Skip to content
← MiCA training

MiCA · In operation

MiCA in operation

Every rule on this page is in force or applying. For each one you get three things: the question it answers, what it makes the firm do at the desk, and what it means in the boardroom — with the citation and its lifecycle stage underneath, where a citation belongs. Read down one column or across both; nothing is hidden behind a tab.

Which rules bind you at all?

Three boundary questions come before any obligation: whether a token is inside MiCA, whether a non-EU desk can serve EU clients without a licence, and whose rules a given instrument actually addresses. Get these wrong and everything downstream is wrong with them.

Is your token inside MiCA — and which title catches it?

The definitions sort every token in a fixed order, and each answer forecloses the ones after it. Learn the order once and most classification arguments resolve themselves.

At the desk

  • Ask the gate question first: is it a financial instrument? Guideline 2's test is cumulative — not a payment instrument, forms a class, negotiable — all three or it is not one.
  • Then the purport test: does the token claim to hold a stable value by referencing something? No claim means Title II, and possibly a utility token.
  • Stable against exactly one official currency is an EMT. Anything else that stabilises — a basket, gold, another asset — is an ART: the definition is expressly the residual.
  • Write the analysis down. Malta applies the qualification guidelines by name; Austria's form asks which crypto-asset types each service touches. The sort is a filed document, not a hallway opinion.

In the boardroom

  • The market is not symmetrical: at the 24 August 2026 snapshot there were 50 e-money-token white papers and zero authorised ART issuers. Plan against the regime that exists, not the one on the org chart of the Regulation.
  • A token that turns out to be a financial instrument is a different licence, timetable and cost base. Finding out late is the expensive version.

So whatRun the sort on paper for one token you know well — gate, purport, one-currency, residual — and file the page. The discipline is the deliverable; no reader's real token is classified here.

the definitions: Arts 2(4), 3(1)(5)–(9) · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
the gate test — when a token is a financial instrument and outside MiCA entirely · ESMA Guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments (ESMA75-453128700-1323) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
the consultation record behind the gate test · ESMA Final Report, Guidelines on the qualification of crypto-assets as financial instruments (ESMA75-453128700-1323, 17 Dec 2024) · draft — not yet adopted · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — definitions and guidelines re-read in the held texts

Can a non-EU desk serve EU clients without a licence?

Only where the client came entirely of their own initiative — and the guidelines close every door a business model could be built through.

At the desk

  • Treat solicitation as anything: pop-ups, sponsorships, app-store presence — even general brand advertising to the EU public may count.
  • Count influencers and intermediaries as the firm: payment is a strong indication, its absence not decisive. An EU entity redirecting clients to a non-EU affiliate makes the provision a breach.
  • Keep records of who initiated what. Disclaimers cannot supersede contrary facts — the checkbox is worth nothing against a marketing trail.
  • Hold the exemption to the original transaction's context: even the same crypto-asset cannot be marketed to the same client a month later.

In the boardroom

  • Reverse solicitation appears in no register and produces no evidence of authorisation. A revenue line that rests on it has no affirmative story to tell a counterparty, a bank or a supervisor.
  • The second limb of the guidelines is a detection-methods list addressed to supervisors — assume a well-resourced authority reads the same internet your marketing team does.

So whatCite Article 61(3) for both guidelines mandates. There is no Article 61(4) — and material citing one has copied a phantom, which tells you who copied whom.

Article 61 — the exemption itself · Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
both Art 61(3) limbs, as issued · ESMA Guidelines on reverse solicitation under MiCA (ESMA35-1872330276-2030; final report ESMA35-1872330276-1899) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — the issued guidelines re-read; stage from the registry

Whose security rules are these — yours, or someone else's?

Start with who these speak to, because it is not who most summaries assume.

Who this speaks toThe systems-and-security guidelines address competent authorities, offerors and persons seeking admission to trading — not CASPs. A CASP's ICT obligations run principally through DORA.

At the desk

  • If you offer or seek admission of a token: five guidelines — proportionality, governance with management-body accountability, physical access, logical access on least privilege, and cryptographic keys managed through their whole lifecycle.
  • Name the person responsible for keys, from generation to destruction, with replacement methods for loss or compromise and a register of certificates for critical assets.
  • If you are a CASP reading these: check your DORA programme first — these guidelines are not your instrument.

In the boardroom

  • Misreading an instrument's addressee produces confident compliance with someone else's rulebook. The five-minute scope check is the cheapest control in this whole stack.

So whatBefore adopting any instrument into your framework, read its scope section's 'Who?' paragraph aloud in the meeting. If your entity type is not in it, file it under context, not obligations.

Art 14(1)(d) — the white-paper side's ICT floor · ESMA Guidelines on the maintenance of systems and security access protocols, Art 14(1)(d) (ESMA75-223375936-6132; final report ESMA75-223375936-6089) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗
where a CASP's own ICT obligations actually live · Regulation (EU) 2022/2554 (DORA) · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the issued guidelines' scope re-read; stage from the registry

The CASP operating stack — what the desk runs every day

Nine modules in the order the work happens: the file that wins the licence, the people who hold it, and the machinery — complaints, continuity, records, conflicts, the venue, the watch for abuse, the conduct rules — that keeps it.

What actually goes in the authorisation file?

The Level-1 list looks like nineteen items. The RTS underneath it is far more demanding — and it is the document the case officer actually reads against.

At the desk

  • Draft the programme of operations as a three-year commitment: group strategy, every activity regulated or not, target countries with client numbers, websites and languages, outsourcing named and located, forecasts with stress scenarios.
  • Build the AML section to the RTS's shape: your own inherent-and-residual risk assessment, a copy of the policies themselves, the named AML officer with evidence of competence, the training plan.
  • Describe segregation to the key-ceremony level: how keys are approved, how omnibus wallets separate one client from another, funds to a credit institution by close of the next business day.
  • Submit on the mandatory form. A mid-assessment change to the file restarts the clock — notify nothing avoidable.

In the boardroom

  • The programme of operations is what you will be supervised against. Changing the permission set later is a fresh application, assessed on the same clock.
  • Expect this file to consume more senior time and external spend than any other phase — the walk-through dossier prices the phases honestly.
Exhibit · What one authority's intake actually looks like
  • One PDF per information point, I to XVII — general information through custody policy and trading-platform rules
  • File names following the structure of the form, with exact references back to its numbered points
  • Submission through the authority's platform, access issued by email before filing
  • Non-applicability of any point justified in writing — never left blank
  • Any change to submitted documents notified immediately, in writing, while the procedure runs

The Austrian FMA's Art 62 application form (EN, held) — the EU-wide CIR 2025/306 template, expanded with the CDR 2025/305 catalogue

So whatOpen the RTS next to your draft file and tick article by article. The application journey dossier then walks the whole process with the statutory clocks — read it before the board asks for a date.

the information catalogue, article by article · Commission Delegated Regulation (EU) 2025/305 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the mandatory form and the procedures around it · Commission Implementing Regulation (EU) 2025/306 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — RTS/ITS and the held FMA form re-read

Who may run the firm — and who may own it?

Two gates on people: the board is assessed one by one and as a collective, and anyone buying a qualifying stake is assessed all over again.

At the desk

  • Assemble per-member proof: no convictions or penalties in AML, fraud, financial services, insolvency or professional liability — and evidence the board collectively knows this business.
  • Treat competence as qualifications and experience together: national practice expects hands-on time, ordinarily with a regulated firm, with supervised practice as the bridge where one limb is thin.
  • Trace ownership to ultimate beneficial owners before someone else does. A qualifying holding is 10% or significant influence — and an acquisition triggers its own assessment with its own file.

In the boardroom

  • Your own record is now a regulatory filing. Disclosure is survivable; discovery is not.
  • An unready shareholder can stall the firm's application: qualifying holders supply their own fit-and-proper evidence, on the firm's timetable.

So whatKeep a living suitability file per board member and per qualifying holder — assessed at appointment and on every change. The Malta and Austria panels on this page show two supervisors running exactly this check, differently.

the Union standard for a fit management body · Joint EBA/ESMA Guidelines on the suitability assessment of members of the management body of issuers of ARTs and of CASPs (EBA/GL/2024/09; ESMA75-453128700-10) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
what a proposed qualifying holder must file · Commission Delegated Regulation (EU) 2025/414 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the joint guidelines and the RTS re-read; national layer per the NCA panels

What must happen when a client complains?

Complaint-handling is specified to the template level — filing, acknowledgment, investigation, decision, and how you talk to the complainant throughout.

At the desk

  • Publish the procedure and the standard complaint template; let clients file by the stated means and languages.
  • Acknowledge receipt, verify admissibility, and investigate on the clock your own published timeline sets — then issue a reasoned decision and say what happens next.
  • Keep the complaint file: the register of complaints, the communications, the measures taken in response.

In the boardroom

  • Complaints data is supervision fuel: the same records you must keep are the first thing an examiner samples. A tidy complaints book is cheap credibility.

So whatTime-stamp your last five complaints end to end and compare them against your published procedure. The gap between the two documents is your finding before it is anyone else's.

Commission Delegated Regulation (EU) 2025/294 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

What must keep running when something breaks?

Continuity and regularity of the service is its own regulated subject — organisational arrangements, a policy, plans, and tests that actually run.

At the desk

  • Stand up the three layers the RTS names: organisational arrangements, a business-continuity policy, and the plans that implement it.
  • Test the plans periodically — a plan that has never run is a document, not a control.
  • Scale everything to complexity and risk: the RTS builds proportionality in, which means your reasoning for the scale you chose must exist in writing.

In the boardroom

  • Continuity failures are client-visible within minutes and supervisor-visible within days. The test calendar is a board agenda item, not an IT one.

So whatFind the date of your last continuity test and the list of what failed. If either takes more than a day to produce, that is the work.

Commission Delegated Regulation (EU) 2025/299 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Which records must exist, and in what shape?

The record-keeping RTS names the records by category — policies, client agreements, safekeeping, orders, transactions — and the shape they must hold.

At the desk

  • Map your stores to the RTS's categories: policies and procedures; the documents setting out the firm's and the client's rights; safekeeping of client crypto-assets and funds; orders; transactions.
  • Key entities by identifier — the firm's own LEI exists precisely so supervisors can join your records to everyone else's.
  • Where platform records overlap other regimes' standards, keep them to those standards — the RTS says so itself.

In the boardroom

  • Records are the firm's memory under examination: every other module on this page is evidenced — or not — by what this one keeps.
Exhibit · The record categories, as the RTS names them
  • Retention of records — the general duty and its clock
  • The firm's policies and procedures, as records in themselves
  • Documents setting out the firm's and the client's rights and obligations
  • Safekeeping records for clients' crypto-assets and funds
  • Records of orders — and of transactions

CDR (EU) 2025/1140, Articles 2–7 (held)

So whatPut the RTS's record categories next to your systems inventory and mark every record you could not produce this week. The regulation names the records; the gap list is yours to own before anyone asks.

Commission Delegated Regulation (EU) 2025/1140 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

How must conflicts be policed — and disclosed?

The conflicts RTS splits the subject the way the risk splits: conflicts that can hurt the firm, conflicts that can hurt clients, and the policies, pay structures and personal trades behind both.

At the desk

  • Run both inventories the RTS runs: conflicts potentially detrimental to the firm, and those potentially detrimental to clients — they are different lists with different owners.
  • Cover remuneration and personal transactions explicitly: the RTS gives each its own policy article, including the connected persons around your people.
  • Disclose with content, not boilerplate: the disclosure states the role and capacity in which the firm acts when providing the service.

In the boardroom

  • Crypto firms concentrate roles — venue, dealer, custodian — that traditional finance separates by licence. The conflicts file is where that concentration is either managed or exposed.

So whatTake one service you provide in two capacities and write down who could be hurt and how the client is told. If the disclosure reads like boilerplate, it is.

Commission Delegated Regulation (EU) 2025/1142 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Running a venue: what must it record and show?

A trading platform carries two data duties of its own: an order book kept to a prescribed content and format, and transparency data presented the prescribed way.

At the desk

  • Keep the order book to the RTS's field set and format — it is a supervisory record, designed to be read by machines other than yours.
  • Present pre- and post-trade transparency data as the second RTS prescribes, not as the product team prefers.
  • Remember the venue's operating rules already owe MiCA an admission process with due diligence on what is admitted — the venue is a gatekeeper, not just a matching engine.

In the boardroom

  • Venue permissions are the rare ones: eighteen platform authorisations existed in the whole register at the 24 August 2026 snapshot. The duties are priced accordingly.

So whatAsk your venue team to export one day of order-book records in the regulatory format today. The exercise finds the schema gaps while they are still cheap.

order-book records — content and format · Commission Delegated Regulation (EU) 2025/416 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how transparency data is presented · Commission Delegated Regulation (EU) 2025/417 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — both RTS re-read in the held texts; count from the register snapshot

What must you detect — and what must you report?

The market-abuse machinery has two moving parts: arrangements that detect, and the STOR that reports — plus a disclosure duty when the firm itself holds inside information.

At the desk

  • Scale your surveillance to your own size, scale and nature — the RTS builds proportionality in, and expects you to have reasoned it.
  • File a STOR on the template when orders, transactions or DLT behaviour look abusive — including conduct in how transactions are ordered on-chain.
  • If the firm holds inside information about a crypto-asset, publish it by the prescribed technical means — and document any delay on the conditions the ITS sets.

In the boardroom

  • Cross-border coordination is wired into the RTS itself: one report can put several authorities around one table. Assume anything filed travels.
  • Who counts as a watcher was a genuinely argued question — the consultation's miners-and-validators debate is on the moving-edge page, resolved into this act.
Exhibit · The STOR template's spine
  • Section 1 — who is reporting: legal form, LEI, the capacity in which you acted
  • Section 2 — what you saw: the crypto-asset by DTI (or described without one), its type — ART, EMT or other
  • The trading platform where the order was placed — or the DLT behaviour observed
  • The narrative and attachments that let an authority reconstruct your suspicion

CDR (EU) 2025/885, Annex (held)

So whatPrint the STOR template and walk one hypothetical through it with your surveillance lead. Every field you cannot populate names a data feed you do not yet have.

the systems and the STOR template · Commission Delegated Regulation (EU) 2025/885 · applicable — this binds · verified 2026-08-26 · Read the text ↗
publishing — and lawfully delaying — inside information · Commission Implementing Regulation (EU) 2024/2861 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how the authorities are told to look · ESMA Guidelines on supervisory practices for competent authorities to prevent and detect market abuse under MiCA (ESMA75-453128700-1039; final report ESMA75-453128700-1408) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — RTS, ITS and the drafting record re-read in the held texts

What do the conduct guidelines add on top?

Three ESMA guideline sets sit above the acts: suitability when you advise or manage, procedures and client rights when you transfer, and competence floors for the people doing the advising. Each is at its own lifecycle stage — read the footer.

At the desk

  • Run suitability to the MiFID-aligned standard the guidelines import — the consultation asked whether crypto deserved a lighter regime, and the answer was no.
  • Give portfolio-management clients their periodic statement in the guideline format.
  • Build transfer procedures around the client's rights in them — the guidelines read the service from the client's side of the transaction.
  • Watch the knowledge-and-competence clock: adopted July 2025, but the comply-or-explain clock starts only when translations publish.

In the boardroom

  • Guidelines bind through pressure on your supervisor, not directly on the firm — but a supervisor that declared compliance examines against them as if they were rules. Know your authority's declarations.

So whatFor each guideline set your services touch, note two dates: when it started applying, and when your authority declared compliance. Where the second is missing, ask — the compliance tables are public.

suitability + the periodic statement · ESMA Guidelines on certain aspects of the suitability requirements under MiCA (ESMA35-1872330276-2031; third-package, Art 81(15)) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗
transfer procedures and client rights · ESMA Guidelines on procedures and policies, including the rights of clients, for crypto-asset transfer services (ESMA35-1872330276-2032; third-package, Art 82(2)) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗
staff knowledge and competence — clock not yet started · ESMA Guidelines for the criteria on the assessment of knowledge and competence under MiCA (final report ESMA35-1872330276-2380) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — all three issued texts re-read; stages from the registry

The disclosure plumbing around you

One module on the machinery that moves disclosure documents around the regime — who must produce machine-readable white papers, and why the format is the point.

Why is a white paper machine-readable — and whose job is it?

One document, two audiences: a retail reader opens the white paper in a browser and reads prose; the register consumes the same file's embedded tags at scale. Inline XBRL is the format that refuses to choose.

Who this speaks toThe drawing-up duty sits with offerors, persons seeking admission and issuers — the white-paper side. A CASP meets this machinery when it seeks admission of a token to its own venue.

At the desk

  • Produce the white paper as one XHTML file with the taxonomy's tags embedded — human-readable without special software, machine-readable without re-keying.
  • Tag the classification data the RTS names: identifiers included — LEIs for persons, the digital token identifier for the asset.
  • Both format acts applied from 23 December 2025 — white papers from year one live in a different format, which any dataset built on the register inherits.

In the boardroom

  • The format is the register's supply chain: what you tag is what supervisors and analysts query. Treat the tagging as disclosure, because it is.

So whatOpen any post-December-2025 white paper from the register, view its source, and find the tags. Once you have seen one, the mandate stops being abstract.

the single XHTML file with Inline XBRL tags · Commission Implementing Regulation (EU) 2024/2984 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the classification data the tags must carry · Commission Delegated Regulation (EU) 2025/421 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the listed-company precedent this borrows from · Commission Delegated Regulation (EU) 2019/815 (ESEF) · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — ITS/RTS re-read; rationale per the acts' own recitals

One regime, thirty implementations

MiCA harmonises the process; it does not harmonise the experience. The map below carries three layers, each from a dated primary — the transitional windows each state chose, the authorisation counts, and the non-compliant register read under the one rule that keeps it honest: a register evidences what it records, never what it omits. Below it, two supervisors are worked in detail, because they teach two different styles of the same regime.

as at ESMA list, 19 May 2026

EEA EFTA — on ESMA’s list, off the EU map frame

Malta

Transitional window (concluded)
18 months, as ESMA’s list of 19 May 2026 records it.
Authorised CASPs · 24 August 2026
22 authorisation records in the register snapshot. Zero is a register fact with a date, not a judgment on the state.
Non-compliant entries · 24 August 2026
0 of the register’s 167entries were notified by this state’s authority.

Two supervisors, worked

Malta shows what a high-volume authoriser asks of the people who will run a firm; Austria shows what an enforcement-first supervisor does with the disclosure rules. Every statement below is traced to a named, dated, published output of the authority itself — and practice goes stale, so each carries its date. Last verified 2026-08-27.

Malta Financial Services Authority

MFSA

What a high-volume authoriser actually asks of the people who will run a CASP — the questionnaire, the competence checking, and a pre-application track with real gates in it.

Transitional window: 18 months. Malta took the full 18-month window (ESMA grandfathering list, 19 May 2026 version). The conference-deck figure happens to agree here — but the list is the citation, not the slide.

  • Journey phase 5. Pre-submission engagement

    The pre-application stage is not voluntary. Prospective applicants are required to submit a Statement of Intent; what is discretionary is the meeting — the Authority 'at its sole discretion' may request further information or attendance at a preliminary meeting, requested within 10 working days of receiving the Intention.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 5. Pre-submission engagement

    The Statement of Intent is a high-level presentation that already reaches the sensitive material: a shareholding diagram to ultimate beneficial owners, any regulatory history of the applicant and related persons including group entities and applications filed with other regulators, directors and key function holders with reporting lines and their time commitments, and an outline of business model, local substance, client types and target markets.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 5. Pre-submission engagement

    Two gates sit before any review: the application fee is non-refundable and payable on submission, and where the MFSA considers a proposal outside its risk appetite or 'not yet mature enough', it guides the prospective applicant accordingly at the Intention Stage — before a fee is paid and without a refusable decision. After a no-objection, the application must be filed within 40 working days or the Intention may be treated as withdrawn.

    MFSA Authorisation Process Service Charter, v1.1 · 2024-09-19 · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Every proposed director and key function holder is assessed through the Personal Questionnaire against four criteria: competence, reputation, conflicts of interest and independence of mind, and time commitment. The entity assesses first — 'the Entity has the primary responsibility to carry out its own due diligence assessment' — and proportionality 'cannot lead to the lowering of the suitability standards applied by the MFSA'.

    MFSA Guidelines to the Personal Questionnaire (updated version) · 2024-03-12 · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Competence is checked through three mechanisms: a published (non-exhaustive) List of Recognised Qualifications; hands-on experience the MFSA expects 'ordinarily with a regulated financial services entity' — the sentence with the most bite for crypto-native management teams; and a supervised-practice bridge, under which a qualified applicant without direct experience may be required to act 'under the supervision of an experienced authorised individual for a specified period', acting unsupervised only once that person confirms competence. Qualifications and experience are alternatives at the margin, not cumulative requirements.

    MFSA Guidelines to the Personal Questionnaire (updated version) · 2024-03-12 · verified 2026-08-27

  • Journey phase 2. Choosing the home authority

    Which route an applicant took depended on what it held on 30 December 2024: Category A (VFA-licensed before that date) could use the grandfathering window and a simplified application anchored in a board resolution, the fee, and the 2024 MiCA thematic exercise; Category B (applying for a VFA licence but not yet licensed) could not use the simplified procedure and ran the full MiCA process from the Statement of Intent up.

    MFSA Circular on the Authorisation Process for MiCA Applicants · 2024-12-10 · verified 2026-08-27

  • Journey phase 4. Building the file

    The pack changed under applicants mid-flight: from 17 June 2025 all CASP applicants, Category A and B alike, had to add two further annexes — AX05 (Digital Operational Resilience Assessment) and AX50 (ICT Third-Party Provider Assessment). That is the DORA layer arriving inside the MiCA application six months after the process opened.

    MFSA Follow-Up Circular on the Authorisation Process for MiCA Applicants · 2025-06-17 · verified 2026-08-27

  • Journey phase 4. Building the file

    Malta's MiCA Rulebook (v3.00) is thin by design because it points outward — it adopts Union instruments by name as the MFSA's own decision rules, including the joint EBA/ESMA suitability guidelines. The national layer is mostly procedure; the substance is the Union standard.

    MFSA Markets in Crypto-Assets Rulebook, v3.00 · 2026-03-10 · verified 2026-08-27

Finanzmarktaufsicht (Austria)

FMA (AT)

What an enforcement-first supervisor does with the white-paper and marketing rules — and what a mechanised application intake looks like. Its first published MiCAR penal decision is the worked enforcement record.

Transitional window: 12 months. Austria shortened the window to 12 months (ESMA list, 19 May 2026 version). The FMA had said so in its own words in August 2024: existing registered providers could continue 'bis längstens Ende 2025' — until the end of 2025 at the latest. The population was small: twelve § 32a FM-GwG registered providers as at August 2024.

Austria's Finanzmarktaufsicht (fma.gv.at) is not the Liechtenstein FMA. Liechtenstein is a separate EEA jurisdiction with its own authority — and its own rows in the CASP register.

  • Journey phase 7. Substantive assessment

    Marking full application on 30 December 2024, the FMA announced a particular focus on CASP authorisation procedures from 2025: sufficient own funds, robust risk management, adequate internal control systems and transparent information on business models — with increased attention to fit-and-proper requirements for owners, managing directors and other key function holders being consistently implemented.

    FMA press release, 'MiCAR-Regime voll anwendbar' · 2024-12-30 · verified 2026-08-27

  • Journey phase 4. Building the file

    The same release flagged DORA applying in parallel from 17 January 2025, with the FMA expecting gapless monitoring of IT systems, regular stress tests and clear contingency plans. The supervisor announced the MiCA file and the ICT expectations together; an applicant that treats the ICT limb as an afterthought is out of step with the FMA's own framing.

    FMA press release, 'MiCAR-Regime voll anwendbar' · 2024-12-30 · verified 2026-08-27

  • Journey phase 4. Building the file

    The Austrian application is mechanised on the face of the form: submission through the FMA Incoming Platform (access issued by email from casp@fma.gv.at before submission); each of points I to XVII answered in a separate PDF with the fillable sections carrying only references; file names following the structure of the form; and non-applicability of any provision justified, never left blank.

    FMA Application Form for authorisation as a CASP (Art 62 MiCAR), EN, as retrieved 26 Aug 2026 · undated (retrieved 2026-08-26) · verified 2026-08-27

  • Journey phase 3. Entity, capital and people

    Point VII of the form places the suitability burden on the applicant: it must supply the results of its own assessment of each management-body member and of the body's collective suitability, including the assessment report. The Union standard is the same as Malta's; the division of labour is not — the FMA receives the applicant's completed assessment, where the MFSA also assesses the person directly through the Personal Questionnaire.

    FMA Application Form for authorisation as a CASP (Art 62 MiCAR), EN, as retrieved 26 Aug 2026 · undated (retrieved 2026-08-26) · verified 2026-08-27

  • Journey phase 4. Building the file

    The form's own cover cites 'Implementing Regulation (EU) 2025/305' for the standard forms — but 2025/305 is the Delegated Regulation (information content) and the forms instrument is Implementing Regulation (EU) 2025/306; 31 March 2025 is the OJ date of both, not either act's own date. Recorded as the state of the document retrieved on 26 August 2026. Two adjacent numbers, one delegated and one implementing: the RTS/ITS distinction is genuinely easy to slip on, which is the argument for teaching it.

    FMA Application Form checked against the held OJ texts of CDR (EU) 2025/305 and CIR (EU) 2025/306 · undated (retrieved 2026-08-26) · verified 2026-08-26

  • Journey phase 8. Register, passport, supervision

    Authorisation extinguishes the old registration: on granting a CASP authorisation, the FMA declares the firm's § 32a FM-GwG virtual-currency registration 'als erloschen' under § 23 of the MiCA-Verordnung-Vollzugsgesetz (MiCA-VVG, BGBl. I Nr. 111/2024) read with Article 143(3) MiCA. The national implementing act is the hinge between the two regimes.

    FMA notice of authorisation of Bitpanda GmbH (Bescheid of 9 April 2025, published 10 April 2025) · 2025-04-10 · verified 2026-08-27

The worked enforcement record

The first published MiCAR penal decision — EUR 70,000, four breaches, final
  • By Bekanntmachung of 14 August 2026 the FMA recorded a fine of EUR 70,000 on Bitpanda GmbH, the proceedings concluded on an accelerated basis under § 22 Abs 2b FMABG. The penal decision is final ('rechtskräftig').
  • The four breaches: failing to transmit a crypto-asset white paper to the FMA at latest 20 working days before publication (Art 8(1) and (5) MiCA); disseminating a marketing communication before the white paper was published (Art 7(2)); omitting the required no-approval statement from a marketing communication (Art 7(1)(e)); and omitting a telephone number and email address from the same communication (Art 7(1)(d)). Three of the four are marketing-communication failures — the mechanical disclosure rules are, on this record, the easier ones to miss.
  • A same-day companion notice records this as the first final MiCAR penal decision the FMA has published — and warns against over-reading it: the fact that it is the first published case 'begründet für sich genommen keine Sonderstellung' — establishes no special position — for the firm or the breaches.
  • The same firm had been authorised by the FMA sixteen months earlier (Bescheid of 9 April 2025). Authorisation and sanction are not alternative states: a firm can clear the entry gate and still be fined under conduct rules that bite in ordinary operation. Any training that presents authorisation as the finish line has mis-taught the regime.

Every statement above is attribution to the FMA's own published notices of 14 August 2026 and 10 April 2025, and goes no further than their text. The record is used because it is closed, dated and final — one published case establishes what happened in that case, not a supervisory pattern.

FMA, Bekanntmachung (sanction) and 'Erste Veröffentlichung eines MiCAR-Straferkenntnisses', both 14 August 2026; FMA notice of authorisation, 10 April 2025 · verified 2026-08-27

As at: instrument lifecycle stages verified 2026-08-26; register figures from the snapshots of 24 August 2026; supervisory-practice statements individually dated above and last verified 2026-08-27. Where an instrument above is a guideline, comply-or-explain is stated on its stage line.