CySEC MiCA reporting requirements may introduce a more detailed supervisory framework for crypto-asset service providers authorized in Cyprus. In December 2025, the Cyprus Securities and Exchange Commission published a proposed Directive covering the submission of prudential information, financial reports, and audited annual financial statements by CASPs.
The proposal was issued under Article 67 of the EU Markets in Crypto-Assets Regulation. The public consultation closed on January 12, 2026. As the requirements were proposed through a consultation paper, CASPs should distinguish between the draft framework described below and the final rules applicable after the Directive enters into force.
What the Proposed CySEC Directive Covers
The proposed Directive would require Cyprus-authorized CASPs to submit three categories of information:
- Prudential information required under Article 67 of MiCA
- Financial reports consisting of a trial balance, balance sheet, and profit and loss statement
- Audited annual financial statements
The framework is intended to help CySEC assess whether CASPs continue to satisfy their prudential obligations after authorization. It is aligned with the reporting model already used for Cyprus Investment Firms and follows deadlines derived from the EU prudential reporting framework.
The requirements would apply to CASPs authorized by CySEC under Article 63 of MiCA. They would not apply to central securities depositories, investment firms, market operators, management companies, or AIFMs providing crypto-asset services under the Article 60 notification procedure. These entities are exempt from the relevant Article 67 prudential requirements.
Authorization status is especially important following the end of the MiCA transitional period. Firms that have not obtained CASP approval can no longer rely on grandfathering to continue regulated EU operations. MiCA Grandfathering Is Over: What Are the Options for Crypto Companies Without a CASP Licence? covers the remaining compliance routes.
Reporting Frequency for Cyprus CASPs
The proposed reporting frequency depends on the CASP category established under Annex IV of MiCA.
Category 1 CASPs would report annually, using December 31 as the reference date. The corresponding prudential information and financial reports would be due by February 11 of the following year.
The financial reports would follow the same submission schedule as the Article 67 prudential information. This would allow CySEC to review a CASP’s financial position and compliance data together.
The proposal allows CASPs to use unaudited figures for periodic prudential submissions. If the subsequent audited figures differ, the CASP would need to file revised information as soon as possible and no later than five months after the end of the financial year. Other amendments to previously submitted information would need to be reported without undue delay.
Audited Annual Financial Statements
All CASPs within the scope of the proposed Directive would need to submit audited annual financial statements within four months after the end of their financial year.
Where a CASP is required to prepare consolidated financial statements under applicable accounting standards or Cyprus company law, the consolidated audited statements would be subject to the same four-month deadline.
This requirement is separate from the five-month period allowed for correcting prudential information when audited and unaudited figures differ. CASPs should therefore plan their audit, regulatory reporting, and reconciliation processes around both deadlines.
What the Proposal Means for CASP Compliance
The proposed framework makes ongoing reporting an important part of MiCA compliance in Cyprus. Obtaining authorization would be followed by recurring obligations relating to financial data, own funds, governance, and record accuracy.
CASPs preparing for authorization should ensure that their accounting and compliance systems can:
- Produce quarterly or annual management accounts within the required timetable
- Track the prudential safeguards established under Article 67 of MiCA
- Reconcile unaudited regulatory data with audited financial statements
- Identify and correct discrepancies without undue delay
- Maintain records supporting the figures submitted to CySEC
- Coordinate reporting responsibilities between management, finance, compliance, and external auditors
The reporting category should also be confirmed at the licensing stage because it determines whether the CASP would report annually or quarterly.
Broader Regulatory Requirements
Prudential reporting forms only one part of the compliance framework for Cyprus CASPs. Authorized firms must also consider MiCA requirements concerning governance, safeguarding, complaints handling, conflicts of interest, outsourcing, and operational controls.
Depending on their activities, CASPs may also be affected by the Digital Operational Resilience Act, the EU anti-money laundering framework, and payment-services rules. In particular, a CASP handling electronic money tokens should assess whether any of its services also qualify as payment services requiring authorization or another arrangement with an eligible payment service provider.
Cyprus authorization supports EU market access through MiCA passporting, but it does not extend to non-EU jurisdictions. CASPs entering the UK, Singapore or other international markets may require additional approvals, as explained in MiCA Secondary Licensing: How Crypto Firms Can Bridge the Gap Between the EU and Global Markets.
Cyprus authorization supports access to the EU market through the MiCA passporting framework, but it does not cover operations outside the Union. CASPs planning international expansion should assess whether MiCA secondary licensing or another local approval is required in each target market.
Conclusion
The proposed CySEC MiCA reporting requirements would establish a structured timetable for prudential data, financial reports, and audited annual financial statements. Category 2 and Category 3 CASPs would face quarterly reporting, while Category 1 firms would report annually.
Crypto companies applying for authorization in Cyprus should incorporate these proposed obligations into their financial controls and compliance planning. They should also monitor CySEC publications for confirmation of the final Directive and its effective date.
Need Help with MiCA Authorization?
Equilex supports crypto businesses with Cyprus CASP authorization, regulatory structuring, and MiCA compliance planning. Submit an inquiry through the website, and an Equilex specialist will review the project and contact you within 24 hours.




