Both for Standard and Critical Services

                Every contract for ICT services must first contain a precise description of the services, rights, and obligations, including the exact locations where data is processed and stored. Information security and data protection are key: Specific technical and organizational measures must be defined to ensure the availability, authenticity, integrity, and confidentiality of all data—regardless of whether it is personal data or not. In addition, regulations on data access in the event of insolvency or termination of the contract are essential to ensure continuity of service. Service level agreements (SLAs) with quantitative and qualitative performance targets are mandatory, as is the service provider’s obligation to provide support in the event of ICT incidents and to relieve the financial company of its reporting obligations. Cooperation with supervisory authorities must be contractually anchored, and the financial company’s termination rights – for example, in the event of violations of compliance requirements or deficiencies in risk management – must be explicitly defined. Finally, participation in digital resilience training should be agreed upon, unless the service provider already has its own qualifications. If critical or important functions are involved, the requirements become more stringent: in this case, extended reporting obligations, emergency plans, participation in penetration tests, and comprehensive audit rights for the financial company are mandatory. Exit management regulations that ensure an orderly transition at the end of the contract or when changing service providers are also particularly relevant. In addition, subcontracting must be strictly controlled and contractually secured in order to avoid unwanted risks.

                FIN LAW

                I.  https://fin-law.de

                E. info@fin-law.de

                subscribe to Newsletter

                This Blog Article as Podcast?

                  Contact

                  info@fin-law.de

                  Oct 20, 2025

                  Payment Services in Online Gambling – Where Are the Limits for What Is Permissible?

                  Gambling regulation in Germany is fundamentally a matter for the federal states. The rules governing the permissibility or impermissibility of gambling are therefore regulated separately in each of the federal states in their respective gambling laws. However, in the area of online gambling, the federal states of Germany have decided to introduce uniform regulations that apply to the entire German territory. The creation of uniform rules for online gambling makes sense, especially since access to it does not usually stop at state borders. To achieve this goal, the sixteen German federal states concluded the State Treaty on Gambling (GlüStV) in 2021. In addition to some general provisions concerning stationary offerings, it also contains provisions for common regulations in the area of internet-based gambling and strict compliance obligations for organizers and intermediaries of online gambling. In addition to the requirement to obtain prior permission to organize virtual slot machine games, online casino games, or sports betting, for example, Section 4 (1) sentence 2 GlüStV provides for a so-called prohibition of contribution, which prohibits the provision of payment services to providers of illegal gambling. However, Section 4 (1) sentence 3 GlüStV extends this comprehensible principle to the extent that contribution to payment transactions for other services of a provider is also prohibited if the provider mixes fundamentally permissible services with the offering of unauthorized gambling.

                  Payment Institutions Must Fully Understand Their Customers’ Business Models

                  Compliance with the prohibition of contribution under Section 4 (1) sentence 3 GlüStV can be quite challenging for payment institutions. In order not to violate the prohibition of contribution, the payment institution must have a comprehensive understanding of the customer’s business model and be able to classify it under gambling law. If the services offered by a payment institution’s customer include gamification elements or simply random chances of winning, the payment institution must determine with legal certainty whether the customer’s business model contains elements of illegal gambling. In such cases, if a mixture of fundamentally permissible services and illegal gambling means that payments relating to these services cannot be clearly separated from payments relating to illegal gambling, and illegal payment flows are therefore not clearly identifiable, the prohibition of contribution under Section 4 (1) sentence 3 GlüStV applies. As a consequence, the payment service provider may not execute such payments or provide payment services in relation to such transactions. Payment institutions must therefore thoroughly review the business models of their commercial customers to determine whether they contain any elements of illegal gambling.

                  When is Gambling Considered Illegal?

                  The general requirement to obtain a license for organizing or brokering public games of chance is set out in Section 4 (1) sentence 1 GlüStV. Unauthorized gambling within the meaning of the prohibition of contribution is therefore any organization or brokering of public games of chance without the necessary license within the meaning of Section 4 (1) sentence 1 GlüStV. Section 3 (1) GlüStV defines what exactly the State Treaty means by gambling. According to this, gambling is when a fee is charged for the opportunity to win in a game and the decision on the winnings depends entirely or predominantly on chance. The concept of chance can be difficult to interpret, particularly in the case of sports betting, horse betting, and online poker, but the State Treaty clarifies in this regard that dependence on chance is to be assumed in any case if the uncertain occurrence or outcome of future events is decisive. A game of chance is considered public if a large, non-closed group of people has the opportunity to participate, but also if it involves games of chance that are habitually organized in clubs or other closed societies. The question of whether a license is required can be difficult in individual cases, especially in cases where the customer of the payment service provider does not actually intend to organize a public game of chance, but rather it is a random by-product, for example, as part of marketing measures, that is part of the customer’s range of services.

                  Attorney Dr. Lutz Auffenberg, LL.M. (London)

                  I.  https://fin-law.de

                  E. info@fin-law.de

                  subscribe to Newsletter

                  This Blog Article as Podcast?

                  The Gist of It:

                  Presentation

                    Contact

                    info@fin-law.de

                    Oct 13, 2025

                    Distributors within the Meaning of PSD3 – Are E-Money Agents a Disappearing Concept?

                    Negotiations on the reform of European payment services law are already well advanced. In future, there will be two new European legal acts, the Payment Services Regulation (PSR) and the third Payment Services Directive (PSD3), which will set out both the private law regulations for payment services in Europe, directly applicable as a regulation (PSR), and the supervisory guidelines for the national legislators of the member states (PSD3). In addition to payment services, the new PSD3 will also regulate the supervisory requirements for companies that conduct business with e-money or issue it. Until now, the relevant provisions were regulated in the second E-Money Directive (EMD2), which is to be abolished when PSD3 comes into force. Art. 3 (4) EMD2 obliges Member States to grant e-money institutions in their respective national supervisory law the possibility of distributing and redeeming e-money via natural or legal persons, also known as e-money agents. However, the issuance of e-money units via e-money agents is not permitted. According to Art. 3 (5) EMD2, e-money units must be issued by the e-money institutions themselves. The German legislature has implemented these requirements in the Payment Services Supervision Act (ZAG). According to Section 1 (10) ZAG, an e-money agent is any natural or legal person who, as an independent commercial operator, distributes and redeems e-money on behalf of an e-money institution. Under the PSD3 regime, however, there will no longer be any e-money agents. The directive provides for the agent concept exclusively for payment services, but not for the new e-money services to be introduced. However, the new term “ distributor” is to be introduced.

                    How is a Distributor Defined under PSD3?

                    According to Article 2(36) of the European Commission’s draft directive (PSD3-E), a distributor is a natural or legal person who distributes or redeems e-money on behalf of a payment institution. This definition is very similar to the definition of e-money agents in the EMD2, which is to be replaced. As far as is apparent, the only difference between the definitions is the fact that distributors can be used by payment institutions and e-money agents by e-money institutions. However, since PSD3 also aims to abolish the concept of e-money institutions and instead allow payment institutions to apply for additional authorization to provide e-money services, the reference to payment institutions in the new definition is not surprising. The departure from the term “e-money agent” provided for in the draft PSD3 appears to serve the purpose of establishing a clearer conceptual distinction between agents that can be used for payment services and distributors that can be used for the distribution and redemption of e-money. It should be noted that, under the future PSD3 regime, e-money services are not intended to be payment services, but rather a separate type of regulated service for which payment institutions can obtain a license. Furthermore, it should be noted that distributors are not to be used to provide e-money services, but can only be subcontracted by payment institutions for the distribution and redemption of e-money. The two concepts differ significantly in this respect. The introduction of the concept of distributors therefore serves to clarify the situation.

                    What May an Electronic Money Distributor Be Permitted to Do?

                    According to Article 20(1) of the draft PSD3, Member States should allow payment institutions providing e-money services to use distributors for the distribution and redemption of e-money. In this context, Article 20(2) of the draft is, at the very least, misleadingly worded, as it stipulates that payment institutions must comply with the requirements for the use of payment agents set out in Article 19 PSD3-E if they intend to provide e-money services through distributors. Given the clear wording of the definition of distributor in Art. 2 para. 36 PSD3-E and the clear definition of e-money services in Annex II PSD3-E, which only covers the issuance of e-money, the management of payment accounts for e-money units, and the transfer of e-money units, but not the distribution and redemption thereof, the provision in Article 20(2) PSD3-E does not make sense. Until the final version of PSD3 is available, Article 20(2) of the draft should therefore be revised in any case. Instead, distributors should only be used for the distribution and redemption of e-money units. They will not be allowed to provide e-money services that require a license. In this respect, there will be little difference between e-money agents under EMD2 and distributors within the meaning of PSD3.

                    Attorney Dr. Lutz Auffenberg, LL.M. (London)

                    I.  https://fin-law.de

                    E. info@fin-law.de

                    subscribe to Newsletter

                    This Blog Article as Podcast?

                    The Gist of It:

                    Presentation

                      Contact

                      info@fin-law.de

                      Sep 29, 2025

                      E-Money Services within the Meaning of PSD3 – What Exactly Will the New Activity Include?

                      European legislators are working diligently to overhaul European payment services law. The final versions of the new Payment Services Regulation (PSR) and the third Payment Services Directive (PSD3) are expected to be adopted at the end of 2025 or early 2026. One of the main concerns of the proposed revisions is the abolition of the second E-Money Directive (EMD2) while incorporating the provisions on e-money into the new PSD3 and PSR. Under the current PSD2 and EMD2 regime, the EU Commission had found that there were differences in the practical interpretation of the directives by the supervisory authorities of the member states, particularly with regard to the distinction between payment and e-money products, which were exploited by applicant companies. In future, therefore, all supervisory and civil law provisions relating to payment services and e-money services are to be regulated uniformly by PSD3 and PSR. The term “e-money institution” will then no longer exist. Instead, payment institutions will be able to apply to BaFin or the competent authority in each individual case for a license to provide e-money services in addition to or exclusively for payment services. But what exactly will e-money services be in this context?

                      E-Money Services as a New and Regulated Activity under Payment Services Law

                      The regulatory treatment of e-money business is to be integrated in accordance with the current draft of PSD3 through the introduction of the new term “e-money services.” According to this, e-money services are to include the issuance of e-money, the maintenance of payment accounts for storing e-money units, and the transfer of e-money units. E-money services would thus not only be the original issuance of e-money, but also downstream services related to the storage of e-money and the transfer of e-money units. It is striking that the definition in the current PSD3 draft does not separate the three different activities of e-money services with an “or.” The draft’s provisions, for example, regarding the required initial capital that payment institutions providing e-money services must have, are also uniform at €400,000, regardless of whether e-money is issued or only transfer services are to be provided in relation to e-money that may not have been issued by the institution itself. Furthermore, the draft PSD3 distinguishes between whether a payment institution offers e-money services or not when calculating the required own funds. Institutions that exclusively offer e-money services must always apply Method D, according to which the institution’s own funds must always amount to at least 2% of the average e-money in circulation. These provisions lead to the conclusion that the provision of e-money services can only be uniform, meaning that, for example, simply offering a storage facility for third-party e-money units in a payment account would not be classified as an e-money service.

                      Services Relating to E-Money Units without Issuer Characteristics Nevertheless Not Unregulated

                      Services provided by payment institutions that do not themselves act as e-money issuers would nevertheless be covered by the new PSD3 and PSR regulations as regulated activities. This is because, according to the new definitions in PSD3, e-money units should always qualify as money. This means that e-money units are generally also potential subjects of traditional payment services. If, for example, a service provider wishes to offer to store e-money units issued by a third party in a payment account and to enable transfers of these units to and from the payment account, this activity could simply constitute deposit and withdrawal business within the meaning of No. 1 and/or 2 of Annex I to PSD3. The provider would then have to obtain a license as a payment institution for this activity. A license to provide e-money services would not be required. In the future, such demarcation issues could arise particularly frequently in the area of e-money tokens, which are also considered e-money under Article 48(2) MiCAR. It is in the nature of tokens that they cannot be held or transferred exclusively by the issuer. Consequently, it is also very likely that companies will use them to provide financial transfer services or other payment services, for example. In such cases, the additional question arises as to whether, in addition to a BaFin license for payment services, a license as a provider of crypto-asset services is also required.

                      Attorney Dr. Lutz Auffenberg, LL.M. (London)

                      I.  https://fin-law.de

                      E. info@fin-law.de

                      subscribe to Newsletter

                      This Blog Article as Podcast?

                      The Gist of It:

                      Presentation

                        Contact

                        info@fin-law.de

                        Sep 15, 2025

                        Which Payment Services do Crypto Custodians Provide with EMT?

                        Since the end of last year, the custody of crypto assets has been regulated as a crypto asset service in the Markets in Crypto Assets Regulation (MiCAR). Providers of this service must obtain a license in accordance with Art. 62 MiCAR from their competent supervisory authority—in Germany BaFin— prior to being permitted to hold crypto assets for clients. With such a license, crypto custodians are authorized to hold all tokens for clients that qualify as crypto assets under MiCAR. In addition to traditional crypto assets such as Bitcoin and Ether, this also includes special forms of crypto assets regulated by MiCAR, such as asset-referenced tokens (ART) and e-money tokens (EMT). Both of the aforementioned types of so-called stablecoins are characterized by the fact that they are designed to achieve value stability by referring to another stable value. In the case of ART, the reference value may be derived from other official currencies, securities, other crypto assets, or other items. If, on the other hand, the reference value of the token is a single official currency such as the euro, US dollar, or Swiss franc, for example, the token is classified as an EMT. Crypto custodians face additional regulatory issues when storing e-money tokens for their customers, as e-money tokens are not only classified as crypto assets under MiCAR, but also as e-money within the meaning of the Second E-Money Directive (2009/110/EC) applicable in the European Union. As a result, they are also considered funds within the meaning of the second Payment Services Directive (PSD2), as recently confirmed once again by the European Banking Authority (EBA).

                        Crypto Custodians Will Forthcoming Require Permission Under the ZAG for Handling E-Money Tokens in Business

                        In its no-action letter dated June 10, 2025, the EBA advises the supervisory authorities of the member states to only require market participants to comply with the regulatory obligations under PSD2, which are implemented in Germany in the Payment Services Supervision Act (ZAG), after March 2, 2026. However, crypto custodians who wish to offer their customers the custody of e-money tokens should already start preparing for the second stage following March 2, 2026, and apply for a ZAG license. The EBA advises supervisory authorities to deprioritize some of the obligations imposed on payment service providers. However, the basic additional licensing requirement still applies in all cases. Crypto custodians who also want to offer their customers the option of keeping EMT in their wallets and sending it to other wallets or receiving EMT from other wallets will then also be providing payment services. In these cases, the payment services of the placement of funds on payment accounts (Section 1 (1) sentence 2 no. 1 ZAG) and the withdrawal of funds from payment accounts (Section 1 (1) sentence 2 no. 2 ZAG) are particularly relevant. Payment transactions pursuant to Section 1 (1) sentence 2 no. 3 ZAG and payment transactions involving the granting of credit pursuant to Section 1 (1) sentence 2 no. 4 ZAG may also be relevant if crypto custodians send EMT from customers to other wallets.

                        What Are the Alternatives for Crypto Custodians to Obtaining Their Own ZAG License?

                        Applying for a separate license under Section 10 (1) ZAG for the provision of payment services does not make sense in every case. In individual cases, crypto custodians may have problems with the fact that their managers may have the professional qualifications for crypto custody, but may not yet have professional experience in the payment services business. It is not unlikely that BaFin will require the management to be changed or expanded to include qualified managers with ZAG experience in the relevant licensing procedures. In such cases, it may be possible to have the additional payment services arising in connection with the custody of e-money tokens provided by another institution, for example, via an outsourcing solution. In this case, it is not necessary to obtain a separate license for the provision of payment services. If the crypto custodian wishes to offer payment services to its customers itself, it may also consider whether the crypto custodian should become a payment agent for the other payment institution. It can then perform the regulated payment services on behalf of the other institution as an independent trader. Its actions are then attributed to the payment institution for supervisory and civil law purposes.

                        Attorney Dr. Lutz Auffenberg, LL.M. (London)

                        I. https://fin-law.de

                        E. info@fin-law.de

                        subscribe to Newsletter

                        This Blog Article as Podcast?

                        The Gist of It:

                        Presentation

                          Contact

                          info@fin-law.de

                          to top