BTC $63 366,94 0.22%
ETH $1 882,73 +0.29%
USDT $0,9990 +0%
BNB $610,32 +0%
USDC $0,9999 0%
XRP $1,01 +0.43%
SOL $76,01 +0.41%
TRX $0,3340 0.52%
HYPE $57,43 +1.89%
DOGE $0,0701 +0.37%
LEO $9,50 +4.02%
ZEC $490,69 0.43%
XMR $394,23 0.15%
ADA $0,1824 0.25%
LINK $8,86 +2.06%
XLM $0,1592 0.59%
DAI $0,9993 0.06%
BCH $206,45 3.38%
USD1 $0,9990 0.02%
USDe $0,9999 +0.01%

BitBullNews Crypto Policy & Regulation Watch – July 21-28: Perimeter Hardens

BitBullNews Crypto Policy & Regulation Watch - July 21-28: Perimeter Hardens

Content

1. Weekly Regulatory Scorecard 2. The SEC Moved From Tokens To Control 3. SEC Vault And Lending Perimeter 4. The Word “DeFi” Does Not Set The Legal Perimeter 5. CLARITY Remained Stuck Between Committee And The Floor 6. FINRA Built A Broker-Dealer Crypto Map 7. FINRA Crypto Activity Map 8. MiCA Compliance Became A Legal-Entity Exercise 9. EEA Service-Perimeter Case Study 10. Partner-Based Compliance Is Becoming A Market Structure 11. The United Kingdom Has The Clearest Clock 12. United Kingdom Implementation Calendar 13. OFAC Showed That Enforcement Remains Network-Based 14. What Compliance Teams Should Do Now 14.1. Map Every Decision Right Inside Yield Products 14.2. Reconcile FINRA Responses With Internal Records 14.3. Verify MiCA At The Service Level 14.4. Separate Regulated Services From Adjacent Products 14.5. Start UK Applications Before The Gateway Opens 14.6. Screen Networks, Not Only Names 15. Regulatory Risk Dashboard 16. Data Sources & References 17. Methodology

Crypto regulation moved closer to products and business models this week.

Related article
BitBullNews Crypto Policy & Regulation Watch – July 14-21: The Implementation Gap BitBullNews Crypto Policy & Regulation Watch – July 14-21: The Implementation Gap Crypto policy moved in two different directions this week. International coordination accelerated. The United States and United Kingdom published a shared framework for cross-border…

The United States still lacks a completed digital-asset market-structure law. The CLARITY Act remained short of a Senate floor vote through July 27. Yet the absence of legislation did not stop regulators from defining where existing rules may apply.

SEC Commissioner Hester Peirce turned attention to crypto vaults and onchain lending. Her July 22 statement drew a line between software that executes a fixed strategy and managers who select assets, set lending terms or redirect user funds. The more discretion a product contains, the harder it becomes to argue that the arrangement is simply autonomous software.

FINRA reached a different milestone. Its July 24 information-request deadline required every member firm to disclose current and planned crypto activities, including direct access provided through affiliates or external companies. The exercise is not a licensing decision, but it gives FINRA a detailed map of how broker-dealers are entering the market.

Europe and the United Kingdom are further into implementation. ESMA refreshed its MiCA register on July 24, while the FCA confirmed a defined authorization window ahead of the UK regime’s October 2027 commencement. Nexo’s European structure provided a live example of what implementation now looks like: one consumer-facing platform, several regulated service providers and separate products sitting outside the cited authorization scope.

The message across jurisdictions is consistent. Crypto regulation is becoming less concerned with labels and more concerned with functions, counterparties and control.

Weekly Regulatory Scorecard

Jurisdiction Development Status At July 28 Market Significance
United States SEC statement on crypto vaults and lending Commissioner statement published July 22; not a Commission rule Managed yield products may implicate securities, investment-company and adviser rules
United States CLARITY Act Advanced from committee 15–9; no Senate floor vote through July 27 Federal market-structure legislation remains unfinished
United States FINRA crypto activity request Responses due July 24 from all member firms Broker-dealer crypto exposure is being mapped at the firm, affiliate and third-party levels
European Union ESMA MiCA register Updated July 24; five datasets published weekly Authorization and non-compliance can be checked by legal entity
European Economic Area Partner-based compliance model Custody, trading and futures can be delivered by different regulated counterparties Brand-level compliance claims do not define every service’s legal perimeter
United Kingdom FCA crypto authorization gateway Expected to open September 30, 2026 and close February 28, 2027 Firms now have a fixed preparation and application timetable
United States OFAC digital-asset sanctions action Four individuals and nine entities designated July 24 Screening must cover wallets, affiliates, payment rails and ownership networks

Sources: SEC, U.S. Senate, FINRA, ESMA, FCA, company legal disclosures and the U.S. Treasury.

Seven-row regulatory status matrix comparing the United States, European Union, European Economic Area and United Kingdom

The SEC Moved From Tokens To Control

Peirce’s statement did not create a new rule. It did something more useful for product teams: it identified the features most likely to pull a vault or lending strategy inside the federal securities-law perimeter.

Her starting point was straightforward. Moving an activity onchain does not remove legal obligations that would apply to the same economic activity offchain. Tokenized securities remain securities, and a smart contract does not neutralize the role of a manager who decides where user capital goes.

Crypto vaults can sit anywhere on a wide spectrum. At one end, an immutable contract follows a fixed allocation without ongoing human decisions. At the other, a curator selects protocols, reallocates funds, changes risk limits or appoints another party to manage those decisions.

The second model carries more regulatory exposure because users may depend on the managerial efforts of an identifiable operator.

SEC Vault And Lending Perimeter

Product Design Feature Potential Regulatory Issue Evidence A Firm Should Maintain
Immutable contract with fixed allocation rules May reduce reliance on ongoing managerial effort, but does not create an automatic exemption Contract immutability, administrator powers, upgrade controls, fee logic and emergency rights
Curator selects or replaces yield strategies Potential investment-contract and investment-adviser analysis Investment mandate, decision process, compensation, disclosures and conflicts policy
Vault pools assets and invests in securities Possible investment-company, unit investment trust or managed-fund treatment Asset classification, portfolio composition, redemption terms and investor eligibility
Operator sets interest rates and accepted collateral Lending arrangements may involve securities or advisory issues Rate-setting methodology, eligible assets, counterparty criteria and governance records
Manager controls loan-to-value and liquidation thresholds Users may rely on active risk management rather than code alone Risk models, change logs, approval authority and liquidation procedures
Vault holds tokenized securities Onchain execution does not remove securities-law status Underlying instrument analysis, transfer restrictions and regulated intermediary roles
Loan instrument resembles a note The lending claim itself may require securities analysis Borrower purpose, distribution model, maturity, expected return and risk disclosures

This table summarizes regulatory questions raised by Commissioner Peirce. Her statement is not a Commission rule, order or definitive legal classification of any specific product.

Place immutable fixed-code vaults at the lower-discretion end and actively curated vaults, managed lending strategies and tokenized-security portfolios at the higher-discretion end.

The Word “DeFi” Does Not Set The Legal Perimeter

The industry often treats decentralization as a binary condition. The SEC statement points toward a functional test instead.

A product may execute through smart contracts while still relying on a small group to:

  • Select the available strategies.
  • Change collateral requirements.
  • Set borrowing costs.
  • approve upgrades.
  • control emergency functions.
  • receive performance-linked compensation.

Those facts can matter more than whether the interface uses the words “vault,” “protocol” or “DeFi.”

For compliance teams, the immediate task is not to decide whether a product is decentralized in the abstract. It is to map every decision right.

Who can change the code? Who selects protocols? Who receives fees? Who can freeze withdrawals? Who decides when an asset becomes unacceptable collateral? Those answers reveal where managerial reliance and regulatory responsibility sit.

The statement also matters for tokenized funds. A vault that automatically allocates into tokenized securities may still resemble an investment company or separately managed account, even when portfolio execution occurs entirely onchain.

CLARITY Remained Stuck Between Committee And The Floor

The Senate Banking Committee advanced the CLARITY Act by a 15–9 vote on May 14, sending the bill toward the Senate floor. The official Senate roll-call record through July 27 showed votes on nominations and another resolution, but no floor vote on the digital-asset market-structure bill.

That distinction matters. Committee passage shows that a bill has enough support to continue. It does not establish final language, a floor coalition or an enactment date.

The negotiation also moved beyond the original division of responsibility between the SEC and CFTC.

New crypto ethics language was released on July 22. Senate Banking Committee minority staff issued a sharply critical fact sheet arguing that the proposal contained enforcement and conflict-of-interest loopholes. That document represents the minority staff’s political and legal analysis, not a neutral regulatory determination. Its existence nevertheless confirms that public-official ethics remains part of the legislative negotiation.

The unresolved package now includes several distinct debates:

  • SEC and CFTC jurisdiction.
  • Treatment of decentralized protocols and software developers.
  • Stablecoin rewards and yield products.
  • Anti-money-laundering obligations.
  • Customer-asset protections.
  • Ethics and conflicts involving government officials.
  • The relationship between a future statute and ongoing agency interpretations.

The market should therefore treat CLARITY as a legislative asset with uncertain duration, not as an enacted framework.

Legislative timeline showing the Senate Banking Committee’s 15–9 vote on May 14, the release of new ethics language on July 22 and the absence of a Senate floor vote through July 27

FINRA Built A Broker-Dealer Crypto Map

FINRA’s July 24 deadline marked a shift from policy discussion to supervisory inventory.

The regulator asked all member firms to report their current and planned crypto activities. FINRA said it intends to use the information to adapt regulatory programs, modernize oversight, support compliance and identify industry trends. Firm-specific responses will remain private, although FINRA may publish anonymized aggregate findings.

The request also clarified several definitions that firms had interpreted inconsistently.

Allowing clients to buy crypto ETFs does not, by itself, mean a broker provides direct crypto trading or custody. Providing access to Bitcoin or Ether through an affiliate does fall within FINRA’s third-party activity question. Making an ETF available to customers also does not make the broker an authorized participant; that term applies to firms that create and redeem fund shares directly in the primary market.

FINRA Crypto Activity Map

Business Activity FINRA Treatment In The Request Supervisory Implication
Direct crypto trading through an affiliate Report as third-party crypto trading access Affiliate structure does not remove the activity from the firm’s regulatory inventory
Third-party custody of Bitcoin or Ether for brokerage customers Report as crypto custody access Vendor governance and customer disclosures become examination issues
Customer access to crypto ETFs Not treated as direct crypto trading or custody for the relevant checkbox Securities-product distribution remains distinct from direct asset activity
Acting as an ETF authorized participant Report only when the firm creates or redeems shares directly with the fund Primary-market operations must be separated from ordinary brokerage access
Planned crypto products or services Included alongside current activities Supervisors are mapping future exposure before products launch
Firm-level responses Not publicly disclosed by FINRA Responses may become a baseline for future risk monitoring and examinations
Industry-wide results May be published in aggregate Market participants may eventually receive a clearer view of broker-dealer adoption

Source: FINRA’s 2026 Crypto Asset Activity Information Request and published FAQs.

The practical risk is inconsistency.

A firm’s FINRA submission should match its board materials, product roadmap, affiliate agreements, public marketing and vendor inventory. A business unit describing an arrangement as “ETF access” while another document describes direct crypto execution could create a credibility problem during examination.

The same applies to plans. FINRA asked about both current and intended activity. A firm that later launches a crypto service omitted from its response may need to explain when the plan changed and how compliance reviewed it.

MiCA Compliance Became A Legal-Entity Exercise

ESMA updated its interim MiCA register on July 24.

The register contains five separate datasets covering non-stablecoin white papers, asset-referenced-token issuers, e-money-token issuers, authorized crypto-asset service providers and non-compliant entities. ESMA publishes updates weekly using information supplied by national competent authorities and the European Banking Authority.

The weekly schedule creates a practical limitation. A national authorization or withdrawal may appear in a domestic register before it reaches ESMA’s central files. Companies, counterparties and journalists should therefore check both the ESMA register and the relevant national regulator when timing matters.

The register also does not approve the contents of listed crypto-asset white papers. ESMA states that responsibility remains with the issuer or offeror. Inclusion proves that a document has been notified and recorded; it does not function as an investment endorsement.

The more difficult issue is service scope.

A group may operate a recognized brand while several legal entities provide custody, execution, transfer, derivatives or lending. Saying that a platform is “MiCA-aligned” does not identify which company is regulated or which services fall within its permission.

EEA Service-Perimeter Case Study

Customer-Facing Service Publicly Identified Provider Authorization Basis Cited By Nexo Scope Note
Crypto custody and administration Tangany GmbH MiCAR authorization and BaFin supervision Tangany is identified as the regulated counterparty for custody and crypto-asset transfers
Crypto-asset transfers Tangany GmbH MiCAR authorization Coverage applies to the stated transfer service, not automatically to every product on the platform
Spot trading through “Exchange On Nexo” DLT Securities GmbH, branded as DLT Finance MiCAR and MiFID II authorization DLT Securities is identified as the regulated execution counterparty
Perpetual futures execution DLT Securities GmbH MiFID-related investment-firm permissions Derivatives exposure sits under a different legal framework from spot crypto custody
Margin collateral administration for perpetuals Tangany GmbH Tangany’s regulated custody role Custody of collateral does not make the underlying derivative a MiCA product
Earn rewards Separate Nexo product Outside the cited Tangany and DLT authorizations Nexo states that Earn is not deposit-taking and is outside MiCAR
Crypto-backed borrowing Separate Nexo product Outside the cited Tangany and DLT authorizations Nexo states that Borrow is not covered by those authorization or protection schemes

The table reflects Nexo’s public EEA disclosures. It does not replace verification through ESMA, BaFin or the relevant contractual documentation.

Nexo customer interface at the top, Tangany handling custody and transfers, DLT Securities handling trading and perpetual execution, and Earn and Borrow displayed separately outside the cited partner authorization perimeter

Partner-Based Compliance Is Becoming A Market Structure

The Nexo example illustrates a model likely to become more common in Europe.

A consumer may experience one interface, account history and brand relationship. Behind that interface, different regulated entities perform different functions. This allows a platform to maintain distribution while outsourcing regulated execution or custody to authorized specialists.

The model can accelerate market access, but it creates additional counterparty and disclosure risk.

Customers need clear answers to four questions:

  1. Which legal entity holds the assets?
  2. Which company executes each transaction?
  3. Which regulator supervises that specific activity?
  4. Which products sit outside the authorization being advertised?

The fourth question is the most important. Nexo’s own disclosure separates Earn and Borrow from the MiCA and MiFID authorizations cited for custody, trading and futures. It also states that those products are not covered by deposit-guarantee or investor-compensation schemes.

This does not mean the separate products are unlawful. It means the regulatory protection attached to one service should not be assumed to cover another.

The United Kingdom Has The Clearest Clock

The UK still has more than a year before its new crypto regime begins, but firms already know the expected sequence.

The FCA published final rules and guidance on June 30 for firms that receive permission under the Financial Services and Markets Act. The broader regime is expected to commence on October 25, 2027. It will move UK crypto supervision beyond the existing anti-money-laundering and financial-promotion framework into authorization, prudential standards, custody, market conduct and operational resilience.

The authorization gateway is expected to open on September 30, 2026 and close on February 28, 2027. Existing FCA anti-money-laundering registration will not convert automatically into FSMA authorization. Already-authorized financial firms will need to vary their permissions for crypto activities.

United Kingdom Implementation Calendar

Date Or Stage Requirement Consequence For Firms
June 30, 2026 FCA published final rules and guidance Firms can begin designing applications against a defined rule package
September 30, 2026 Expected authorization gateway opening New applicants may apply; existing FSMA firms may submit permission variations
February 28, 2027 Expected gateway closing date Applications after this point lose the benefit of the standard application-period route
Before October 25, 2027 FCA assesses applications and permission variations Firms should maintain evidence on governance, capital, safeguarding and operational resilience
October 25, 2027 New crypto regime expected to commence In-scope activity requires appropriate FSMA authorization or a valid statutory transition
On-Time Application Still Pending Saving provision may allow continued service Firm may continue while the application or qualifying appeal remains unresolved
Late Application Still Pending Transitional provision applies at commencement Firm may service pre-existing contracts but cannot enter new UK customer contracts
No Application Business must be run off before commencement Continued in-scope activity could breach the UK general prohibition

Sources: FCA crypto-regime and authorization-gateway guidance.

UK regulatory implementation timeline from the June 30 rule package through the September 30 gateway opening, February 28 application deadline and October 25, 2027 commencement

The UK timetable changes the operational conversation.

U.S. firms are still waiting to see whether Congress completes the market-structure framework. UK firms already need to prepare legal-entity charts, financial projections, safeguarding systems, senior-manager responsibilities and product-level permission maps.

The application form was still being finalized when the FCA published its gateway guidance, but the regulator had already released an information document and financial-data template showing the expected scope of submissions.

Waiting until the gateway opens would leave firms only five months to assemble a full application.

OFAC Showed That Enforcement Remains Network-Based

The week’s enforcement action came from the U.S. Treasury rather than a market regulator.

On July 24, OFAC designated four individuals and nine entities connected to the sanctions-evasion network of Iranian financier Babak Zanjani. Treasury said the wider operation included financial services, digital-asset trading, gold and precious gems, transportation and infrastructure businesses.

The action targeted entities supporting the previously designated digital-asset exchanges Zedcex and Zedxion. OFAC said addresses attributed to the exchanges had processed funds on behalf of wallets attributed to Iran’s Islamic Revolutionary Guard Corps.

The network extended beyond exchange wallets.

Treasury described Zedpay as an integrated wallet, transfer and fiat-settlement provider for Zedxion. It also identified corporate entities that supported exchange infrastructure or interacted with associated wallets.

The compliance lesson is broader than screening an exchange name against a sanctions list.

A defensible control framework should cover:

  • Designated wallet addresses.
  • Newly generated addresses linked through transaction behavior.
  • Corporate owners and controlled entities.
  • Integrated payment and settlement providers.
  • Executives and beneficial owners.
  • Tokens or NFT projects connected to the sanctioned network.
  • Cross-border counterparties providing technical or financial support.

The policy environment may be becoming more supportive of regulated crypto activity. Illicit-finance enforcement is not becoming softer.

What Compliance Teams Should Do Now

Map Every Decision Right Inside Yield Products

Vault operators should document who can select strategies, change contracts, set fees, modify risk parameters and stop withdrawals.

The legal analysis should reflect actual control, not the decentralization language used in marketing.

Reconcile FINRA Responses With Internal Records

Broker-dealers should compare their submitted activity inventory with board papers, affiliate agreements, vendor contracts, public websites and product roadmaps.

Future examinations may test whether the firm’s regulatory submission matched what the business was building.

Verify MiCA At The Service Level

A brand name is not a regulatory permission.

Before relying on a MiCA claim, identify the contracting entity, the exact authorized service and the responsible national regulator. Check ESMA and national registers, allowing for ESMA’s weekly publication lag.

Separate Regulated Services From Adjacent Products

Custody authorization does not automatically cover lending. A trading permission does not necessarily cover yield products. MiFID derivatives execution and MiCA spot-asset services should not be presented as the same regulatory protection.

Start UK Applications Before The Gateway Opens

The FCA expects applications to be tailored to each business model. Firms should complete their activity classification, legal opinions, governance map, prudential forecasts and safeguarding design before September 30.

Screen Networks, Not Only Names

OFAC’s action shows how exchanges, wallets, payment companies, affiliated businesses and token projects can form one sanctions-evasion system.

Transaction monitoring should connect blockchain activity with ownership and corporate-intelligence data.

Regulatory Risk Dashboard

Signal Current Reading Interpretation Confirmation Needed
U.S. Market-Structure Legislation No Senate floor vote through July 27 Statutory jurisdiction remains unresolved Scheduled floor action and final negotiated text
CLARITY Committee Status Advanced 15–9 on May 14 Bipartisan support exists but is insufficient for enactment Senate passage and reconciliation with the House
Crypto Ethics Negotiation New language released July 22 and contested by minority staff Ethics remains part of the legislative coalition problem Bipartisan enforcement and conflict-of-interest framework
SEC Vault Guidance Commissioner statement, not binding rule Regulatory attention is moving toward control and managerial discretion Commission-level guidance, rulemaking or adjudication
Managed Onchain Lending Rates, LTV and liquidations may be actively controlled “DeFi” branding does not remove potential adviser or securities issues Product-specific legal analysis
FINRA Information Request Responses due July 24 from all member firms Broker exposure is now documented across current and planned activity Aggregate findings or updated examination priorities
ESMA MiCA Register Updated July 24 and published weekly EU authorization is increasingly verifiable by entity Reconciliation with national registers and service scope
Partner-Based EU Models Custody, trading and lending may sit with different entities One platform can contain several regulatory perimeters Clear contracts and customer disclosures
UK Authorization Gateway September 30, 2026–February 28, 2027 Implementation timetable is fixed and approaching Final application readiness and FCA processing capacity
UK Regime Commencement Expected October 25, 2027 Existing AML registration will not be enough FSMA permission for each regulated activity
Digital-Asset Sanctions Risk Four people and nine entities designated July 24 Enforcement targets networks rather than isolated wallets Continuous affiliate, ownership and wallet monitoring
Beyond the License: The New Reality of Crypto Compliance

The regulatory perimeter hardened this week without a major new crypto law.

The SEC’s focus moved toward vaults, lending strategies and managerial control. Commissioner Peirce’s statement was not binding rulemaking, but it made the analytical direction clear: putting an investment or lending process inside a smart contract does not remove federal securities-law questions.

CLARITY remained unfinished. The Senate Banking Committee had already advanced the bill, but the official floor record showed no vote through July 27. Ethics language added another contested issue to a negotiation already covering agency jurisdiction, DeFi, stablecoin rewards and customer protection.

FINRA moved faster than Congress. Its information request gave the regulator a firm-by-firm inventory of direct crypto access, affiliate models, third-party custody and planned activity. That data can shape future supervision before the statutory market-structure framework is complete.

Europe is operating on a different timetable. ESMA’s MiCA register now provides a regularly updated authorization and non-compliance record. The Nexo structure shows what this means in practice: one interface, regulated custody and execution partners, and separate lending and yield products outside the authorizations cited for other services.

The UK has gone further in implementation planning. Its gateway opens in September, closes in February and leads toward an October 2027 regime. Firms know when to apply and what happens if they apply late or not at all.

OFAC supplied the final warning. Regulatory openness and sanctions enforcement can advance at the same time. Legal crypto activity is gaining clearer routes into financial markets. Networks tied to illicit finance are being mapped across exchanges, wallets, affiliates and settlement providers.

The winning compliance model will not rely on a license headline. It will show, service by service, who controls the product, who holds the assets, who executes the transaction and which regulator stands behind each activity.

Methodology

https://bitbullnews.com/wp-content/uploads/2026/06/BitBullNews_Crypto_Policy_Regulation_Watch_Methodology.pdf