MiCA Ongoing Compliance

    MiCA ongoing compliance for authorised CASPs

    Authorisation was the entry ticket. Supervision is the job.

    The obligations that start the day your licence is granted, evidenced on a cycle rather than reconstructed when someone asks. Annual compliance reviews, safeguarding and segregation verified on-chain, prudential figures that tie to audited accounts, and responses to CySEC information requests and inspections. We work alongside your compliance function and your counsel, not in place of them.

    The Obligations Do Not Pause

    A licence is granted against arrangements. Supervision tests whether those arrangements are still running, and it tests them on its own schedule.

    Annually

    Own funds against fixed overheads

    Article 67 sets own funds at the higher of your service-class floor and a quarter of the preceding year’s fixed overheads, reviewed annually. The overhead figure comes out of audited accounts.

    Annually

    Governance and suitability review

    Article 68 governance arrangements, management body suitability, and the outsourcing and conflicts registers, re-assessed and minuted rather than assumed to still hold.

    Continuously

    Safeguarding and segregation evidence

    Article 70 requires client assets to be segregated and ownership rights protected in insolvency. That is a standing state, so the evidence has to be produced on a cadence, not once at authorisation.

    On the event

    Notifications without delay

    Article 69 requires notifying the competent authority of any change to the management body before new members act. Material changes to the conditions of your authorisation follow the same logic.

    Article references are to Regulation (EU) 2023/1114. CySEC sets its own periodic reporting cadences by circular on top of these, so confirm the current ones with your compliance function rather than assuming last year's.

    Two Ways Firms Arrive Here

    Either the licence is new and nobody owns the cycle yet, or a supervisor has asked a question the records do not comfortably answer.

    Newly authorised CASPs in the first supervisory year

    The licence arrived and the project team moved on. What replaces it is a cycle: evidence that has to be produced whether or not anyone asks, reviews that have to be minuted, and a first supervisory contact that will test whether the arrangements described in the application are the arrangements actually running. Most firms discover the gap between the two in year one.

    • An obligations register mapped to your specific services, not a generic MiCA checklist
    • The recurring evidence cycle set up and handed over, so it survives staff changes
    • A first annual review that tells you what a supervisor would find before one looks

    Established CASPs facing an inspection or information request

    A request has landed, or the Common Supervisory Action on custody resilience has reached you, and the evidence is spread across wallets, spreadsheets, and people who have since left. We reconstruct what can be reconstructed, say plainly what cannot, and build the response so the same request costs a fraction of the effort next time.

    • Evidence assembled against the specific articles the request cites
    • On-chain reconstruction of custody and segregation for the period under review
    • An honest position on what the records do not support, before you assert it

    What the Service Covers

    The recurring evidence a supervised firm has to be able to produce, built on a cadence so producing it is retrieval rather than reconstruction.

    Annual compliance review

    A documented review of your arrangements against the CASP obligations that apply to your services, article by article, with findings rated and assigned. The output is something your board can act on and your supervisor can read, rather than a restatement of the policies you already have.

    Obligations register and compliance calendar

    Every recurring duty, who owns it, what evidences it, and when it falls due. Built once against your permissions and maintained after, so nothing depends on one person remembering that a review was due in March.

    Safeguarding and segregation attestations

    Recurring on-chain verification that client assets are held where you say, segregated from your own, and reconcilable to client balances. This is the Article 70 evidence that is hardest to reconstruct after the fact and easiest to produce on a cadence.

    Own funds and prudential evidence

    The Article 67 calculation prepared and evidenced: the class floor, the fixed overhead figure from your audited accounts, the higher of the two, and proof the funds are held as own funds rather than sitting in the same account as operating cash.

    Material change and notification evidence

    Article 69 requires notifying changes to the management body before new members act. We maintain the evidence pack behind each notification, including suitability assessments, so the filing your counsel makes is supported rather than asserted.

    Supervisory request and inspection response

    When CySEC asks, we assemble the on-chain and reconciliation evidence against the articles cited, in the format requested, to the deadline given. Where the records do not support an answer, we say so in the response rather than after it.

    Records, complaints and outsourcing evidence

    The unglamorous obligations that inspections actually open with: Article 71 complaints handled and logged, Article 72 conflicts identified and disclosed, Article 73 outsourcing arrangements documented and monitored, and records retained in a form that can be produced.

    AML and DAC8 data alignment

    Your MiCA evidence, AML audit trail, and DAC8 reporting all rest on the same transaction data. We reconcile them once so the three do not tell a supervisor three slightly different stories about the same year.

    How the Cycle Runs

    Set up once against your permissions, then run on a calendar that fires before a deadline rather than after one.

    01

    Onboarding review

    We read the authorisation file and compare what it describes to what is running. The output is a gap list between your stated arrangements and your actual ones, which is the gap a supervisor tests first.

    02

    Register and calendar

    Your obligations mapped to your permissions, each with an owner, an evidence definition, and a due date. This becomes the control document the cycle runs from.

    03

    Recurring evidence cycle

    Safeguarding and segregation verified on-chain, reconciliations run, prudential figures refreshed, and each one filed where it can be produced on request rather than rebuilt on request.

    04

    Supervisory response

    When a request or inspection arrives, the evidence is assembled against the articles cited and delivered in the format asked for. Prepared cycles turn a scramble into a retrieval.

    05

    Annual board report

    A written position on where the firm stands against its obligations, what changed this year, what was remediated, and what remains open. The document a board needs to sign off compliance honestly.

    Where Our Role Starts and Stops

    Your compliance officer stays accountable. We produce the evidence underneath them.

    We do

    • Run the annual compliance review and document the findings
    • Verify safeguarding and segregation on-chain, on a recurring cadence
    • Prepare the Article 67 own funds evidence from your audited accounts
    • Assemble responses to supervisory information requests and inspections
    • Maintain the obligations register, compliance calendar and evidence trail

    We do not

    • Act as your appointed compliance officer or MLCO; those roles carry personal accountability and cannot be contracted out
    • Give legal advice or interpret MiCA on contested points; that is counsel’s work
    • File regulatory returns or notifications on your behalf; we evidence them, your compliance function files them
    • Take board seats or supply nominee directors; the independence our audit work rests on requires staying off your board
    • Certify compliance we could not verify against the chain or your records

    Not yet authorised? Gap assessments and application evidence are MiCA readiness. For the AML side of the same supervisory picture, see AML & compliance audits, and the audited accounts behind your own funds figure come from statutory crypto audits.

    MiCA Ongoing Compliance FAQ

    What are a CASP’s ongoing obligations under MiCA after authorisation?

    They run continuously and they are not a subset of the application. Under Regulation (EU) 2023/1114 a CASP must keep acting honestly, fairly and professionally in clients’ best interests (Article 66); hold own funds at the higher of its service-class floor and a quarter of the preceding year’s fixed overheads, reviewed annually (Article 67); maintain governance arrangements and a suitable management body (Article 68); notify the competent authority of changes to that body before new members act (Article 69); safeguard and segregate client crypto-assets and funds (Article 70); operate complaints-handling procedures (Article 71); identify, prevent, manage and disclose conflicts of interest (Article 72); control and monitor outsourcing (Article 73); and maintain a wind-down plan (Article 74). On top of the regulation sit CySEC’s own periodic returns and circulars.

    What is MiCA ongoing compliance, and how is it different from MiCA readiness?

    Readiness is everything up to the licence: a gap assessment, remediation, and the evidence pack behind an application. Ongoing compliance is everything after it: the recurring cycle of reviews, evidence, notifications and supervisory responses that proves you still meet the conditions you were authorised against. The distinction matters commercially because firms routinely budget for the first and not the second, then find that their first supervisory contact tests arrangements nobody has looked at since the application was filed. Authorisation is the entry ticket. Supervision is the job.

    What does CASP compliance monitoring involve in practice?

    Producing evidence on a cadence rather than on demand. In practice that means a register of every obligation that applies to your specific permissions, an owner and an evidence definition for each, and a calendar that fires before the due date rather than after. The recurring work is mostly custody and segregation verification, reconciliation of on-chain activity to the ledger, refreshing the prudential figures, and keeping the complaints, conflicts and outsourcing records current. The test of whether monitoring is real is simple: if a supervisor asked today for last quarter’s safeguarding evidence, could you produce it without reconstructing it?

    What should a CASP annual compliance review cover?

    Every obligation that applies to your permissions, assessed against what the firm actually did rather than what its policies say it does. That means governance and management body suitability re-assessed rather than assumed; the Article 67 own funds calculation rerun against the latest audited fixed overheads; safeguarding and segregation tested on-chain for the period; complaints, conflicts and outsourcing registers reviewed; and last year’s open findings either closed or carried with a reason. The output should be a rated findings list with owners and dates, and a written position the board can sign.

    What does CySEC ask for in a supervisory information request or on-site inspection?

    Evidence, in a specified format, to a deadline. Typically that means the arrangements described in your authorisation file, records demonstrating they operated over a stated period, wallet and client-balance data supporting your safeguarding and segregation claims, the prudential calculation and its inputs, minutes of the governance decisions you are relying on, and the complaints and outsourcing registers. ESMA’s Common Supervisory Action on CASPs’ digital operational resilience for custody runs from the second half of 2026 into the first half of 2027, and CySEC communicated it to Cyprus firms by circular in August 2026, so custody arrangements are the live focus.

    How often should a CASP evidence safeguarding and segregation of client assets?

    More often than annually, because Article 70 describes a standing state rather than a periodic event. Client assets must be segregated and their ownership protected including in the event of the firm’s insolvency, which means the question a supervisor asks is not whether you segregated at year end but whether you were segregated throughout. A monthly or quarterly on-chain verification tied to client balances answers that; an annual snapshot does not. The practical argument for the shorter cycle is cost: a break found this month is explainable, and the same break found eleven months later usually is not.

    How is the Article 67 own funds requirement reviewed each year, and where do audited accounts come in?

    Article 67 sets own funds at the higher of the floor for your service class and one quarter of the fixed overheads of the preceding year, reviewed annually. The second limb is why the audit matters: the fixed overhead figure has to come from somewhere defensible, and that is your audited financial statements. This is the point where MiCA compliance and the statutory audit stop being separate workstreams, because a supervisor reviewing your prudential position is reading numbers an auditor signed. Holding own funds in the same account as operating cash is a common and avoidable finding.

    Which changes must be notified to CySEC after authorisation?

    Article 69 is explicit about the management body: a CASP must notify its competent authority without delay of any changes to that body, before any new member exercises activities, and provide the information needed to assess suitability under Article 68. Beyond that, material changes to the conditions on which authorisation was granted follow the same principle, including changes to the services provided, custody arrangements, outsourcing of critical functions, and qualifying shareholdings. The filing itself belongs to your compliance function and counsel. What we maintain is the evidence pack underneath it, so the notification is supported rather than asserted.

    Does DORA apply to CASPs, and how does it interact with MiCA supervision?

    Yes. Authorised CASPs are financial entities for the purposes of the Digital Operational Resilience Act, so ICT risk management, incident reporting, resilience testing and third-party risk obligations apply alongside MiCA. The two intersect most visibly in custody: ESMA’s Common Supervisory Action for 2026 and 2027 examines CASPs’ digital operational resilience specifically in relation to custody activities, which is a MiCA Article 70 subject being tested through a DORA lens. Firms that treat the two as separate projects tend to produce two sets of evidence about one set of systems.

    Can you act as our outsourced MiCA compliance function?

    No, and you should be wary of anyone who says yes. The compliance function and the anti-money-laundering compliance officer are roles the firm appoints and the supervisor assesses; they carry personal accountability and cannot be contracted out to a service provider. What can be outsourced, subject to the Article 73 outsourcing requirements, is the evidence work underneath: the recurring verification, reconciliation, register maintenance and review documentation that your compliance function relies on. That is what we do, and your appointed officer remains the accountable person.

    What happens if a CASP falls out of compliance after authorisation?

    It depends almost entirely on whether you found it or the supervisor did. Competent authorities have a graduated toolkit, from information requests and remediation timetables through to administrative fines, public statements, restrictions on services and, under Article 64, withdrawal of authorisation. A breach that is self-identified, documented, notified and remediated is a different conversation from one a supervisor uncovers in an inspection while the firm is asserting that the arrangements work. That asymmetry is the strongest practical argument for a real review cycle rather than a nominal one.

    How does ongoing MiCA compliance fit with the AML audit and DAC8 reporting cycle?

    They draw on the same data, so they should be run off one reconciled foundation rather than three. Your MiCA safeguarding evidence, your AML transaction monitoring and control testing, and your DAC8 reporting all ultimately describe the same wallets, the same client balances and the same movements. Firms that build them separately end up defending small inconsistencies between three descriptions of one year, which is an avoidable and expensive way to spend an inspection. We reconcile once and let the three obligations draw from it.

    More questions answered on our general FAQ.

    Sources

    The regulations, guidance and registers this page relies on. Check them directly.

    1. EUR-Lex: Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA)

      Articles 66 to 74, the continuing obligations of every authorised CASP, and Article 64 on withdrawal of authorisation.

    2. ESMA: Markets in Crypto-Assets Regulation (MiCA) hub

      Technical standards and guidelines that fill in the reporting and record-keeping detail, plus the register of authorised CASPs.

    3. ESMA: Common Supervisory Action on CASPs’ digital operational resilience for custody activities

      The exercise running from the second half of 2026 into the first half of 2027, communicated to Cyprus firms by CySEC Circular C794 on 6 August 2026.

    4. EUR-Lex: Regulation (EU) 2022/2554 on digital operational resilience (DORA)

      Applies to authorised CASPs as financial entities, and supplies the resilience lens the custody supervisory action is applied through.

    5. CySEC: Circulars

      Where the Cyprus supervisor publishes the reporting cadences and supervisory notices that sit on top of MiCA, including Circular C794 on the custody supervisory action.

    6. CySEC: CASP register

      The public register of authorised Cyprus CASPs.

    Could you produce last quarter's evidence today?

    Tell us when you were authorised, which services you are permitted for, and whether a supervisor has been in touch. We will scope the review and the cycle that follows it.

    • A first review that finds what an inspection would
    • An obligations register and calendar you keep
    • Evidence produced on a cadence, not on demand

    Reply within one business day, then a 20-minute scoping call and a fixed-fee proposal.

    Statutory opinions are issued by our ICPAC-licensed audit partner. Verify us before you engage.

    Last reviewed: September 21, 2026