MiCA Regulation (EU) 2023/1114 — In force since December 2024
VASP→CASP Transition Deadline: 1 July 2026
Offices in Düsseldorf · Vilnius · Tallinn
Free Initial Consultation

MiCA Compliance Checklist for CASPs — 2026 Edition

MiCA compliance checklist for crypto-asset service providers 2026

MiCA compliance is not a single milestone — it is a standing condition across capital, governance, AML, technology, and conduct. This 2026 checklist pulls the whole framework into one place so you can see, at a glance, what a compliant CASP must have in place for authorization and for the ongoing supervision that follows. Use it as a gap analysis against your own operation.

1. Authorization & Legal Entity

  • ☐ EU legal entity established and effectively managed in your home member state
  • ☐ CASP authorization granted (or application filed) with the home NCA — see the application checklist
  • ☐ Services correctly classified under MiCA service definitions
  • ☐ Passporting notifications filed for any other member states served
  • ☐ White papers published/notified for any tokens offered (see white paper guide)

2. Capital & Prudential Safeguards

  • ☐ Correct capital class identified — Class 1 (€50k), Class 2 (€125k), or Class 3 (€150k)
  • ☐ Permanent minimum capital held in qualifying own funds
  • ☐ One-quarter-of-fixed-overheads test calculated and the higher amount maintained
  • ☐ Ongoing monitoring of own funds against the requirement

Detail in our capital requirements guide.

3. Governance, People & Risk

  • ☐ Fit-and-proper management body with relevant experience
  • ☐ Qualifying shareholders identified and assessed
  • ☐ Governance arrangements, internal controls, and risk management documented
  • ☐ Conflict-of-interest policy
  • ☐ Complaints-handling procedure
  • ☐ Outsourcing policy and oversight
  • ☐ Business-continuity policy

4. AML / CFT & Travel Rule

  • ☐ Business-wide ML/TF risk assessment
  • ☐ KYC/CDD and onboarding with verification tooling
  • ☐ Transaction monitoring and blockchain analytics
  • ☐ Sanctions screening
  • ☐ Travel Rule data flows (no threshold for crypto) — see Travel Rule guide
  • ☐ Appointed MLRO and SAR/STR process — see MLRO guide
  • ☐ Training, independent testing, recordkeeping

5. ICT Resilience & DORA

  • ☐ Board-approved ICT risk-management framework
  • ☐ Incident classification and 4h/72h/1-month reporting capability
  • ☐ Resilience-testing programme (TLPT if significant)
  • ☐ Register of information for ICT third parties
  • ☐ DORA-compliant supplier contracts and exit strategies

Full detail in our DORA compliance guide.

6. Conduct & Client Protection

  • ☐ Segregation of client crypto-assets and funds (custodians — see custody rules)
  • ☐ Register of client positions (custody)
  • ☐ Fair, clear, not-misleading marketing communications
  • ☐ Market-abuse detection and reporting for trading platforms — see market abuse rules
  • ☐ Clear client information and risk disclosures

7. Ongoing Obligations

Compliance is continuous. Maintain capital, refresh the AML risk assessment, keep the ICT register current, monitor for market abuse, report incidents and suspicious activity on time, and notify your NCA of material changes. Supervisory reviews can come at any time — keep the evidence current rather than reconstructing it under pressure.

The fastest way to find your gaps is a structured review against this checklist. That is exactly what our MiCA consulting team delivers.

Frequently Asked Questions

What does MiCA compliance involve for a CASP?
MiCA compliance spans authorization and correct service classification, holding the right capital class, fit-and-proper governance, a full AML/CFT and Travel Rule programme, DORA ICT resilience, client-asset protection and custody safekeeping, market-abuse controls for trading platforms, and ongoing reporting and monitoring. It is a standing condition, not a one-time milestone.
Is MiCA compliance a one-off or ongoing?
Ongoing. After authorization, a CASP must continuously maintain capital, keep its AML risk assessment and ICT third-party register current, monitor for market abuse, report incidents and suspicious activity within deadlines, and notify the NCA of material changes. Supervisory reviews can occur at any time.
What are the biggest MiCA compliance gaps regulators find?
Common gaps include incorrect service classification and capital, generic AML policies not tailored to the business, weak ICT/DORA documentation, missing or inaccurate registers (client positions or ICT third parties), and inadequate market-abuse surveillance on trading platforms.
How do I run a MiCA gap analysis?
Assess your operation against each pillar — authorization, capital, governance, AML and Travel Rule, DORA, and conduct/client protection — identifying where evidence is missing or out of date. A structured gap analysis, ideally with specialist support, turns the checklist into a prioritised remediation plan.
Does MiCA require DORA compliance too?
Yes, in practice. DORA (Regulation (EU) 2022/2554) applies to CASPs and sets the operational-resilience standard that complements MiCA. A complete MiCA compliance posture includes an ICT risk framework, incident reporting, resilience testing, and an ICT third-party register under DORA.
Thomas Mueller — MiCA Compliance Specialist
MiCA Compliance Specialist
Thomas Mueller
Senior CASP Licensing Advisor · Düsseldorf & Vilnius

Thomas Mueller helps crypto-asset service providers achieve and maintain MiCA compliance — from authorization through ongoing supervision — across capital, governance, AML, ICT resilience, and conduct obligations. Speak with our team →

Find Your MiCA Gaps Before the Regulator Does

We run structured MiCA gap analyzes across capital, governance, AML, DORA, and conduct — and deliver a prioritised remediation plan. Free 30-minute consultation.

Get a MiCA Gap Analysis