Get a CASP authorisation under MiCA — and keep it
A crypto-asset service provider needs an authorisation under Art. 59–63 MiCA before serving EU customers, and then has to meet ongoing conduct, prudential and ICT obligations — including DORA, because a CASP is a financial entity. Audomate audits the application file article by article, drafts the missing policies and white paper sections, and keeps the file current so the authorisation, once granted, is not put at risk.
The application is a set of documents
Programme of operations, governance, internal control, ICT and security, custody policy, conflicts, complaints, AML — each with its legal basis in Art. 62 MiCA.
The white paper has a prescribed structure
Art. 6 MiCA and Annex I list the mandatory sections. Missing or non-conforming sections delay the notification.
DORA applies from day one
A CASP is a financial entity under Art. 2(1)(f) DORA. The ICT risk framework, incident reporting and vendor clauses are part of being authorisable.
The authorisation is only the beginning
Reporting, changes to the programme of operations, new services and new sub-custodians all require updated documentation the supervisor can ask for.
What the competent authority reads
| Application element | Basis in MiCA | What Audomate checks |
|---|---|---|
| Programme of operations and services | Art. 62(2)(a)–(c) | Every service in the programme mapped to an Art. 3 definition and to the specific rules in Art. 70–83 |
| Governance, fitness and propriety | Art. 62(2)(d)–(g), Art. 68 | Management arrangements, evidence of competence and good repute, shareholder information |
| Internal control and risk management | Art. 62(2)(h), Art. 68 | The policies exist, are consistent with each other and name the people responsible |
| ICT systems and security | Art. 62(2)(i), DORA | ICT risk framework, incident process, business continuity, vendor clauses |
| Custody and segregation of client assets | Art. 62(2)(j), Art. 70, 75 | Custody policy, segregation, key management, liability for loss |
| Complaints, conflicts, outsourcing | Art. 62(2)(k)–(m), Art. 71–73 | Procedures with escalation and record-keeping |
| White paper (issuers/offerors) | Art. 6, Annex I | Every mandatory section present and consistent with the programme |
After authorisation
The obligations that most often catch an authorised CASP out are operational: notifying material changes, keeping the DORA ICT vendor register current, reporting major ICT incidents and updating the white paper when the facts change. Audomate's continuous compliance turns those into tasks and re-verifies the file, so when the supervisor asks for current documentation you answer from a file that is already current.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Reach this outcome in four weeks
One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.