NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
MiCA Compliance Cost After 1 July 2026
Learn

MiCA Compliance Cost After 1 July 2026

·Alexander Sverdlov

The Markets in Crypto-Assets Regulation puts exactly one price in the text. Annex IV sets permanent minimum capital for a crypto-asset service provider at EUR 50 000, EUR 125 000 or EUR 150 000 depending on the class of services, and Article 35 sets EUR 350 000 as the floor for an issuer of asset-referenced tokens. Every other number you will read about MiCA compliance is a firm-specific estimate, including the application fee, because MiCA does not set one.

The date on this page matters. The transitional regime in Article 143(3) let crypto-asset service providers operating lawfully before 30 December 2024 continue until 1 July 2026 or until authorisation was granted or refused, whichever came sooner. That window has closed, and with it the simplified procedure Member States could offer under Article 143(6). Anyone budgeting now is budgeting for a full application under Articles 62 and 63.

Cost lineWhat sets itSource
Permanent minimum capitalEUR 50 000 class 1, EUR 125 000 class 2, EUR 150 000 class 3, by service.Annex IV, Art. 67(1)(a)
The fixed overheads testOne quarter of the preceding year's fixed overheads, if that is higher.Art. 67(1)(b) and (3)
Issuer own fundsEUR 350 000, or 2% of the average reserve of assets, or a quarter of fixed overheads. Highest wins.Art. 35(1)
Application feeSet nationally by your home competent authority. MiCA sets no figure.Not in the Regulation
Build and recurringGovernance, ICT, segregation, complaints, AML, supervision, audit, DORA.Arts. 62, 66 to 70; DORA Art. 2(1)(f)
MiCA permanent minimum capital by crypto-asset service provider class under Annex IV, and the asset referenced token issuer floor under Article 35

What does MiCA compliance cost?

Honestly, nobody can quote you a total, and the pages that do are quoting one firm's programme without saying so. What can be stated exactly is the floor the Regulation imposes, and the structure of everything above it.

The floor is the capital figure. Class 1, covering execution of orders, placing, transfer services, reception and transmission of orders, advice and portfolio management, is EUR 50 000. Class 2 adds custody and administration on behalf of clients and the two exchange services, and is EUR 125 000. Class 3 adds operation of a trading platform, and is EUR 150 000. Those are permanent minimum capital requirements, not one-off fees, and Article 67(1) requires them at all times.

Above the floor, the honest framing is that MiCA prices four things and only prices the first of them in euros: the capital you must hold, the fee your home authority charges, the build you have to complete before you can file, and what supervision costs you every year afterwards.

What does the Regulation actually price?

Article 67(1) requires prudential safeguards equal to at least the higher of the Annex IV amount and one quarter of the fixed overheads of the preceding year. That second limb is the one most cost articles skip, and it is arithmetic you can do today.

A quarter of fixed overheads overtakes the Annex IV floor once annual fixed overheads pass EUR 200 000 for a class 1 provider, EUR 500 000 for class 2 and EUR 600 000 for class 3. Any crypto-asset service provider with a real payroll is therefore bound by the overheads test rather than by the headline capital figure, and the number rises with the business. Article 67(3) defines the calculation, subtracting profit-dependent bonuses, profit shares, fully discretionary variable remuneration and non-recurring expenses from non-ordinary activities in the most recent audited statements. A firm that has not been in business a year uses the projected fixed overheads submitted with its application.

One relief is worth knowing before you raise capital. Article 67(4) allows the prudential safeguards to be met by own funds, by an insurance policy covering the Union territories where services are provided or a comparable guarantee, or by a combination of the two. The insurance route has conditions in Article 67(5), starting with an initial term of not less than one year, and it converts a balance sheet requirement into a premium.

For issuers, Article 35(1) sets own funds for asset-referenced token issuers at the highest of EUR 350 000, 2% of the average amount of the reserve of assets, and a quarter of the preceding year's fixed overheads. The 2% limb only overtakes the EUR 350 000 floor once the reserve passes EUR 17 500 000. Article 35(3) lets the home competent authority require up to 20% more than the reserve-based figure where its assessment shows a higher degree of risk. E-money token issuers come at it differently: Article 48(1) requires the issuer to be authorised as a credit institution or an electronic money institution, and Article 4 of Directive 2009/110/EC sets electronic money institution initial capital at not less than EUR 350 000.

The MiCA authorisation clock in Article 63: five working days to acknowledge, twenty five to check completeness, forty to assess and five to notify the decision

How long does the authorisation itself take?

The regulator's own clock is fixed and short. Article 63(1) gives competent authorities five working days to acknowledge an application in writing. Article 63(2) gives them 25 working days to assess whether the application is complete. Article 63(9) gives them 40 working days from receipt of a complete application to adopt a fully reasoned decision, and five further working days to notify it.

That is roughly 70 working days of statutory clock, because the five day acknowledgement runs inside the 25 day completeness window rather than after it. It is not the elapsed time. The gap between the two is the completeness loop. Where an application is incomplete, the authority sets a deadline for the missing information, and under Article 63(3) it may refuse to review an application that is still incomplete when that deadline passes. Every incomplete filing restarts the 40 working day assessment from the date the application becomes complete, so the cost of an underprepared application is measured in months, not in fees.

What makes an application complete is Article 62(2), a list of nineteen items from (a) to (s). Twelve apply to everyone: identity and legal entity identifier, legal form, articles of association, programme of operations, proof of the Article 67 prudential safeguards, governance arrangements, fit and proper evidence for the management body, qualifying holdings and the repute of those holders, internal control mechanisms including money laundering and terrorist financing risk and a business continuity plan, ICT systems technical documentation with a non-technical description, the client asset and fund segregation procedure, and complaints handling. Seven more attach to specific services: a custody and administration policy, trading platform operating rules with a market abuse detection system, a non-discriminatory commercial policy and pricing methodology for exchange, an execution policy, knowledge and expertise evidence for advisers and portfolio managers, an account of how transfer services will be provided, and the type of crypto-asset concerned.

The four lines that make up a MiCA compliance budget: permanent capital, the national application fee, the build before filing, and recurring supervision and audit

Which requirements create the recurring cost?

The build is finite. The recurring line is not, and it is the one that decides whether the programme is affordable in year three.

Four sources feed it. Article 68 requires management body members of sufficiently good repute with appropriate knowledge, skills and experience, which is a permanent hiring and governance cost rather than a project one. Article 70 requires client crypto-assets and funds to be held so that clients' ownership rights are protected and the provider cannot use them for its own account, which is an operational control that has to be evidenced continuously. The Article 67 prudential safeguard is reviewed annually against the previous year's audited accounts, so it grows with the firm. And Article 35(1) attaches an audited-statement dependency to issuers on the same annual cycle.

The fourth source is not in MiCA at all. Article 2(1)(f) of the Digital Operational Resilience Act names crypto-asset service providers authorised under MiCA, and issuers of asset-referenced tokens, as financial entities in its own scope. Authorisation therefore imports the full DORA stack: ICT risk management, incident classification and reporting, digital operational resilience testing and the register of information on third party ICT arrangements. Firms that budget MiCA and DORA separately usually discover the overlap after the authorisation decision rather than before it. Our line-by-line model of DORA compliance cost covers what that second regime adds.

What takes cost off the bill?

One route removes most of it, and it is written into the Regulation. Article 60 lets certain regulated entities provide crypto-asset services by notification instead of authorisation. A credit institution may provide crypto-asset services if it notifies its home competent authority at least 40 working days before providing them for the first time. An investment firm may provide the crypto-asset services equivalent to the investment services it is already authorised for, on the same 40 working day notification, with Article 60(3) mapping each crypto-asset service to its MiFID equivalent point by point. A central securities depository may provide custody and administration on the same basis.

If you already hold one of those authorisations, the marginal cost of adding crypto-asset services is a notification and the delta between your existing control set and the MiCA-specific requirements, not a fresh authorisation. If you do not, the Article 60 route is closed and Article 62 is the only door.

Two smaller levers are worth pricing before you commit. The insurance option in Article 67(4)(b) can substitute for own funds. And the class you apply for is a choice: adding trading platform operation moves you from EUR 125 000 to EUR 150 000 in capital, but it also pulls in the Article 62(2)(n) operating rules and market abuse detection system, which is a far larger cost than the EUR 25 000 difference suggests.

What sets a MiCA compliance number: own funds under Article 67, the application under Article 62, governance under Article 68, segregation under Article 70, the Article 60 notification route and DORA Article 2

What the other results get wrong

The published cost pages share three faults.

The first is quoting an EU-wide application fee. There is not one. MiCA leaves fees to national competent authorities, and they have not converged: some publish a fixed schedule by class, and others do not publish an amount at all. BaFin states that the fee for a MiCAR authorisation is based on the amount of time required, under the Finanzdienstleistungsaufsichtsgebuehrenverordnung, and that it is payable even if the application is withdrawn or rejected. Any single euro figure presented as the MiCA application fee is a figure for one Member State.

The second is presenting the Annex IV capital as the capital requirement. It is the floor, and Article 67(1) takes the higher of it and a quarter of fixed overheads. For most firms with staff, the binding number is the overheads one, and it is not in the table anybody reproduces.

The third is writing about the transitional regime in the present tense. It ended on 1 July 2026. ESMA's public statement of 23 June 2026 tells unauthorised providers to stop onboarding new EU clients immediately, limit services to what is necessary for an orderly exit, and set a deadline by which residual positions close. Costing a MiCA programme as though continuing to trade while you apply is an option is costing the wrong thing.

Size your own MiCA budget

Fill this in before asking anyone for a quote. Four of the six rows have an answer in the Regulation, and the other two are where your real number lives.

QuestionYour answerWhat it decides
Which class of services will you apply for?Annex IV. EUR 50 000, EUR 125 000 or EUR 150 000, and which parts of Art. 62(2) you must file.
What were your fixed overheads last year, as defined in Art. 67(3)?A quarter of that figure replaces the Annex IV floor once it is higher.
Do you already hold a credit institution, investment firm or CSD authorisation?Art. 60. A 40 working day notification instead of a full authorisation.
Which of the nineteen Art. 62(2) items do you have in a filable state today?The gap is your build cost and most of your elapsed time.
Own funds, an Art. 67(4)(b) insurance policy, or a combination?Balance sheet versus premium. The policy has conditions in Art. 67(5).
Have you scoped DORA alongside it?DORA Art. 2(1)(f). Authorisation puts you in scope of a second regime.

If the fourth row is mostly blank, the number you need is not a licence budget, it is a readiness assessment. A free compliance check gives you a baseline, and the MiCA framework page sets out how the six requirement areas fit together.

The bottom line on MiCA compliance cost: the permanent minimum capital is the smallest and most predictable line on the bill

Frequently asked questions

What is the minimum capital for a MiCA licence?

EUR 50 000, EUR 125 000 or EUR 150 000 under Annex IV, depending on the class of crypto-asset services. Article 67(1) requires the higher of that figure and one quarter of the preceding year's fixed overheads, at all times.

How much is the MiCA application fee?

MiCA does not set one. Fees are set by each home Member State's competent authority, and the models differ: some are fixed by class, and some, BaFin's among them, are charged on the time the authority actually spends, which means no amount is knowable in advance. Check your own authority's schedule rather than a cross-border average.

Can we still operate under a national licence while we apply?

No. The Article 143(3) transitional period ended on 1 July 2026, and Member States were free to end it earlier. ESMA has asked unauthorised providers to wind down in an orderly way and to stop onboarding new EU clients immediately.

Is there a cheaper route if we are already regulated?

Yes, if you are a credit institution, an investment firm or a central securities depository. Article 60 lets you provide the equivalent crypto-asset services on a notification made at least 40 working days in advance, rather than a full Article 62 authorisation.

Does MiCA authorisation pull in any other regulation?

It pulls in DORA. Article 2(1)(f) of Regulation (EU) 2022/2554 names MiCA-authorised crypto-asset service providers and asset-referenced token issuers as financial entities in scope, so the ICT risk management, incident reporting, resilience testing and third party register requirements apply.

How long does the authorisation take?

The statutory clock is about 70 working days: 25 to check completeness, with the five day acknowledgement inside that window, then 40 to assess a complete application and five to notify. Elapsed time depends on how many rounds the completeness check takes, and each round restarts the 40 working day assessment.

Primary sources

Capital, application and authorisation figures are taken from Annex IV and Articles 35, 48, 60, 62, 63, 67, 68, 70 and 143 of Regulation (EU) 2023/1114, the Markets in Crypto-Assets Regulation. The electronic money institution initial capital figure is from Article 4 of Directive 2009/110/EC. The DORA scope provision is Article 2(1)(f) of Regulation (EU) 2022/2554. The end of the transitional period and the wind-down expectations are from ESMA's public statement ESMA75-113276571-1710 of 23 June 2026. Fee models are national; no euro figure for an application fee appears in MiCA, and the time based German model is stated on BaFin's own cryptoasset services page. Confirm the current text and your own authority's schedule before relying on a number.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING