MiCA compliance guide 2026: how EU crypto companies can avoid €5m penalties
For crypto companies in the EU, the period when MiCA preparations could be postponed by relying on transitional arrangements is over. Regulators now expect CASPs to have more than a formal set of documents: they require an effective system of governance, risk management, and client protection. Incorrect token classification, inadequate oversight of a custody provider, or failure to comply with disclosure requirements may have consequences beyond an order to remedy the breach. MiCA provides for multimillion-euro fines, restrictions on senior management, and the suspension or withdrawal of authorisation. In this article, we examine the core elements of an effective MiCA compliance framework and the vulnerabilities companies should address first.
Why MiCA compliance is now critical for crypto companies
The MiCA transition period has effectively ended. The Regulation has applied in full since 30 December 2024. Transitional regimes introduced by individual EU Member States could remain in place only until 1 July 2026. As ESMA stresses, CASPs without the required authorisation had to cease regulated activities and implement an orderly wind-down plan by that date. Filing an application alone does not allow a company to continue operating after the relevant transition period if authorisation has not yet been granted.
Regulatory risks also remain for authorised companies. MiCA requires ongoing compliance with organisational, prudential, and operational standards. Companies must protect client assets, manage conflicts of interest, and provide clear information to clients. National competent authorities may review both internal documents and their practical implementation. They can also assess governance quality and management’s ability to control risks.
ESMA’s public MiCA register has become another supervisory tool. It contains information on authorised CASPs, issuers, crypto-asset white papers, and entities that provide crypto-asset services without meeting regulatory requirements. A breach may therefore lead not only to a fine or loss of authorisation but also to public reputational damage.
Which companies and activities fall under MiCA
Before developing a compliance framework, a company must determine its regulatory status. MiCA requirements differ for crypto-asset service providers, token issuers, and persons that offer crypto-assets to the public or seek their admission to trading.
CASPs and regulated crypto-asset services
CASP authorisation is required for companies that professionally provide crypto-asset custody and administration, operate trading platforms, exchange crypto-assets for funds or other tokens, execute and transmit client orders, place assets, provide advice, manage portfolios, or transfer crypto-assets in the EU. The specific services determine the scope of authorisation, capital requirements, and operational obligations. A company cannot provide services outside its authorisation.
The requirements also apply to non-EU companies offering these services to EU clients. The reverse solicitation exemption is interpreted narrowly and applies only when the client initiates the relationship entirely on their own initiative.
Token issuers and white paper requirements
MiCA divides crypto-assets into asset-referenced tokens (ARTs), e-money tokens (EMTs), and other crypto-assets. Their classification determines the requirements for issuers, authorisation, asset reserves, holder rights, and white paper content. Companies may use the standardised test and templates developed by the EBA and ESMA, but the final assessment must reflect the token’s actual features and functions.
Activities outside MiCA and related regimes
MiCA does not apply to assets classified as financial instruments or already regulated under other EU financial services legislation. Genuinely unique NFTs and services provided in a fully decentralised manner without an intermediary may also fall outside MiCA. However, labelling an asset as an NFT or DeFi product does not create an exemption. An incorrect regulatory perimeter assessment may result in unauthorised activity and penalties before other compliance procedures are even reviewed.
MiCA penalties: why liability may exceed €5 million
The penalty depends on the type and duration of the breach, the benefit gained, the company’s financial position, and the impact on clients. MiCA sets the minimum enforcement powers that EU Member States must give national regulators. National law may impose higher penalties.
Administrative fines for legal entities
Under Article 111 of MiCA, competent authorities must be able to impose maximum fines of at least €5 million on legal entities for breaches involving crypto-asset issuance, ARTs, EMTs, and CASP activities. Depending on the breach, a percentage of total annual turnover may apply instead:
- Up to 3% for breaches involving the offer or admission to trading of crypto-assets other than ARTs or EMTs;
- Up to 12.5% for breaches of rules applying to ART and EMT issuers;
- Up to 5% for breaches of CASP requirements.
If the offender is a parent company or its subsidiary, turnover may be calculated from the ultimate parent company’s consolidated accounts. The fine may also reach at least twice the profits gained or losses avoided, where this amount can be determined, even if it exceeds the standard limit.
Separate liability for market abuse
Stricter rules apply to insider dealing, unlawful disclosure of inside information, and market manipulation. For the most serious breaches, a legal entity may face a fine of at least €15 million or 15% of its total annual turnover. If the benefit can be calculated, the fine may reach at least three times that amount.
These rules are especially important for trading platforms and other CASPs with access to information on listings, large orders, and client transactions. Weak suspicious activity controls may be treated as both an operational failure and a threat to market integrity.
Non-financial consequences of breaches
Regulatory measures are not limited to fines. A competent authority may also impose:
- A public statement naming the offender and the breach;
- An order to stop the unlawful conduct;
- Disgorgement of profits gained from the breach;
- Suspension or withdrawal of CASP authorisation;
- A temporary management ban for responsible executives;
- A management ban of at least ten years for repeated breaches of certain market abuse rules.
MiCA non-compliance therefore creates financial, operational, and reputational risks. Losing the right to operate in the EU may be more damaging than the fine itself.
Core elements of a MiCA compliance framework
MiCA compliance must cover corporate governance, financial resilience, client protection, and operational risk controls. ESMA stresses that written policies cannot replace sufficient staff, effective management oversight, and a genuine CASP presence in the EU.
Governance and management body
Management body members must have the required knowledge, experience, and good repute. A CASP must:
- Clearly assign responsibilities among managers;
- Approve risk management and internal control procedures;
- Give the management body direct access to compliance information;
- Regularly document decisions, breaches, and corrective actions;
- Maintain sufficient human and technical resources in the EU.
According to the ESMA supervisory briefing, regulators should closely examine complex group structures, extensive outsourcing, and models where key functions are performed outside the EU.
Prudential safeguards and asset protection
A CASP must maintain prudential safeguards equal to the higher of one quarter of the previous year’s fixed overheads or the minimum capital required for its service class. Depending on the activity, the threshold is €50,000, €125,000, or €150,000.
Companies must also:
- Separate client crypto-assets and funds from their own assets;
- Keep accurate records of each client’s positions;
- Prevent client assets from being used for the company’s own account;
- Maintain asset return and business continuity procedures;
- Provide clients with clear custody agreements.
Conduct of business and client protection
Client information, including marketing communications, must be fair, clear, and not misleading. The compliance framework must cover:
- Disclosure of service costs and related risks;
- Complaint handling within applicable deadlines;
- Identification, prevention, and disclosure of conflicts of interest;
- Execution and transmission of client orders;
- Suitability assessments for advice or portfolio management;
- Prevention and detection of market abuse.
Outsourcing and third-party risk
Outsourcing KYC, cloud infrastructure, transaction monitoring, or other functions does not transfer the CASP’s responsibility. The company must assess providers in advance, include access and audit rights in contracts, monitor service quality, and maintain an exit plan. Outsourcing must not leave the CASP without its own resources, management control, or operational independence.
MiCA does not operate alone: AML, Travel Rule and DORA
MiCA authorisation does not replace other EU requirements. A CASP must combine MiCA compliance with AML/CFT controls, the Travel Rule, sanctions screening, and digital operational resilience rules.
AML/CFT and the Travel Rule
Regulation (EU) 2023/1113 requires crypto-asset transfers to include information on the originator and beneficiary. In practice, a CASP must:
- Collect and verify the required data before a transfer;
- Detect missing or incomplete information;
- Apply risk-based procedures to execute, suspend, or reject transfers;
- Verify ownership of self-hosted addresses for transfers above €1,000;
- Store and transmit information securely;
- Assess the counterparty’s sanctions and AML/CFT risks.
The EBA Travel Rule Guidelines have applied since 30 December 2024. They clarify how to handle incomplete data, intermediary transfers, and transactions involving self-hosted addresses.
DORA and operational resilience
DORA has applied to authorised CASPs since 17 January 2025. Companies must manage ICT risks, record and classify incidents, test digital resilience, and control contracts with ICT third-party providers. The MiCA outsourcing policy and DORA framework should align on responsibilities, reporting lines, and recovery plans.
Stablecoins and asset review
Before listing or providing services for ARTs and EMTs, a CASP must verify the issuer’s status and the token’s MiCA compliance. ESMA and the European Commission required certain services involving non-compliant ARTs and EMTs to cease. The token approval procedure should therefore include documented classification, issuer verification, and ongoing monitoring.
Practical MiCA compliance checklist for crypto companies
A compliance review should be conducted regularly and before launching a new product, entering another EU country, or changing the operating model. The review should cover the following actions:
- Determine the regulatory classification of each token, product, and service;
- Compare actual activities with the scope of CASP authorisation;
- Review responsibilities across the management body, compliance, risk, and operational teams;
- Confirm compliance with capital and prudential safeguard requirements;
- Test the segregation, recording, and return of client assets;
- Update disclosures, marketing communications, and complaint-handling rules;
- Review the conflicts of interest policy and client order execution procedures;
- Assess outsourcing arrangements, contractual safeguards, and exit plans;
- Align MiCA procedures with AML/CFT, the Travel Rule, and DORA;
- Introduce listing controls for ARTs and EMTs;
- Review mechanisms for detecting insider dealing and market manipulation;
- Document incidents, management decisions, and corrective actions.
The results should be recorded in a gap analysis that identifies each weakness, its risk level, the responsible person, and the remediation deadline. This document helps the management body monitor corrective measures and shows the regulator that the company detects and addresses breaches promptly.
How Key2Law helps crypto companies maintain MiCA compliance
The Key2Law team supports crypto companies at every stage of operating in the regulated EU market, from defining the regulatory perimeter and preparing for authorisation to regular compliance reviews after approval. We help align corporate governance, internal procedures, and operating models with MiCA and related regulatory regimes.
Key2Law’s support includes:
- Classification of crypto-assets, ARTs, and EMTs;
- Assessment of products and services under MiCA;
- Support with CASP authorisation;
- MiCA compliance gap analysis;
- Development and updating of governance and internal control frameworks;
- Review of safeguarding, custody, and complaint-handling procedures;
- Assessment of outsourcing arrangements and third-party risks;
- Integration of AML/CFT, Travel Rule, and DORA requirements;
- Review of token listings and marketing communications;
- Preparation for regulatory inspections and remediation of identified gaps;
- Ongoing regulatory monitoring and updates to internal procedures.
If your company needs to review its MiCA compliance framework, close compliance gaps, or prepare for a supervisory inspection, contact the Key2Law team. We will develop a practical action plan based on your authorisation, products, structure, and target markets.
__________________________________________________________________________________________________-
This article is provided for general informational purposes and does not constitute legal, tax or financial advice. Applicable requirements depend on the jurisdiction and specific circumstances; professional advice should be obtained before making legal or business decisions.