Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

MiCA compliance checklist explained

MiCA Compliance Checklist: 60 Essential Items by Title (2026)

A MiCA compliance checklist has to follow the Regulation’s own structure, because Regulation (EU) 2023/1114 imposes different obligations on four kinds of actor — offerors of ordinary crypto-assets, issuers of asset-referenced tokens, issuers of e-money tokens, and crypto-asset service providers — and a single firm can be more than one at once.

Title II governs white papers for crypto-assets other than stablecoins; Titles III and IV govern the two stablecoin types and have applied since 30 June 2024; Title V governs CASP authorisation and conduct and Title VI market abuse, both applying since 30 December 2024; the transitional period for pre-existing providers ended on 1 July 2026 at the latest. The checklist below is organised by Title, then by article, with the document or control that evidences each item, so it can be worked as a gap assessment: mark each row met, partly met or not met, attach the evidence, and the open rows are the remediation plan.

MiCA compliance checklist by Title
Title II white papers (Arts 4–15) · Title III ARTs (Arts 16–47) · Title IV EMTs (Arts 48–58) · Title V CASPs: authorisation (Arts 59–64), conduct (Arts 66–74), per-service rules (Arts 75–82) · Title VI market abuse (Arts 86–92) · plus the travel rule (Reg 2023/1113) and DORA.

Step 1: classify what you are

If you… You are a… Titles that apply
Offer a crypto-asset to the public or seek its admission to trading, and it is not an ART or EMT Offeror or person seeking admission II, VI
Issue a token referencing anything other than a single official currency Issuer of an asset-referenced token III (and II for the white paper mechanics it cross-refers to), VI
Issue a token referencing one official currency Issuer of an e-money token — must be a credit institution or EMI IV, VI
Provide custody, a trading platform, exchange, execution, placing, RTO, advice, portfolio management or transfer services Crypto-asset service provider V, VI, plus the travel rule and DORA
Are a credit institution, investment firm, EMI, UCITS manager or similar providing crypto-asset services Financial entity under Article 60 V by notification rather than authorisation, with the conduct rules

Our guide to asset-referenced tokens vs e-money tokens settles the stablecoin classification; the MiCA Regulation guide covers the Titles.

MiCA compliance checklist — Title II: offers and white papers

Article Requirement Evidence
4–5 No offer to the public or admission to trading unless the offeror is a legal person, has drawn up, notified and published a white paper, and complies with Article 14; exemptions for free offers, small offers (below €1 million over 12 months), offers to fewer than 150 persons per Member State, and qualified-investor-only offers Exemption analysis; white paper
6 White paper content: the nine parts (offeror, issuer, operator, project, offer, rights and obligations, technology, risks, climate impact) with the required statements and summary White paper against the ESMA template
7 Marketing communications identifiable as such, consistent with the white paper Marketing review log
8–9 Notify the white paper to the competent authority at least 20 working days before publication; publish before the offer starts Notification receipt; publication record
12 Modified white papers notified and published with reasons Version register
13 14-day right of withdrawal for retail holders buying directly from the offeror Withdrawal procedure
14 Act honestly, fairly and professionally; manage conflicts; safeguard funds raised; maintain systems Conduct policy; funds safeguarding arrangement

Our guide to the crypto-asset white paper covers Article 6 part by part.

Title III and IV: stablecoin issuers

Article Requirement Evidence
16 / 48 ART: authorisation under Article 21 or a credit institution, with an approved white paper; EMT: credit institution or EMI, white paper notified Authorisation or licence; white paper approval or notification
23 / 58(3) Means-of-exchange cap: stop issuing and submit a plan within 40 working days if daily use exceeds 1 million transactions and €200 million in a single currency area Quarterly transaction estimates
27–34 / 53 Conduct, complaints, conflicts, governance, marketing, disclosure of holders’ rights Policy set
35 / EMD Own funds: ART highest of €350,000, 2% of reserve, ¼ fixed overheads; EMT per the E-Money Directive Capital calculation
36–38 / 54 ART reserve of assets, segregated and invested in highly liquid instruments; EMT at least 30% deposited, remainder in secure low-risk assets in the referenced currency Reserve policy; custody agreements; reserve reports
39 / 49 Permanent redemption right — ART at market value or by delivery; EMT at par at any time Redemption policy
40 / 50 No interest Product terms review
43–45 / 56–58 Significant-token classification and the additional obligations that follow Reporting to the competent authority
46–47 / 55 Recovery plan and redemption plan Plans approved by the management body

MiCA compliance checklist — Title V: CASP authorisation and conduct

Article Requirement Evidence
59 / 60 Authorisation as a CASP, or notification for financial entities; legal person with a registered office and effective management in the EU, at least one resident director Authorisation decision; register entry
62–63 Application content; 25 working days completeness, 40 working days assessment Application file
66 Act honestly, fairly and professionally in clients’ best interests; fair, clear, not misleading information; warnings on risk; pricing and fee policies published Client communications policy
67 Prudential safeguards: higher of Annex IV capital (€50,000 / €125,000 / €150,000) and ¼ fixed overheads, as own funds and/or insurance Capital calculation; insurance policy
68 Governance: fit and proper management and shareholders; policies and procedures; business continuity; ICT systems; records Governance manual; fit-and-proper files
69 Information to competent authorities on changes to management Notification log
70 Safekeeping of clients’ crypto-assets and funds: segregation, no use of client assets for own account, client funds at a credit institution or central bank Safeguarding policy; reconciliations
71 Complaints handling: free, documented procedure; records; timely responses Complaints register
72 Conflicts of interest: identify, prevent, manage, disclose Conflicts register
73 Outsourcing: responsibility retained; written agreements; access for authorities Outsourcing register
74 Orderly wind-down plan Plan approved by the management body

Title V: per-service rules

Article Service Key requirements
75 Custody and administration Written agreement; register of positions; custody policy; segregation; quarterly statements; liability for loss of instruments
76 Operation of a trading platform Operating rules; admission policy with due diligence; no own-account dealing on the platform; resilience; market abuse detection; transparent pre- and post-trade data; settlement within 24 hours
77 Exchange for funds or other crypto-assets Non-discriminatory commercial policy; firm prices or price-determination method published; post-trade publication
78 Execution of orders Best possible result; execution policy; client information
79 Placing Information to the issuer before agreement; conflicts management
80 Reception and transmission of orders Prompt transmission; no inducements for routing
81 Advice and portfolio management Suitability assessment; competence of advisers; periodic suitability statements for portfolio management
82 Transfer services Written agreement with the client on the service terms

Our guide to CASP authorisation covers Articles 59–68; MiCA compliance cost covers what the Title V programme costs to run.

MiCA compliance checklist — Title VI and the obligations beside MiCA

Source Requirement Evidence
MiCA Articles 86–92 Market abuse: inside information disclosure with five-year archive; insider dealing, unlawful disclosure and manipulation prohibited; surveillance and suspicious-transaction reporting for anyone professionally arranging or executing transactions Market abuse policy; surveillance system; STOR log
Regulation (EU) 2023/1113 Travel rule: Article 14 originator and beneficiary data with every transfer, no threshold; self-hosted address rules; five-year retention Travel rule procedure; counterparty CASP register
Directive (EU) 2015/849 as amended AML/CFT obligations as an obliged entity: customer due diligence, monitoring, reporting, MLRO AML framework
Regulation (EU) 2022/2554 (DORA) ICT risk management, incident reporting, resilience testing, third-party risk, register of information — from 17 January 2025 ICT risk framework; incident register
GDPR Personal data in white papers, KYC, travel rule messaging and transfers to third-country CASPs Records of processing; transfer mechanisms

Our guides to MiCA market abuse and the crypto travel rule cover the first two rows in depth.

Working the MiCA compliance checklist

  1. Classify first. Which of the four actors you are, and for CASPs which of the ten services — the Annex IV class follows from it and so does the per-service table.
  2. Assign an owner and an evidence item per row. A row without a document is a gap whatever the owner believes.
  3. Score three ways. Met, partly met, not met — and date each score; the competent authority will ask what changed since authorisation.
  4. Prioritise by consequence. Article 67 capital, Article 70 safeguarding and the Title VI surveillance rows are where sanctions are heaviest; the per-service rows follow.
  5. Re-run at each trigger. A new service, a new listed asset, a new Member State, a significant-token classification or a technical standard update changes the rows that apply.

Frequently asked questions

What should a MiCA compliance checklist cover?
Every Title that applies to your role: II (white papers) for offerors, III or IV for stablecoin issuers, V (authorisation, conduct, per-service rules) for CASPs, VI (market abuse) for anyone dealing in listed crypto-assets — plus the travel rule, AML, DORA and GDPR obligations that sit beside MiCA.

Does the checklist differ by CASP service?
Yes. Articles 66–74 apply to every CASP; Articles 75–82 add service-specific rules for custody, trading platforms, exchange, execution, placing, RTO, advice and portfolio management, and transfer services. The Annex IV capital class also follows the services.

Which items carry the heaviest sanctions?
Market abuse (Article 111 floors of €15 million or 15% of turnover), safeguarding of client assets, prudential requirements and operating without authorisation. Prioritise those rows.

Is the transitional period still available?
No. Article 143’s grandfathering for providers operating under national law ended on 1 July 2026 at the latest, and several Member States ended it earlier; a CASP must now be authorised or notified to operate.

Does DORA apply to CASPs?
Yes, from 17 January 2025: ICT risk management, incident reporting, resilience testing and third-party risk, with the register of information — and it is part of what the competent authority assesses at authorisation under Article 62.

Where this leaves you

Use the MiCA compliance checklist as a gap assessment: classify your role, take the Titles that apply, assign an owner and an evidence item to every article-level row, score it, and let the open rows become the remediation plan — starting with capital, safeguarding and market abuse, because those are the rows the competent authority and Article 111 weigh most heavily.

References

More on MiCA

The MiCA Gap Assessment Workbook with every article-level row above, the Title V policy and procedure set, the per-service operating procedures, the white paper templates and the market abuse and travel rule procedures are in the MiCA Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.