MiCA Article 67 requires a crypto-asset service provider to maintain prudential safeguards equal to at least the higher of the fixed minimum set for its service class and one quarter of the preceding year’s fixed overheads. The formula creates a regulatory floor, but the number cannot be read as a deposit guarantee or a prediction of resilience. Regulation (EU) 2023/1114 on markets in crypto-assets
Follow the evidence
Trace how the event could reach markets, then inspect a competing explanation.
Compare explanations
Switch lenses to see what each account explains—and what remains uncertain.
Prudential resources can absorb operating losses and support an orderly response to incidents. They do not stop a token price from falling, guarantee every withdrawal, or ensure that customer assets were properly segregated. A provider may satisfy the capital floor and still have weak governance, technology or outsourcing controls. Each protection answers a different risk question. For growing firms, the overhead test can increase the required safeguard as the cost base expands. Compliance teams need reliable accounting classifications, a repeatable calculation and evidence that eligible resources remain available. A one-day capital snapshot may miss intra-period deterioration, so monitoring and escalation thresholds are important operating controls even when the legal calculation is periodic.
Prudential resources can absorb operating losses and support an orderly response to incidents. They do not stop a token price from falling, guarantee every withdrawal, or ensure that customer assets were properly segregated. A provider may satisfy the capital floor and still have weak governance, technology or outsourcing controls. Each protection answers a different risk question. For growing firms, the overhead test can increase the required safeguard as the cost base expands. Compliance teams need reliable accounting classifications, a repeatable calculation and evidence that eligible resources remain available. A one-day capital snapshot may miss intra-period deterioration, so monitoring and escalation thresholds are important operating controls even when the legal calculation is periodic.
Customers and counterparties should first verify the authorised entity and the crypto services it may provide. Then distinguish own funds from insurance and ask whether a public disclosure refers to the regulated entity or a wider corporate group. MiCA authorisation is not a statement that the regulator has approved an investment or guaranteed the firm’s obligations. A mature due-diligence review combines the prudential requirement with custody arrangements, client-asset records, incident history, outsourcing dependencies and complaint procedures. Public information may not reveal every supervisory figure. The correct conclusion is therefore limited: Article 67 creates a minimum financial-resilience framework, while operational quality must be assessed through additional evidence. For management, the key control is not a once-a-year capital calculation but a documented process that detects deterioration between reporting dates. Scenarios should consider a revenue shock, fraud loss, cyber incident, legal cost, outsourcing failure and a rapid increase in customer-support or reconciliation work. The firm should know which data feed the fixed-overheads calculation, who challenges assumptions and what action follows if the buffer approaches the minimum. Customers cannot recreate a supervisor’s prudential review from public material, but they can check the authorised entity, services, financial disclosures and continuity arrangements. A large brand or high trading volume is not a substitute for the specific safeguards that apply to the entity holding the relationship.
Safeguards can consist of own funds, insurance or a combination
The regulation permits qualifying own funds, an insurance policy covering relevant territories, or a combination. Fixed minimum amounts differ by the classes of crypto services listed in MiCA’s annex. The overhead-based limb makes the requirement responsive to the provider’s cost base, while the fixed amount prevents the floor from collapsing solely because a firm reports low expenses. Regulation (EU) 2023/1114 on markets in crypto-assets
Insurance must address risks specified by the regulation, including loss of documents, misrepresentation, breach of confidentiality, business disruption and certain liability exposures. Policy exclusions, deductibles, limits and territorial scope therefore matter. Saying that a provider is insured without identifying the insured entity and covered risks provides little usable information.
Capital supports continuity but does not remove asset or counterparty risk
Prudential resources can absorb operating losses and support an orderly response to incidents. They do not stop a token price from falling, guarantee every withdrawal, or ensure that customer assets were properly segregated. A provider may satisfy the capital floor and still have weak governance, technology or outsourcing controls. Each protection answers a different risk question.
For growing firms, the overhead test can increase the required safeguard as the cost base expands. Compliance teams need reliable accounting classifications, a repeatable calculation and evidence that eligible resources remain available. A one-day capital snapshot may miss intra-period deterioration, so monitoring and escalation thresholds are important operating controls even when the legal calculation is periodic.
Ask which entity, service class and safeguard supports the claim
Customers and counterparties should first verify the authorised entity and the crypto services it may provide. Then distinguish own funds from insurance and ask whether a public disclosure refers to the regulated entity or a wider corporate group. MiCA authorisation is not a statement that the regulator has approved an investment or guaranteed the firm’s obligations.
A mature due-diligence review combines the prudential requirement with custody arrangements, client-asset records, incident history, outsourcing dependencies and complaint procedures. Public information may not reveal every supervisory figure. The correct conclusion is therefore limited: Article 67 creates a minimum financial-resilience framework, while operational quality must be assessed through additional evidence.
For management, the key control is not a once-a-year capital calculation but a documented process that detects deterioration between reporting dates. Scenarios should consider a revenue shock, fraud loss, cyber incident, legal cost, outsourcing failure and a rapid increase in customer-support or reconciliation work. The firm should know which data feed the fixed-overheads calculation, who challenges assumptions and what action follows if the buffer approaches the minimum. Customers cannot recreate a supervisor’s prudential review from public material, but they can check the authorised entity, services, financial disclosures and continuity arrangements. A large brand or high trading volume is not a substitute for the specific safeguards that apply to the entity holding the relationship.
