MiCAR Compliance Checklist 2026: Everything a CASPs Operator Needs to Do Before Year-End
The Markets in Crypto-Assets Regulation — MiCAR, Reg (EU) 2023/1114 — became applicable for CASPs on **30 December 2024**. If you are operating as a Crypto Asset Service Provider without meeting the authorization requirements, you are operating illegally in the EU.
This is not an academic concern. National competent authorities — BaFin, AMF, ACMF, and others — have already opened enforcement proceedings. The window to get compliant is narrowing.
This checklist covers every authorization requirement, what evidence regulators expect to see, and how Arkē's three-pillar platform maps to the obligations.
Who Must Comply
MiCAR distinguishes between:
- **CASPs (Crypto Asset Service Providers):** Firms providing one or more of the following services commercially to third parties — custody and administration of crypto assets, operation of a trading platform, exchange of crypto assets for fiat or other crypto assets, execution of orders on behalf of clients, placing of crypto assets, advice on crypto assets, or portfolio management.
- **ARTs (Asset-Referenced Tokens):** Token issuers subject to Title III — significant ART issuers fall under the European Banking Authority.
- **EMTs (E-money Tokens):** Token issuers subject to Title IV.
**This checklist is written for CASP operators.** If you also issue ARTs or EMTs, additional obligations apply under Titles III and IV respectively.
The 12-Step Authorization Checklist
1. Appoint a Board That Passes the "Stress Test"
MiCAR Art. 3 requires that CASP directors and persons with management responsibilities demonstrate **sufficient expertise and good repute**.
- Compile a CV and fitness-and-probity dossier for every board member and MLRO
- Include criminal record checks (expanded to all EU jurisdictions under AMLD6)
- Regulators expect the board to demonstrate understanding of crypto-specific risks — token volatility, smart contract exposure, oracle manipulation — not just financial services experience
- If you have a shareholder with >25% holdings, that person's suitability is also assessed
**What to prepare:** Individual file per board member including DBS-equivalent certificates, CV, and a signed self-declaration of conflicts of interest.
2. Establish a Governance Framework
Art. 3 requires an appropriate governance structure including clear organizational chart, separation of duties, and internal control functions.
- Written governance policy approved by the board
- Terms of reference for all committees (Risk, Audit, Compliance)
- Succession planning
- Conflict of interest policy with mandatory disclosure
**Red flag:** Regulators have rejected applications where the MLRO reported to the COO rather than directly to the board. Independence matters.
3. Build an AML/CFT Program That Goes Beyond FCA Box-Ticking
Art. 3 and the companion AMLD6 (Directive (EU) 2026/XXXX — in force from Q1 2026) create a combined AML/CFT framework with teeth.
- Conduct risk assessments updated at least annually — not static templates
- Apply CDD on all new clients, enhanced due diligence for high-risk clients (PEP exposure, non-face-to-face onboarding, high-volume wallets)
- Screen against all applicable sanctions lists (EU, UN, OFAC as applicable) — real-time for new onboarding, batch for existing clients
- Maintain a UBO register (25%+ threshold)
- File SARs when you suspect money laundering — **do not wait for certainty**, file on reasonable grounds to suspect
- Preserve records for 5 years minimum
**What to prepare:** AML manual, risk assessment framework, on-boarding procedures, SAR filing procedure.
4. Write a White Paper (If Issuing Crypto Assets)
Art. 6 requires a crypto asset white paper for any crypto assets offered to the public in the EU — unless an exemption applies (e.g., automated trading, limited to qualified investors, or existing tokens where a white paper was already published under national law).
For CASPs offering services on third-party tokens, you typically do not need a white paper — but consult your national regulator, as the rules vary by member state implementation.
**If you are issuing your own token:** The white paper must be published free of charge, registered with the national competent authority, and include a clear description of the token's purpose, technical characteristics, and risk factors. Updating the white paper after launch triggers a new notification obligation.
5. Capital Requirements — Choose Your Category and Build the Buffer
Art. 14 specifies three tiers of own funds requirements:
| Service Category | Minimum Own Funds |
|---|---|
| Custody/administration + exchange | €125,000 |
| Trading platform operation | €150,000 |
| Advice + portfolio management | €75,000 |
| Multiple services | Highest applicable requirement |
The own funds must be permanently available — no cross-collateralization with operational funds, no relying on credit lines.
**What to prepare:** Capital adequacy model, minimum threshold calculation, 12-month cash flow projection, bank confirmation of available funds.
6. Implement Client Asset Safeguarding (If Holding Crypto Assets)
Art. 34–36 applies to CASPs that hold crypto assets on behalf of clients. Requirements:
- Client crypto assets must be held in cold storage except where real-time liquidity needs justify hot wallets
- Segregation: client assets must be identifiable separately from the firm's own assets
- In case of insolvency, client assets must be excluded from the CASP's estate
- Record-keeping of all client asset positions in real-time
- Regular reconciliation (daily recommended for hot wallets, weekly for cold)
**What to prepare:** Wallet management policy, segregation protocol, insolvency scenario runbook, reconciliation logs.
7. Market Abuse Controls — Article 51–59
MiCAR Title VII introduces market abuse rules for crypto assets admitted to trading. If you operate a trading platform (MTF or CTP), you must:
- Establish surveillance systems to detect insider dealing, market manipulation, and unlawful disclosure
- Report suspicious transactions to the national competent authority
- Maintain order books and trade reporting for 5 years
- Publish a market abuse policy
Even if you are not operating a platform, if you trade your own token or manage a portfolio, insider dealing rules apply to your operations.
**What to prepare:** Market surveillance procedures, trade surveillance system documentation, insider register, market abuse policy, SAR reporting mechanism for market abuse.
8. Complaint Handling and Dispute Resolution
Art. 37 requires every CASP to have a complaint handling procedure accessible in the official language(s) of the member state. Consumers must receive an acknowledgment within 24 hours and a final response within 15 business days.
Additionally, for cross-border disputes you must be a member of an accredited out-of-court dispute resolution scheme (Art. 40).
**What to prepare:** Complaint handling procedure, complaint log, membership certificate for the relevant out-of-court scheme (e.g., FIN-NET for cross-border disputes).
9. Disclosure Obligations — Risk Warnings
- The nature and risks of the crypto assets involved
- Your fees and charges (complete, transparent, non-conflicting)
- Whether you act as principal or agent
- Applicable safeguard arrangements
These disclosures must be provided in a durable medium or on your platform in a way that is continuously accessible.
**What to prepare:** Standard risk disclosure template, fee schedule, client agreement with embedded disclosures.
10. ICT Security — Art. 53–59
- Business continuity and disaster recovery
- Backup and recovery procedures
- Cyber incident response plan
- Penetration testing at least annually (pen-test report to be submitted to NCA)
- Cryptographic key management
- Data classification and access controls
This overlaps with DORA (Regulation (EU) 2022/2554) for CASPs that also provide services to financial institutions.
**What to prepare:** ICT security policy, pen-test report, incident response runbook, backup schedule documentation.
11. MiFID II Integration — Scope and Exemptions
If your firm holds an existing MiFID II investment firm license, you can add CASP services via a supplemental passport application (Art. 56). The NCA will assess the additional CASP services under MiCAR requirements regardless of the MiFID II authorization.
Firms currently operating under national transitional regimes (e.g., French PSAN register, German Kryptoverwahrstellenerlaubnis) must apply for full CASP authorization before the national transitional period ends. The Commission has set 30 June 2026 as the outer limit for most of these regimes — **check your national implementation**.
12. Complete and Submit the Authorization Application
The authorization application to your national competent authority (NCA) must include:
1. Program of operations
2. Instruments of incorporation
3. Proof of initial capital
4. Directors' fitness and probity files
5. Governance arrangements documentation
6. AML/CFT program description
7. ICT security framework documentation
8. Safeguarding arrangement description (if applicable)
9. Complaint handling procedures
10. Market abuse controls (if operating a trading platform)
NCAs are required to respond within 3 months for complete applications, 6 months for incomplete ones. **Start your application now** — the queue is growing.
How Arkē Maps to These Requirements
| MiCAR Requirement | Arkē Pillar | How Arkē Helps |
|---|---|---|
| AML/CFT program | Screening | Real-time sanctions/PEP/adverse media screening in <5s, risk scores 0–100 |
| Market abuse controls | Monitoring | AML typology detection across transaction batches |
| SAR filing | Reporting | FIU-format SAR draft generation |
| ICT security | All pillars | AES-256 encryption, TLS 1.3, GDPR Art. 28 processor status |
| Client risk assessment | Screening | Structured adverse media search, UBO enrichment |
| Ongoing monitoring | Monitoring | Batch CSV/JSON transaction monitoring with full audit trail |
Timeline and Priorities
- If you are not yet authorized — this is your single most critical business priority. Operating without authorization is a criminal offence in most member states.
- Engage a regulatory counsel with MiCAR experience in your jurisdiction.
- Submit your application to your NCA.
- Complete steps 1, 2, 3, 5, and 9 — these are the most common rejection reasons.
- Engage your NCA's pre-application meeting if offered (most offer informal pre-application discussions).
- Steps 4–12 become live obligations. Implement them before you go live with any new service.
Key Deadlines to Track
- **30 June 2026:** National transitional regimes expire for most existing operators
- **Q4 2026:** ESMA guidelines on CASP authorization expected to be finalized
- **Q1 2027:** AMLA Regulation (AMLD6 companion) enters application — additional UBO and corporate liability requirements
*This checklist is for informational purposes and does not constitute legal advice. Consult a qualified regulatory counsel for your specific jurisdiction.*
*→ [View Arkē's full regulatory framework →](/regulations#micar)*