MiCA Custody Requirements
MiCA custody requirements mapped provision by provision: Article 70's safekeeping baseline for every CASP, Article 75's nine-paragraph custody rulebook, the three-limb segregation test, the liability cap at market value at time of loss and the evidence a CASP should have ready for each obligation.
Key takeaways: MiCA custody requirements 5
What Articles 70 and 75 actually require, where they diverge from common shorthand and what a CASP should have ready as evidence for each obligation.
- Custody authorization is now the majority position in the ESMA register 207 of 295 active CASPs (70%) hold custody authorization as of 20 July 2026, so this obligation set applies to most of the register, not a niche subset.
- Article 70 applies to every CASP holding client assets or funds The rehypothecation ban and the fiat-placement rule bind any CASP holding client crypto-assets or client funds, whether or not custody is the service it is authorized for.
- Segregation under Article 75(7) has three distinct limbs On-DLT, legal and operational segregation are three separate requirements. The Article 75(2) register of positions is a distinct obligation, not a fourth segregation limb, a common shorthand error.
- Liability for lost assets is capped at value at the time of loss Article 75(8) caps CASP liability at the market value of the lost crypto-asset at the time the loss occurred, not at claim or judgment time, a timing detail that creates real exposure asymmetry in a volatile market.
- Proof of reserves is voluntary evidence, not a MiCA requirement Reserve and audit duties under MiCA attach to ART and EMT issuers, not CASP custodians. Proof-of-reserves publications and independent attestations are useful but optional evidence of segregation.
MiCA Custody Requirements sit in two article clusters, not one. Article 70 sets a safekeeping baseline binding every Crypto-Asset Service Provider that holds client crypto-assets or client funds, whether or not custody is the service it is authorized for. Article 75 adds a detailed rulebook for CASPs authorized to provide custody and administration of crypto-assets as a licensed service: a mandatory agreement, a register of positions, a custody policy, segregation, liability and rules for using another custodian. In our work building compliance evidence for CASPs, the two clusters get confused constantly, so this article keeps them separate and maps every claim to the article that actually makes it.
In short: Article 70(1), the rehypothecation ban, bans a CASP from using clients' crypto-assets for its own account and applies to every CASP holding client assets. Article 70(2)-(3) requires client funds to sit with a credit institution or central bank by the end of the next business day, in a separately identifiable account. Article 75 requires a seven-item custody agreement, a per-client register of positions, a custody policy, quarterly statements, three-limb segregation of client assets from the CASP's own estate and liability for loss capped at market value at the time of loss. Sub-custody may only use Article 59-authorized CASPs (Art 75(9)), and ESMA guidance (non-binding) extends the same rule to pre-funding with client assets. As of 20 July 2026, 207 of 295 active CASPs in the ESMA register (70%) hold custody authorization, so this is the obligation set most of the register now has to evidence.
What MiCA requires for crypto-asset custody
MiCA defines custody once, in Article 3(1)(17): "the safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys". Article 70 applies horizontally to any CASP holding client crypto-assets or client funds, regardless of the specific service on its authorization. Article 75 applies to CASPs authorized to provide custody and administration of crypto-assets, and it is more detailed because custody is the service where client assets sit directly under the provider's control.
Custody authorization is now the majority position in the ESMA register, not an edge case. Per our raw-CSV parse, 207 of 295 active CASPs (70%) held custody authorization as of the 20 July 2026 snapshot, tracked alongside the wider authorization landscape in our ESMA CASP register data study. The table below maps every provision this article covers to its obligation and binding status, since the ESMA Q&A layer is guidance, not statute, and the two should never be quoted as carrying equal legal weight.
| Provision | What it requires | Binding |
|---|---|---|
| Art 3(1)(17) | Defines custody as safekeeping or controlling crypto-assets or means of access (private keys) on behalf of clients | Yes |
| Art 70(1) | Safeguard clients' ownership rights, especially in insolvency. Ban on using clients' crypto-assets for the CASP's own account | Yes |
| Art 70(2)-(3) | Place client funds with a credit institution or central bank by end of the next business day, in a separately identifiable account | Yes |
| Art 70(5) | Disapplies 70(2)-(3) for CASPs that are credit institutions, e-money institutions or payment institutions | Yes |
| Art 75(1) | Mandatory custody agreement covering at least seven items | Yes |
| Art 75(2) | Per-client register of positions. Movements recorded as soon as possible, each evidenced by a registered transaction | Yes |
| Art 75(3) | Custody policy minimizing loss from fraud, cyber threats or negligence. Client-facing summary on request | Yes |
| Art 75(4) | Facilitate client rights. Default entitlement to fork or airdrop assets per positions at the time of the event | Yes |
| Art 75(5) | Statement of position at least every three months and on request | Yes |
| Art 75(6) | Return client crypto-assets or means of access as soon as possible | Yes |
| Art 75(7) | Three-limb segregation: on-DLT, legal, operational | Yes |
| Art 75(8) | Liability for loss from attributable incidents, capped at market value at the time of loss | Yes |
| Art 75(9) | Sub-custody only via Article 59-authorized CASPs, with client notification | Yes |
| Art 67(1) + Annex IV | Own funds: higher of the class minimum or one quarter of prior-year fixed overheads. Class 2 minimum EUR 125,000 | Yes |
| Art 111(2), (3) | National sanction floors: EUR 700,000 natural persons, EUR 5,000,000 or 5% of turnover for CASP legal persons | Yes (floor for national law) |
| Recital 83 | Custody assets should stay unencumbered at all times. Liability extends to ICT-related incidents | No, interpretive |
| ESMA Q&A 2608 | Pre-funding with client crypto-assets is sub-custody. Third party must be an Article 59 CASP | No, guidance |
| ESMA Q&A 2578 | Group-entity commingling sits outside Article 75(7)'s wording but raises Article 72 conflicts. ESMA recommends avoiding it | No, guidance |
Article 70: the safekeeping baseline for every CASP
Article 70 applies to any CASP holding client crypto-assets, client funds or the means of access to those crypto-assets, independent of what specific license it holds. Two obligations sit inside it: the rehypothecation ban on the crypto-asset side, and a next-business-day placement rule on the fiat side.
The rehypothecation ban (Art 70(1))
This provision requires a CASP holding clients' crypto-assets or the means of access to those assets to make adequate arrangements to safeguard clients' ownership rights, especially in the event of insolvency, and to prevent the use of clients' crypto-assets for the CASP's own account. That second half is the rehypothecation ban: a custodian cannot lend out, stake, pledge or otherwise deploy client holdings for its own benefit, and it attaches to any CASP holding client assets, not only to firms authorized specifically for custody.
Client funds: the next-business-day rule (Art 70(2)-(3), carve-outs 70(5))
The fiat leg that crypto-focused custody coverage routinely skips sits in Article 70(2)-(3): client funds other than e-money tokens must be placed with a credit institution or a central bank by the end of the business day following the day the funds were received, in an account separately identifiable from the CASP's own accounts. Article 70(5) disapplies these two paragraphs where the CASP is itself a credit institution, an e-money institution or a payment institution, since those entities already sit under their own funds-safeguarding regime.
Article 75: the custody service rulebook
Nine numbered paragraphs make up Article 75, covering the agreement, the register, the policy, client rights, reporting, return, segregation, liability and sub-custody for any CASP authorized to provide custody and administration of crypto-assets on behalf of clients. We work through each in the order MiCA states them.
The custody agreement: 7 mandatory items (75(1))
Under Article 75(1), a custody agreement must cover at least seven items: the parties, the nature and description of the custody service, the custody policy, the CASP's means of communication including its client-authentication system, a description of its security systems, the fees, costs and charges applied and the applicable law. An agreement missing any one of these seven is not compliant on its face.
Register of positions (75(2))
Article 75(2) requires a register of positions opened in each client's name, corresponding to that client's rights to the crypto-assets held. Movements on client instruction must be recorded as soon as possible, evidenced by a transaction regularly registered in the client's register. Note the exact wording, "as soon as possible", not a fixed interval: a CASP that reconciles the register against on-chain balances daily is meeting a supervisory expectation, not a literal statutory deadline.
Custody policy (75(3))
A custody policy under Article 75(3) must set internal rules and procedures that ensure safekeeping and minimize the risk of loss due to fraud, cyber threats or negligence, with a summary available to clients on request in electronic format. It is the document a supervisor asks for first, and it has to describe the controls a CASP actually runs, not restate the statute back at the regulator.
Forks, airdrops and client rights (75(4))
Client rights come next: Article 75(4) requires a CASP to facilitate the exercise of rights attached to custodied crypto-assets. Where a fork or airdrop creates new assets or rights, the client is entitled by default to them, on the basis and to the extent of the client's positions at the time of the event, unless the agreement expressly provides otherwise. That default is a contract-drafting point: an agreement silent on forks hands the new assets to the client by operation of Article 75(4).
Quarterly statements and asset return (75(5)-(6))
For reporting, Article 75(5) requires a statement of position at least once every three months and on request, identifying the assets held, balance, value and transfers made in the period. Article 75(6) requires procedures to return client crypto-assets or means of access as soon as possible on request.
Asset segregation and insolvency remoteness (Art 75(7))
Article 75(7) is the segregation article, and it states three separate limbs, not one blended safeguard. In our review of adjacent coverage, including our own earlier shorthand, the register of positions from Article 75(2) sometimes gets folded into "segregation" as a fourth limb. It is a distinct obligation, and Article 75(7) itself contains exactly three requirements.
The three limbs: on-DLT, legal, operational
First, holdings and on-DLT separation: client crypto-assets identified separately from the CASP's own, and on the distributed ledger itself held separately from the CASP's own crypto-assets. Second, legal segregation: client holdings legally segregated from the CASP's own estate, in accordance with applicable law, so that the CASP's creditors have no recourse to crypto-assets held in custody, in particular in insolvency. Third, operational segregation from the CASP's own estate. MiCA does not elaborate what operational segregation concretely requires beyond that wording, so we treat it in advice voice, mapped to access-structure isolation between client-asset signing paths and corporate treasury, rather than overclaiming a technical standard the statute does not itself define.
Why "bankruptcy-remote" depends on national law
The legal-segregation limb orders an outcome, no creditor recourse to custodied assets, but delivers it "in accordance with applicable law". Commentary on this point is consistent: application varies between Member States, since MiCA does not itself harmonize crypto-asset property rights across the EU. Germany is the commonly cited example of a state that legislated specific insolvency protection for safekept crypto-assets, per commentary we reviewed rather than a MiCA provision itself. The honest framing is conditional: MiCA requires legal segregation designed to keep custodied assets out of the insolvency estate, and whether that design holds up depends on the Member State's own property and insolvency law. "MiCA makes client crypto-assets bankruptcy-remote", stated unconditionally, overstates what the article delivers.
Group entities and commingling (ESMA Q&A 2578)
Article 75(7)'s wording only requires separating client assets from the CASP's own. Assets belonging to a sister company or group entity fall outside that literal wording. ESMA's Q&A 2578, published 20 February 2025 and answered 17 June 2025, closes that gap through a different route: commingling client assets with group assets creates conflicts of interest under Article 72, and ESMA recommends avoiding it, or refraining from servicing sister entities where the risks cannot be mitigated. This is guidance, not a statutory rule, so we treat it as a recommendation a CASP should show it has considered, not an Article 75(7) requirement in its own right.
Liability for loss of client crypto-assets (Art 75(8))
Article 75(8) makes a CASP liable to clients for loss of crypto-assets or means of access caused by an incident attributable to the CASP, capped at the market value of the lost asset at the time the loss occurred. That timing detail creates real exposure asymmetry in a volatile market: the cap tracks value at the moment of loss, not at claim or judgment time. The article carves out incidents the CASP demonstrates occurred independently of the relevant service or its own operations, such as a problem inherent in the distributed ledger's operation that the CASP does not control. Recital 83 adds that custody CASPs should keep assets unencumbered at all times and remain liable for ICT-related losses including cyber-attacks, theft or malfunctions, though a recital is interpretive rather than an operative obligation.
Sub-custody and pre-funding (Art 75(9) and ESMA Q&A 2608)
On sub-custody, Article 75(9) itself is narrow: where a custody CASP uses other providers of the custody service, it shall only use crypto-asset service providers authorized under Article 59, and inform clients that it does so. The statute says nothing about pre-funding specifically. That reading comes from ESMA's Q&A 2608, published 20 February 2025 and answered 9 July 2025, guidance rather than statutory text.
Per ESMA's guidance, pre-funding a client transaction with the client's own crypto-assets constitutes sub-custody, even where the holding is temporary and linked to trade execution, so Articles 70 and 75 apply. The arrangement is permissible only where the third party holding the assets is an Article 59-authorized CASP and the client has been informed. ESMA also draws a timing red line: transferring assets to settle an already-executed transaction for a specific order is not sub-custody. The line is timing: a transfer before execution is pre-funding, a transfer after execution settles an order the client already instructed.
Evidencing compliance: the three-layer framework
MiCA states obligations. It does not prescribe an evidence format for demonstrating compliance with them. In our work advising CASPs through custody authorization and ongoing supervision, we organize the evidence a CASP should be able to hand a national competent authority into three layers, each mapped back to the article it evidences.
| Layer | What it covers |
|---|---|
| Policy | Custody policy with the fraud/cyber-threat/negligence language of Art 75(3) plus a client-ready summary. Custody agreement template covering all seven Art 75(1) items. Conflicts-of-interest policy addressing group structures (Art 72, Q&A 2578). Sub-custody policy with authorization checks on any third party, including pre-funding flows (Art 75(9), Q&A 2608) |
| Controls | On-DLT address separation between client and corporate/fee wallets (Art 75(7) limb 1). Operational isolation of client-asset signing paths from corporate treasury (limb 3). A register-of-positions engine recording movements as soon as possible, each evidenced by a registered transaction (Art 75(2)). Reconciliation between on-chain balances and the register with a documented discrepancy protocol, industry practice rather than a literal statutory cadence. Next-business-day placement of client funds in a separately identifiable account (Art 70(3)) |
| Proof | Address inventories with client/corporate attribution plus ledger extracts showing on-DLT separation. Register extracts and movement audit trails per client. Archived quarterly statements with delivery evidence (Art 75(5)). Sub-custodian due-diligence files with date-stamped ESMA register lookups proving Art 59 authorization plus client-notification records. A legal opinion on insolvency effectiveness under the applicable national law, speaking directly to the Art 75(7) "in accordance with applicable law" hedge |
Two items belong in the proof layer as voluntary artifacts, never obligations: a proof-of-reserves publication, which MiCA does not require of CASP custodians (reserve and audit duties under MiCA attach to ART and EMT issuers, not custodians), and an independent attestation over segregation and register controls, industry practice rather than a statutory duty. Both are useful evidence of segregation. Neither is a MiCA requirement.
The controls above are legal and procedural, not cryptographic. Which key-management scheme enforces on-DLT and operational segregation, MPC, HSM or multi-sig, is engineering detail that maps to these same Art 70/75 requirements and is covered in our companion article, MPC vs Multisig vs HSM.
Sanctions and supervision
National sanction regimes for MiCA infringements must allow fines of at least EUR 700,000 for natural persons and at least EUR 5,000,000 or 5% of turnover for CASP legal persons under Article 111(2) and (3). The higher 12.5% tier applies only to ART and EMT issuer infringements, not CASPs. Article 67(1) and Annex IV set own-funds requirements at the higher of the class minimum or one quarter of prior-year fixed overheads, and Class 2, covering custody, carries a minimum of EUR 125,000.
Supervisory pressure on this exact obligation set is already live: ESMA launched a Common Supervisory Action on custody on 8 July 2026, running from the second half of 2026 through the first half of 2027, covered in full, including its six focus areas and the engineering evidence it points toward, in our custody CSA preparation guide. That review lands on the majority of the register. Our MiCA Review 2026 hub tracks how this and other supervisory developments may feed into the framework's first legislative review.
How Pharos Production helps
We build the custody compliance evidence trail as engineering, not paperwork assembled after the fact: register-of-positions systems satisfying Article 75(2)'s "as soon as possible" standard, segregation architecture mapped to each of Article 75(7)'s three limbs, sub-custody due-diligence checks against the live ESMA register and reconciliation logs a national competent authority can actually follow. If your platform holds client crypto-assets or client funds under MiCA and needs an evidence framework mapped cleanly to Articles 70 and 75, we can walk through what that looks like for your architecture.
See our MiCA compliance software development services.
Sources: Regulation (EU) 2023/1114 (MiCA), Articles 3(1)(17), 67, 70, 75, Annex IV and Recital 83, full text verified against EUR-Lex CELEX 32023R1114 (2026-07-21). ESMA Q&A 2608, published 20 February 2025, answered 9 July 2025 (esma.europa.eu/publications-data/questions-answers/2608). ESMA Q&A 2578, published 20 February 2025, answered 17 June 2025 (esma.europa.eu/publications-data/questions-answers/2578). Our ESMA CASP register raw-CSV analysis dated 20 July 2026.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 6
No matches
Try a different keyword, change the topic or clear filters
-
A custody agreement with 7 mandatory items, a per-client register of positions, a custody policy, at least quarterly statements of position, three-limb segregation of client assets from the CASP's own estate and liability for loss from incidents attributable to the CASP.
-
No. Article 70(1) requires adequate arrangements to prevent the use of clients' crypto-assets for the CASP's own account, and the rehypothecation ban applies to every CASP holding client assets or means of access, not only custody-authorized ones.
-
Per ESMA Q&A 2608 (non-binding guidance, answered 9 July 2025), pre-funding client transactions with client crypto-assets is sub-custody, permissible only where the third party holding the assets is an Article 59-authorized CASP and clients have been informed. Settling an already-executed order is not sub-custody.
-
Article 75(7) requires legal segregation so a CASP's creditors have no recourse to custodied assets, in particular in insolvency, but the segregation operates "in accordance with applicable law", so the actual protection depends on national property and insolvency law in the CASP's jurisdiction.
-
Loss of crypto-assets or means of access caused by an incident attributable to the CASP, capped at the market value of the lost asset at the time the loss occurred. Incidents inherent to the distributed ledger that the CASP does not control are carved out under Article 75(8).
-
No, not for CASP custodians. Reserve and audit obligations under MiCA attach to ART and EMT issuers.
Proof-of-reserves publications and independent attestations are voluntary evidence a custodian can use to demonstrate segregation.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.