Matter Labs Open-Sources Prividium as Bundesbank Tests It
Matter Labs, the developer behind ZKsync, has open-sourced the core permissioning engine of Prividium, its distributed ledger technology platform built for regulated financial institutions. The move, announced on 8 September 2026, comes with a significant signal of institutional confidence: Deutsche Bundesbank, Germany's central bank, is the first institution to test and deploy the platform within its own infrastructure. For accounting firms, CFOs, and auditors working with digital asset systems, this development reshapes how permissioned blockchain infrastructure can be evaluated, governed, and audited going forward.
What Prividium Is and What Changed
Prividium is a permissioned DLT platform designed specifically for financial institutions. It uses zero-knowledge proofs to verify the correctness of transactions while keeping smart contract and token data within the operator's own environment. That privacy-by-design approach is precisely what makes it attractive to regulated entities that cannot expose client or settlement data to external parties.
Prior to this announcement, several components of Prividium were already available as open-source code. These included the OS core, the Atlas sequencer, the Airbender prover, interoperability contracts, and the block explorer and monitoring stack. What was not open-sourced until now was the core permissioning engine, the component that controls which participants can join the network, what they can do, and how governance rules are enforced.
Why the Permissioning Engine Is the Critical Component
The permissioning engine is the gatekeeper of a private chain. It defines who can transact, who can validate, and under what conditions access can be revoked. For any regulated institution, that logic is not just operationally important; it is the layer that must align with licensing conditions, AML obligations, and internal governance frameworks. Keeping that layer as a closed, vendor-controlled black box was, according to Matter Labs CEO Alex Gluchowski, the single most consistent barrier to adoption among regulated institutions.
Gluchowski said the decision to open-source the engine followed direct feedback from those institutions: "The most consistent feedback from regulated institutions was that a commercial-only core meant a single-vendor dependency they could not accept in critical infrastructure. The ability to run, inspect and modify the code independently is a precondition for adoption, and open-sourcing the core removes that barrier structurally."
What Remains Commercial
The permissioning engine is planned to run as a standalone component. An institution can operate a permissioned chain from entirely public code in its own environment without a commercial agreement with Matter Labs. However, administration tools and integrations into existing institutional systems will remain commercial products. The open-sourcing of the core does not alter ZKsync's own architecture or role, Gluchowski confirmed.
Bundesbank as First Adopter: Why It Matters
The Deutsche Bundesbank is not a minor proof-of-concept partner. As one of the founding members of the Eurosystem and a key participant in Europe's TARGET payment infrastructure, the Bundesbank carries enormous institutional weight. Its decision to test and deploy Prividium's open-source permissioning engine in its own infrastructure is arguably the most consequential part of this announcement.
The Eurosystem Context
The Bundesbank's involvement does not exist in isolation. The Eurosystem, the central banking system of the eurozone, is currently developing Pontes, a system designed to connect market DLT platforms with Europe's TARGET payment services. According to the European Central Bank and the Bundesbank, an initial launch of Pontes was planned for the third quarter of 2026. The Prividium testing sits squarely within this broader push to connect tokenized asset platforms with central bank settlement infrastructure.
Gluchowski described the Bundesbank's participation in strong terms: "A central bank running public code is the clearest possible signal of where this is going. Every central bank and regulated institution on earth can now inspect and reproduce exactly what the Bundesbank is testing." Matter Labs said it will continue collaborating with the Bundesbank on the platform's design and testing going forward.
Accounting and Audit Implications for Firms and CFOs
For accounting firms advising financial institutions on digital asset infrastructure, and for CFOs evaluating permissioned blockchain adoption, this development introduces several concrete considerations worth examining now rather than later.
Auditability of the Ledger Layer
One of the persistent challenges in auditing digital asset systems has been the opacity of the underlying ledger infrastructure. When a permissioning engine is proprietary and vendor-controlled, an auditor has no reliable way to independently verify that the governance rules encoded in the system match the institution's stated policies. Open-sourcing the engine changes that: an external auditor or internal controls team can now inspect the actual code, confirm what the permissioning logic does, and assess whether it aligns with the institution's AML and KYC obligations.
This is not a trivial point. Under the EU's Markets in Crypto-Assets Regulation (MiCA) and the related technical standards being developed by the European Banking Authority and ESMA, crypto-asset service providers and financial institutions operating DLT infrastructure face increasingly specific requirements around governance, access controls, and operational resilience. The ability to reference and cite a publicly auditable codebase in a compliance submission is a meaningful step forward compared to relying on vendor assurances.
Vendor Concentration Risk in Financial Statements
The open-sourcing decision speaks directly to a risk category that auditors and CFOs should already be tracking: vendor concentration risk in critical infrastructure. When a financial institution's settlement or tokenization layer depends entirely on a single vendor's proprietary code, that dependency creates a disclosure obligation under several frameworks. IFRS 7 requires disclosure of significant concentrations of risk; DORA (the EU's Digital Operational Resilience Act), which applies from January 2025, imposes contractual and oversight requirements on critical ICT third-party dependencies.
By enabling institutions to run the permissioning engine independently, Matter Labs is structurally reducing the third-party dependency that would otherwise trigger DORA's enhanced oversight requirements for critical ICT providers. For a CFO or risk officer, that has direct implications for how the institution describes its ICT risk profile in regulatory filings and how it structures its vendor contracts going forward.
How Crypto Accounting Software Intersects With Permissioned DLT
Firms using crypto accounting software to track digital asset positions, generate audit trails, and produce regulatory reports need to understand how permissioned DLT infrastructure like Prividium interacts with their existing systems. Unlike public blockchains where transaction data is openly accessible, permissioned chains control who can read ledger state. That means the data feeds flowing into any accounting or reporting tool depend on the permissioning layer being correctly configured to grant the relevant access.
With the Prividium permissioning engine now public, firms evaluating whether to connect their accounting workflows to a Prividium-based network can inspect exactly what access grants are possible, how they are structured, and what the audit log of those grants looks like. That transparency is directly relevant to the quality and reliability of the accounting data those systems will produce. Separately, while administration and integration tooling remains commercial, any firm standardising on open-source digital asset accounting software infrastructure should factor the boundary between the open core and the commercial layer into its integration planning.
Broader Market Structure Signals
Central bank digital currency and tokenized settlement projects across Europe have accelerated noticeably in 2025 and 2026. The Eurosystem's Pontes initiative, the ECB's continued exploration of a wholesale CBDC, and the Bundesbank's active participation in multiple DLT pilots all point toward a future where the settlement layer for regulated financial markets is a permissioned blockchain, not a legacy RTGS system or an adaptation of public chain infrastructure.
The Open-Source Model as an Industry Standard
Gluchowski drew an explicit parallel with the AI industry: "What open weights did for AI, giving serious institutions the option to hold the technology in their own hands, open source is now doing for financial infrastructure." The comparison is apt. In AI, open-weight models allowed enterprises to self-host and independently validate model behaviour rather than accept a vendor's claims about outputs. In financial DLT, open-sourcing the permissioning engine allows institutions to independently validate the governance logic that underpins their settlement infrastructure.
If the Bundesbank's adoption proves successful, other central banks and regulated institutions in the EU and beyond are likely to follow, not least because MiCA and DORA together create strong regulatory incentives for institutions to be able to demonstrate control over their critical digital infrastructure. The open-source model directly answers that requirement in a way a proprietary stack cannot.
Practical Next Steps for Accounting and Finance Teams
Finance and compliance teams at institutions considering permissioned DLT adoption, or those already in testing phases, should take several concrete steps in light of this development.
Review ICT Third-Party Risk Registers
Under DORA, institutions must maintain registers of their ICT third-party service providers and classify critical dependencies. If Prividium is or becomes part of a firm's settlement or tokenization stack, the open-sourcing of the permissioning engine changes the risk classification. Update the register to reflect the distinction between the open-source core (which the institution can now run independently) and the commercial administration layer (which remains a vendor dependency).
Engage Auditors Early on Ledger Governance
External auditors who have not yet developed a methodology for reviewing permissioned DLT governance should begin that work now. The availability of public code means there is no longer a barrier to performing a substantive technical review of the permissioning logic as part of an IT general controls assessment. Firms should brief their audit committees accordingly and include the open-source codebase reference in any future audit scope discussions.
Monitor the Pontes Timeline
If Pontes launches on schedule, it will create a live connection between tokenized market platforms and TARGET settlement. Firms with EU settlement exposure should track the Bundesbank and ECB announcements closely, as the accounting treatment of positions settled through that infrastructure may differ from current OTC or CSD-based settlement in ways that require a policy update.
Source: The Block
Frequently Asked Questions
What is the Prividium permissioning engine?
It is the core software component of Matter Labs' Prividium DLT platform that controls who can join a permissioned blockchain network, what actions participants can take, and how governance rules are enforced. Matter Labs open-sourced this component on 8 September 2026, meaning any institution can now run, inspect, and modify it without a commercial agreement.
Why is the Bundesbank testing Prividium?
The Bundesbank is actively involved in several Eurosystem DLT infrastructure projects, including the development of Pontes, a system designed to connect market DLT platforms with Europe's TARGET payment services. Testing Prividium aligns with that broader programme of evaluating permissioned blockchain infrastructure for central bank settlement use cases.
What does this mean for DORA compliance?
DORA requires EU financial institutions to manage and document ICT third-party dependencies, including critical ones. Because the Prividium permissioning engine can now be run independently from public code, it reduces the institution's dependency on a single vendor for that component. Firms should update their ICT third-party risk registers to reflect the changed dependency profile and review contractual requirements accordingly.
How does open-source permissioning affect a digital asset audit?
It significantly improves auditability. When the permissioning logic is proprietary, auditors must rely on vendor attestations. With public code, an auditor can directly inspect the governance rules encoded in the system, verify they match the institution's stated policies, and include that review in an IT general controls assessment. This is relevant under both ISA 315 and MiCA's governance requirements.
Does this announcement affect how firms should select crypto accounting software?
Indirectly, yes. Firms evaluating digital asset accounting software for use alongside permissioned DLT infrastructure should understand that data feeds from a Prividium-based network depend on correct permissioning configuration. The public availability of the engine's code means integration architects and compliance teams can now verify exactly what read-access grants are possible before committing to an accounting workflow design that depends on that data.
