How to Comply with CASP Requirements Under MiCA

The EU’s Markets in Crypto-Assets Regulation (MiCA) introduces a unified licensing regime for crypto businesses operating in Europe. If your company provides one or more regulated crypto-asset services, you’ll need to become an authorized Crypto-Asset Service Provider (CASP).

But what exactly does compliance involve? This article walks through the core regulatory requirements for CASPs under MiCA — from licensing and governance to AML, security, and client protection.

Step 1: Understand Which Services You Offer

Before you apply, identify which of the 10 regulated crypto-asset services your business provides. These include services like:

  • Custody of crypto-assets
  • Operation of a trading platform
  • Crypto-fiat or crypto-crypto exchange
  • Execution of orders
  • Portfolio management
  • Providing advice, and more

MiCA licensing is activity-based, so you must apply for each service you intend to offer.

Step 2: Incorporate in the EU

Only companies established in an EU Member State are eligible to apply for CASP authorization. This means:

  • You must incorporate as a legal person (e.g., a limited company) in an EU country.
  • The company’s registered office and central administration must be within the EU.

Non-EU entities must either set up a subsidiary in the EU or restructure to apply for a license.

Step 3: Prepare Your Application for Authorization

Each application must be submitted to the National Competent Authority (NCA) of the EU Member State where your company is based.

The application must include detailed documentation, including:

  • A program of operations outlining your services, business model, and operational plan
  • A description of internal control mechanisms, especially for AML/CFT compliance
  • A custody and safeguarding policy (if applicable)
  • Documentation of your ICT systems, security protocols, and risk management
  • A business continuity and disaster recovery plan
  • Governance structure, including fit-and-proper assessments of managers and key personnel
  • Policies for conflicts of interest, client asset segregation, and complaint handling

Each NCA may provide its own templates and procedural guidance.

Step 4: Appoint Key Function Holders

MiCA requires CASPs to appoint competent individuals to critical roles, such as:

  • Compliance Officer
  • AML/CFT Officer
  • Risk Manager
  • ICT Security Lead

These individuals must demonstrate relevant qualifications and experience, and in some jurisdictions, they may need to be based in the EU.

Step 5: Implement AML/CFT Controls

MiCA works in tandem with EU anti-money laundering frameworks. CASPs must:

  • Perform customer due diligence (CDD) and KYC procedures
  • Monitor transactions for suspicious activity
  • Submit Suspicious Transaction Reports (STRs) to relevant authorities
  • Appoint an MLRO (Money Laundering Reporting Officer) if required by national law

You must also maintain a transaction record-keeping system in accordance with MiCA and national AML laws.

Step 6: Meet IT Security and Operational Standards

MiCA requires CASPs to implement robust ICT systems and cybersecurity protocols that ensure:

  • Protection of private keys and client data
  • Defense against cyberattacks
  • Business continuity in case of disruption
  • Secure communication with authorities and clients

These requirements are closely aligned with the EU’s Digital Operational Resilience Act (DORA) and NIS2 Directive.

Step 7: Set Up Client Protection Mechanisms

CASPs must ensure:

  • Clear and fair client disclosures
  • Proper segregation of client assets from company assets
  • Transparent pricing and fee structures
  • Complaints-handling procedures
  • Periodic reporting to clients (e.g., portfolio statements, transaction confirmations)

For portfolio management and advisory services, you must also conduct suitability assessments to ensure products match client risk profiles.

Step 8: Prepare for Ongoing Supervision

Once licensed, CASPs are subject to continuous supervision by their NCA, including:

  • Periodic reporting obligations
  • Audits and inspections
  • Capital adequacy reviews
  • Record-keeping and internal controls assessments

Non-compliance may result in fines, license suspension, or public enforcement actions.

Conclusion

Becoming a CASP under MiCA is not just a regulatory checkbox — it requires real operational readiness, robust governance, and ongoing compliance.

For EU-based crypto firms, MiCA provides long-term regulatory clarity and the ability to passport services across all EU Member States. But to take advantage of this opportunity, companies should begin preparing now — well before the 2026 deadline.

Gemini_Generated_Image_ksrzflksrzflksrz
ChatGPT Image May 2, 2026, 12_18_27 PM
Gemini_Generated_Image_9ij459ij459ij459
Gemini_Generated_Image_z4mxksz4mxksz4mx
ChatGPT Image Mar 31, 2026, 05_23_45 PM

Share on Social Media

X
LinkedIn