Glossary / Regulation & tax
Crypto-asset custody service
Also known as Custody and administration on behalf of clients, Crypto-asset custody and administration.
- What is Crypto-asset custody service?
- Crypto-asset custody service is the MiCA-regulated activity of safekeeping or controlling crypto-assets, or the means of access to them, on behalf of clients.
Holding the private keys is what triggers the obligation, not holding the coins in any physical sense. Annex IV of Regulation (EU) 2023/1114 puts custody providers in Class 2, with a permanent minimum capital requirement of EUR 125 000. If a platform can move your bitcoin without asking you, it owes you this service and its rules.
How it works
MiCA lists providing custody and administration of crypto-assets on behalf of clients first among the ten crypto-asset services in Article 3(1)(16), and Article 3(1)(17) defines it as the safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys. The phrase "means of access" is doing the work there: a firm that never touches a coin but does hold the key sits inside the definition.
Article 75 attaches the duties. The provider signs a client agreement covering seven specific points, among them the custody policy, the client authentication system, a description of the security systems used, the fees, and the applicable law. It keeps a register of positions opened in the name of each client, and records movements in that register as instructions arrive. It runs a written custody policy aimed at minimising loss from fraud, cyber threats or negligence, and gives a summary of that policy in electronic format to any client who asks.
Three further paragraphs of Article 75 are the ones worth memorising:
- Reporting. Clients get a statement of position at least once every three months, identifying the assets, their balance, their value and the transfers made during the period.
- Segregation. Client holdings sit separately from the provider's own on the distributed ledger, and are legally segregated from the provider's estate so that its creditors have no recourse to them, in particular in an insolvency.
- Liability. The provider answers for assets lost through an incident attributable to it, capped at the market value of the lost crypto-asset at the time the loss occurred.
Sub-custody is permitted, but only with another provider authorised under Article 59, and clients have to be told it is happening.
Where you see it
Custody is the authorisation class that decides whether a European venue may hold your coins at all. Under Annex IV a firm offering custody or exchange falls in Class 2, above the Class 1 that covers order execution, reception and transmission of orders, placing, transfer services on behalf of clients, advice and portfolio management, and Article 67(1) sets the requirement at the higher of that Annex IV figure and one quarter of the previous year's fixed overheads. An applicant has to file a description of its custody and administration policy with the authorisation application itself, under Article 62.
Narrower permissions exist. An electronic money institution may provide custody only for the e-money tokens it has issued, and only after notifying its home authority at least 40 working days before it starts.
On this site that line runs through the crypto-licence guides, where the class a national regulator grants tells you which services a firm may actually sell, and through every exchange review: leaving bitcoin on a platform makes that platform your custodian. Article 75 binds only a crypto-asset service provider, which Article 3(1)(15) ties to an authorisation under Article 59.
Crypto-asset custody service vs non-custodial wallet
A crypto-asset custody service holds the means of access to someone else's coins, while a non-custodial wallet hands that means of access to the owner and keeps none of it. Recital 83 of the Regulation says plainly that hardware or software providers of non-custodial wallets do not fall within its scope, which is why a device maker needs no authorisation to sell you one. The consequence runs both ways: none of Article 75 protects you once you hold your own keys. There is no register of positions, no statement every three months, and nobody liable at market value when a seed phrase is lost.