MiCA checklist: launching a crypto exchange in the EU
What the EU's Markets in Crypto-Assets Regulation asks of an exchange: authorisation, capital, governance, client assets, the trading platform rules, and the laws that sit beside it.

MiCA, the EU's Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114), replaced a patchwork of national regimes with one set of rules for crypto-asset service providers (CASPs). Its CASP rules have applied since 30 December 2024, and the transitional period that let existing firms keep operating under national regimes ended on 1 July 2026 at the latest. Running an exchange for EU clients now means meeting MiCA.
This checklist walks through what that involves for an exchange. It is a practical overview, not legal advice: the details depend on the services you offer and on your national authority, so work through it with your counsel.
1. Authorisation
Apply for CASP authorisation to the national competent authority of the member state where you have your registered office.
Be established in the EU: a registered office in a member state where you provide at least part of your services, your place of effective management in the EU, and at least one director resident in the EU.
Describe the services you will provide. Operating a trading platform, exchanging crypto for funds or for other crypto, and custody are separate services, and each has its own requirements.
Once authorised, you can serve clients across the EU by notification (passporting), and you appear in the public register kept by ESMA.
Some regulated firms, such as banks and investment firms, can offer crypto-asset services by notifying their authority instead of applying for a new authorisation. Most new exchanges apply.
2. Own funds
MiCA sets a permanent minimum capital by class of service: €50,000, €125,000 or €150,000. Operating a trading platform puts you in the top class. If a quarter of your previous year's fixed overheads is higher, you hold that instead. The requirement can be met with own funds, an insurance policy, or a combination.
3. Governance and people
Members of the management body of good repute, with the knowledge, skills and experience to run the business.
Suitable shareholders with qualifying holdings.
Written policies and procedures, including business continuity and complaints handling.
Sound ICT systems and security. DORA, the EU's Digital Operational Resilience Act, has applied to authorised CASPs since 17 January 2025.
4. Client assets
Keep clients' crypto-assets segregated from your own, and never use them for your own account.
Place clients' funds (fiat) with a credit institution or a central bank, by the end of the business day after you receive them.
If you provide custody: a custody policy, a register of positions per client, and liability for losses of the crypto-assets you hold.
5. If you operate a trading platform
Clear, non-discretionary operating rules, published, covering admission of crypto-assets and of participants.
Due diligence on every crypto-asset before it is listed.
Pre- and post-trade transparency on prices and volumes.
Surveillance for market abuse, with suspicious orders and transactions reported to your authority.
No dealing on your own account on the platform you operate.
6. The rules beside MiCA
Anti-money laundering. CASPs are obliged entities under EU AML rules: customer due diligence, ongoing monitoring and reporting.
The travel rule. Under the Transfer of Funds Regulation ((EU) 2023/1113), information on the originator and beneficiary must travel with crypto-asset transfers. It has applied since 30 December 2024.
Operational resilience. DORA's requirements on ICT risk, incident reporting and testing, as above.
Marketing and disclosures. Communications to clients must be fair, clear and not misleading, with the information on costs and risks that MiCA requires.
What this means for the platform
None of these items is code, but almost all of them show up in it: segregated wallets and approval flows for custody, a ledger that reconciles every client balance, surveillance alerts on the order book, travel-rule data on every transfer, audit logs your authority can follow.
Our crypto exchange platform ships with the KYC/AML and compliance-reporting modules built in, and we configure it to match your authorisation.
This article is a general overview, not legal advice. Check the requirements for your services with your national competent authority and your counsel.

