MiCA compliance software for crypto-asset service providers
Continuous, provision-level assessment against Regulation (EU) 2023/1114, from authorisation readiness to reserve adequacy, with the governing article cited on every finding.
What MiCA requires of a CASP
The Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114, is the European Union's single rulebook for crypto-assets. It replaced the patchwork of national regimes with one authorisation that passports across the Union, and it applies to crypto-asset service providers, issuers of asset-referenced tokens and issuers of e-money tokens.
For a CASP the substantive obligations sit mainly in Titles II and V. In practice a compliance function has to be able to evidence, on demand, that the following are in place and still true:
- Authorisation and prudential safeguards under Articles 59 and 67, including own funds and safeguarding arrangements
- Governance arrangements under Article 68, with a management body that has approved and oversees the framework
- Conduct of business under Article 66, acting honestly, fairly and professionally in clients' best interests
- Record-keeping under Article 68(8), retained and retrievable
- Complaints handling under Article 71, documented with a logged resolution trail
- Reserve of assets under Articles 35 and 36 where asset-referenced tokens are issued
The deadline has already passed
MiCA applied in full to crypto-asset service providers from 30 December 2024. Member States were permitted to grant a transitional period, commonly called grandfathering, allowing firms already operating under national regimes to continue while they applied for authorisation. The longest of those transitional windows closed on 1 July 2026.
The consequence is that authorisation is no longer a forward-looking project. A firm providing crypto-asset services in the Union either holds a MiCA authorisation or is operating outside the regime. Penalties under MiCA reach EUR 5 million or 12.5 percent of annual turnover for legal persons, depending on the infringement and the national implementing measures.
Why MiCA compliance is hard to hold manually
The authorisation file is a point-in-time document. Compliance is not. Once authorised, a firm has to keep its safeguarding, governance and record-keeping controls continuously true, and be able to show that to a supervisor at any moment.
The usual approach is a periodic readiness review by an external firm. That produces a report that is accurate on the day it is delivered and progressively less accurate afterwards, at a cost that a mid-size CASP typically measures in hundreds of thousands of euros a year across MiCA and its neighbouring regimes.
The gap is not knowledge of the rules. It is evidence that the controls behind them are still operating.
How Regulix assesses MiCA
Regulix encodes the provisions of MiCA as structured, testable obligations, then connects to a firm's systems through read-only APIs and analyses encrypted metadata only. Raw customer data, transaction content and private keys are never accessed, stored or transferred.
The engine resolves which obligations actually bind the entity, scores each one, and returns findings that cite the governing article with a specific remediation. It produces an audit report a firm can hand to a supervisor.
| Capability | What it does |
|---|---|
| Obligation-level scoring | Each MiCA obligation assessed separately, with the article reference attached to every finding |
| Reserve adequacy | Coverage ratio and liquid-asset tests assessed against MiCA Articles 35 and 36, alongside other regimes for cross-border context |
| Continuous re-assessment | Re-scored as systems and the law change, rather than once a quarter |
| Regulator-ready reporting | Automated audit report citing the specific provisions engaged |
| Metadata-only architecture | Read-only access, encrypted metadata, no raw customer data |
MiCA is assessed alongside the other 23 frameworks in the engine, across 7 jurisdictions, so a firm sees its MiCA position in the context of GDPR, DORA, the EU AI Act, AMLR and the national regimes that also apply to it.
Frequently asked questions
Does Regulix get my firm authorised under MiCA?
No. The authorisation application is legal work and belongs with your lawyers and advisers. Regulix produces the technical evidence that goes inside the file, covering governance, ICT integrity, record-keeping and data protection, and then continuously monitors that those controls stay true after authorisation.
What is MiCA compliance software?
Software that assesses a crypto-asset service provider against the obligations in Regulation (EU) 2023/1114 and evidences the result. The distinction that matters is between tools that tell you a rule exists and tools that test your own systems against it. Regulix does the second.
Has the MiCA deadline passed?
MiCA applied in full from 30 December 2024. National transitional periods for firms already operating under previous regimes ran no later than 1 July 2026, so authorisation obligations are live now.
What are the penalties for MiCA non-compliance?
MiCA provides for administrative penalties up to EUR 5 million or 12.5 percent of total annual turnover for legal persons, depending on the infringement and the national implementing measures.
Does Regulix access our customer data?
No. The engine connects through read-only APIs and analyses encrypted metadata and configuration state only. It never ingests raw customer data, transaction content or private keys.
Related
See where your firm stands
Connect a read-only data source and get a provision-level assessment across MiCA and the other frameworks that apply to you.
Regulix provides decision support and evidence for compliance functions. It does not constitute legal advice, and it does not replace authorisation by a competent authority or sign-off by qualified counsel.