MiCA Readiness Checklist — Self-Assessment for CASPs 2026

MiCA Readiness Checklist 2026 — Is Your CASP Ready to File?

The substantive MiCA readiness checklist for a crypto-asset service provider runs across seven operational phases: classification, capital and substance, AML/CFT programme, ICT and DORA framework, white paper compliance, customer protection, and governance and reporting. Tick the 15 components below to score your application readiness. The interactive checker returns a percentage score and a gap-list with links to the substantive practitioner guidance. The expanded reading below covers each phase in detail — what the regulator actually tests, the substantive timeline to readiness, the cost-and-effort drivers, and the common gaps that derail authorisation files at the NCA completeness check.

0%

Tick the items below

0 of 15 components in place

Foundations
Capital & substance
Compliance framework
Operational

Working out where to file, or what it costs?

MiCA readiness — what the regulator actually tests

MiCA readiness is not a checklist exercise — it is the substantive question of whether the NCA's completeness check will accept your application as filed and start the 5-month statutory clock under MiCA Article 63. Substantive completeness requires evidence across seven operational phases. An application missing material content in any phase faces NCA information-request rounds that delay authorisation by 3–12 months and add EUR 25,000–100,000 in legal-advisory time per round. The substantive practitioner standard: file complete, not file early. The 15-point checker above identifies the components; this guide explains what each component actually requires for substantive completeness.

The 7-phase MiCA readiness framework

The substantive MiCA readiness framework runs across seven phases mapped to MiCA Articles 7, 14–17, 32, 63, 67–82, and the Title II white paper rules. Each phase must be substantively complete before the NCA considers the application file ready for review:

  1. Phase 1 — Classification. Token category (utility / asset-referenced / e-money token), regulated activities (Class 1 / 2 / 3 service set), MiFID II boundary check confirming the asset is not a financial instrument under MiCA vs MiFID classification.
  2. Phase 2 — Capital and substance. Article 67 own funds calculation, Annex IV class floor, substantive Maltese/Irish/Lithuanian/etc. local substance, fit-and-proper management body documented under Article 68 + EBA Guidelines.
  3. Phase 3 — AML/CFT programme. Substantive AML manual aligned with FATF Recommendations, EU AMLR, MLRO appointment with documented EEA residency and substantive operational engagement, transaction monitoring infrastructure (Chainalysis / Elliptic / TRM Labs), sanctions screening (OFAC, EU, UN lists).
  4. Phase 4 — ICT and DORA framework. Substantive ICT-risk-management framework under DORA Article 5, business-continuity plan, incident-reporting infrastructure with 4-hour initial notice and 72-hour full-report capability, ICT third-party risk management under DORA Article 30.
  5. Phase 5 — White paper compliance. Where the operator issues crypto-assets, substantive Title II white paper drafted with the content elements required by Articles 6–15, jurisdictional notification logistics, marketing-consistency framework under Article 7.
  6. Phase 6 — Customer protection. Substantive customer-protection framework, complaints-handling procedure under MiCA Article 71, custody segregation under Article 75, best-execution policy under Article 80 (where applicable), conflicts-of-interest framework under Article 72.
  7. Phase 7 — Reporting and governance. Record-keeping infrastructure under Article 68 (5-year retention, substantive retrievability), prudential reporting infrastructure, conduct-of-business reporting, internal audit cycles, board-level oversight documentation.

Capital and substance — Article 67 + Annex IV

Capital readiness requires substantive own funds calculated under MiCA Article 67 and Annex IV. The class floors (EUR 50,000 / 125,000 / 150,000 for Class 1 / 2 / 3) are overridden by the one-quarter-of-fixed-overheads rule wherever that produces a higher number. NCAs expect substantive working buffer above the regulatory minimum — typical expectation is 150–200% of the binding figure. See the CASP cost calculator for the substantive own-funds and operational-cost estimate.

Substance readiness covers: substantive home-state legal entity (incorporated, capitalised, banking arrangements in place), substantive local director with documented residency and operational engagement, registered office that is more than a corporate-services-provider address, substantive senior management headcount including Chief Compliance Officer and Money Laundering Reporting Officer with EEA residency and direct board access. Substance shortcuts — letterbox entities, nominal local directors, outsourced MLRO without substantive engagement — face NCA pushback during fit-and-proper review.

AML/CFT programme readiness — MLRO, monitoring, sanctions, Travel Rule

AML readiness is the substantive component most CASP applicants underestimate. The substantive AML programme must address:

ICT and DORA framework readiness

DORA (Digital Operational Resilience Act, Regulation EU 2022/2554) became operationally binding on 17 January 2025 and applies to CASPs alongside MiCA. Substantive DORA readiness requires:

White paper compliance — Title II readiness

Operators issuing crypto-assets face Title II white paper notification obligations under MiCA Articles 6–15. Substantive white paper readiness requires:

CASPs that do not issue crypto-assets — pure exchange, custody, trading-platform operators — face lighter Title II obligations focused on white-paper-compliance verification before admitting third-party-issued assets to trading.

Customer protection and complaints-handling readiness

Substantive customer-protection framework covers the substantive interaction between CASP and customer:

Operational resilience and incident reporting — 4h/72h

Operational resilience readiness combines DORA ICT obligations with MiCA conduct rules. The substantive incident reporting timeline is sharp:

Operators without substantive incident-classification framework face supervisory engagement on inadequate readiness. The substantive 4h/72h timeline cannot be retrofitted reactively — it requires substantive pre-existing infrastructure and trained response teams.

Governance, internal controls, and reporting readiness

Governance readiness covers the substantive board and management-body framework:

Common readiness gaps that derail authorisation files

Substantive supervisory engagement patterns through 2025–2026 identify recurring readiness gaps:

  1. Evidence gaps — substantive policies in place but inadequate evidence of operational implementation. NCAs test substantive evidence of policy operation, not just policy existence.
  2. Token classification errors — incorrect classification of crypto-assets as utility tokens when substantive analysis indicates asset-referenced or e-money token status. Triggers substantive Title III or Title IV reauthorisation.
  3. Change-related breakage — operational changes not reflected in policy documentation, creating substantive divergence between actual operation and authorised framework.
  4. Inadequate marketing consistency — marketing materials inconsistent with white paper content or operating-framework documentation. Substantive supervisory engagement on Article 7 compliance.
  5. Record-keeping infrastructure gaps — substantive records nominally retained but inadequate retrievability under NCA supervisory testing. See Article 68 record-keeping guide.
  6. Missed escalations — substantive operational events not escalated through substantive framework, creating substantive operational-risk-management documentation gaps.
  7. Undisclosed conflicts — substantive structural conflicts not documented in conflict-management framework, particularly for operators running combined trading-platform + market-making + custody operations.

Timeline from start to readiness

Substantive MiCA readiness build for a venture-stage operator typically requires 9–15 months. The substantive breakdown:

For operators with substantive existing financial-services authorisation infrastructure (MiFID-licensed investment firms, EMI licensees, banking-services providers) the substantive readiness timeline compresses to 6–9 months. For venture-stage operators starting from minimal regulatory infrastructure, 15–24 months is realistic. See How long MiCA CASP authorisation takes 2026 for substantive timeline expectations.

FAQ — MiCA readiness

How long does it take to become MiCA-ready?

Substantive MiCA readiness build typically takes 9–15 months for venture-stage operators starting from minimal regulatory infrastructure. Operators with existing financial-services authorisation (MiFID, EMI, banking) face compressed 6–9 month timelines. The substantive file completion is followed by 5-month statutory NCA review under Article 63 from complete-file determination.

What percentage readiness score should I aim for before filing?

Substantive practitioner standard: 90%+ on the readiness checklist with substantive evidence behind each component. NCAs accept substantively complete files; substantively incomplete files trigger 2–4 rounds of information requests adding 3–12 months to authorisation timeline plus EUR 25,000–100,000 in legal-advisory time per round.

Can I file without an MLRO appointed?

No. Substantive MLRO appointment is mandatory under MiCA + EU AMLR. The MLRO must have substantive EEA residency, fit-and-proper documentation, direct board access, and substantive operational engagement. Outsourced MLRO arrangements face heightened NCA scrutiny — nominal appointments do not satisfy substantive expectation.

Does DORA readiness need to be complete before filing the CASP application?

Yes substantively. DORA applies to CASPs from 17 January 2025 alongside MiCA. The substantive ICT framework, incident-reporting infrastructure, and ICT third-party risk management must be substantively in place at the application phase, not deferred to post-authorisation build-out.

What is the 4-hour / 72-hour incident reporting rule?

Under DORA, major ICT-related incidents require 4-hour initial notice to the home-state NCA and 72-hour full incident report with substantive root-cause analysis, customer-impact quantification, and remediation actions. A final incident report follows within one month of resolution. Operators without substantive incident-classification framework face supervisory engagement on inadequate readiness.

Do I need a white paper if I am only running an exchange?

Substantive white paper notification under MiCA Title II is required only where the operator issues crypto-assets. Pure exchange, custody, or trading-platform operators face lighter Title II obligations focused on white-paper-compliance verification before admitting third-party-issued assets to trading. See MiCA token sale white paper rules.

What penalties apply for inadequate MiCA readiness?

Under MiCA Article 109, NCAs can impose administrative fines up to the higher of EUR 5 million, 3% of annual turnover, or twice the gain made or loss avoided. Individual fines up to EUR 700,000 for senior managers. Individual bans on holding management positions in MiCA-authorised entities. Public statements identifying the breaching entity.

MiCA readiness is the substantive question that determines whether an authorisation application succeeds at first NCA completeness check or triggers 3–12 months of information-request rounds. The 15-point checker above identifies the components. The substantive readiness build requires 9–15 months of focused operational work across the seven phases. Substantive readiness pays substantive dividends in authorisation timeline, supervisory relationship quality, and ongoing operational economics.