Regulatory guide

MiCA & CASP compliance for crypto-asset service providers

The Markets in Crypto-Assets Regulation (MiCA) brings crypto-asset service providers into a single EU authorisation regime. This guide summarises who is in scope, the core obligations, and the key thresholds a CASP has to manage.

What MiCA is, and who it applies to

MiCA is the EU's harmonised framework for crypto-assets that fall outside existing financial-services legislation. It regulates two things: the issuance and public offering of crypto-assets — including asset-referenced tokens and e-money tokens — and the firms that provide crypto-asset services to the public. Before MiCA, these activities were governed by a patchwork of national rules; MiCA replaces that with one authorisation and conduct regime across the Union.

The regulation applies to any firm providing crypto-asset services in the EU on a professional basis — a crypto-asset service provider, or CASP. That covers custody and administration of crypto-assets, operating a trading platform, exchanging crypto-assets for funds or for other crypto-assets, executing, placing, receiving and transmitting orders, providing transfer services, and giving advice or portfolio management. Issuers and offerors of crypto-assets are also in scope for the disclosure and reserve obligations.

Core obligations and thresholds

Authorisation as a CASP

Firms providing crypto-asset services in the EU — custody, exchange against funds or other crypto-assets, operation of a trading platform, execution, placement, reception and transmission of orders, advice or portfolio management — must be authorised by a national competent authority before operating, unless a limited transitional regime applies.

Own funds and prudential safeguards

A CASP must hold minimum capital set by the class of services it provides, expressed as a fixed money floor or a proportion of fixed overheads, whichever is higher. This own-funds requirement is a continuous prudential obligation, not a one-off entry test.

Reserve of assets and reconciliation (issuers)

Issuers of asset-referenced and e-money tokens must maintain a segregated reserve backing the tokens in circulation and reconcile it regularly, so redemption rights are protected and the reserve is not commingled with the issuer’s own funds.

Crypto-asset white papers and disclosure

Offering crypto-assets to the public or seeking admission to trading generally requires a white paper with fair, clear and non-misleading disclosure of the asset, the issuer, the rights attached and the principal risks — notified to the competent authority before publication.

Travel Rule for crypto transfers

Under the Transfer of Funds Regulation extended to crypto-assets, originator and beneficiary information must accompany transfers of crypto-assets. The de-minimis exemptions that apply to low-value conventional transfers do not carve out crypto transfers above EUR 1,000, so identifying data is expected on transfers at and beyond that threshold.

Governance, conduct and market-abuse rules

CASPs face conduct-of-business, complaints-handling, conflict-of-interest, safeguarding of client assets and market-abuse obligations, alongside the AML/CTF customer-due-diligence duties that apply to obliged entities across the EU AML framework.

How ReguShield helps

ReguShield is Compliance Intelligence Infrastructure: it maps a crypto business's operational and transaction data against the MiCA and CASP obligations that apply to it, and turns that mapping into decision-support a compliance officer can stand behind. It does not file with, or claim any certification or approval from, a regulator.

  • Obligation mapping — connects in-scope MiCA/CASP obligations, including Travel Rule data expectations above EUR 1,000, to the parts of the business responsible for them.
  • Inherent and residual risk scoring — scores exposure before and after controls, so the effect of each control is visible rather than assumed.
  • Control-effectiveness assessment — gauges how well existing controls reduce inherent risk, and highlights the gaps that remain.
  • Evidence lifecycle and audit lineage — ties evidence to each obligation and preserves the lineage of what was reviewed, when, and by whom.
  • Explainable decision support — every conclusion traces back to the signal and the rule that produced it; the analysis is on-demand, deterministic and explainable, not a black box.
  • Board-ready executive reporting — produces reporting suitable for boards and supervisory scrutiny, with the reasoning attached.

Frequently asked

Who counts as a CASP under MiCA?

A crypto-asset service provider is a legal person or undertaking whose occupation or business is providing one or more crypto-asset services to third parties on a professional basis — for example custody and administration of crypto-assets, operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing or placing orders, providing transfer services, or offering advice and portfolio management. Providing any of these services in the EU generally requires MiCA authorisation.

What is the crypto Travel Rule threshold?

Originator and beneficiary information must travel with crypto-asset transfers. Unlike low-value conventional funds transfers, crypto transfers are not exempted below a small threshold in the same way, and identifying data is expected on transfers of EUR 1,000 or more between crypto-asset service providers. Firms should treat EUR 1,000 as the practical trigger for full originator/beneficiary data collection and transmission.

Do CASPs need to hold regulatory capital?

Yes. A CASP must maintain minimum own funds calibrated to the classes of service it provides, expressed as a fixed monetary floor or a fraction of fixed overheads, whichever is higher. It is a continuous prudential requirement that must be monitored, not just met at authorisation.

When is a crypto-asset white paper required?

A white paper is generally required when a firm offers crypto-assets to the public in the EU or seeks their admission to trading, with limited exemptions. It must disclose the asset, the issuer or offeror, the rights and obligations attached, the underlying technology and the principal risks in a fair, clear and non-misleading way, and be notified to the competent authority before publication.

Is MiCA the only regime a CASP has to satisfy?

No. MiCA sits alongside the EU AML framework (AMLA and the AML Rulebook), the Travel Rule under the Transfer of Funds Regulation, and — where a CASP is a financial entity — DORA operational-resilience duties. A single crypto business typically has to demonstrate readiness across several overlapping frameworks at once.

ReguShield provides compliance decision-support — not legal advice; final decisions require human review and sign-off.

View the guided demoTrust CenterBack to Resources