ISO/IEC 27001:2022, ISO 27001, certifications, security, compliance P2P.org Achieves ISO/IEC 27001:2022 Certification

<h2 id="p2porgs-security-compliance-certifications">P2P.org's Security Compliance Certifications</h2><p><br>P2P.org is now certified to <a href="https://www.bsigroup.com/en-AE/products-and-services/standards/iso-iec-27001-information-security-management-system/?ref=p2p.org">ISO/IEC 27001:2022</a>, the international standard for information security management systems. The certification, audited and issued by the <a href="https://www.bsigroup.com/en-US/?ref=p2p.org">BSI Group</a> (certificate IS 845360), covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions across operations at P2P.org's Cayman-registered parent entity (P2P Staking - ISMS CF) and its Limassol, Cyprus location. It is valid through 3 August 2029, subject to annual surveillance audits.</p><p>This latest certification adds to a growing set of independently verified security and compliance credentials at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>, including its existing <a href="https://p2p.org/economy/p2p-org-achieves-soc-2-type-ii-certification/">SOC 2 Type II attestation,</a> <a href="https://www.linkedin.com/posts/blockchain-security-standards-council_blockchainsecurity-cybersecurity-blockchain-activity-7490785453969833984-wARU?utm_source=social_share_send&utm_medium=member_desktop_web&rcm=ACoAAACZFM4BKAvTYfki7_XDYioeT_mkicu9mbQ">membership in the Blockchain Security Standards Council</a> (BSSC), and its work with <a href="https://p2p.org/economy/p2p-org-sumsub-risk-intolerant-sentinel-compliance/">SumSub Sentinel</a> on transaction monitoring and compliance screening.</p><h2 id="key-takeaways">Key Takeaways<br></h2><p>⟡ Institutions evaluating staking and digital asset infrastructure providers can use this combination of credentials- SOC 2 Type II, ISO/IEC 27001:2022, BSSC membership, and SumSub Sentinel- to reduce the diligence burden typically required before deploying capital with a new validator operator.</p><p>⟡ ISO/IEC 27001:2022 requires ongoing surveillance audits to remain valid, so the certification reflects a sustained security discipline rather than a point-in-time assessment.</p><p>⟡ The certification's scope reaches beyond technical infrastructure into the operational functions that shape the day-to-day client relationship, which is often the layer institutions scrutinize most in vendor risk reviews.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">🗣️</div><div class="kg-callout-text">"ISO 27001 certification is an important milestone for us, but what matters more is what sits behind it: how we identify risk, how we respond when things go wrong, and how we keep improving. For our institutional clients, this provides independent assurance that security at P2P.org is not a point-in-time exercise, but a discipline embedded in how we operate."<br><br><b><strong style="white-space: pre-wrap;">- Sheetal Joseph, Chief Information Security Officer, P2P.org</strong></b></div></div><h2 id="what-isoiec-270012022-certification-means-for-p2porg">What ISO/IEC 27001:2022 Certification Means for P2P.org</h2><p>ISO/IEC 27001:2022 requires organizations to build, document, and continuously improve a formal information security management system, verified through an independent audit and ongoing surveillance reviews. For institutions evaluating staking and digital asset infrastructure providers, the certification offers evidence of operational maturity that is otherwise difficult to verify externally, covering incident response, access controls, and security governance to the standard expected of regulated financial infrastructure.</p><p>An ISMS, or Information Security Management System, is the formal framework an organization uses to manage information security risk: the policies, controls, and processes that govern how data and systems are protected, monitored, and improved over time. ISO/IEC 27001:2022 is the internationally recognized standard for building and certifying one.</p><h2 id="what-the-isoiec-270012022-certification-scope-covers">What the ISO/IEC 27001:2022 Certification Scope Covers</h2><p>The certification's scope spans the operational functions that touch client relationships directly, including customer support, business development, product management, and engineering, alongside the technical infrastructure functions of data management, lab, and validation. It applies company-wide at P2P.org, reflecting controls maintained consistently across its global footprint.</p><h2 id="how-isoiec-270012022-complements-soc-2-type-ii">How ISO/IEC 27001:2022 Complements SOC 2 Type II</h2><p>ISO/IEC 27001:2022 certification sits alongside P2P.org's existing SOC 2 Type II attestation. Where SOC 2 Type II evaluates the operating effectiveness of security controls over a sustained period, ISO/IEC 27001:2022 verifies the management system that governs those controls. Institutions increasingly request both frameworks as part of vendor risk assessments, and holding both reduces the burden on institutional compliance teams conducting that review.</p><p>P2P.org operates non-custodial staking infrastructure across 35+ proof-of-stake networks, and client assets always remain under institutional control.</p><h2 id="frequently-asked-questions-faq">Frequently Asked Questions (FAQ)</h2><h3 id="what-is-isoiec-270012022"><br>What is ISO/IEC 27001:2022?</h3><p>ISO/IEC 27001:2022 is the current version of the international standard for information security management systems, jointly developed by the International Organization for Standardization and the International Electrotechnical Commission. It requires organizations to build and continuously improve a formal information security management system and to pass an independent audit confirming compliance.</p><h3 id="what-does-p2porgs-isoiec-270012022-certification-cover">What does P2P.org's ISO/IEC 27001:2022 certification cover?</h3><p>The certification covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions, spanning P2P.org's blockchain token staking and white-label blockchain node operations across its Cayman Islands and Cyprus entities.</p><h3 id="how-is-isoiec-270012022-different-from-soc-2-type-ii">How is ISO/IEC 27001:2022 different from SOC 2 Type II?</h3><p>SOC 2 Type II evaluates whether an organization's security controls operated effectively over a sustained review period. ISO/IEC 27001:2022 certifies the management system that governs those controls on an ongoing basis and is verified through periodic surveillance audits. Institutions often request both as part of vendor risk assessments.</p><h3 id="how-long-is-p2porgs-isoiec-270012022-certification-valid">How long is P2P.org's ISO/IEC 27001:2022 certification valid?</h3><p>The certification is valid through August 2029, subject to ongoing surveillance audits conducted by BSI to confirm the information security management system continues to meet the standard.</p><h3 id="does-this-certification-affect-how-p2porg-handles-client-assets">Does this certification affect how P2P.org handles client assets?</h3><p>No. P2P.org operates non-custodial staking infrastructure, meaning client assets remain under the client's own control throughout. ISO/IEC 27001:2022 certification applies to the way P2P.org manages information security across its operations and systems.</p><hr><p><strong>About P2P.org</strong></p><p>Founded in 2018, P2P.org helps institutional capital protect digital asset yield across non-custodial staking infrastructure and curated DeFi strategies. With over $10B in assets secured and operating on 35+ proof-of-stake networks, P2P.org maintains a zero-slashing-incident track record, is trusted by over 190 institutional clients and is SOC 2 Type II attested and ISO/IEC 27001:2022 certified. To explore how P2P.org can support your institution's staking or DeFi infrastructure needs, <a href="https://p2p.org/contact?ref=p2p.org">get in touch with our team</a>.</p><hr><p><strong>Disclaimer</strong></p><p>This material is provided for informational purposes only and does not constitute investment, financial, legal, or tax advice. <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> accepts no liability for any actions taken based on it. Latency and performance figures referenced are estimates based on internal benchmarks and may vary depending on network conditions, geography, and client infrastructure. Past performance is not indicative of future results.</p>

Fito Benitez

from p2p validator

legal layer, regulation, News, compliance, legislation Legal Layer: Institutional Staking & DeFi Regulatory Update [July 2026]

<p>Legal Layer is P2P.org's monthly regulatory intelligence series for custodians, ETF issuers, treasury teams, staking product managers, and validator risk committees navigating the intersection of institutional finance, proof-of-stake infrastructure, and on-chain capital markets. Each edition covers the regulatory developments, legislative updates, and policy signals that matter most for institutions building or evaluating staking and DeFi strategies.</p><p>Previously in the series: <a href="https://p2p.org/economy/legal-layer-institutional-staking-defi-regulatory-update-june-2026/">Legal Layer: Institutional Staking &amp; DeFi Regulatory Update — June 2026</a></p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">🗞️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Subscribe to our newsletter</strong></b> at the bottom of this page to receive a monthly summary of the latest staking and DeFi regulatory developments, curated for institutional participants.</div></div><hr><h2 id="quick-learnings-for-busy-readers">Quick Learnings for Busy Readers</h2><p>Short on time? Here are the key takeaways. For the full analysis, continue reading below.</p><ul><li>CLARITY Act missed its July 4 political target date and is now racing against the Senate's shrinking legislative window before the August recess. With August 7 widely viewed as the final practical pre-recess date for Senate action, the bill's 2026 prospects have become increasingly uncertain.</li><li>MiCA full enforcement began July 1, 2026. Approximately 80% of the 1,200-plus pre-MiCA registered entities failed to obtain CASP authorization. Major platforms including Binance, MEXC, Bybit, and KuCoin exited the EU market or restricted services, while licensed platforms including Kraken, OKX Europe, and Bitstamp absorbed the consolidating liquidity.</li><li>The GENIUS Act rulemaking deadline passed on July 18, with no coordinated set of final rules published by the federal agencies required to act. Key comment periods run into August, pushing the Act's effective date toward January 18, 2027 at the earliest.</li><li>Japan's parliament approved landmark legislation on July 15 reclassifying approximately 105 crypto assets, including Bitcoin, Ethereum, and XRP as financial instruments under the Financial Instruments and Exchange Act, paving the way for spot Bitcoin ETFs and a flat 20% capital gains tax effective January 2028.</li><li>Brazil's Travel Rule framework entered into force on February 2, 2026, with mandatory domestic compliance beginning February 2, 2027 and cross-border requirements following in February 2028. Combined with the Central Bank's stablecoin framework already in effect, Brazil now operates the most formally regulated crypto infrastructure in Latin America, drawing compliance scrutiny on multi-jurisdictional staking and DeFi programs that use stablecoin collateral across the region.</li></ul><h2 id="what-does-july-2026s-regulation-news-mean-for-institutions-building-staking-and-defi-programs">What does July 2026's regulation news mean for institutions building staking and DeFi programs?</h2><p>In the United States, the CLARITY Act has entered its most perilous legislative stretch since committee passage, with Senate leadership acknowledging the bill may miss the August recess while the GENIUS Act rulemaking deadline passed without final rules, pushing implementation toward 2027. In Europe, MiCA's hard enforcement began on July 1, consolidating the EU crypto market dramatically overnight and establishing a new counterparty risk baseline for institutional staking and custody stacks. In Asia, Japan passed the most consequential crypto legislation in its history, reclassifying digital assets as financial instruments and opening a clear path to regulated ETF products and materially lower tax rates. And in Latin America, Brazil's stacking of Travel Rule implementation onto its existing stablecoin framework is creating the most complex multi-layer compliance environment for institutional on-chain programs in the region.</p><h2 id="1-clarity-act-races-final-pre-recess-deadline-as-senate-leadership-signals-possible-slip">1. CLARITY Act Races Final Pre-Recess Deadline as Senate Leadership Signals Possible Slip</h2><p>Senate Majority Leader John Thune told reporters on July 23 that the CLARITY Act was not expected to find floor time before the August recess, delivering the most significant acknowledgment yet that the bill's pre-recess window may close without a vote. The industry and congressional negotiators working on crypto market structure legislation had focused on August 7 as the hard deadline for pre-recess passage. White House crypto adviser Patrick Witt quickly pushed back, telling CoinDesk he still believes the first week of August carries potential, noting that getting the floor process started before recess could preserve viability in a brief September window, though election politics and competing priorities will be looming.</p><p>As of July 31, Senator Cynthia Lummis confirmed to crypto journalist Eleanor Terrett that Senate leadership is still seeking a floor vote on the CLARITY Act before recess. Lummis acknowledged that lawmakers have one more week in Washington and that multiple competing priorities including nominations, a continuing resolution, and sanctions votes on Iran and Russia-Ukraine are fighting for the same floor time. She noted that Senate Majority Leader Thune has kept a place for the CLARITY Act on the agenda for many, many weeks.</p><p>Source: <a href="https://www.coindesk.com/policy/2026/07/23/clarity-act-expected-to-miss-its-window-before-congress-summer-break-leadership-says?ref=p2p.org">CoinDesk</a>, <a href="https://coingape.com/senator-lummis-confirms-clarity-act-senate-floor-vote-next-week-ahead-august-recess/?ref=p2p.org">Coingape</a>, <a href="https://www.techtimes.com/articles/320563/20260715/clarity-act-heads-federal-hall-senate-vote-doubt-after-ethics-impasse.htm?ref=p2p.org">TechTimes</a>, July 2026.</p><h3 id="why-relevant-for-validators-and-the-staking-ecosystem">Why relevant for validators and the staking ecosystem:</h3><ul><li>Thune's acknowledgement that the bill may miss the recess represents a material shift in the legislative probability distribution. A bill that fails to clear the Senate before August 7 faces a fall calendar crowded by midterm election positioning, reducing the probability of 2026 passage below Galaxy Research's earlier estimate, which had already fallen to 50% by late June, even further.</li><li>If the CLARITY Act does not pass in 2026, the legal classification of staking as a non-securities activity under the March 17 SEC-CFTC joint interpretation remains reversible administrative guidance rather than binding statute for at least two more years, preserving the compliance uncertainty that has constrained institutional staking program development.</li><li>The narrowing window has a direct operational implication: institutions that have built compliance timelines assuming 2026 CLARITY Act passage should immediately activate their contingency planning frameworks for a 2027 or later rulemaking scenario.</li></ul><h2 id="2-mica-transitional-period-ends-july-1-raising-the-bar-for-eu-crypto-market-access">2. MiCA Transitional Period Ends July 1, Raising the Bar for EU Crypto Market Access</h2><p>MiCA regulation entered full enforcement on July 1, 2026, with EU law requiring all crypto-asset service providers serving EU clients to hold a full MiCA CASP license or cease operations immediately. Only 17% to 20% of crypto firms secured licenses, triggering what analysts described as a massive market consolidation. Firms that failed to convert their old national VASP registrations into MiCA CASP licenses were expected to guide existing clients through fund withdrawals and account closures. OKX Europe delisted stablecoins including USDT to comply with MiCA's stablecoin provisions. Binance began implementing restrictions on certain services for EU-based clients as regulatory pressure mounted through the first half of 2026.</p><p>MEXC issued an official communication in June 2026 advising EU users to withdraw their funds before July 1. Bybit, KuCoin, <a href="http://gate.io/?ref=p2p.org">Gate.io</a>, Bitget, HTX, BingX, Phemex, CoinEx, and BloFin did not appear on the ESMA interim CASP register as of late June 2026. Their combined EU user base was estimated at over 25 million accounts. The consequences of operating without a license after July 1 range from forced user offboarding and asset freezes to criminal prosecution of exchange directors in some EU member states, including up to two years of imprisonment and a 30,000 euro fine for directors in France.</p><p>Source: <a href="https://cryptobriefing.com/mica-crypto-regulation-eu-enforcement/?ref=p2p.org">CryptoBriefing</a>, <a href="https://hyperdash.com/learn/mica-crypto-exchange-ban-europe-2026?ref=p2p.org">Hyperdash</a>, July 2026.</p><h3 id="why-relevant-for-validators-and-the-staking-ecosystem-1">Why relevant for validators and the staking ecosystem:</h3><ul><li>The exit of Binance, MEXC, Bybit, and KuCoin from EU markets concentrates EU crypto liquidity among a small number of licensed platforms, creating direct counterparty concentration risk for institutional staking programs that rely on these venues for ETH and SOL liquidity management.</li><li>The criminal liability provisions now active across EU member states for unlicensed operation mean that institutional compliance departments must verify CASP authorization not just for primary counterparties but for any downstream service provider in their staking and custody stack operating in EU jurisdictions.</li><li>Restrictions on non-MiCA-compliant stablecoins, including USDT on some EU-regulated platforms, are reshaping the stablecoin collateral mix available to European institutions building DeFi vault strategies and stablecoin yield programs.</li></ul><h2 id="3-genius-act-rule-making-deadline-passes-on-july-18-with-final-rules-still-in-proposed-form">3. GENIUS Act Rule making Deadline Passes on July 18 With Final Rules Still in Proposed Form</h2><p>July 18, 2026 marked the one-year statutory deadline for six U.S. federal agencies to finalize implementing rules for the GENIUS Act, covering a $309.5 billion payment stablecoin market where USDT and USDC together account for approximately $257 billion or 83% of total supply. As of July 16, no coordinated set of final rules was publicly visible across all agencies. Key comment periods for the OCC's AML rules close July 24, the FDIC's compliance framework closes August 4, and a five-agency customer identification rule closes August 21, all after the statutory deadline. The Act's effective date remains the earlier of January 18, 2027, or 120 days after primary federal regulators issue final implementing regulations.</p><p>A joint proposal from five federal agencies, including the Federal Reserve Board, was published on June 22, 2026, with a comment period running to August 21. The July 18 deadline is not a stablecoin shutdown date. The broad restriction on U.S. digital-asset service providers offering non-permitted stablecoins begins July 18, 2028, giving the market a two-year runway from the missed rulemaking deadline. The OCC's proposed rule sets a $5 million minimum capital floor for new stablecoin issuers seeking federal approval, with a three-tier liquidity framework requiring 10% same-day redemption capability.</p><p>Source: <a href="https://stablecoininsider.org/the-genius-act-july-18-rulemaking-deadline-has-arrived-the-rules-are-not-ready/?ref=p2p.org">Stablecoin Insider</a>, <a href="https://www.financemagnates.com/cryptocurrency/regulation/ten-days-to-the-genius-act-deadline-what-the-draft-rules-already-reveal/?ref=p2p.org">Finance Magnates</a>, <a href="https://www.thebrightminded.com/news/genius-act-rulemaking-deadline-the-agencies-opened-a-comment-window-that-closes-a-month-after-it/?ref=p2p.org">The Bright Minded</a>, July 2026.</p><h3 id="why-relevant-for-validators-and-the-staking-ecosystem-2">Why relevant for validators and the staking ecosystem:</h3><ul><li>The missed July 18 statutory deadline pushes the GENIUS Act effective date toward January 18, 2027 at the latest, meaning the stablecoin issuance framework that determines which reserve assets, custody arrangements, and yield structures are compliant will not be final before the end of 2026 at the earliest.</li><li>The no-yield prohibition, which bans permitted payment stablecoin issuers from paying direct interest to holders, is the most commercially significant element of the entire framework. Its finalization directly affects the structural advantage of staking as the primary mechanism through which institutional capital earns protocol-native returns on-chain, as constrained stablecoin yield redirects institutional demand toward proof-of-stake participation.</li><li>The OCC's proposed $5 million capital floor and three-tier liquidity framework, including a 10% same-day redemption requirement, will directly affect how bank-affiliated stablecoin issuers structure their reserve assets. Issuers that hold tokenized Treasury instruments or on-chain yield-bearing assets to meet liquidity tiers will require the proof-of-stake networks settling those instruments to operate at institutional-grade reliability standards.</li></ul><h2 id="4-japan-passes-landmark-fiea-reform-reclassifying-crypto-as-financial-instruments-and-paving-the-way-for-etfs">4. Japan Passes Landmark FIEA Reform, Reclassifying Crypto as Financial Instruments and Paving the Way for ETFs</h2><p>Japan's parliament officially approved legislation moving crypto regulation under the Financial Instruments and Exchange Act on July 15, 2026, paving the way for a 20% separate tax treatment on eligible crypto gains once the law takes effect. The bill cleared the Upper House on July 15 after passing the House of Representatives and the Finance and Banking Committee last month, winning final approval in Japan's National Diet. The reforms transfer oversight of crypto trading from the Payment Services Act to the FIEA, with the Financial Services Agency treating crypto assets as financial products distinct from traditional securities.</p><p>The reform reclassifies approximately 105 tokens, including Bitcoin, Ethereum, and XRP, as financial instruments. The 2026 Tax Reform Outline proposes replacing the current progressive tax rate, which can reach as high as 55%, with a flat 20% rate matching the treatment applied to stocks and bonds, along with a three-year loss carry-forward provision. That tax change is not scheduled to take effect until January 2028, roughly a year after the FIEA framework itself becomes operative in fiscal 2027. Japan's Finance Minister designated 2026 a year for financial reform, with the FSA opening a public consultation on licensing, stablecoin issuance, taxation, and custody, aiming to finalize the framework by the end of 2026.</p><p>Source: <a href="https://www.coindesk.com/policy/2026/07/15/japan-reclassifies-crypto-as-a-financial-asset-paves-way-for-tax-cuts?ref=p2p.org">CoinDesk</a>, <a href="https://www.techtimes.com/articles/320705/20260716/japan-passes-crypto-law-etfs-could-arrive-before-tax-rate-drops-20-percent.htm?ref=p2p.org">TechTimes</a>, July 2026.</p><h3 id="why-relevant-for-validators-and-the-staking-ecosystem-3"><strong>W</strong>hy relevant for validators and the staking ecosystem:</h3><ul><li>The FIEA reclassification of approximately 105 tokens as financial instruments brings Japan's crypto market under the same regulatory perimeter as its securities markets, applying insider-trading prohibitions, disclosure requirements, and investor-protection rules that directly affect how institutional participants in Japan structure staking and DeFi allocation programs.</li><li>The path toward spot Bitcoin and potentially Ethereum ETFs on the Tokyo Stock Exchange, expected in 2027 to 2028, represents a new institutional access channel for Japanese asset managers, pension funds, and insurance companies, creating a multi-year demand driver for validator infrastructure capable of serving regulated product structures in one of Asia's largest institutional capital markets.</li><li>The staking and DeFi income tax treatment remains unchanged at progressive rates potentially reaching 55% until January 2028. Institutions planning Japan-facing staking programs in the 2026 to 2028 window should model the pre-reform tax environment as the operative framework, and time product launches carefully around the tax cliff.</li></ul><h2 id="5-brazil-travel-rule-takes-full-effect-adding-compliance-layer-to-multi-jurisdictional-staking-programs">5. Brazil Travel Rule Takes Full Effect, Adding Compliance Layer to Multi-Jurisdictional Staking Programs</h2><p>Brazil's Travel Rule framework entered into force on February 2, 2026, with mandatory domestic compliance beginning February 2, 2027 and cross-border requirements following in February 2028. The rule applies to firms operating with a substantive Brazilian presence or serving Brazilian clients. Combined with the Central Bank's stablecoin framework that took full effect in early 2026, Brazil now operates the most formally regulated crypto compliance infrastructure in Latin America.</p><p>Brazil receives nearly one-third of all Latin American crypto volume, making it effectively the LATAM market. With $318.8 billion in on-chain volume in 2025, any significant policy development in Brazil carries outsized consequences across the region. Colombia, Peru, Panama, and Uruguay are drafting VASP and AML laws expected between 2025 and 2026, using Brazil's framework as a regional reference point. The outcome of Brazil's stablecoin consultation, specifically whether foreign stablecoins will be restricted in domestic payments, could have a direct impact on the most traded asset class in the region's dominant market.</p><p>Source: <a href="https://gomarkets.com/en/articles/latin-americas-crypto-moment-why-2026-could-be-latams-biggest-year-yet?ref=p2p.org">GoMarkets</a>, <a href="https://hackenproof.com/blog/for-business/crypto-regulations-latin-america-2025-2026?ref=p2p.org">HackenProof</a>, July 2026.</p><h3 id="why-relevant-for-validators-and-the-staking-ecosystem-4">Why relevant for validators and the staking ecosystem:</h3><ul><li>Brazil's Travel Rule framework is now in force, with mandatory domestic compliance beginning February 2027. Institutions with Brazilian client exposure have a defined window to build transaction monitoring and data-sharing architecture before the domestic requirement becomes enforceable.</li><li>The phased timeline gives multi-jurisdictional staking infrastructure providers a structured planning window: domestic compliance architecture must be in place by February 2027, with cross-border data-sharing requirements following in February 2028.</li><li>As Colombia, Peru, and Argentina develop their own licensing frameworks using Brazil as a reference, the compliance infrastructure that validator and staking providers build for Brazil positions them ahead of the broader Latin American regulatory buildout, where institutional staking demand is growing alongside adoption rates that are three times faster than the U.S.</li></ul><h2 id="frequently-asked-questions-faq">Frequently Asked Questions (FAQ)</h2><h3 id="what-does-the-clarity-act-missing-its-pre-recess-deadline-mean-for-institutions-that-have-already-launched-staking-programs">What does the CLARITY Act missing its pre-recess deadline mean for institutions that have already launched staking programs?</h3><p>Existing staking programs are not affected by the bill's failure to pass before the August recess. The March 17 SEC-CFTC joint interpretation, which classified protocol staking as a non-securities activity across all four operational models, remains in effect as the operative compliance framework regardless of whether the CLARITY Act passes. What changes is the durability of that protection: administrative guidance can be rescinded by a future administration, while statute cannot. Institutions with active staking programs should treat the current compliance environment as stable but not permanent, and build their governance documentation to withstand a scenario where the guidance is revisited.</p><h3 id="what-does-mica-full-enforcement-mean-for-institutions-that-use-unlicensed-custody-or-execution-venues-in-their-staking-stacks">What does MiCA full enforcement mean for institutions that use unlicensed custody or execution venues in their staking stacks?</h3><p>After July 1, 2026, any institution using an unlicensed CASP as a custody or execution counterparty for EU-facing staking programs is operating with a live compliance gap. The gap is not theoretical. Criminal liability for directors is now active in multiple EU member states, and forced offboarding procedures at unlicensed platforms can disrupt staking positions held during unbonding periods. Institutions should conduct an immediate audit of every counterparty in their EU-facing staking and custody stack against the ESMA CASP register, and replace any unlicensed provider before their next audit cycle.</p><h3 id="what-does-the-genius-act-rulemaking-deadline-passing-without-final-rules-mean-for-stablecoin-backed-defi-vault-strategies">What does the GENIUS Act rulemaking deadline passing without final rules mean for stablecoin-backed DeFi vault strategies?</h3><p>The July 18 deadline passing without final rules does not change the operational status of existing stablecoin products. The GENIUS Act takes effect on the earlier of January 18, 2027, or 120 days after final rules are published. The broad restriction on non-permitted stablecoins begins July 18, 2028. For institutions running DeFi vault strategies that use stablecoin collateral, the practical implication is that the compliance environment for those strategies will not be fully defined until late 2026 at the earliest. Institutions should monitor the remaining comment periods, particularly the five-agency customer identification rule closing August 21, as these will shape the AML and KYC obligations that apply to stablecoin-backed vault positions.</p><h3 id="what-does-japans-fiea-reclassification-mean-for-institutions-evaluating-ethereum-staking-programs-in-the-asia-pacific-region">What does Japan's FIEA reclassification mean for institutions evaluating Ethereum staking programs in the Asia-Pacific region?</h3><p>Japan's reclassification of approximately 105 tokens, including Ethereum, as financial instruments brings crypto assets under the same investor-protection, disclosure, and insider-trading framework as securities. For institutions evaluating Ethereum staking programs in Japan, this means that the compliance framework governing staking arrangements will increasingly resemble the securities compliance framework rather than the payments compliance framework that applied previously. The 55% progressive tax on staking income remains in effect until January 2028, making the tax efficiency of staking programs in Japan materially lower than in jurisdictions that have adopted flat rates. Institutions should factor this into the economics of Japan-facing staking product timelines.</p><h3 id="why-does-brazils-travel-rule-matter-for-non-brazilian-staking-programs">Why does Brazil's Travel Rule matter for non-Brazilian staking programs?</h3><p>Brazil's Travel Rule framework entered into force on February 2, 2026, with mandatory domestic compliance beginning February 2, 2027 and cross-border requirements following in February 2028. For non-Brazilian staking providers serving Brazilian institutional clients, this means that any transaction flow touching a Brazilian-regulated VASP, including custody transfers related to staking positions, must be structured to support data-sharing obligations. The more significant forward-looking risk is the potential restriction on foreign stablecoins in domestic payments, which could directly affect the stablecoin collateral layer used in DeFi vault strategies targeting Brazilian institutional capital. Providers building multi-jurisdictional staking and DeFi programs should treat Brazil's regulatory trajectory as the leading indicator for LATAM compliance requirements broadly.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">🗞️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Subscribe to our newsletter</strong></b> at the bottom of this page to receive a monthly summary of the latest staking and DeFi regulatory developments, curated for institutional participants.</div></div><hr><p><strong>About </strong><a href="http://p2p.org/?ref=p2p.org"><strong>P2P.org</strong></a></p><p>Founded in 2018, <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> helps institutional capital protect Digital Asset Yield across non-custodial staking infrastructure and curated DeFi strategies. With over $10B in assets secured and operating on 40+ proof-of-stake networks, <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> maintains a zero slashing incident track record, is trusted by over 190 institutional clients and is SOC 2 Type II attested. To explore how <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> can support your institution's staking or DeFi infrastructure needs, <a href="https://p2p.org/contact?ref=p2p.org">get in touch with our team</a>.</p><hr><p><strong>Disclaimer</strong></p><p>This material is provided for informational purposes only and does not constitute investment, financial, legal, or tax advice. <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> accepts no liability for any actions taken based on it. Latency and performance figures referenced are estimates based on internal benchmarks and may vary depending on network conditions, geography, and client infrastructure. Past performance is not indicative of future results.</p>

Fito Benitez

from p2p validator

compliance, certifications P2P.org Earns Sumsub Risk Intolerant Sentinel Recognition: What It Means for Our Partners

<p>P2P Certified | Compliance</p><h2 id="introduction">Introduction</h2><p>Compliance claims are easy to make. In an industry where regulatory expectations are rising faster than most firms realise, the difference between a compliance page and genuine compliance practice is measured not in words but in independent validation.</p><p>At <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>, we have built our customer due diligence (CDD) framework as a living system, one designed for where regulation is heading rather than where it has been. That commitment recently received external recognition from Sumsub in the form of their Risk Intolerant Sentinel designation, a badge awarded to organisations that demonstrate proactive, comprehensive standards across KYC, AML monitoring, fraud prevention and identity verification.</p><p>This post explains what that recognition means, how it was earned, and what it signals to the institutions and regulated businesses that partner with P2P.org.</p><h2 id="key-learnings-for-busy-readers">Key learnings for busy readers</h2><p>If you are short on time, here is what this article covers:</p><p>P2P.org has been awarded the <a href="https://sumsub.com/risk-intolerant/?ref=p2p.org" rel="noreferrer">Sumsub Risk Intolerant Sentinel</a> designation, an independent recognition awarded by a globally trusted compliance and identity verification platform operating across 220+ countries. The designation is not self-reported. It is the result of a third-party assessment of P2P.org's use of Sumsub's verification and monitoring infrastructure across our compliance operations. For institutional partners and regulated businesses, this is a concrete, externally verified signal of the compliance standards they are dealing with when they work with <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>. Our CDD framework was reviewed against current AMLR expectations as a deliberate investment in partnership quality, not as a reactive compliance exercise.</p><h2 id="independent-recognition-in-an-industry-where-it-matters-most">Independent recognition in an industry where it matters most</h2><p>Recognition of compliance standards is only meaningful when it comes from outside the organisation. Anyone can write a compliance page. Third-party validation from a globally recognised authority is a different kind of signal.</p><p><a href="https://sumsub.com/about/?ref=p2p.org" rel="noreferrer">Sumsub</a> is a global compliance and identity verification platform trusted by thousands of regulated businesses across fintech, crypto, traditional financial institutions and digital asset businesses worldwide. Their infrastructure spans KYC, KYB, AML monitoring, transaction screening and fraud prevention across more than 220 countries and territories.</p><p>The Risk Intolerant initiative was created specifically to address what Sumsub describes as a gap in the industry: compliance work is largely invisible until something goes wrong. The project shifts that dynamic by publicly recognising organisations that manage risk proactively, turning otherwise unseen compliance efforts into verifiable, public proof.</p><p>The Sentinel designation is awarded following Sumsub's assessment of a company's KYC, AML, fraud prevention and compliance systems. It goes to organisations whose risk mitigation practices are comprehensive, current and effective. Importantly, it is not a self-reported badge. It requires assessment against Sumsub's global client base and the standards they apply across their entire platform.</p><p><a href="http://p2p.org/?ref=p2p.org">P2P.org</a> has received this designation based on our use of Sumsub's verification and monitoring infrastructure across our compliance operations. For our partners, it means one thing practically: your counterpart at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> has been independently evaluated by a recognised global compliance authority.</p><p>You can read more about the Risk Intolerant initiative directly at <a href="https://sumsub.com/risk-intolerant/?ref=p2p.org">sumsub.com/risk-intolerant</a>.</p><h2 id="the-thinking-behind-our-compliance-approach">The thinking behind our compliance approach</h2><p>Compliance is not a static checklist at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>. It is a framework we treat as an ongoing investment in the quality of our partnerships.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://p2p.org/economy/content/images/2026/04/-p2p-org-sumsub-compliance-validation-flow.png" class="kg-image" alt="Diagram showing how P2P.org compliance operations connect through Sumsub's verification platform to the Risk Intolerant Sentinel designation, resulting in independently verified partner trust for institutions and regulated businesses." loading="lazy" width="1600" height="900" srcset="https://p2p.org/economy/content/images/size/w600/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 600w, https://p2p.org/economy/content/images/size/w1000/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 1000w, https://p2p.org/economy/content/images/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 1600w" sizes="(min-width: 720px) 720px"><figcaption><i><em class="italic" style="white-space: pre-wrap;">How </em></i><span style="white-space: pre-wrap;">P2P.org</span><i><em class="italic" style="white-space: pre-wrap;">'s CDD framework and Sumsub's global platform combine to produce independent compliance validation.</em></i></figcaption></figure><p>As the <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> Compliance team put it:</p><blockquote>"Compliance in this industry is moving faster than most firms realise. We made the decision early on to treat our CDD framework as a living system, one that needs to be built for where regulation is going, not where it has been. The AMLR review was not a defensive move. It was a deliberate investment in the quality of the partnerships we want to maintain."</blockquote><p>The EU Anti-Money Laundering Regulation (AMLR) is reshaping expectations for regulated and high-risk sectors across financial services, crypto and digital assets. Rather than waiting to react, <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> reviewed and aligned our CDD processes against AMLR requirements as a deliberate, proactive step.</p><p>The diagram above illustrates how our internal compliance operations connect through Sumsub's platform infrastructure to the independent assessment process, culminating in the Sentinel designation that now represents verified partner trust for the institutions and funds working with us.</p><h2 id="what-the-sentinel-designation-means-in-practice">What the Sentinel designation means in practice</h2><p>The Risk Intolerant project structures recognition across tiers based on assessment results. The Sentinel designation reflects a proactive, best-in-class approach to fraud prevention, AML screening, identity verification and customer onboarding. It is not awarded by request alone. It follows Sumsub's evaluation of how a company's systems are designed, operated and updated.</p><p>For institutions evaluating staking infrastructure providers or digital asset service partners, compliance validation from a recognised global platform provides a layer of due diligence assurance that internal claims cannot offer. When P2P.org's compliance standards are assessed by the same platform that serves thousands of regulated businesses globally, the result carries a weight that self-certification does not.</p><p>This is particularly relevant given the direction regulatory frameworks are moving. FATF's 2025 guidance and the EU's broader AML package are pushing regulated industries toward a unified, risk-based approach where continuous monitoring and adaptive controls are the expectation, not the exception. P2P.org's investment in a living CDD framework, validated independently through Sumsub, places us ahead of that curve rather than behind it.</p><h2 id="why-independent-validation-matters-for-institutional-partners">Why independent validation matters for institutional partners</h2><p>Institutions choosing infrastructure partners in the staking and digital asset space carry compliance obligations of their own. They are not just choosing a technology provider. They are choosing a counterparty whose compliance posture either supports or complicates their own regulatory standing.</p><p>A self-reported compliance page provides limited assurance. What institutions need is a signal they can actually rely on: an assessment conducted by a third party with the global reach and technical authority to evaluate compliance infrastructure objectively.</p><p>The Sumsub Risk Intolerant Sentinel designation provides exactly that. It is a third-party determination, applied consistently across a global client base, that P2P.org's approach to risk management meets the standard Sumsub sets for comprehensive, proactive compliance.</p><p>When you partner with <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> for staking infrastructure across our 40+ supported networks, you are working with a business that has been independently evaluated, not just one that has declared its own compliance. That distinction matters increasingly in the regulatory environment we are all operating in.</p><h2 id="p2porg-compliance-as-part-of-a-broader-standard">P2P.org compliance as part of a broader standard</h2><p>The Sumsub recognition sits alongside P2P.org's existing compliance achievements. We achieved SOC 2 Type II certification in 2025, confirming that our security and operational frameworks meet the standards institutional clients require. Our infrastructure supports more than $10 billion in assets under management across 40+ blockchain networks, with a zero-slashing incident record and 99.9% uptime across all validator infrastructure.</p><p>Compliance and operational excellence are not separate tracks at P2P.org. They are part of the same commitment to being a partner that regulated institutions can rely on.</p><p>If you would like to explore our institutional staking products and understand how our compliance framework supports the businesses we work with, visit <a href="https://www.p2p.org/products/staking-as-a-business?ref=p2p.org">P2P.org Staking-as-a-Business</a>.</p><p>For more compliance coverage and updates from the P2P Certified series, explore the <a href="https://www.p2p.org/economy/?ref=p2p.org">P2P.org blog</a>.</p><h2 id="key-takeaways">Key takeaways</h2><p>P2P.org has received the Sumsub Risk Intolerant Sentinel designation following an independent third-party assessment of our compliance and verification infrastructure. The designation reflects a proactive, comprehensive approach to KYC, AML, fraud prevention and CDD, aligned with where regulation is heading under AMLR and broader global AML frameworks. For institutional partners and regulated businesses, this is a verifiable external signal of the compliance standards P2P.org operates to, not a self-declared claim. Our CDD framework is built as a living system, designed to evolve ahead of regulatory expectations rather than react to them.</p><h2 id="frequently-asked-questions-faqs">Frequently Asked Questions (FAQs)</h2><h3 id="what-is-the-sumsub-risk-intolerant-sentinel-designation"><br><strong>What is the Sumsub Risk Intolerant Sentinel designation?</strong> </h3><p>The Risk Intolerant Sentinel is a recognition awarded by Sumsub as part of their Risk Intolerant initiative, which publicly identifies companies that demonstrate comprehensive, proactive standards in KYC, AML, fraud prevention and identity verification. It is based on a third-party assessment of a company's compliance systems, not a self-reported application.</p><h3 id="is-this-the-highest-designation-in-the-risk-intolerant-programme"><strong>Is this the highest designation in the Risk Intolerant programme?</strong> </h3><p>The Risk Intolerant project has three tiers: Vanguard, Sentinel and Titan. The Sentinel designation is awarded to companies that demonstrate a proactive, best-in-class approach to compliance and fraud prevention, going beyond baseline requirements.</p><h3 id="what-is-sumsub-and-why-does-its-recognition-matter"><strong>What is Sumsub, and why does its recognition matter?</strong> </h3><p>Sumsub is a global compliance and identity verification platform operating in 220+ countries, trusted by thousands of regulated businesses, including traditional financial institutions, fintech companies and digital asset businesses. Their assessment reflects global compliance benchmarks, which is why their recognition carries weight beyond the digital asset sector.</p><h3 id="what-is-the-amlr-and-why-did-p2porg-review-its-cdd-framework-against-it"><strong>What is the AMLR, and why did P2P.org review its CDD framework against it?</strong> </h3><p>The EU Anti-Money Laundering Regulation (AMLR) is reshaping compliance expectations across financial services and digital assets. P2P.org reviewed and aligned our CDD framework against AMLR as a proactive investment in compliance quality and partnership standards, not as a reactive measure to regulatory pressure.</p><h3 id="does-p2porg-hold-any-other-compliance-certifications"><strong>Does P2P.org hold any other compliance certifications?</strong> </h3><p>Yes. P2P.org achieved SOC 2 Type II certification in 2025, confirming that our security and operational control frameworks meet institutional standards. The Sumsub Sentinel designation adds an independent layer of compliance-specific validation to that foundation.</p><h3 id="how-does-this-affect-institutional-partners-working-with-p2porg"><strong>How does this affect institutional partners working with P2P.org?</strong> </h3><p>Institutional partners carry their own compliance obligations when selecting counterparties. The Sumsub Sentinel designation gives them an independently verified signal of P2P.org's compliance standards, one assessed by a globally recognised authority rather than declared internally.</p>

Fito Benitez

from p2p validator