XregOS · MiCA
Compliance OS · MiCA
← Blog2026-09-03

Article 75 MiCA Custody Obligations Compliance Guide

Article 75 of Regulation (EU) 2023/1114 (MiCA) sets out the custody and safeguarding obligations for crypto-asset service providers that hold or control client crypto-assets. A CASP providing custody and administration of crypto-assets on behalf of clients must segregate those assets from its own holdings, maintain an accurate register of positions for each client, and transfer crypto-assets on request without delay. The CASP remains liable to the client for any loss of crypto-assets, regardless of whether the CASP uses a third-party custodian.

Which CASPs must comply with Article 75

Article 75 MiCA applies to any CASP authorized to provide the service of custody and administration of crypto-assets on behalf of clients. This is one of the ten crypto-asset services listed in Annex I, Section A of MiCA. The obligation also extends to CASPs providing other services if, in the course of those services, they hold or control client crypto-assets — for example, an exchange or trading platform that holds customer deposits.

The requirement applies from 30 December 2024 for new applicants and existing firms that did not benefit from transitional grandfathering. CASPs operating under national regimes before MiCA entered into force had until 1 July 2026 to align with Article 75, provided their home member state granted a transitional authorization under Article 143 MiCA. You can check a firm's authorization status and the services covered on the ESMA register.

Segregation of client crypto-assets from the CASP's own holdings

Article 75(1) MiCA requires a CASP to make adequate arrangements to safeguard client crypto-assets. The central requirement is segregation: client crypto-assets must be held separately from the CASP's own crypto-assets. The segregation must be verifiable on-chain or in the CASP's internal ledger, depending on whether the assets are held in distributed-ledger wallets or custodial accounts.

Segregation serves two purposes. First, it ensures that client assets cannot be used by the CASP for its own account, proprietary trading, or to cover the CASP's liabilities. Second, it protects client holdings in the event of the CASP's insolvency — segregated client crypto-assets should not form part of the insolvency estate available to the CASP's creditors, subject to national insolvency law.

The segregation must be maintained at all times. A CASP may not co-mingle client crypto-assets with its own, even temporarily. If the CASP uses omnibus wallets or pooled accounts for operational efficiency, it must still maintain internal records that attribute each unit of crypto-asset to the correct client, and the omnibus structure must be clearly designated as holding client property.

Record-keeping and position registers

Article 75(2) MiCA requires a CASP to maintain a register of the positions held for each client. The register must be updated without delay to reflect deposits, withdrawals, transfers, and any other movements. Each client must be able to identify their crypto-assets at any time.

The position register is an internal ledger, separate from the blockchain itself. It records which client owns which quantity of which crypto-asset. For fungible tokens held in pooled wallets, the register assigns beneficial ownership; for non-fungible tokens or assets held in segregated wallets, the register links the wallet or token identifier to the client account.

The CASP must keep the register accurate and reconcile it regularly against on-chain balances. A mismatch between the register and the blockchain — such as a shortfall in the omnibus wallet — must be identified and rectified immediately. Competent authorities expect daily reconciliation for liquid crypto-assets and at least weekly reconciliation for less frequently traded tokens.

Article 75(2) also requires the CASP to provide clients with access to their position information. A client must be able to log in and see their holdings in real time or near-real time. This transparency obligation prevents the CASP from obscuring losses or unauthorized use of client crypto-assets.

Transfer of crypto-assets on client request

Article 75(3) MiCA requires a CASP to transfer a client's crypto-assets to another address or service provider on the client's instruction, without delay. The CASP may not impose unreasonable conditions or fees that would effectively lock in the client's holdings.

The transfer obligation applies to both withdrawals to the client's own wallet and transfers to another CASP. The CASP may apply its standard withdrawal process, including identity verification and anti-money laundering checks under the Transfer of Funds Regulation (TFR), but it may not delay the transfer beyond what is necessary for those checks. A delay of more than 24 hours after the client's instruction, absent a clear compliance or technical reason, would likely breach Article 75(3).

The CASP may charge a fee for withdrawals, provided the fee is disclosed in advance in the contractual terms and is proportionate to the cost of executing the on-chain transaction. A withdrawal fee set at a level that discourages clients from moving their crypto-assets would be inconsistent with Article 75(3).

Liability for loss of client crypto-assets

Article 75(4) MiCA provides that a CASP is liable to the client for any loss of crypto-assets held on behalf of that client. The liability applies regardless of whether the loss results from the CASP's own actions, a technical failure, a cyberattack, or the default of a third-party custodian.

The CASP may only escape liability if it can prove that the loss resulted from an external event beyond its reasonable control, the consequences of which would have been unavoidable despite all reasonable efforts to the contrary. This is a high threshold. A hack of the CASP's infrastructure does not automatically qualify, because the CASP is expected to have implemented reasonable security measures. A force majeure event such as a ledger-wide protocol failure might qualify, but the CASP would need to demonstrate that no reasonable safeguard could have prevented the loss.

If a CASP uses a third-party custodian to hold client crypto-assets — for example, outsourcing cold storage to a specialized vault provider — the CASP remains liable to its own clients under Article 75(4). The CASP may have a claim against the third-party custodian under the contractual or tortious law of the relevant jurisdiction, but the client's claim is against the CASP, not the custodian. This liability stacking ensures that clients always have a solvent, regulated counterparty to pursue.

Operational requirements and supervisory expectations

Competent authorities expect a CASP to document its custody procedures in written policies that cover wallet generation, key management, access controls, reconciliation frequency, and incident response. The policies must be approved by the CASP's management body and reviewed at least annually.

For cold storage, supervisors expect multi-signature schemes, geographic distribution of key shards, and physical security measures. For hot wallets, supervisors expect network segmentation, intrusion detection, and insurance or reserve funds to cover potential losses. The CASP must conduct penetration testing at least annually and engage an external auditor to assess the adequacy of its custody controls.

Article 75(5) MiCA requires the CASP to have an investment policy for any client funds (fiat currency) it holds. Client crypto-assets themselves are not subject to an investment policy because they must be held in segregated wallets, not invested. However, if a client deposits euros or another fiat currency that the CASP holds pending execution of a trade, that fiat must be placed in one or more accounts with a credit institution or invested in safe, liquid assets such as government bonds. The investment policy must prioritize capital preservation over yield.

Interaction with the Transfer of Funds Regulation

When a client requests a withdrawal under Article 75(3), the CASP must comply with the information requirements in the Transfer of Funds Regulation (TFR). For transfers above EUR 1,000, the CASP must collect and transmit the client's name, account number, address, and date of birth to the beneficiary service provider (if the beneficiary uses one). For transfers to a client's own self-hosted wallet, the CASP must collect the same information and store it for five years, but does not transmit it because there is no beneficiary service provider.

The TFR does not override the Article 75(3) requirement to transfer without delay. The CASP must structure its compliance processes so that it can collect the required information and execute the transfer within the timeframe that Article 75(3) implies. Supervisors will not accept a multi-day delay in a standard withdrawal on the grounds that the CASP needed time to gather TFR data — the CASP should have collected that data at onboarding or requested it at the time of the withdrawal instruction.

Consequences of non-compliance

A breach of Article 75 MiCA is a Category 2 breach under Article 111 MiCA, subject to administrative fines of up to EUR 5,000,000 or, if the CASP is a legal person, 10 per cent of its total annual turnover. Competent authorities may also impose periodic penalty payments, suspend the CASP's authorization, or require the CASP to cease the custody service until it remediates the breach.

Clients who suffer loss due to a CASP's breach of Article 75 may bring a civil claim for damages under national law. The strict liability standard in Article 75(4) shifts the burden of proof: the CASP must prove it took all reasonable measures and that the loss was unavoidable, rather than the client having to prove negligence. National courts in most member states recognize a private right of action for breach of a protective statutory duty such as Article 75.

Verifying a CASP's custody authorization

Before transferring crypto-assets to a CASP for custody, you may verify that the CASP is authorized for the custody and administration service. The ESMA register lists all MiCA-authorized CASPs, the services they are authorized to provide, and the member state that supervises them. The register is updated in near-real time as competent authorities grant, vary, or withdraw authorizations.

A CASP that is authorized to operate a trading platform or provide exchange services may also hold client crypto-assets incidentally to those services, even if custody and administration is not listed as a separate authorized service. In that case, Article 75 still applies to the CASP's custody function, but the register entry may show only the primary service. If in doubt, contact the competent authority of the CASP's home member state to confirm the scope of authorization.