What MiCA Custody Covers
MiCA defines the custody and administration of crypto-assets on behalf of clients as a distinct crypto-asset service: safekeeping or controlling crypto-assets (or the means of access, such as private keys) for clients. Any business that holds client crypto — exchanges with hosted wallets, dedicated custodians, staking services that take control of assets — provides custody and needs authorization for it.
Non-custodial services, where the user retains sole control of their keys, generally fall outside this service. The dividing line is control: if you can move client assets, you are a custodian.
Core Custodian Duties
A MiCA custodian must:
- Enter a written custody agreement with each client setting out the parties' rights and duties;
- Maintain a register of positions opened in each client's name, recording their rights to the crypto-assets;
- Segregate client crypto-assets from the custodian's own holdings;
- Ensure clients' assets are not used for the custodian's own account;
- Have policies to minimise the risk of loss from fraud, cyber threats, or negligence;
- Provide clients with periodic statements of positions.
Segregation and the Register of Positions
Segregation is the heart of client protection. Client crypto-assets must be held so they are clearly distinguishable from the custodian's own assets — on-chain segregation, clear internal records, or both — so that in an insolvency clients' assets can be identified and returned and are shielded from the custodian's creditors.
The register of positions records, per client, the assets held and any movements. It must be accurate and current — it is the evidence that a given client owns a given balance, and supervisors will test its integrity.
Liability for Loss
This is the obligation that makes custody serious. Under MiCA, a custodian is liable to its clients for the loss of crypto-assets or the means of access resulting from an incident attributable to it — up to the market value of the assets lost. Liability is hard to disclaim.
That makes operational security and insurance commercial necessities, not nice-to-haves. A custodian's risk framework, key architecture, and insurance cover must be sized to the assets under custody.
Key Management & Operational Security
MiCA does not prescribe a single technology, but the duty to minimise loss drives the standard. Strong custody operations typically combine:
- Cold/hot wallet separation, with the majority of assets in cold storage;
- Multi-signature or MPC key architectures so no single person can move assets;
- Strict access controls, segregation of duties, and withdrawal approval workflows;
- Resilience and incident response aligned with DORA;
- Independent security audits.
Key management documentation is a core part of the custody authorization file.
Capital & Authorization for Custodians
Custody is a Class 2 service, requiring permanent minimum capital of €125,000 (or a quarter of fixed overheads if higher) — see our capital requirements guide. A custodian that also operates a trading platform moves up to Class 3 (€150,000).
To be authorised for custody, your application must include the custody agreement template, segregation model, register design, key-management and security architecture, and loss-mitigation policies. We build these as part of a custody licence engagement.