MiCA, the Markets in Crypto-Assets Regulation, is the European Union's harmonised framework for crypto-asset issuance and services. It replaced a patchwork of national approaches with a single set of rules that apply, largely uniformly, across every EU member state. If your business touches crypto and has any connection to EU customers, understanding MiCA's shape is the starting point for everything else.
1. What MiCA actually is
MiCA is a regulation, not a directive, which means it applies directly in EU member states rather than requiring each country to transpose it into national law separately. That's a deliberate design choice: it's meant to give crypto-asset businesses one set of rules to build against, rather than 27 slightly different national regimes.
2. Who MiCA applies to
MiCA defines a set of regulated categories:
- Crypto-Asset Service Providers (CASPs) | exchanges, custodians, brokers, portfolio managers and advisory services dealing in crypto-assets
- Asset-Referenced Token (ART) issuers | tokens referencing a basket of assets, currencies or commodities
- E-Money Token (EMT) issuers | tokens referencing a single fiat currency, functioning similarly to stablecoins
- Issuers of other crypto-assets not falling into the categories above, subject to lighter-touch disclosure obligations
Businesses offering more than one of these activities (for example, an exchange that also issues its own token) need to satisfy the requirements attached to each category they fall into.
3. What MiCA requires
The specific obligations vary by category, but common threads include:
- Formal authorisation from a national competent authority before operating
- Governance and fit-and-proper requirements for key function holders
- A documented AML/CTF programme, sitting alongside MiCA's own requirements rather than replacing existing AML law
- Capital and prudential safeguards, particularly for token issuers
- Consumer protection measures, including clear disclosure and complaint-handling procedures
- Market abuse prevention, including rules on insider dealing and market manipulation involving crypto-assets
- Ongoing reporting to the relevant national authority
4. Passporting: MiCA's central trade-off
Once authorised in one EU member state, a CASP can generally passport its services to operate across the rest of the EU without needing separate authorisation in each country. This is the core exchange MiCA offers: more upfront prescription and documentation, in return for single-market access rather than 27 separate licensing processes.
5. What falls outside MiCA
MiCA generally excludes crypto-assets that are unique and non-fungible, which covers most NFTs, along with certain fully decentralised services with no identifiable intermediary. These exclusions are interpreted narrowly, however | an NFT collection with fungible characteristics, or a nominally decentralised protocol with an identifiable operating entity, may still fall in scope. This is an area worth getting a specific read on rather than assuming based on the product label alone.
6. MiCA alongside other frameworks
MiCA doesn't operate in isolation. CASPs authorised under MiCA are also within scope of the Digital Operational Resilience Act (DORA) for ICT risk management, and remain subject to the EU's existing AML/CTF legislation. A MiCA-authorised business needs governance that holds all three frameworks together consistently, not three separate documentation trails.
The bottom line
MiCA gives crypto-asset businesses a clearer, more harmonised path into the EU market than existed before | but that clarity comes with real prescriptive requirements around governance, capital, disclosure and AML/CTF. Businesses that treat the authorisation file as seriously as the product itself tend to move through the process fastest, and tend to have fewer surprises once they're operating under supervision.