MiCAFinancialEuropean UnionCrypto / Web3 / Digital Assets

EU Markets in Crypto-Assets Regulation

EU regulation establishing uniform rules for crypto-asset service providers. Effective 2024, requires comprehensive audit trails for distributed ledger operations.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

MiCAArticle 68Retention and availability

Record Keeping

Crypto-asset service providers MUST keep records of all services, orders, and transactions for 5 years.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

MiCAArticle 76Patching, hardening, and exposureA record of access

Custody Safeguards

Custodians MUST maintain audit trails for wallet-custody databases with complete transaction history.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

MiCAArticle 78A record of access

Transfer Traceability

REQUIRES complete traceability of crypto-asset transfers including originator and beneficiary information.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

MiCAArticle 83Continuity of the record

Operational Resilience

Providers MUST implement systems to ensure business continuity and access to transaction records.

A continuity requirement asks two different things, and only one of them is a database control. The recovery plan, the failover drill, and the tested restore are yours. What is produced here is the evidence layer under them: backups and exports are hashed and baselined alongside the datafiles, so a backup that was silently truncated, moved, or never written is evident rather than discovered at the restore. Audit events land in columnar storage on immutable object storage with a verification hash per record, so the history survives the incident that made you need it and is still queryable in seconds afterwards. Collection failure is itself an alerting condition, which is what evidences that the record was continuous rather than merely intended to be.

What MiCA covers

This instrument defines no data category of its own. Regulates crypto-asset SERVICES and the entities providing them. The regulated object is the activity and the authorisation, not a data class.

How MiCA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by National competent authorities, with EBA and ESMA supervision for significant issuers.

Published maximumChargedAs at
EUR 5 million or 3% of turnovera published minimum maximum; tiers differ by infringement and by Member State transposition2026-08

MiCA sets minimum maximums and requires Member States to legislate the rest, so the tiers differ by infringement type and by country. Published summaries disagree with each other for exactly that reason. The reliable statement is that the ceilings are turnover-linked, that they reach the management body as well as the firm, and that the authorising national regulator is the one to ask.

Because the tiers are set nationally, a single headline figure would be wrong somewhere. Check the transposition in your authorising Member State.

Uncapped exposure that sits outside this instrument

These come from company law rather than from MiCA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for MiCA,
not configured for it afterwards

Policy Template

Crypto Transaction Monitoring

Track all distributed ledger entry points and wallet operations

Report

MiCA Compliance Report

5-year transaction history with complete audit trail

Classification

Crypto Asset Patterns

Identify wallet addresses, transaction hashes, and digital asset data

Alert

Suspicious Transaction Detection

Alert on unusual crypto-asset movements

Other Financial frameworks

Walk into the MiCA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment