02 · Audit
Gap analysis, documentation, AML/CFT procedures, security testing and support with the KNF authorization for crypto-asset service providers and token issuers — MiCA and DORA in one engagement.
Service details
MiCA (Markets in Crypto-Assets Regulation, EU 2023/1114) is the European Union's single rulebook for crypto-assets. It sets uniform rules for issuing crypto-assets and for providing crypto-asset services, with the aim of protecting investors, keeping the market transparent and stable, and preventing market abuse.
For crypto-asset service providers (CASPs) and token issuers, MiCA compliance is no longer optional: providing crypto-asset services in the EU requires authorization from the national supervisor — in Poland, the KNF. Remote Admin supports you at every stage: from the compliance audit and gap analysis, through documentation and procedures, to the authorization application and maintaining compliance afterwards.
Our services
A detailed audit of your operations against MiCA and the related technical standards (RTS/ITS), with a prioritized list of what needs to change.
Advice on adapting your organization, governance and processes to MiCA, and on implementing the policies and procedures the regulation requires.
Anti-money laundering and counter-terrorist financing procedures and monitoring, including customer identification, transaction monitoring and the crypto "travel rule".
CASPs are also covered by DORA. We assess ICT risk management, incident handling and resilience testing in the same engagement.
Policies, terms and conditions, business continuity plan, crypto-asset white paper and all reports needed to demonstrate compliance.
Training for your team and management, compiling the CASP application and answering the supervisor's questions until the license is granted.
Material scope
Who it applies to
Exchanges, currency exchange services, trading platforms, wallet custody, advisory and portfolio management — KNF (Polish Financial Supervision Authority) authorization and supervision required.
Tokens that reference a basket of currencies, commodities or assets — authorization, reserve of assets, capital requirements.
Stablecoins pegged to a single fiat currency — credit institutions and e-money institutions only.
Obligation to publish a crypto-asset white paper and comply with marketing communication rules.
Audit scope
Key facts
How we work
Questions and answers
MiCA (Markets in Crypto-Assets, Regulation (EU) 2023/1114) is the EU regulation that sets common rules for issuing crypto-assets and providing crypto-asset services. It covers authorization, governance, capital, client protection, transparency and the prevention of market abuse.
Any company that provides crypto-asset services in the EU on a professional basis — for example operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, custody of crypto-assets, executing or transmitting orders, placing, advice or portfolio management. In Poland, the authorization is granted by the KNF.
MiCA has applied to crypto-asset service providers since 30 December 2024. Firms already operating under national rules could use a transitional period of at most 18 months, which ended by 1 July 2026 at the latest (member states could set shorter periods). Today, providing crypto-asset services in the EU requires a MiCA authorization — so the sooner the gap analysis is done, the better.
Crypto-asset service providers and issuers of asset-referenced tokens are financial entities under DORA, so they must also meet its requirements on ICT risk management, incident reporting, resilience testing and third-party risk. That is why we audit both regulations together — see our DORA audit.
It is the information document that issuers and offerors of crypto-assets must publish under MiCA. It describes the issuer, the project, the crypto-asset, the rights attached to it, the underlying technology and the risks, and must be fair, clear and not misleading.
Yes. A CASP authorized in one member state can provide its services in other EU countries through passporting, after notifying the home supervisor — one of the main benefits of the MiCA regime.
Alongside MiCA, crypto-asset service providers are obliged entities under anti-money laundering rules and must apply customer due diligence, transaction monitoring and suspicious activity reporting, as well as the "travel rule" of the Transfer of Funds Regulation for crypto-asset transfers. We help design and implement these procedures.
A gap analysis report comparing your current state with MiCA and DORA requirements, a prioritized action plan with effort estimates and — if you continue with us — the documentation, technical evidence and application package needed for authorization.
Yes. As part of the evidence for the supervisor we run penetration tests and configuration reviews of your exchange, wallets and infrastructure, and can provide continuous monitoring through our 24/7 SOC.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact