2026-02-26

Added · Updated

ESMA Guidelines on criteria for assessment of knowledge and competence under the Markets in Crypto-Assets Regulation (MiCA)

The European Securities and Markets Authority (ESMA) issued guidelines to establish consistent supervisory practices and uniform criteria for assessing the knowledge and competence of staff providing information or advice on crypto-assets. The document mandates that crypto-asset service providers ensure their personnel meet specific educational, experiential, and training requirements, distinguishing between higher standards for advisors and lower thresholds for information providers. It further requires regular professional development, annual internal reviews by management, and compliance with MiCA obligations regarding investor protection and market integrity.

Securities Market Agency Slovenia logo

Slovenia

Securities Market Agency Slovenia

Click to view thumbnail

28/01/2026 ESMA35-24871704-2922 Guidelines on criteria for the assessment of knowledge and competence under the Markets in Crypto-Assets Regulation (MiCA)

1 Table of Contents 1 Scope..........................................................................................................2 2 References to legal sources, abbreviations and definitions.............................................3 2.1 References to legal sources .....................................................................................3 2.2 Abbreviations....................................................................................................................3 2.3 Definitions ....................................................................................................................4 3 Purpose...........................................................................................................................4 4 Compliance and reporting obligations.....................................................................5 4.1 Role of these Guidelines ..................................................................................................5 4.2 Reporting requirements .......................................................................................5 5 Guidelines on criteria for the assessment of knowledge and competence......................................................6 5.1 General (Guideline 1).............................................................................................6 5.2 Criteria for knowledge and competence of staff providing information on crypto-assets or services related to crypto-assets (Guideline 2) ..................................................................7 5.3 Criteria for knowledge and competence of staff advising on crypto-assets or services related to crypto-assets (Guideline 3)..................................................................................10 5.4 Organisational requirements for the assessment, renewal and upgrading of knowledge and competence (Guideline 4) .................................................................................................13 Annex: Illustrative examples of the use of certain aspects of the Guidelines.....................................15

2 1 Scope Who?

  1. These Guidelines are addressed to: a. competent authorities and b. crypto-asset service providers, as defined in Article 3(1), point 15, of the MiCA Regulation. What?
  2. These Guidelines apply to the provision of services related to crypto-assets, referred to in Article 3(1), point 16, of the MiCA Regulation. When?
  3. These Guidelines shall apply six months after the date of their publication in all official EU languages on the ESMA website.

3 2 References to legal sources, abbreviations and definitions 2.1 References to legal sources ESMA Regulation Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority) and amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC1 Insurance Distribution Directive Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution2 MiCA Regulation Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/19373 MiFID II Directive Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU 2.2 Abbreviations EU European Union ESFS European System of Financial Supervision ESMA European Securities and Markets Authority 1 OJ L 331, 15.12.2010, p. 84. 2 OJ L 26, 2.2.2016, p. 19. 3 OJ L 150, 9.6.2023, p. 40.

4 2.3 Definitions 4. Unless otherwise specified, the terms used in the MiCA Regulation have the same meaning in these Guidelines. In addition, the following definitions apply: a. “staff” means natural persons who perform the relevant services for clients on behalf of the crypto-asset service provider; b. “relevant services” means advising on or providing information on crypto-assets or services related to crypto-assets to clients; c. “providing information” means the direct provision of information to clients on crypto-assets or services related to crypto-assets at their request or at the initiative of the crypto-asset service provider in the course of providing services referred to in Article 3(1), point 16, of the MiCA Regulation, provided by employees to clients; d. “knowledge and competence” means appropriate training and appropriate experience in accordance with the requirements of Articles 68 and 81 of the MiCA Regulation for the performance of the relevant services; e. “appropriate training” means completed training or passed test or educational course that meets the criteria set out in these Guidelines; f. “appropriate experience” means that the employee has successfully demonstrated through previous work that they are qualified to perform the relevant services. In addition to the minimum guidelines on appropriate experience set out in these Guidelines, the competent authority may differentiate between periods of experience depending on the appropriate training acquired by the staff and also depending on the relevant services being performed; g. “under supervision” means the performance of relevant services for clients under the responsibility of an employee who is appropriately trained and has appropriate experience. 3 Purpose 5. These Guidelines, prepared by ESMA, are based on Article 81(15), point (a), of the MiCA Regulation and Article 16(1) of the ESMA Regulation. Their purpose is to establish consistent, effective and efficient supervisory practices within the ESFS and to ensure a common, uniform and harmonised application of the provisions of Article 68(5) and Article 81(7) of the MiCA Regulation. 6. ESMA expects in particular that these Guidelines will promote greater harmonisation of criteria for assessing the knowledge and competence of staff advising or providing information on crypto-assets or services related to crypto-assets, and their use. These Guidelines provide important guidance that will help crypto-asset service providers to fulfil their obligations to act in the best interests of the client and enable competent authorities to properly assess how crypto-asset service providers fulfil these obligations. Taking these Guidelines into account, ESMA expects appropriate strengthening of investor protection. 7. The Annex includes a number of illustrative examples of how a crypto-asset service provider could use these Guidelines. 4 Compliance and reporting obligations 4.1 Role of these Guidelines 8. In accordance with Article 16(3) of the ESMA Regulation, competent authorities and crypto-asset service providers must make every effort to comply with these Guidelines. 9. Competent authorities to whom these Guidelines are addressed should comply with them by appropriately incorporating them into their national legal and/or supervisory frameworks, even if individual guidelines are primarily addressed to financial market participants, i.e. crypto-asset service providers. In this case, competent authorities should ensure through their supervision that financial market participants comply with the Guidelines. 4.2 Reporting requirements 10. Competent authorities to whom these Guidelines are addressed must notify the Authority within two months from the date of their publication in all official EU languages on the ESMA website whether they (i) comply with the Guidelines, (ii) do not comply with the Guidelines but intend to comply, or (iii) do not comply with the Guidelines and do not intend to comply. 11. The notification form is available on the ESMA website. The completed form is sent to ESMA. 12. Crypto-asset service providers are not required to report whether they comply with these Guidelines.

6 5 Guidelines on criteria for the assessment of knowledge and competence4 5.1 General (Guideline 1) 13. Crypto-asset service providers should ensure that staff performing relevant services have the necessary knowledge and competence corresponding to the relevant legal and regulatory requirements and standards of business ethics. 14. Crypto-asset service providers should ensure that staff know, understand and apply the internal policies and procedures of the crypto-asset service provider intended to ensure compliance with the MiCA Regulation. To ensure proportional application of knowledge and competence requirements, crypto-asset service providers should ensure that staff have the necessary level of knowledge and competence to fulfil their obligations, taking into account the scope and level of the relevant services being performed. 15. The administrative organ of the crypto-asset service provider should assess and review at least once a year the effectiveness of policies and procedures established to ensure compliance with Article 68(5) and Article 81(7) of the MiCA Regulation and these Guidelines, and take appropriate measures to remedy any deficiencies identified in this regard. 16. Staff providing advice on crypto-assets and services related to crypto-assets are expected to have a greater scope and depth of knowledge and competence than staff who merely provide information on crypto-assets and services related to crypto-assets. 17. Where information or advice on crypto-assets or services related to crypto-assets is provided automatically or semi-automatically, crypto-asset service providers should ensure that these Guidelines apply to staff responsible for determining the content of information or advice provided to clients. Staff determining parameters and deciding on settings for such information or advice provided should also have sufficient knowledge and competence to ensure that relevant information or advice is provided accurately, in appropriate circumstances and to the right recipients. 4 These Guidelines apply without prejudice to any other guidelines on knowledge and competence of staff providing financial services, such as Guidelines on the assessment of knowledge and competence under the MiFID II Directive (ESMA71-1154262120-153).

7 5.2 Criteria for knowledge and competence of staff providing information on crypto-assets or services related to crypto-assets (Guideline 2) 18. Crypto-asset service providers should ensure that staff providing information on crypto-assets or services related to crypto-assets available through the crypto-asset service provider have the necessary knowledge and competence to understand: a. the main characteristics, risks and specifics of the crypto-asset services offered by the crypto-asset service provider and the crypto-assets made available by the crypto-asset service provider through these services, and the operation of distributed ledger technology, the main characteristics and operation of various protocols used, and the impact they may have on transactions in crypto-assets or services related to crypto-assets. Special care is required when providing information on risks associated with more complex and volatile crypto-assets; b. the types of costs and commissions incurred by the client in transactions in crypto-assets or the provision of services related to crypto-assets, and how they contribute to the total amount; including commissions charged by crypto-asset service providers for their services, and other costs, such as costs incurred through the relevant distributed ledger technology network (e.g. transaction fees); c. the operation of crypto-asset markets and their impact on the value and price of crypto-assets on which staff provide information to clients, including: ● characteristics, operation and risk of different types of crypto-assets, ● possible impact of investor sentiment and social media on rapid price changes of crypto-assets in very short time periods (“high price volatility”), which may be difficult to predict, ● possible impact of holders of large amounts of crypto-assets on liquidity and price volatility in crypto-asset markets5 ; 5 For example, regarding liquidity, investors holding large amounts of crypto-assets often hold their assets for longer periods, which results in less crypto-assets being available to other investors in the market. Or regarding volatility, holders of a large number of crypto-assets can cause significant price movements in the market if they suddenly sell a large portion of their crypto-assets or all their crypto-assets.

8 d. the impact of economic data, key national/regional/global events on markets and the value of crypto-assets on which information is provided; e. the difference between past performance and future performance scenarios and the limitations of forecasting; f. the difference between investor protection measures for clients investing in crypto-assets and using services related to crypto-assets under the MiCA Regulation and clients investing in financial instruments and using investment services regulated by the MiFID II framework, and the impact of these differences on the protection of clients investing in crypto-assets and using services related to crypto-assets; g. issues related to market abuse and the prevention of money laundering and terrorist financing; h. data relating to crypto-assets on which staff provide information to clients, such as white papers and financial statements or financial data; i. specific market structures for crypto-assets on which staff provide information to clients, and their trading platforms6 or the existence of secondary markets, where appropriate; j. the basic valuation mechanisms used for crypto-assets on which information is provided. For the purposes of point a. above, the following key risks should be taken into account at least: ● volatility, ● cybersecurity risks, such as risks of intrusions and theft of clients’ crypto-assets, ● risks related to the client’s improper storage of private cryptographic keys, ● risks related to IT programming, for example, incorrect operation of IT programs due to software programming defects (“bugs”) could result in the loss of clients’ crypto-assets, 6 For example, crypto-asset trading platforms that are open 24 hours.

9 ● risks related to the transfer of crypto-assets, such as the risk of loss of crypto-assets if the client chooses a distributed ledger technology network that does not support the transfer of the crypto-asset. For the purposes of point a. above and in particular to understand the main characteristics and operation of specific protocols, staff providing information on crypto-assets or services related to crypto-assets should have, in particular, a basic understanding of: ● the consensus mechanism used for the protocol and its implications, ● rules for validating transactions within this protocol, ● the scalability of the protocol, ● its level of decentralisation and governance structure and measures taken to protect the network against attacks or fraud, ● its interoperability, ● its use case (main purpose or use supported by the protocol, such as payment systems, supply chain, smart contracts), ● the economic model governing the crypto-asset, including supply, distribution and incentives for validation. 19. Crypto-asset service providers should ensure that staff providing information on crypto-assets or services related to crypto-assets on their behalf have acquired appropriate knowledge and competence regarding the points in paragraph 18 before providing such information. This should be demonstrated by a successful assessment conducted by the crypto-asset service provider itself or an external body, for example: a. completed professional training of at least 80 hours and at least six months of appropriate experience under supervision or b. at least one year of appropriate experience under supervision. 20. Crypto-asset service providers may consider existing employees who, on the date of application of these Guidelines, provide information on crypto-assets or services related to crypto-assets7, to have the necessary knowledge and competence to fulfil their obligations, by (i) successfully providing information on crypto-assets or services related to crypto-assets on a full-time equivalent basis, (ii) under supervision or without it and (iii) for at least one year prior to the application of these Guidelines. 7 This includes employees who provided clients with information on crypto-assets or services related to crypto-assets on behalf of providers of services related to virtual assets under the national regulatory framework before the application of the MiCA Regulation.

10 obligations, by (i) successfully providing information on crypto-assets or services related to crypto-assets on a full-time equivalent basis, (ii) under supervision or without it and (iii) for at least one year prior to the application of these Guidelines. 21. Crypto-asset service providers should determine an appropriate minimum number of hours of continuing professional development or training per year for staff providing information on crypto-assets or services related to crypto-assets, based on the nature of the crypto-assets and services related to crypto-assets on which they provide information, taking into account: ● the existing knowledge and competence of employees providing information on crypto-assets or services related to crypto-assets, and ● relevant regulatory changes, key market developments and new emerging technologies, including any associated risks for investors. For example, staff providing information on a limited range of crypto-assets or services related to the least complex crypto-assets should complete 10 hours of continuing professional development or training. Crypto-asset service providers should ensure that their staff providing information on crypto-assets or services related to crypto-assets complete the appropriate number of hours of continuing professional development or training per year, as determined by themselves, either by participating in a continuing professional development or training scheme managed by an external professional educational body providing a recognised qualification, or within the framework of continuing professional development or training hours organised by themselves. Both options for organising continuing professional development or training should include verification of the acquired knowledge and competence of participants. Competent authorities may publish a list of external professional educational bodies providing a recognised qualification. 5.3 Criteria for knowledge and competence of staff advising on crypto-assets or services related to crypto-assets (Guideline 3) 22. Crypto-asset service providers should ensure that staff advising on crypto-assets or services related to crypto-assets comply with paragraph 18 of Guideline 2, as it is also appropriate for such staff. 23. In addition, crypto-asset service providers should ensure that staff advising on crypto-assets or services related to crypto-assets understand: a. the total costs and commissions incurred by the client in the course of advice, including commissions charged by crypto-asset service providers for their services (including advice), and other costs, such as costs incurred through the relevant distributed ledger technology network (e.g. transaction fees); b. the obligations of crypto-asset service providers related to suitability requirements under Article 81 of the MiCA Regulation, including obligations set out in the Guidelines on certain aspects of suitability requirements and the form of the regular report on portfolio management activities under the MiCA Regulation8 ; c. that a specific crypto-asset or crypto-assets provided by the crypto-asset service provider may not be suitable for the client, after reviewing the relevant information provided by the client, given changes that may have occurred since the relevant information was collected; d. the basics of portfolio management, also by understanding the consequences of diversification in individual other investment options, and e. the valuation mechanisms used for crypto-assets on which advice is given. 24. Crypto-asset service providers should ensure that staff advising on crypto-assets or services related to crypto-assets on their behalf have acquired appropriate knowledge and competence regarding the points in paragraphs 22 and 23 before providing such advice. This should be demonstrated by a successful assessment conducted by the crypto-asset service provider itself or an external body, and for example: a. with a tertiary education diploma9 for a three-year study, appropriate for advising on crypto-assets or services related to crypto-assets, and at least one year of appropriate experience in performing relevant services related to crypto-assets under supervision, or b. with secondary education and completed at least three-year professional training and at least one year of appropriate experience in performing relevant services related to crypto-assets under supervision, or c. with completed professional training of at least 160 hours and at least one year of appropriate experience in performing relevant services related to crypto-assets under supervision, or d. with at least two years of work experience in advising under the MiFID II Directive or the Insurance Distribution Directive before starting advice on crypto-assets and services related to crypto-assets and at least six months of appropriate experience in performing relevant services related to crypto-assets under supervision. 8 Available here. 9 For example, a university degree or equivalent education in a field such as economics, law or business administration.

12 d. with at least two years of work experience in advising under the MiFID II Directive or the Insurance Distribution Directive before starting advice on crypto-assets and services related to crypto-assets and at least six months of appropriate experience in performing relevant services related to crypto-assets under supervision. 25. Crypto-asset service providers may consider existing employees who, on the date of application of these Guidelines, advise on crypto-assets or services related to crypto-assets10, to have the necessary knowledge and competence to fulfil their obligations, by (i) successfully advising on crypto-assets or services related to crypto-assets on a full-time equivalent basis, (ii) under supervision or without it and (iii) for at least one year prior to the application of these Guidelines. 26. Crypto-asset service providers should determine an appropriate minimum number of hours of continuing professional development or training per year for staff advising on crypto-assets or services related to crypto-assets available through the crypto-asset service provider, based on the nature of the crypto-assets and services related to crypto-assets on which they advise, taking into account: a. the existing knowledge and competence of employees advising on crypto-assets or services related to crypto-assets11, and b. regulatory changes, key market developments and new emerging technologies, including any associated risks for investors. For example, staff advising on a limited range of crypto-assets or services related to the least complex crypto-assets should complete 20 hours of continuing professional development or training12. Crypto-asset service providers should ensure that their staff advising on crypto-assets or services related to crypto-assets complete the appropriate number of hours of continuing professional development or training per year, as determined by themselves, either by participating in a continuing professional development or training scheme managed by an external professional educational body providing a recognised qualification, or within the framework of continuing professional development or training hours organised by themselves. Both options for organising continuing professional development or training should