Skip to content
Client Focus

Regulatory readiness

MiCA: authorization and the operating obligations behind the license

The Markets in Crypto-Assets Regulation created a single European Union authorization regime for crypto-asset service providers and issuers. Authorization is an operating commitment rather than a one-time filing, and DORA supplies the resilience rules MiCA presumes.

What the regime is

MiCA sets authorization, conduct, custody and disclosure requirements for crypto-asset service providers, and separate requirements for issuers of asset-referenced and electronic money tokens. National transition periods ran through 2025, after which firms operate under the license and the supervisory reporting that comes with it.

MiCA and DORA interlock. MiCA requires sound administrative and operating arrangements; DORA specifies the ICT risk, incident reporting, testing and third-party rules that make those arrangements testable. A firm that treats them as one program produces one set of records.

Who it applies to

  • Crypto-asset service providers authorized in a European Union member state.
  • Issuers of asset-referenced tokens and electronic money tokens.
  • Firms passporting services into the European Union under a MiCA license.
  • Groups whose non-EU entities support an authorized EU entity through outsourcing.

Last reviewed: August 22, 2026

Colleagues reviewing documents across a meeting room table

What the rules require in operation

Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.

Obligations, operational meaning and evidence for MiCA
ObligationWhat it means for a digital asset operationEvidence to produce
Custody and segregation of client assetsClient holdings held separately from firm assets, with position records reconciled against chain state.Custody policy, segregation records and reconciliation output with exceptions.
Conduct and disclosureClear service descriptions including availability targets, incident notification and support paths.Published service descriptions, client notices and change history.
Complaints and incident handlingA single intake for client-reported issues that feeds the same incident process as detected events.Complaint register, incident records and resolution timelines.
Governance and outsourcingNamed accountable owners for outsourced monitoring and operations, with access and change authority documented.Outsourcing register, service agreements and oversight meeting records.
Operational resilienceContinuous coverage of the infrastructure behind deposits, withdrawals and settlement.Availability reporting, escalation records and continuity test results.

Key dates

  1. June 2023

    Regulation (EU) 2023/1114 enters into force.

  2. June 30, 2024

    Requirements for asset-referenced and e-money tokens apply.

  3. December 30, 2024

    Crypto-asset service provider regime applies.

  4. Through 2025

    National transition periods close and authorizations take effect.

How Client Focus supports it

Secure

Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.

Run

ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.

Trust and compliance

Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.

Prepare for supervisory review.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.