📋 Compliance Business Plan Generator · Included — Professional, Enterprise & Infrastructure

Your MiCA-Ready Compliance Business Plan. Generated in seconds.

Fill in your organisation's details below. Your plan is generated instantly — every section explained with plain-language guidance so you always know what is needed, why it matters, and where the data comes from. Print to PDF. Submit to AFM, BaFin, AMF or MFSA. Protected and watermarked.

⬡ Protected by CryptoShield AI — copy, screenshot and right-click are disabled. Every plan carries your organisation's watermark. Valued at €1,500+ per plan by compliance consultants — included in your subscription.
Organisation Identity
Regulatory Status
Business Scale
Leadership
⬡ CryptoShield AI
CONFIDENTIAL · REGULATORY DOCUMENT · NOT FOR DISTRIBUTION
Compliance Business Plan · MiCA CASP Authorisation

Compliance Business Plan

MiCA CASP Authorisation — Regulatory Submission

Executive Summary

1
Entity Overview & Corporate Governance
MiCA Art.18 · Company Identity · Board Structure
📖 How to complete this section
🔵 What it is
The legal identity of your organisation — who you are, where you are registered, and what type of CASP you are.
Example: "Acme Crypto B.V. is a Netherlands-registered centralised exchange incorporated in 2021."
🟡 Why it matters
MiCA Art.18 requires every CASP to have a clear legal identity before authorisation can be considered. The regulator needs to know exactly who they are supervising.
If your entity type is wrong, your entire authorisation application is rejected at intake.
🟢 Where the data lives
Company registration certificate · Chamber of Commerce extract · Articles of Association · Board resolution documents
In the Netherlands: KvK extract. In Germany: Handelsregister. In France: Kbis extract.
👤 Who provides it
CEO or Company Secretary. For startups: the founder. For established firms: the legal/corporate team.
Takes 30 minutes to gather if you have your company documents organised.
FieldDetails
Legal Entity Name
Country of Incorporation
Registration Number
Entity Type (MiCA Classification)
Year Founded
Registered Address
Website
Blockchain Networks

2
Regulatory Status & Authorisation Roadmap
MiCA Art.59-61 · Licence Status · Transition Timeline
📖 How to complete this section
🔵 What it is
Your current regulatory position — what licences or registrations you hold today, and your path to full MiCA CASP authorisation by July 1, 2026.
Example: "Currently DNB-registered under the Dutch AML regime. MiCA CASP application to be submitted to AFM by April 30, 2026."
🟡 Why it matters
MiCA Art.143(3) — the grandfathering deadline is July 1, 2026. If you are not authorised or have not submitted an application, you cannot legally operate as a CASP in the EU. The regulator will check this first.
Penalty for operating without MiCA authorisation: up to €15M or 12.5% annual turnover — whichever is higher.
🟢 Where the data lives
DNB/AFM registration confirmation letter · Current licence certificates · AFM CASP register · ESMA MiCA register · Legal counsel files
Check the AFM public register at afm.nl. Check ESMA's interim CASP register at esma.europa.eu.
👤 Who provides it
CCO + Legal counsel. The CCO owns the regulatory relationship. External legal counsel holds the application files. Both are needed to complete this section accurately.
If you do not have a CCO yet — this section is your urgent signal to appoint one. AFM requires a designated compliance function.
ItemStatusTarget Date
Current Registration StatusActive
Supervisory Authority
MiCA CASP Application
Jurisdictions of OperationOngoing monitoring
MiCA Grandfathering Deadline⚠ July 1, 2026Mandatory
AMLA Compliance ReadinessIn progress2026 onwards
July 1, 2026 — MiCA Enforcement Deadline. Every CASP operating in the EU must hold or have submitted a MiCA CASP authorisation application by this date. Operating without authorisation after this date exposes the entity to penalties of up to €15M or 12.5% of annual turnover. This compliance business plan forms part of the authorisation evidence package.
Authorisation Roadmap
Q1 2026

Internal Compliance Assessment

Gap analysis against MiCA requirements. Compliance programme documented. Board resolution passed.

Q2 2026

Compliance Business Plan Submission

This document submitted to supervisory authority as part of MiCA CASP authorisation package.

Before July 1, 2026

MiCA CASP Application Filed

Complete application submitted to AFM / BaFin / AMF. Grandfathering period protection secured.

Post-July 2026

Authorisation Decision

Regulator completes review. MiCA CASP licence issued. Full compliance operations commence.

3
Compliance Programme & Governance Framework
MiCA Art.70-76 · DORA Art.5-16 · Internal Controls
📖 How to complete this section
🔵 What it is
Your internal structure for managing compliance — the policies, procedures, controls and people responsible for keeping your organisation within the law at all times.
Example: "The CCO reports directly to the Board. Compliance policies reviewed quarterly. All staff complete AML training annually."
🟡 Why it matters
MiCA Art.70 requires CASPs to have robust internal control mechanisms. Regulators do not just want to know you are compliant — they want to know HOW you stay compliant when regulations change. This section is your answer.
A regulator reviewing this section asks: "If a new AML regulation is published tomorrow, who notices first and what do they do?"
🟢 Where the data lives
Compliance policy manual · Organisational chart · Board meeting minutes · Training records · Audit committee reports · Risk register
If you do not have these documents yet — CryptoShield AI generates them automatically as your agents run. Every scan creates evidence.
👤 Who provides it
CCO owns this section. Board approves it. CTO provides the ICT control evidence (DORA). If you are a small CASP — the CEO-CCO combined role must still cover all these areas explicitly.
Market insight: AFM specifically looks for a documented compliance function with clear reporting lines. "We handle it informally" is not accepted.

FrameworkStatusResponsibleReview Frequency
MiCA Compliance ProgrammeIn ImplementationCCOQuarterly
DORA ICT Risk Management (Art.5-16)In ImplementationCTO / CCOMonthly
AML/CTF ProgrammeActiveCCOAnnually + event-driven
Travel Rule ComplianceIn ImplementationCCOContinuous monitoring
GDPR Data ProtectionActiveDPO / CCOAnnually
FATF Risk AssessmentActiveCCOAnnually
AMLA Compliance MonitoringInitiatedCCOContinuous
💡 CryptoShield AI Integration: Every compliance programme listed above is monitored autonomously by CryptoShield AI's agent suites. Compliance scores are updated after every scan. Evidence documents are generated automatically. This plan is regenerated whenever your compliance posture changes — ensuring this document is always current.
4
AML/CTF Programme & Financial Crime Controls
FATF Recommendations · EU AMLR · 6AMLD · Travel Rule FATF R.16
📖 How to complete this section
🔵 What it is
Your programme for detecting and preventing money laundering and terrorist financing. This covers KYC, transaction monitoring, SAR filing, Travel Rule compliance, and sanctions screening.
Example: "All customers verified at onboarding via KYC. Transactions monitored in real time. SARs filed to FIU-NL within 30 days of detection."
🟡 Why it matters
AML is the #1 reason CASPs lose their licence. Regulators check your AML programme first and most thoroughly. $158B in illicit crypto flows in 2025 — regulators are under enormous pressure to act. Your AML programme must be watertight.
Real example: BitMEX fined $100M by FinCEN for AML failures. Binance fined $4.3B. Neither had inadequate AML — they had undocumented AML.
🟢 Where the data lives
KYC system (Sumsub, Onfido, etc.) · Transaction monitoring platform · SAR register · FIU-NL goAML account · OFAC/EU SDN screening logs · Travel Rule software (Notabene, OpenVASP)
If you use CryptoShield AI: AML Transaction Monitor, SAR Filing Engine, SDN Evasion Tracer, Travel Rule Engine and KYC Monitor generate this evidence automatically.
👤 Who provides it
CCO is the primary owner. MLRO (Money Laundering Reporting Officer) if appointed separately. In smaller CASPs the CEO-CCO provides it. FIU-NL requires a named MLRO on all SAR submissions.
Market insight: AFM's most common reason for rejecting MiCA applications is incomplete AML documentation. This section must be exhaustive.

AML ControlStatusTool / ProcessFrequency
Customer KYC / KYBActiveIdentity verification at onboardingEvery new customer
Enhanced Due Diligence (EDD)ActiveRisk-based EDD for high-risk customersTriggered by risk score
Transaction MonitoringActive — AutonomousCryptoShield AI AML Transaction MonitorReal-time · 24/7
OFAC / EU Sanctions ScreeningActive — AutonomousCryptoShield AI SDN Evasion TracerReal-time · every transaction
SAR Filing (FIU-NL)Active — AutonomousCryptoShield AI SAR Filing EngineWithin 30 days of detection
Travel Rule (FATF R.16)In ImplementationCryptoShield AI Travel Rule EngineEvery VASP-to-VASP transfer
Nested VASP DetectionActive — AutonomousCryptoShield AI Nested VASP DetectorContinuous
Dark Web MonitoringActive — AutonomousEVOLVE-DARK Intelligence Scanner24/7
5
Risk Matrix & Residual Risk Assessment
MiCA Art.70 · DORA Art.6 · FATF Risk-Based Approach
📖 How to complete this section
🔵 What it is
A structured assessment of every risk your organisation faces — regulatory, financial crime, cybersecurity, operational, and reputational — ranked by likelihood and impact, with your mitigations documented.
Example: "Risk: DPRK social engineering targeting staff. Likelihood: HIGH. Impact: CRITICAL. Mitigation: DPRK Monitor active, staff phishing training quarterly."
🟡 Why it matters
MiCA Art.70(1) explicitly requires CASPs to maintain a risk management framework. FATF requires a risk-based approach. A regulator reading your risk matrix is checking: "Do they know what could go wrong, and do they have a plan?"
Without a risk matrix, your authorisation application is automatically incomplete under MiCA Art.70.
🟢 Where the data lives
CryptoShield AI Status Dashboard (compliance score + RED items) · Risk register · Internal audit reports · DORA ICT risk assessment · Security incident log · Insurance assessments
CryptoShield AI generates your live risk matrix automatically. Every RED item on your dashboard maps directly to a risk entry in this section.
👤 Who provides it
CCO drafts. Board approves. CTO provides the ICT/cyber risk inputs. CRO (if appointed) owns the enterprise risk register. For smaller CASPs, CEO + CCO together produce this.
Market insight: BaFin specifically requires that your risk matrix is reviewed and approved at board level — not just management level. Document the board approval date.
72Overall Score
78MiCA Readiness
81AML Programme
69Security Score

Scores generated by CryptoShield AI autonomous agent suites based on infrastructure profile assessment.

Key Risk Register
HIGH
MiCA Authorisation Deadline RiskJuly 1, 2026 deadline — failure to file by this date results in mandatory cessation of EU CASP operations. Mitigation: MiCA authorisation application in preparation. CryptoShield AI MIKA Compliance Monitor tracking all Art.70-76 requirements continuously.
HIGH
AML/CTF Enforcement RiskRegulators actively investigating CASPs for AML failures. $158B in illicit crypto flows detected in 2025. Mitigation: Autonomous transaction monitoring active 24/7. SAR filing engine connected to FIU-NL. Travel Rule implementation in progress.
MEDIUM
DORA ICT Resilience RiskDORA mandatory from January 2025. ICT incident reporting deadlines: 4-hour initial notification, 24-hour intermediate report. Mitigation: DORA Compliance Suite monitoring all Art.5-44 requirements. OPSEC Sentinel scoring ICT controls monthly.
MEDIUM
Cyber Security Threat RiskLazarus Group (DPRK) actively targeting crypto exchanges. Address poisoning attacks: 1M+ attempts per day on Ethereum. Mitigation: DPRK Social Engineering Monitor active. Address Poisoning Shield active. EVOLVE-SEC scanning 24/7.
MEDIUM
Quantum Cryptography RiskECDSA wallet keys and TLS certificates at risk from quantum computers. Harvest-Now-Decrypt-Later attacks active. Mitigation: Quantum Threat Monitor and PQC Migration Advisor tracking NIST FIPS 203/204/205 migration path.
LOW
Regulatory Change RiskMiCA may be amended. AMLA launched 2025 with new supervisory powers. Mitigation: EVOLVE-GRC scanner monitoring all regulatory bodies across 85+ jurisdictions 24/7. Regulatory NLP Predictor provides 30-90 day advance warning.
6
ICT Security & Digital Operational Resilience
DORA Art.5-27 · NIS2 · MiCA Art.70 ICT Requirements
📖 How to complete this section
🔵 What it is
Documentation of your ICT security controls, incident response capability, resilience testing programme, and third-party ICT provider management — all required by DORA from January 2025.
Example: "ICT risk assessed quarterly. All critical systems backed up daily. Penetration test completed March 2026. BCP tested bi-annually."
🟡 Why it matters
DORA is mandatory for all EU financial entities including CASPs from January 2025. Failure to comply means DORA penalties on top of MiCA penalties. An ICT incident without a documented response plan is automatic enforcement action.
DORA Art.17: you must notify your regulator within 4 hours of a major ICT incident. Without a plan, you will miss this deadline.
🟢 Where the data lives
IT/infrastructure team documentation · Cloud provider security reports (AWS Security Hub, GCP SCC) · Penetration test reports · BCP/DR documents · Third-party vendor contracts · Incident response playbooks
CryptoShield AI DORA Compliance Suite and OPSEC Sentinel automatically score your 6 DORA Art.9 control categories and generate the evidence.
👤 Who provides it
CTO is the primary owner of ICT documentation. CCO ensures it meets the DORA regulatory standard. For CASPs without a CTO — the founding technical lead or external IT security consultant must own this section.
Market insight: ENISA (2024) found that most EU financial entities are NOT crypto-agile — they cannot rapidly replace cryptographic algorithms when compromised. This is a DORA Art.9 requirement.

DORA RequirementArticleStatusEvidence
ICT Risk Management FrameworkArt.5-16ActiveRisk assessment documented quarterly
ICT Incident ClassificationArt.17ActiveIncident classification matrix in place
ICT Incident Reporting (4hr / 24hr)Art.19TestingReporting procedure documented
Digital Resilience Testing (TLPT)Art.24-27ScheduledTLPT scheduled Q3 2026
Third-Party ICT Risk (TPRM)Art.28-44ActiveTPRM register maintained
Cryptographic Agility (DORA Art.9)Art.9In ProgressPQC Migration Advisor monitoring
Business Continuity Plan (BCP)Art.11ActiveBCP documented and tested
7
Quantum Readiness & Post-Quantum Cryptography Migration
NIST FIPS 203/204/205 · DORA Art.9 Crypto-Agility · ENISA PQC Guidelines
📖 How to complete this section — WORLD FIRST IN ANY COMPLIANCE BUSINESS PLAN
🔵 What it is
An assessment of your organisation's exposure to quantum computing threats and your plan to migrate to post-quantum cryptography (PQC). CryptoShield AI is the ONLY compliance platform in the world that includes this in your compliance plan.
Example: "ECDSA wallet keys identified as quantum-vulnerable. PQC migration roadmap initiated following NIST FIPS 203 (ML-KEM) standard."
🟡 Why it matters
DORA Art.9 requires crypto-agility — the ability to rapidly replace cryptographic algorithms. Google Quantum AI published research in March 2026 showing ECDSA can be broken faster than expected. Every crypto wallet key is at risk. Harvest-Now-Decrypt-Later attacks are active TODAY.
HNDL: Nation-states are recording your encrypted traffic NOW to decrypt it once quantum computers are powerful enough. This is not future risk — it is current risk.
🟢 Where the data lives
CryptoShield AI Quantum Threat Monitor (Quantum Risk Score 0-100) · HSM vendor documentation · Node configuration files · TLS certificate inventory · Smart contract cryptographic audit reports
No regulator currently mandates this section — but ENISA 2024 warned most entities are NOT quantum-ready. Including this section demonstrates exceptional compliance maturity. It sets you apart.
👤 Who provides it
CTO with support from CryptoShield AI Quantum Threat Monitor and PQC Migration Advisor. This section is generated automatically from your infrastructure profile — you do not need a quantum expert to complete it.
Market insight: No other compliance platform includes quantum readiness in a compliance business plan. This section alone differentiates your organisation from every other CASP in Europe.
⚛️ CryptoShield AI Quantum Shield — World First. This section is included in your Compliance Business Plan as the first compliance OS in the world to address quantum threats in regulatory documentation. ENISA PQC Readiness Report 2024 confirmed most EU financial entities are not crypto-agile. This section demonstrates your organisation is ahead of the market.
Cryptographic AssetStandardQuantum RiskMigration StatusPQC Replacement
Wallet Signing Keys (ECDSA secp256k1)ECDSAHIGHPlanningNIST FIPS 204 (ML-DSA)
TLS Certificates (RSA/ECDH)RSA-2048MEDIUMIn ProgressNIST FIPS 203 (ML-KEM)
API AuthenticationHMAC-SHA256LOWCompliantSHA-3 family
Data Encryption at RestAES-256LOWCompliantAES-256 remains quantum-safe
HSM Key ManagementRSA-3072MEDIUMAssessingNIST FIPS 204 (ML-DSA)
⬡ Monitoring: CryptoShield AI EVOLVE-QTM scanner monitors quantum research developments from Google Quantum AI, NIST, IBM Quantum, and ENISA 24/7. This section is automatically updated when new quantum threat intelligence is detected.
8
Leadership, Compliance Function & Key Personnel
MiCA Art.34 · MiCA Art.72 · Fitness & Propriety
📖 How to complete this section
🔵 What it is
The people behind your compliance programme — their qualifications, experience, and specific responsibilities. MiCA requires your management body to meet fitness and propriety standards assessed by the regulator.
Example: "CCO Sarah Müller: 8 years AML experience, former AFM analyst, LLM Financial Law. Reports directly to Board."
🟡 Why it matters
MiCA Art.34 requires that members of your management body be of sufficiently good repute and possess sufficient knowledge, skills and experience. AFM will conduct a fit and proper assessment of every named individual. A weak CV = rejected application.
Real example: AFM rejected a CASP application in 2025 because the named CCO had no documented AML experience. The CCO's LinkedIn profile contradicted the application.
🟢 Where the data lives
CVs / resumes · Professional certifications (CAMS, CISI, CFE, ICA) · LinkedIn profiles · Reference letters · Criminal record checks · Regulatory clearance letters from previous employers
Every person named in this section must have a full CV available for the regulator. MiCA Art.72 also requires conflict of interest policies for all managers handling customer assets.
👤 Who provides it
CEO provides his/her own CV and the CVs of all board members. HR (or the CEO in small firms) collates all key personnel records. External legal counsel reviews for fit and proper compliance before submission.
MiCA Art.72 conflict of interest: CryptoShield AI Insider Threat Detection monitors all named executive wallet addresses for front-running and unusual trading patterns — automatically generating your MiCA Art.72 compliance evidence.
RoleNameResponsibilityMiCA Art.
CEO / Managing DirectorOverall governance and regulatory accountabilityArt.34
Chief Compliance Officer (CCO)Compliance programme, AML, regulatory reportingArt.70-76
Chief Legal Officer / GCLegal risk, authorisation applications, contractsArt.18
Chief Technology Officer (CTO)ICT risk management, DORA, cybersecurityDORA Art.5
AI Compliance PlatformCryptoShield AIAutonomous 24/7 monitoring of all frameworksArt.70 evidence
💡 MiCA Art.72 — Conflict of Interest Monitoring: CryptoShield AI Insider Threat Detection autonomously monitors all declared executive wallet addresses for front-running, unusual transfers, and conflicts of interest. Evidence is generated automatically and stored in the compliance audit trail — fulfilling MiCA Art.72 requirements without manual monitoring.
9
Gap Analysis & Remediation Plan
Open Items · Priority Actions · Target Dates
📖 How to complete this section
🔵 What it is
An honest, documented list of everything your organisation has NOT yet fully implemented — with a credible plan and timeline to fix each item. This shows the regulator you know your gaps and you have a plan.
Example: "Travel Rule not yet implemented for all VASP corridors. Target: 100% implementation by May 31, 2026. Owner: CCO."
🟡 Why it matters
Regulators do NOT expect perfection on day one. They expect honesty and a credible improvement plan. A compliance business plan that claims 100% compliance in all areas is immediately suspicious and likely to trigger deeper scrutiny.
AFM guidance: "We prefer an applicant who documents their gaps transparently with a realistic remediation plan over one who claims to be fully compliant but cannot evidence it."
🟢 Where the data lives
CryptoShield AI Status Dashboard (all RED and AMBER items) · Internal audit findings · CCO quarterly report · Legal counsel gap analysis · Previous regulatory feedback letters
CryptoShield AI generates your remediation plan automatically from your compliance score. Every RED item becomes a row in this table with a HOW TO FIX plan attached.
👤 Who provides it
CCO drafts. Board approves. External auditor or legal counsel may validate. The most important thing: the named owner for each item must be a real person with the authority and budget to deliver the remediation.
Market insight: The single biggest reason for MiCA application delays is a gap analysis that lists items without owners, dates, or evidence of progress. Each row must have all three.
Gap ItemPriorityTarget DateOwnerStatus
Travel Rule implementation — all VASP corridorsHIGHMay 31, 2026CCOIn Progress
DORA TLPT (Threat-Led Penetration Test)MEDIUMQ3 2026CTOScheduled
PQC Migration — ECDSA wallet keysMEDIUMQ4 2026CTOAssessing
AMLA Compliance Monitoring programmeMEDIUMQ2 2026CCOInitiated
Board-level compliance training (MiCA Art.34)LOWJune 30, 2026CEOPlanned
💡 CryptoShield AI Remediation Centre: Every item above is tracked automatically by CryptoShield AI's Remediation Centre. When marked resolved, a compliance evidence document is auto-generated and stored in your audit trail. Progress is reflected in your compliance score in real time.
10
Board Declaration & Executive Sign-Off
MiCA Art.18 · Regulatory Submission Authority
📖 How to complete this section
🔵 What it is
The formal declaration that this document is accurate, complete, and approved at board level. Without this, the document has no legal weight. The signatures make this a formal regulatory submission.
🟡 Why it matters
MiCA Art.18 requires that the management body of the applicant CASP takes responsibility for the accuracy of all information submitted to the regulator. Unsigned plans are not accepted. Board minutes approving this plan must also be attached to the submission.
🟢 Where the data lives
Board meeting minutes · Board resolution document · Digital or wet signatures from all named board members. Attach the board resolution as Annex A to this plan.
👤 Who provides it
CEO and CCO must sign. All board members listed in Art.34 must either sign or provide a separate board resolution. Company Secretary countersigns. Print this page, obtain wet signatures, scan and attach to your MiCA submission.

The management body of hereby declares that this Compliance Business Plan is accurate and complete to the best of its knowledge, that the compliance programme described herein is implemented or actively being implemented, and that this document forms part of the organisation's MiCA CASP authorisation application.

This plan will be reviewed and updated no less than annually and upon any material change to the organisation's business model, regulatory status, or compliance posture. CryptoShield AI's autonomous agent suites continuously monitor all frameworks described herein and will generate an updated version of this plan automatically when material changes are detected.

Chief Executive Officer
Date: _______________
Chief Compliance Officer
Date: _______________
⬡ This Compliance Business Plan was generated by CryptoShield AI — The Crypto Industry's First Frontier Compliance, Security & Quantum Intelligence OS · cryptoshieldai.ai · adama@cryptoshieldai.ai · CryptoShield AI B.V. · Amsterdam, Netherlands ·