MiCAR Compliance Checklist 2026: Everything a CASPs Operator Needs to Do Before Year-End

A practical 12-step checklist for crypto asset service providers navigating MiCAR authorization — from AML/CFT programs to market abuse controls.

MiCAR Compliance Checklist 2026: Everything a CASPs Operator Needs to Do Before Year-End

The Markets in Crypto-Assets Regulation — MiCAR, Reg (EU) 2023/1114 — became applicable for CASPs on **30 December 2024**. If you are operating as a Crypto Asset Service Provider without meeting the authorization requirements, you are operating illegally in the EU.

This is not an academic concern. National competent authorities — BaFin, AMF, ACMF, and others — have already opened enforcement proceedings. The window to get compliant is narrowing.

This checklist covers every authorization requirement, what evidence regulators expect to see, and how Arkē's three-pillar platform maps to the obligations.


Who Must Comply

MiCAR distinguishes between:

**This checklist is written for CASP operators.** If you also issue ARTs or EMTs, additional obligations apply under Titles III and IV respectively.


The 12-Step Authorization Checklist

1. Appoint a Board That Passes the "Stress Test"

MiCAR Art. 3 requires that CASP directors and persons with management responsibilities demonstrate **sufficient expertise and good repute**.

**What to prepare:** Individual file per board member including DBS-equivalent certificates, CV, and a signed self-declaration of conflicts of interest.


2. Establish a Governance Framework

Art. 3 requires an appropriate governance structure including clear organizational chart, separation of duties, and internal control functions.

**Red flag:** Regulators have rejected applications where the MLRO reported to the COO rather than directly to the board. Independence matters.


3. Build an AML/CFT Program That Goes Beyond FCA Box-Ticking

Art. 3 and the companion AMLD6 (Directive (EU) 2026/XXXX — in force from Q1 2026) create a combined AML/CFT framework with teeth.

**What to prepare:** AML manual, risk assessment framework, on-boarding procedures, SAR filing procedure.


4. Write a White Paper (If Issuing Crypto Assets)

Art. 6 requires a crypto asset white paper for any crypto assets offered to the public in the EU — unless an exemption applies (e.g., automated trading, limited to qualified investors, or existing tokens where a white paper was already published under national law).

For CASPs offering services on third-party tokens, you typically do not need a white paper — but consult your national regulator, as the rules vary by member state implementation.

**If you are issuing your own token:** The white paper must be published free of charge, registered with the national competent authority, and include a clear description of the token's purpose, technical characteristics, and risk factors. Updating the white paper after launch triggers a new notification obligation.


5. Capital Requirements — Choose Your Category and Build the Buffer

Art. 14 specifies three tiers of own funds requirements:

| Service Category | Minimum Own Funds |
|---|---|
| Custody/administration + exchange | €125,000 |
| Trading platform operation | €150,000 |
| Advice + portfolio management | €75,000 |
| Multiple services | Highest applicable requirement |

The own funds must be permanently available — no cross-collateralization with operational funds, no relying on credit lines.

**What to prepare:** Capital adequacy model, minimum threshold calculation, 12-month cash flow projection, bank confirmation of available funds.


6. Implement Client Asset Safeguarding (If Holding Crypto Assets)

Art. 34–36 applies to CASPs that hold crypto assets on behalf of clients. Requirements:

**What to prepare:** Wallet management policy, segregation protocol, insolvency scenario runbook, reconciliation logs.


7. Market Abuse Controls — Article 51–59

MiCAR Title VII introduces market abuse rules for crypto assets admitted to trading. If you operate a trading platform (MTF or CTP), you must:

Even if you are not operating a platform, if you trade your own token or manage a portfolio, insider dealing rules apply to your operations.

**What to prepare:** Market surveillance procedures, trade surveillance system documentation, insider register, market abuse policy, SAR reporting mechanism for market abuse.


8. Complaint Handling and Dispute Resolution

Art. 37 requires every CASP to have a complaint handling procedure accessible in the official language(s) of the member state. Consumers must receive an acknowledgment within 24 hours and a final response within 15 business days.

Additionally, for cross-border disputes you must be a member of an accredited out-of-court dispute resolution scheme (Art. 40).

**What to prepare:** Complaint handling procedure, complaint log, membership certificate for the relevant out-of-court scheme (e.g., FIN-NET for cross-border disputes).


9. Disclosure Obligations — Risk Warnings

These disclosures must be provided in a durable medium or on your platform in a way that is continuously accessible.

**What to prepare:** Standard risk disclosure template, fee schedule, client agreement with embedded disclosures.


10. ICT Security — Art. 53–59

This overlaps with DORA (Regulation (EU) 2022/2554) for CASPs that also provide services to financial institutions.

**What to prepare:** ICT security policy, pen-test report, incident response runbook, backup schedule documentation.


11. MiFID II Integration — Scope and Exemptions

If your firm holds an existing MiFID II investment firm license, you can add CASP services via a supplemental passport application (Art. 56). The NCA will assess the additional CASP services under MiCAR requirements regardless of the MiFID II authorization.

Firms currently operating under national transitional regimes (e.g., French PSAN register, German Kryptoverwahrstellenerlaubnis) must apply for full CASP authorization before the national transitional period ends. The Commission has set 30 June 2026 as the outer limit for most of these regimes — **check your national implementation**.


12. Complete and Submit the Authorization Application

The authorization application to your national competent authority (NCA) must include:

1. Program of operations
2. Instruments of incorporation
3. Proof of initial capital
4. Directors' fitness and probity files
5. Governance arrangements documentation
6. AML/CFT program description
7. ICT security framework documentation
8. Safeguarding arrangement description (if applicable)
9. Complaint handling procedures
10. Market abuse controls (if operating a trading platform)

NCAs are required to respond within 3 months for complete applications, 6 months for incomplete ones. **Start your application now** — the queue is growing.


How Arkē Maps to These Requirements

| MiCAR Requirement | Arkē Pillar | How Arkē Helps |
|---|---|---|
| AML/CFT program | Screening | Real-time sanctions/PEP/adverse media screening in <5s, risk scores 0–100 |
| Market abuse controls | Monitoring | AML typology detection across transaction batches |
| SAR filing | Reporting | FIU-format SAR draft generation |
| ICT security | All pillars | AES-256 encryption, TLS 1.3, GDPR Art. 28 processor status |
| Client risk assessment | Screening | Structured adverse media search, UBO enrichment |
| Ongoing monitoring | Monitoring | Batch CSV/JSON transaction monitoring with full audit trail |


Timeline and Priorities


Key Deadlines to Track


*This checklist is for informational purposes and does not constitute legal advice. Consult a qualified regulatory counsel for your specific jurisdiction.*

*→ [View Arkē's full regulatory framework →](/regulations#micar)*

See Arkē's MiCAR coverage

Real-time sanctions screening, PEP checks, and adverse media — mapped to your MiCAR authorization requirements.

See Arkē's MiCAR coverage →
← Back to All Posts Try Arkē Screen Counterparty