KYB under MiCA: a CASP compliance guide for corporate onboarding (2026)

MiCA — Regulation (EU) 2023/1114 — is the EU-wide licensing and conduct framework for crypto-asset issuers and crypto-asset service providers (CASPs) such as exchanges, custodians, brokers, and portfolio managers. The CASP authorisation regime has applied since 30 December 2024. Firms operating under prior national registrations could continue during a transitional (grandfathering) period, but that window ends no later than 1 July 2026 — several member states set an earlier cut-off. After the deadline, serving EU clients without MiCA authorisation is a breach; for legal persons, penalties can reach EUR 5 million or 3% of total annual turnover, whichever is higher.

The five KYB/AML checks — and where Prometiam fits

For every corporate client or counterparty, five checks recur, and Prometiam covers the registry-and-sanctions leg of each:

Where it does not fit

Prometiam is business-side (KYB) only. It does not provide Travel Rule messaging, wallet or blockchain analytics, individual-consumer identity verification, adverse-media, or MiCA authorisation itself, and its PEP screening is beta and Spain-only (no relatives or close associates) — pair it with dedicated vendors for those legs.

Read more · Get a free API key

Frequently asked questions

What is MiCA and who does it apply to?
MiCA — Regulation (EU) 2023/1114 — is the EU-wide licensing and conduct framework for crypto-asset issuers and crypto-asset service providers (CASPs), such as exchanges, custodians, brokers, and portfolio managers. The CASP authorisation regime has applied since 30 December 2024.
What happens after the MiCA transitional period ends?
Firms operating under prior national registrations could continue during a transitional, or grandfathering, period while seeking full MiCA authorisation. The length varies by member state, generally ending no later than 1 July 2026. After that date, providing crypto-asset services to EU clients without MiCA authorisation is a breach of the regulation.
What are the penalties for non-compliance with MiCA?
For legal persons, penalties linked to MiCA breaches can reach EUR 5 million or 3% of total annual turnover, whichever is higher, in addition to possible withdrawal of authorisation.
Does Prometiam make a CASP MiCA-compliant?
No single API does. Prometiam is the registry-verification and sanctions-screening layer: it confirms a corporate client or counterparty legally exists, screens it and its directors against sanctions and US export-control lists (six sources), and monitors it afterward. It complements the licensing, governance, capital, Travel Rule, and consumer-KYC obligations that already apply to a CASP; it does not replace them.
Does Prometiam cover the Travel Rule or wallet screening?
No. Prometiam does not provide VASP-to-VASP Travel Rule messaging under Regulation (EU) 2023/1113, wallet or blockchain analytics, or individual-consumer identity verification. It is designed to sit alongside dedicated Travel Rule, chain-analytics, and consumer-KYC vendors, covering the corporate registry and sanctions leg of KYB.