Skip to content
Blueprints / BP-2 · Banks & credit institutions

One Licence, Activated Bank by Bank Across the Network

If you are the central institution for a network of independent banks, you can license and build crypto trading once, then switch it on bank by bank inside the app those banks already ship - and at network scale the value builds from that repeatable per-bank activation, run for every member bank.

Maturity
Proven
Model
Central institution
Proven stack
Boerse Stuttgart Digital · EUWAX · Atruvia · dwpbank
Last verified
August 2026

Reviewed by Rado Patus, Offer Owner at Protofire

Trusted across 60+ networks and 95+ protocols
1 of 3

of the three network shapes has gone live - DZ Bank's, running inside the group banking app since January 2026 (as at 13 August 2026).

Building the platform centrally is the straightforward half. Every member bank still has to switch it on in its own name, so progress shows up as banks activated per month rather than as a launch date.

01. The opportunity

A network of legally independent banks shares a central institution, a group IT provider and one banking app. Each member bank is small enough that obtaining a crypto-asset authorisation on its own would be disproportionate, yet in aggregate the network is one of the largest retail distribution channels in its market. The central institution can hold the authorisation and run the product once, then switch it on inside the app each member bank already ships to its customers.

This is no longer theoretical. A German co-operative central institution received its authorisation at the end of December 2025 and had the product live inside the group's banking app in January 2026; a second group has announced the same shape for its savings-bank network for 2026. Between them the public reporting describes tens of millions of retail customers reachable through channels that already exist, which is why the recurring value sits in the per-bank activation done for every member bank.

02. The regulatory position

There are two regulatory layers. The central institution needs its own MiCA authorisation or an Art. 60 credit-institution notification. Each member bank then needs its own regulatory step before it can switch the product on - in Germany, its own MiCAR notification to BaFin - so the rollout is decentralised by construction even while the technology is centralised. On top of that sit the EBA outsourcing guidelines and DORA Arts. 28-30 for ICT third-party arrangements, since the central institution becomes a critical provider to many supervised entities at once, plus the recast Transfer of Funds Regulation.

03. Who's already done this

Market references, not our clients
DZ Bank
Central institution for the German co-operative network; MiCAR authorisation from BaFin, late December 2025 · Live 13 Jan 2026

meinKrypto, live inside the existing VR Banking App and operated centrally by DZ Bank, with Boerse Stuttgart Digital custody, EUWAX execution and infrastructure built by Atruvia. The pilot began with six banks. The only fully live instance located.

04. Does this fit you?

  • Yes if you are a central institution, group IT provider or shared processor serving legally independent member banks, you hold or can obtain your own crypto-asset authorisation, and the group's app is already where those customers bank.
  • Not if you are a single bank with no network behind you - the product is the same but the economics are not, and a different blueprint fits. Not if your members are branches rather than separate legal entities: with no per-member regulatory step, the factory this pattern sells does not exist.

05. Where the delivery risk actually sits

The build is centralised, but the rollout cannot be. Each member bank needs its own regulatory step before it can switch on - in the German case, its own notification to BaFin - and each decides on its own strategy, risk assessment and timetable. The network cannot be activated centrally, so a headline such as "71% of banks interested" is not a count of banks live. Closing the gap between those two numbers is an administrative programme run once per bank, and it is where the delivery effort concentrates rather than in the technology.

06. The stack, layer by layer

Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.

Yours

The channel, the customers and the member-bank relationships

The retail channel and customer base in an app they already use, the core banking relationship and group IT provider, the outsourcing framework the member banks already consume, and the governance forums that actually reach them. None of this is rentable and it is the reason the pattern works at all.

Rented

Custody and execution at the regulated edges

Crypto custody under the provider's own authorisation, plus trade execution and market access. No app, no core banking, no member-bank relationship and no licence for the group, by design - the two rented edges are narrow and everything between them stays inside the network.

Boerse Stuttgart DigitalEUWAXAtruviaTanganyTradias
Ours

The activation factory (built and operated by Protofire)

The activation pipeline built as a system with per-bank state and a named owner per stage; the integration seam to the app and the providers with position reconciliation against central custody; per-member DORA register and outsourcing evidence generated rather than assembled; and fan-out incident response that reaches every activated bank.

Yours, never rentableRented from a named vendorBuilt and run by Protofire

07. Why this stack

  • The central institution is the licensed party, so the member banks do not each have to become a crypto firm. Each one switches on a finished product rather than running its own build.
  • The module lives in the app the customer already has. No second app, no separate brand, no re-acquisition of a customer the bank already owns.
  • The regulated edges are rented from specialists. Custody and execution sit outside the group, which keeps the build inside the group's existing IT relationship.
  • The per-bank rollout is the real deliverable. Contracts, pricing, staff training, disclosures, the per-bank regulatory filing and the go-live runbook get executed once for every member bank. No vendor packages that as a product, and at network scale it is what determines whether the business case actually lands.

Request the full blueprint

This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.

What is inside
  • The regulatory position, stated article by article
  • Proven options at each layer, with the vendors that hold up
  • The risk table with a named owner for each risk
  • The division of labour: what is rented, built, and operated
  • The third-party-risk pack a DORA governance function can lift
  • The delivery path, step by step, with the monitoring and incident model

FAQ

What authorisations are needed for a central institution to roll crypto out across its member banks?

The One Licence, Hundreds of Member Banks pattern has two regulatory layers. The central institution needs its own MiCA authorisation or Art. 60 credit-institution notification, and then each member bank needs its own regulatory step before activation, which in Germany is its own MiCAR notification to BaFin. On top sit the EBA outsourcing guidelines and DORA Arts. 28-30, because the central institution becomes a critical ICT provider to hundreds of supervised entities at once, plus the recast Transfer of Funds Regulation.

Who already runs the central-institution crypto rollout across independent banks?

DZ Bank, the central institution for the German co-operative network, received its MiCAR authorisation from BaFin in late December 2025 and went live on 13 January 2026 with meinKrypto inside the existing VR Banking App, operated centrally. Custody is by Boerse Stuttgart Digital, execution by EUWAX, and the infrastructure was built with Atruvia. The pilot began with six banks, and it is the only fully live instance located for this pattern.

What does the central institution build itself versus rent in this pattern?

The central institution keeps the retail channel and customer base, the member-bank relationships, the core banking and group IT provider, the outsourcing framework and the governance forums, none of which is rentable. It rents only the two regulated edges: crypto custody under the provider's own authorisation and trade execution, from vendors such as Boerse Stuttgart Digital, EUWAX, Atruvia, Tangany or Tradias. What it builds is the activation factory, a pipeline with per-bank state and a named owner per stage, plus per-member DORA and outsourcing evidence and fan-out incident response.

Already evaluating this for your institution?

When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.

Run this pattern in production, or tried to and stopped? .

Related readingBank crypto trading & custodyCrypto custody approachesEnterprise blockchain engineering

Protofire 2026. All rights reserved

Message us on Telegram