Skip to content
Skip article header Engineering

MiCA Compliance Checklist 2026: CASP Authorisation, Travel Rule and Proof of Reserves

A practical MiCA compliance checklist for CASPs and token issuers: CASP authorisation, KYC AML, Travel Rule, proof of reserves, market abuse, token white papers and DORA, mapped to EU deadlines.

Updated 7 min read 263 views
MiCA compliance checklist concept with glowing checkmarks, EU stars and crypto-asset tokens
MiCA compliance checklist concept with glowing checkmarks, EU stars and crypto-asset tokens
Skip key takeaways

Key takeaways 5

  • CASP authorisation requires minimum capital MiCA sets minimum own funds at 50,000, 125,000 or 150,000 euro depending on which of the ten crypto-asset services a CASP provides.
  • Travel Rule applies from December 2024 The crypto Travel Rule under the Transfer of Funds Regulation (EU) 2023/1113 applies to all crypto transfers from 30 December 2024.
  • One authorisation passports across 27 states A single MiCA authorisation can be passported across all 27 EU member states, so controls must satisfy every regulator in scope.
  • Wash trading exceeds 70% on unregulated venues An NBER study found more than 70% of reported crypto trading volume on unregulated venues is wash trading, making surveillance mandatory.
  • Transitional period ends 1 July 2026 Existing CASPs that operated under national law before 30 December 2024 may rely on a transitional period that runs until 1 July 2026 in most member states.

MiCA, the EU Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114), is now the baseline for any crypto-asset business that wants to operate in the European Union. This checklist maps every major MiCA obligation to the controls and software you need in place, whether you run a crypto-asset service provider (CASP) or issue tokens. It is a practical engineering checklist, not legal advice: your token classification and authorisation must be confirmed by qualified counsel.

Use it to scope a gap assessment, brief your engineering team or sanity-check a vendor. Each section below is a standalone checklist you can lift straight into your own readiness review. If you want the controls built into one auditable system, see our MiCA compliance software development.

Who needs to comply with MiCA, and by when

MiCA applies to two broad groups: crypto-asset service providers (CASPs) such as exchanges, custodians, brokers and wallet providers, and issuers of tokens. The rules arrived in stages, and the Travel Rule and operational-resilience obligations sit in separate regulations that apply in parallel.

Date What applies
29 June 2023 MiCA enters into force
30 June 2024 Rules for asset-referenced tokens (ART) and e-money tokens (EMT) apply
30 December 2024 CASP rules apply, and the crypto Travel Rule under the Transfer of Funds Regulation applies
17 January 2025 DORA (Digital Operational Resilience Act) applies
1 July 2026 Transitional period ends for existing CASPs in most member states

A single MiCA authorisation can be passported across all 27 EU member states, so the controls you build for one national competent authority must hold up under every regulator in scope. Existing CASPs that operated under national law before 30 December 2024 may rely on a transitional period that runs until 1 July 2026 in most member states, though some states have shortened it. Dates are per ESMA.

CASP authorisation checklist

To be authorised as a CASP you must evidence an organization a regulator can supervise. MiCA defines ten crypto-asset services, and you are authorised only for the specific services you provide. Each control below should produce examiner-ready evidence automatically rather than through manual collation.

  • A programme of operations covering each crypto-asset service you provide
  • Sound governance, fit-and-proper management and a clear organizational structure
  • Minimum own funds per MiCA Annex IV: 50,000 euro, 125,000 euro or 150,000 euro depending on the services provided
  • Safeguarding of clients' crypto-assets and funds, segregated from your own assets
  • Business continuity and ICT resilience aligned with DORA
  • A complaints-handling procedure and a conflicts-of-interest policy and register
  • An outsourcing policy and register for any critical or important functions
  • Record keeping and an immutable audit trail for every client action

The ten services map cleanly to software modules, from custody and trading-platform operation to order execution and transfer services. See the full mapping on our MiCA compliance page.

KYC, AML and Travel Rule checklist

Anti-money-laundering controls sit underneath MiCA and are tightening under the EU AML single rulebook (AMLR) and the new authority AMLA. The AMLR (Regulation (EU) 2024/1624) applies directly across the EU from 10 July 2027, adding a harmonized customer due diligence baseline that AMLA will help supervise. The crypto Travel Rule itself comes from the Transfer of Funds Regulation (Regulation (EU) 2023/1113), not from MiCA, and applies to crypto transfers from 30 December 2024. The EBA's Travel Rule Guidelines (EBA/GL/2024/11), adopted 4 July 2024 and applying since 30 December 2024, require CASPs to attach the originator and beneficiary data fields set out in TFR Article 14(1) and (2) and to verify ownership or control of a self-hosted wallet address once a transfer reaches EUR 1,000 under TFR Article 14(5) and Article 16(2).

  • KYC and KYB onboarding with identity verification and customer risk scoring
  • Sanctions and PEP screening at onboarding and on an ongoing basis
  • AML transaction monitoring with explainable risk scoring and analyst alert triage
  • Wallet and address screening (KYT) through Chainalysis, TRM Labs or Elliptic
  • Travel Rule data exchange using IVMS101 over Notabene, 21 Analytics or VerifyVASP
  • Counterparty VASP due diligence and risk-based handling of unhosted wallet transfers
  • Suspicious transaction reporting to your national competent authority

The Travel Rule and GDPR pull in opposite directions: one forces you to exchange originator and beneficiary data, the other forces you to minimize it. Build IVMS101 payloads over encrypted VASP-to-VASP channels with strict retention limits and a lawful-basis register. Our crypto exchange development and RegTech teams wire these providers in.

Custody and proof-of-reserves checklist

Proof of reserves concept with a transparent vault of segregated crypto-assets and a Merkle tree verifying balances

If you hold client crypto-assets, MiCA requires you to safeguard and segregate them. Proof of reserves is an engineering obligation, not a marketing badge.

  • Segregation of client crypto-assets and funds from your operational holdings
  • A custody policy and clear liability terms for the loss of client crypto-assets
  • Real-time reconciliation of on-chain balances against the internal ledger
  • Signed wallet-ownership proofs and an append-only ledger
  • Periodic Merkle-tree attestation for external assurance
  • Integration with institutional custody such as Fireblocks or Copper where relevant

Market abuse and regulatory reporting checklist

MiCA Title VI extends the EU market-abuse regime to crypto-assets admitted to trading. A CASP operating a trading platform must prevent, detect and report abuse.

  • Order-book and trade surveillance against statistical baselines
  • Detection of wash trading, spoofing, layering and momentum ignition
  • Detection of insider dealing around listings, delistings and token events
  • Suspicious transaction and order report (STOR) generation for the national competent authority
  • Regulatory reporting pipelines and an immutable audit trail feeding every report

Credible surveillance matters because most reported volume on unregulated venues is fabricated: an NBER study found more than 70% of reported crypto trading volume is wash trading.

Token issuer checklist: ART, EMT and the white paper

Token issuers face a different control set. The first job is classification, which sits with your legal counsel: an asset-referenced token (ART) references a basket of assets or rights, an e-money token (EMT) references a single official currency, and other crypto-assets are neither. Significant ARTs and EMTs fall under direct supervision by the European Banking Authority.

  • Crypto-asset white paper drafting, version control and notification to the competent authority
  • Reserve management and reserve-of-assets attestation for ART and EMT
  • Redemption at par and clear redemption rights for holders
  • Marketing-communications compliance aligned with the white paper
  • Ongoing disclosure and reporting, with enhanced obligations for significant tokens

DORA and operational resilience checklist

DORA (Regulation (EU) 2022/2554) applies to financial entities including CASPs from 17 January 2025. It runs alongside MiCA and cannot be treated as an afterthought.

  • ICT-risk management framework and governance
  • Incident classification and reporting workflows for major ICT incidents
  • A register of information for ICT third-party providers
  • Digital operational resilience testing and evidence

How to build MiCA compliance into your software

The pattern that survives a regulatory review is simple: every control writes to one immutable audit trail, so authorisation evidence and regulatory reports are a query rather than a manual scramble. Build the gap assessment first, map your in-scope services and token types against MiCA, the Transfer of Funds Regulation and DORA, then build the controls in priority order. Wire named providers (Sumsub, Onfido, ComplyAdvantage, Chainalysis, TRM Labs, Notabene) behind clean abstractions so coverage is a configuration choice, not a rebuild.

If you want this delivered as one auditable system, Pharos Production builds MiCA compliance software for CASPs and token issuers, aligned with ISO 27001 and SOC 2. Run our MiCA readiness scorecard to see where your gaps are, or request a gap assessment for a fixed-scope estimate in 48 hours. For what it all costs, see our MiCA compliance cost breakdown. See it in practice in our Ludera.io case study. We are not a law firm: token classification and CASP authorisation must be confirmed by qualified counsel before launch.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    If you provide any of the ten MiCA crypto-asset services in the EU - custody, operating a trading platform, exchange, order execution, placing, reception and transmission of orders, advice, portfolio management or transfer services - you need authorisation as a crypto-asset service provider. The exact scope and any exemptions are a legal question for qualified counsel.

  • Copy link Copies a direct link to this answer to your clipboard.

    An asset-referenced token (ART) references a basket of assets, rights or currencies. An e-money token (EMT) references a single official currency. Both require reserve management, redemption at par and white paper compliance, and significant tokens of either type fall under direct EBA supervision.

  • Copy link Copies a direct link to this answer to your clipboard.
  • Copy link Copies a direct link to this answer to your clipboard.

    MiCA entered into force on 29 June 2023. Rules for asset-referenced and e-money tokens applied from 30 June 2024, and CASP rules from 30 December 2024. The crypto Travel Rule under the Transfer of Funds Regulation also applies from 30 December 2024, and DORA from 17 January 2025.

  • Copy link Copies a direct link to this answer to your clipboard.

    MiCA requires CASPs that hold client crypto-assets to safeguard and segregate them. Proof of reserves is how you evidence that obligation.

    We build real-time reconciliation of on-chain balances against the internal ledger, with periodic Merkle-tree attestation for external assurance.

  • Copy link Copies a direct link to this answer to your clipboard.

    MiCA governs crypto-asset services provided in the EU and tokens offered to the EU public. A firm outside the EU that targets EU clients generally needs authorisation.

    One MiCA authorisation passports across all 27 member states. Confirm your specific position with counsel.

  • Copy link Copies a direct link to this answer to your clipboard.

    A focused MiCA compliance MVP - onboarding, screening, monitoring and reporting for your in-scope services - typically takes about 12 weeks. Travel Rule and proof-of-reserves modules add 2 to 4 weeks each depending on the providers and custody stack involved.

Skip glossary

MiCA and crypto-compliance glossary 5

CASP
Crypto-asset service provider - an entity authorised under MiCA to provide one or more of the ten defined crypto-asset services, such as custody or exchange operation.
Travel Rule
Obligation under Transfer of Funds Regulation (EU) 2023/1113 requiring CASPs to exchange originator and beneficiary data for crypto transfers using the IVMS101 standard.
ART
Asset-referenced token - a crypto-asset that references a basket of assets or rights; significant ARTs fall under direct supervision by the European Banking Authority.
EMT
E-money token - a crypto-asset that references a single official fiat currency and must support redemption at par; significant EMTs are supervised by the European Banking Authority.
DORA
Digital Operational Resilience Act (EU) 2022/2554 - requires CASPs and other financial entities to maintain ICT-risk frameworks and report major incidents from 17 January 2025.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day