Outcome · Get and keep the authorisation

Get a CASP authorisation under MiCA — and keep it

A crypto-asset service provider needs an authorisation under Art. 59–63 MiCA before serving EU customers, and then has to meet ongoing conduct, prudential and ICT obligations — including DORA, because a CASP is a financial entity. Audomate audits the application file article by article, drafts the missing policies and white paper sections, and keeps the file current so the authorisation, once granted, is not put at risk.

01

The application is a set of documents

Programme of operations, governance, internal control, ICT and security, custody policy, conflicts, complaints, AML — each with its legal basis in Art. 62 MiCA.

02

The white paper has a prescribed structure

Art. 6 MiCA and Annex I list the mandatory sections. Missing or non-conforming sections delay the notification.

03

DORA applies from day one

A CASP is a financial entity under Art. 2(1)(f) DORA. The ICT risk framework, incident reporting and vendor clauses are part of being authorisable.

04

The authorisation is only the beginning

Reporting, changes to the programme of operations, new services and new sub-custodians all require updated documentation the supervisor can ask for.

What the competent authority reads

Application elementBasis in MiCAWhat Audomate checks
Programme of operations and servicesArt. 62(2)(a)–(c)Every service in the programme mapped to an Art. 3 definition and to the specific rules in Art. 70–83
Governance, fitness and proprietyArt. 62(2)(d)–(g), Art. 68Management arrangements, evidence of competence and good repute, shareholder information
Internal control and risk managementArt. 62(2)(h), Art. 68The policies exist, are consistent with each other and name the people responsible
ICT systems and securityArt. 62(2)(i), DORAICT risk framework, incident process, business continuity, vendor clauses
Custody and segregation of client assetsArt. 62(2)(j), Art. 70, 75Custody policy, segregation, key management, liability for loss
Complaints, conflicts, outsourcingArt. 62(2)(k)–(m), Art. 71–73Procedures with escalation and record-keeping
White paper (issuers/offerors)Art. 6, Annex IEvery mandatory section present and consistent with the programme

After authorisation

The obligations that most often catch an authorised CASP out are operational: notifying material changes, keeping the DORA ICT vendor register current, reporting major ICT incidents and updating the white paper when the facts change. Audomate's continuous compliance turns those into tasks and re-verifies the file, so when the supervisor asks for current documentation you answer from a file that is already current.

Let's talk about your MiCA file

Questions we get most often

No. Audomate audits the file, drafts the missing documents and keeps it consistent; your counsel and your board file the application and answer the authority's questions. We make the file complete; we do not represent you.
Yes — the audit finds inconsistencies between documents written by different people at different times, which is the most common reason for a request for further information. And after authorisation the file has to stay current, which is where a tool beats a one-off engagement.
Your ICT and security arrangements are part of the application (Art. 62(2)(i)), and DORA applies to CASPs as financial entities. In practice the authority expects the ICT risk framework and the incident process to exist at the point of authorisation.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Reach this outcome in four weeks

One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.