MiCA CASP post-authorisation compliance lifecycle timeline illustration on navy background
Back to blog

MiCA CASP Ongoing Obligations After Authorisation: Prudential, Reporting & Compliance Lifecycle

Getting a MiCA CASP authorisation is the starting gate, not the finish line. From day one of your licence, Article 67 prudential requirements run continuously, ESMA's knowledge and competence guidelines apply from 28 July 2026, and AML/TFR obligations under Regulation (EU) 2023/1113 sit entirely outside MiCA's Title V. This guide maps the full post-authorisation compliance stack every authorised CASP must manage.

Contents

Key facts

The Post-Authorisation Compliance Lifecycle: What Changes After You Receive Your CASP Licence

From the date your authorisation is granted, every CASP operates under an always-on compliance clock — the licence is a starting point, not a destination. MiCA does not reward firms for clearing the authorisation hurdle; it immediately imposes a continuous, interlocking set of obligations that must be maintained for as long as the entity operates.

Those obligations span five distinct pillars. First, prudential maintenance: ongoing own-funds or insurance adequacy under Article 67. Second, governance and staffing: fit-and-proper requirements and knowledge and competence standards for relevant staff under Articles 68 and 81(7). Third, client-protection conduct: conflicts of interest, safeguarding, complaints, and wind-down planning under Articles 70–85. Fourth, regulatory reporting to your national competent authority, including material changes and significant-CASP thresholds under Article 83. Fifth, parallel AML and transfer-of-funds obligations under the EU AML framework and Regulation (EU) 2023/1113 — entirely separate from MiCA itself.

Passporting rights under Article 65 add a sixth operational dimension once you scale across borders; that process is covered in the dedicated EU passporting guide. This article focuses on the operational compliance stack every authorised CASP must manage domestically from day one.

Article 67 Prudential Safeguards: Own Funds, Insurance, or Both

Under Article 67 MiCA, an authorised CASP must maintain its prudential safeguard at all times — not merely at the point of authorisation. The required amount is the higher of the fixed Annex IV minimum capital for the firm's service class, or 25% of fixed overheads (the Fixed Overheads Requirement). ESMA Q&A 2349 (answered 18 February 2026 by the Commission) confirms that the overhead base starts from all overheads — both fixed and variable — and only the deductions listed in Article 67(3)(a)–(d) are permitted. That list is exhaustive; no other adjustments are allowed. For firms operating fewer than twelve months, Article 67(2) requires use of projected fixed overheads drawn from the authorisation application — not prior-year actuals.

Article 67(4) permits three forms of prudential safeguard — or any combination of them: (a) own funds, (b) a qualifying professional indemnity insurance policy, or (c) a comparable guarantee. The own-funds route requires capital composed of Common Equity Tier 1 items as defined in Articles 26–30 of Regulation (EU) No 575/2013 (CRR) after the deductions required by Article 36 CRR; the threshold exceptions under Articles 46 and 48 CRR do not apply. The CRR reference is relevant only for the own-funds route — firms electing the insurance or guarantee path operate under a separate set of requirements. A CASP that unnecessarily locks up equity capital without exploring the insurance route may be forgoing a legitimate and potentially more efficient option under the Regulation.

The qualifying insurance path is governed by Articles 67(5)–(6). A compliant policy must: cover all EU territories where the CASP provides services; be publicly disclosed on the CASP's website; carry a minimum initial term of one year; require at least 90 days' written notice to cancel; be placed with an insurer authorised under EU law; and cover the risk categories specified in Article 67(6) — including loss of documents, errors and omissions, business disruption, gross negligence in safeguarding client assets, conflicts-of-interest failures, and CASP liability under Article 75(8). The table below maps Annex IV classes to service types; the classes are cumulative and the applicable minimum is the highest class triggered by the firm's licensed services.

Annex IV Class Minimum Capital Crypto-Asset Services Covered
Class 1 €50,000 Reception & transmission of orders; execution of orders; placing of crypto-assets; investment advice; portfolio management; transfer services for crypto-assets
Class 2 €125,000 All Class 1 services plus custody & administration; exchange for funds; exchange for other crypto-assets
Class 3 €150,000 Operation of a trading platform (alone or combined with other services)

Governance, Wind-Down Plans, and Business Continuity: Articles 68, 74, and the Key Distinctions

Article 68 sets the baseline governance architecture every authorised CASP must maintain on an ongoing basis. The management body must remain fit and proper — competence and good repute are not assessed once at authorisation and forgotten; Article 68(1) requires CASPs to ensure those standards are upheld continuously, and NCAs can reassess them. Separately, Article 72 mandates a documented conflicts-of-interest policy identifying situations where the CASP's interests, its staff's interests, or related parties' interests could damage clients — and the measures taken to manage or disclose those conflicts. Article 73 covers outsourcing: material outsourcing arrangements must not impair internal controls or supervisory access, and the CASP retains full regulatory accountability for any function it delegates.

Article 68(8) requires a separate, documented orderly wind-down plan — a structured plan for permanent cessation of operations. At minimum it must address the sequencing of service wind-down, the return of client assets and funds, notification to the competent NCA, and continuity of client access during the process. NCAs are scrutinising wind-down plans with particular intensity since the July 2026 authorisation wave: ESMA's supervisory briefing flagged inadequate wind-down documentation as a recurring gap in CASP applications. This is a live examination point, not a formality.

Article 74 is distinct. It requires a business continuity policy covering ICT systems, operational failures, and service interruptions — a plan for surviving a disruption and restoring normal operations. The two instruments address different scenarios and must exist as separate, documented policies. ICT continuity under Article 74 also overlaps with DORA obligations for in-scope CASPs; see the DORA compliance guide for CASPs for the interaction.

Dimension Art 68(8) — Wind-Down Plan Art 74 — Business Continuity Policy
Trigger Permanent cessation of operations Operational disruption or ICT failure
Scope Asset return, service sequencing, NCA notification ICT recovery, service restoration, staff procedures
NCA filing Must be available to NCA on request; scrutinised at authorisation and ongoing supervision Must be maintained and testable; NCA may review
Review frequency At minimum annually and after material business change At minimum annually and after significant ICT incidents
DORA overlap Limited Direct — ICT continuity plans must align with DORA RTS

Staff Knowledge and Competence: ESMA Guidelines Under Article 81(7) Applicable from 28 July 2026

On 28 January 2026, ESMA published its Guidelines on knowledge and competence requirements for CASP staff under Article 81(7) MiCA and Article 68(5) MiCA. These are formal Guidelines issued under Article 16 of the ESMA Regulation (EU) No 1095/2010 — not a binding Delegated Regulation or RTS. They operate on a comply-or-explain basis: national competent authorities must notify ESMA whether they comply or intend to comply, and if not, explain why. The Guidelines became applicable across all EU jurisdictions on 28 July 2026, six months after publication in all official EU languages. On 7 July 2026, ESMA published a compliance table showing each NCA's position — firms should verify their home-NCA status before assuming uniform application.

Although Article 81(7) MiCA literally targets CASPs providing advice on crypto-assets, ESMA explicitly extended the scope of these Guidelines to staff providing information about crypto-assets — not only formal advice. ESMA's rationale: all client-facing staff with potential to influence investor decisions must meet a defined competence baseline, regardless of whether their role is formally classified as advisory. This scope expansion is material. A CASP cannot limit compliance to its "advice team" and ignore information-desk or customer-support staff who explain products and services to clients. The Guidelines establish two tiers:

  • Information staff: minimum 80 hours of qualifying training or one year of supervised relevant experience; at least 10 CPD hours per year; competence may be assessed by the CASP itself or an external body.
  • Advisory staff: higher qualification standard; at least 20 CPD hours per year; formal assessment required.

The management body must conduct an annual review of compliance with Articles 68(5) and 81(7) and document its conclusions. NCAs may request training records at any time; failure to maintain adequate documentation exposes the firm to supervisory measures and sanctions under Article 111 MiCA. Practically, every authorised CASP should maintain four artefacts from day one: a staff register identifying each person's tier classification, individual competence records (qualifications and assessment outcomes), a CPD log updated at least annually, and a signed management-body review sign-off. These records should be ready for NCA inspection on short notice — not reconstructed retroactively.

Ongoing Reporting to the NCA: Article 69 and Level 2 Requirements

Article 69 MiCA imposes a standing transparency obligation: an authorised CASP must supply its national competent authority (NCA) with all information necessary to verify ongoing compliance — not merely at the point of authorisation, but continuously throughout the licence lifecycle. This is not a passive duty. NCAs expect CASPs to maintain live communication channels and to escalate proactively rather than wait for supervisory enquiry.

The main reporting streams fall into three categories. First, changes to authorisation conditions: any planned material change to the scope of crypto-asset services, composition of the management body, or holders of key functions (compliance, risk, MLRO) must be pre-notified to the home NCA before implementation, or notified promptly where a change is unplanned. Second, material operational incidents: ICT-related incidents meeting DORA significance thresholds trigger mandatory reporting to the NCA under Regulation (EU) 2022/2554; other material operational events — system outages, custody breaches, liquidity stress — feed into NCA notification under Article 69. For a full treatment of DORA obligations, see our DORA compliance guide for CASPs. Third, EMT and ART data reporting: where a CASP custodies or transfers significant e-money tokens or asset-referenced tokens, Commission Implementing Regulation (EU) 2024/2902 requires periodic data submissions to the token issuer — quarterly figures are due by the 21st of April, July, October and January for the preceding quarter, with daily reporting obligations for tokens exceeding significance thresholds. On the passporting dimension: any variation to services notified to a host NCA under Article 65 must flow through a variation notification via the home NCA — see the EU passporting guide for procedure. Records underpinning all of these streams — orders, transactions, service activities — must be maintained in the form and retention periods specified by Commission Delegated Regulation (EU) 2025/1140.

Reporting event Obligation / legal basis Timing
Change to authorised services or management body Pre-notification or prompt notification — Art. 69 MiCA Before implementation (planned); promptly (unplanned)
Material ICT incident DORA major-incident report — Regulation (EU) 2022/2554 Initial: 4 hours; intermediate: 72 hours; final: 1 month
EMT/ART quarterly data to issuer Commission IR (EU) 2024/2902 By 21st of April, July, October, January
Passporting service variation Variation notice via home NCA — Art. 65 MiCA Before extension of services in host state
Records retention (all services) Commission DR (EU) 2025/1140 Ongoing; minimum 5 years

AML, KYC, and Travel Rule: The Parallel Compliance Stack Outside MiCA Title V

MiCA Title V governs the authorisation and conduct of CASPs — but it does not contain AML or KYC obligations. Those requirements flow from a separate, parallel stack of EU legislation that applies to CASPs as obliged entities in their own right. Confusing these frameworks is a compliance risk: being authorised under MiCA does not satisfy AML obligations, and vice versa.

AML and KYC obligations for CASPs arise from Regulation (EU) 2024/1624 (AMLR) and the applicable AML Directives, which require customer due diligence, beneficial ownership identification, suspicious transaction reporting, and internal AML controls. The Travel Rule — the obligation to accompany crypto-asset transfers with originator and beneficiary information — flows from Regulation (EU) 2023/1113 (TFR). Unlike funds transfers, where a €1,000 threshold applies, the TFR imposes Travel Rule requirements on all crypto-asset transfers involving a CASP, regardless of amount, with only narrow exclusions (e.g. certain person-to-person transfers without a CASP intermediary). From 2027, the newly established Anti-Money Laundering Authority (AMLA) will directly supervise the highest-risk obliged entities — including certain large CASPs — under Regulation (EU) 2024/1620. For deeper analysis of both frameworks, see the AMLA compliance guide and the TFR Travel Rule guide.

Two MiCA articles are frequently misattributed in this context. Article 72 MiCA governs conflicts-of-interest policy — it has no AML content. Article 92 MiCA (Title VI) requires suspicious transaction and order reporting (STOR) for potential market abuse — a distinct, parallel obligation that is not an AML measure. The table below maps each obligation to its correct legal source.

Obligation Legal Source Key Requirement
AML / KYC / CDD Regulation (EU) 2024/1624 (AMLR) + AML Directives Customer due diligence, UBO identification, internal AML controls, STR filing
Travel Rule (crypto transfers) Regulation (EU) 2023/1113 (TFR) Originator and beneficiary data on all CASP-involved transfers; no minimum amount threshold
Direct AML supervision (large CASPs) Regulation (EU) 2024/1620 (AMLA Regulation) AMLA direct oversight from 2027 for highest-risk obliged entities
Market abuse / STOR reporting Article 92 MiCA (Title VI) Report suspicious transactions and orders to competent authority; distinct from AML STRs
Conflicts of interest Article 72 MiCA (Title V) Written policy; identify, manage and disclose conflicts — not an AML obligation

Becoming a Significant CASP: Article 83 Threshold, Process, and Enhanced Obligations

Under Article 83 MiCA, a CASP is designated a significant CASP once it reaches 15 million average active EU users per year. The threshold sounds straightforward, but the calculation methodology matters enormously in practice. Authoritative commentary — including KPMG's MiCA analysis — notes that the operative metric is built from a daily active user average rather than a simple count of unique users over the year. A platform may have 15 million unique EU users who visited once in a twelve-month period, yet fall well below the threshold if the daily active base is substantially smaller. Firms must apply the correct averaging methodology before concluding they are or are not within scope; an incorrect self-assessment in either direction carries regulatory risk.

The procedural trigger is self-monitoring followed by mandatory notification. Once a CASP identifies that it has crossed the threshold, it must notify its NCA within two months; the NCA then forwards that notification to ESMA. Significant status brings materially enhanced obligations: heightened supervisory scrutiny, more granular reporting requirements, and — depending on the outcome of the proposed Market Integration and Supervision Package — the possibility of direct ESMA supervision replacing NCA oversight entirely. Even below the 15 million threshold, ESMA's January 2025 Supervisory Briefing identifies indicators that trigger heightened NCA scrutiny: more than 1 million yearly active users, a balance sheet exceeding €3 billion, more than 200,000 cross-border users, complex group structures, or a combination of trading platform and custody roles.

Practically, this means significant-CASP risk is not a one-time assessment. Firms should implement continuous user-metric tracking — logged, timestamped, and tied to a documented notification-readiness procedure — so that the two-month notification window can be met without internal scramble. The comparison below outlines where standard and significant CASP obligations diverge.

DimensionStandard CASPSignificant CASP (Art. 83)
Primary supervisorNational competent authority (NCA)NCA + ESMA involvement; possible future direct ESMA oversight
Reporting intensityStandard periodic reportingEnhanced reporting; additional data demands from supervisors
Supervisory reviewsRisk-based NCA scheduleHeightened scrutiny; on-site inspections more likely
Governance expectationsArt. 68 baselineGreater senior-management accountability; stricter documentation
Threshold triggerN/A15 million avg. active EU users/year; self-notify NCA within 2 months
Internal monitoring requirementGood practiceEssential; documented notification-readiness procedure required

Post-Authorisation Compliance Calendar: Key Deadlines and Recurring Obligations

Authorisation is not the finish line — it opens a continuous compliance lifecycle with recurring deadlines, annual reviews, and event-driven notifications. The table below maps each core obligation to its correct legal source and cadence. Use it as a baseline checklist; your actual programme will need to layer in NCA-specific requirements and any conditions attached to your authorisation.

Two points warrant emphasis before the table. First, the prudential safeguards review under Article 67 is not purely a year-end exercise: a material change in business volume, service mix, or group structure can trigger an out-of-cycle recalculation. Second, changes notification under Article 69 operates on a prompt basis — there is no grace period to batch-notify your NCA; the obligation attaches on the change itself. For DORA-linked obligations, see also the DORA compliance guide for CASPs; for AML and Travel Rule detail, see the AMLA/AML guide and the TFR compliance guide.

ObligationLegal sourceFrequency / Deadline
Prudential safeguards review (own funds or insurance)Art. 67 MiCAAnnually; also on any material change in business or service scope
Fixed-overheads calculation updateArt. 67 MiCA; ESMA Q&A 2349Annually, based on prior-year audited financials; all overheads (fixed + variable) as the starting base
Insurance policy renewal / adequacy checkArts. 67(5)–(6) MiCAAnnually; policy must maintain minimum one-year term and EU-territory coverage
Staff competence records and CPD logESMA Guidelines (Arts. 68(5) / 81(7) MiCA); applicable from 28 July 2026Ongoing; annual management review of records; comply-or-explain basis
Wind-down plan reviewArt. 68(8) MiCAAt least annually and on any material operational or structural change
Business continuity policy reviewArt. 74 MiCA; DORA (Reg. (EU) 2022/2554)At least annually; DORA testing requirements on their own schedule
Changes notification to NCAArt. 69 MiCAPromptly on each qualifying change; no batching
EMT data reporting to issuerImplementing Reg. (EU) 2024/2902Quarterly aggregate + daily transaction-level reporting
AML / CDD periodic reviewsAMLR; AMLD; Reg. (EU) 2023/1113 (TFR)Risk-based, ongoing; enhanced due diligence for higher-risk relationships
Travel Rule complianceReg. (EU) 2023/1113Ongoing; per-transaction originator / beneficiary data obligations
Market abuse monitoring and STOR filingArt. 92 MiCAOngoing surveillance; STOR filed without delay on reasonable suspicion
Passporting variation notificationArt. 65 MiCAPrior to adding a new service or host Member State; notification-based, not re-authorisation

Frequently asked questions

Can a CASP use a professional indemnity insurance policy instead of holding own funds under Article 67?

Yes. Article 67(4) of MiCA expressly permits prudential safeguards to take the form of own funds (CET1 per CRR Arts 26–30), a qualifying insurance policy covering all EU territories where services are provided, a comparable guarantee, or a combination of these. If the insurance route is chosen, the policy must meet the characteristics in Articles 67(5)–(6): publicly disclosed on the CASP website, initial term of at least one year, 90-day cancellation notice, placed with an authorised EU insurer, and covering the risk categories listed in Article 67(6). Using insurance can preserve balance-sheet capital, but the overhead calculation base remains the same regardless of which form of safeguard is chosen.

What is the difference between the Article 68(8) wind-down plan and the Article 74 business continuity policy?

They serve distinct purposes. Article 68(8) requires a documented orderly wind-down plan covering how the CASP would permanently cease operations while protecting client assets and notifying the NCA — it is a governance document for permanent cessation. Article 74 requires a separate business continuity policy addressing how the CASP maintains or restores services after an operational interruption (ICT failure, disaster, etc.). Conflating them in a single document is a regulatory gap; NCAs expect two separate, cross-referenced policies. DORA also imposes overlapping continuity requirements for ICT systems.

How is the Article 83 significant CASP threshold calculated — annual unique users or daily average?

The 15 million user threshold in Article 83 is expressed as average active EU users per year. However, the calculation methodology uses daily active user averaging across the year rather than counting unique annual users — a distinction that matters for large platforms. A firm with 15 million unique users over a calendar year may still sit below the threshold if its average daily active user count is substantially lower. Firms approaching scale should build ongoing user-metric tracking into their compliance monitoring framework and be ready to self-notify the NCA within two months of crossing the threshold.

Are the ESMA knowledge and competence guidelines under Article 81(7) legally binding?

These are ESMA Guidelines under Article 16 of the ESMA Regulation, not a directly binding EU Regulation or RTS. They operate on a comply-or-explain basis: national competent authorities (NCAs) must notify ESMA whether they comply, do not comply but intend to comply, or do not intend to comply. For CASPs, this means in practice that NCAs in the vast majority of Member States will enforce the guidelines as if they were binding standards. ESMA published its NCA compliance table on 7 July 2026. The guidelines apply from 28 July 2026 to all authorised CASPs. Notably, although Article 81(7) MiCA literally refers only to CASPs providing advice, ESMA explicitly extended the guidelines' scope to staff providing information as well.

What AML and Travel Rule obligations does a MiCA-authorised CASP have, and which MiCA articles cover them?

MiCA Title V does not contain AML/KYC obligations. CASPs remain subject to the EU AML framework — including Regulation (EU) 2024/1624 (AMLR) and the forthcoming AMLA supervision from 2027. The Travel Rule obligation for crypto-asset transfers comes from Regulation (EU) 2023/1113 (the Transfer of Funds Regulation), which applies to all crypto-asset transfers involving a CASP regardless of amount. Within MiCA itself, Article 72 covers conflicts of interest (not AML), and Article 92 governs market abuse suspicious transaction and order reporting (STOR) under Title VI — a separate obligation. Compliance teams must maintain parallel compliance stacks for AML/TFR and MiCA conduct obligations.

When must a CASP notify its NCA of changes after authorisation, and what triggers a passporting variation?

Under Article 69, CASPs must provide the NCA with all information needed to verify ongoing compliance, and any planned material change — to the services provided, management body composition, key function holders, or governance arrangements — must be notified promptly, with some changes requiring prior NCA approval. For passported cross-border services under Article 65, any change to the services or Member States notified in the original passport notification requires a variation notification through the home NCA. Failure to notify a change can expose a CASP to supervisory measures under Article 111, even if the underlying activity is otherwise compliant.

Link copied to clipboard