DeFi protocol frontend in Cyprus
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD on all customers (natural persons: full name, DOB, place of birth, nationality, address, ID/passport number; verification from reliable independent sources)
- UBO identification for legal entities (≥25% ownership threshold)
- Understand purpose and nature of business relationship
- Source of Funds/Source of Wealth checks for high-risk clients or significant transactions
- Enhanced Due Diligence (EDD) for PEPs, high-risk third-country customers, non-face-to-face relationships without safeguards, and unusual/high-value transactions
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile
- Internal reporting of suspicions to MLRO; MLRO must submit STRs to MOKAS (Cyprus FIU)
- Record-keeping for at least 5 years (CDD docs, transaction records, policies, training records)
- Appointment of a qualified MLRO at management level
- Regular and ongoing AML/CFT staff training
Key Restrictions
- Must be registered as a CASP with CySEC under the current framework and subsequently authorized under MiCA by December 30, 2024
- Must have physical presence in Cyprus and demonstrate substance
- Must have at least two executive directors (fit and proper test) resident in Cyprus
- Minimum initial capital of €125,000 if offering custody/administration of crypto-assets; otherwise tiered capital requirements apply
- Must implement robust IT systems, secure cryptographic key storage, access controls, cybersecurity protocols, and business continuity plans
- Client assets must be segregated from the operator's own assets and not used for the operator's own account
- Professional indemnity insurance or own funds required to cover liability risks (custody services)
- Fee-taking from frontend operations likely constitutes 'offering and/or selling of crypto assets' or 'participation in distribution' — bringing the frontend fully into CASP scope
Key Risks
- If the frontend does not take custody of keys and merely provides an interface to permissionless contracts, it may still be deemed a CASP if it offers/sells crypto-assets or provides financial services related to distribution — unclear boundary under MiCA
- Regulatory ambiguity: whether a pure UI/aggregator with no custody and no fees constitutes a 'crypto-asset service' is unresolved; CySEC/MiCA guidance will be needed
- Enforcement precedent: CySEC has fined major platforms (eToro Europe Ltd, Bitpanda GmbH) for AML/CFT compliance failures — demonstrating active enforcement posture
- Geofencing US persons is a separate US regulatory risk; Cyprus regulation requires CDD on all customers, not just US persons
- If the frontend screens no users and charges no fees, it may try to argue it is not a CASP — high risk that CySEC disagrees and imposes penalties for unregistered activity
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Directive (EU) 2018/843 (5AMLD): Crucially extended the scope of EU AML rules to include crypto-asset exchanges and custodian wallet providers, requiring them to be regulated and subject to AML/CFT obligations.
CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.
CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.
Offering and/or selling of crypto assets, including the initial offering.
Participation in and/or provision of financial services relating to the distribution, offering and/or selling of crypto assets, including the initial offering.
The entity must meet local management and control tests to maintain its status, not strictly be a legal person established in Cyprus.
Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.
Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.
Organisational requirements in Cyprus continue to include robust internal controls and compliance with data protection laws, while effective risk management systems, IT systems, security mechanisms, and business continuity plans have been significantly enhanced and made more prescriptive through the Security of Networks and Information Systems Law (N.89 (I)/2020 as amended by N.60 (I)/2025) implementing the NIS2 Directive, which mandates specific technical, operational, and organisational measures for essential and important organisations with compliance by October 2024.
AML/CFT Compliance: Comprehensive AML/CFT policies, procedures, and internal controls, including customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting.
Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
December 30, 2024: Rules for all other crypto-assets and CASPs (including custody providers) will apply.
Article 67: CASPs providing custody services must hold crypto-assets on behalf of clients separately from their own assets. They must ensure that client crypto-assets are not used for their own account and are identifiable from the CASP's own crypto-assets.
Article 67(4): CASPs providing custody services must either have a professional indemnity insurance policy or own funds equivalent to the potential liability risks arising from their activities. The amount of such insurance or own funds must be sufficient to cover losses that may arise from negligence, errors, omissions, fraud, or operational failures. ESMA will develop regulatory technical standards (RTS) to specify the minimum monetary amount of the professional indemnity insurance or own funds.
Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.
Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.
Natural Persons: Full name, date and place of birth, nationality, permanent residential address, unique identification number (e.g., passport or ID number). Verification requires reliable, independent source documents and/or data.
Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.
Understanding the Purpose and Nature of the Business Relationship: CASPs must understand why the customer wants to use their services and the expected type and volume of transactions.
Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.
Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.
MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).
Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.
Internal Policies and Procedures: CASPs must establish and maintain robust internal AML/CFT policies, controls, and procedures, including a comprehensive risk assessment. These should be documented in an "AML Manual."
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Cyprus residents will likely be classified as a CASP (crypto-asset service provider) under CySEC/MiCA, requiring registration/authorization, physical presence in Cyprus, minimum capital (€125k+), full AML/CFT compliance, CDD on all users, appointment of an MLRO, and segregation of client assets if custody is involved; the key open question is whether a purely non-custodial, fee-free aggregator falls outside scope, but the regulatory trend points to bringing such interfaces within the CASP definition, and fee-taking almost certainly triggers full regulation.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?