🔒 Luxembourg · MiCA Title V · 0 custody incidents

MiCA Compliance

Custodia Systems engineers custody architecture, client-asset safeguarding and proof of reserves so crypto-asset service providers meet MiCA compliance with confidence. EUR 6.8 billion in client assets segregated. Zero custody incidents since 2019.

Custodia Systems S.a r.l. is a MiCA compliance engineering firm based in Luxembourg City, Luxembourg, that designs and implements custody architecture, client-asset safeguarding and proof-of-reserves systems for crypto-asset service providers under Regulation (EU) 2023/1114. Founded in 2019, it has segregated EUR 6.8 billion in client assets across 16 safeguarding builds with zero custody incidents to date.

Custodia Systems · At a glance
Luxembourg City, Luxembourg · founded 2019 · 37 engineers
EUR 6.8B client assets segregated across 16 live builds
Zero custody incidents since inception
ISO 27001 (LU-27001-2215 · LNE) · SOC 2 Type II · ISO 27017
Speciality: custody architecture, key ceremonies, proof of reserves
Pricing from EUR 13,000/month (Assure) to EUR 72,000 (Custody)
EUR 6.8B
Client assets segregated
16
Live safeguarding builds
0
Custody incidents since 2019
Monthly
Proof of reserves cadence

What we build for MiCA compliance

Custodia Systems delivers the technical layer that sits beneath a CASP's MiCA compliance posture: custody infrastructure, client-asset segregation, key management and the monthly proof of reserves that regulators and clients expect.

🔒

Custody Architecture

Design and implementation of custody wallet structures, signing policies and asset storage tiers (hot, warm, cold) aligned with MiCA Title V Article 70 safeguarding obligations and CSSF supervisory expectations.

📋

Client-Asset Segregation

End-to-end segregation architecture separating client assets from the firm's own holdings. Covers individual-wallet segregation, omnibus structures with sub-ledger reconciliation, daily balance attestation and insolvency-proof controls.

Proof of Reserves

Automated monthly proof-of-reserves system using Merkle-tree attestations, independent auditor integration and a client-facing verification portal. Satisfies ESMA guidance on CASP safeguarding evidence.

🔑

Key Management Infrastructure

HSM-rooted key management architecture including key ceremony design, MPC wallet integration (Fireblocks, Qredo or bespoke), key rotation schedules and the operational playbooks that satisfy ISO 27001 Annex A controls.

📝

AML and Travel Rule Integration

Blockchain analytics onboarding (Chainalysis or Elliptic), Travel Rule messaging via Notabene or TRP, and the transaction screening workflow documentation required by the FATF and EU Transfer of Funds Regulation.

📈

Assure Retainer

Ongoing monthly MiCA compliance coverage: proof-of-reserves attestation, key ceremony oversight, segregation reconciliation review, regulatory alert monitoring and a quarterly safeguarding health report for your board and your regulator.

Who we engineer MiCA compliance solutions for

Custodia Systems works with the full spectrum of crypto-asset service providers seeking MiCA compliance, with particular depth in custody-intensive business models.

Digital Asset Custodians
Crypto Exchange Operators
Institutional Trading Desks
Wallet Service Providers
EMT & ART Issuers
FinTech Platforms
Asset Managers with DLT Exposure
Crypto Broker-Dealers
Transfer & Execution CASPs
Payment Institutions (Crypto)
DeFi Bridge Operators
VASPs Seeking MiCA Authorisation

Custody and safeguarding technology stack

Every Custodia Systems custody build uses proven, auditable components, no experimental infrastructure in a client's asset protection layer.

Key Management

Fireblocks MPC Qredo Thales HSM Utimaco HSM BYOK / BIP-32 Shamir Secret Sharing

Proof of Reserves

Merkle Tree Attestation Armanino Mazars PoR Framework zk-SNARK balance proof Verification Portal

AML & Screening

Chainalysis Reactor Elliptic TRM Labs Notabene (Travel Rule) TRP Protocol

Chains Supported

Bitcoin Ethereum Polygon Avalanche Solana Algorand Stellar Tezos

Segregation & Reconciliation

Individual wallet segregation Omnibus + sub-ledger Daily balance attestation Real-time reconciliation

Compliance & Audit

ISO 27001 SOC 2 Type II MiCA Title V FATF Travel Rule CSSF reporting 5-yr retention

Regulatory frameworks and security track record

Every Custodia Systems custody build is engineered to the applicable regulatory framework and independently certified. The security track record below is drawn from live client deployments.

🛡

Security track record. Across 16 live safeguarding builds: EUR 6.8 billion in client assets segregated · zero custody incidents since 2019 · zero insider-threat findings across 11 key ceremonies · 100% of clients passed their CSSF or home-regulator custody review on first submission. External penetration test most recent result: zero critical, zero high-severity findings.

🛡

ISO 27001

Cert LU-27001-2215 · Issued by LNE (Laboratoire National de Métrologie et d’Essais) · Information security management for custody and key management systems

SOC 2 Type II

Annual SOC 2 Type II attestation covering Security, Availability and Confidentiality trust service criteria · Audited by an AICPA-registered firm · Report available under NDA

ISO 27017

Cloud security controls for custody infrastructure hosted on managed cloud platforms · Complements ISO 27001 with cloud-specific implementation guidance per ISO/IEC 27017:2015

Regulatory frameworks

Custodia Systems engineers custody to the following frameworks. Where a public Wikipedia reference exists, we link it for entity-graph clarity.

MiCA Regulation (EU) 2023/1114 Primary
The Markets in Crypto-Assets Regulation that defines custody and safeguarding obligations for CASPs across EU member states. Full text via EUR-Lex.
CSSF, Commission de Surveillance du Secteur Financier LU regulator
Luxembourg’s financial regulator and the competent authority for CASP authorisation under MiCA for Luxembourg-domiciled firms. See cssf.lu.
AML and KYC Obligations FATF / AMLD
Anti-money laundering and know-your-customer requirements derived from the EU’s AMLD6 and FATF Recommendation 15, applied to CASPs under MiCA and the Transfer of Funds Regulation.
Travel Rule (FATF R.16 / TFR) Wire data
Requirement for CASPs to transmit originator and beneficiary data on transfers above EUR 1,000, implemented in the EU via the Transfer of Funds Regulation. FATF and EBA provide authoritative guidance.
ESMA Guidelines on CASPs EU supervisory
The European Securities and Markets Authority publishes technical standards and guidelines that supplement MiCA Title V, including safeguarding expectations. See esma.europa.eu.
EBA Crypto-Asset Guidelines Banking integration
European Banking Authority guidance on prudential treatment of crypto-asset exposures and safeguarding for credit institutions and CASPs. See eba.europa.eu.

The Custodia Secure-by-Design Methodology

Every MiCA compliance engagement follows our four-phase methodology. Each phase has a fixed deliverable set and a quality gate before the next phase begins.

Custody Mapping

We map every asset type, chain, wallet structure and sub-custodian relationship. Output: a Custody Topology Document and a MiCA Title V gap register.

Architecture Design

Segregation architecture, key management design, signing policy and proof-of-reserves methodology are specified and reviewed by Dr. Reuter before build begins.

Build and Key Ceremony

Custody infrastructure is built, HSMs provisioned and the key ceremony conducted under witnessed, recorded conditions. All artifacts are archived in your evidence repository.

Attestation and Handover

First proof-of-reserves attestation produced, segregation controls tested, documentation packaged for your regulator and the Assure Retainer begins if selected.

Engagement packages (EUR, excl. VAT, valid to 2026-12-31)

All MiCA compliance packages are fixed-scope and fixed-price. No hourly billing surprises. IP ownership transfers to you on final delivery.

Assure

Monthly oversight retainer

EUR 13,000
per month · 12-month minimum

Ongoing proof-of-reserves, key ceremony oversight and safeguarding reviews for firms already holding custody infrastructure.

  • Monthly proof-of-reserves attestation
  • Key ceremony oversight (up to 2/year)
  • Segregation reconciliation review
  • Regulatory alert monitoring
  • Quarterly safeguarding health report
  • CSSF inquiry support (2 hrs/month)
Enquire

Custody

Full custody infrastructure build

EUR 72,000
fixed · 12–16 weeks

End-to-end MiCA compliance custody build: key management, MPC wallet integration, proof of reserves and full Title V compliance file.

  • Everything in Safeguard
  • HSM provisioning and key ceremony
  • MPC wallet integration
  • Key rotation schedule and playbooks
  • AML & Travel Rule integration
  • Full MiCA Title V compliance file
  • CSSF authorisation support
Enquire

What determines your MiCA compliance project cost

Six factors drive the price of a custody and safeguarding engagement. Understanding them up front prevents scope surprises.

Asset types and chains

Each additional blockchain or token standard requires a separate wallet architecture, key type and proof-of-reserves sub-proof. Wider chain coverage increases scope.

Sub-custodian count

Engagements that route assets through one or more third-party sub-custodians require additional segregation controls, contractual review and reconciliation flows.

Key management architecture

Bespoke HSM deployment or multi-party key ceremonies add four to six weeks and specialist hardware costs not present in MPC-SaaS deployments.

Proof-of-reserves cadence

Monthly attestations (standard) require automated pipeline build. Daily or real-time attestations require additional infrastructure and ongoing compute costs.

AML and Travel Rule scope

The number of blockchain analytics platforms, jurisdictions and Travel Rule counterparties directly affects integration complexity and testing time.

Regulatory target (competent authority)

CSSF (Luxembourg) authorisation files have specific technical annexes. Filings for BaFin, AFM or FCA require jurisdiction-specific adaptations that add scope.

Selected MiCA compliance custody engagements

Three engagements illustrating Custodia Systems’ depth across custody, safeguarding and proof of reserves for regulated CASPs.

Custodian · Luxembourg

LuxVault S.A., MiCA Title V Custody Build

LuxVault, a Luxembourg-domiciled digital asset custodian seeking CSSF authorisation, retained Custodia Systems to design and build their full custody infrastructure. The engagement covered wallet architecture for eight chains, HSM provisioning, a witnessed three-party key ceremony, client-asset segregation with daily reconciliation and the initial proof-of-reserves attestation.

EUR 1.4B assets segregated on Day 1 · CSSF authorisation granted within 9 weeks of file submission · Zero findings in CSSF custody technical review · 2024 Q2
Wallet Provider · Belgium

Aldgate Wallet, Safeguarding & Proof of Reserves

Aldgate Wallet, a Belgian wallet service provider transitioning from VASP to MiCA-authorised CASP, needed client-asset segregation and automated monthly proof of reserves before their authorisation deadline. Custodia Systems implemented individual-wallet segregation for retail clients and an omnibus sub-ledger for institutional accounts, plus the Merkle-tree attestation pipeline audited by an independent Big Four team.

Monthly attestation cycle reduced from 14 days (manual) to 18 hours (automated) · 31 consecutive months zero discrepancy · 2023 Q4
Institutional Desk · Ireland

Archway Prime, MPC Key Management Migration

Archway Prime, a Dublin-based institutional crypto trading desk, held client assets under a legacy single-signature custody model that failed MiCA Title V requirements. Custodia Systems designed a Fireblocks MPC migration path, conducted key ceremonies for all existing wallets, rebuilt the segregation ledger and produced the Travel Rule integration documentation required by the Central Bank of Ireland.

Migration completed with zero downtime · EUR 820M assets transitioned · 100% Travel Rule message success rate at go-live · 2025 Q1

How to choose a MiCA compliance partner for custody

Six questions to ask any custody and safeguarding firm before you sign. Useful whether you are evaluating Custodia Systems or any competitor.

What is your proof-of-reserves methodology?

Look for Merkle-tree attestations with an independent auditor, not just internal balance exports. Ask whether the verification portal is client-facing. Custodia Systems produces monthly Merkle-tree PoR attestations reviewed by a registered audit firm.

Have you conducted live key ceremonies for MiCA clients?

Key ceremony experience is not interchangeable with general HSM knowledge. Ask for a ceremony protocol document and reference contacts. Custodia Systems has conducted 11 witnessed key ceremonies, all archived with video records.

Are you familiar with the CSSF authorisation file requirements?

Luxembourg’s CSSF requires a specific custody technical annex. Firms without CSSF experience will slow your application. Custodia Systems is Luxembourg-domiciled and has supported three CSSF submissions.

What is your incident record?

Ask for a written incident summary covering all live custody builds. Zero incidents is a concrete and verifiable claim. Custodia Systems has zero custody incidents across all live builds since 2019.

Do you hold ISO 27001 and SOC 2 Type II?

Both certifications are required by most institutional clients and are expected by the CSSF. Ask for the certificate number and issuing body. Our ISO 27001 cert is LU-27001-2215 issued by LNE.

Who will personally lead my engagement?

For a EUR 34k–72k custody build, the lead engineer’s credentials matter. Dr. Elodie Reuter personally designs and reviews every custody architecture produced by Custodia Systems.

Engagement model and chain selection tables

Two tables to help you select the right MiCA compliance engagement and chain approach for your business model.

Table 1, Engagement model comparison

Engagement Cost model Timeline Best for MiCA scope
Assure EUR 13,000/month Ongoing · starts in 2 wks CASPs with existing custody needing monthly PoR and oversight PoR · key ceremony oversight · segregation review
Safeguard EUR 34,000 fixed 8–10 weeks CASPs needing Article 70 segregation but with existing key management Segregation architecture · reconciliation · first PoR
Custody EUR 72,000 fixed 12–16 weeks New CASPs or full custody rebuilds for MiCA Title V authorisation Full Title V · key management · MPC · AML · CSSF file
Custody + Assure EUR 72,000 + 13,000/mo 12–16 wks + ongoing CASPs wanting build and managed custody operations in one firm Complete ongoing MiCA compliance coverage

Table 2, Chain and custody approach selection

Approach Best for Key management Compliance fit Cost range
MPC Wallet (Fireblocks/Qredo) Institutional desks & exchanges Distributed key shares · no single HSM Strong · preferred for CSSF submissions Mid · SaaS fees ongoing
HSM + MPC Hybrid High-value custodians (>EUR 500M) HSM root of trust + distributed signing Strongest · insurance-grade High · hardware capex
Omnibus + Sub-ledger Retail wallet providers Fewer wallets · sub-ledger reconciliation Acceptable under MiCA Article 70 with daily attestation Low–mid
Individual Wallet Segregation Premium custody for institutional clients Per-client key material Highest MiCA alignment · cleanest insolvency protection High · wallet scaling costs
Sub-custodian Model CASPs outsourcing key management Third-party HSM and custody Permissible · requires contractual & due-diligence controls Variable by provider

The Custodia Systems team structure

37 specialists across custody engineering, key management and MiCA compliance. Every engagement has a named lead from each discipline.

Custody Architect

Designs the wallet structure, segregation topology and signing policy. Personally reviewed by Dr. Reuter on every engagement above EUR 50k.

Key Management Engineer

Provisions HSMs, configures MPC wallet policies, designs key rotation schedules and leads the key ceremony. Holds certified HSM administrator credentials.

Proof of Reserves Lead

Builds and maintains the Merkle-tree attestation pipeline, coordinates with the external auditor and produces the client-facing verification portal.

MiCA Compliance Specialist

Maps the custody build to MiCA Title V obligations, drafts the technical annex for the competent authority submission and supports regulatory Q&A.

AML and Travel Rule Engineer

Integrates blockchain analytics platforms, configures the Travel Rule message exchange and builds the transaction screening workflow documentation.

Security and QA Lead

Coordinates external penetration tests, reviews all key material handling against ISO 27001 controls and signs off the final security assurance report.

Custody project deliverables

Every MiCA compliance engagement produces a defined set of documented, tested and regulator-ready outputs. You own all IP and source documentation on final payment.

Custody Topology Document (wallet structures, chains, signing policies)
MiCA Title V Gap Register and remediation plan
Client-asset segregation architecture and sub-ledger specification
Key ceremony protocol, video archive and witness records
HSM and MPC wallet configuration runbook
Key rotation schedule and emergency recovery playbook
Proof-of-reserves Merkle-tree pipeline (code & documentation)
First independent proof-of-reserves attestation report
AML and Travel Rule integration documentation
ISO 27001-aligned control framework (Annex A custody controls)
Regulator-ready MiCA technical annex and evidence package
Staff onboarding guide and knowledge-transfer session (4 hrs)

Our commitment to you

Custody is not a place for hedged promises. These are the commitments Custodia Systems makes in every engagement contract.

Free scoping call (90 min): We map your current state and produce a preliminary gap register before you sign anything.
Fixed-price contracts: The Safeguard and Custody packages are fixed-price. No hourly overruns; scope changes are priced as change orders with your approval.
You own everything: All code, runbooks, ceremony records, attestation pipelines and documentation are transferred to you on final payment. No licence fees, no vendor lock-in.
Regulator submission support: We attend up to two CSSF (or your home regulator) technical Q&A sessions as part of the Custody package at no additional fee.
Zero-incident exit: If a custody incident occurs during our build or Assure retainer period due to our system or process design, we remediate at zero additional cost and provide a root-cause report within 72 hours.
Clean handover: If you ever wish to transition to another provider, we provide a full transition package including all key material records, configuration exports and a structured handover call.

AI meets MiCA compliance: what we see in 2026

AI is changing how CASPs approach MiCA compliance monitoring, anomaly detection and proof-of-reserves verification. Custodia Systems is active in three areas.

🤖

AI-Assisted Anomaly Detection in Segregation Ledgers

Machine learning models trained on normal reconciliation patterns can flag sub-ledger discrepancies hours before a daily attestation cycle, giving compliance teams time to investigate before a client balance mismatch becomes a MiCA Article 70 finding.

📊

Continuous Proof-of-Reserves Monitoring

Moving from monthly Merkle attestations to near-real-time reserve monitoring using on-chain data feeds and AI risk scoring. Custodia Systems is piloting continuous PoR with two Assure clients, targeting hourly balance verification against sub-ledger positions.

🕵

AI-Driven Travel Rule Risk Scoring

Large language models applied to counterparty context enrichment, combining blockchain analytics signals with public entity data, to score Travel Rule message completeness risk and flag high-risk transaction corridors before FATF review cycles.

Research Note CS-2025-03

Custodia Systems
Research Note
CS-2025-03
Sep 2025

Proof-of-Reserves Frequency and Audit Confidence: An Empirical Study Across 22 CASPs

Analysis of proof-of-reserves cadence and audit confidence thresholds across 22 crypto-asset service providers active in the EU. Finds that monthly attestations reduce reserve discrepancy incidents by 78% compared with quarterly schedules. Identifies the five most common key management gaps that generate MiCA Title V findings during CASP authorisation reviews.

Key findings: (1) 63% of CASPs that shifted from quarterly to monthly PoR eliminated discrepancy incidents entirely within six months; (2) the most common Title V finding is the absence of a witnessed key ceremony record; (3) Merkle-tree attestation combined with a client-facing verification portal increases client confidence scores by 41 points on a 100-point scale versus internal balance exports.

Author: Dr. Elodie Reuter, Custodia Systems 31 pages Dataset: 22 EU CASPs, 2022–2025 Request full paper

What clients say about MiCA compliance with Custodia Systems

Clutch 4.9 / 5 (33 reviews) · G2 4.8 / 5 (21 reviews) · All quotes are from verified client contacts. Last reviewed: June 2026.

“Custodia Systems delivered our full MiCA Title V custody build in 14 weeks and our CSSF submission passed with zero technical findings. Dr. Reuter’s personal review of the architecture was a level of scrutiny we hadn’t experienced from any other firm.”
Head of Compliance Digital asset custodian · Luxembourg · Clutch
“The proof-of-reserves pipeline they built reduced our monthly attestation cycle from two weeks of manual work to 18 hours automated. Our auditor said it was the cleanest Merkle-tree setup they had reviewed for a European CASP.”
CTO Wallet service provider · Belgium · G2
“We migrated EUR 820 million in client assets to an MPC custody model with zero downtime. The key ceremony protocol was thorough, witnessed and archived in a way that will stand up to any regulatory inspection.”
Chief Risk Officer Institutional trading desk · Ireland · Clutch
“Their AML integration work with Chainalysis was seamless. More importantly they understood the Travel Rule requirements deeply enough to write our regulatory documentation, which saved us significant legal fees.”
VP Product Crypto exchange operator · Netherlands · G2
“We engaged the Assure retainer after our initial custody build. Having Custodia Systems oversee the monthly proof of reserves means our board gets a signed attestation rather than a spreadsheet. It’s changed how we talk about custody to our institutional clients.”
CEO FinTech platform with crypto custody · France · Clutch
Custody Insider Proof of Reserves Report Safeguarding Standard The Segregation Brief Luxembourg Asset Journal

Security certifications and industry recognition

🛡

ISO 27001:2022

Certificate LU-27001-2215 · Issued by LNE · Scope: custody key management, proof-of-reserves infrastructure and client-asset segregation systems

SOC 2 Type II

Annual attestation · Trust service criteria: Security, Availability, Confidentiality · Report available under NDA on request

ISO 27017:2015

Cloud security controls · Covers custody infrastructure hosted on managed cloud platforms · Companion certification to ISO 27001

🏆

Safeguarding Standard Award 2025

Best MiCA Custody Implementation · Awarded by Safeguarding Standard publication · Recognised for the LuxVault CSSF-authorisation engagement

📋

Custody Insider Top Firm 2024

Named a top European custody engineering firm by Custody Insider · Based on client review scores and verified asset volume under management

🎓

Clutch Global Leader 2025

Clutch Global Leader in Financial Services Technology · Recognised on the basis of 33 verified client reviews with an average rating of 4.9 / 5

Dr. Elodie Reuter, Founder and CEO

Last reviewed on 21 June 2026 by Dr. Elodie Reuter, Founder and CEO, Custodia Systems S.a r.l.

ER

Dr. Elodie Reuter

Founder & CEO · Custodia Systems

🎓 PhD Cryptographic Key Management, University of Luxembourg (2013)
📋 Ex-custodian security architect (8 years)
🔑 Specialism: client-asset segregation, key ceremonies, proof of reserves

Dr. Elodie Reuter spent eight years as a security architect at one of Europe’s largest regulated custodians before founding Custodia Systems in Luxembourg in 2019. During that time she designed the key management infrastructure protecting over EUR 12 billion in institutional assets and led three major custody platform migrations without a single incident.

Her PhD from the University of Luxembourg focused on the failure modes of distributed key management systems under adversarial conditions, a study that shaped her conviction that most custody failures originate not in cryptography but in ceremony design and operational process. She is a named author on two peer-reviewed papers in the Journal of Cryptographic Engineering.

The formative moment that led to Custodia Systems came in 2018, when Elodie was asked to review a CASP’s custody controls ahead of a regulatory inspection. She found the firm’s client-asset ledger was reconciled once a week using a manual spreadsheet process. A EUR 3.4 million discrepancy had been accumulating undetected for eleven days. It was recoverable, but barely. She founded Custodia Systems to ensure that no CASP seeking MiCA compliance ever faces that kind of operational risk.

Elodie personally designs and reviews every custody architecture produced by Custodia Systems and leads each key ceremony. The firm will not take on more than five simultaneous new-build engagements so that her direct involvement is maintained on each one.

Frequently asked questions about MiCA compliance and custody

What does a MiCA compliance firm do?
A MiCA compliance firm engineers the technical and procedural infrastructure that crypto-asset service providers need to satisfy Regulation (EU) 2023/1114. This includes custody architecture, client-asset safeguarding, AML and Travel Rule integration, reporting pipelines and audit trail systems, enabling CASPs to obtain and maintain their authorisation from an EU competent authority such as the CSSF in Luxembourg.
How much does MiCA compliance engineering cost?
Custodia Systems prices MiCA compliance projects in three bands. The Assure Retainer (monthly custody oversight and proof of reserves) starts at EUR 13,000 per month. The Safeguard Package (client-asset segregation architecture) is EUR 34,000 fixed. The full Custody Package (key management, MPC integration, proof of reserves and Title V compliance) is EUR 72,000 fixed. Cost is driven by the number of asset types, chains supported, sub-custodian count, key management architecture and compliance scope.
How do I choose a MiCA compliance firm for custody and safeguarding?
Evaluate the firm on five criteria: (1) demonstrated custody architecture experience with a proven segregation track record; (2) proof-of-reserves methodology and cadence; (3) key management specialism, including HSM and MPC wallet delivery; (4) ISO 27001 and SOC 2 certification; and (5) familiarity with your competent authority, in Luxembourg, the CSSF. Ask for a client list with verifiable asset volumes and zero-incident references.
What is proof of reserves under MiCA?
Under MiCA Title V, CASPs that provide custody services must be able to demonstrate at any time that they hold client crypto-assets at least equal to the aggregate of client balances. Proof of reserves is the cryptographic and operational mechanism, typically a Merkle-tree attestation reviewed by an independent auditor, that provides this assurance. Custodia Systems builds and automates monthly proof-of-reserves attestations for its clients.
Does Custodia Systems work with the CSSF?
Yes. Custodia Systems is based in Luxembourg City and is familiar with the Commission de Surveillance du Secteur Financier (CSSF) authorisation process for CASPs. The firm has supported three Luxembourg-domiciled clients through their MiCA authorisation submissions, including preparation of the custody and safeguarding technical file required by the CSSF.
What is client-asset segregation under MiCA Title V?
MiCA Title V Article 70 requires CASPs providing custody to hold client crypto-assets separately from the firm’s own assets at all times, use client-specific wallets or clearly labelled omnibus structures with sub-ledger reconciliation, and implement controls that prevent commingling. Custodia Systems designs and implements the segregation architecture, reconciliation engine and internal control framework that satisfies this requirement.
How long does a MiCA custody build take?
A focused Safeguard Package (client-asset segregation only) typically delivers in eight to ten weeks. A full Custody Package including key management infrastructure, MPC wallet integration and proof-of-reserves automation takes twelve to sixteen weeks. The Assure Retainer for ongoing oversight can begin within two weeks of contract signing. Timeline depends on the number of chains, sub-custodians and the readiness of the client’s existing infrastructure.
What is a key ceremony and why does it matter for MiCA compliance?
A key ceremony is a formal, witnessed procedure for generating, distributing and documenting cryptographic private key material, with roles separated across independent parties to prevent any single point of compromise. It matters for MiCA compliance because the absence of a witnessed key ceremony record is one of the most common technical findings during CASP authorisation reviews. Custodia Systems has conducted 11 witnessed key ceremonies, all archived with video records and independent witness statements.

MiCA custody and safeguarding glossary

Key terms used in custody and MiCA compliance engineering, defined plainly for compliance, legal and technical readers.

Proof of Reserves PoR
A cryptographic attestation, typically using Merkle tree proofs, that a CASP holds client assets at least equal to the sum of all client balances, produced at a defined cadence and attested by an independent auditor.
Client-Asset Segregation MiCA Art. 70
The legal and operational separation of client crypto-assets from the CASP’s own proprietary assets, as required by MiCA Title V Article 70, preventing commingling and protecting clients in insolvency.
Key Ceremony Key management
A formal, witnessed procedure for generating, distributing and documenting cryptographic private key material, with roles separated across independent parties to prevent any single point of compromise.
MPC Wallet Multi-party computation
A multi-party computation wallet that distributes private key shares across multiple independent signers so that no single party holds a complete key, substantially reducing key theft and insider risk.
CASP Crypto-Asset Service Provider
A legal entity authorised by an EU competent authority to provide one or more crypto-asset services such as custody, exchange, transfer or advice, as defined by MiCA Title V.
MiCA Title V Regulation (EU) 2023/1114
The chapter of Regulation (EU) 2023/1114 that sets out the authorisation requirements, operational rules and safeguarding obligations for crypto-asset service providers across the EU.
HSM Hardware Security Module
A tamper-resistant physical device that safeguards and manages cryptographic keys, performs signing operations, and provides the root of trust in a custody key management architecture.
Travel Rule FATF R.16 / TFR
The FATF requirement, implemented in the EU via the Transfer of Funds Regulation, that CASPs collect and transmit originator and beneficiary data for crypto-asset transfers above the EUR 1,000 threshold.

Start your MiCA compliance custody engagement

Every engagement starts with a free 90-minute scoping call. We map your current state and produce a preliminary MiCA Title V gap register before you commit to anything.

🏠
Headquarters Custodia Systems S.a r.l.
12 rue Guillaume Kroll
L-1882 Luxembourg City
Luxembourg
RCS Luxembourg B 248917
📞
Phone +352 27 86 4400
Mon–Fri 08:30–18:00 CET
📋
Legal VAT LU28759384 · RCS Luxembourg B 248917
Registered in Luxembourg

Request a scoping call