Stacked gold bars representing safekeeping and crypto custody licensing in 2026
Guides: Licensing & Compliance

What Is a Crypto Custody License? Qualified Custodian Rules Explained in 2026

A crypto custody license authorises a business to safekeep clients' crypto-assets and private keys. This guide explains the MiCA custody service and its EUR 125,000 Class 2 capital, the Article 75 segregation and liability rules, the US qualified custodian concept, hot versus cold storage, proof of reserves, and how to get authorised in 2026.

Reading time~9 minutes
Last updatedJune 2026
CategoryLicensing & Compliance

Meet Dr. Marcus Hartmann

Dr. Marcus Hartmann, Senior Crypto Licensing Advisor
Dr. Marcus Hartmann
Senior Licensing Advisor · Zug, Switzerland
LL.M. International Financial Law · Dr. iur. · Zurich Bar

Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through the full spectrum of crypto-asset service provider licensing, where custody and key-management controls are now among the most heavily scrutinised parts of any application.

He has built custody and safekeeping frameworks for clients authorised under MiCA in the EU, under banking and DLT law in Switzerland, and against the US qualified custodian standard, and advises on segregation, sub-custody delegation, and proof of reserves across more than 60 jurisdictions.

22 years in financial services regulation
400+ crypto licensing mandates across 60+ jurisdictions
Certified AML Officer (ACAMS), FINMA-registered
Fluent in English, German, and French
View Full Profile →
Definition · Crypto Custody License

A crypto custody license is the regulatory authorisation a business needs to safekeep crypto-assets, or the private keys that control them, on behalf of clients. In the EU it is the MiCA service of custody and administration of crypto-assets on behalf of clients, carried out under a crypto-asset service provider authorisation rather than a standalone permit.

Key Takeaways
  • A crypto custody license authorises a firm to safekeep clients' crypto-assets and the private keys that control them, with strict segregation and liability rules
  • Under MiCA, custody and administration of crypto-assets sits in Class 2 of Annex IV and carries a permanent minimum capital of EUR 125,000
  • MiCA Article 75 requires a custody agreement, a register of positions, operational segregation, a custody policy, and liability for loss capped at market value
  • The US uses the qualified custodian concept under the Investment Advisers Act Custody Rule rather than a single federal custody license
  • Custodians keep most assets in cold storage and use proof of reserves to evidence that client balances are fully backed

What a Crypto Custody License Actually Is

Custody is the act of safekeeping something valuable for someone else. In crypto, that value lives behind a private cryptographic key: whoever controls the key controls the assets. A crypto custody license is the regulatory permission a business needs before it can hold those keys, and therefore those assets, on behalf of clients. It is one of the most sensitive activities in the sector, because a single key compromise can wipe out client funds in seconds.

In the European Union, the relevant rules sit inside the Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114. MiCA defines the service of custody and administration of crypto-assets on behalf of clients as the safekeeping or control of crypto-assets, or of the means of access to them in the form of private keys, for clients. It is not a separate license but one of the services a crypto-asset service provider, or CASP, can be authorised to perform. If you are new to the broader framework, our explainer on what a crypto license is and how the categories fit together sets the scene.

Custody is closely tied to the wider concept of a Virtual Asset Service Provider. A firm that safekeeps client crypto is a VASP under FATF terminology and a CASP under MiCA. Our companion guide on what a VASP is and which businesses fall in scope shows exactly where custodians sit in that taxonomy, and our custody license overview covers how the authorisation works in practice.

€125k
MiCA Class 2 Min. Capital
Class 2
MiCA Annex IV Tier
Art. 75
MiCA Custody Article
3 mo.
Statement of Position
80–90%
Assets in Cold Storage
2023/1114
MiCA Regulation Number

Sources: Regulation (EU) 2023/1114 (MiCA) Annex IV and Article 75; industry custody-practice norms for cold-storage allocation.

When You Need a Custody License

The trigger is simple: if you safekeep crypto-assets or control the private keys for clients, you almost certainly need authorisation. The dividing line is control. A firm that holds its own assets is self-custodying and generally needs no custody license. A firm that holds keys, or the means of access, on behalf of others is providing a regulated custody service and falls in scope.

This catches more businesses than founders expect. An exchange that lets users keep balances on the platform is custodying their assets. A staking provider that pools client tokens, a payment processor that holds crypto before settlement, and a wallet provider that retains the keys are all, in substance, custodians. Even brief or temporary holding can cross the line once the firm has the technical ability to move client assets without further instruction.

Non-custodial models are the main carve-out. A pure software wallet where the user alone controls the keys, or a genuinely non-custodial protocol, typically does not require a custody license because the provider never holds the means of access. The distinction matters commercially: many providers deliberately design for non-custody to stay outside the heaviest part of the regime. Our wallet license overview explains how custodial and non-custodial wallet models are treated differently.

MiCA Custody Requirements Under Article 75

MiCA is the most detailed custody framework in force in 2026. Custody and administration of crypto-assets sits in Class 2 of Annex IV, which carries a permanent minimum capital requirement of EUR 125,000. The custodian must also hold own funds equal to at least one quarter of the previous year's fixed overheads where that figure is higher. Capital is only the entry ticket. The operating rules in Article 75 are what regulators inspect most closely.

Article 75 obliges a custodian to conclude a custody agreement with each client setting out duties and responsibilities, to keep a register of positions opened in the name of each client, and to operationally segregate clients' crypto-assets from the firm's own holdings and from its estate. That segregation is the heart of client protection: it is what keeps client assets ring-fenced if the custodian itself fails. The custodian must also maintain a custody policy designed to minimise the risk of loss from fraud, cyber threats, or negligence, and must send each client a statement of position at least once every three months and on request.

Crucially, MiCA imposes liability for loss. Where crypto-assets, or the means of access to them, are lost as a result of an incident attributable to the custodian, such as a hack of its own systems, the custodian is liable to the client. That liability is capped at the market value of the lost crypto-asset at the time the loss occurred. The exposure is therefore real but bounded, which is why robust key management and insurance arrangements are central to any credible custody application.

Obligation What MiCA Article 75 Requires
Capital EUR 125,000 (Class 2) or 25% of fixed overheads, whichever is higher
Custody agreement Written contract with each client setting out duties and responsibilities
Register of positions Positions opened in the name of each client; movements recorded
Segregation Client assets operationally segregated from the custodian's own estate
Custody policy Internal rules minimising loss from fraud, cyber threats, or negligence
Liability for loss Liable for attributable losses, capped at market value at time of loss
Statement of position Provided to each client at least once every three months and on request

Based on Regulation (EU) 2023/1114 (MiCA) Annex IV and Article 75. National competent authorities may apply additional supervisory expectations.

"Founders budget for the EUR 125,000 and stop there, but capital is never what derails a custody application. What regulators dig into is the key-management architecture: how keys are generated, who can sign, how cold and hot wallets are split, and how the firm evidences segregation. Build that story before you file, not in response to questions."

Dr. Marcus Hartmann, Senior Licensing Advisor

MiCA vs US Qualified Custodian vs Switzerland

Crypto custody is regulated very differently across the major markets, and the right route depends on where you operate and who your clients are. The EU offers a single, codified custody service under MiCA. The United States has no equivalent federal custody license and instead leans on the qualified custodian concept. Switzerland folds crypto custody into its banking and DLT framework. Our regulation hub tracks how individual countries treat the activity.

In the United States, the key rule is the Custody Rule, 17 CFR 275.206(4)-2, under the Investment Advisers Act of 1940. A registered investment adviser with custody of client assets, including crypto held as securities, must keep those assets with a qualified custodian: a bank or savings association, a registered broker-dealer, a registered futures commission merchant, or certain foreign financial institutions. In September 2025 the SEC staff issued a no-action letter allowing advisers to treat certain state-chartered trust companies as banks for crypto custody, subject to conditions such as annual due diligence and no rehypothecation of client assets.

In Switzerland, FINMA Guidance 01/2026 confirms that banks may hold crypto-based assets as segregable custody assets that benefit from bankruptcy protection, provided the assets are held in readiness for clients at all times in individual custody, or in collective custody with clear customer shares. Where custody is delegated abroad, the foreign custodian must be prudentially supervised and foreign law must guarantee bankruptcy protection. The Swiss model treats well-structured crypto custody much like the safekeeping of any other client asset.

Jurisdiction Framework License Type Key Feature
European Union MiCA (Reg. 2023/1114) CASP authorisation, custody service EUR 125,000 capital; Article 75 segregation and liability
United States Investment Advisers Act No federal custody license; qualified custodian Custody Rule 206(4)-2; banks, broker-dealers, FCMs, trust cos.
Switzerland Banking & DLT law (FINMA) Banking / securities authorisation Segregable custody assets with bankruptcy protection (Guidance 01/2026)

Why this matters for licensing: the same custody business can require an EU CASP authorisation, a relationship with a US qualified custodian, or a Swiss banking-grade setup, depending on the market. The choice shapes your capital, governance, and timeline, so it belongs at the start of your jurisdiction selection. See our custody license overview for how this fits the full application.

◆ Need Help?

Unsure whether your model needs a custody license? Get a free 30-minute consultation. We will assess your custody arrangements and recommend a licensing route across the EU, US, and Switzerland.

Get Free Consultation →

Hot Storage, Cold Storage & Proof of Reserves

A custody license is granted on paper, but it stands or falls on the technical safekeeping of keys. The first decision every custodian makes is how to split assets between hot and cold storage. A hot wallet is connected to the internet, which makes it convenient for trading, withdrawals, and day-to-day movement, but also exposes it to cyber attack. Cold storage keeps private keys offline on hardware or air-gapped devices, which is far more secure but slower to access.

The industry norm reflects that trade-off. Institutional custodians typically keep 80 to 90 percent of assets in cold storage as long-term reserves and only 10 to 20 percent in hot wallets to support operational activity. Most also layer in multi-signature or multi-party computation so that no single person can move funds, alongside withdrawal whitelists, time delays, and crime insurance. Regulators reviewing a custody application expect to see this architecture documented, not improvised.

Proof of reserves has become the public-facing complement to segregation. It is a cryptographic attestation, often built on a Merkle tree, that the custodian holds enough crypto-assets to cover every client balance. Each client can verify that their balance was included in a snapshot without exposing any other account, and an independent auditor usually certifies the result. After several high-profile collapses, regulators and counterparties increasingly treat a credible proof-of-reserves process as a baseline expectation rather than a marketing extra.

From Our Practice

In our custody licensing work across more than 60 jurisdictions, the single most common reason an application stalls is a key-management model the firm cannot fully explain. The founders have a custody provider and a cold-storage setup, but they cannot map who holds which signing key, how the hot and cold split is enforced, or how segregation is evidenced if the company itself fails. Regulators read that gap as operational risk.

We also see firms underestimate the liability dimension. Under MiCA, a custodian is on the hook for the market value of assets lost in an attributable incident, so the custody policy, insurance cover, and incident-response plan are not paperwork: they are the controls that cap that exposure. Building the safekeeping architecture, segregation evidence, and proof-of-reserves process together, before filing, is consistently the difference between a clean review and months of regulator queries.

How to Get a Custody License Authorised

Getting authorised for crypto custody is a structured process, not a form-filling exercise. The five steps below describe the core path a firm follows to a MiCA custody authorisation, which is broadly representative of how regulated markets approach the activity. Our AML and KYC compliance service and licensing team run this end to end as part of a single engagement.

1
Scope
Confirm custody is in scope and choose a jurisdiction
Establish that your model holds client keys or assets, then select a regime, MiCA CASP in the EU, a qualified custodian relationship in the US, or a Swiss banking-grade setup.
2
Capital & entity
Set up the entity and meet the capital floor
Incorporate the licensed entity, fund the EUR 125,000 MiCA Class 2 minimum or the higher overhead-based figure, and appoint qualified directors and a compliance function.
3
Build controls
Design the custody policy and key management
Document segregation, the hot and cold storage split, multi-signature or MPC signing, the register of positions, insurance, and the proof-of-reserves approach.
4
Apply
File the authorisation application
Submit the application with the business plan, AML framework, custody policy, governance, and IT security model, then respond to the regulator's questions.
5
Operate & report
Maintain the license and report to clients
Once authorised, keep segregation and capital current, issue statements of position at least every three months, and evidence ongoing compliance to the regulator.

Crypto Custody License: Common Questions

A crypto custody license is the regulatory authorisation a business needs to safekeep crypto-assets, or the private keys that control them, on behalf of clients. In the EU this is the MiCA service of custody and administration of crypto-assets on behalf of clients, which forms part of a crypto-asset service provider authorisation rather than a standalone permit.
Yes, if you safekeep crypto-assets or control private keys for clients in a regulated market. Under MiCA, custody and administration of crypto-assets on behalf of clients is a licensed activity, so you must be authorised as a crypto-asset service provider. Pure self-custody, where you only hold your own assets, generally does not require a custody license.
Custody and administration of crypto-assets sits in Class 2 of MiCA Annex IV, which carries a permanent minimum capital requirement of EUR 125,000. The provider must also hold own funds equal to at least one quarter of the preceding year's fixed overheads where that figure is higher than the permanent minimum.
A qualified custodian is a term from the US Investment Advisers Act Custody Rule, 17 CFR 275.206(4)-2. It means a bank or savings association, a registered broker-dealer, a registered futures commission merchant, or certain foreign financial institutions that hold client assets segregated from their own. Registered investment advisers with custody must use one.
Article 75 requires a custodian to conclude a custody agreement with each client, keep a register of positions opened in each client's name, operationally segregate client crypto-assets from its own estate, maintain a custody policy that minimises loss from fraud, cyber threats, or negligence, and provide a statement of position at least once every three months.
Under MiCA Article 75, a custodian is liable to clients for the loss of crypto-assets or of the means of access resulting from an incident attributable to it, such as a hack of its systems. That liability is capped at the market value of the lost crypto-asset at the time the loss occurred, so the exposure is significant but defined.
A hot wallet is connected to the internet, which makes it convenient for trading and withdrawals but more exposed to cyber attack. Cold storage keeps private keys offline on hardware or air-gapped devices, which is far more secure. Institutional custodians typically keep 80 to 90 percent of assets in cold storage and only 10 to 20 percent hot.
Proof of reserves is a cryptographic attestation, often built on a Merkle tree, that a custodian or exchange holds enough crypto-assets to cover all client balances. Clients can verify their balance was included in the snapshot without exposing other accounts. It is usually certified by an independent auditor to confirm solvency at a point in time.
There is no single federal crypto custody license. Registered investment advisers must keep client crypto held as securities with a qualified custodian under the Investment Advisers Act Custody Rule. In September 2025 the SEC staff issued a no-action letter allowing advisers to treat certain state-chartered trust companies as banks for crypto custody, subject to conditions.
Switzerland treats crypto custody under banking and DLT law, supervised by FINMA. FINMA Guidance 01/2026 confirms that banks may hold crypto-based assets as segregable custody assets with bankruptcy protection, provided they are kept ready for clients at all times in individual custody or in collective custody with clear customer shares.
They overlap but are not identical. A custody license covers safekeeping and administration of clients' crypto-assets and private keys with full segregation and liability rules. A wallet license is a looser, marketing-driven term often used for providers that hold keys for users. In a MiCA context both map to custody and administration of crypto-assets on behalf of clients.
Timelines vary by jurisdiction and the quality of the application. A MiCA crypto-asset service provider authorisation that includes custody typically takes several months from a complete filing, because the regulator must assess capital, governance, the custody policy, segregation arrangements, and the IT and key-management security model before granting authorisation.
Yes, custody can be delegated to a sub-custodian, but the licensed firm remains responsible to clients and to the regulator. Under FINMA Guidance 01/2026, delegation to a foreign custodian is acceptable where that custodian is prudentially supervised and foreign law guarantees bankruptcy protection for the crypto-based assets held in custody.
Custody is one of several crypto-asset services a provider can be authorised for, alongside exchange, order execution, and transfer services. Many exchanges add custody to hold client assets in-house. Regulators expect the custody policy, segregation, key management, and proof-of-reserves approach to be evidenced as part of the overall license application.

Sources & Official References

MH
Senior Licensing Advisor · LL.M. International Financial Law
22 years in financial services regulation. Advised 400+ crypto licensing mandates across 60+ jurisdictions. Based in Zug, Switzerland.
Free Consultation

Get Your Crypto Custody License Right From Day One

Share your custody model and target markets, and we will assess whether you need a license, recommend the right jurisdiction, and build the segregation, key-management, and proof-of-reserves framework regulators expect to see. No obligation.

  • 🇨🇭 Swiss-registered firm, Zug
  • ⚡ Response within 24 hours
  • 🔒 Strictly confidential
  • ✓ 80+ jurisdictions covered

Confidential · No obligation · No spam