MiCA Obligations After Authorisation: The CASP Compliance Calendar

By Panayiotis Kattides · September 21, 2026
A licence is granted against arrangements you described. Supervision tests whether those arrangements are still running. The gap between the two opens quietly, and almost always in the first year.
Key takeaways
- MiCA's continuing obligations for CASPs sit in Articles 66 to 74 and apply from the day the licence is granted, not from the first inspection.
- Article 69 requires notifying changes to the management body before new members act, not at the next convenient reporting date.
- Article 67 own funds are reviewed annually against the preceding year's fixed overheads, which ties your prudential position to your audited accounts.
- The test of whether your cycle is real: could you produce last quarter's safeguarding evidence today, without rebuilding it?
Authorisation projects have a shape. There is a deadline, a visible goal, external counsel, a board that pays attention, and a moment when the licence arrives and everyone is relieved. Then the project team returns to its day jobs, the external advisers close their files, and the arrangements described in the application carry on running, unexamined, for somewhere between one and three years.
What replaces the project is a cycle, and in most newly authorised firms nobody has written it down. This article is an attempt at that document: the continuing obligations under Regulation (EU) 2023/1114, arranged by how often they actually fall due rather than by article number.
One caveat before the calendar. The cadences below that come from the regulation are stated as the regulation states them. Cadences for a national supervisor's own periodic returns are set by circular and change, so confirm the current ones with your compliance function rather than working from any article on the internet, including this one.
Day One After the Licence
Three things are worth doing in the first fortnight, while the application file is still fresh in everyone's memory and the people who built it are still reachable.
Write down what you actually told them. The application described specific arrangements: how client assets are segregated, who is on the management body, which functions are outsourced, how complaints are handled. That description is now the standard you are measured against. Extract it into a register of commitments, because in eighteen months nobody will remember what was in an annex.
Assign every obligation an owner. Not a department. A person, with a named deputy. The most common failure mode we see is an obligation that everyone assumed belonged to someone else, discovered during an information request.
Prove wallet control now. Control is demonstrable in the present tense and not retrospectively. Establishing it while the current keys, custodians and staff are in place costs very little; reconstructing it after a key rotation and a departure may be impossible.
Continuous: The Obligations That Never Fall Due
Some obligations have no date attached because they describe a standing state. Article 70 safeguarding is the important one: client assets must be segregated and their ownership protected, including in the event of your insolvency, and client assets must not be used for your own account.
The practical implication is that evidence has to be produced periodically even though the obligation is continuous. A supervisor asking about segregation is not asking about the reporting date. They are asking about a period, and a firm that took one snapshot at year-end cannot answer. This is the single biggest difference between how firms think about this obligation and how it is tested.
Monthly or Quarterly: The Reconciliation Cadence
The recurring work is mostly reconciliation. On-chain client holdings matched against the internal client balance ledger, differences investigated and resolved, exceptions logged with their cause and resolution.
The argument for a short cycle is not regulatory purity, it is cost. A break found this month is explainable, because the person who caused it is still here and still remembers. The same break found eleven months later is an investigation. Firms that reconcile monthly spend less in total than firms that reconcile annually, which is counterintuitive until the first year-end reconstruction.
Complaints handling under Article 71 belongs in the same rhythm. Supervisors ask for the complaints log early in an inspection, because it is a cheap and reliable indicator of whether a firm's procedures exist in practice. An empty log is not automatically good news; it usually prompts a question about whether complaints are being recognised as complaints.
Annual: The Review That Should Not Be a Formality
Own funds. Article 67 requires prudential safeguards at the higher of your class floor and a quarter of the preceding year's fixed overheads, reviewed annually. The review is explicit in the article, and the overhead figure comes from audited accounts, which is why a stalled audit becomes a compliance problem rather than an accounting one. If you grew last year, recompute before assuming the floor still governs.
Governance and suitability. Article 68 covers governance arrangements and the requirement that the management body have appropriate knowledge, skills and experience and be of good repute. Suitability is not assessed once at authorisation and then assumed to persist. Circumstances change, and the assessment should be redone and minuted rather than inherited.
Outsourcing. Article 73 requires that outsourcing does not impair the quality of internal control or the supervisor's ability to monitor compliance. Crypto firms outsource a great deal, often to providers chosen quickly during build-out, and the register drifts. An annual review of what is outsourced, to whom, under what contract, and with what monitoring is usually where the surprises are.
Wind-down. Article 74 requires a plan for orderly wind-down. Written once and never revisited, it describes a business that no longer exists.
Event Driven: The Ones With No Warning
Article 69 is explicit and it is the obligation most often missed. A CASP must notify its competent authority without delay of any changes to its management body, before any new member exercises activities, and provide the information needed to assess suitability under Article 68.
Read the sequencing: the notification comes before the person starts, not at the next reporting date and not once their appointment is confirmed internally. A director who joined in March and was notified in June created a breach that runs for three months and is trivially visible from your own board minutes.
Material changes to the conditions on which authorisation was granted follow the same principle: new services, a changed custody model, outsourcing a critical function, a change in qualifying shareholdings. When in doubt, the cost of an unnecessary notification is an email, and the cost of a missed one is a finding.
Who Owns What
A boundary worth stating plainly, because it is routinely blurred by service providers.
- The board owns the arrangements and signs off that they work. This cannot be delegated outward.
- The compliance officer and the MLCO are appointed roles assessed by the supervisor, carrying personal accountability. They cannot be contracted out to a firm, and anyone offering to be your outsourced compliance officer is describing something that does not exist.
- Legal counsel owns interpretation and the filings.
- An evidence provider produces the verification, reconciliation and review documentation the compliance function relies on. That work can be outsourced, subject to Article 73.
We are in the fourth category, which is why our MiCA ongoing compliance page says plainly what we do not do.
One Test
If you want a single question to judge whether your cycle is real rather than nominal, it is this: if CySEC asked today for last quarter's client asset segregation evidence, could you produce it, or would you have to rebuild it?
Firms that can produce it have a short, unremarkable supervisory relationship. Firms that rebuild it discover during the rebuild what else has drifted, on a deadline, in front of an audience. The difference between the two is not diligence or headcount. It is whether the evidence is generated on a cadence or on request.
How Ondology Labs can help: We run the recurring evidence cycle underneath your compliance function: annual reviews, safeguarding and segregation verified on-chain, Article 67 evidence reconciled to audited accounts, and responses to supervisory requests. That is MiCA ongoing compliance. If you are not yet authorised, start at MiCA readiness. The AML side is AML and compliance audits, and the reporting side is DAC8 and tax reporting.
Related reading: CASP audit requirements under MiCA in Cyprus · MiCA authorisation in Cyprus · AML audit readiness for crypto firms in Cyprus