Fill in your organisation's details below. Your plan is generated instantly — every section explained with plain-language guidance so you always know what is needed, why it matters, and where the data comes from. Print to PDF. Submit to AFM, BaFin, AMF or MFSA. Protected and watermarked.
MiCA CASP Authorisation — Regulatory Submission
—
| Field | Details |
|---|---|
| Legal Entity Name | — |
| Country of Incorporation | — |
| Registration Number | — |
| Entity Type (MiCA Classification) | — |
| Year Founded | — |
| Registered Address | — |
| Website | — |
| Blockchain Networks | — |
—
| Item | Status | Target Date |
|---|---|---|
| Current Registration Status | — | Active |
| Supervisory Authority | — | — |
| MiCA CASP Application | — | — |
| Jurisdictions of Operation | — | Ongoing monitoring |
| MiCA Grandfathering Deadline | ⚠ July 1, 2026 | Mandatory |
| AMLA Compliance Readiness | In progress | 2026 onwards |
Gap analysis against MiCA requirements. Compliance programme documented. Board resolution passed.
This document submitted to supervisory authority as part of MiCA CASP authorisation package.
Complete application submitted to AFM / BaFin / AMF. Grandfathering period protection secured.
Regulator completes review. MiCA CASP licence issued. Full compliance operations commence.
—
| Framework | Status | Responsible | Review Frequency |
|---|---|---|---|
| MiCA Compliance Programme | In Implementation | CCO | Quarterly |
| DORA ICT Risk Management (Art.5-16) | In Implementation | CTO / CCO | Monthly |
| AML/CTF Programme | Active | CCO | Annually + event-driven |
| Travel Rule Compliance | In Implementation | CCO | Continuous monitoring |
| GDPR Data Protection | Active | DPO / CCO | Annually |
| FATF Risk Assessment | Active | CCO | Annually |
| AMLA Compliance Monitoring | Initiated | CCO | Continuous |
—
| AML Control | Status | Tool / Process | Frequency |
|---|---|---|---|
| Customer KYC / KYB | Active | Identity verification at onboarding | Every new customer |
| Enhanced Due Diligence (EDD) | Active | Risk-based EDD for high-risk customers | Triggered by risk score |
| Transaction Monitoring | Active — Autonomous | CryptoShield AI AML Transaction Monitor | Real-time · 24/7 |
| OFAC / EU Sanctions Screening | Active — Autonomous | CryptoShield AI SDN Evasion Tracer | Real-time · every transaction |
| SAR Filing (FIU-NL) | Active — Autonomous | CryptoShield AI SAR Filing Engine | Within 30 days of detection |
| Travel Rule (FATF R.16) | In Implementation | CryptoShield AI Travel Rule Engine | Every VASP-to-VASP transfer |
| Nested VASP Detection | Active — Autonomous | CryptoShield AI Nested VASP Detector | Continuous |
| Dark Web Monitoring | Active — Autonomous | EVOLVE-DARK Intelligence Scanner | 24/7 |
Scores generated by CryptoShield AI autonomous agent suites based on infrastructure profile assessment.
Key Risk Register—
| DORA Requirement | Article | Status | Evidence |
|---|---|---|---|
| ICT Risk Management Framework | Art.5-16 | Active | Risk assessment documented quarterly |
| ICT Incident Classification | Art.17 | Active | Incident classification matrix in place |
| ICT Incident Reporting (4hr / 24hr) | Art.19 | Testing | Reporting procedure documented |
| Digital Resilience Testing (TLPT) | Art.24-27 | Scheduled | TLPT scheduled Q3 2026 |
| Third-Party ICT Risk (TPRM) | Art.28-44 | Active | TPRM register maintained |
| Cryptographic Agility (DORA Art.9) | Art.9 | In Progress | PQC Migration Advisor monitoring |
| Business Continuity Plan (BCP) | Art.11 | Active | BCP documented and tested |
| Cryptographic Asset | Standard | Quantum Risk | Migration Status | PQC Replacement |
|---|---|---|---|---|
| Wallet Signing Keys (ECDSA secp256k1) | ECDSA | HIGH | Planning | NIST FIPS 204 (ML-DSA) |
| TLS Certificates (RSA/ECDH) | RSA-2048 | MEDIUM | In Progress | NIST FIPS 203 (ML-KEM) |
| API Authentication | HMAC-SHA256 | LOW | Compliant | SHA-3 family |
| Data Encryption at Rest | AES-256 | LOW | Compliant | AES-256 remains quantum-safe |
| HSM Key Management | RSA-3072 | MEDIUM | Assessing | NIST FIPS 204 (ML-DSA) |
| Role | Name | Responsibility | MiCA Art. |
|---|---|---|---|
| CEO / Managing Director | — | Overall governance and regulatory accountability | Art.34 |
| Chief Compliance Officer (CCO) | — | Compliance programme, AML, regulatory reporting | Art.70-76 |
| Chief Legal Officer / GC | — | Legal risk, authorisation applications, contracts | Art.18 |
| Chief Technology Officer (CTO) | — | ICT risk management, DORA, cybersecurity | DORA Art.5 |
| AI Compliance Platform | CryptoShield AI | Autonomous 24/7 monitoring of all frameworks | Art.70 evidence |
| Gap Item | Priority | Target Date | Owner | Status |
|---|---|---|---|---|
| Travel Rule implementation — all VASP corridors | HIGH | May 31, 2026 | CCO | In Progress |
| DORA TLPT (Threat-Led Penetration Test) | MEDIUM | Q3 2026 | CTO | Scheduled |
| PQC Migration — ECDSA wallet keys | MEDIUM | Q4 2026 | CTO | Assessing |
| AMLA Compliance Monitoring programme | MEDIUM | Q2 2026 | CCO | Initiated |
| Board-level compliance training (MiCA Art.34) | LOW | June 30, 2026 | CEO | Planned |
The management body of — hereby declares that this Compliance Business Plan is accurate and complete to the best of its knowledge, that the compliance programme described herein is implemented or actively being implemented, and that this document forms part of the organisation's MiCA CASP authorisation application.
This plan will be reviewed and updated no less than annually and upon any material change to the organisation's business model, regulatory status, or compliance posture. CryptoShield AI's autonomous agent suites continuously monitor all frameworks described herein and will generate an updated version of this plan automatically when material changes are detected.