A crypto-asset service provider that holds clients' crypto-assets or the means of access to them — the private keys — provides custody and administration, a Class 2 service under MiCA. The application must contain a custody policy, and the Financial Supervision Authority reads it together with the security and key management procedure. This guide explains what Article 75 of MiCA requires and what the two documents must answer.
The guide is general information, not legal advice.
What Article 75 of MiCA requires
- a written agreement with each client on the custody service, stating the parties' rights and obligations, the type of crypto-assets, the custody policy and the fees;
- a register of positions, opened in the name of each client, recording each client's rights to the crypto-assets, updated promptly after every movement;
- a custody policy with internal rules and procedures to ensure the safekeeping or control of the crypto-assets or the means of access to them, minimising the risk of loss through fraud, cyber threats or negligence;
- segregation: clients' crypto-assets are held separately from the CASP's own holdings and are legally not part of its estate in insolvency; on-chain addresses are segregated;
- liability: the CASP is liable for the loss of crypto-assets or the means of access resulting from an incident attributable to it, up to the market value of the lost assets;
- at least once every three months, and on request, a statement of positions to each client.
A Class 3 trading platform () may also provide the Class 2 services, including custody, and then needs the same documents; a Class 2 application is .
The security and key management procedure
The custody policy says what the CASP promises; the key management procedure shows how it keeps the promise. It covers:
- the wallet architecture: cold, warm and hot wallets and the limits between them;
- key generation and storage: hardware security modules, multi-party computation or multi-signature schemes;
- access control and the "four-eyes" rule for movements from cold storage;
- backup, recovery and key rotation, and what happens when a key holder leaves;
- incident handling, aligned with the ICT risk management framework required by DORA.
Our documents
- custody and administration policy — , for a Class 2 or Class 3 application;
- security and key management procedure — , written from your technical architecture.
Both are ordered with the MiCA CASP application; see also MiCA classes and capital and the Travel Rule.
What you receive
- a custody policy that meets Article 75 and matches your client agreement;
- a key management procedure the authority can test against your systems;
- answers to the Financial Supervision Authority's questions on both during the application.
Prices are starting prices confirmed in a written quote and exclude VAT. We prepare the documents; the authorisation decision is the Financial Supervision Authority's. All communication takes place by email.
Ready to start? Choose MiCA Class 2 or Class 3 and tick the custody policy and key management procedure. Open the quote form.
Frequently asked questions
Which MiCA class includes custody of crypto-assets?
Custody and administration of crypto-assets on behalf of clients is a Class 2 service under Annex IV of MiCA. A Class 3 trading platform may also provide it. Either way the application needs a custody policy under Article 75.
Is the CASP liable if clients' crypto-assets are lost?
Yes, for a loss resulting from an incident attributable to the CASP, up to the market value of the crypto-assets lost (MiCA Article 75(8)). The key management procedure is the CASP's main tool to prevent such incidents.
Related guides
- MiCA CASP licence in Estonia
- MiCA licence classes and capital
- Crypto-asset white paper requirements under MiCA
- Travel Rule for crypto-asset service providers
More on this topic: MiCA crypto licensing.