All frameworks

Markets in Crypto-Assets Regulation

MiCA readiness assessment

Evidence your MiCA obligations before the competent authority asks.

Obligation libraries (45) for both token issuers and crypto-asset service providers (CASPs).

45 obligation entries · versioned & change-controlled

Who it’s for

Crypto-asset token issuers and crypto-asset service providers (CASPs) preparing for MiCA obligations in the EU.

What readiness means for MiCA

For MiCA, readiness means the issuer and/or CASP obligations relevant to your scope are evidenced — white paper, governance, prudential safeguards, complaints handling and custody controls.

How Netallion handles it

Your MiCA readiness journey

  1. 1

    Scope role & obligations

    Determine whether you are a token issuer, a crypto-asset service provider (CASP), or both, and scope only the issuer and/or CASP obligations relevant to your activity.

  2. 2

    Map evidence to obligations

    Attach the white paper, governance arrangements, safeguarding records and complaints procedures to the obligations they support, with ownership and review dates.

  3. 3

    Assess evidence

    Each obligation is assessed for whether the evidence substantiates it — prudential safeguards actually held, the required competent-authority notification made — not merely a drafted document.

  4. 4

    Surface blockers

    Obligations with missing or stale evidence — an unevidenced notification, an unsegregated client-asset arrangement — become explicit, ranked blockers.

  5. 5

    Review & finalise

    An authorised assessor reviews the determinations and pins a readiness conclusion; MiCA authorisation is granted by the national competent authority, not by Netallion.

The control library

What the MiCA library gives you

Obligation libraries (45) for both token issuers and crypto-asset service providers (CASPs).

A curated, versioned catalogue of this framework’s 45 obligation entries — with provenance — to collect, own, organise and track the currency of your evidence against.

From the field

Common MiCA blockers we find

Where evidence most often falls short — surfaced explicitly, not averaged away.

  • A white paper is drafted but the required competent-authority notification is unevidenced, so the issuer step is incomplete.
  • A CASP holds client crypto-assets but there is no evidence of segregation from the firm's own assets.
  • Governance arrangements name responsible persons but the fit-and-proper evidence for them is missing.
  • A complaints procedure is published but there is no log demonstrating complaints are actually handled and closed.

Evidence

The evidence you'll bring

You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:

Issuer obligations

  • white paper
  • competent-authority notification records
  • marketing-communications controls
  • reserve-of-assets arrangements (where applicable)

CASP obligations

  • authorisation application evidence
  • programme of operations
  • conflict-of-interest policy
  • market-abuse detection arrangements

Governance & safeguards

  • governance & fit-and-proper records
  • prudential-safeguard / own-funds evidence
  • business-continuity arrangements
  • outsourcing controls

Custody & complaints

  • client-asset segregation & custody controls
  • safeguarding reconciliations
  • complaints-handling procedure & log
  • record-keeping evidence

Start now — free

Prepare your MiCA evidence

Assess your MiCA evidence with Netallion

There’s no self-serve kit for MiCA yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.

From evidence to a conclusion

How readiness is reached

The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you get out

  • Requirement-level readiness across the 45 MiCA obligations scoped to your issuer/CASP role
  • separate issuer and CASP obligation views
  • explicit blocker list with reasons
  • evidence index + audit ZIP with SHA-256 manifest

FAQ

MiCA readiness — common questions

Does Netallion grant MiCA authorisation?

No. MiCA authorisation or registration is granted by the relevant national competent authority. Netallion assesses your readiness against the applicable issuer and CASP obligations.

Do you cover both issuers and CASPs?

Yes — Netallion maintains obligation libraries for both, and scopes an engagement to the obligations relevant to your activity (45 obligations across both).

How does MiCA relate to DORA?

Many crypto-asset service providers are also in scope for DORA's operational-resilience requirements; the two are commonly assessed together.

Related

Cross-framework leverage

Evidence you assemble for one framework often supports another. Commonly paired with:

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. MiCA authorisation or registration is granted by the relevant national competent authority, not by any assessor. Where the boundary sits.

See what your MiCA evidence proves

See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.