Tape scan →

MiCA Article 92 market-abuse surveillance — what CASPs must do

Under Article 92 of MiCA (Regulation (EU) 2023/1114), every crypto-asset service provider must have systems and procedures to prevent, detect and report market abuse. The transitional period that let pre-existing CASPs keep trading without full authorisation is now closed in every EU/EEA state — the latest national window shut 1 July 2026, and several states closed six to twelve months earlier. If you're not authorised now, supervisors expect a demonstrably working surveillance system already in place — not a policy document. This guide covers the behaviours you must monitor, the reporting obligation, the exact deadline by country, and what a credible system looks like.

What Article 92 requires

CASPs operating a trading platform — and, more broadly, any CASP handling client orders and trades — must establish and maintain effective arrangements, systems and procedures to prevent and detect market abuse, and to report suspicious orders and transactions to their national competent authority. MiCA deliberately mirrors the Market Abuse Regulation (MAR) that governs traditional markets, so the detection bar is comparable to a regulated exchange's.

The behaviours you have to detect

PatternWhat it looks like on the tape
Wash tradingThe same beneficial owner on both sides of a trade — no real change of ownership.
SpoofingLarge orders placed away from the touch and cancelled before execution to mislead.
LayeringMultiple non-bona-fide orders at several price levels, then cancelled.
Marking the closeA participant dominating volume in the closing window to move the reference price.
Momentum ignition / rampingAggressive buying to start a price move, then reversing into the crowd.
Insider dealing & unlawful disclosureTrading or tipping ahead of inside information about a crypto-asset.

The reporting obligation (STOR)

When your monitoring flags activity that might constitute market abuse, your compliance officer assesses it and, if suspicion is confirmed, files a Suspicious Transaction and Order Report (STOR) with the competent authority without delay. A working system therefore needs not just detection but triage and a draftable, auditable report trail — supervisors will ask to see both the alerts you raised and the ones you dismissed, with reasons.

What a credible system needs

Status, as of todayClosed — everywhereEvery national transitional window is now shut. The latest (18-month default) closed 1 July 2026; several states closed as early as 30 June 2025. A CASP still operating without authorisation today is not grandfathered.

The exact deadline, by country

Article 92 sits inside the same transitional regime as CASP authorisation itself (MiCA Article 143(3)): a provider active before 30 December 2024 could keep operating for a window each member state set individually, from 6 to 18 months. Every window has now closed. Verified against ESMA's official published list of national grandfathering periods.

WindowClosedStates
18 months (default)1 Jul 2026Belgium, Bulgaria, Czechia, Denmark, Estonia, Greece, Spain, France, Croatia, Italy, Cyprus, Luxembourg, Malta, Portugal, Romania, Iceland, Liechtenstein
12 months30 Dec 2025Germany, Ireland, Lithuania, Austria, Slovakia, Norway
9 months30 Sep 2025Sweden
6 months30 Jun 2025Latvia, Hungary, Netherlands, Poland, Slovenia, Finland

A few states attached extra conditions to keep the window open (e.g. Bulgaria, Czechia and Italy required an authorisation application filed by a specific date in 2025) — check your national competent authority for anything state-specific.

Scan your tape for market abuse

Run the surveillance scan →
No signup · your tape never leaves your browser

This guide is general information, not legal advice. Confirm the current requirement against MiCA (Regulation (EU) 2023/1114), the relevant RTS, and your national competent authority before you rely on it.