MiCA Readiness Checklist — Self-Assessment for CASPs 2026
MiCA Readiness Checklist 2026 — Is Your CASP Ready to File?
The substantive MiCA readiness checklist for a crypto-asset service provider runs across seven operational phases: classification, capital and substance, AML/CFT programme, ICT and DORA framework, white paper compliance, customer protection, and governance and reporting. Tick the 15 components below to score your application readiness. The interactive checker returns a percentage score and a gap-list with links to the substantive practitioner guidance. The expanded reading below covers each phase in detail — what the regulator actually tests, the substantive timeline to readiness, the cost-and-effort drivers, and the common gaps that derail authorisation files at the NCA completeness check.
Tick the items below
0 of 15 components in place
Gaps to close before filing
Working out where to file, or what it costs?
MiCA readiness — what the regulator actually tests
MiCA readiness is not a checklist exercise — it is the substantive question of whether the NCA's completeness check will accept your application as filed and start the 5-month statutory clock under MiCA Article 63. Substantive completeness requires evidence across seven operational phases. An application missing material content in any phase faces NCA information-request rounds that delay authorisation by 3–12 months and add EUR 25,000–100,000 in legal-advisory time per round. The substantive practitioner standard: file complete, not file early. The 15-point checker above identifies the components; this guide explains what each component actually requires for substantive completeness.
The 7-phase MiCA readiness framework
The substantive MiCA readiness framework runs across seven phases mapped to MiCA Articles 7, 14–17, 32, 63, 67–82, and the Title II white paper rules. Each phase must be substantively complete before the NCA considers the application file ready for review:
- Phase 1 — Classification. Token category (utility / asset-referenced / e-money token), regulated activities (Class 1 / 2 / 3 service set), MiFID II boundary check confirming the asset is not a financial instrument under MiCA vs MiFID classification.
- Phase 2 — Capital and substance. Article 67 own funds calculation, Annex IV class floor, substantive Maltese/Irish/Lithuanian/etc. local substance, fit-and-proper management body documented under Article 68 + EBA Guidelines.
- Phase 3 — AML/CFT programme. Substantive AML manual aligned with FATF Recommendations, EU AMLR, MLRO appointment with documented EEA residency and substantive operational engagement, transaction monitoring infrastructure (Chainalysis / Elliptic / TRM Labs), sanctions screening (OFAC, EU, UN lists).
- Phase 4 — ICT and DORA framework. Substantive ICT-risk-management framework under DORA Article 5, business-continuity plan, incident-reporting infrastructure with 4-hour initial notice and 72-hour full-report capability, ICT third-party risk management under DORA Article 30.
- Phase 5 — White paper compliance. Where the operator issues crypto-assets, substantive Title II white paper drafted with the content elements required by Articles 6–15, jurisdictional notification logistics, marketing-consistency framework under Article 7.
- Phase 6 — Customer protection. Substantive customer-protection framework, complaints-handling procedure under MiCA Article 71, custody segregation under Article 75, best-execution policy under Article 80 (where applicable), conflicts-of-interest framework under Article 72.
- Phase 7 — Reporting and governance. Record-keeping infrastructure under Article 68 (5-year retention, substantive retrievability), prudential reporting infrastructure, conduct-of-business reporting, internal audit cycles, board-level oversight documentation.
Capital and substance — Article 67 + Annex IV
Capital readiness requires substantive own funds calculated under MiCA Article 67 and Annex IV. The class floors (EUR 50,000 / 125,000 / 150,000 for Class 1 / 2 / 3) are overridden by the one-quarter-of-fixed-overheads rule wherever that produces a higher number. NCAs expect substantive working buffer above the regulatory minimum — typical expectation is 150–200% of the binding figure. See the CASP cost calculator for the substantive own-funds and operational-cost estimate.
Substance readiness covers: substantive home-state legal entity (incorporated, capitalised, banking arrangements in place), substantive local director with documented residency and operational engagement, registered office that is more than a corporate-services-provider address, substantive senior management headcount including Chief Compliance Officer and Money Laundering Reporting Officer with EEA residency and direct board access. Substance shortcuts — letterbox entities, nominal local directors, outsourced MLRO without substantive engagement — face NCA pushback during fit-and-proper review.
AML/CFT programme readiness — MLRO, monitoring, sanctions, Travel Rule
AML readiness is the substantive component most CASP applicants underestimate. The substantive AML programme must address:
- Substantive AML manual aligned with FATF Recommendations 10–24, EU AMLR substantive requirements, member-state AML transposition. The substantive manual runs 80–150 pages covering risk assessment, CDD/EDD procedures, ongoing monitoring, sanctions screening, reporting workflows, training, independent testing, and record-keeping.
- MLRO appointment with substantive seniority, EEA residency, direct board access, documented operational engagement, fit-and-proper review evidence. See the MLRO substance practitioner guide.
- Transaction monitoring infrastructure — substantive transaction-graph analysis using Chainalysis, Elliptic, or TRM Labs. For crypto-native operations, substantive on-chain monitoring with cross-chain bridging analysis. Typical infrastructure investment EUR 150,000–400,000 in Year 1.
- Sanctions screening — substantive real-time screening against OFAC, EU, UN sanctions lists. Both customer-identity screening and wallet-address screening. See Sanctions compliance for CASPs guide.
- Travel Rule (TFR) infrastructure — substantive cross-CASP information exchange under Regulation (EU) 2023/1113, originator and beneficiary information on all crypto-asset transfers, enhanced due diligence on self-hosted wallet transfers above EUR 1,000. See EU Travel Rule TFR implementation by member state.
- Suspicious-transaction reporting — substantive STR workflow to home-state FIU, documented escalation procedures, training across all customer-facing staff.
ICT and DORA framework readiness
DORA (Digital Operational Resilience Act, Regulation EU 2022/2554) became operationally binding on 17 January 2025 and applies to CASPs alongside MiCA. Substantive DORA readiness requires:
- ICT-risk-management framework — written framework covering ICT asset inventory, incident classification, business-continuity plan, ICT third-party risk management, periodic testing. Substantive documentation runs 60–120 pages.
- Incident reporting infrastructure — substantive infrastructure supporting 4-hour initial notice for major ICT-related incidents and 72-hour full-report submission. Operators without substantive incident-classification framework face supervisory engagement on inadequate readiness.
- Threat-Led Penetration Testing (TLPT) — substantive infrastructure for TLPT cycles under DORA Article 26. Required every three years for significant CASPs, on-demand for other CASPs at NCA request. Per-cycle cost EUR 80,000–250,000.
- ICT third-party risk management — substantive contractual provisions under DORA Article 30 for ICT providers. Heightened obligations for Critical ICT Third-Party Providers (CTPP) designated by the ESAs Joint Committee. See DORA CTPP designation guide.
- Operational-risk tooling — substantive SIEM, EDR, threat-monitoring infrastructure, key-management infrastructure for custody operators.
White paper compliance — Title II readiness
Operators issuing crypto-assets face Title II white paper notification obligations under MiCA Articles 6–15. Substantive white paper readiness requires:
- Substantive white paper draft with the content elements required by Article 6 — project description, issuer information, token-economics, rights and obligations of token holders, risks disclosure, governance arrangements.
- Jurisdictional notification logistics — home-state NCA notification under Article 14, with notification period before public offering or admission to trading.
- Marketing-consistency framework — all marketing materials substantively consistent with white paper content under Article 7. Marketing that contradicts or materially extends beyond white paper disclosure triggers substantive supervisory engagement.
- Liability documentation — substantive understanding that white paper liability attaches to the offeror and management body individually. Substantive content errors or material omissions create individual liability for senior managers responsible for approval.
CASPs that do not issue crypto-assets — pure exchange, custody, trading-platform operators — face lighter Title II obligations focused on white-paper-compliance verification before admitting third-party-issued assets to trading.
Customer protection and complaints-handling readiness
Substantive customer-protection framework covers the substantive interaction between CASP and customer:
- Complaints-handling procedure under MiCA Article 71 — substantive procedure for receiving, investigating, and resolving customer complaints within regulatory timeframes, escalation procedures, NCA reporting infrastructure. See CASP complaints handling guide.
- Custody segregation under Article 75 — substantive segregation of customer crypto-assets from operator assets, separate addresses, accounting separation, customer-asset return procedures in operator-insolvency scenarios. See Article 75 custody segregation guide.
- Best-execution policy under Article 80 — for CASPs providing execution services, substantive best-execution framework with multi-factor analysis (price, costs, speed, likelihood of execution and settlement, size), monitoring infrastructure, annual disclosure.
- Conflicts-of-interest framework under Article 72 — substantive identification, management, and disclosure of structural and transaction-level conflicts. See Article 78 inducements + conflicts guide.
- Customer-facing disclosure framework — substantive risk disclosure, fee transparency, terms-and-conditions clarity, marketing-conduct compliance.
Operational resilience and incident reporting — 4h/72h
Operational resilience readiness combines DORA ICT obligations with MiCA conduct rules. The substantive incident reporting timeline is sharp:
- 4-hour initial notice for major ICT-related incidents to home-state NCA. Substantive initial notice covers incident classification, affected systems, customer-impact estimate, response actions in progress.
- 72-hour full incident report with substantive root-cause analysis, customer-impact quantification, remediation actions completed, lessons-learned framework.
- Final incident report within one month of incident resolution with substantive post-incident review and framework-improvement actions.
- Operational-risk-event reporting — substantive ongoing reporting framework for operational risk events, with quarterly aggregate reporting to NCA.
Operators without substantive incident-classification framework face supervisory engagement on inadequate readiness. The substantive 4h/72h timeline cannot be retrofitted reactively — it requires substantive pre-existing infrastructure and trained response teams.
Governance, internal controls, and reporting readiness
Governance readiness covers the substantive board and management-body framework:
- Management body fit-and-proper under Article 68 + EBA Guidelines — substantive fit-and-proper review of every management body member including documented criminal-record checks across all jurisdictions of nationality and residence, reputation review, financial-position verification, professional-qualifications evidence.
- Qualifying-holdings notification under Article 83 — substantive notification procedures for any acquisition or disposal of qualifying holdings (10%+) including substantive due-diligence documentation.
- Internal audit function — substantive internal audit cycles, audit-committee oversight, documented internal-audit charter, independent reporting line to board.
- Risk-management function — substantive risk-appetite framework, key risk indicators, risk-committee oversight, independent reporting line to board.
- Compliance function — substantive compliance officer with substantive board access, documented compliance programme, regular board-level compliance reporting.
- Record-keeping infrastructure under Article 68 — 5-year retention minimum, substantive retrievability standards, cross-border accessibility for NCA cooperation.
Common readiness gaps that derail authorisation files
Substantive supervisory engagement patterns through 2025–2026 identify recurring readiness gaps:
- Evidence gaps — substantive policies in place but inadequate evidence of operational implementation. NCAs test substantive evidence of policy operation, not just policy existence.
- Token classification errors — incorrect classification of crypto-assets as utility tokens when substantive analysis indicates asset-referenced or e-money token status. Triggers substantive Title III or Title IV reauthorisation.
- Change-related breakage — operational changes not reflected in policy documentation, creating substantive divergence between actual operation and authorised framework.
- Inadequate marketing consistency — marketing materials inconsistent with white paper content or operating-framework documentation. Substantive supervisory engagement on Article 7 compliance.
- Record-keeping infrastructure gaps — substantive records nominally retained but inadequate retrievability under NCA supervisory testing. See Article 68 record-keeping guide.
- Missed escalations — substantive operational events not escalated through substantive framework, creating substantive operational-risk-management documentation gaps.
- Undisclosed conflicts — substantive structural conflicts not documented in conflict-management framework, particularly for operators running combined trading-platform + market-making + custody operations.
Timeline from start to readiness
Substantive MiCA readiness build for a venture-stage operator typically requires 9–15 months. The substantive breakdown:
- Months 1–3: jurisdiction selection, legal entity incorporation, capital raising or deployment, initial governance documentation, MLRO and CCO recruitment.
- Months 3–6: substantive AML/CFT programme drafting, ICT and DORA framework build, customer-protection framework, business plan substantively complete.
- Months 6–9: white paper drafting (where applicable), substantive policy stack completion, pre-application NCA engagement, fit-and-proper documentation completion.
- Months 9–12: substantive file submission, NCA information-request rounds, supervisory engagement on substantive completeness, technical specifications refinement.
- Months 12–15+: substantive NCA review under 5-month statutory clock from complete-file determination, technical certification, authorisation grant.
For operators with substantive existing financial-services authorisation infrastructure (MiFID-licensed investment firms, EMI licensees, banking-services providers) the substantive readiness timeline compresses to 6–9 months. For venture-stage operators starting from minimal regulatory infrastructure, 15–24 months is realistic. See How long MiCA CASP authorisation takes 2026 for substantive timeline expectations.
FAQ — MiCA readiness
How long does it take to become MiCA-ready?
Substantive MiCA readiness build typically takes 9–15 months for venture-stage operators starting from minimal regulatory infrastructure. Operators with existing financial-services authorisation (MiFID, EMI, banking) face compressed 6–9 month timelines. The substantive file completion is followed by 5-month statutory NCA review under Article 63 from complete-file determination.
What percentage readiness score should I aim for before filing?
Substantive practitioner standard: 90%+ on the readiness checklist with substantive evidence behind each component. NCAs accept substantively complete files; substantively incomplete files trigger 2–4 rounds of information requests adding 3–12 months to authorisation timeline plus EUR 25,000–100,000 in legal-advisory time per round.
Can I file without an MLRO appointed?
No. Substantive MLRO appointment is mandatory under MiCA + EU AMLR. The MLRO must have substantive EEA residency, fit-and-proper documentation, direct board access, and substantive operational engagement. Outsourced MLRO arrangements face heightened NCA scrutiny — nominal appointments do not satisfy substantive expectation.
Does DORA readiness need to be complete before filing the CASP application?
Yes substantively. DORA applies to CASPs from 17 January 2025 alongside MiCA. The substantive ICT framework, incident-reporting infrastructure, and ICT third-party risk management must be substantively in place at the application phase, not deferred to post-authorisation build-out.
What is the 4-hour / 72-hour incident reporting rule?
Under DORA, major ICT-related incidents require 4-hour initial notice to the home-state NCA and 72-hour full incident report with substantive root-cause analysis, customer-impact quantification, and remediation actions. A final incident report follows within one month of resolution. Operators without substantive incident-classification framework face supervisory engagement on inadequate readiness.
Do I need a white paper if I am only running an exchange?
Substantive white paper notification under MiCA Title II is required only where the operator issues crypto-assets. Pure exchange, custody, or trading-platform operators face lighter Title II obligations focused on white-paper-compliance verification before admitting third-party-issued assets to trading. See MiCA token sale white paper rules.
What penalties apply for inadequate MiCA readiness?
Under MiCA Article 109, NCAs can impose administrative fines up to the higher of EUR 5 million, 3% of annual turnover, or twice the gain made or loss avoided. Individual fines up to EUR 700,000 for senior managers. Individual bans on holding management positions in MiCA-authorised entities. Public statements identifying the breaching entity.
Related practitioner resources
- CASP cost calculator — substantive cost estimate alongside readiness assessment.
- Jurisdiction finder — substantive jurisdiction selection framework.
- DORA ICT resilience for CASPs — substantive DORA compliance framework.
- MLRO substance requirements — substantive MLRO appointment framework.
- CASP management body fit-and-proper — substantive governance readiness.
- Best EU MiCA passport hub comparison 2026 — jurisdiction selection.
MiCA readiness is the substantive question that determines whether an authorisation application succeeds at first NCA completeness check or triggers 3–12 months of information-request rounds. The 15-point checker above identifies the components. The substantive readiness build requires 9–15 months of focused operational work across the seven phases. Substantive readiness pays substantive dividends in authorisation timeline, supervisory relationship quality, and ongoing operational economics.