Skip to content
Skip article header Business

MiCA Compliance Cost in 2026: CASP Authorisation, Software and Ongoing Spend

What MiCA compliance costs in 2026: CASP authorisation and capital, compliance software and tooling, ongoing and DORA spend, build vs buy, and the cost of getting it wrong.

5 min read 15 views

There is no single price tag for MiCA compliance. The cost of operating legally under the EU Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) depends on which crypto-asset services you provide, what tokens you issue, how many member states you target and how much you build versus buy. This article breaks the cost into the parts you can actually verify, and flags where published figures stop and quote-based pricing begins.

It is a budgeting guide, not legal or financial advice. If you want the software portion scoped to a fixed estimate, see our MiCA compliance software development or run the readiness scorecard.

What drives MiCA compliance cost

Four variables move the number more than anything else:

  • Scope of CASP services. Authorisation for custody or operating a trading platform carries higher capital and control requirements than advice or order transmission.
  • Token types. Issuing an asset-referenced token (ART) or e-money token (EMT) adds reserve management, redemption and white paper obligations on top of the service layer.
  • Jurisdictions. One MiCA authorisation passports across all 27 member states, but the national competent authority you choose sets the fees and supervisory intensity.
  • Build versus buy. The biggest swing is whether you build proprietary compliance software, license vendor tools, or start on a licensed CASP-as-a-service partner.

Authorisation and capital cost

MiCA sets minimum own-funds requirements by authorisation class. You must hold the higher of the class floor or 25% of your prior-year fixed overheads (MiCA Article 67 and Annex IV).

Class Services included Minimum own funds
Class 1 Advice, reception and transmission of orders, execution, placing, transfer services, portfolio management 50,000 euro
Class 2 Class 1 plus custody and administration, exchange of crypto-assets for funds or other crypto-assets 125,000 euro
Class 3 Class 2 plus operating a trading platform 150,000 euro

Own funds are capital you hold, not a fee you spend. The spend is in getting authorised: drafting the programme of operations and AML programme, plus the application itself. Industry estimates put legal and advisory work to prepare a CASP authorisation in the region of 80,000 to 200,000 euro, with most national application fees in a 5,000 to 25,000 euro range. Several regulators, including Germany’s BaFin, charge time-based rather than fixed fees, so there is no single published number to quote.

Compliance software and tooling cost

This is where build-versus-buy decides the budget. A CASP needs onboarding, screening, monitoring, Travel Rule, proof of reserves and reporting. You can assemble these from vendors, build them, or both.

  • KYC and onboarding. Public per-verification pricing starts around 1 to 1.50 US dollars per check (for example Sumsub), scaling with volume.
  • Transaction monitoring and analytics (KYT). Chainalysis, TRM Labs and Elliptic price by quote, not a public page. A CASP analytics budget commonly lands in the low-to-mid six figures per year.
  • Travel Rule. Notabene and 21 Analytics are subscription, quote-based; budget a five-figure annual subscription.
  • Security attestations. A SOC 2 Type II audit fee runs roughly 15,000 to 30,000 US dollars, and 60,000 to 100,000 all-in with readiness, tooling and a penetration test (Secureframe).

For the custom build itself, Pharos Production scopes a focused MiCA compliance system from about 60,000 US dollars for a module set to 500,000 and up for a full CASP or issuer control suite with custody integration and surveillance. The driver is the number of in-scope services, token types and integrations, not headcount.

Ongoing and year-two cost

Authorisation is the start, not the finish. The recurring cost is where most budgets are underestimated.

  • DORA operational resilience. The Digital Operational Resilience Act applies to CASPs from 17 January 2025. In a Deloitte survey, 64% of financial entities expected to spend 2 to 5 million euro on DORA readiness.
  • Audits and reporting. Annual audit and regulatory reporting are recurring line items, commonly in the tens of thousands of euro per year.
  • Staffing. A money-laundering reporting officer, compliance lead and analysts are mandatory roles, not optional ones.
  • Model and rule maintenance. ESMA and EBA keep finalising level-2 technical standards, so rule sets need ongoing tuning.

Across these, industry estimates put a mid-sized CASP’s ongoing regulatory operating cost in the region of several hundred thousand euro per year before headcount above the core regulated roles.

Build vs buy vs CASP-as-a-service

Three paths, three cost profiles:

Path Cost shape Best when
Custom build Higher one-off, predictable annual, no per-seat lock-in Proprietary custody, multi-jurisdiction, high volume
Off-the-shelf RegTech Lower one-off, per-seat or per-transaction fees that grow with volume Standard control set, faster start
CASP-as-a-service Lowest one-off, revenue share or platform fees, least control Early-stage products testing the market

We tell clients honestly when a licensed CASP-as-a-service partner ships faster than a custom build. See the full comparison on our MiCA compliance page, and our RegTech and crypto exchange services for the build path.

The cost of getting it wrong

Under-investing in compliance is the most expensive option. EU enforcement is now live: in November 2025 the Central Bank of Ireland fined Coinbase’s European entity about 21.5 million euro for anti-money-laundering failures, including transaction-monitoring gaps (Irish Times). Globally, Binance settled US charges for over 4.3 billion US dollars in 2023 (US DOJ). DORA breaches carry penalties of up to 2% of annual worldwide turnover.

Market integrity is part of the same picture: an NBER study found more than 70% of reported volume on unregulated crypto exchanges is wash trading, which is exactly what MiCA Title VI surveillance exists to catch.

How to control MiCA compliance cost

The cheapest path is rarely the lowest line item, it is the one that avoids rework and fines. Start with a gap assessment that maps your in-scope services and token types against MiCA, the Transfer of Funds Regulation and DORA, then build in priority order. Wire vendors behind clean abstractions so coverage is a configuration choice. Put every control on one immutable audit trail so authorisation evidence and reporting are a query, not a manual project.

Pharos Production builds MiCA compliance software for CASPs and token issuers, aligned with ISO 27001 and SOC 2. Run the readiness scorecard or request a gap assessment for a fixed-scope estimate in 48 hours. For the obligation-by-obligation view, see our MiCA compliance checklist. We are not a law firm: token classification and CASP authorisation must be confirmed by qualified counsel.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    There is no fixed figure. You must hold minimum own funds of 50,000, 125,000 or 150,000 euro depending on your authorisation class, plus legal and advisory work to prepare the application (industry estimates of roughly 80,000 to 200,000 euro) and national application fees that are often time-based.

    The largest variable is the compliance software, which depends on build versus buy.

  • Copy link Copies a direct link to this answer to your clipboard.

    MiCA Annex IV sets minimum own funds at 50,000 euro for Class 1 services, 125,000 euro for Class 2 (adds custody and exchange) and 150,000 euro for Class 3 (adds operating a trading platform). You must hold the higher of that floor or 25% of prior-year fixed overheads.

  • Copy link Copies a direct link to this answer to your clipboard.

    It depends on volume and scope. Off-the-shelf RegTech has a lower one-off cost but per-seat or per-transaction fees that grow with you.

    A custom build has a higher one-off cost but predictable annual cost and no lock-in, and wins for proprietary custody, multi-jurisdiction operations or high volume. We scope custom MiCA systems from about 60,000 to 500,000 US dollars and up.

  • Copy link Copies a direct link to this answer to your clipboard.

    The recurring ones: DORA operational resilience (Deloitte found 64% of financial entities expected to spend 2 to 5 million euro), annual audits, regulatory reporting, mandatory compliance staffing and ongoing tuning of rules as ESMA and EBA finalise technical standards. These are usually larger than the one-off authorisation cost.

  • Copy link Copies a direct link to this answer to your clipboard.

    It varies with size and scope. Industry estimates put a mid-sized CASP’s annual regulatory operating cost in the region of several hundred thousand euro before headcount above the core regulated roles, covering audits, reporting, monitoring tools and compliance staff.

  • Copy link Copies a direct link to this answer to your clipboard.

    More than compliance. In November 2025 the Central Bank of Ireland fined Coinbase’s European entity about 21.5 million euro for AML failures.

    DORA breaches carry penalties of up to 2% of annual worldwide turnover. Globally, Binance settled US charges for over 4.3 billion US dollars in 2023.

  • Copy link Copies a direct link to this answer to your clipboard.

    Yes, for early-stage products. Operating under a licensed partner has the lowest one-off cost and fastest start, at the price of revenue share and less control.

    It is a good way to test the market before investing in your own authorisation and custom software. We will tell you when that is the better call.

Role: Founder and CTO, Pharos Production

Focus: Architecture, Web3 products, smart contract security, high-load systems

Experience: 23 years in production delivery

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let’s work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 1 business day

What happens next?

  1. Contact us

    Contact us today to discuss your project. We’re ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We’re committed to keeping your information confidential, so we’ll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we’ll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let’s connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day