Building a MiCA-Ready Compliance Team: How Crypto Companies Can Overcome Hiring Challenges

August 13, 2026 · 11 min read
How to Build a MiCA-Ready Compliance Team: Hiring Challenges and Solutions

MiCA, the EU’s Markets in Crypto-Assets Regulation, reached its transition deadline on July 1, 2026. From that date, any company acting as a crypto-asset service provider, or CASP, without authorisation can no longer legally serve EU clients.

July 1 was a hard cutoff for operating without authorisation, not for submitting an application. Companies that had not received CASP authorisation by the deadline had to stop serving EU clients immediately. They can still apply, but they cannot resume operations until their licence is granted.

According to ESMA’s interim MiCA register, 244 companies held CASP authorisation across EU member states as of June 26, 2026. Before MiCA, more than 2,700 entities held Virtual Asset Service Provider registrations across Europe.

The common explanation is that many companies were not ready for the regulatory requirements. From what I have seen while helping crypto and fintech businesses build their compliance teams, there is another important reason: many were not ready to hire for them.

What Does a MiCA-Compliant CASP Team Need?

MiCA replaces the previous patchwork of national VASP registrations with a single European framework. A CASP authorisation obtained in one EU country gives a company passporting rights to serve clients across the EU.

The challenge is the organisational substance that authorisation requires.

A CASP must have a complete company and governance structure in place before authorisation is granted. In practice, the scope is often much broader than crypto companies expect when they first review the regulation.

Directors, compliance leaders, AML specialists, risk professionals, and ICT leads may all be formally accountable to the regulator. That means each appointment must satisfy both the company’s internal expectations and the regulator’s standards.

Core Roles Required for MiCA Authorisation

Depending on the company, jurisdiction, and business model, the required structure may include:

  • A competent Management Board whose members can demonstrate relevant industry experience and competence in the areas they oversee
  • In certain jurisdictions, a separate Supervisory Board with expertise across areas such as finance, AML, risk, business strategy, and ICT
  • A Compliance Officer responsible for ongoing regulatory compliance
  • An AML or MLRO function responsible for anti-money laundering and counter-terrorist financing controls
  • A Risk Manager covering operational, market, and regulatory risk
  • An Internal Auditor who remains independent from the company’s other functions
  • An ICT or Information Security function responsible for digital operational resilience, including requirements arising under DORA
  • A Data Protection Officer, particularly where the CASP processes personal data at scale

The number of board members will vary according to the company’s size, direction, and chosen jurisdiction. What remains consistent is that the people appointed to these positions must usually be presented to, and approved by, the regulator.

Additional roles may be necessary depending on the business model. A CASP holding client funds may need a Safeguarding Officer, while a token issuer may need someone responsible for its white paper. A Legal Officer may not be expressly mandated by MiCA, but in most licensing processes, legal expertise is practically essential.

The table below is an example of an organizational structure created for the Lithuanian regulator as part of a CASP license application for a specific business.

Core Roles Required for MiCA Authorisation

Why MiCA Compliance Roles Cannot Always Be Combined

One of the most frequent structural mistakes is assigning compliance, MLRO, and risk responsibilities to the same individual.

These functions carry different forms of accountability. A proper three-lines-of-defence model requires a clear separation between operational activity, oversight, and independent assurance.

The appropriate headcount will also depend on the size of the client base, transaction volumes, product complexity, and risk profile. Combining critical control functions may appear efficient, but it can create conflicts of interest that regulators are likely to challenge.

Regulators do not approve an organisational chart in isolation. They also assess the people named within it.

Every key-function nominee may require formal sign-off, so the suitability of the person, and the way the company presents that person’s experience, can materially affect the authorisation process.

3 Common MiCA Compliance Hiring Mistakes

Over the past 18 months, I have worked on searches for compliance professionals moving through MiCA licensing processes at crypto-native businesses and fintech scale-ups across Europe.

Three recurring hiring mistakes consistently make those processes slower and more difficult.

1. Hiring Before Building a Realistic MiCA Licensing Roadmap

Delays often begin when a company starts searching for board members, MLROs, or compliance officers before it fully understands what the licensing process will involve.

The timeline, budget, target jurisdiction, local substance requirements, and regulator expectations should not be discovered halfway through a search.

When costs rise or the licensing timeline slips, companies sometimes pause hiring, switch jurisdictions, or abandon their European plans altogether. This has made experienced compliance professionals increasingly cautious.

In my first conversations with candidates, almost every second person raises some version of the same concern: is the company genuinely committed to the licence?

Strong professionals will often choose a less exciting but stable position over a more attractive opportunity that may disappear within a year.

This matters because experienced compliance professionals are predominantly passive candidates. They are not necessarily applying through job boards. They need to be identified, approached, and persuaded.

One of the first things they assess is whether there is a credible plan behind the role. A crypto company without a realistic MiCA authorisation roadmap can lose a candidate before the first interview is over.

2. Searching for a MiCA Candidate Who Does Not Yet Exist

When preparing a hiring brief, companies often look for a perfect match: someone whose CV appears to satisfy every possible regulatory and commercial requirement.

Crypto companies frequently ask for candidates who have both substantial crypto experience and a proven compliance record in an identical or very similar business model.

The logic is understandable, but the market has not yet had enough time to produce that talent pool at scale.

As the CASP authorisation figures show, many EU countries had issued fewer than ten licences by late June 2026, while some had issued none. The regulated crypto environment in which ideal candidates could have developed several years of directly comparable experience is still relatively new.

Crypto-native candidates may understand the technology, products, and market very well. However, professionals with deep compliance experience in a fully regulated crypto setting remain scarce.

The mistake is treating previous crypto experience as non-negotiable when the more important requirement is often competence within a regulated financial environment.

In my experience, learning the fundamentals of crypto is considerably easier than building genuine expertise in a highly regulated business.

Candidates from banking, payments, electronic money, asset management, or other parts of traditional finance may already understand governance, regulatory accountability, reporting obligations, risk controls, and supervisory relationships.

Broadening the search to include these sectors can immediately increase the number of credible candidates.

3. Treating the Regulator as an Unchangeable Barrier

Another common mistake is building a candidate specification around assumptions about what the regulator will accept, without asking the regulator directly.

Those assumptions are not always correct.

In several EU jurisdictions, regulators are willing to engage with credible crypto businesses before a formal application is submitted. Depending on the market, companies may be able to discuss prospective candidate profiles and obtain guidance on whether a person’s experience is likely to be considered suitable.

At Evotym, we have contacted central banks ahead of formal submissions in multiple jurisdictions and received detailed feedback on candidate profiles.

Requirements that initially appeared rigid were often more open to discussion than the client expected. In certain jurisdictions, the company could raise questions about a candidate’s suitability before submitting the full documentation.

In one case, a regulator initially returned the profile of an MLRO who came from another regulated sector and did not have direct crypto experience.

The company explained why the candidate’s background was relevant and presented a structured onboarding plan to close the crypto knowledge gap. The regulator accepted the explanation, the candidate was approved, and the company subsequently received its licence.

The lesson is not that regulators will relax their standards. It is that companies should engage with them, understand the purpose behind those standards, and make a well-supported case for strong candidates.

How to Hire a MiCA-Ready Compliance Team

These hiring problems are avoidable. The following five practices can save time and improve the chances of finding suitable candidates in a constrained market.

Present the Company as Clearly as You Present the Role

Compliance candidates assess stability just as carefully as they assess career opportunity.

Be transparent about the licensing timeline, the current stage of the application, and the issues that may cause delays. Explain what the business intends to do if authorisation takes longer than expected.

Honesty usually creates more confidence than a polished recruitment pitch that avoids difficult questions.

Research the Local Compliance Talent Market Before Hiring

Before committing to a jurisdiction, assess the local candidate market.

How many qualified MLROs, compliance officers, or board members are actually resident there? What salary ranges are realistic? How many candidates are actively searching, and how many will need to be approached directly?

These answers should inform the licensing strategy and hiring timeline from the beginning. They should not emerge as surprises after the search has started.

Look Beyond Crypto When Recruiting Compliance Leaders

Regulated experience from banking, payments, electronic money, asset management, and other financial sectors can transfer directly to many of the governance and control functions required under MiCA.

Crypto knowledge can be developed through structured education and onboarding. Deep experience in governance, regulatory accountability, and supervisory engagement cannot be accelerated as easily.

A candidate with strong regulatory foundations and the ability to learn the business may be more valuable than someone with crypto exposure but limited experience in a regulated institution.

Build Crypto and Product Knowledge Through Structured Onboarding

A new compliance hire needs sufficient time to understand the company’s product, customer journey, technology, transaction flows, business model, and risk exposure.

Good onboarding enables that person to engage with the regulator confidently and explain how the company operates in practice.

It also tends to produce stronger licence applications because the compliance function can connect regulatory requirements to the actual business rather than treating compliance as a separate documentation exercise.

Engage With the Regulator Before Submitting Candidate Profiles

Where the jurisdiction permits it, build a relationship with the regulator early.

Ask which types of candidate profile are likely to work for the company’s specific licence, business model, and governance structure. Discuss profiles that are not obvious matches before completing the formal submission.

When you believe a candidate is suitable, support the case with clear evidence. Explain how their previous experience transfers to the role, identify any knowledge gaps, and present a credible plan for addressing them.

How Long Does MiCA Authorisation Take in Practice?

Since MiCA came into force, I have watched companies move through the full process — from initial preparation and team design to application submission and eventual authorisation.

I have also helped place professionals who led these processes internally. That has made the amount of work behind a licence very clear.

A well-designed compliance team can accelerate the process. A poorly defined or unstable team can stall it.

The strongest candidates are not people who treat every regulatory issue as a reason to retreat. They are people who can interpret requirements, communicate with supervisors, identify workable solutions, and build the internal structures needed to support them.

There are more of these professionals in the market than many crypto companies initially assume. Finding them depends on defining the role correctly, broadening the candidate profile where appropriate, and approaching the regulator as a source of guidance rather than only as an obstacle.

MiCA Compliance Hiring Is Part of the Licensing Process

The companies that move through MiCA authorisation most effectively do not treat recruitment as a parallel HR exercise. They treat hiring as part of the regulatory process itself.

That means starting with a credible licensing plan, understanding the local labour market, remaining open to candidates from other regulated sectors, investing in onboarding, and engaging with the regulator early.

Flexibility does not mean lowering standards. It means understanding which skills are genuinely essential, which can be developed, and how to demonstrate a candidate’s suitability with evidence.

In a difficult licensing environment, that approach can shorten the hiring process, strengthen the application, and give a crypto company a meaningful advantage.

Table of Contents: