top of page

MiCA Crypto Compliance Consulting Experts 2026: Ongoing CASP Compliance Guide

  • Aug 8
  • 13 min read
MiCA Crypto Compliance Consulting Experts 2026: Ongoing CASP Compliance Guide

MiCA authorisation is the start of the compliance lifecycle, not the end of it. An authorised crypto-asset service provider must continue meeting Regulation (EU) 2023/1114 across governance, prudential safeguards, safeguarding of client assets and funds, complaints, conflicts, outsourcing, conduct and the activity-specific requirements attached to each authorised cryptoasset service. MiCA also operates alongside DORA, the EU Transfer of Funds Regulation and wider AML, sanctions, data protection and national supervisory requirements.


For firms operating in 2026, ongoing compliance has become especially important because the transitional period for legacy providers is ending across the EU and national competent authorities are moving from authorisation build-out into active supervision. ESMA has made supervisory convergence for CASPs a continuing priority, while 2026 guidance has further developed areas such as staff knowledge and competence. A CASP should therefore maintain evidence that its regulatory framework works in practice rather than treating the authorisation file as a static set of documents.


MiCA CASP compliance requirements at a glance

Compliance area

Principal obligation

MiCA Title V

General organisational, governance and conduct rules for CASPs

Prudential safeguards

Own funds or qualifying insurance based on the higher applicable requirement

Client assets and funds

Segregation, safeguarding, records and return of client assets

Complaints

Effective complaint handling and record keeping

Conflicts of interest

Identification, prevention, management and disclosure

Outsourcing

Written arrangements, risk management, access and continued CASP responsibility

Activity-specific rules

Custody, trading platform, execution, exchange, order handling, advice and transfer requirements

Market abuse

MiCA Title VI controls for inside information and market manipulation

DORA

ICT risk, incidents, testing, third-party risk and operational resilience

EU Travel Rule

Originator and beneficiary information for cryptoasset transfers

AML and sanctions

Risk-based customer, transaction and sanctions controls under EU and national law

Knowledge and competence

Competence standards for relevant staff, including information and advice roles

Reporting and governance

Regulatory submissions, records, board oversight and ongoing supervisory engagement


The exact compliance framework depends on the services authorised. A custody provider, exchange operator, adviser and transfer service provider do not have identical obligations, although they share MiCA's general CASP requirements. Firms should therefore maintain a permission-by-permission obligations map rather than one generic MiCA compliance policy.


MiCA is fully operational for authorised CASPs

MiCA created a harmonised EU regime for cryptoasset service providers and permits authorised CASPs to provide covered services across the Union through the applicable passporting framework. The authorisation is granted by the firm's national competent authority, but ESMA develops common standards and supervisory convergence across Member States. This makes ongoing compliance both a national and EU-level concern.


Legacy transitional arrangements were intended to give firms operating before MiCA sufficient time to move into the new regime, but those arrangements are not a permanent alternative to authorisation. ESMA has repeatedly emphasised that unauthorised provision of cryptoasset services should end when the applicable transition expires. Firms should therefore check the specific transitional position in their home Member State rather than relying on a general EU headline date.


Authorised firms should also remember that passporting does not eliminate all local-law issues. AML supervision, consumer matters and other national requirements can still interact with MiCA depending on the activity and host state. Cross-border expansion should therefore be governed rather than treated as automatic once the licence is received.


Governance must demonstrate sound and prudent management

MiCA requires CASPs to have effective governance, appropriate management and organisational arrangements proportionate to their activities. Members of the management body need sufficient good repute, knowledge, skills and experience, while shareholders and qualifying holders are subject to regulatory suitability requirements. Governance should therefore remain a live compliance function after authorisation.


The board should receive information covering prudential position, client assets, financial crime, complaints, conflicts, outsourcing, operational resilience and material regulatory issues. Management information should allow the board to identify deterioration or emerging risk rather than simply confirm that each policy exists. Decisions on new products, tokens, jurisdictions or critical service providers should include a regulatory impact assessment.


Changes to ownership or management can also trigger notification or approval requirements. Firms should maintain a regulatory change process that considers whether a corporate transaction, new director or restructuring needs competent-authority engagement before implementation. Group decisions should not bypass the regulated entity's governance obligations.


MiCA prudential safeguards continue after authorisation

CASPs must maintain prudential safeguards equal to at least the higher of the applicable fixed minimum capital requirement and the relevant fixed-overheads requirement under MiCA. The fixed minimum depends on the class of cryptoasset services and broadly ranges from EUR 50,000 to EUR 150,000. Firms should therefore monitor both service permissions and expenditure as the business changes.


A growing CASP can become subject to a higher practical capital need even where its permission class does not change. Staff growth, technology expenditure and other relevant costs can increase the fixed-overheads component, while losses can reduce available own funds. Finance and compliance should therefore monitor headroom and escalation thresholds throughout the year.


Prudential safeguards can be met through own funds, qualifying insurance or a combination subject to MiCA conditions. The firm should confirm that any insurance arrangement actually satisfies the regulatory criteria rather than treating ordinary commercial liability cover as a substitute. The capital plan should also be consistent with the business and wind-down plan.


Client cryptoassets and funds require robust safeguarding

A CASP holding client cryptoassets should make adequate arrangements to safeguard ownership rights and prevent use of those assets for the firm's own account. Records should allow client positions to be identified and reconciled, and the firm should have processes for returning assets if the relationship ends or the CASP fails. Custody agreements and technology should therefore operate as one control framework.


Where the CASP holds client funds, MiCA contains requirements intended to protect those funds and separate them appropriately from the firm's own assets. Firms should understand the role of banks or other institutions in the custody chain and maintain evidence of due diligence and contractual protections. Customer money should not become an unmanaged treasury resource simply because it sits temporarily within the platform.


Custody architecture should also be tested operationally. Private keys, multi-signature controls, multi-party computation, wallet allocation and recovery processes need appropriate access controls and segregation of duties. A legal policy cannot compensate for weak means-of-access security.


Custody providers need detailed operational controls

A CASP providing custody and administration of cryptoassets on behalf of clients has activity-specific MiCA obligations. The custody policy, agreement and internal records should define the service, customer rights, security arrangements and the firm's responsibilities. The CASP needs controls capable of maintaining accurate positions and handling events such as forks, protocol changes or loss of access appropriately.


Third-party sub-custody should be governed carefully. The authorised CASP remains responsible for meeting its MiCA obligations and should conduct due diligence, maintain contractual rights and understand the legal and operational risks created by the provider. International custody chains may also create insolvency and jurisdictional questions that need legal analysis.


Incident and loss processes should be explicit. The firm should know how it will identify compromised keys, suspend activity where necessary, communicate with customers and restore service. DORA and MiCA should be considered together because a custody failure can be both a client-asset and ICT incident.


Trading platforms face specific MiCA requirements

A CASP operating a trading platform for cryptoassets is subject to additional requirements concerning operating rules, access, order handling, transparency and market integrity. The platform should have clear rules governing admission and trading and ensure that its systems can operate reliably at the expected scale. Governance should consider both customer protection and orderly market functioning.


ESMA has also clarified that an EU-authorised platform cannot simply pool its order book with non-EU entities that are not authorised where that would amount to unauthorised operation of the trading platform service in the Union. Global exchange groups should therefore map the legal entity that manages order books and liquidity rather than assuming technology integration is neutral from a regulatory perspective. Cross-border architecture can directly affect the permission analysis.


Trading data should support surveillance and supervisory requests. The firm should retain sufficient records to reconstruct orders and transactions and investigate suspicious patterns. Market abuse compliance therefore needs to be designed into the trading infrastructure rather than added as an external review after launch.


Execution, exchange and order handling each create conduct duties

CASPs executing orders, exchanging cryptoassets for funds or other cryptoassets, receiving and transmitting orders or providing related brokerage services have activity-specific obligations under MiCA. Policies should explain how orders are handled, how pricing is determined and how conflicts are managed. The firm should also ensure customer disclosures match the service actually delivered.


Where best execution or similar conduct requirements apply to the service, the CASP should be able to demonstrate how execution arrangements are designed and monitored. Venue selection, spreads, liquidity and group conflicts can all affect customer outcomes. Automated execution should be subject to governance and testing.


Order-handling systems should maintain appropriate records and prevent misuse of client information. Staff access, personal dealing and conflicts should be controlled where relevant. The design should follow the authorised service rather than simply adopt practices from an unregulated exchange model.


Advice and portfolio services require knowledge and competence

MiCA contains specific requirements for CASPs providing advice on cryptoassets or portfolio management, and ESMA published final knowledge and competence guidelines in January 2026. Firms should identify which employees provide information or advice and ensure that training, experience and supervision satisfy the applicable standard. Competence should be demonstrated and maintained rather than inferred from general crypto industry experience.


Suitability and customer information requirements also become important where advice or portfolio management is provided. The firm should gather enough information to understand the customer's knowledge, experience, objectives and circumstances according to the applicable MiCA framework. Records should explain why the recommendation or service is appropriate.


Marketing and advice should also be separated clearly. Content that appears educational can become personalised or influential enough to engage regulated conduct depending on the context. Governance should therefore cover digital channels, influencers and staff communications rather than only formal advice meetings.


Complaints handling must be formal and auditable

MiCA requires CASPs to establish and maintain effective and transparent procedures for the prompt, fair and consistent handling of client complaints. The process should be accessible, documented and supported by records showing how complaints were investigated and resolved. Customer support tickets should be classified correctly so that regulatory complaints are not lost inside ordinary service queues.


Complaint data should feed into governance and product review. Recurring issues with withdrawals, execution, fees, custody or customer communications can identify systemic weaknesses. Root-cause analysis should determine whether remediation needs to extend beyond the individual complainant.


Cross-border CASPs should also understand language and host-state practical requirements. A passported service should remain accessible to customers in the markets the firm targets. Complaint handling should therefore form part of the expansion plan rather than being designed only around the home-state customer base.


Conflicts of interest require structured management

CASPs must identify, prevent, manage and disclose conflicts of interest. Crypto business models can create conflicts between the firm, group companies, token issuers, market makers, employees and customers, particularly where the same group operates a trading venue, provides liquidity, lists tokens and holds customer assets. A generic conflicts policy may not capture those structural issues.


The firm should maintain a conflicts inventory and assess how each material conflict is controlled. Organisational separation, disclosure, restrictions, independent decision-making and monitoring can each play a role depending on the risk. The objective is not to rely on disclosure where the conflict can be prevented or managed more effectively.


Token listing and commercial relationships deserve particular attention. Revenue-sharing, proprietary holdings or group incentives can influence decisions that affect customers or market integrity. Governance should ensure that commercial teams cannot bypass regulatory approval where a material conflict exists.


MiCA outsourcing does not transfer accountability

A CASP can outsource functions, including important or critical activities, subject to MiCA and DORA requirements. The firm remains fully responsible for its regulatory obligations and should retain enough expertise and access to supervise the provider. Contracts should define services, information rights, security, audit, sub-outsourcing, continuity and exit.


Outsourcing risk is especially significant where custody, cloud infrastructure, blockchain analytics, KYC, Travel Rule messaging or trading technology is externally provided. A failure in one vendor can affect several regulatory obligations simultaneously. The firm should therefore map dependencies and concentration rather than review each contract in isolation.


Ongoing monitoring should be risk-based. Changes in the provider's financial condition, security, jurisdiction or regulatory status can alter the risk profile even where the service remains technically available. Exit planning should be credible enough to maintain customer protection during transition.


DORA applies alongside MiCA

The Digital Operational Resilience Act applies to relevant financial entities, including CASPs, and creates a detailed ICT risk management framework. Firms need governance over ICT risk, incident management, resilience testing, third-party risk and contractual arrangements. MiCA compliance should therefore be designed alongside DORA rather than through separate technology and compliance projects.


Important systems should be mapped to the regulated services they support. Exchanges, custody platforms, blockchain nodes, cloud infrastructure, identity systems and third-party APIs can each become critical dependencies. The firm should understand how disruption affects customers and what recovery capability exists.

ICT incidents should be classified and escalated according to DORA requirements, with records supporting regulatory reporting where thresholds are met. Scenario testing should also consider crypto-specific events such as key compromise or chain disruption. Board oversight should focus on residual vulnerabilities and remediation rather than technical detail alone.


The EU Travel Rule is a separate but connected obligation

Regulation (EU) 2023/1113 extends transfer-of-funds information requirements to cryptoasset transfers. CASPs need processes for collecting, verifying and transmitting required originator and beneficiary information and for dealing with incomplete or problematic transfer data. Self-hosted addresses can create additional verification requirements depending on the value and circumstances of the transfer.


Travel Rule implementation requires technology integration and counterparty governance. The firm should understand which messaging solution it uses, how data is matched to blockchain transactions and how cases are handled where the counterparty CASP cannot exchange the required information. Privacy and data-security controls should be considered at the same time.


The Travel Rule should connect with AML and sanctions monitoring rather than operate as a separate data exercise. Originator and beneficiary information can improve risk assessment and investigation, while discrepancies may require escalation. Compliance monitoring should test the completeness and accuracy of transmitted data.


AML and sanctions remain critical under MiCA

MiCA does not replace the EU AML framework. CASPs are obliged entities and need risk-based customer due diligence, beneficial ownership checks, enhanced due diligence, ongoing monitoring, suspicious transaction reporting and sanctions controls under applicable EU and national requirements. The framework should reflect crypto-specific risks such as self-hosted wallets, mixers, cross-chain activity, high-risk jurisdictions and rapid movement of value.


Blockchain analytics can support monitoring but should be governed carefully. Firms should understand vendor methodologies, risk labels, threshold calibration and false-positive behaviour rather than accepting automated risk scores without challenge. Investigators should combine on-chain information with customer and transactional context.


Sanctions controls need similar depth. Wallet screening, customer screening, ownership and control analysis and transaction counterparties may all be relevant. The firm should have processes for responding quickly to list changes and for documenting decisions on potential matches.


MiCA market abuse rules apply to crypto markets

Title VI of MiCA creates a dedicated market abuse regime covering inside information, insider dealing, unlawful disclosure and market manipulation in relation to cryptoassets within scope. Trading platforms and other market participants need controls capable of detecting and escalating suspicious behaviour. Traditional surveillance models may require adaptation because crypto markets operate continuously and can involve fragmented liquidity and on-chain activity.


The firm should understand who has access to potentially inside information and how that information is protected. Token listings, major partnerships, protocol events and issuer information can create market-sensitive circumstances. Staff dealing and personal account activity should be governed where relevant.


Surveillance should be calibrated and tested. Large volumes of alerts do not demonstrate effective compliance if investigations are superficial or backlogged. Governance should track alert quality, trends and significant cases and ensure suspicious activity is reported through the required channels.


Regulatory reporting and record keeping should be designed into systems

MiCA and associated technical standards create reporting and record-keeping requirements that vary by service. Firms should identify the required data fields and retention periods and ensure operational systems capture information in a form that can be reproduced accurately. Manual reconstruction after an NCA request is both inefficient and risky.


Records should support customer activity, orders, transactions, custody positions, complaints, conflicts, outsourcing and prudential monitoring as applicable. Data ownership and quality controls should be documented. Changes to systems should consider whether required regulatory evidence will remain available after migration.


Supervisory requests can also extend beyond routine reporting. A CASP should maintain a regulatory-response process that coordinates compliance, legal, technology and operations and preserves version control. The quality of regulatory information influences the authority's confidence in the wider control framework.


A practical ongoing MiCA compliance programme

The first layer should be a detailed obligations register mapped to the services for which the CASP is authorised. Each obligation should identify the legal source, policy, operational control, responsible owner, evidence and monitoring activity. This prevents the common problem of maintaining a large authorisation document set without a clear link to day-to-day operations.


The second layer is assurance. Prudential calculations, custody records, complaints, Travel Rule data, AML controls, outsourcing and DORA processes should be tested using real evidence, with the frequency based on risk and previous findings. New tokens, products, jurisdictions or group arrangements should trigger change assessments before launch.


The final layer is governance and remediation. Board MI should identify material risks and trends and demonstrate that findings are resolved sustainably. A CASP that can evidence this cycle is better positioned for NCA supervision than one whose compliance framework exists primarily in policies created for the original licence application.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting provides MiCA CASP licensing and compliance support for crypto exchanges, custodians, brokers and digital-asset platforms operating across Europe. We can undertake complete MiCA gap assessments covering permissions, governance, prudential safeguards, custody, complaints, conflicts, outsourcing, DORA, AML, Travel Rule, market abuse and the activity-specific requirements attached to the firm's authorised services. The work is tailored to the home jurisdiction and actual operating model rather than built around a generic MiCA checklist.


For authorised CASPs, we can establish or review the ongoing compliance programme, including regulatory obligations mapping, compliance monitoring, board MI, prudential monitoring, regulatory change and remediation. We can also support firms that need to transition from a legacy VASP framework into MiCA-level operational controls or prepare for supervisory review after authorisation. Where a CASP also provides payment or e-money services, our payments specialism allows the interaction between MiCA and payment regulation to be addressed within the same group strategy. To discuss MiCA compliance consulting, a CASP gap assessment, ongoing compliance support or European authorisation, contact Buckingham Capital Consulting.


Frequently asked questions

What ongoing compliance does a MiCA-authorised CASP need?

An authorised CASP must continue satisfying MiCA's governance, prudential, conduct, complaints, conflicts, outsourcing and activity-specific requirements. DORA, the EU Travel Rule, AML, sanctions and national supervisory requirements also apply alongside MiCA. The exact programme depends on the services authorised.


How much capital does a CASP need under MiCA?

MiCA sets class-based fixed minimum capital requirements broadly ranging from EUR 50,000 to EUR 150,000 depending on the services provided. The CASP must maintain prudential safeguards equal to at least the higher of the relevant fixed amount and the applicable fixed-overheads requirement. Growth in expenditure can therefore increase the practical requirement even where permissions do not change.


Does DORA apply to MiCA crypto firms?

Yes, relevant CASPs are within the DORA operational-resilience framework. They need ICT risk governance, incident management, resilience testing, third-party controls and appropriate contractual arrangements. DORA should be integrated with MiCA outsourcing and operational governance rather than treated as a separate technology project.


What is the MiCA Travel Rule?

The cryptoasset Travel Rule comes from Regulation (EU) 2023/1113 rather than MiCA itself, but it operates alongside the MiCA CASP regime. CASPs need to collect, transmit and verify required originator and beneficiary information for cryptoasset transfers and deal appropriately with incomplete information and self-hosted addresses. The process should connect with AML and sanctions controls.


Can one MiCA licence be used across the EU?

An authorised CASP can use MiCA's cross-border framework to provide authorised cryptoasset services across the EU, subject to the applicable notification process and continuing compliance. The home NCA remains central to supervision, while host-state and other legal requirements can still apply. Firms should therefore govern passporting and market entry rather than assuming all cross-border obligations disappear after authorisation.


#MiCA Crypto Compliance Consulting Experts 2026: Ongoing CASP Compliance Guide

 
 
bottom of page