[codicts-css-switcher id=”346″]

Global Law Experts Logo
mica exchange requirements

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Mica Exchange Requirements: What Crypto Trading Platforms Must Do to Get Authorised in the EU

By Jonathon Richards
– posted 17 hours ago

The EU’s Markets in Crypto-Assets Regulation Regulation (EU) 2023/1114 has fundamentally reshaped the MiCA exchange requirements that every crypto trading platform must satisfy before it can lawfully serve customers across the European Economic Area. Whether you are a compliance officer mapping obligations, a founder planning market entry, or a legal team advising on licensing strategy, this guide delivers a concrete authorisation playbook: the governance, capital, custody, disclosure and filing steps you must complete, the typical timeline and cost ranges involved, and the downloadable checklists and templates you need to move from gap analysis to authorisation certificate.

The urgency is real. The European Commission has already launched its review and consultation on MiCA’s functioning following initial implementation, and National Competent Authorities (NCAs) across the EU are now actively processing applications and initiating supervisory actions. Exchanges that have not begun the authorisation process face the risk of market exclusion, operational restrictions, or enforcement fines.

Quick summary: MiCA scope and who it applies to

MiCA establishes a harmonised EU-level framework for crypto-asset issuers and crypto-asset service providers (CASPs). According to the EUR-Lex summary of the Regulation, in-scope entities include:

  • Issuers of crypto-assets entities offering crypto-assets to the public or seeking admission to trading, including issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs).
  • Crypto-asset service providers (CASPs) exchanges and trading platforms, custodians of crypto-assets, brokers and dealers, portfolio managers, transfer service providers, and advisers.
  • Stablecoin issuers subject to enhanced prudential and reserve requirements under Titles III and IV of MiCA.

Principal exclusions from MiCA’s scope cover crypto-assets that already qualify as financial instruments under MiFID II, certain intragroup transactions, services provided by public authorities and central banks, and fully decentralised arrangements with no identifiable service provider. Firms operating at the boundary between MiCA and MiFID should commission a formal classification opinion before filing a step discussed in detail below.

Corporate and governance changes required under MiCA

MiCA imposes rigorous organisational requirements on exchanges seeking authorisation as CASPs. The ESMA Interactive Single Rulebook for MiCA consolidates supervisory expectations that NCAs will assess during the application review. Key MiCA governance obligations include:

  • EU-incorporated entity the applicant must be a legal person established in an EU Member State with its registered office in the same Member State where it applies for authorisation.
  • Fit-and-proper management members of the management body must demonstrate good repute, adequate knowledge, skills and experience. NCAs assess individual directors against criteria including criminal record, financial probity, and sector expertise.
  • Organisational structure clear internal reporting lines, segregation of duties, a dedicated compliance function, and an internal audit capability proportionate to the scale of the CASP’s activities.
  • AML/CFT governance appointment of a Money Laundering Reporting Officer (MLRO), board-level accountability for AML risk, transaction monitoring rules, and suspicious activity reporting protocols.
  • Outsourcing and third-party risk documented policies for outsourcing critical or important functions, with due diligence, contractual controls and exit plans that the NCA can review.
  • Incident response and business continuity policies covering cybersecurity incidents, system outages and operational disruptions, with defined escalation procedures and notification obligations to the NCA.

Exchanges should prepare a governance checklist that includes board minutes evidencing oversight of risk, IT security and AML, a complete set of internal policies (compliance manual, conflicts of interest policy, complaints handling procedure), and a staffing plan that maps roles to MiCA’s organisational requirements.

Capital and prudential tests MiCA capital requirements and modelling guidance

MiCA sets minimum initial capital thresholds and ongoing own-funds requirements for CASPs. The exact minimum depends on the services provided. The European Commission’s published list of Level-2 implementing and delegated acts specifies the detailed prudential ratios, reporting templates and capital calculation methodologies that firms must follow.

Under MiCA, a CASP operating a trading platform for crypto-assets must hold a higher minimum capital buffer than a firm providing only advisory or order-transmission services. In practice, exchanges should expect the following prudential obligations:

  • Minimum initial capital a fixed minimum (varying by CASP service category) that must be evidenced at the time of application and maintained on an ongoing basis.
  • Ongoing own-funds requirement the higher of the fixed minimum, a quarter of the previous year’s fixed overheads, or a percentage-based calculation linked to the volume and nature of activity.
  • Stress testing and liquidity modelling applicants must present financial projections and scenario analyses covering adverse market conditions. Industry observers recommend modelling at least three stress scenarios: a sudden market halt, a stablecoin depeg event, and a custody incident involving partial or total loss of client assets.
  • Auditor attestation financial projections should be accompanied by an auditor’s letter confirming the assumptions, methodology and adequacy of the capital model.

A capital modelling spreadsheet covering scenario inputs, volume shocks, liquidity buffers and reverse stress tests is an essential deliverable for any exchange preparing its MiCA application. Firms should begin building this model at least six months before their planned filing date.

Whitepaper and transparency/disclosure requirements

MiCA whitepaper requirements apply directly to issuers of crypto-assets, but exchanges that list tokens or operate primary-market services must verify that compliant whitepapers are in place for every asset admitted to trading. The whitepaper must include:

  • Token description technical characteristics, underlying protocol, consensus mechanism and rights attached.
  • Governance and economics tokenomics, supply schedule, fee structures and governance rights.
  • Risk disclosure material risks including market, technology, regulatory and liquidity risk.
  • AML controls and roadmap measures to prevent misuse and the project’s development timeline.
  • Legal opinion and classification test a formal opinion confirming that the crypto-asset does not constitute a financial instrument under MiFID, attached as an annex using the ESAs classification template.

Exchanges should establish an internal listing committee that reviews each whitepaper for MiCA transparency and disclosure compliance before a token is admitted to trading.

Custody and safeguarding obligations

Where an exchange holds client crypto-assets, MiCA’s custody rules require strict safeguarding measures. These include segregation of client assets from the CASP’s own holdings, documented custody policies covering both hot and cold wallet management, and operational security controls such as penetration testing, SOC 2 or ISO 27001 evidence, and multi-signature authorisation protocols. Exchanges must choose between maintaining an insurance policy covering custody risk or holding an additional capital buffer. There is also a notable overlap with the Digital Operational Resilience Act (DORA), and firms should map both sets of requirements concurrently a topic explored further in MiCA vs DORA operational overlap guidance.

MiCA exchange requirements: step-by-step authorisation checklist and timeline

The MiCA authorisation process follows a structured sequence. Timelines vary by NCA workload and the completeness of the applicant’s filing, but the typical end-to-end journey spans 12 to 24 months from initial scoping to operational go-live.

Pre-filing phase (3–6 months)

  1. Conduct MiCA classification and scope mapping. Produce a legal opinion confirming whether each crypto-asset and service falls within MiCA’s scope, using the ESAs classification template. Deliverable: classification report and legal opinion.
  2. Build governance, compliance and AML/KYC framework. Draft and adopt all required internal policies, hire or appoint an MLRO, implement transaction monitoring systems, and establish board oversight protocols. Deliverable: complete policy set and staffing plan.
  3. Complete capital modelling and liquidity stress tests. Prepare multi-scenario financial projections, obtain auditor attestation, and evidence initial capital. Deliverable: capital model, auditor letter and proof of funds.
  4. Draft the whitepaper and disclosure pack. For any tokens the exchange issues or for which it acts as the first admission point, prepare a MiCA-compliant whitepaper with all required annexes. Deliverable: whitepaper and legal opinion annex.
  5. Implement custody and technical safeguards. Finalise custodian agreements (whether in-house or third-party), implement asset segregation, cold storage protocols, and obtain penetration test and SOC/ISO reports. Deliverable: custody policy, custodian contracts and test reports.

Filing phase (6–12 months)

  1. Prepare the filing bundle. Collate all deliverables, prepare local-language translations where required by the NCA, and map every document to the NCA’s specific filing checklist. Deliverable: complete filing packet.
  2. Submit the application to the chosen NCA. File with the National Competent Authority of the Member State where the entity is incorporated. Request a pre-application meeting many NCAs offer these and they materially reduce review cycles. Deliverable: filing confirmation and pre-application meeting notes.
  3. Respond to NCA queries. NCAs typically issue one or more rounds of questions. Prepare response logs, provide supplementary evidence, and submit any remedial plans where deficiencies are identified. Deliverable: response logs and remediation plans.

Post-authorisation phase (3–6 months)

  1. Receive authorisation and execute go-live plan. Upon receiving the authorisation certificate, map to an operational go-live plan covering ongoing compliance monitoring, periodic reporting to the NCA, consumer disclosure updates, and passporting notifications via the ESMA register. Deliverable: authorisation certificate and go-live checklist.

Resourcing note: Industry experience suggests that a mid-size exchange should budget 0.5 to 1.0 FTE-equivalent of dedicated internal staff for 6 to 9 months, supplemented by external legal counsel and technical advisers. Cost ranges depend on the complexity of the business model and are discussed in the comparison table below.

Comparison table: MiCA authorisation routes, timelines and indicative costs

Business model / route Authorisation type Custody burden Typical timeline Indicative pre-authorisation cost (EUR)
Full exchange with custody and trading Full MiCA CASP authorisation (passporting across EEA) Full segregation, insurance/capital buffer, pen testing 6–12 months 150,000–600,000
Trading-only platform (no custody) MiCA CASP authorisation with lower capital buffer Reduced relies on authorised third-party custodian 4–9 months 80,000–300,000
Exchange using EEA custodian partner MiCA CASP authorisation with custodian dependency Contractual controls required; operational due diligence on partner 3–8 months 60,000–200,000

These figures are indicative and vary significantly by NCA jurisdiction, the applicant’s existing compliance maturity, and whether a full technology build or remediation is required. Exchanges planning to passport across the EEA should factor in additional time for ESMA register notifications.

Practical implementation examples and downloadable templates

To support firms in preparing their MiCA applications, the following downloadable assets are available:

  • MiCA authorisation checklist (Excel) maps every required document to the relevant MiCA Article, the responsible NCA, the internal filing owner and current status. Download the MiCA authorisation checklist to begin your gap analysis.
  • Sample whitepaper sections (Word template) redactable template covering tokenomics, governance structure, risk disclosure and AML controls, aligned with MiCA whitepaper requirements. Access the MiCA whitepaper template.
  • Capital modelling spreadsheet scenario-based stress testing tool with pre-built inputs for volume shocks, stablecoin depeg events and custody loss incidents. Request the MiCA capital modelling template.
  • Custody readiness checklist and pen test template operational controls mapping and penetration test scope document aligned with MiCA safeguarding standards and DORA requirements.

Implementation case studies (anonymised)

Exchange A restructured its governance by incorporating a new entity in an EU Member State, appointing an experienced MLRO from the traditional financial services sector, and commissioning an early classification opinion from external counsel. The combination of proactive NCA engagement (including a pre-application meeting) and a complete filing bundle enabled authorisation within nine months. Key success factor: early classification and governance build, completed before the capital modelling phase.

Exchange B adopted a faster route to market by partnering with an authorised EU custodian, reducing its custody compliance burden. However, the NCA identified material deficiencies in the exchange’s disclosure documentation specifically incomplete risk disclosures and a missing legal opinion annex. Remediation added four months to the timeline. Lesson learned: disclosure completeness is as critical as operational readiness, and whitepaper review should be prioritised alongside custody arrangements.

Common pitfalls and remediation strategies

  • Weak asset classification: Failing to produce a robust legal opinion on whether listed tokens fall under MiCA or MiFID is the single most common cause of NCA pushback. Remediation: use the ESAs classification template and engage specialist counsel before filing.
  • Underestimated capital and liquidity modelling: Many applicants present optimistic base-case projections without adequate stress scenarios. Remediation: run reverse stress tests, include at least three adverse scenarios, and attach an independent auditor attestation to every capital model submission.
  • Insufficient AML/KYC processes for cross-border customers: Exchanges serving multiple EU jurisdictions must align their KYC procedures to the highest-risk jurisdiction served. Remediation: document risk assessment reports (RARs) by jurisdiction and implement enhanced due diligence for high-risk customer segments.
  • Poor custody segregation and contract terms: Generic custodian agreements drafted before MiCA often lack the specific safeguarding provisions NCAs now require. Remediation: rebuild custody agreements to mirror MiCA’s segregation, insurance and reporting standards explicitly.
  • Late engagement with the NCA: Firms that file without a pre-application meeting typically face longer review cycles and more rounds of queries. Remediation: request a pre-application meeting early and use it to clarify the NCA’s specific expectations and preferred filing format.

How Global Law Experts supports MiCA authorisation

Global Law Experts connects exchanges and crypto-asset service providers with specialist legal and advisory professionals across every EU Member State. Through its multi-jurisdiction network, GLE facilitates end-to-end MiCA authorisation support from initial scope mapping and classification opinions through governance build, capital modelling, whitepaper drafting, custody policy design, NCA filing and post-authorisation compliance monitoring. Firms can request an authorisation readiness review, access the downloadable MiCA exchange requirements checklists and templates referenced throughout this guide, and obtain tailored introductions to qualified advisers experienced in the specific NCA process relevant to their chosen jurisdiction.

Sources

FAQs

What is the MiCA regulation for crypto?
MiCA — the Markets in Crypto-Assets Regulation — is Regulation (EU) 2023/1114, published in the Official Journal on 9 June 2023. It is the EU’s comprehensive regulatory framework for crypto-asset issuers and crypto-asset service providers, establishing harmonised rules on authorisation, governance, prudential requirements, consumer protection and market integrity across all EU Member States.
Exchanges operating as CASPs must obtain authorisation from a National Competent Authority, satisfy ongoing governance and organisational requirements, maintain minimum capital and own-funds buffers, implement custody safeguarding measures for client assets, produce or verify MiCA-compliant whitepapers for listed tokens, and comply with AML/KYC obligations. The ESMA Interactive Single Rulebook consolidates the detailed supervisory expectations for each obligation.
MiCA does not apply to crypto-assets that qualify as financial instruments, deposits or structured deposits under existing EU financial services legislation (such as MiFID II). It also excludes certain intragroup transactions, services provided by the European Central Bank, national central banks and other public authorities, and fully decentralised protocols with no identifiable issuer or service provider. A detailed breakdown of exclusions is available in the EUR-Lex summary of MiCA.
Each National Competent Authority maintains a public register of authorised CASPs in its jurisdiction, and ESMA is building a consolidated EU-wide register. To verify whether a specific exchange holds a MiCA licence, check the register of the NCA in the Member State where the exchange is incorporated (for example, BaFin in Germany, AMF in France, or CSSF in Luxembourg). ESMA’s consolidated register will provide a single reference point as more authorisations are granted.
The process follows a structured sequence: first, conduct a classification and scope mapping exercise; second, build out governance, compliance and AML frameworks; third, complete capital modelling with stress tests and auditor attestation; fourth, prepare the whitepaper and disclosure pack; fifth, implement custody safeguards; sixth, compile and submit the full filing bundle to the relevant NCA; and finally, respond to NCA queries until authorisation is granted. The full process, including deliverables, is detailed in the step-by-step section above. The European Commission’s Level-2 measures document specifies the templates and procedural requirements that must be followed.
MiCA sets minimum initial capital thresholds that vary by CASP service category, plus an ongoing own-funds requirement calculated as the higher of the fixed minimum, a quarter of prior-year fixed overheads, or a percentage-based formula tied to activity volumes. For custody, exchanges must segregate client crypto-assets from proprietary holdings, implement robust operational security controls, and either maintain an insurance policy covering custody risk or hold an additional capital buffer. Detailed capital calculation methodologies are set out in the Commission’s implementing and delegated acts.

Our Expert

Jonathon Richards

Global Law Experts

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Mica Exchange Requirements: What Crypto Trading Platforms Must Do to Get Authorised in the EU

Send welcome message

Custom Message