Skip to content
← The MiCA course

Reference layer — the MiCA course now starts at the front door; this page is where you look things up once you know the shape.

MiCA · In operation

MiCA in operation

Every rule on this page is in force or applying. For each one you get three things: the question it answers, what it makes the firm do at the desk, and what it means in the boardroom — with the citation and its lifecycle stage underneath, where a citation belongs. Read down one column or across both; nothing is hidden behind a tab.

Which rules bind you at all?

Three boundary questions come before any obligation: whether a token is inside MiCA, whether a non-EU desk can serve EU clients without a licence, and whose rules a given instrument actually addresses. Get these wrong and everything downstream is wrong with them.

Is your token inside MiCA — and which title catches it?

The definitions sort every token in a fixed order, and each answer forecloses the ones after it. Learn the order once and most classification arguments resolve themselves.

At the desk

  • Ask the gate question first: is it a financial instrument? The qualification guidelines put nine guidelines behind that gate, not one test — only what survives them is sorted inside MiCA.
  • Guideline 2's transferable-security test is cumulative — not a payment instrument, forms a class, negotiable — all three or it is not one.
  • Failing Guideline 2 settles nothing: Guidelines 3 to 6 then test money-market instrument, fund unit, derivative and emission allowance in turn — and a hybrid showing any financial-instrument feature sorts as one (Guideline 9).
  • Sort on substance, never on form: the guidelines are technology-neutral, a tokenised bond stays a bond, and an issuer's label decides nothing.
  • Cite the guidelines by date as well as reference: the final report and the issued guidelines share the same ESMA document number — the date is what makes a citation unambiguous.
  • Then the purport test: does the token claim to hold a stable value by referencing something? No claim means Title II, and possibly a utility token.
  • Stable against exactly one official currency is an EMT. Anything else that stabilises — a basket, gold, another asset — is an ART: the definition is expressly the residual.
  • Write the analysis down. Malta applies the qualification guidelines by name; Austria's form asks which crypto-asset types each service touches. The sort is a filed document, not a hallway opinion.

In the boardroom

  • The market is not symmetrical: at the 24 August 2026 snapshot the register held 43 e-money-token white-paper records from 23 issuers — and zero authorised ART issuers. Plan against the regime that exists, not the one on the org chart of the Regulation.
  • A token that turns out to be a financial instrument is a different licence, timetable and cost base. Finding out late is the expensive version.

So whatRun the sort on paper for one token you know well — gate, purport, one-currency, residual — and file the page. The discipline is the deliverable; no reader's real token is classified here.

the definitions: Arts 2(4), 3(1)(5)–(9) · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the gate test — when a token is a financial instrument and outside MiCA entirely · ESMA Guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments (ESMA75-453128700-1323) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
the consultation record behind the gate test · ESMA Final Report, Guidelines on the qualification of crypto-assets as financial instruments (ESMA75-453128700-1323, 17 Dec 2024) · draft — not yet adopted · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — definitions and guidelines re-read in the held texts

Can a non-EU desk serve EU clients without a licence?

Only where the client came entirely of their own initiative — and the guidelines close every door a business model could be built through.

At the desk

  • Treat solicitation as anything: pop-ups, sponsorships, app-store presence — even general brand advertising to the EU public may count.
  • Count influencers and intermediaries as the firm: payment is a strong indication, its absence not decisive. An EU entity redirecting clients to a non-EU affiliate makes the provision a breach.
  • Keep records of who initiated what. Disclaimers cannot supersede contrary facts — the checkbox is worth nothing against a marketing trail.
  • Hold the exemption to the original transaction's context: even the same crypto-asset cannot be marketed to the same client a month later.

In the boardroom

  • Reverse solicitation appears in no register and produces no evidence of authorisation. A revenue line that rests on it has no affirmative story to tell a counterparty, a bank or a supervisor.
  • Half of the guidelines is written for supervisors, not firms: a list of methods for detecting who is really marketing into the EU. Assume the authority reads the same internet your marketing team writes on.

So whatCite Article 61(3) for both guidelines mandates. There is no Article 61(4) — and material citing one has copied a phantom, which tells you who copied whom.

Article 61 — the exemption itself · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
both Art 61(3) limbs, as issued · ESMA Guidelines on reverse solicitation under MiCA (ESMA35-1872330276-2030; final report ESMA35-1872330276-1899) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — the issued guidelines re-read; stage from the registry

Whose security rules are these — yours, or someone else's?

Start with who these speak to, because it is not who most summaries assume.

Who this speaks toThe systems-and-security guidelines address competent authorities, offerors and persons seeking admission to trading — not CASPs. A CASP's ICT obligations run principally through DORA.

At the desk

  • If you offer or seek admission of a token: five guidelines — proportionality, governance with management-body accountability, physical access, logical access on least privilege, and cryptographic keys managed through their whole lifecycle.
  • Name the person responsible for keys, from generation to destruction, with replacement methods for loss or compromise and a register of certificates for critical assets.
  • If you are a CASP reading these: check your DORA programme first — these guidelines are not your instrument.
  • Read each guideline's own applies-from clause, never a generalisation: these security guidelines run 60 calendar days from their translation date, while the market-abuse supervisory guidelines chose three months — same document type, two different clocks.

In the boardroom

  • Misreading an instrument's addressee produces confident compliance with someone else's rulebook. The five-minute scope check is the cheapest control in this whole stack.

So whatBefore adopting any instrument into your framework, read its scope section's 'Who?' paragraph aloud in the meeting. If your entity type is not in it, file it under context, not obligations.

Art 14(1)(d) — the white-paper side's ICT floor · ESMA Guidelines on the maintenance of systems and security access protocols, Art 14(1)(d) (ESMA75-223375936-6132; final report ESMA75-223375936-6089) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗
where a CASP's own ICT obligations actually live · Regulation (EU) 2022/2554 (DORA) · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the issued guidelines' scope re-read; stage from the registry

2024 H220252025 H22026Titles III–IV applyMiCA applies in full2024/28612024-12-032025/2942025/2992025/4162025/4172025/3052025/3062025/4142025-03-05 – 04-202025/11402025/11422025-06-302025/8852025-09-092024/29842025/4212025-12-23
When each act in the operating stack started biting — applies-from dates drawn from the instrument registry at build, against MiCA’s own two Level-1 application dates.

What actually goes in the authorisation file?

The Level-1 list looks like nineteen items. The RTS underneath it is far more demanding — and it is the document the case officer actually reads against.

At the desk

  • Draft the programme of operations as a three-year commitment: group strategy, every activity regulated or not, target countries with client numbers, websites and languages, outsourcing named and located, forecasts with stress scenarios.
  • Build the AML section to the RTS's shape: your own inherent-and-residual risk assessment, a copy of the policies themselves, the named AML officer with evidence of competence, the training plan.
  • Describe segregation to the key-ceremony level: how keys are approved, how omnibus wallets separate one client from another, funds to a credit institution by close of the next business day.
  • Submit on the mandatory form. A mid-assessment change to the file restarts the clock — notify nothing avoidable.

In the boardroom

  • The programme of operations is what you will be supervised against. Changing the permission set later is a fresh application, assessed on the same clock.
  • Budget more senior time and external spend for this file than for any other phase of the journey — and budget it before the filing date is promised, not after.
Exhibit · What one authority's intake actually looks like
  • One PDF per information point, I to XVII — general information through custody policy and trading-platform rules
  • File names following the structure of the form, with exact references back to its numbered points
  • Submission through the authority's platform, access issued by email before filing
  • Non-applicability of any point justified in writing — never left blank
  • Any change to submitted documents notified immediately, in writing, while the procedure runs

The Austrian FMA's Art 62 application form (EN, held) — the EU-wide CIR 2025/306 template, expanded with the CDR 2025/305 catalogue

So whatOpen the RTS next to your draft file and tick article by article. The application journey dossier then walks the whole process with the statutory clocks — read it before the board asks for a date.

the information catalogue, article by article · Commission Delegated Regulation (EU) 2025/305 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the mandatory form and the procedures around it · Commission Implementing Regulation (EU) 2025/306 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — RTS/ITS and the held FMA form re-read

Who may run the firm — and who may own it?

Two gates on people: the board is assessed one by one and as a collective, and anyone buying a qualifying stake is assessed all over again.

At the desk

  • Assemble per-member proof: no convictions or penalties in AML, fraud, financial services, insolvency or professional liability — and evidence the board collectively knows this business.
  • Treat competence as qualifications and experience together: national practice expects hands-on time, ordinarily with a regulated firm, with supervised practice as the bridge where one limb is thin.
  • Trace ownership to ultimate beneficial owners before someone else does. A qualifying holding is 10% or significant influence — and an acquisition triggers its own assessment with its own file.

In the boardroom

  • Your own record is now a regulatory filing. Disclosure is survivable; discovery is not.
  • An unready shareholder can stall the firm's application: qualifying holders supply their own fit-and-proper evidence, on the firm's timetable.

So whatKeep a living suitability file per board member and per qualifying holder — assessed at appointment and on every change. The Malta and Austria panels on this page show two supervisors running exactly this check, differently.

the Union standard for a fit management body · Joint EBA/ESMA Guidelines on the suitability assessment of members of the management body of issuers of ARTs and of CASPs (EBA/GL/2024/09; ESMA75-453128700-10) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
what a proposed qualifying holder must file · Commission Delegated Regulation (EU) 2025/414 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the joint guidelines and the RTS re-read; national layer per the NCA panels

What must happen when a client complains?

Complaint-handling is specified to the template level — filing, acknowledgment, investigation, decision, and how you talk to the complainant throughout.

At the desk

  • Publish the procedure and the standard complaint template; let clients file by the stated means and languages.
  • Acknowledge receipt, verify admissibility, and investigate on the clock your own published timeline sets — then issue a reasoned decision and say what happens next.
  • Keep the complaint file: the register of complaints, the communications, the measures taken in response.

In the boardroom

  • The complaints book is the first thing an examiner samples, because the rules make you keep exactly the records that show how clients are actually treated. A tidy book is the cheapest credibility the firm can buy.

So whatTime-stamp your last five complaints end to end and compare them against your published procedure. The gap between the two documents is your finding before it is anyone else's.

Commission Delegated Regulation (EU) 2025/294 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

What must keep running when something breaks?

Continuity and regularity of the service is its own regulated subject — organisational arrangements, a policy, plans, and tests that actually run.

At the desk

  • Stand up the three layers the RTS names: organisational arrangements, a business-continuity policy, and the plans that implement it.
  • Test the plans periodically — a plan that has never run is a document, not a control.
  • Scale everything to complexity and risk: the RTS builds proportionality in, which means your reasoning for the scale you chose must exist in writing.

In the boardroom

  • Continuity failures are client-visible within minutes and supervisor-visible within days. The test calendar is a board agenda item, not an IT one.

So whatFind the date of your last continuity test and the list of what failed. If either takes more than a day to produce, that is the work.

Commission Delegated Regulation (EU) 2025/299 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Which records must exist, and in what shape?

The record-keeping RTS names the records by category — policies, client agreements, safekeeping, orders, transactions — and the shape they must hold.

At the desk

  • Map your stores to the RTS's categories: policies and procedures; the documents setting out the firm's and the client's rights; safekeeping of client crypto-assets and funds; orders; transactions.
  • Key entities by identifier — the firm's own LEI exists precisely so supervisors can join your records to everyone else's.
  • Where platform records overlap other regimes' standards, keep them to those standards — the RTS says so itself.

In the boardroom

  • Records are the firm's memory under examination: every other module on this page is evidenced — or not — by what this one keeps.
Exhibit · The record categories, as the RTS names them
  • Retention of records — the general duty and its clock
  • The firm's policies and procedures, as records in themselves
  • Documents setting out the firm's and the client's rights and obligations
  • Safekeeping records for clients' crypto-assets and funds
  • Records of orders — and of transactions

CDR (EU) 2025/1140, Articles 2–7 (held)

So whatPut the RTS's record categories next to your systems inventory and mark every record you could not produce this week. The regulation names the records; the gap list is yours to own before anyone asks.

Commission Delegated Regulation (EU) 2025/1140 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

How must conflicts be policed — and disclosed?

The conflicts RTS splits the subject the way the risk splits: conflicts that can hurt the firm, conflicts that can hurt clients, and the policies, pay structures and personal trades behind both.

At the desk

  • Run both inventories the RTS runs: conflicts potentially detrimental to the firm, and those potentially detrimental to clients — they are different lists with different owners.
  • Cover remuneration and personal transactions explicitly: the RTS gives each its own policy article, including the connected persons around your people.
  • Disclose with content, not boilerplate: the disclosure states the role and capacity in which the firm acts when providing the service.

In the boardroom

  • Crypto firms concentrate roles — venue, dealer, custodian — that traditional finance separates by licence. The conflicts file is where that concentration is either managed or exposed.

So whatTake one service you provide in two capacities and write down who could be hurt and how the client is told. If the disclosure reads like boilerplate, it is.

Commission Delegated Regulation (EU) 2025/1142 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Running a venue: what must it record and show?

A trading platform carries two data duties of its own: an order book kept to a prescribed content and format, and transparency data presented the prescribed way.

At the desk

  • Keep the order book to the RTS's field set and format — it is a supervisory record, designed to be read by machines other than yours.
  • Present pre- and post-trade transparency data as the second RTS prescribes, not as the product team prefers.
  • Remember the venue's operating rules already owe MiCA an admission process with due diligence on what is admitted — the venue is a gatekeeper, not just a matching engine.

In the boardroom

  • Venue permissions are rare — eighteen platform authorisations in the whole register at the 24 August 2026 snapshot — because the duties attached to them are the heaviest in this stack. If the plan includes a venue, the plan includes that cost.

So whatAsk your venue team to export one day of order-book records in the regulatory format today. The exercise finds the schema gaps while they are still cheap.

order-book records — content and format · Commission Delegated Regulation (EU) 2025/416 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how transparency data is presented · Commission Delegated Regulation (EU) 2025/417 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — both RTS re-read in the held texts; count from the register snapshot

What must you detect — and what must you report?

The market-abuse machinery has two moving parts: arrangements that detect, and the STOR that reports — plus a disclosure duty when the firm itself holds inside information.

At the desk

  • Scale your surveillance to your own size, scale and nature — the RTS builds proportionality in, and expects you to have reasoned it.
  • File a STOR on the template when orders, transactions or DLT behaviour look abusive — including conduct in how transactions are ordered on-chain.
  • If the firm holds inside information about a crypto-asset, publish it by the prescribed technical means — and document any delay on the conditions the ITS sets.

In the boardroom

  • Cross-border coordination is written into the act itself: one suspicious-transaction report can put several authorities around one table. File every report on the assumption that every relevant supervisor will read it.
  • Who counts as a watcher was a genuinely argued question — the consultation's miners-and-validators debate is on the moving-edge page, resolved into this act.
Exhibit · The STOR template's spine
  • Section 1 — who is reporting: legal form, LEI, the capacity in which you acted
  • Section 2 — what you saw: the crypto-asset by DTI (or described without one), its type — ART, EMT or other
  • The trading platform where the order was placed — or the DLT behaviour observed
  • The narrative and attachments that let an authority reconstruct your suspicion

CDR (EU) 2025/885, Annex (held)

So whatPrint the STOR template and walk one hypothetical through it with your surveillance lead. Every field you cannot populate names a data feed you do not yet have.

the systems and the STOR template · Commission Delegated Regulation (EU) 2025/885 · applicable — this binds · verified 2026-08-26 · Read the text ↗
publishing — and lawfully delaying — inside information · Commission Implementing Regulation (EU) 2024/2861 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how the authorities are told to look · ESMA Guidelines on supervisory practices for competent authorities to prevent and detect market abuse under MiCA (ESMA75-453128700-1039; final report ESMA75-453128700-1408) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — RTS, ITS and the drafting record re-read in the held texts

What do the conduct guidelines add on top?

Three ESMA guideline sets sit above the acts: suitability when you advise or manage, procedures and client rights when you transfer, and competence floors for the people doing the advising. Each is at its own lifecycle stage — read the footer.

At the desk

  • Run suitability to the MiFID-aligned standard the guidelines import — the consultation asked whether crypto deserved a lighter regime, and the answer was no.
  • Give portfolio-management clients their periodic statement in the guideline format.
  • Build transfer procedures around the client's rights in them — the guidelines read the service from the client's side of the transaction.
  • Watch the knowledge-and-competence clock: adopted July 2025, but the comply-or-explain clock starts only when translations publish.

In the boardroom

  • Guidelines bind through pressure on your supervisor, not directly on the firm — but a supervisor that declared compliance examines against them as if they were rules. Know your authority's declarations.

So whatFor each guideline set your services touch, note two dates: when it started applying, and when your authority declared compliance. Where the second is missing, ask — the compliance tables are public.

suitability + the periodic statement · ESMA Guidelines on certain aspects of the suitability requirements under MiCA (ESMA35-1872330276-2031; third-package, Art 81(15)) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗
transfer procedures and client rights · ESMA Guidelines on procedures and policies, including the rights of clients, for crypto-asset transfer services (ESMA35-1872330276-2032; third-package, Art 82(2)) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗
staff knowledge and competence — clock not yet started · ESMA Guidelines for the criteria on the assessment of knowledge and competence under MiCA (final report ESMA35-1872330276-2380) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — all three issued texts re-read; stages from the registry

The issuer stack — if you stand behind an ART or EMT

Five modules for the other side of the market: the firms behind the tokens. CASP readers can pass through — nothing here binds a service provider as such. EMT issuers should read with one borrow in mind: Title III's recovery-and-redemption chapter applies to them too, mutatis mutandis, through Article 55.

How much capital stands behind the promise — and when must it rise?

The own-funds line is the first number every stablecoin plan must survive, and it moves twice: with the reserve, and with the supervisor's risk read.

At the desk

  • Hold, at all times, the highest of three floors: EUR 350,000; 2% of the average reserve of assets; a quarter of last year's fixed overheads.
  • Track the average reserve daily — the 2% floor is computed on end-of-day figures over the preceding six months, summed across every ART you issue.
  • Build the stress-testing programme the adopted RTS requires, and expect the authority to read it: its results feed the uplift decision.
  • Plan for the uplift: the home authority can require up to 20% more own funds where risk management, reserve quality and volatility, or the rights granted to holders indicate higher risk.

In the boardroom

  • Capital scales with the promise, not with revenue: growing the token grows the reserve, and 2% of the reserve is the floor that usually binds. Price growth plans against it.
  • The 20% uplift is the supervisor's lever on quality: weak controls or a volatile reserve raise the capital line without any rule changing.

So whatPut the three floors and the uplift trigger on one page with live numbers, refreshed monthly. The day the binding floor changes from EUR 350,000 to 2% of reserve is the day the business model is real.

Article 35 — the floors and the uplift · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
when the authority requires higher own funds, and the stress-testing programme · Commission Delegated Regulation (EU) 2025/415 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — Art 35 re-read in the held OJ text; CDR 2025/415 in the held extract

What must the reserve hold — and how fast must it turn to cash?

The reserve is the promise made physical. One layer of its rules is adopted and binds; the sharpest layer is still a draft — and the difference is exactly what the moving edge teaches.

At the desk

  • Keep a reserve segregated from your own assets, composed and managed so the tokens are backed in substance at all times.
  • Write the liquidity management policy the adopted RTS requires: robust strategies and processes to identify, measure and manage liquidity risk, keeping reserve levels adequate.
  • Where you issue more than one token, set out the policy per token — the RTS expects each reserve's management to be legible on its own.
  • Treat the pending liquidity ladder — minimum bank deposits per currency, concentration limits, the over-collateralisation add-on — as a draft: nothing to comply with tonight, everything to plan against.

In the boardroom

  • Liquidity rules decide who your banks are: deposit minimums and concentration limits, if adopted as drafted, turn reserve management into a bank-relationship strategy. The consultation record on that fight is on the moving-edge page.

So whatSplit the reserve file into two tabs — 'binds now' (Article 36 + the adopted policy RTS) and 'still a draft' (the ladder) — and date both. Most reserve mistakes are stage mistakes.

Article 36 — the reserve of assets itself · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the liquidity management policy and procedures, as adopted · Commission Delegated Regulation (EU) 2025/1264 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the pending reserve-liquidity ladder — a draft, argued both ways on the moving edge · Draft RTS further specifying the liquidity requirements of the reserve of assets, Art 36(4) (EBA/RTS/2024/10) · draft — not yet adopted · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — Art 36 re-read in the held OJ text; CDR 2025/1264 in the held extract; draft stage from the registry

What happens when an issuer wobbles — before anyone fails?

Two plans, written in peacetime: one for recovering, one for winding the promise down in an orderly way. Both are judged long before they are needed.

Who this speaks toEMT issuers too: Title III's recovery-and-redemption chapter applies to them mutatis mutandis through Article 55 — though the reserve-of-assets sections do not reach credit institutions issuing EMTs.

At the desk

  • Structure the recovery plan as the guidelines do: a summary, then governance information, recovery options, and a communication-and-disclosure plan.
  • Choose indicators that are both quantitative and qualitative, calibrated to your own risk profile — and include the one indicator required of every issuer: de-pegging risk.
  • Vary the scenarios: the guidelines expect a set diverse enough to cover the ways your specific token could come under stress.
  • Know the redemption plan's trigger precisely: it is implemented on the competent authority's decision that the issuer is 'unable or likely to be unable to fulfil its obligations' — not on your own assessment.

In the boardroom

  • These plans are pre-crisis filings, reviewed in calm weather. A thin recovery plan reads as a governance finding today, not a contingency for later.
  • The redemption trigger sits with the supervisor. Once that decision is made, the plan you wrote years earlier is the script — which is the argument for writing it as if it will run.

So whatTest the de-pegging indicator this quarter: who sees it, at what threshold, and what meeting does it convene? An indicator nobody is wired to act on is a paragraph, not a control.

Arts 46–47 and the Art 55 borrow · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the recovery plan's content and indicators · EBA Guidelines on recovery plans under Articles 46 and 55 of MiCA (EBA/GL/2024/07) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
the redemption plan's content and triggers · EBA Guidelines on redemption plans under Articles 47 and 55 of MiCA (EBA/GL/2024/13) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — both final reports read in the held extracts made this session

Who answers for the token, day to day?

The governance guidelines write the minimum content of how an issuer is actually run — and the suitability standard for the people running it is the same joint standard CASP boards face.

At the desk

  • Cover the guidelines' three titles in your framework: the management body's role and composition, its management and supervisory functions, and the governance framework itself.
  • Run risk across all three lines of defence — the business managing its risks, the control functions checking, audit assuring — with the management body owning the strategy.
  • Apply proportionality honestly: the guidelines scale with nature, scale and complexity, but proportionality adjusts depth, never removes a topic.

In the boardroom

  • The suitability bar for an issuer's board is the joint EBA/ESMA standard — the same one Malta's questionnaire machinery enforces on CASPs. Nobody at this table is exempt from the fit-and-proper file.

So whatMap your current governance pack against the guidelines' three titles and mark every gap with an owner and a date. The map is the artefact an examiner asks for first.

Article 34 — governance arrangements · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the minimum content of the arrangements · EBA Guidelines on the minimum content of the governance arrangements for issuers of ARTs (EBA/GL/2024/06) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
the joint EBA/ESMA suitability standard for the people · Joint EBA/ESMA Guidelines on the suitability assessment of members of the management body of issuers of ARTs and of CASPs (EBA/GL/2024/09; ESMA75-453128700-10) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — final report read in the held extract made this session

When does your supervisor change to the EBA?

Significance is measured, not chosen: cross the thresholds and supervision itself moves — with heavier duties and the EBA's own fee schedule attached.

At the desk

  • Track the seven criteria continuously, with the three bright lines on a dashboard: 10 million holders; EUR 5 billion issued, capitalised or reserved; 2.5 million transactions worth EUR 500 million a day.
  • Report the data honestly and on time — classification runs on the information periods the Regulation defines, not on press coverage.
  • On classification, expect the mechanics of the EBA's transfer decision: supervision, colleges and reporting lines change owner.

In the boardroom

  • Significance is a cost event as well as a supervisory one: higher own-funds and liquidity duties, plus the EBA's supervision fees. Model the thresholds into growth scenarios before marketing does.

So whatAdd the three bright lines to the same monthly page as the own-funds floors. The issuer stack's numbers belong together — and the board should see the distance to each line, not just today's value.

Article 43 — the criteria and the transfer · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the criteria, as further specified · Commission Delegated Regulation (EU) 2024/1506 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the EBA's own decision machinery for the transfer · EBA Decision on the classification of ARTs and EMTs as significant and the transfer of supervision (EBA/DC/558) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
the EBA's fees on significant issuers · Commission Delegated Regulation (EU) 2024/1503 · applicable — this binds · verified 2026-08-26 · Read the text ↗
what the EBA said it would look at first · EBA statement: supervisory priorities for issuers of ARTs and EMTs 2024/2025 · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — Art 43 re-read in the held OJ text; criteria act and transfer decision from the registry

The disclosure plumbing around you

One module on the machinery that moves disclosure documents around the regime — who must produce machine-readable white papers, and why the format is the point.

Why is a white paper machine-readable — and whose job is it?

One document, two audiences: a retail reader opens the white paper in a browser and reads prose; the register consumes the same file's embedded tags at scale. Inline XBRL is the format that refuses to choose.

Who this speaks toThe drawing-up duty sits with offerors, persons seeking admission and issuers — the white-paper side. A CASP meets this machinery when it seeks admission of a token to its own venue.

At the desk

  • Produce the white paper as one XHTML file with the taxonomy's tags embedded — human-readable without special software, machine-readable without re-keying.
  • Tag the classification data the RTS names: identifiers included — LEIs for persons, the digital token identifier for the asset.
  • Use the standard identifiers by name: the digital token identifier is ISO 24165, and the tagged file is built to flow onward — the national register today, the European Single Access Point as it phases in.
  • Both format acts applied from 23 December 2025 — white papers from year one live in a different format, which any dataset built on the register inherits.

In the boardroom

  • The register is built from the tags in your white paper — what you tag is what supervisors and analysts will query about you. Treat the tagging as disclosure, because that is what it is.

So whatOpen any post-December-2025 white paper from the register, view its source, and find the tags. Once you have seen one, the mandate stops being abstract.

the single XHTML file with Inline XBRL tags · Commission Implementing Regulation (EU) 2024/2984 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the classification data the tags must carry · Commission Delegated Regulation (EU) 2025/421 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the listed-company precedent this borrows from · Commission Delegated Regulation (EU) 2019/815 (ESEF) · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — ITS/RTS re-read; rationale per the acts' own recitals

One regime, thirty implementations

MiCA harmonises the process; it does not harmonise the experience. The map below carries three layers, each from a dated primary — the transitional windows each state chose, the authorisation counts, and the non-compliant register read under the one rule that keeps it honest: a register evidences what it records, never what it omits. Below it, two supervisors are worked in detail, because they teach two different styles of the same regime.

as at ESMA list, 19 May 2026

EEA EFTA — on ESMA’s list, off the EU map frame

Malta

Transitional window (concluded)
18 months, as ESMA’s list of 19 May 2026 records it.
Authorised CASPs · 24 August 2026
22 authorisation records in the register snapshot. Zero is a register fact with a date, not a judgment on the state.
Non-compliant entries · 24 August 2026
0 of the register’s 167entries were notified by this state’s authority.

Two supervisors, worked

Malta shows what a high-volume authoriser asks of the people who will run a firm; Austria shows what an enforcement-first supervisor does with the disclosure rules. Every statement below is traced to a named, dated, published output of the authority itself — and practice goes stale, so each carries its date. Last verified 2026-08-27.

Malta Financial Services Authority

MFSA

What a high-volume authoriser actually asks of the people who will run a CASP — the questionnaire, the competence checking, and a pre-application track with real gates in it.

Transitional window: 18 months. Malta took the full 18-month window (ESMA grandfathering list, 19 May 2026 version). The conference-deck figure happens to agree here — but the list is the citation, not the slide.

  • Journey phase 5. Pre-submission engagement

    The pre-application stage is not voluntary. Prospective applicants are required to submit a Statement of Intent; what is discretionary is the meeting — the Authority 'at its sole discretion' may request further information or attendance at a preliminary meeting, requested within 10 working days of receiving the Intention.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 5. Pre-submission engagement

    The Statement of Intent is a high-level presentation — and it already reaches the sensitive material:

    • a shareholding diagram to the ultimate beneficial owners;
    • any regulatory history of the applicant and related persons, group entities and prior applications to other regulators included;
    • directors and key function holders, with reporting lines and each person's time commitment;
    • an outline of the business model, local substance, client types and target markets.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 5. Pre-submission engagement

    Two gates sit before any review. The application fee is non-refundable and payable on submission. And where the MFSA considers a proposal outside its risk appetite or 'not yet mature enough', it guides the prospective applicant at the Intention Stage — before any fee is paid, without a refusable decision. After a no-objection, the application must follow within 40 working days or the Intention may be treated as withdrawn.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Every proposed director and key function holder is assessed through the Personal Questionnaire against four criteria: competence, reputation, conflicts of interest and independence of mind, and time commitment. The entity assesses first — 'the Entity has the primary responsibility to carry out its own due diligence assessment' — and proportionality 'cannot lead to the lowering of the suitability standards applied by the MFSA'.

    MFSA Guidelines to the Personal Questionnaire (updated version) · 2024-03-12 · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Competence is checked through three mechanisms:

    • a published, non-exhaustive List of Recognised Qualifications;
    • hands-on experience the MFSA expects 'ordinarily with a regulated financial services entity' — the sentence with the most bite for crypto-native management teams;
    • a supervised-practice bridge: a qualified applicant without direct experience may be required to act 'under the supervision of an experienced authorised individual for a specified period', unsupervised only once that person confirms competence. Qualifications and experience are alternatives at the margin, not cumulative requirements.

    MFSA Guidelines to the Personal Questionnaire (updated version) · 2024-03-12 · verified 2026-08-27

  • Journey phase 2. Choosing the home authority

    Which route an applicant took depended on what it held on 30 December 2024. Category A — already licensed under Malta's earlier Virtual Financial Assets (VFA) framework — could use the grandfathering window and a simplified application anchored in a board resolution, the fee and the 2024 MiCA thematic exercise. Category B — mid-application, not yet licensed — ran the full MiCA process from the Statement of Intent up.

    MFSA Circular on the Authorisation Process for MiCA Applicants · 2024-12-10 · verified 2026-08-27

  • Journey phase 4. Building the file

    The pack changed under applicants mid-flight: from 17 June 2025 all CASP applicants, Category A and B alike, had to add two further annexes — AX05, the Digital Operational Resilience Assessment, and AX50, the ICT Third-Party Provider Assessment. That is the EU's Digital Operational Resilience Act (DORA) arriving inside the MiCA application six months after the process opened.

    MFSA Follow-Up Circular on the Authorisation Process for MiCA Applicants · 2025-06-17 · verified 2026-08-27

  • Journey phase 4. Building the file

    Malta's MiCA Rulebook (v3.00) is thin by design because it points outward — it adopts Union instruments by name as the MFSA's own decision rules, including the joint EBA/ESMA suitability guidelines. The national layer is mostly procedure; the substance is the Union standard.

    MFSA Markets in Crypto-Assets Rulebook, v3.00 · 2026-03-10 · verified 2026-08-27

So what — treat Malta's Intention Stage as the application: the sensitive material is on the table before any fee is paid, and the people file is won or lost in the questionnaire.

Finanzmarktaufsicht (Austria)

FMA (AT)

What an enforcement-first supervisor does with the white-paper and marketing rules — and what a mechanised application intake looks like. Its first published MiCAR penal decision is the worked enforcement record.

Transitional window: 12 months. Austria shortened the window to 12 months (ESMA list, 19 May 2026 version). The FMA had said so in its own words in August 2024: existing registered providers could continue until the end of 2025 at the latest ('bis längstens Ende 2025'). The population was small: twelve providers registered under § 32a of Austria's anti-money-laundering act (FM-GwG) as at August 2024.

Austria's Finanzmarktaufsicht (fma.gv.at) is not the Liechtenstein FMA. Liechtenstein is a separate EEA jurisdiction with its own authority — and its own rows in the CASP register.

  • Journey phase 7. Substantive assessment

    Marking full application on 30 December 2024, the FMA announced a particular focus on CASP authorisation procedures from 2025: sufficient own funds, robust risk management, adequate internal control systems and transparent information on business models. It added that fit-and-proper requirements for owners, managing directors and other key function holders would receive increased attention, consistently implemented.

    FMA press release, 'MiCAR-Regime voll anwendbar' · 2024-12-30 · verified 2026-08-27

  • Journey phase 4. Building the file

    The same release flagged DORA applying in parallel from 17 January 2025, with the FMA expecting gapless monitoring of IT systems, regular stress tests and clear contingency plans. The supervisor announced the MiCA file and the ICT expectations together; an applicant that treats the ICT limb as an afterthought is out of step with the FMA's own framing.

    FMA press release, 'MiCAR-Regime voll anwendbar' · 2024-12-30 · verified 2026-08-27

  • Journey phase 4. Building the file

    The Austrian application is mechanised on the face of the form:

    • submission through the FMA Incoming Platform, with access issued by email before submission;
    • each of points I to XVII answered in a separate PDF, the fillable sections carrying only references;
    • file names following the structure of the form;
    • non-applicability of any provision justified, never left blank.

    FMA Application Form for authorisation as a CASP (Art 62 MiCAR), EN, as retrieved 26 Aug 2026 · undated (retrieved 2026-08-26) · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Point VII of the form places the suitability burden on the applicant: it must supply the results of its own assessment of each management-body member and of the body's collective suitability, including the assessment report. The Union standard is the same as Malta's; the division of labour is not — the FMA receives the applicant's completed assessment, where the MFSA also assesses the person directly through the Personal Questionnaire.

    FMA Application Form for authorisation as a CASP (Art 62 MiCAR), EN, as retrieved 26 Aug 2026 · undated (retrieved 2026-08-26) · verified 2026-08-27

  • Journey phase 4. Building the file

    The form's own cover cites 'Implementing Regulation (EU) 2025/305' for the standard forms — but 2025/305 is the Delegated Regulation (information content) and the forms instrument is Implementing Regulation (EU) 2025/306; 31 March 2025 is the OJ date of both, not either act's own date. Recorded as the state of the document retrieved on 26 August 2026. Two adjacent numbers, one delegated and one implementing: the distinction is genuinely easy to slip on — check it every time.

    FMA Application Form checked against the held OJ texts of CDR (EU) 2025/305 and CIR (EU) 2025/306 · undated (retrieved 2026-08-26) · verified 2026-08-26

  • Journey phase 8. Register, passport, supervision

    Authorisation extinguishes the old registration: on granting a CASP authorisation, the FMA declares the firm's § 32a FM-GwG virtual-currency registration extinguished ('als erloschen') under § 23 of the MiCA-Verordnung-Vollzugsgesetz (MiCA-VVG, BGBl. I Nr. 111/2024) read with Article 143(3) MiCA. The national implementing act is the hinge between the two regimes.

    FMA notice of authorisation of Bitpanda GmbH (Bescheid of 9 April 2025, published 10 April 2025) · 2025-04-10 · verified 2026-08-27

The worked enforcement record

The first published MiCAR penal decision — EUR 70,000, four breaches, final
  • By Bekanntmachung of 14 August 2026 the FMA recorded a fine of EUR 70,000 on Bitpanda GmbH, the proceedings concluded on an accelerated basis under § 22 Abs 2b FMABG. The penal decision is final ('rechtskräftig').
  • The four breaches: failing to transmit a crypto-asset white paper to the FMA at latest 20 working days before publication (Art 8(1) and (5) MiCA); disseminating a marketing communication before the white paper was published (Art 7(2)); omitting the required no-approval statement from a marketing communication (Art 7(1)(e)); and omitting a telephone number and email address from the same communication (Art 7(1)(d)). Three of the four are marketing-communication failures — the mechanical disclosure rules are, on this record, the easier ones to miss.
  • A same-day companion notice records this as the first final MiCAR penal decision the FMA has published — and warns against over-reading it: the fact that it is the first published case establishes no special position ('begründet für sich genommen keine Sonderstellung') for the firm or the breaches.
  • The same firm had been authorised by the FMA sixteen months earlier (Bescheid of 9 April 2025). Authorisation and sanction are not alternative states: a firm can clear the entry gate and still be fined under conduct rules that bite in ordinary operation. Authorisation is the entry gate; the conduct rules bite in ordinary operation, every day after it.

Every statement above is attributed to the FMA's own published notices of 14 August 2026 and 10 April 2025, and goes no further than their text. The record is used because it is closed, dated and final — one published case establishes what happened in that case, not a supervisory pattern.

FMA, Bekanntmachung (sanction) and 'Erste Veröffentlichung eines MiCAR-Straferkenntnisses', both 14 August 2026; FMA notice of authorisation, 10 April 2025 · verified 2026-08-27

So what — read Austria as the discipline check: a mechanised intake that a sloppy file fails on format alone, and a supervisor whose first published fine was for marketing mechanics, not exotic misconduct.

So whatBefore any cross-border step, write the three-line divergence check for the target state: its transitional window from the map, its authority’s process, and any known national reading of the instrument boundary. One page, dated — the panels above show why it is worth a day of anyone’s time.

As at — instrument lifecycle stages verified 2026-08-26 to 2026-08-28, per instrument (each citation above shows its own date); register figures are from the dated snapshots of 24 August 2026. Supervisory-practice statements are individually dated above and were last verified 2026-08-27. Where an instrument above is a guideline, comply-or-explain is stated on its stage line.