Live Updates

Circular CSSF 26/909

AI Analysis

Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.

Key dates

1 April 2026
Circular CSSF 26/909 published; immediate application of ESMA competence guidelines.; [User-provided content]

Suggested considerations

  • Assess Staff Competence: Implement ESMA-guided evaluations (e.g., exams, certifications) for all relevant personnel handling crypto services; document results in governance frameworks.
  • Update Policies and Training: Integrate competence criteria into HR, onboarding, and annual reviews; roll out MiCA-specific training on reporting, breaches, and governance.
  • Licensing Dossier Enhancement: Include competence attestations in CSSF applications; appoint dedicated compliance/risk officers with verified qualifications.
  • Ongoing Monitoring: Conduct regular audits, penetration tests, and incident planning; confirm compliance annually via management body statements.
  • Early CSSF Engagement: Schedule dialogues and info sessions; create MiCA readiness scorecards for board and regulator discussions.

What changed

  • - Adoption of ESMA Guidelines: CSSF mandates application of ESMA's criteria for evaluating staff knowledge and competence in crypto-asset services, including roles in custody, trading, portfolio management, and issuance/redemption of ART/EMT.
  • Assessment Framework: Firms must implement standardized tests and processes to verify staff qualifications, aligning with MiCA Article 62 on CASP authorization, focusing on technical crypto knowledge, regulatory awareness, and ethical standards.
  • No New Standalone Rules: This circular builds on prior CSSF MiCA circulars (e.g., 25/890 on crypto-asset classification), integrating competence checks into licensing dossiers and ongoing supervision.

Compliance impact

Urgency: High – With publication today (1 April 2026) and MiCA's CASP regime live since 30 December 2024, firms face immediate supervisory scrutiny during licensing and VASP transitions ending 1 July 2026. Non-compliance risks authorization denial, enforcement, or operational halts, especially as CSSF audits dossiers for competence gaps amid Luxembourg's role as MiCA hub.

Who is affected

  • Crypto-Asset Service Providers (CASPs)
  • defined services (e.g., trading venues, custodial wallets, order execution, payment services, portfolio management).
  • ART/EMT Issuers and Service Providers
  • referenced tokens (ART) or e-money tokens (EMT), compliant since 30 June 2024.
  • Transitional VASPs
  • 30 December 2024 registered virtual asset service providers under 18-month grandfathering until 1 July 2026.
  • Regulated Financial Entities
  • ESMA Guidelines (ESMA35-24871704-2922)
  • Circular CSSF 25/890 (30 April 2025)
  • asset classification (Article 97(1) MiCA), complementary to competence assessments (https
  • content/uploads/cssf25_890eng.pdf).25
  • Copla Blog on MiCA in Luxembourg
  • CSSF MiCA Page

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

Crypto ExchangeBankFintechPayment Provider
View Original on CSSF Back to Feed

Share this update