Meet Dr. Marcus Hartmann
Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through the full spectrum of crypto-asset service provider licensing, where custody and key-management controls are now among the most heavily scrutinised parts of any application.
He has built custody and safekeeping frameworks for clients authorised under MiCA in the EU, under banking and DLT law in Switzerland, and against the US qualified custodian standard, and advises on segregation, sub-custody delegation, and proof of reserves across more than 60 jurisdictions.
A crypto custody license is the regulatory authorisation a business needs to safekeep crypto-assets, or the private keys that control them, on behalf of clients. In the EU it is the MiCA service of custody and administration of crypto-assets on behalf of clients, carried out under a crypto-asset service provider authorisation rather than a standalone permit.
- A crypto custody license authorises a firm to safekeep clients' crypto-assets and the private keys that control them, with strict segregation and liability rules
- Under MiCA, custody and administration of crypto-assets sits in Class 2 of Annex IV and carries a permanent minimum capital of EUR 125,000
- MiCA Article 75 requires a custody agreement, a register of positions, operational segregation, a custody policy, and liability for loss capped at market value
- The US uses the qualified custodian concept under the Investment Advisers Act Custody Rule rather than a single federal custody license
- Custodians keep most assets in cold storage and use proof of reserves to evidence that client balances are fully backed
What a Crypto Custody License Actually Is
Custody is the act of safekeeping something valuable for someone else. In crypto, that value lives behind a private cryptographic key: whoever controls the key controls the assets. A crypto custody license is the regulatory permission a business needs before it can hold those keys, and therefore those assets, on behalf of clients. It is one of the most sensitive activities in the sector, because a single key compromise can wipe out client funds in seconds.
In the European Union, the relevant rules sit inside the Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114. MiCA defines the service of custody and administration of crypto-assets on behalf of clients as the safekeeping or control of crypto-assets, or of the means of access to them in the form of private keys, for clients. It is not a separate license but one of the services a crypto-asset service provider, or CASP, can be authorised to perform. If you are new to the broader framework, our explainer on what a crypto license is and how the categories fit together sets the scene.
Custody is closely tied to the wider concept of a Virtual Asset Service Provider. A firm that safekeeps client crypto is a VASP under FATF terminology and a CASP under MiCA. Our companion guide on what a VASP is and which businesses fall in scope shows exactly where custodians sit in that taxonomy, and our custody license overview covers how the authorisation works in practice.
Sources: Regulation (EU) 2023/1114 (MiCA) Annex IV and Article 75; industry custody-practice norms for cold-storage allocation.
When You Need a Custody License
The trigger is simple: if you safekeep crypto-assets or control the private keys for clients, you almost certainly need authorisation. The dividing line is control. A firm that holds its own assets is self-custodying and generally needs no custody license. A firm that holds keys, or the means of access, on behalf of others is providing a regulated custody service and falls in scope.
This catches more businesses than founders expect. An exchange that lets users keep balances on the platform is custodying their assets. A staking provider that pools client tokens, a payment processor that holds crypto before settlement, and a wallet provider that retains the keys are all, in substance, custodians. Even brief or temporary holding can cross the line once the firm has the technical ability to move client assets without further instruction.
Non-custodial models are the main carve-out. A pure software wallet where the user alone controls the keys, or a genuinely non-custodial protocol, typically does not require a custody license because the provider never holds the means of access. The distinction matters commercially: many providers deliberately design for non-custody to stay outside the heaviest part of the regime. Our wallet license overview explains how custodial and non-custodial wallet models are treated differently.
MiCA Custody Requirements Under Article 75
MiCA is the most detailed custody framework in force in 2026. Custody and administration of crypto-assets sits in Class 2 of Annex IV, which carries a permanent minimum capital requirement of EUR 125,000. The custodian must also hold own funds equal to at least one quarter of the previous year's fixed overheads where that figure is higher. Capital is only the entry ticket. The operating rules in Article 75 are what regulators inspect most closely.
Article 75 obliges a custodian to conclude a custody agreement with each client setting out duties and responsibilities, to keep a register of positions opened in the name of each client, and to operationally segregate clients' crypto-assets from the firm's own holdings and from its estate. That segregation is the heart of client protection: it is what keeps client assets ring-fenced if the custodian itself fails. The custodian must also maintain a custody policy designed to minimise the risk of loss from fraud, cyber threats, or negligence, and must send each client a statement of position at least once every three months and on request.
Crucially, MiCA imposes liability for loss. Where crypto-assets, or the means of access to them, are lost as a result of an incident attributable to the custodian, such as a hack of its own systems, the custodian is liable to the client. That liability is capped at the market value of the lost crypto-asset at the time the loss occurred. The exposure is therefore real but bounded, which is why robust key management and insurance arrangements are central to any credible custody application.
| Obligation | What MiCA Article 75 Requires |
|---|---|
| Capital | EUR 125,000 (Class 2) or 25% of fixed overheads, whichever is higher |
| Custody agreement | Written contract with each client setting out duties and responsibilities |
| Register of positions | Positions opened in the name of each client; movements recorded |
| Segregation | Client assets operationally segregated from the custodian's own estate |
| Custody policy | Internal rules minimising loss from fraud, cyber threats, or negligence |
| Liability for loss | Liable for attributable losses, capped at market value at time of loss |
| Statement of position | Provided to each client at least once every three months and on request |
Based on Regulation (EU) 2023/1114 (MiCA) Annex IV and Article 75. National competent authorities may apply additional supervisory expectations.
"Founders budget for the EUR 125,000 and stop there, but capital is never what derails a custody application. What regulators dig into is the key-management architecture: how keys are generated, who can sign, how cold and hot wallets are split, and how the firm evidences segregation. Build that story before you file, not in response to questions."
Dr. Marcus Hartmann, Senior Licensing Advisor
MiCA vs US Qualified Custodian vs Switzerland
Crypto custody is regulated very differently across the major markets, and the right route depends on where you operate and who your clients are. The EU offers a single, codified custody service under MiCA. The United States has no equivalent federal custody license and instead leans on the qualified custodian concept. Switzerland folds crypto custody into its banking and DLT framework. Our regulation hub tracks how individual countries treat the activity.
In the United States, the key rule is the Custody Rule, 17 CFR 275.206(4)-2, under the Investment Advisers Act of 1940. A registered investment adviser with custody of client assets, including crypto held as securities, must keep those assets with a qualified custodian: a bank or savings association, a registered broker-dealer, a registered futures commission merchant, or certain foreign financial institutions. In September 2025 the SEC staff issued a no-action letter allowing advisers to treat certain state-chartered trust companies as banks for crypto custody, subject to conditions such as annual due diligence and no rehypothecation of client assets.
In Switzerland, FINMA Guidance 01/2026 confirms that banks may hold crypto-based assets as segregable custody assets that benefit from bankruptcy protection, provided the assets are held in readiness for clients at all times in individual custody, or in collective custody with clear customer shares. Where custody is delegated abroad, the foreign custodian must be prudentially supervised and foreign law must guarantee bankruptcy protection. The Swiss model treats well-structured crypto custody much like the safekeeping of any other client asset.
| Jurisdiction | Framework | License Type | Key Feature |
|---|---|---|---|
| European Union | MiCA (Reg. 2023/1114) | CASP authorisation, custody service | EUR 125,000 capital; Article 75 segregation and liability |
| United States | Investment Advisers Act | No federal custody license; qualified custodian | Custody Rule 206(4)-2; banks, broker-dealers, FCMs, trust cos. |
| Switzerland | Banking & DLT law (FINMA) | Banking / securities authorisation | Segregable custody assets with bankruptcy protection (Guidance 01/2026) |
Why this matters for licensing: the same custody business can require an EU CASP authorisation, a relationship with a US qualified custodian, or a Swiss banking-grade setup, depending on the market. The choice shapes your capital, governance, and timeline, so it belongs at the start of your jurisdiction selection. See our custody license overview for how this fits the full application.
Unsure whether your model needs a custody license? Get a free 30-minute consultation. We will assess your custody arrangements and recommend a licensing route across the EU, US, and Switzerland.
Get Free Consultation →Hot Storage, Cold Storage & Proof of Reserves
A custody license is granted on paper, but it stands or falls on the technical safekeeping of keys. The first decision every custodian makes is how to split assets between hot and cold storage. A hot wallet is connected to the internet, which makes it convenient for trading, withdrawals, and day-to-day movement, but also exposes it to cyber attack. Cold storage keeps private keys offline on hardware or air-gapped devices, which is far more secure but slower to access.
The industry norm reflects that trade-off. Institutional custodians typically keep 80 to 90 percent of assets in cold storage as long-term reserves and only 10 to 20 percent in hot wallets to support operational activity. Most also layer in multi-signature or multi-party computation so that no single person can move funds, alongside withdrawal whitelists, time delays, and crime insurance. Regulators reviewing a custody application expect to see this architecture documented, not improvised.
Proof of reserves has become the public-facing complement to segregation. It is a cryptographic attestation, often built on a Merkle tree, that the custodian holds enough crypto-assets to cover every client balance. Each client can verify that their balance was included in a snapshot without exposing any other account, and an independent auditor usually certifies the result. After several high-profile collapses, regulators and counterparties increasingly treat a credible proof-of-reserves process as a baseline expectation rather than a marketing extra.
In our custody licensing work across more than 60 jurisdictions, the single most common reason an application stalls is a key-management model the firm cannot fully explain. The founders have a custody provider and a cold-storage setup, but they cannot map who holds which signing key, how the hot and cold split is enforced, or how segregation is evidenced if the company itself fails. Regulators read that gap as operational risk.
We also see firms underestimate the liability dimension. Under MiCA, a custodian is on the hook for the market value of assets lost in an attributable incident, so the custody policy, insurance cover, and incident-response plan are not paperwork: they are the controls that cap that exposure. Building the safekeeping architecture, segregation evidence, and proof-of-reserves process together, before filing, is consistently the difference between a clean review and months of regulator queries.
How to Get a Custody License Authorised
Getting authorised for crypto custody is a structured process, not a form-filling exercise. The five steps below describe the core path a firm follows to a MiCA custody authorisation, which is broadly representative of how regulated markets approach the activity. Our AML and KYC compliance service and licensing team run this end to end as part of a single engagement.
Crypto Custody License: Common Questions
Sources & Official References
- ESMA: Markets in Crypto-Assets Regulation (MiCA)
- EUR-Lex: Regulation (EU) 2023/1114 (MiCA) full text
- EUR-Lex: European crypto-assets regulation (MiCA) summary
- SEC: Custody of Funds or Securities of Clients by Investment Advisers (Rule 206(4)-2)
- Cornell LII: 17 CFR 275.206(4)-2 (qualified custodian definition)
- Investor.gov (SEC): Crypto Asset Custody Basics Investor Bulletin
- FINMA: Guidance 01/2026 on risks associated with the custody of crypto-based assets