Key facts
The Post-Authorisation Compliance Lifecycle: What Changes After You Receive Your CASP Licence
From the date your authorisation is granted, every CASP operates under an always-on compliance clock — the licence is a starting point, not a destination. MiCA does not reward firms for clearing the authorisation hurdle; it immediately imposes a continuous, interlocking set of obligations that must be maintained for as long as the entity operates.
Those obligations span five distinct pillars. First, prudential maintenance: ongoing own-funds or insurance adequacy under Article 67. Second, governance and staffing: fit-and-proper requirements and knowledge and competence standards for relevant staff under Articles 68 and 81(7). Third, client-protection conduct: conflicts of interest, safeguarding, complaints, and wind-down planning under Articles 70–85. Fourth, regulatory reporting to your national competent authority, including material changes and significant-CASP thresholds under Article 83. Fifth, parallel AML and transfer-of-funds obligations under the EU AML framework and Regulation (EU) 2023/1113 — entirely separate from MiCA itself.
Passporting rights under Article 65 add a sixth operational dimension once you scale across borders; that process is covered in the dedicated EU passporting guide. This article focuses on the operational compliance stack every authorised CASP must manage domestically from day one.
Article 67 Prudential Safeguards: Own Funds, Insurance, or Both
Under Article 67 MiCA, an authorised CASP must maintain its prudential safeguard at all times — not merely at the point of authorisation. The required amount is the higher of the fixed Annex IV minimum capital for the firm's service class, or 25% of fixed overheads (the Fixed Overheads Requirement). ESMA Q&A 2349 (answered 18 February 2026 by the Commission) confirms that the overhead base starts from all overheads — both fixed and variable — and only the deductions listed in Article 67(3)(a)–(d) are permitted. That list is exhaustive; no other adjustments are allowed. For firms operating fewer than twelve months, Article 67(2) requires use of projected fixed overheads drawn from the authorisation application — not prior-year actuals.
Article 67(4) permits three forms of prudential safeguard — or any combination of them: (a) own funds, (b) a qualifying professional indemnity insurance policy, or (c) a comparable guarantee. The own-funds route requires capital composed of Common Equity Tier 1 items as defined in Articles 26–30 of Regulation (EU) No 575/2013 (CRR) after the deductions required by Article 36 CRR; the threshold exceptions under Articles 46 and 48 CRR do not apply. The CRR reference is relevant only for the own-funds route — firms electing the insurance or guarantee path operate under a separate set of requirements. A CASP that unnecessarily locks up equity capital without exploring the insurance route may be forgoing a legitimate and potentially more efficient option under the Regulation.
The qualifying insurance path is governed by Articles 67(5)–(6). A compliant policy must: cover all EU territories where the CASP provides services; be publicly disclosed on the CASP's website; carry a minimum initial term of one year; require at least 90 days' written notice to cancel; be placed with an insurer authorised under EU law; and cover the risk categories specified in Article 67(6) — including loss of documents, errors and omissions, business disruption, gross negligence in safeguarding client assets, conflicts-of-interest failures, and CASP liability under Article 75(8). The table below maps Annex IV classes to service types; the classes are cumulative and the applicable minimum is the highest class triggered by the firm's licensed services.
| Annex IV Class | Minimum Capital | Crypto-Asset Services Covered |
|---|---|---|
| Class 1 | €50,000 | Reception & transmission of orders; execution of orders; placing of crypto-assets; investment advice; portfolio management; transfer services for crypto-assets |
| Class 2 | €125,000 | All Class 1 services plus custody & administration; exchange for funds; exchange for other crypto-assets |
| Class 3 | €150,000 | Operation of a trading platform (alone or combined with other services) |
Governance, Wind-Down Plans, and Business Continuity: Articles 68, 74, and the Key Distinctions
Article 68 sets the baseline governance architecture every authorised CASP must maintain on an ongoing basis. The management body must remain fit and proper — competence and good repute are not assessed once at authorisation and forgotten; Article 68(1) requires CASPs to ensure those standards are upheld continuously, and NCAs can reassess them. Separately, Article 72 mandates a documented conflicts-of-interest policy identifying situations where the CASP's interests, its staff's interests, or related parties' interests could damage clients — and the measures taken to manage or disclose those conflicts. Article 73 covers outsourcing: material outsourcing arrangements must not impair internal controls or supervisory access, and the CASP retains full regulatory accountability for any function it delegates.
Article 68(8) requires a separate, documented orderly wind-down plan — a structured plan for permanent cessation of operations. At minimum it must address the sequencing of service wind-down, the return of client assets and funds, notification to the competent NCA, and continuity of client access during the process. NCAs are scrutinising wind-down plans with particular intensity since the July 2026 authorisation wave: ESMA's supervisory briefing flagged inadequate wind-down documentation as a recurring gap in CASP applications. This is a live examination point, not a formality.
Article 74 is distinct. It requires a business continuity policy covering ICT systems, operational failures, and service interruptions — a plan for surviving a disruption and restoring normal operations. The two instruments address different scenarios and must exist as separate, documented policies. ICT continuity under Article 74 also overlaps with DORA obligations for in-scope CASPs; see the DORA compliance guide for CASPs for the interaction.
| Dimension | Art 68(8) — Wind-Down Plan | Art 74 — Business Continuity Policy |
|---|---|---|
| Trigger | Permanent cessation of operations | Operational disruption or ICT failure |
| Scope | Asset return, service sequencing, NCA notification | ICT recovery, service restoration, staff procedures |
| NCA filing | Must be available to NCA on request; scrutinised at authorisation and ongoing supervision | Must be maintained and testable; NCA may review |
| Review frequency | At minimum annually and after material business change | At minimum annually and after significant ICT incidents |
| DORA overlap | Limited | Direct — ICT continuity plans must align with DORA RTS |
Staff Knowledge and Competence: ESMA Guidelines Under Article 81(7) Applicable from 28 July 2026
On 28 January 2026, ESMA published its Guidelines on knowledge and competence requirements for CASP staff under Article 81(7) MiCA and Article 68(5) MiCA. These are formal Guidelines issued under Article 16 of the ESMA Regulation (EU) No 1095/2010 — not a binding Delegated Regulation or RTS. They operate on a comply-or-explain basis: national competent authorities must notify ESMA whether they comply or intend to comply, and if not, explain why. The Guidelines became applicable across all EU jurisdictions on 28 July 2026, six months after publication in all official EU languages. On 7 July 2026, ESMA published a compliance table showing each NCA's position — firms should verify their home-NCA status before assuming uniform application.
Although Article 81(7) MiCA literally targets CASPs providing advice on crypto-assets, ESMA explicitly extended the scope of these Guidelines to staff providing information about crypto-assets — not only formal advice. ESMA's rationale: all client-facing staff with potential to influence investor decisions must meet a defined competence baseline, regardless of whether their role is formally classified as advisory. This scope expansion is material. A CASP cannot limit compliance to its "advice team" and ignore information-desk or customer-support staff who explain products and services to clients. The Guidelines establish two tiers:
- Information staff: minimum 80 hours of qualifying training or one year of supervised relevant experience; at least 10 CPD hours per year; competence may be assessed by the CASP itself or an external body.
- Advisory staff: higher qualification standard; at least 20 CPD hours per year; formal assessment required.
The management body must conduct an annual review of compliance with Articles 68(5) and 81(7) and document its conclusions. NCAs may request training records at any time; failure to maintain adequate documentation exposes the firm to supervisory measures and sanctions under Article 111 MiCA. Practically, every authorised CASP should maintain four artefacts from day one: a staff register identifying each person's tier classification, individual competence records (qualifications and assessment outcomes), a CPD log updated at least annually, and a signed management-body review sign-off. These records should be ready for NCA inspection on short notice — not reconstructed retroactively.
Ongoing Reporting to the NCA: Article 69 and Level 2 Requirements
Article 69 MiCA imposes a standing transparency obligation: an authorised CASP must supply its national competent authority (NCA) with all information necessary to verify ongoing compliance — not merely at the point of authorisation, but continuously throughout the licence lifecycle. This is not a passive duty. NCAs expect CASPs to maintain live communication channels and to escalate proactively rather than wait for supervisory enquiry.
The main reporting streams fall into three categories. First, changes to authorisation conditions: any planned material change to the scope of crypto-asset services, composition of the management body, or holders of key functions (compliance, risk, MLRO) must be pre-notified to the home NCA before implementation, or notified promptly where a change is unplanned. Second, material operational incidents: ICT-related incidents meeting DORA significance thresholds trigger mandatory reporting to the NCA under Regulation (EU) 2022/2554; other material operational events — system outages, custody breaches, liquidity stress — feed into NCA notification under Article 69. For a full treatment of DORA obligations, see our DORA compliance guide for CASPs. Third, EMT and ART data reporting: where a CASP custodies or transfers significant e-money tokens or asset-referenced tokens, Commission Implementing Regulation (EU) 2024/2902 requires periodic data submissions to the token issuer — quarterly figures are due by the 21st of April, July, October and January for the preceding quarter, with daily reporting obligations for tokens exceeding significance thresholds. On the passporting dimension: any variation to services notified to a host NCA under Article 65 must flow through a variation notification via the home NCA — see the EU passporting guide for procedure. Records underpinning all of these streams — orders, transactions, service activities — must be maintained in the form and retention periods specified by Commission Delegated Regulation (EU) 2025/1140.
| Reporting event | Obligation / legal basis | Timing |
|---|---|---|
| Change to authorised services or management body | Pre-notification or prompt notification — Art. 69 MiCA |
Before implementation (planned); promptly (unplanned) |
| Material ICT incident | DORA major-incident report — Regulation (EU) 2022/2554 |
Initial: 4 hours; intermediate: 72 hours; final: 1 month |
| EMT/ART quarterly data to issuer | Commission IR (EU) 2024/2902 |
By 21st of April, July, October, January |
| Passporting service variation | Variation notice via home NCA — Art. 65 MiCA |
Before extension of services in host state |
| Records retention (all services) | Commission DR (EU) 2025/1140 |
Ongoing; minimum 5 years |
AML, KYC, and Travel Rule: The Parallel Compliance Stack Outside MiCA Title V
MiCA Title V governs the authorisation and conduct of CASPs — but it does not contain AML or KYC obligations. Those requirements flow from a separate, parallel stack of EU legislation that applies to CASPs as obliged entities in their own right. Confusing these frameworks is a compliance risk: being authorised under MiCA does not satisfy AML obligations, and vice versa.
AML and KYC obligations for CASPs arise from Regulation (EU) 2024/1624 (AMLR) and the applicable AML Directives, which require customer due diligence, beneficial ownership identification, suspicious transaction reporting, and internal AML controls. The Travel Rule — the obligation to accompany crypto-asset transfers with originator and beneficiary information — flows from Regulation (EU) 2023/1113 (TFR). Unlike funds transfers, where a €1,000 threshold applies, the TFR imposes Travel Rule requirements on all crypto-asset transfers involving a CASP, regardless of amount, with only narrow exclusions (e.g. certain person-to-person transfers without a CASP intermediary). From 2027, the newly established Anti-Money Laundering Authority (AMLA) will directly supervise the highest-risk obliged entities — including certain large CASPs — under Regulation (EU) 2024/1620. For deeper analysis of both frameworks, see the AMLA compliance guide and the TFR Travel Rule guide.
Two MiCA articles are frequently misattributed in this context. Article 72 MiCA governs conflicts-of-interest policy — it has no AML content. Article 92 MiCA (Title VI) requires suspicious transaction and order reporting (STOR) for potential market abuse — a distinct, parallel obligation that is not an AML measure. The table below maps each obligation to its correct legal source.
| Obligation | Legal Source | Key Requirement |
|---|---|---|
| AML / KYC / CDD | Regulation (EU) 2024/1624 (AMLR) + AML Directives |
Customer due diligence, UBO identification, internal AML controls, STR filing |
| Travel Rule (crypto transfers) | Regulation (EU) 2023/1113 (TFR) |
Originator and beneficiary data on all CASP-involved transfers; no minimum amount threshold |
| Direct AML supervision (large CASPs) | Regulation (EU) 2024/1620 (AMLA Regulation) |
AMLA direct oversight from 2027 for highest-risk obliged entities |
| Market abuse / STOR reporting | Article 92 MiCA (Title VI) |
Report suspicious transactions and orders to competent authority; distinct from AML STRs |
| Conflicts of interest | Article 72 MiCA (Title V) |
Written policy; identify, manage and disclose conflicts — not an AML obligation |
Becoming a Significant CASP: Article 83 Threshold, Process, and Enhanced Obligations
Under Article 83 MiCA, a CASP is designated a significant CASP once it reaches 15 million average active EU users per year. The threshold sounds straightforward, but the calculation methodology matters enormously in practice. Authoritative commentary — including KPMG's MiCA analysis — notes that the operative metric is built from a daily active user average rather than a simple count of unique users over the year. A platform may have 15 million unique EU users who visited once in a twelve-month period, yet fall well below the threshold if the daily active base is substantially smaller. Firms must apply the correct averaging methodology before concluding they are or are not within scope; an incorrect self-assessment in either direction carries regulatory risk.
The procedural trigger is self-monitoring followed by mandatory notification. Once a CASP identifies that it has crossed the threshold, it must notify its NCA within two months; the NCA then forwards that notification to ESMA. Significant status brings materially enhanced obligations: heightened supervisory scrutiny, more granular reporting requirements, and — depending on the outcome of the proposed Market Integration and Supervision Package — the possibility of direct ESMA supervision replacing NCA oversight entirely. Even below the 15 million threshold, ESMA's January 2025 Supervisory Briefing identifies indicators that trigger heightened NCA scrutiny: more than 1 million yearly active users, a balance sheet exceeding €3 billion, more than 200,000 cross-border users, complex group structures, or a combination of trading platform and custody roles.
Practically, this means significant-CASP risk is not a one-time assessment. Firms should implement continuous user-metric tracking — logged, timestamped, and tied to a documented notification-readiness procedure — so that the two-month notification window can be met without internal scramble. The comparison below outlines where standard and significant CASP obligations diverge.
| Dimension | Standard CASP | Significant CASP (Art. 83) |
|---|---|---|
| Primary supervisor | National competent authority (NCA) | NCA + ESMA involvement; possible future direct ESMA oversight |
| Reporting intensity | Standard periodic reporting | Enhanced reporting; additional data demands from supervisors |
| Supervisory reviews | Risk-based NCA schedule | Heightened scrutiny; on-site inspections more likely |
| Governance expectations | Art. 68 baseline | Greater senior-management accountability; stricter documentation |
| Threshold trigger | N/A | 15 million avg. active EU users/year; self-notify NCA within 2 months |
| Internal monitoring requirement | Good practice | Essential; documented notification-readiness procedure required |
Post-Authorisation Compliance Calendar: Key Deadlines and Recurring Obligations
Authorisation is not the finish line — it opens a continuous compliance lifecycle with recurring deadlines, annual reviews, and event-driven notifications. The table below maps each core obligation to its correct legal source and cadence. Use it as a baseline checklist; your actual programme will need to layer in NCA-specific requirements and any conditions attached to your authorisation.
Two points warrant emphasis before the table. First, the prudential safeguards review under Article 67 is not purely a year-end exercise: a material change in business volume, service mix, or group structure can trigger an out-of-cycle recalculation. Second, changes notification under Article 69 operates on a prompt basis — there is no grace period to batch-notify your NCA; the obligation attaches on the change itself. For DORA-linked obligations, see also the DORA compliance guide for CASPs; for AML and Travel Rule detail, see the AMLA/AML guide and the TFR compliance guide.
| Obligation | Legal source | Frequency / Deadline |
|---|---|---|
| Prudential safeguards review (own funds or insurance) | Art. 67 MiCA | Annually; also on any material change in business or service scope |
| Fixed-overheads calculation update | Art. 67 MiCA; ESMA Q&A 2349 | Annually, based on prior-year audited financials; all overheads (fixed + variable) as the starting base |
| Insurance policy renewal / adequacy check | Arts. 67(5)–(6) MiCA | Annually; policy must maintain minimum one-year term and EU-territory coverage |
| Staff competence records and CPD log | ESMA Guidelines (Arts. 68(5) / 81(7) MiCA); applicable from 28 July 2026 | Ongoing; annual management review of records; comply-or-explain basis |
| Wind-down plan review | Art. 68(8) MiCA | At least annually and on any material operational or structural change |
| Business continuity policy review | Art. 74 MiCA; DORA (Reg. (EU) 2022/2554) | At least annually; DORA testing requirements on their own schedule |
| Changes notification to NCA | Art. 69 MiCA | Promptly on each qualifying change; no batching |
| EMT data reporting to issuer | Implementing Reg. (EU) 2024/2902 | Quarterly aggregate + daily transaction-level reporting |
| AML / CDD periodic reviews | AMLR; AMLD; Reg. (EU) 2023/1113 (TFR) | Risk-based, ongoing; enhanced due diligence for higher-risk relationships |
| Travel Rule compliance | Reg. (EU) 2023/1113 | Ongoing; per-transaction originator / beneficiary data obligations |
| Market abuse monitoring and STOR filing | Art. 92 MiCA | Ongoing surveillance; STOR filed without delay on reasonable suspicion |
| Passporting variation notification | Art. 65 MiCA | Prior to adding a new service or host Member State; notification-based, not re-authorisation |
Frequently asked questions
Can a CASP use a professional indemnity insurance policy instead of holding own funds under Article 67?
Yes. Article 67(4) of MiCA expressly permits prudential safeguards to take the form of own funds (CET1 per CRR Arts 26–30), a qualifying insurance policy covering all EU territories where services are provided, a comparable guarantee, or a combination of these. If the insurance route is chosen, the policy must meet the characteristics in Articles 67(5)–(6): publicly disclosed on the CASP website, initial term of at least one year, 90-day cancellation notice, placed with an authorised EU insurer, and covering the risk categories listed in Article 67(6). Using insurance can preserve balance-sheet capital, but the overhead calculation base remains the same regardless of which form of safeguard is chosen.
What is the difference between the Article 68(8) wind-down plan and the Article 74 business continuity policy?
They serve distinct purposes. Article 68(8) requires a documented orderly wind-down plan covering how the CASP would permanently cease operations while protecting client assets and notifying the NCA — it is a governance document for permanent cessation. Article 74 requires a separate business continuity policy addressing how the CASP maintains or restores services after an operational interruption (ICT failure, disaster, etc.). Conflating them in a single document is a regulatory gap; NCAs expect two separate, cross-referenced policies. DORA also imposes overlapping continuity requirements for ICT systems.
How is the Article 83 significant CASP threshold calculated — annual unique users or daily average?
The 15 million user threshold in Article 83 is expressed as average active EU users per year. However, the calculation methodology uses daily active user averaging across the year rather than counting unique annual users — a distinction that matters for large platforms. A firm with 15 million unique users over a calendar year may still sit below the threshold if its average daily active user count is substantially lower. Firms approaching scale should build ongoing user-metric tracking into their compliance monitoring framework and be ready to self-notify the NCA within two months of crossing the threshold.
Are the ESMA knowledge and competence guidelines under Article 81(7) legally binding?
These are ESMA Guidelines under Article 16 of the ESMA Regulation, not a directly binding EU Regulation or RTS. They operate on a comply-or-explain basis: national competent authorities (NCAs) must notify ESMA whether they comply, do not comply but intend to comply, or do not intend to comply. For CASPs, this means in practice that NCAs in the vast majority of Member States will enforce the guidelines as if they were binding standards. ESMA published its NCA compliance table on 7 July 2026. The guidelines apply from 28 July 2026 to all authorised CASPs. Notably, although Article 81(7) MiCA literally refers only to CASPs providing advice, ESMA explicitly extended the guidelines' scope to staff providing information as well.
What AML and Travel Rule obligations does a MiCA-authorised CASP have, and which MiCA articles cover them?
MiCA Title V does not contain AML/KYC obligations. CASPs remain subject to the EU AML framework — including Regulation (EU) 2024/1624 (AMLR) and the forthcoming AMLA supervision from 2027. The Travel Rule obligation for crypto-asset transfers comes from Regulation (EU) 2023/1113 (the Transfer of Funds Regulation), which applies to all crypto-asset transfers involving a CASP regardless of amount. Within MiCA itself, Article 72 covers conflicts of interest (not AML), and Article 92 governs market abuse suspicious transaction and order reporting (STOR) under Title VI — a separate obligation. Compliance teams must maintain parallel compliance stacks for AML/TFR and MiCA conduct obligations.
When must a CASP notify its NCA of changes after authorisation, and what triggers a passporting variation?
Under Article 69, CASPs must provide the NCA with all information needed to verify ongoing compliance, and any planned material change — to the services provided, management body composition, key function holders, or governance arrangements — must be notified promptly, with some changes requiring prior NCA approval. For passported cross-border services under Article 65, any change to the services or Member States notified in the original passport notification requires a variation notification through the home NCA. Failure to notify a change can expose a CASP to supervisory measures under Article 111, even if the underlying activity is otherwise compliant.