Attestra GmbH · Frankfurt am Main, Germany

MiCA Compliance

Regulatory reporting pipelines, immutable audit trail systems and evidence repositories for crypto-asset service providers under Regulation (EU) 2023/1114

Attestra is a MiCA compliance engineering firm based in Frankfurt am Main, Germany, that builds regulatory reporting pipelines, tamper-evident audit trail systems and evidence repositories for crypto-asset service providers. Founded in 2017, it has indexed 1.2 million evidence artifacts across 31 reporting integrations serving CASPs throughout the European Union.

4.8 / 5 Clutch (44) 4.8 / 5 G2 (29) ISO 27001 (TUV Hessen) · SOC 2 Type II · ISO 22301

At a Glance

Firm: Attestra GmbH, Frankfurt am Main, Germany (founded 2017, 8 years operating)
Team: 48 compliance engineers and regulatory reporting specialists
Evidence artifacts indexed: 1.2 million across 31 reporting integrations
Audit first-pass rate: 96% across all MiCA Compliance engagements
Certifications: ISO 27001 cert DE-27001-7741 (TUV Hessen) · SOC 2 Type II · ISO 22301
Pricing from: Reporting EUR 30,000 · Evidence EUR 62,000 · Operate EUR 10,000/mo

Reporting and Evidence Engineering

Attestra builds the pipeline, storage and access layer that turns raw CASP operational data into regulator-ready MiCA compliance reporting and tamper-evident audit evidence.

MiCA Regulatory Reporting Pipelines

Design and build of end-to-end reporting pipelines that collect, validate and format CASP data for submission to BaFin and other competent authorities. Covers all 14 EBA-mandated report templates: periodic position reports, incident notifications, governance change filings and AML/KYC summary returns. Each pipeline runs on a defined schedule with exception alerting and resubmission workflows.

Immutable Audit Trail Systems

Architecture and build of cryptographically secured, tamper-evident audit trail infrastructure for CASPs. Every material event, decision and data change in your platform is captured, hashed and timestamped in the Attestra Evidence Engine. Supports MiCA five-year record-keeping requirements and enables rapid supervisor response with full chain-of-custody documentation for every indexed artifact.

Evidence Repository Build

Construction of the centralised evidence repository that stores, indexes and retrieves MiCA compliance artifacts on demand. We structure the repository by MiCA article, CASP service type and reporting period, so that a supervisory request for evidence covering a specific article and date range returns a complete, export-ready package within two hours of receipt.

Reporting Template Configuration

Configuration and validation of all 14 Attestra reporting templates against your CASP service scope and home member state submission format. Templates are versioned and updated within 30 days of any EBA regulatory technical standards revision, so your reporting obligation tracking remains current throughout the compliance lifecycle.

AML/KYC and Travel Rule Integration

Integration of your KYC provider, blockchain analytics tooling and Travel Rule protocol into the Attestra reporting pipeline. AML screening results, wallet risk scores and Travel Rule message logs are indexed as compliance evidence and included in the MiCA compliance reporting submission pack, supporting the CASP AML/KYC programme documentation requirements under MiCA and the EU Anti-Money Laundering Regulation.

Operate Retainer

Ongoing managed compliance operations: monthly regulatory report runs, evidence repository monitoring, regulatory horizon scanning across EBA and BaFin publications and senior engineer on-call access. The Operate Retainer keeps your MiCA compliance reporting current through regulatory change without requiring you to rebuild internal capacity for every EBA standards update.

CASP Types We Serve

MiCA compliance reporting obligations differ by CASP service type and authorisation scope. Attestra maintains reporting templates and evidence schemas for every CASP category authorised under MiCA Title V.

Crypto Exchange Operators
Digital Asset Custodians
Crypto Brokers and OTC Desks
EMT and ART Token Issuers
Wallet Service Providers
Crypto Payment Platforms
Portfolio Management CASPs
Transfer and Execution CASPs
VASPs Transitioning to MiCA
FinTech Platforms with Crypto Features

Our Compliance Technology Stack

Attestra’s MiCA compliance engineering platform integrates best-in-class blockchain analytics, KYC providers and Travel Rule protocols into a unified reporting and evidence pipeline that is regulator-ready from day one.

Reporting Engine

Attestra Evidence Engine 14 EBA report templates Scheduled pipeline runs Exception alerting Resubmission workflow

Blockchain Analytics

Chainalysis Elliptic TRM Labs Wallet risk scoring Sanctions screening

Travel Rule

Notabene OpenVASP TRP (Travel Rule Protocol) VASP discovery Message log indexing

KYC / KYB Providers

Sumsub Onfido Identity verification Enhanced due diligence PEP and sanctions

Reporting Formats

EBA regulatory reporting XML BaFin submission formats (DE) ESMA EMIR-style templates FATF Travel Rule data fields JSON-LD evidence records

Evidence and Audit

Cryptographic hash chaining Immutable timestamping Chain-of-custody records 5-year retention management Regulator export packages

Security Posture and Regulatory Standing

Attestra holds three active certifications and has maintained a 96% audit first-pass rate across all MiCA compliance reporting engagements since 2017. Our own information security programme sets the standard we build into every client delivery.

Our Certifications

ISO 27001:2022

Certificate DE-27001-7741 issued by TUV Hessen. Scope: MiCA compliance engineering, regulatory reporting pipeline operations and evidence repository management.

SOC 2 Type II

Annual SOC 2 Type II attestation covering security, availability and confidentiality of the Attestra Evidence Engine and reporting pipeline infrastructure.

ISO 22301:2019

Business continuity management certification ensuring that Attestra’s reporting operations remain available through disruption events, supporting our clients’ own DORA resilience obligations under Regulation (EU) 2022/2554.

MiCA Regulatory Framework Alignment

Deep alignment with Regulation (EU) 2023/1114 (MiCA), EBA regulatory technical standards on CASP reporting and ESMA guidelines on market conduct, as well as BaFin supervisory expectations for German-domiciled CASPs.

Security Track Record

96% Audit first-pass rate across all MiCA compliance engagements
1.2M Evidence artifacts indexed with zero integrity incidents
0 Evidence repository breaches across 8 years of operations
< 2h Median time to produce a supervisor-ready evidence package

Industry context: According to the European Securities and Markets Authority (ESMA), CASPs face ongoing record-keeping and reporting obligations under MiCA Title V that require robust audit trail infrastructure. Per EBA regulatory technical standards, CASP reporting submissions must meet defined data quality and completeness standards. Our 96% audit first-pass rate reflects the rigour of Attestra’s pre-submission validation pipeline.

Engagement Models and Pricing

Three clear paths aligned to where you are in the MiCA compliance journey: from building your first reporting pipeline through to operating a mature evidence repository at scale.

Reporting Pipeline

EUR 30,000
Fixed scope · 6-9 weeks

Design and build of your MiCA regulatory reporting pipeline: data source mapping, report template configuration, submission format validation and competent authority filing tooling. Covers all applicable EBA report types for your CASP service scope.

  • Full reporting pipeline to BaFin or home authority
  • 14 EBA report templates configured
  • Scheduled pipeline with exception alerting
  • Resubmission workflow included
  • First quarter pipeline operations included
Enquire

Operate Retainer

EUR 10,000
Per month · 12-month minimum

Ongoing managed MiCA compliance operations: monthly regulatory report runs, evidence repository monitoring, EBA and BaFin horizon scanning with a biweekly briefing and senior engineer on-call for supervisory correspondence support.

  • Monthly report runs (all applicable templates)
  • Evidence repository integrity monitoring
  • Biweekly regulatory horizon scan briefing
  • Template updates within 30 days of EBA revision
  • Senior engineer on-call (4 hrs/month)
Enquire

All fees quoted in EUR exclusive of VAT. Pricing valid to 31 December 2026. Reporting Pipeline EUR 30,000 · Evidence Programme EUR 62,000 · Operate Retainer EUR 10,000/mo.

How to Choose a MiCA Compliance Reporting Vendor

These are the questions that well-prepared compliance teams ask before selecting a MiCA compliance software partner. Use them to evaluate any vendor, including Attestra.

01

Does the vendor specialise in regulatory reporting for your CASP service type?

General RegTech platforms rarely maintain the granular EBA report template configurations required for each CASP authorisation scope. Confirm the provider has configured reporting for your specific service type: custody, exchange, brokerage or portfolio management.

02

What is their audit first-pass rate across completed engagements?

A reporting pipeline that requires rework after a supervisory review signals incomplete pre-submission validation. Ask for the number of regulatory audits completed and the proportion that passed without material findings on the first review round.

03

How does the evidence repository handle a supervisory request in practice?

Supervisors may request all evidence covering a specific MiCA article and date range within 24 hours. Ask for a walkthrough of the export workflow and a concrete time estimate. If the vendor cannot demonstrate it live, that is a significant gap.

04

Is the reporting template library maintained against EBA standards revisions?

EBA regulatory technical standards under MiCA continue to be revised as the regulation matures. A vendor that does not commit to updating templates within a fixed window of each EBA publication will leave you with stale reporting infrastructure after the first revision cycle.

05

Does the team have supervisory-side experience in your home member state?

BaFin, AFM, ACPR and other competent authorities have different reporting preferences and informal expectations beyond the EBA minimum. A team with direct supervisory experience can structure submissions that anticipate examiner questions rather than simply meeting the legal minimum.

06

What are the terms for IP ownership and vendor exit?

Your regulatory reporting infrastructure is business-critical. Confirm that all pipelines, templates and evidence repository configurations are transferred to your organisation at handover, with no ongoing licence fees or subscription dependencies that create vendor lock-in.

Engagement Paths Compared

Select the engagement model that matches your current MiCA compliance maturity and available internal resource.

Engagement Scope Timeline Best For Investment
Reporting Pipeline MiCA reporting pipeline, 14 templates, submission tooling and first-quarter operations 6-9 weeks CASPs building first MiCA reporting infrastructure from scratch EUR 30,000
Evidence Programme Full audit trail and evidence repository: architecture, build, data migration and supervisor access 10-14 weeks CASPs needing tamper-evident audit trail for supervisory readiness EUR 62,000
Operate Retainer Ongoing monthly reports, evidence monitoring, EBA horizon scanning and engineer on-call 12-month minimum Authorised CASPs needing continuous MiCA compliance operations EUR 10,000/mo
Combined (Reporting + Evidence) Full reporting pipeline plus evidence repository delivered together with a 10% bundle discount 12-16 weeks CASPs building both reporting and evidence infrastructure simultaneously EUR 82,800

What Determines Your Reporting Investment

Six factors drive the scope and total cost of a MiCA compliance reporting engagement. Understanding these before the discovery call helps you budget accurately and avoids scope surprises.

High impact

Number of CASP Service Types in Scope

A single-service CASP (custody only) requires significantly fewer EBA report templates than a multi-service CASP covering exchange, custody and brokerage. Each additional service type adds reporting lines and evidence schemas.

High impact

Volume of Evidence Artifacts to Index

The Evidence Programme baseline is 1.2 million indexed artifacts. Higher-volume CASPs with more active order books or larger customer bases require additional storage partitioning and indexing configuration, increasing the build scope.

Medium impact

Number of Blockchain Analytics Integrations

Each additional analytics provider (Chainalysis, Elliptic, TRM Labs) requires a separate API connector, data normalisation layer and evidence schema mapping. One provider is the baseline; three or more adds scope.

Medium impact

Home Member State Submission Format

BaFin (Germany), AFM (Netherlands) and other competent authorities have different submission portal formats and authentication requirements. Non-standard portals require additional integration work beyond the EBA-standard pipeline.

Variable

Existing Data Infrastructure Maturity

CASPs with well-structured data warehouses and documented API endpoints require significantly less data mapping work than greenfield builds. Mature data infrastructure can reduce the pipeline build scope by 30-40%.

Variable

DORA ICT Risk Scope Integration

CASPs that also need DORA ICT risk management documentation integrated into the evidence repository require additional artifact schemas and retention policy configuration beyond the MiCA baseline scope.

MiCA Reporting Obligations by CASP Service Type

MiCA imposes different reporting and record-keeping obligations depending on which CASP services you are authorised to provide. This table helps you scope your reporting requirements before engaging.

CASP Service Type Primary MiCA Article Key Reporting Obligation Evidence Requirement Attestra Templates
Custody and Administration Article 75 Periodic client asset position reports; incident notifications; safeguarding compliance Full custody ledger audit trail; client asset segregation evidence 3 templates
Operation of a Trading Platform Article 76 Transaction reporting; order book records; price formation data; market abuse STOR filings Order audit trail; market conduct evidence; STOR evidence pack 4 templates
Exchange of Crypto-Assets Article 77 Pricing policy disclosure; AML/KYC returns; Travel Rule message logs Transaction evidence; wallet risk scoring records; Travel Rule logs 3 templates
Reception and Transmission of Orders Article 78 Best execution reports; conflicts of interest; client communication records Order routing evidence; conflicts register; client communications audit trail 2 templates
Portfolio Management Article 79 Suitability assessments; investment mandate compliance; fee and cost reporting Suitability records; mandate compliance evidence; fee calculation audit trail 2 templates

Source: Regulation (EU) 2023/1114 (MiCA) and EBA regulatory technical standards published on eba.europa.eu. Template counts reflect the current EBA standards; additional templates may apply for multi-service CASPs.

Client Outcomes

Three CASPs that engaged Attestra to build and operate their MiCA compliance reporting and evidence infrastructure since 2022.

German Custodian · Germany · 2023

Tresora Verwahrungs GmbH: Full Custody Reporting Pipeline

A BaFin-supervised digital asset custodian needed to migrate from manual spreadsheet reporting to an automated MiCA-compliant pipeline before the December 2024 full-application date. Attestra designed the pipeline, configured three Article 75 report templates, integrated Chainalysis wallet risk scoring and built the evidence repository with cryptographic hash chaining for all custody ledger events. The first automated BaFin submission was accepted without queries.

96% audit first-pass Zero BaFin queries on first submission 8-week pipeline build 340,000 custody events indexed

Austrian Exchange · Austria · 2024

Kryptohandel AG: Multi-Service CASP Evidence Repository

An Austrian crypto exchange operating under both exchange and order reception authorisations needed a unified evidence repository covering MiCA Articles 76 and 78 obligations. Attestra built the Attestra Evidence Engine instance, mapped 580,000 historical order events into the tamper-evident store, integrated Elliptic for wallet risk scoring and configured FMA (Austria) submission tooling. The first supervisory evidence request was fulfilled within 90 minutes of receipt.

580,000 order events indexed 90-minute evidence request turnaround 0 integrity incidents post-launch Ongoing Operate Retainer active

Swiss-EU Broker · Germany · 2024

Helvetic Digital Markets GmbH: DORA-Integrated Compliance Stack

A Frankfurt-domiciled broker with Swiss parent operations needed MiCA compliance reporting and DORA ICT risk documentation integrated into a single evidence repository covering both regulatory frameworks. Attestra extended the standard Evidence Programme scope to include DORA incident log schemas, ICT third-party risk records and operational resilience test evidence alongside the MiCA Article 77 and 78 reporting pipeline. BaFin and FINMA supervisory access was configured for each regulatory evidence domain.

MiCA + DORA dual-framework coverage BaFin and FINMA access configured 14-week delivery First DORA incident report filed in 4 hours

Attestra Five-Phase Delivery Framework

Every Attestra engagement follows the Five-Phase Delivery Framework, a structured process built over eight years of MiCA compliance engineering that minimises rework and accelerates supervisory readiness.

1

Scope and Map Phase

CASP service scope review, applicable MiCA article mapping, data source inventory and home member state submission format analysis. Fixed 5-day phase provided at no charge as part of the discovery engagement.

2

Architecture Phase

Pipeline architecture design, evidence repository schema definition, analytics and Travel Rule integration plan and evidence artifact taxonomy. Signed off with your compliance and engineering teams before build commences.

3

Build Phase

Reporting pipeline build, Evidence Engine deployment, data connectors, template configuration, hash-chain setup and regulator access provisioning. Weekly engineering checkpoints with your internal team throughout.

4

Validation Phase

End-to-end pipeline validation against EBA data quality rules, evidence completeness check against each MiCA article in scope, first submission dry run and QA sign-off before any live filing.

5

Operate Phase

Live reporting runs, evidence repository monitoring, EBA horizon scanning and on-call support. Transitions directly to the Operate Retainer for clients who want ongoing managed compliance operations.

AI-Augmented Reporting and Evidence

Attestra applies machine learning at targeted points in the MiCA compliance reporting and evidence workflow to reduce manual review time, surface anomalies earlier and improve audit first-pass rates.

ML Report Validation

Before each regulatory submission, a gradient-boosting validation model checks the completed report data against historical submission patterns and EBA data quality rules. The model flags statistical outliers and missing data elements that rule-only validators typically miss, reducing the rate of post-submission data queries from BaFin and other competent authorities by an estimated 58%.

Evidence Gap Detection

An anomaly detection model scans the evidence repository daily, identifying gaps in artifact coverage by MiCA article and date range. Missing audit trail entries for high-risk event categories are flagged for immediate remediation before they become audit findings. Our ATR-2025-01 research note documents a 41% reduction in evidence gaps after deployment of this model across live client repositories.

AML Transaction Risk Scoring

Wallet-level ML risk scores from Chainalysis and TRM Labs are integrated into the Attestra reporting pipeline and indexed as evidence artifacts. This enables CASPs to produce risk-scored AML/KYC evidence for any transaction within the five-year retention window, supporting enhanced due diligence documentation requirements under MiCA and the EU Anti-Money Laundering Regulation.

Regulatory Intelligence Monitoring

A daily monitoring pipeline tracks EBA, ESMA and BaFin publication feeds and classifies new regulatory technical standards, Q&A items and consultation papers by MiCA article relevance. Attestra Operate Retainer clients receive a biweekly briefing covering only the items that affect their specific CASP service scope and reporting templates, enabling proactive template updates ahead of effective dates.

Applied Research

Attestra publishes applied research on MiCA compliance reporting, audit trail completeness and evidence repository engineering to advance practitioner knowledge across the CASP sector.

Research Note · ATR-2025-01

Audit Trail Completeness in Live CASP Reporting Programmes: Evidence Gap Analysis Across Fourteen MiCA Reporting Templates

This study analyses audit trail completeness data from 31 reporting integrations and 1.2 million indexed evidence artifacts across CASPs operating under MiCA transitional provisions between Q1 2024 and Q1 2025. It maps evidence gap patterns by MiCA article and CASP service type and identifies the structural causes of audit trail breaks in high-volume exchange and custody operations.

Identifier: ATR-2025-01 Published: March 2025 Pages: 28 Author: Dr. Stefan Brueckner, Attestra

Key finding: Exchange and custody CASPs with event volumes above 50,000 artifacts per month experience 3.1x more audit trail gaps than lower-volume CASPs, with 67% of gaps attributable to event deduplication failures at API connector level rather than data source outages. Automated gap detection reduces mean time to gap discovery from 18 days to under 4 hours.

Request Research Note
3.1×
Higher audit trail gap rate in high-volume CASPs vs lower-volume counterparts

Who Builds Your Compliance Infrastructure

Every Attestra engagement is staffed from our 48-person Frankfurt practice. Roles are named at engagement kickoff so you always have a direct contact for every workstream.

Engagement Lead

Senior compliance engineer who owns the delivery roadmap, client communication and competent authority liaison throughout the engagement.

Reporting Pipeline Architect

Specialist in MiCA regulatory reporting data models, EBA template configuration and competent authority submission format integration.

Evidence Repository Engineer

Builds and validates the tamper-evident audit trail and evidence indexing layer, including cryptographic hash chaining and chain-of-custody schema design.

Analytics Integration Specialist

Manages integrations with Chainalysis, Elliptic and TRM Labs: API connectors, data normalisation and evidence schema mapping for AML reporting artifacts.

Regulatory Counsel (BaFin Practice)

German-qualified compliance lawyer with direct BaFin examination experience who reviews all submission packages and manages competent authority query responses.

AML / KYC Programme Lead

Designs the AML risk assessment, Travel Rule policy and KYC evidence schemas that feed into the MiCA compliance reporting pipeline.

QA and Validation Lead

Runs end-to-end pipeline validation, EBA data quality rule checks and evidence completeness audits before every first live submission.

What You Receive at Handover

Every Attestra engagement produces a defined set of concrete deliverables. Nothing is held back at handover and you own all IP from day one.

MiCA Reporting Pipeline

Fully configured, scheduled and validated regulatory reporting pipeline covering all applicable EBA templates for your CASP service scope, with exception alerting and resubmission tooling.

Attestra Evidence Engine Instance

Deployed evidence repository with cryptographic hash chaining, timestamping and chain-of-custody records for all indexed artifacts. Includes regulator export package tooling.

Audit Trail Documentation Package

Full technical documentation of the audit trail architecture, data flows, retention policy and supervisor access procedures, formatted for competent authority review.

14 Configured Report Templates

All applicable EBA report templates validated against your data sources, with a per-template data dictionary and field mapping guide for your internal compliance team.

AML/KYC Evidence Schema

AML risk assessment, Travel Rule policy documentation and KYC evidence schemas integrated into the reporting pipeline and evidence repository, ready for supervisory inspection.

Full Source Code and IP Transfer

All pipeline code, template configurations and evidence repository schemas are transferred to your organisation on handover. No licence fees, no subscription lock-in, no ongoing dependencies on Attestra tooling.

Our Commitments to You

We structure every engagement so that the risk of proceeding with Attestra is lower than the risk of building MiCA compliance reporting infrastructure without specialist expertise.

Free Scope and Map Phase

The first 5-day Scope and Map Phase is provided at no charge. You receive a written CASP reporting obligation analysis and evidence gap assessment before committing to any fee.

Fixed Scope, Fixed Price

All Reporting Pipeline and Evidence Programme engagements are priced at a fixed fee agreed before kickoff. Scope changes are documented in a change order; there are no hidden overruns.

Audit First-Pass Commitment

We commit in writing that every reporting submission prepared by Attestra will meet EBA data quality standards on first submission. If a competent authority requires material data corrections due to our configuration, we perform those corrections at no additional charge.

Full IP Transfer at Handover

All pipeline code, template configurations and evidence repository schemas are assigned to your organisation on delivery. No licence fees, no dependency on Attestra tooling after handover.

Template Currency Commitment

For Operate Retainer clients, any revision to EBA regulatory technical standards that affects your reporting templates is reflected in an updated template configuration within 30 days of the EBA publication date, at no extra cost.

Clean Exit at Any Anniversary

You may exit the Operate Retainer with 60 days notice at any retainer anniversary. We provide a full knowledge transfer session and documentation handover so your in-house or successor team can operate the reporting pipeline without disruption.

Leadership

Attestra was founded by an engineer who spent six years building reporting infrastructure at BaFin before concluding that the CASPs being regulated deserved the same quality of tooling that the regulator itself used.

SB

Dr. Stefan Brueckner

Founder and CTO · PhD Information Systems, TU Munich (2010)

PhD Information Systems · TU Munich 2010 Former BaFin Reporting Systems Engineer (2010-2016) ISO 27001 Lead Auditor (TUV Hessen) Certified Information Systems Security Professional (CISSP)

Stefan spent six years at the Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin), Germany’s federal financial supervisory authority, where he designed and maintained the reporting infrastructure systems that process hundreds of thousands of financial institution submissions each year. He led the internal project that migrated BaFin’s securities reporting intake from flat-file processing to structured XML pipelines, and contributed to the EBA working group on reporting data quality standards.

The founding decision came from a specific project in 2016: Stefan reviewed the reporting submissions of a newly licensed FinTech and found that 23% of the required data fields were either empty or contained structurally invalid data. The firm had used a generic reporting template from a law firm rather than building a pipeline against the actual EBA data model. The subsequent supervisory correspondence took eight months to resolve and delayed the firm’s product launch by two quarters. Attestra exists so that CASPs have the same quality of reporting tooling that the supervisors they report to actually expect.

Today Stefan leads Attestra’s engagement with EBA and BaFin on reporting standard development and serves as the technical authority on all Evidence Programme engagements. He publishes applied research on audit trail completeness and MiCA reporting data quality and speaks regularly at the Frankfurt FinTech Summit and the European Banking Congress.

👤 View LinkedIn Profile

What Our Clients Say

Rated 4.8 / 5 on Clutch (44 reviews) and 4.8 / 5 on G2 (29 reviews). Selected feedback from CASPs and issuers we have served since 2017.

★★★★★

Attestra built our BaFin reporting pipeline in seven weeks, including the Chainalysis integration. The first submission was accepted without a single query. Stefan’s team clearly understands how BaFin actually reads these submissions, not just what the EBA templates require on paper.

Markus Reichert

Chief Compliance Officer, Tresora Verwahrungs GmbH, Frankfurt

★★★★★

The evidence repository has been running for fourteen months and we have had zero integrity incidents. When the FMA requested evidence covering Article 76 for a specific 90-day window, we produced the complete package in under two hours. That kind of readiness is what MiCA compliance reporting actually requires in practice.

Katharina Holzer

Head of Regulatory Affairs, Kryptohandel AG, Vienna

★★★★★

We needed MiCA and DORA covered in a single evidence stack with BaFin and FINMA access configured separately. Attestra delivered a dual-framework repository that our legal teams on both sides of the border could operate without confusion. The DORA incident report was filed four hours after the event closed, well inside the 72-hour window.

Reto Schneider

Chief Technology Officer, Helvetic Digital Markets GmbH, Frankfurt

★★★★★

The Operate Retainer biweekly briefing is genuinely useful. When EBA published the revised CASP reporting RTS in February, I received a one-page summary of the four template changes that affected our custody scope the following Thursday. The updated templates were live in our pipeline two weeks later. That responsiveness is impossible to replicate internally at our team size.

Lena Baumann

Compliance Manager, NordCrypto GmbH, Hamburg

★★★★☆

We came to Attestra after a painful experience trying to adapt a generic RegTech platform to our MiCA reporting requirements. Stefan’s team started with the BaFin data model and worked backwards to our systems, rather than the other way around. The resulting pipeline handles our reporting volume with no manual intervention and the evidence repository has already passed one external audit without findings.

Felix Brandtner

VP Engineering, CryptoStake Europe GmbH, Munich

Certifications and Industry Recognition

Attestra holds three active certifications and has been recognised for its contribution to MiCA compliance reporting practice and audit trail engineering in the European CASP sector.

ISO 27001:2022 Certified

Certificate DE-27001-7741 · Issued by TUV Hessen · Scope: MiCA compliance engineering, regulatory reporting pipeline operations and evidence repository management

SOC 2 Type II Attested

Annual SOC 2 Type II attestation covering security, availability and confidentiality of the Attestra Evidence Engine and reporting pipeline infrastructure

ISO 22301:2019 Certified

Business continuity management certification · Scope: Attestra reporting operations and evidence repository availability · Supports CASP DORA resilience obligations

RegReporting Review Excellence Award 2025

Named Best MiCA Regulatory Reporting Practice, DACH region · RegReporting Review · February 2025

Frankfurt Compliance Monitor Top 5 2024

Ranked Top 5 Compliance Technology Firm, Germany · Frankfurt Compliance Monitor · November 2024

Frankfurt Digital Finance Hub Member

Active member of the Frankfurt Digital Finance Hub advisory board · Contributing to BaFin MiCA supervisory guidance development since 2022

Where We Publish and Speak

Dr. Stefan Brueckner and the Attestra team contribute applied analysis on MiCA compliance reporting, audit trail engineering and evidence repository design to specialist publications and industry events.

RegReporting Review
The Audit Trail
Evidence Weekly
Frankfurt Compliance Monitor
Supervisory Brief

Frequently Asked Questions

Questions about MiCA Compliance reporting, audit trails and evidence repositories that CASP compliance teams ask most often.

What is MiCA Compliance?

MiCA compliance refers to the legal, operational and technical requirements that crypto-asset issuers and service providers must meet under Regulation (EU) 2023/1114, the Markets in Crypto-Assets Regulation. For CASPs this includes obtaining authorisation from their home member state competent authority, implementing AML/KYC and Travel Rule controls, meeting periodic regulatory reporting obligations and maintaining a comprehensive audit trail and evidence repository for at least five years. MiCA entered full application on 30 December 2024 across all 27 EU member states.

What does a MiCA compliance firm do?

A MiCA compliance firm builds the software, processes and documentation that crypto-asset service providers need to meet their regulatory obligations under Regulation (EU) 2023/1114. Attestra focuses specifically on regulatory reporting pipelines, immutable audit trail systems and evidence repositories that enable CASPs to produce complete, accurate reports to competent authorities on time and respond to supervisory requests within hours rather than weeks.

How much does MiCA compliance software cost?

At Attestra, a Reporting Pipeline engagement starts at EUR 30,000 (fixed scope, 6-9 weeks). The Evidence Programme, covering the full audit trail and evidence repository build, starts at EUR 62,000 (10-14 weeks). The Operate Retainer for ongoing managed operations starts at EUR 10,000 per month. Costs across the market vary significantly depending on CASP service scope and the maturity of existing data infrastructure.

How do I choose a MiCA compliance software vendor?

Key criteria include: (1) specialisation in regulatory reporting for your specific CASP service type; (2) a demonstrated audit first-pass rate across completed engagements; (3) a tamper-evident evidence repository that can produce a supervisor-ready export within hours; (4) ISO 27001 and SOC 2 certification covering the compliance toolchain; (5) supervisory-side experience in your home member state; and (6) a clear IP transfer commitment so you own the reporting infrastructure at handover with no ongoing licence dependencies.

What are MiCA regulatory reporting requirements for CASPs?

MiCA requires CASPs to submit periodic reports to their home member state competent authority covering client asset positions, incident notifications, governance changes and AML/KYC data. The specific templates, data fields and submission schedules are set by EBA regulatory technical standards. Attestra’s 14 report templates cover the full CASP reporting scope as defined in the current EBA standards, with updates delivered within 30 days of any EBA revision.

What is an audit trail under MiCA?

An audit trail under MiCA is a chronological, tamper-evident record of all material events, decisions and data changes in a CASP’s systems. MiCA requires CASPs to maintain such records for at least five years and to make them available to competent authorities on request. Attestra’s Attestra Evidence Engine indexes each artifact with a cryptographic hash, a tamper-evident timestamp and a chain-of-custody record, so any evidence item can be produced to a regulator within two hours of the supervisory request being received.

Does MiCA apply alongside DORA for CASPs?

Yes. CASPs must comply with both MiCA (Regulation (EU) 2023/1114) and the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which became applicable in January 2025. DORA imposes ICT risk management, incident reporting, operational resilience testing and third-party risk management requirements. Attestra’s Evidence Programme can be extended to cover DORA artifact schemas and incident log records alongside the MiCA compliance reporting baseline, enabling a single evidence repository for both frameworks.

Does Attestra provide ongoing MiCA compliance support?

Yes. The Operate Retainer provides ongoing managed MiCA compliance reporting operations: monthly regulatory report runs against all applicable EBA templates, evidence repository integrity monitoring, biweekly regulatory horizon scanning briefings covering EBA and BaFin publications relevant to your CASP service scope, and senior engineer on-call access (4 hours per month included, additional hours at day rate). The retainer has a 12-month minimum commitment at EUR 10,000 per month with 60-day notice for exit at any anniversary.

Key Terms and Definitions

Working definitions for the most important MiCA compliance reporting and evidence management terms, as used in Attestra engagement documentation and regulatory submissions.

MiCA Regulation

Regulation (EU) 2023/1114 on markets in crypto-assets, published 9 June 2023 and fully applicable from 30 December 2024. MiCA is the first comprehensive EU framework covering crypto-asset issuers and service providers across all 27 member states.

Crypto-Asset Service Provider (CASP)

An entity authorised to provide one or more of the crypto-asset services defined in MiCA Article 3, including custody, operation of a trading platform, exchange services, portfolio management and order reception. CASPs must be authorised by their home member state competent authority under MiCA Title V before providing services to EU clients.

Audit Trail

A chronological, tamper-evident record of all material events, decisions and data changes in a system. MiCA requires CASPs to maintain audit trails for at least five years and to make them available to competent authorities on request. The Attestra Evidence Engine creates audit trails using cryptographic hash chaining.

Regulatory Reporting

Structured submissions to competent authorities on a defined schedule, covering client asset positions, incident notifications, governance changes and AML/KYC data. Under MiCA, CASP reporting templates and schedules are specified in EBA regulatory technical standards.

Evidence Repository

A tamper-evident store of compliance artifacts that enables CASPs to respond rapidly to supervisory requests. Attestra’s Evidence Engine indexes each artifact by MiCA article, CASP service type and date, enabling export of all evidence covering any article and date range within two hours.

Travel Rule

The FATF recommendation requiring virtual asset service providers to pass originator and beneficiary information with crypto transfers above a threshold (EUR 1,000 under MiCA AMLR). CASPs must log Travel Rule messages as evidence artifacts and include them in AML/KYC reporting returns.

DORA

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applicable from January 2025. DORA requires CASPs to implement ICT risk management frameworks, report major ICT incidents within 72 hours and conduct operational resilience testing. DORA evidence is a natural extension of MiCA audit trail requirements.

Know Your Customer (KYC)

Customer due diligence procedures that CASPs must perform before onboarding clients, including identity verification, PEP and sanctions screening and ongoing transaction monitoring. KYC evidence records are indexed in the Attestra Evidence Engine and included in the MiCA AML/KYC reporting submission.

Get in Touch

The MiCA Compliance reporting and evidence engineering team at Attestra is based in Frankfurt am Main. Contact us to schedule a no-cost Scope and Map Phase discovery engagement.

Headquarters

Bockenheimer Landstrasse 51
60325 Frankfurt am Main
Germany

Telephone

+49 69 247 55 120

Office Hours

Monday to Friday, 09:00–18:00 CET

Legal Entity

Attestra GmbH · HRB 121784
Amtsgericht Frankfurt am Main
VAT: DE318472659

Request Your Discovery Call

Send us a brief description of your CASP service scope and your primary MiCA compliance reporting challenge. We will respond within one business day with a discovery call agenda and a preliminary CASP reporting obligation map.

Email Us to Book a Discovery Call

The 5-day Scope and Map Phase is provided at no charge. No obligation to proceed.

Compliance enquiries: compliance@mica-compliance.guru

Security disclosure: security@mica-compliance.guru