Skip to main content
Category: Virtual Assets and Technology

Markets in Crypto-Assets Regulation (MiCA)

Also known as: MiCA, MiCAR, Regulation (EU) 2023/1114, Markets in Crypto-Assets Regulation
Simply put

MiCA is a European Union regulation that creates a common set of rules for crypto-assets and the businesses that provide crypto-asset services across the EU. It is designed to protect consumers and investors while supporting innovation in the digital asset sector. It became fully applicable on 30 December 2024.

Formal definition

The Markets in Crypto-Assets Regulation (MiCA), formally Regulation (EU) 2023/1114, is described in the evidence as the first EU-level framework establishing harmonised rules for crypto-assets and crypto-asset service providers within the European Union. Because it is an EU Regulation rather than a Directive, it applies directly across member states without requiring national transposition, and the evidence indicates it became fully applicable on 30 December 2024. Its stated objectives include protecting consumers and investors and fostering innovation. Note that the scope, categories of crypto-assets covered, and specific obligations for issuers and service providers should be confirmed against the text of the Regulation itself, as those details are not fully set out in the evidence provided.

Why it matters

For much of the crypto-asset sector's history, businesses operating in the European Union faced a fragmented regulatory landscape, with obligations varying from one member state to another and, in some areas, no clear framework at all. MiCA matters because, according to the evidence, it is the first European-level framework establishing harmonised rules for crypto-assets and crypto-asset service providers across the EU. As an EU Regulation rather than a Directive, it applies directly in member states without requiring national transposition, which reduces the divergence that previously allowed for inconsistent treatment of the same activity in different jurisdictions.

The stated objectives of MiCA include protecting consumers and investors while fostering innovation in the digital asset sector. For compliance professionals, the significance lies in having a common reference point for how crypto-assets and the businesses that provide crypto-asset services are treated within the EU, rather than piecing together disparate national rules. The evidence indicates MiCA became fully applicable on 30 December 2024, marking the point from which its harmonised framework took effect across member states.

It is important to note that MiCA's precise scope, the categories of crypto-assets it covers, and the specific obligations it imposes on issuers and service providers are not fully set out in the evidence provided and should be confirmed against the text of the Regulation itself. Firms should also be careful not to assume that MiCA displaces or duplicates separate anti-money laundering and counter-terrorist-financing obligations, which arise under distinct EU instruments; the evidence here describes MiCA as a framework for regulating crypto-assets and their service providers, not as an AML/CFT regime in itself.

Who it's relevant to

Crypto-asset service providers operating in the EU
The evidence describes MiCA as a framework regulating crypto-asset service providers within the European Union. Businesses that provide crypto-asset services to EU customers are therefore likely to fall within its scope, though the specific categories of service and the obligations attaching to each should be confirmed against the Regulation itself, as they are not detailed in the evidence provided.
Issuers of crypto-assets
As a framework establishing harmonised rules for crypto-assets in the EU, MiCA is relevant to entities that issue crypto-assets. The precise requirements for issuers, including any distinctions between different types of crypto-assets, are not set out in the evidence and should be verified directly against the text of Regulation (EU) 2023/1114.
Compliance and regulatory affairs teams
Compliance officers and regulatory affairs professionals within crypto-asset firms need to understand that MiCA applies directly across EU member states from 30 December 2024 without national transposition. Because MiCA is a market-conduct and consumer-protection framework, these teams should treat it as distinct from, and additional to, separate EU AML/CFT obligations, and should map their firm's activities against the Regulation's scope.
National competent authorities and supervisors
Supervisory bodies in EU member states, such as national central banks and financial regulators, are relevant stakeholders in the application of MiCA. The evidence references national competent authority guidance on the framework; the exact supervisory roles and the division of responsibilities between national and EU-level bodies should be confirmed against the Regulation and authority publications.
Consumers and investors in crypto-assets
MiCA's stated objectives include protecting consumers and investors while fostering innovation. Individuals and entities that acquire or use crypto-assets within the EU are the intended beneficiaries of these protections, although the specific protective measures are not detailed in the evidence provided.

Inside MiCA

Scope and Covered Activities
MiCA is an EU regulation establishing a harmonised framework for crypto-asset markets across EU member states. It generally applies to issuers of crypto-assets and to crypto-asset service providers (CASPs). Its scope typically excludes crypto-assets that already qualify as financial instruments under existing EU financial services law (such as MiFID II), as well as certain other categories that fall under separate regimes. Practitioners should confirm the precise perimeter against the regulation, as classification can be fact-specific.
Crypto-Asset Categories
MiCA distinguishes between different types of crypto-assets, including asset-referenced tokens (ARTs), electronic money tokens (EMTs), and other crypto-assets not covered by those categories. Different obligations generally attach depending on the classification, so correct categorisation is a threshold compliance step.
Authorisation and Supervision of CASPs
MiCA generally requires crypto-asset service providers to be authorised and subject to ongoing supervision by competent authorities in the EU. This is a regulatory licensing framework and is conceptually distinct from AML/CFT registration or authorisation, which stems from separate instruments.
Relationship to AML/CFT Frameworks
MiCA is primarily a market-integrity, consumer-protection, and prudential regulation for crypto-assets. It is not itself the principal source of AML/CFT obligations; anti-money laundering and counter-terrorist-financing requirements for crypto activity in the EU generally derive from the EU AML framework (the AML Directives and, going forward, the AML Regulation and related instruments). Obliged-entity status and CDD duties should be traced to those instruments rather than to MiCA alone.
Issuer and Disclosure Obligations
MiCA generally imposes transparency and disclosure requirements on issuers, such as producing certain information documents for offered crypto-assets, alongside conduct and governance expectations. Exact requirements vary by asset category and should be confirmed against the regulation.

Common questions

Answers to the questions practitioners most commonly ask about MiCA.

Does MiCA function as an anti-money laundering framework for crypto-assets?
No. MiCA is primarily a market-conduct, prudential, and consumer-protection regime governing the issuance of crypto-assets and the provision of crypto-asset services in the EU. It is not itself an AML instrument. AML/CFT obligations for crypto-asset service providers arise from the EU's separate anti-money laundering framework, historically the AML Directives and, going forward, the AML Regulation and related instruments, rather than from MiCA. In practice a MiCA-authorised provider is typically also an obliged entity under the applicable EU AML rules, but the two frameworks are distinct in source and purpose, and their requirements should be assessed separately.
Does obtaining MiCA authorisation mean a crypto-asset service provider has satisfied its customer due diligence and screening duties?
No. MiCA authorisation addresses licensing and operational requirements to provide crypto-asset services in the EU; it does not discharge AML/CFT obligations such as customer due diligence, ongoing monitoring, sanctions screening, or suspicious transaction reporting. Those duties flow from the EU AML framework and, where relevant, from EU sanctions rules, which operate independently. A provider may hold MiCA authorisation and still be non-compliant with its AML/CFT and screening obligations, and vice versa. The exact scope of each set of obligations should be confirmed against the applicable EU instruments and national transposition where relevant.
Which entities generally fall within MiCA's scope, and what falls outside it?
MiCA generally applies to issuers of certain crypto-assets and to firms providing crypto-asset services within the EU. Its scope boundaries are defined by the regulation itself, and certain assets or activities that are already covered by other EU financial-services regimes may fall outside MiCA to avoid duplication. Because the precise perimeter, including exclusions and the treatment of particular asset types, is set out in the regulation and can be subject to interpretation, firms should map their specific activities against the applicable MiCA provisions and any guidance from the relevant EU or national authorities rather than assuming coverage or exclusion.
How should a firm coordinate its MiCA compliance work with its existing AML/CFT programme?
Because MiCA and the EU AML framework are separate but overlapping in application, firms typically treat them as complementary workstreams rather than a single project. A common operational approach is to map obligations from each source to responsible functions, so that authorisation, governance, and market-conduct requirements under MiCA are addressed alongside, but not merged with, customer due diligence, monitoring, and reporting obligations under the AML rules. This helps avoid the assumption that compliance with one regime satisfies the other. The specific allocation of responsibilities should reflect the firm's structure and the applicable legal texts.
What documentation and governance arrangements are generally relevant for a firm seeking to operate under MiCA?
As a market and prudential regime, MiCA generally contemplates authorisation processes and ongoing operational, governance, and disclosure requirements for in-scope issuers and service providers. Firms typically need to demonstrate appropriate organisational arrangements to the competent authority. Where AML/CFT risk is concerned, the relevant policies, controls, and records derive from the EU AML framework rather than MiCA. Firms should confirm the exact documentation, thresholds, and governance expectations against the applicable MiCA provisions and any guidance issued by the relevant supervisory authorities, as these can vary in detail and interpretation.
How does a firm determine which competent authority and national rules apply to its MiCA activities?
MiCA operates within the EU framework, which involves both EU-level rules and national transposition or supervisory arrangements. The applicable competent authority generally depends on the firm's place of establishment and the nature of its activities. Because supervisory allocation and any national-level specifics can differ across Member States, firms should identify the relevant authority and confirm applicable national provisions rather than assuming a single uniform approach applies across the EU. Exact designations and procedures should be verified against the applicable regulation and the guidance of the relevant national and EU authorities.

Common misconceptions

MiCA is the EU's anti-money laundering law for crypto.
MiCA is principally a market-conduct, consumer-protection, and prudential framework for crypto-assets and their service providers. AML/CFT obligations for crypto activity in the EU generally stem from the separate EU AML framework rather than from MiCA itself. The two regimes operate alongside each other and should not be treated as interchangeable.
Being authorised as a CASP under MiCA satisfies a firm's AML compliance obligations.
MiCA authorisation is a market-access and supervisory licensing matter. It does not, by itself, discharge AML/CFT duties such as customer due diligence, ongoing monitoring, or suspicious-activity reporting, which arise under the applicable AML instruments. A firm may need to comply with both frameworks concurrently.
MiCA applies uniformly to all crypto-assets.
MiCA distinguishes between categories such as asset-referenced tokens, electronic money tokens, and other crypto-assets, with obligations that generally differ by category. It also typically excludes crypto-assets that qualify as financial instruments under existing EU law and certain other categories. Scope and applicable duties are fact-specific and should be confirmed against the regulation.

Best practices

Classify each crypto-asset correctly at the outset (for example, as an asset-referenced token, electronic money token, or other crypto-asset), since applicable obligations generally depend on the category and misclassification can cascade through the compliance programme.
Treat MiCA authorisation and AML/CFT compliance as separate workstreams, mapping AML/CFT obligations to the applicable EU AML instruments rather than assuming MiCA coverage satisfies them.
Confirm scope boundaries before onboarding activity, identifying where a crypto-asset may fall outside MiCA (for example, where it qualifies as a financial instrument under existing EU law) and which regime then applies.
Verify precise thresholds, disclosure requirements, and category-specific obligations against the text of the regulation and competent-authority guidance rather than relying on generalised summaries, as details vary by asset type.
Coordinate MiCA authorisation and supervisory obligations with the firm's wider AML/CFT controls so that licensing, governance, and financial-crime measures operate consistently rather than in isolation.
Document the classification rationale and the mapping of obligations across MiCA and the applicable AML framework, so the basis for compliance decisions is auditable and can be revisited as the EU regime evolves.