TRUSTIFY LEGAL

Adaptation to MICA (the new EU crypto legislation) Adaptation to DORA (the new EU information security legislation)

We provide comprehensive legal assistance in adapting to the new European crypto legislation MICA, including:

  1. Advising on the full scope of the MICA requirements for various types of activities of crypto companies (“VASPs”), including the “transition period” for the adaptation to the MICA
  2. Advising on the classification of tokens under the MICA
  3. Advising on the procedure for issuing tokens, preparation of relevant documentation for their issuance
  4. Assistance in preparing applications for VASP authorization in accordance with MICA
  5. Developing policies and procedures that meet the requirements of MICA:
  • Revising the User agreement in accordance with MICA requirements
  • Preparation of all documents required to be posted on the website in accordance with MICA
  • Conflict of interest policies
  • Business continuity plan and policy
  • Complaint handling policy (in accordance with the new requirements)
  • Procedure for segregation of clients’ crypto assets and ensuring that the means of access to clients’ crypto assets are clearly identified
  • Accounting policy
  • Custodial and administrative policies
  • Commercial policy
  • Policy on execution of client orders
  • Warnings about the risks associated with crypto assets
  • Policy for identifying, preventing, managing and disclosing conflicts of interest
  • Policy on remuneration in VASP
  • Policy on insider information
  • Policy on outsourcing 
  • Notification of the major negative climate impacts and other negative environmental impacts of the mechanism used to issue each crypto asset for which the VASP provides services
  • Revising the relevant AML policies
  • Wind down policy
  • Policies and procedures for risk identification, assessment and management
  • Technical documentation on information security systems
  • Rules of operation of the trading platform and procedures and systems for detecting market abuse
  • Pricing policy
  • Policies in accordance with the DORA (on the use of information and communication technology (“ICT”) services provided by third-party service providers, on the ICT risk management system, on ensuring the availability, authenticity, integrity and confidentiality of data, etc.)
  • Procedure for keeping records of all cryptoasset services, orders and transactions
  • Other policies and procedures, depending on the type of VASP’s activities. 
  •  

6. Preparation of documents and registration of VASP capital increase

7. Advising on the technical requirements developed by the European Securities and Markets Authority (ESMA), requirements of local legislation of EU member states

8. Assistance in developing marketing and advertising strategies that meet the requirements of MICA

9. Advice on cross-border compliance for VASPs operating in several EU jurisdictions

10. Conducting a company audit for compliance with MICA requirements

11. Advising on the provision of services by crypto companies registered outside the EU.

We provide comprehensive legal assistance in adapting to the new European information security legislation DORA, including:

  1. Advising on the application of DORA
  2. Development of policies and procedures that meet the requirements of DORA: 
  • ICT asset management policy 
  • Encryption & cryptographic controls policy
  • ICT project management policy
  • Acquisition, development and maintenance of ICT systems policy
  • Physical and environmental security policy
  • Human resources policy
  • Identity management policy
  • Access control policy
  • ICT-related incident management policy
  • ICT business continuity policy
  • ICT asset management procedure
  • Capacity and performance management procedure
  • Vulnerability and patch management procedure
  • Data and system security procedure
  • Logging procedure
  • Acquisition, development, and maintenance of ICT systems procedure
  • ICT change management procedure 
  • Identity management procedure
  • ICT risk management policy and procedure
  • ICT operations policy and procedure
  • Network security management policy and procedure
  • Security information in transit policy and procedure
  • Other policies, procedures, forms, registers
  •  

Request a consultation

    More on our other services

    Subscribe to our newsletter

    Sign up to receive email updates on new product announcements, special offers, sales and more.

    Subscription Form