MiCA compliance in Cyprus and across the EU
The transition window has closed. Enforcement has started.
MiCA readiness built on evidence, not policy documents. For crypto-asset service providers seeking or holding CASP authorisation, and for firms whose national registrations expired with the transition windows. We assess your gaps against the CASP obligations, verify custody and client asset segregation on-chain, attest reserves, and keep the compliance evidence current, working alongside your legal counsel rather than instead of them.
MiCA fully in force
The CASP authorisation regime applies across all 27 member states.
Last transition windows closed
France, Italy, Luxembourg, Czechia, and Spain ended the final grandfathering periods.
Enforcement has started
Austria's FMA issued the first published MiCA fine. Supervisors are now testing, not onboarding.
Transition periods were set nationally under Article 143(3), so the earliest closed in mid 2025. There is no member state left where a pre-MiCA registration still works.
One Rulebook, Two Starting Points
Whether you hold a licence or missed the window, the supervisor's question is the same: can you prove what your policies claim?
For authorised CASPs and firms mid-application
Authorisation is the entry ticket, not the finish line. Once you hold or seek a CASP licence, the obligations become operational: client assets segregated and provably safeguarded, reserves that can be evidenced on demand, records that reconcile to the chain, and reporting that arrives on time. We build and maintain that evidence layer, so what your policies promise is what your data shows.
- Custody and segregation of client assets evidenced on-chain, not just in policy documents
- Recurring reserve and safeguarding attestations supervisors and clients can rely on
- Application-stage evidence packs prepared with your legal counsel, not instead of them
For firms that outgrew their national registration
The transition era is over. If you served EU clients under a national registration and did not complete a CASP authorisation, you are now operating in a market where the grace periods have closed and enforcement has started. The way back in is a gap assessment that tells you honestly how far you are from the requirements, and a remediation plan sequenced against what an application actually needs.
- A documented gap assessment against the CASP obligations that apply to your services
- Remediation work sequenced so the application-critical evidence is built first
- One data foundation that also serves your AML audit and DAC8 reporting duties
What the Service Covers
From an honest gap assessment to a running evidence cycle, with every claim a supervisor might test backed by data.
MiCA gap assessment
Your governance, custody, safeguarding, conflicts, complaints, and record-keeping arrangements assessed against the CASP obligations that apply to your specific services. Documented per requirement, with each gap rated and a concrete close-out action, so the result is a work plan rather than a scare memo.
Custody and segregation evidence
MiCA requires client assets to be segregated and safeguarded. We verify wallet control cryptographically, map client asset flows against your own, and document the segregation on-chain, producing evidence a supervisor can test rather than assertions they have to take on trust.
Reserve and safeguarding attestations
Recurring, independently prepared attestations that reserves back what you owe clients, built on the same discipline as our proof of reserves work: cryptographic verification of wallet ownership on one side, a committed liability set on the other.
Authorisation evidence pack
For the application itself: the data and controls evidence your legal counsel needs to substantiate the custody, safeguarding, and record-keeping sections of a CySEC or other EU CASP application. Counsel drafts and files; we make sure the operational claims in the filing are true and demonstrable.
Ongoing compliance cycle
Supervision is continuous, so the evidence has to be. We set up the recurring reconciliation, attestation, and reporting cycle, and keep it running, so a supervisory information request is answered from live records instead of triggering a reconstruction project.
AML and DAC8 alignment
MiCA authorisation, AML supervision, and DAC8 reporting all draw on the same underlying records. We build the data foundation once, so the same reconciled, chain-verified dataset serves all three, instead of three teams paying for the same work three times.
How an Engagement Runs
Scoped honestly, evidenced from the chain up, documented for the people who have to rely on it.
Scoping
We establish which MiCA obligations actually apply: which crypto-asset services you provide, where your clients are, what authorisation you hold or need, and the state of your records. If MiCA does not catch you, we say so and stop there.
Gap assessment
Custody, safeguarding, segregation, governance evidence, and record-keeping tested against the requirements, on real data rather than policy documents. You get a concrete list of what is missing and what closing each gap takes.
Evidence build
Wallet control verified cryptographically, client asset segregation documented on-chain, reserves attested, and books reconciled to chain activity. The claims your application or your supervisor relies on become demonstrable.
Documentation and handover
Findings and evidence assembled into the form the consumer needs it: an evidence pack for your legal counsel during authorisation, or a remediation record and attestation set for ongoing supervision.
Ongoing cycle
The reconciliation and attestation cadence is set up to repeat, so year two is routine. We stay available for supervisory follow-ups and for the questions your counsel or auditor raises along the way.
Where Our Role Starts and Stops
We do the evidence. Legal interpretation and the application itself belong to your counsel, and pretending otherwise would make both jobs worse.
We do
- Assess your operations against the CASP obligations and document the gaps
- Verify wallet control cryptographically and evidence client asset segregation on-chain
- Prepare recurring reserve and safeguarding attestations
- Build the evidence pack your legal counsel needs for authorisation and supervision
We do not
- Give legal advice or interpret MiCA on contested points; that is counsel’s work
- Draft or file the authorisation application; we evidence it
- Certify compliance we could not verify against the chain or your records
- Promise timelines before scoping has seen the state of your data
For the AML side of the same supervisory picture, see AML & compliance audits. If your books have never been tied to on-chain activity, start with transaction reconciliation.
MiCA Readiness FAQ
What is MiCA, in one paragraph?
MiCA is the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114), the EU's single rulebook for crypto-asset markets. It has applied in full since 30 December 2024. Firms providing crypto-asset services to EU clients must be authorised as Crypto-Asset Service Providers (CASPs) in one member state, after which they can passport their services across all 27. The authorisation bar is high: governance, capital adequacy, operational resilience, segregation and safeguarding of client assets, complaints handling, and record-keeping are all tested, and the obligations continue for as long as the licence does. Stablecoin issuers face separate, stricter titles covering e-money tokens and asset-referenced tokens.
Is the transition window really closed?
Yes, for practical purposes. MiCA let each member state set its own grandfathering window under Article 143(3), which is why deadlines varied: the Netherlands, Finland, and Hungary ended theirs in mid 2025, Germany, Ireland, and Lithuania in December 2025, and the longest windows, in France, Italy, Luxembourg, Czechia, and Spain, closed on 1 July 2026. As of today there is no member state where a firm can rely on a pre-MiCA national registration to serve clients. A firm without CASP authorisation serving EU clients is operating outside the regime, and grandfathering rights were always national, so they never covered passporting into other states anyway.
Who supervises CASPs in Cyprus, and what do they expect?
The Cyprus Securities and Exchange Commission (CySEC) authorises and supervises CASPs in Cyprus. An application stands or falls on whether the firm can demonstrate what its policies claim: that client assets are actually segregated and safeguarded, that governance and capital meet the requirements, that systems are resilient, and that records are complete and retrievable. Supervision after authorisation runs on the same logic. Our role is the demonstrable part: we verify wallet control, document segregation on-chain, attest reserves, and reconcile records, so the operational claims in an application or a supervisory response are backed by evidence rather than assertion.
Has anyone actually been fined under MiCA yet?
Yes. Enforcement has started. The first published MiCA fine came on 14 August 2026, when Austria's Financial Market Authority penalised Bitpanda EUR 70,000 for late white paper filing, premature marketing, and missing disclaimers. The amount is small; the signal is not. Supervisors have moved from onboarding the industry to testing it, and the early cases show they are willing to act on procedural failures, not just on collapses. Firms whose compliance exists mainly in policy documents should assume the gap between paper and practice is now the thing being examined.
What evidence do supervisors actually ask for?
The recurring themes are custody and client asset protection: proof that the firm controls the wallets it claims to control, that client assets are segregated from the firm's own, that reserves cover what is owed to clients, and that the books agree with the chain. These are exactly the questions an on-chain verification answers well and a policy document answers badly. A firm that can produce a cryptographic wallet-control verification, a current reserve attestation, and a reconciliation of ledger to chain is in a different conversation with its supervisor than a firm that needs weeks to assemble the same picture.
Are you lawyers? Who runs the authorisation application?
We are not a law firm, and this service is deliberately drawn to stop where legal advice starts. The authorisation application, the legal interpretation of MiCA, and regulatory strategy belong to your legal counsel, and we work alongside whoever that is. What we own is the evidence layer: the gap assessment on the operational side, cryptographic verification of custody claims, reserve attestations, and records reconciled to the chain. In practice counsel drafts the application and we make sure the operational statements in it are true and demonstrable, which is the part applications most often stumble on.
How does MiCA readiness relate to your AML audits and DAC8 reporting?
They are three regimes drawing on one data foundation. MiCA governs your authorisation and conduct as a CASP, AML law makes you an obliged entity whose controls get audited, and DAC8 makes you a tax reporting entity from January 2026. All three ultimately test whether your records agree with the chain. We build that foundation once: reconciled transactions, verified wallet control, documented client asset segregation. The same dataset then serves the MiCA evidence pack, the AML compliance audit, and the DAC8 crypto report, which is materially cheaper than treating them as three unrelated projects.
We issue a stablecoin. Does this service cover us?
Partly, and we are precise about which part. MiCA's e-money token and asset-referenced token titles impose reserve, redemption, and disclosure obligations on issuers, and the reserve side is squarely our work: independent attestation that the reserve exists, is controlled, and covers the tokens in circulation. The legal structuring of an EMT or ART, and the overlap with payment services law where token flows resemble payment processing, are questions for your counsel. If you need both, we slot into the counsel-led engagement as the party that proves the reserve numbers.
We are a non-EU platform. Does MiCA reach us?
If you serve EU-resident clients, assume yes. MiCA allows a narrow reverse solicitation exemption, where a client approaches the firm entirely on their own initiative, and EU supervisors have made clear they read it narrowly: marketing into the EU in any form defeats it. A non-EU platform with a real EU client base needs a CASP authorisation in a member state, and the same platform is very likely also a reporting crypto-asset operator under DAC8. We scope both questions honestly at the start, with your counsel on the legal perimeter, and tell you if the answer is that you are outside the regime.
How long does it take to get ready?
It depends almost entirely on the state of your records and custody arrangements, which is why the engagement starts with scoping rather than a quote. A firm with clean books, documented wallet control, and existing reconciliation discipline can assemble an evidence pack in weeks. A firm whose client asset segregation exists in spirit but not on-chain, or whose ledger has never been tied to chain activity, is looking at a remediation project first, and the honest sequencing is to fix the foundation before asserting anything to a supervisor. The gap assessment gives you that timeline with reasons, not a number invented to win the work.
More questions answered on our general FAQ.
Related Reading
Where do you stand under MiCA?
Tell us what services you provide, where your clients are, and whether you hold or are seeking a CASP authorisation. We will tell you honestly which obligations catch you, what evidence you are missing, and what it takes to close the gaps before a supervisor asks rather than after.
- A clear picture of which MiCA obligations apply to you
- A gap list rated by severity, with the work sequenced
- Evidence your counsel and your supervisor can actually test