CASP platform assessment: legal & technical review before MiCA authorization
Key2Law conducts a regulatory and technical CASP platform assessment before the authorisation application is filed. We examine whether the platform’s actual operations align with its stated business model, internal policies, MiCA requirements and applicable DORA obligations. The client receives a structured report with classified findings and practical recommendations.
- Identify inconsistencies between documentation and actual platform operations
- Assess ICT infrastructure and operational resilience mechanisms against DORA requirements
- Classify findings according to their regulatory significance
- Provide a prioritised remediation plan
- Support remediation and conduct a follow-up readiness review where required
What regulators actually check in a CASP application
Regulators assess more than the completeness of submitted documents. They examine whether the applicant can deliver the proposed services in practice. Under Article 62 of MiCA, an application must cover the operating model, governance and internal controls, business continuity arrangements, and technical documentation of ICT systems and security measures. ESMA’s 2025 peer review of the MFSA also confirmed the need for thorough scrutiny of ICT systems and DORA preparedness before authorisation is granted. Policies, platform architecture and actual operating processes must therefore be consistent.
Issues that may delay or obstruct authorisation include:
- Inconsistencies between the services described in the CASP application and the platform’s actual architecture
- The absence of an implemented ICT risk management framework aligned with DORA
- Weaknesses in custody infrastructure, key management and client asset segregation
- Inadequate procedures for detecting, classifying, escalating and recording ICT-related incidents
- Unclear outsourcing arrangements and insufficient oversight of third-party ICT providers
- A lack of evidence that backup, business continuity and disaster recovery arrangements work in practice
What we analyse: scope of the platform assessment
We review the platform from legal, regulatory and technical perspectives to assess its readiness for CASP authorisation under MiCA and the applicable DORA, TFR and AML/CFT requirements.
Legal and regulatory alignment
We compare the platform’s actual operations with the documentation included or intended to be included in the CASP application:
- Verify whether platform functions, user journeys and operational processes correspond to internal policies and procedures
- Map the proposed CASP services against actual transaction, asset and data flows
- Assess whether documented controls are embedded in day-to-day platform workflows
- Identify inconsistencies in the allocation of responsibilities between the applicant, group entities and external providers
- Review whether client disclosures and terms of service accurately reflect the platform’s functionality
Technical architecture and key systems
The technical assessment covers the critical components on which the security, continuity and control of CASP services depend. We examine not only whether the required systems and controls exist, but also how they operate in practice and whether they are consistent with the applicant’s documentation.
- Overall platform architecture. Core components, system interconnections, data flows and critical dependencies are mapped and analysed.
- Custody and wallet infrastructure. The assessment covers asset storage, key management, client asset segregation and controls over wallet operations.
- Transaction and order processing. The review focuses on routing, execution, confirmation, reconciliation and record-keeping.
- Access controls and authentication. User permissions, employee access, multi-factor authentication and privileged access management are examined.
- Logging and audit trails. Particular attention is given to the completeness, protection, retention and accessibility of system logs.
- Data storage and processing. The analysis covers data location, access rules, retention periods and protection during transmission and processing.
- Information security controls. Existing measures are evaluated for their ability to prevent, detect and address cyber threats and vulnerabilities.
- Third-party integrations and APIs. Connections are reviewed for security, access restrictions, data exchange controls and ongoing oversight.
- Outsourcing and external ICT providers. Responsibilities, contractual safeguards, monitoring arrangements and third-party risks are examined.
- Operational resilience. The platform’s ability to maintain critical functions during system failures and other disruptions is evaluated.
- Backup and recovery arrangements. Backup procedures, business continuity plans, disaster recovery measures and testing evidence form part of the review.
- Incident management and monitoring. Detection, classification, escalation, documentation and regulatory reporting procedures are assessed.
Regulatory gap analysis: what we identify
We compare the documentation, platform functionality, technical infrastructure and operational processes. Each finding is classified according to its regulatory significance and potential impact on the CASP application.
- Regulatory compliance gaps. Missing, incomplete or incorrectly implemented requirements under MiCA, DORA and other applicable frameworks.
- Technical deficiencies. Weaknesses in ICT infrastructure, security systems, access controls, monitoring or operational resilience mechanisms.
- Documentation and platform inconsistencies. Cases in which policies and procedures describe processes that differ from the system’s actual operation.
- Missing disclosures or controls. Required information, procedures or technical mechanisms that are absent or cannot be evidenced in practice.
- Authorisation risks. Issues that may complicate the assessment, require substantial remediation or affect the regulator’s decision.
- Issues likely to generate regulatory questions. Unclear or contradictory elements that may result in additional requests for information or supporting evidence from the NCA.
Each finding is assigned a significance level. Critical findings may materially affect authorisation and require immediate remediation. Medium findings may generate regulatory questions or require further work. Low findings have a limited potential impact but should still be addressed to improve the platform’s overall readiness.
What you receive: assessment report and recommendations
The final deliverable is a structured report for internal use and CASP authorisation preparation. It explains which issues require remediation, how significant they are and how they may affect the application review.
- Detailed findings report. Each finding identifies the affected process or platform component, the relevant regulatory basis and the assigned significance level.
- Prioritised action plan. Recommendations are arranged so that critical and high-impact deficiencies can be addressed first.
- CASP application impact assessment. The report identifies issues that may generate additional NCA requests, delay the review or require substantial remediation.
Additional support
After delivering the report, Key2Law can assist the client’s team with implementing the recommended changes and addressing the identified deficiencies. A follow-up readiness review can also be conducted before submission to assess the completed remediation and determine whether any material authorisation risks remain.
Who this service is for?
The assessment is suitable for crypto companies preparing for CASP authorisation, refining an application or seeking to verify their platform’s alignment with MiCA and DORA requirements.
- Centralised crypto exchanges. Platforms providing crypto-asset exchange, order execution and trading operations.
- Custodial wallet providers. Companies responsible for safeguarding client crypto-assets, managing keys and controlling wallet operations.
- Crypto brokers and order execution services. Providers receiving, transmitting or executing client orders.
- Crypto payment and transfer providers. Services processing, routing or facilitating crypto-asset transfers.
- Trading platforms and portfolio management services. Businesses with complex transaction execution, access control and client data processing arrangements.
- Companies transitioning from a former VASP regime to CASP authorisation. Businesses that need to align their platform, documentation and internal processes with MiCA and DORA.
- Crypto projects preparing to approach an NCA. New or existing platforms seeking an independent assessment of their regulatory position before filing an application or engaging with the competent authority.
Want to know where your platform stands before the regulator does?
A free consultation will help define the assessment scope based on your business model, proposed CASP services, target jurisdiction and current application status.
How the CASP platform assessment works
The assessment follows five structured stages. Its scope and timeline depend on the business model, infrastructure complexity, proposed CASP services and the readiness of the supporting documentation.
Stage 1. Scoping call
The initial discussion provides a clear understanding of the client’s business model and defines the precise boundaries of the assessment. This allows the review to focus on the systems, processes and regulatory requirements that are directly relevant to the specific CASP application.
- Review of the business model and proposed CASP services.
- Confirmation of the target jurisdiction and current application status.
- Agreement on priority areas, required documentation and the appropriate form of platform access.
Stage 2. Document and platform review
The client’s internal documentation is examined alongside the platform’s actual operation. The purpose is to determine whether the procedures and controls described in the application materials are properly implemented within the technical infrastructure and day-to-day workflows.
- Analysis of internal policies, procedures, architecture diagrams and technical descriptions.
- Review of key systems, integrations, controls and operational processes within the agreed scope.
- Comparison of the documentation with actual transaction, asset and data flows and user journeys.
Stage 3. Gap identification and classification
The collected information is assessed against the applicable MiCA, DORA and related regulatory requirements. Each finding is linked to the affected platform component, its likely relevance to the NCA and the urgency of the required remediation.
- Identification of regulatory gaps, technical deficiencies and internal inconsistencies.
- Evaluation of each finding’s potential impact on the CASP application.
- Assignment of a critical, medium or low significance level.
Stage 4. Report delivery
The client receives a structured working document rather than a generic list of observations. The report explains what was identified, why each issue matters for authorisation and which corrective actions should be addressed first.
- Description of each finding, its regulatory basis and potential consequences.
- Development of a prioritised action plan.
- Presentation of the results to the client’s team with clarification of the recommended next steps.
Stage 5. Remediation support and follow-up review
Key2Law can continue supporting the client after the main report has been delivered. This may include assistance with implementing the recommended changes, reviewing supporting evidence and reassessing the platform’s readiness before submission.
- Assistance with implementing changes to documentation, processes and technical controls.
- Verification that critical and material findings have been addressed appropriately.
- A follow-up readiness assessment before final submission of the CASP application.
Why conduct the assessment before filing your CASP application?
Once an application has been submitted, any material inconsistency becomes part of the regulatory dialogue. The applicant has less flexibility to change its architecture, processes and documentation, while remediation must be managed during an active NCA review. A pre-licensing platform review creates an opportunity to address these issues in advance and present a more coherent and substantiated operating model.
- Fewer additional information requests. A complete and consistent application reduces the likelihood of NCA requests for further explanations or supporting evidence.
- Alignment between the application and the platform. Submitted documentation reflects the actual architecture, functionality and operational processes.
- Earlier identification of critical deficiencies. Complex technical and organisational issues are detected before the formal review begins.
- Controlled remediation. Necessary changes can be planned and implemented without the pressure of an active regulatory request.
- A stronger CASP application. Clear processes, evidenced controls and consistent documentation improve the credibility of the proposed operating model.
- DORA readiness from the start. ICT systems, incident management, business continuity and third-party oversight are reviewed before authorisation.
Why choose Key2Law for your CASP platform assessment
CASP authorisation readiness cannot be assessed through documentation or technical infrastructure in isolation. Key2Law brings these areas together in one review and explains how specific platform features may affect the regulatory assessment.
- Legal, regulatory and technical expertise. Documentation, processes and infrastructure are examined as connected elements of a single operating model.
- An integrated MiCA and DORA approach. The assessment considers both CASP authorisation requirements and the related digital operational resilience obligations.
- Focus on NCA expectations. Findings are evaluated in light of the questions and evidence likely to be relevant during the application review.
- Risk-based classification. Each issue receives a significance level, allowing the client’s team to identify which changes require priority.
- Practical deliverables. The final report provides both a clear explanation of the deficiencies and prioritised remediation recommendations.
- Post-assessment support. Key2Law can assist with implementation and conduct a follow-up readiness review before submission.
This approach gives technical, compliance and management teams a shared understanding of the platform’s current readiness. Instead of receiving disconnected observations, the client obtains a coordinated action plan linked to specific requirements, systems and CASP application risks.
Ready to check your platform before the regulator does?
Book a free consultation to discuss your platform’s current status, CASP application preparation and priority assessment areas. The scope will be tailored to your business model, infrastructure and target jurisdiction.
Frequently asked questions
What is a CASP platform assessment?
A CASP platform assessment is a pre-licensing review of a crypto platform’s documentation, operational processes and technical infrastructure. It determines whether the system’s actual operation is consistent with the proposed business model and the applicable MiCA and DORA requirements.
Is the assessment mandatory for a MiCA application?
No. MiCA does not require applicants to commission a separate external platform assessment. However, Article 62 of MiCA requires information on internal controls, business continuity, ICT systems, security arrangements and other operational mechanisms. A pre-filing review helps verify that this information is supported by the platform’s actual operation.
What is DORA and why does it matter for CASP authorisation?
DORA establishes requirements for ICT risk management, incident handling, operational resilience and oversight of external technology providers. The regulation has applied since 17 January 2025 and covers CASPs. Relevant systems and processes must therefore be ready to operate when authorisation is granted.
How long does the assessment take?
The timeline depends on the platform architecture, the number of proposed CASP services, the volume of available documentation and the complexity of third-party integrations. A schedule is established after the scoping call and confirmation of the assessment scope.
Do you need access to our platform’s source code?
Not in every case. Architecture diagrams, technical documentation, configurations, process descriptions, system demonstrations and other supporting evidence are often sufficient. Any need to access specific components or source code is identified in advance and agreed with the client.
What happens if you find critical issues?
A critical finding is documented together with its regulatory basis, potential application impact and recommended remediation. Its identification does not automatically mean that authorisation will be refused. It indicates which deficiencies require priority attention before filing or continuing the dialogue with the NCA.
Can Key2Law help us fix the issues identified?
Yes. Additional support may include revising documentation, adjusting processes, implementing or strengthening controls and coordinating changes with the technical team. A follow-up readiness review can be conducted after remediation.
Is the assessment relevant if we have already submitted the CASP application?
Yes, although the scope will depend on the current review stage and any requests already received from the NCA. The assessment can identify inconsistencies, support the preparation of responses and establish remediation priorities. An earlier review generally provides more flexibility to align the documentation, systems and processes.