EDCA-P06 · Governed by EDCA-STD-07
Crypto-Asset Service Certification
An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.
This certification is an assessment of security and operational controls. It is not an authorisation to provide crypto-asset services, and it is not a licence, registration or approval under Regulation (EU) 2023/1114 (MiCA), Regulation (EU) 2023/1113, or any national anti-money-laundering registration regime. An organisation requiring such authorisation must obtain it from the competent authority of its Member State; certification by the Agency neither substitutes for it nor influences it.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- Named crypto-asset services and the chains and assets they support
- Custody arrangements, wallet architecture and signing infrastructure
- Client asset segregation, records and reconciliation
- Smart contracts deployed or controlled by the organisation
- Nodes, bridges and third-party providers the service depends on
What is examined
Each area below is assessed against the requirements of EDCA-STD-07, Crypto-Asset and Distributed Ledger Security, version 1.0.
- Key generation, storage, backup and recovery
- Wallet architecture and separation of hot, warm and cold holdings
- Transaction authorisation, approval thresholds and dual control
- Segregation of client assets and reconciliation to on-chain balances
- Counterparty and address screening, including transfer-of-funds data
- Smart contract security, audit history and change control
- Availability of the service and handling of on-chain incidents
Programme particulars
- Programme code
- EDCA-P06
- Governing standard
- EDCA-STD-07 — Crypto-Asset and Distributed Ledger Security, version 1.0, issued 14 July 2026
- Levels available
-
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology - Typical duration
- Ten to sixteen weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Custody model documentation and key ceremony records
- Wallet inventory with the classification of each wallet
- Signing policy, approval thresholds and authorised signatory list
- Reconciliation reports between internal records and on-chain balances
- Screening procedure and provider configuration
- Smart contract source, deployment records and third-party audit reports
- Business continuity plan covering loss of key material
Apply for Crypto-Asset Service Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.