ComplyOne-Chain
MiCA made crypto a regulated industry. Run it like one.
MiCA authorisation, Travel Rule data on every transfer, AMLR customer due diligence, DORA incident reporting — ComplyOne maps every applicable regulation to your crypto business in one platform.
Why crypto compliance cannot live in spreadsheets
Since MiCA became fully applicable in December 2024, crypto-asset service providers face the same supervisory intensity as traditional financial firms — with less regulatory history to lean on. MiCA authorisation and ongoing conduct rules, Travel Rule information on every transfer, AMLR due diligence and monitoring, DORA ICT resilience and 4-hour incident reporting, GDPR for customer data: each carries documentation, audit-trail and reporting duties. National transition windows are closing, and supervisors expect evidence — not intentions.
What's included in ComplyOne-Chain
The regulations that matter most for casps, exchanges, custodians and token issuers — covered, mapped to your business, and tracked over time.
MiCA
Markets in Crypto-Assets Regulation — CASP authorisation, whitepaper obligations, conduct and custody rules, market-abuse provisions. Fully applicable since December 2024.
TFR (Travel Rule)
Transfer of Funds Regulation — originator and beneficiary information must accompany every crypto transfer, including rules for unhosted wallets. No de-minimis threshold.
AMLR
Customer Due Diligence, Know Your Customer, transaction monitoring and suspicious-activity reporting. CASPs are obliged entities under the EU AML framework.
DORA
Digital Operational Resilience Act — ICT risk framework, third-party register, 4-hour incident reporting, resilience testing. CASPs are in scope as financial entities.
GDPR
Customer and employee data protection. Privacy notices, data subject rights, processor agreements, breach response — including the tension between Travel Rule data retention and data minimisation.
How ComplyOne-Chain works
Onboard in minutes
Answer 5 questions about your business — sector, locations, data flows. No account needed for the free check.
Get your compliance map
See exactly which regulations apply to your business, where the gaps are, and what severity each carries.
Act on it
A prioritised task list, document templates, and an evidence pack organised for audit — guided through to a defensible compliance baseline.
Daily regulatory horizon scanning
ComplyOne scans EU regulatory sources every day — directives, implementing acts, regulator guidance, enforcement notices. When something changes that affects your obligation map, you get a structured alert: what changed, why it applies to you, and what you need to do. No more discovering enforcement deadlines from a news headline.
How to approach casps, exchanges, custodians and token issuers compliance
Map your obligations by licence and activity
What applies depends on what you do. An exchange faces MiCA conduct rules, TFR, AMLR and DORA. A custodian adds MiCA custody safeguards. A token issuer faces whitepaper and marketing rules. Start by mapping every applicable regulation to your actual activities — authorisation scope errors are the most expensive kind.
Confirm your MiCA authorisation path and deadline
CASPs operating under national regimes before December 2024 have member-state transition windows — many end during 2026. New entrants need full MiCA authorisation before operating. Fix your authorisation date, work backwards, and treat the application pack as a compliance programme, not a form-filling exercise.
Build overlapping foundations once
MiCA, AMLR, DORA and GDPR ask for much of the same underlying work: governance arrangements, an ICT risk framework, a customer due-diligence procedure, a data processing register, and documented outsourcing. Build these once and reference them across regulations instead of duplicating per regime.
Operationalise the Travel Rule
TFR compliance is a daily operational duty, not a policy on a shelf: originator/beneficiary data on every transfer, counterparty CASP due diligence, unhosted-wallet procedures, and rejection/return processes for non-compliant transfers. Document the workflow and evidence that it runs.
Prepare an audit-ready evidence pack
Crypto supervisors inspect early and often — authorisation is the beginning, not the end. Maintain an audit-ready folder: policies signed and dated, incident records, transaction-monitoring logs, Travel Rule evidence, vendor contracts and board minutes. ComplyOne structures this automatically across your applicable regulations.
Swiss-hosted
All data hosted in Switzerland — outside US data-access frameworks.
10 EU regulations
GDPR, AI Act, NIS2, DORA, FADP, UK GDPR, Data Act, CSRD, AMLR, CRA — one platform.
Daily horizon scanning
Regulatory changes alerted, mapped to your obligations, every day.
Frequently asked questions
We operated before MiCA — do we still need authorisation?+
Yes. Pre-existing CASPs benefit from national transitional periods (up to 18 months, varying by member state), but full MiCA authorisation is required before the window closes. Several member states chose shorter windows — confirm yours and work backwards from it.
Does the Travel Rule really apply to every transfer?+
Effectively yes — the EU chose no de-minimis threshold. Originator and beneficiary information must accompany crypto transfers of any amount, with specific verification duties for transfers involving unhosted wallets above €1,000. This is one of the most operationally demanding obligations for CASPs.
Are crypto companies really in scope for DORA?+
Yes — CASPs and issuers of asset-referenced tokens are financial entities under DORA. That means an ICT risk-management framework, a register of ICT third-party providers, resilience testing and incident reporting on DORA's timelines (initial notification within 4 hours of classification).
Can one platform cover MiCA, TFR, AMLR and DORA?+
Yes — and it should, because they overlap heavily. A wallet-infrastructure incident can trigger DORA incident reporting, MiCA operational-resilience duties and GDPR breach notification at once. ComplyOne maps the overlaps so one piece of work satisfies every regime it belongs to.
We're a small team — how demanding is this really?+
Company size affects the intensity of requirements, not whether they apply. A five-person CASP still needs MiCA authorisation, Travel Rule operations, AML procedures and DORA-proportionate ICT risk management. The advantage of starting small is building it right the first time.
How quickly can our team get started?+
The compliance check takes about 5 minutes and produces your obligation map immediately. A structured task list then guides your team through documentation and controls — prioritised by authorisation deadline and enforcement risk. Most crypto teams reach a defensible baseline in 2 to 3 weeks.
See where you stand — in 60 seconds
Free compliance check, no signup required. Get your obligation map and gap report instantly.
Related guides
Practical guidance for casps, exchanges, custodians and token issuers.