Skip to content
Client Focus

Insights

MiCA authorization for crypto-asset service providers: the operating obligations behind the license

As national transition periods under MiCA ran through 2025, firms discovered that authorization is an operating commitment, not a one-time filing.

Regulatory briefings

Published
August 22, 2026
Covers
July 2025
Reading time
5 minutes
By
Client Focus

The Markets in Crypto-Assets Regulation set a single authorization regime for crypto-asset service providers across the European Union, with national transition arrangements running through 2025. Firms that concentrated on the application file learned during that period that the license is the start of a continuing obligation. Supervisors examine how the service is operated, not how it was described.

Custody and segregation

Providers holding client crypto-assets must segregate them from their own, maintain records that allow client positions to be identified at any moment, and manage the keys that control those assets under documented procedures. The practical test is reconstruction: can the firm show, for an arbitrary past date, which client held which asset, where the keys were held, and who had authority to move them.

Conduct, disclosure and complaints

Acting honestly, fairly and professionally in clients' interests translates into disclosure of terms, fees and risks, order handling and best execution practices where relevant, and a complaints handling procedure with recorded outcomes and timelines. Complaints data is one of the first datasets a supervisor asks for, because it reveals operating problems before incident reports do.

Governance, outsourcing and incidents

Management bodies must have appropriate knowledge and dedicate sufficient time to the activity. Outsourcing does not transfer responsibility: the provider remains accountable for outsourced functions and must be able to supervise them. Incidents must be handled through a defined process with records that support notification to clients and authorities.

How MiCA and DORA interlock

MiCA presumes operational resilience without specifying most of it. DORA supplies that layer: the ICT risk management framework, incident classification and reporting, resilience testing and the register of ICT third-party arrangements. A firm treating the two regimes as separate projects duplicates work and creates inconsistent records. A firm treating them as one operating model produces a single evidence set that answers both.

An operations checklist

Custody records that reconstruct client positions and key control by date. Written operational procedures for issuance, transfer, withdrawal and exception handling, versioned and approved. Incident logs with classification, timestamps, notification decisions and named owners. An outsourcing and ICT third-party register with criticality, monitoring output and tested exit plans. Complaints records with resolution times. Continuity and testing results with remediation tracked to closure.

None of these are novel to financial services. What is novel is applying them to infrastructure the firm does not own, on networks that operate continuously. That is an operations problem, and it is solved with staffing, clocks and records rather than with additional policy text.

Compliance analysts reviewing documentation in a meeting room

Continue reading

Hands annotating a printed regulatory document with a pen on a desk

DORA is in force: what crypto-asset service providers must now evidence

From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.

Bank technology leaders in discussion beside a window in a corporate office

Market structure legislation: what digital asset operators should watch in the CLARITY Act

The House passed the CLARITY Act in July 2025; Senate consideration continued through 2026.

Printed operational reports and a notebook on a desk in daylight

2025 in review: the year digital assets became an operations problem

Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.

Apply this to your own operations.

Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.