One of the sources of systemic misunderstanding of MiCA in practice is the conflation of two distinct regulatory planes: the classification of CASP services by license classes and the qualification of activities as custody or non-custody. These planes intersect, but they do not coincide.
An analysis of the staffing policy of the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego) in 2025–2026 shows that the implementation of MiCA is accompanied not by a formal redistribution of tasks, but by a targeted strengthening of staff in key areas of regulatory risk. The significant increase in vacancies in departments responsible for banking and investment inspections, AML/CFT, cybersecurity, and enforcement indicates a transition by the KNF to a model of intensive, operationally oriented supervision. The regulator is proactively investing in the human capital necessary to verify the actual functioning of CASP business models, rather than merely their formal compliance with MiCA requirements.
The content of the published job postings allows one to reconstruct future supervisory practice more accurately than official strategic documents. Recurring formulations indicate the predominance of on-site inspections and the subsequent procedural documentation of violations. This implies that MiCA licensing in Poland is being designed from the outset as a multi-stage verification of the operational reality of CASPs, structured to withstand judicial review of regulatory decisions.
MiCA — and, following it, the Polish Act on the Crypto-Assets Market — introduces a gradation of crypto-asset service providers into Class 1, Class 2, and Class 3, primarily for the purposes of setting minimum capital requirements and determining the scale of activity.
| CASP Class | Scope of services | Minimum capital |
|---|---|---|
| Class 1 | Execution of orders on behalf of clients; placement of crypto-assets; transfer services on behalf of clients; reception and transmission of orders; advice on crypto-assets; portfolio management. | EUR 50 000 |
| Class 2 | All Class 1 services, plus: exchange of crypto-assets for funds; exchange of crypto-assets for other crypto-assets; safekeeping and administration of crypto-assets on behalf of clients. | EUR 125 000 |
| Class 3 | All Class 2 services, plus: operation of a crypto-asset trading platform. | EUR 150 000 |
From a market perspective, this structure leads to an intuitive but erroneous conclusion: custody is supposedly «tied» to a particular license class, and Class 2 is automatically perceived as a «typical crypto exchange» without deeper regulatory implications beyond the capital requirement.
However, license classes do not constitute a qualification of custody. Annex IV to Regulation (EU) 2023/1114 on Markets in Crypto-Assets describes bundles of services that may be combined within a single licence, but it does not answer the key custody question: whether a given business model exercises actual control over a client’s crypto-assets.
In other words, classification by licence class is a matter of the scope of activity, whereas custody is a matter of the functional role of the entity. This is precisely where the «fault line» arises.
A typical crypto exchange, classified as Class 2, may either not perform custody or, conversely, fall within the category of a custodial CASP, depending not on the label of the service but on whether it:
- holds clients’ crypto-assets, even if only temporarily;
- exercises operational control over private keys or their components;
- controls the timing and conditions of settlement;
- is able unilaterally to initiate, delay, or block the transfer of crypto-assets.
Accordingly, custody may «arise» within Class 2 even in cases where a company does not formally provide safekeeping and administration of crypto-assets on behalf of clients. This fundamentally distinguishes the logic of MiCA from the formalistic approach to which the market had become accustomed in the pre-regulatory period.
Hence the key conclusion for CASPs preparing for authorisation: Class 2 is not, by default, equivalent to non-custody. Under MiCA, custody is not a question of which class a provider belongs to, but of the actual role it performs in relation to the client’s assets.
Custody as a composite of elements
One of the key shifts introduced by MiCA is the rejection of technological formalism in the qualification of CASP activities. The regulator deliberately moves away from attempts to tie custody to specific technical solutions, architectures, or user interfaces. Instead, MiCA proceeds from functional reality — the role the entity actually performs in relation to the client’s crypto-assets.
- Holding — the factual possession of crypto-assets or their equivalents, including where such possession is temporary, transitional, or conditioned by the technological process of service execution. The decisive factor is that the assets are under the control of the CASP, even if only for a limited period.
- Control — the ability of the CASP to exert a determining influence over the fate of a client’s crypto-assets, through access to private keys, operational management of infrastructure, configuration of transaction rules, or the capacity to intervene in the transaction flow.
- Ability to dispose — the capacity to initiate, approve, delay, or block the transfer of crypto-assets. Even where actions are formally carried out «on the client’s instructions,» the fact that disposal is not possible without the CASP has independent regulatory significance.
- Safeguarding on behalf of clients — the assumption of responsibility for safekeeping, the management of risks of loss, and procedures to protect client interests in the event of operational failures, insolvency, or cessation of activity.
It is the aggregate of these elements, rather than their formal description in documentation, that determines the existence of custody for the purposes of MiCA.
Why technical arguments do not provide a safe harbour
In practice, many market participants still proceed from the assumption that a properly designed technological architecture automatically places a business model outside the scope of custody. MiCA consistently refutes this approach.
A user interface that creates the impression of full client control over assets is not, in itself, decisive. If such a UX conceals an underlying infrastructure in which the CASP manages transaction execution, controls entry and exit points, or provides mandatory intermediation, the regulator will assess actual control, not user perception.
The use of multi-party computation (MPC) is sometimes perceived as a universal solution that neutralizes custody risk. However, MiCA does not equate the absence of unilateral access to a private key with the absence of custody. If an MPC architecture assigns the CASP a decisive role in access recovery, transaction signing, or management of key system parameters, the element of control remains. MPC is a cryptographic technique, not a regulatory safe harbor.
The common argument that crypto-assets are held «only for the duration of execution» is likewise not determinative. MiCA does not distinguish between temporary and permanent holding where, during the relevant period, the CASP effectively controls the client’s assets and bears responsibility for their safekeeping.
Where custody typically arises
In practice, custody is rarely an intentionally chosen service. Much more often, it emerges as a by-product of product architecture, operational processes, or risk management requirements — at the periphery of the core service, within settlement, recovery mechanisms, safeguarding arrangements, partner interactions, or even corporate documentation.
- Exchanges and broker models remain the most obvious locus of custody risk — through omnibus wallets, internal ledgers that record client balances off chain, and settlement windows during which assets are temporarily held.
- On-/off-ramps and quasi-payment models generate custody in the transitional zone between fiat and crypto-assets: when funds have been debited in fiat but not yet credited in crypto, the question is who controls the asset until final settlement.
- Wallet providers and embedded solutions often create custody through security and recovery mechanisms rather than direct holding — MPC architectures, recovery mechanisms, and operational access related to updates or emergency procedures.
- Fintech hybrids and white-label structures obscure custody risk through a diffuse allocation of roles. Following a look-through approach, the KNF evaluates the actual distribution of functions and control, not the contractual structure.
Regulatory consequences of custody misclassification
Under MiCA, an error in the qualification of custody is not a theoretical defect; it is a practical regulatory risk that directly affects licensing, business structure, and the ability of a CASP to operate across the EU.
- Applying for the «wrong» licence profile triggers requalification: suspension of review, requests for additional documentation, a requirement to amend the licence scope, and in some cases the need to resubmit entirely.
- Capital and safeguarding requirements become more stringent: minimum own-funds calibrated to the custody profile, segregation of clients’ crypto-assets, insolvency protection, and secure storage measures.
- Governance and personal liability increase: formal board-level responsibility for safeguarding, clear delineation of roles, conflict-of-interest policies, and documented decision-making procedures affecting access to client assets.
- Delays, restructuring, refusal, or conditional approval become likely, alongside constraints on EU passporting potential, since an error at the initial licensing stage propagates across the entire European market footprint.
Strategic approaches to custody under MiCA
MiCA does not require CASPs to avoid custody at all costs. It requires informed strategic choice. A proper functional analysis makes clear that custody is a strategic fork: either accept the custodial profile with its regulatory consequences or genuinely redesign the business model.
- Conscious acceptance of custody — selecting a licence aligned with actual activities, meeting heightened capital requirements, and investing in safeguarding, governance, and ICT infrastructure.
- Genuine de-custodialization — not a change in terminology, but a substantive elimination of control over client assets, verifiable in practice and able to withstand regulatory scrutiny.
- Functional separation and outsourcing — placing custody in a dedicated or specialized entity, effective only if consistent with the regulatory look-through principle and a genuine redistribution of control.
- Mixed strategy — reducing, though not eliminating, custody elements through stronger governance, transparent disclosures, and clear contractual allocation of rights, rendering custody manageable and regulatorily transparent.
Conclusion: MiCA as a stress test for business maturity
For the Polish market, the implementation of MiCA does not merely represent a transition to a new licensing regime. It constitutes a qualitative shift in regulatory logic, whereby licensing becomes an assessment of the maturity of a business model rather than a formal compliance exercise.
The key practical conclusion is unequivocal: the optimal moment to determine whether custody exists is before engaging with the regulator. An independent and critical assessment of the business model allows custody to be transformed from a source of risk into a manageable strategic element — and avoids a situation in which the qualification is effectively determined by the supervisory authority under conditions of limited time and heightened pressure.
In Polish practice, MiCA is being implemented as a regime of enhanced operational supervision: the expansion of KNF staffing in early 2026 in AML, ICT, inspection, and enforcement functions indicates that the focus of supervision will be not the declared CASP profile, but its actual ability to manage custody-related risks.
Custody under MiCA: key takeaways
- Under MiCA, custody is defined by functional control over client assets, not by CASP licence class — Class 2 is not automatically non-custody.
- Technical arguments (MPC, «temporary holding», client-facing UX) do not remove custody if the CASP effectively controls assets or settlement.
- Misclassifying custody is a concrete licensing risk; resolve the functional custody question before engaging the regulator.
Framework: Regulation (EU) 2023/1114 (MiCA). Our services: CASP / MiCA licensing and post-licensing services.



