MiCA Regulation (EU) 2023/1114 — In force since December 2024
VASP→CASP Transition Deadline: 1 July 2026
Offices in Düsseldorf · Vilnius · Tallinn
Free Initial Consultation

Crypto Custody Rules Under MiCA — Safekeeping & Liability (Article 75)

Crypto custody rules under MiCA — safekeeping and key management

Holding clients' crypto is one of the most heavily regulated activities under MiCA — because when a custodian fails, clients lose their assets. MiCA's custody regime (centred on Article 75) imposes strict duties: segregate client assets, keep a register of positions, manage keys securely, and accept liability for loss. This guide explains what a compliant crypto custodian must do and why custody sits in the €125,000 capital class.

What MiCA Custody Covers

MiCA defines the custody and administration of crypto-assets on behalf of clients as a distinct crypto-asset service: safekeeping or controlling crypto-assets (or the means of access, such as private keys) for clients. Any business that holds client crypto — exchanges with hosted wallets, dedicated custodians, staking services that take control of assets — provides custody and needs authorization for it.

Non-custodial services, where the user retains sole control of their keys, generally fall outside this service. The dividing line is control: if you can move client assets, you are a custodian.

Core Custodian Duties

A MiCA custodian must:

  • Enter a written custody agreement with each client setting out the parties' rights and duties;
  • Maintain a register of positions opened in each client's name, recording their rights to the crypto-assets;
  • Segregate client crypto-assets from the custodian's own holdings;
  • Ensure clients' assets are not used for the custodian's own account;
  • Have policies to minimise the risk of loss from fraud, cyber threats, or negligence;
  • Provide clients with periodic statements of positions.

Segregation and the Register of Positions

Segregation is the heart of client protection. Client crypto-assets must be held so they are clearly distinguishable from the custodian's own assets — on-chain segregation, clear internal records, or both — so that in an insolvency clients' assets can be identified and returned and are shielded from the custodian's creditors.

The register of positions records, per client, the assets held and any movements. It must be accurate and current — it is the evidence that a given client owns a given balance, and supervisors will test its integrity.

Liability for Loss

This is the obligation that makes custody serious. Under MiCA, a custodian is liable to its clients for the loss of crypto-assets or the means of access resulting from an incident attributable to it — up to the market value of the assets lost. Liability is hard to disclaim.

That makes operational security and insurance commercial necessities, not nice-to-haves. A custodian's risk framework, key architecture, and insurance cover must be sized to the assets under custody.

Key Management & Operational Security

MiCA does not prescribe a single technology, but the duty to minimise loss drives the standard. Strong custody operations typically combine:

  • Cold/hot wallet separation, with the majority of assets in cold storage;
  • Multi-signature or MPC key architectures so no single person can move assets;
  • Strict access controls, segregation of duties, and withdrawal approval workflows;
  • Resilience and incident response aligned with DORA;
  • Independent security audits.

Key management documentation is a core part of the custody authorization file.

Capital & Authorization for Custodians

Custody is a Class 2 service, requiring permanent minimum capital of €125,000 (or a quarter of fixed overheads if higher) — see our capital requirements guide. A custodian that also operates a trading platform moves up to Class 3 (€150,000).

To be authorised for custody, your application must include the custody agreement template, segregation model, register design, key-management and security architecture, and loss-mitigation policies. We build these as part of a custody licence engagement.

Frequently Asked Questions

How does MiCA regulate crypto custody?
MiCA treats custody and administration of crypto-assets on behalf of clients as a distinct regulated service. A custodian must enter a written custody agreement, keep a register of positions per client, segregate client assets from its own, avoid using client assets for its own account, minimise the risk of loss, and provide periodic statements — and it is liable to clients for losses attributable to it.
Is a custodian liable if client crypto is lost or hacked?
Yes. Under MiCA a custodian is liable to its clients for the loss of crypto-assets or the means of access resulting from an incident attributable to it, generally up to the market value of the assets lost. This liability is difficult to disclaim, which is why strong key management and insurance are essential.
Does an exchange with hosted wallets need a custody licence?
Yes. If a business holds client crypto-assets or controls the private keys — as exchanges with hosted wallets do — it provides custody under MiCA and must be authorised for it. The dividing line is control: if you can move client assets, you are a custodian. Purely non-custodial services where users keep sole control generally fall outside.
What capital does a crypto custodian need under MiCA?
Custody is a Class 2 service requiring €125,000 in permanent minimum capital, or a quarter of the preceding year's fixed overheads if that is higher. A custodian that also operates a trading platform moves to Class 3 at €150,000.
What key-management standards does MiCA require?
MiCA does not mandate a specific technology but requires custodians to minimise the risk of loss. In practice supervisors expect cold/hot wallet separation, multi-signature or MPC key architectures, strict access controls and segregation of duties, DORA-aligned resilience, and independent security audits, all documented in the authorization file.
Elena Fischer — MiCA Custody & Client-Asset Specialist
MiCA Custody & Client-Asset Specialist
Elena Fischer
Senior Compliance Advisor · Düsseldorf & Luxembourg

Elena Fischer advises crypto custodians and exchanges on MiCA's safekeeping obligations — segregation, the register of positions, key management, and custodian liability — and helps them build custody operations that meet supervisory expectations. Speak with our team →

Build a Custody Operation That Meets MiCA

We help custodians and exchanges design MiCA-compliant safekeeping — segregation, register of positions, key management, and loss-mitigation — and secure the custody authorization. Free 30-minute consultation.

Get Custody Licensing Advice