# EU Markets in Crypto-Assets Regulation (MiCA)

Framework id: `mica`. Digital Asset Regulation. Publisher: European Parliament and Council. Version: Regulation (EU) 2023/1114. Region: EU. Mapping licence: CC BY-SA 4.0.
Source text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1114

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (41, average coverage 44%)
- Art.34(1) ART governance arrangements — management body requirements: PL-01, PM-01, PM-02, PS-02, PS-08, PS-09 (30%)
- Art.34(5) ART governance arrangements — internal controls and risk management: CA-01, CA-02, CA-07, PL-02, PM-09, RA-01, RA-03, RA-07, SA-02, SI-01 (68%)
- Art.35(1) ART risk management — identifying and managing risks: PM-09, RA-01, RA-02, RA-03, RA-05, RA-07, RA-09, SA-02, SI-05 (65%)
- Art.36(1) ART conflicts of interest — policies and procedures: AC-05, AC-06, PM-01, PS-06, PS-08 (30%)
- Art.40(1) ART reserve of assets — custody and safeguarding: AC-03, AC-06, CM-08, IA-02, IA-05, MP-02, MP-04, SC-12, SC-13, SC-28 (45%)
- Art.41(1) ART reserve assets — investment policy and risk: PM-09, RA-03, SA-02 (15%)
- Art.43(1) ART — independent audit of reserve: CA-02, CA-07, AU-01, PM-01 (28%)
- Art.47(1) ART — redemption rights and liquidity management: CP-02, CP-09, PM-09, RA-03 (22%)
- Art.54(1) EMT governance — management body and internal controls: CA-01, PM-01, PM-02, PM-09, PS-02, PS-09, RA-01, SA-02 (32%)
- Art.55(1) EMT reserve of assets — custody and safeguarding: AC-03, AC-06, IA-02, IA-05, SC-12, SC-13, SC-28, MP-02, MP-04 (40%)
- Art.59(1) CASP authorisation — application and conditions: PM-01, PM-02, PM-09, PL-01, CA-06 (22%)
- Art.62(1) CASP ongoing requirements — prudential and ICT requirements: CA-01, CA-07, CM-01, CM-06, PM-09, RA-01, RA-03, RA-07, SA-01, SA-02, SI-01 (65%)
- Art.62(5) CASP ICT systems — security, reliability, and adequate resources: CM-02, CM-06, CM-07, CP-07, CP-09, SA-03, SA-08, SC-05, SC-07, SI-02, SI-04, SI-13 (78%)
- Art.62(6) CASP business continuity — ICT continuity policy: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-09, CP-10, PM-09 (80%)
- Art.62(7) CASP security policies — ICT and cyber security: AC-01, AT-01, AT-02, CA-01, CM-01, IA-01, IR-01, PL-01, RA-01, SA-01, SC-01, SI-01 (82%)
- Art.62(8) CASP incident management — detection and reporting: AU-06, IR-01, IR-04, IR-05, IR-06, IR-07, IR-08, SI-04, SI-05 (72%)
- Art.62(9) CASP data protection — personal data handling: AC-03, AU-01, MP-06, PT-01, PT-02, PT-03, PT-04, PT-05, PT-06, SC-28 (55%)
- Art.63(1) CASP safeguarding — clients' crypto-assets and funds: AC-03, AC-04, AC-06, IA-02, IA-05, SC-12, SC-13, SC-17, SC-28, MP-02, MP-04 (48%)
- Art.63(2) CASP safeguarding — segregation and record-keeping: AC-05, AU-01, AU-09, AU-11, AU-12, CM-08, IA-04, PM-01 (50%)
- Art.64(1) CASP complaints-handling — procedures and records: IR-01, IR-04, IR-07, IR-08, PM-01 (38%)
- Art.65(1) CASP conflicts of interest — identification and management: AC-05, AC-06, PM-01, PS-06, PS-08 (28%)
- Art.66(1) CASP outsourcing — conditions and ongoing oversight: CA-03, PM-09, RA-03, SA-04, SA-09, SR-01, SR-02, SR-03, SR-05, SR-06 (68%)
- Art.66(3) CASP outsourcing — contractual provisions and audit rights: CA-03, SA-04, SA-09, SR-04, SR-05, SR-06, SR-11 (60%)
- Art.67(1) Custody and administration of crypto-assets — specific service requirements: AC-02, AC-03, AC-06, AU-11, AU-12, IA-02, IA-05, SC-12, SC-13, SC-17, SC-28 (50%)
- Art.68(1) Operation of a trading platform for crypto-assets — rules and systems: AC-04, AU-02, AU-03, AU-12, CM-07, SA-08, SC-05, SC-07, SI-04, SI-10 (55%)
- Art.68(5) Trading platform — system resilience and business continuity: CP-01, CP-02, CP-04, CP-06, CP-07, CP-09, CP-10, SA-08, SC-05, SI-13 (72%)
- Art.69(1) Exchange services — policies for determining crypto-asset prices: AU-02, AU-12, SA-08, SI-10 (28%)
- Art.70(1) Execution of orders — best execution and order handling: AU-02, AU-12, SA-08 (18%)
- Art.72(1) Reception and transmission of orders — client order handling: AU-02, AU-12, IA-02, SA-08 (22%)
- Art.73(1) Providing advice and portfolio management — suitability: PM-01, PS-06 (10%)
- Art.76(1) Transfer services — handling crypto-asset transfers: AC-04, IA-02, IA-05, SC-08, SC-12, SC-13, SI-10 (55%)
- Art.82(1) Record-keeping — transaction and order records: AU-01, AU-09, AU-11, AU-12, CM-08, SI-12 (60%)
- Art.83(1) Information to clients — disclosures and marketing communications: PT-05, PM-01 (15%)
- Art.84(1) Crypto-asset white paper — publication requirements: PM-01, SA-05 (12%)
- Art.86(1) Prohibition of insider dealing — policy and access controls: AC-02, AC-05, AC-06, AU-02, AU-12, PM-01, PS-06 (32%)
- Art.88(1) Market manipulation — prohibition and detection: AU-02, AU-06, AU-12, SI-04, SI-07 (38%)
- Art.92(1) CASP detection and prevention of market abuse — policies and procedures: AC-05, AC-06, AU-02, AU-06, AU-12, IR-04, PM-01, PS-06, SI-04 (50%)
- Art.94(1) Powers of competent authorities — supervisory and investigatory powers: CA-02, CA-07, AU-01, PM-01 (20%)
- Art.97(1) Professional secrecy — confidentiality of supervisory information: AC-03, AC-06, MP-02, MP-04, PT-01, SC-08, SC-12, SC-28 (52%)
- Art.98(1) Data protection — processing of personal data: PT-01, PT-02, PT-03, PT-04, PT-05, PT-06, PT-07, PT-08, SC-28 (55%)
- Art.111(1) EBA/ESMA guidelines — technical standards and regulatory cooperation: CA-01, CA-02, PM-01, PM-09, RA-01 (20%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=mica
- Control-to-clause mappings as JSON: /api/v1/frameworks/mica?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/mica.json
- Page for people: /frameworks/mica/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
