By NHI Mgmt Group Editorial TeamBased on SumSub: “EU Watchdog EBA Outlines Fines Under MiCA Enforcement Framework” (June 29, 2026)

TL;DR: The European Banking Authority has outlined a draft method for calculating MiCA fines, with penalties for significant ART issuers capped at 12.5% of annual turnover and significant EMT issuers at 10%, according to SumSub. That enforcement posture turns regulatory passporting, disclosures, and organisational controls into immediate governance priorities rather than back-office compliance tasks.


At a glance

What this is: This is a report on the EBA’s draft MiCA fines methodology, which would let the regulator scale penalties for significant ART and EMT issuers based on seriousness, duration, intent, financial strength, and mitigating or aggravating factors.

Why it matters: It matters because crypto compliance teams now have to treat passporting, disclosures, and organisational controls as measurable enforcement exposures, not just regulatory paperwork.


Context

The European Banking Authority has moved MiCA enforcement from general expectations into a draft penalty methodology. For crypto issuers, the practical issue is no longer only whether a rule exists, but how the regulator will score intent, duration, financial strength, and organisational weakness when setting a fine.

That matters most for significant asset-referenced token and e-money token issuers supervised under MiCA, because enforcement now has a visible calculus rather than an open-ended warning. The article frames the problem as compliance execution under regulatory scrutiny, not product design or market expansion.


Key questions

Q: What fails when MiCA compliance is treated as paperwork instead of an operational control?

A: What fails is the evidence chain. If passporting, disclosures, and governance decisions are not recorded as operational controls, a firm cannot show how long a weakness existed, who approved it, or whether remediation happened before the regulator calculated a fine.

Q: Why does the EBA’s MiCA fines framework raise accountability risk for management bodies?

A: Because the draft proposal explicitly covers management body members when an infringement is intentional or negligent. That means oversight, escalation, and approval records can become part of the enforcement case, not just internal governance notes.

Q: What should crypto compliance teams review before MiCA passporting deadlines?

A: They should review whether disclosures, organisational controls, and supervisory records are ready to withstand enforcement scrutiny. If the firm cannot demonstrate control maturity before the deadline, it risks operational interruption as well as penalties.

Q: What is the difference between a MiCA disclosure failure and an organisational failure?

A: A disclosure failure is a specific compliance lapse, while an organisational failure shows the control environment itself is weak. Under the draft EBA approach, both can influence the penalty outcome because the regulator is assessing not only the breach, but how governance failed around it.


Technical breakdown

How the EBA’s MiCA fines methodology turns compliance into a scored control problem

The draft framework describes a multi-step penalty calculation rather than a flat sanction model. That means the regulator can translate seriousness, duration, intent, negligence, financial strength, and aggravating or mitigating circumstances into an administratively defensible fine. For practitioners, the key technical shift is that compliance evidence must be structured enough to show control performance, not just policy existence. In practice, this places more weight on auditability, governance records, and the ability to demonstrate why an issue happened and how long it persisted.

Practical implication: Build evidence trails that can withstand a fines methodology based on severity, duration, and intent.

Why management body accountability now sits inside MiCA enforcement

The draft proposal explicitly covers members of an issuer’s management body when an infringement is intentional or negligent. That broadens the governance surface beyond operational compliance teams and places responsibility on decision-makers who approve posture, disclosures, and remediation timing. In identity terms, this is an organisational accountability problem as much as a regulatory one. When oversight is weak, penalties can attach to governance failure, not just a missing control checkbox.

Practical implication: Assign named ownership for MiCA obligations at management level, with documented decisions and escalation paths.

What passporting and disclosure failures mean under the new enforcement posture

The article ties enforcement pressure to failures such as unauthorised disclosures and organisational shortcomings that can force firms to halt operations. That makes regulatory passporting a live governance dependency rather than a static licence condition. The mechanism here is simple: once the regulator has a penalty framework, disclosure quality, organisational readiness, and timing of compliance actions become part of the enforcement record. Teams should treat passport maintenance and disclosure controls as continuously monitored obligations.

Practical implication: Review passporting, disclosure, and organisational control readiness before deadlines create avoidable enforcement exposure.


NHI Mgmt Group analysis

MiCA enforcement is becoming a governance measurement problem, not a policy exercise. Once fines are calculated through seriousness, duration, intent, and mitigating factors, firms must prove how controls behaved over time, not merely that controls existed. That shifts compliance evidence into the same operational discipline as identity governance and audit readiness. Practitioners should assume the regulator will judge the story their controls tell, not only the policy they point to.

Management accountability now extends the enforcement surface beyond the compliance function. The draft framework explicitly includes members of the issuer’s management body where infringements are intentional or negligent. That means regulatory failure can no longer be isolated to an operational team’s backlog or a single control owner. For practitioners, governance records, approvals, and escalation evidence become part of the control system itself.

Regulatory passporting has become an operational dependency with a penalty profile. The article’s warning about organisations that fail to secure passports by the deadline shows that MiCA compliance is not just about meeting disclosure rules. It is also about preserving the right to operate without interruption. The implication is that compliance status, organisational readiness, and remediation speed must be managed as one control plane.

Organisational failures are now enforceable, not merely internal deficiencies. The draft methodology gives regulators a way to convert weak process, delayed response, and poor oversight into quantified penalties. That matters because it collapses the gap between legal obligation and operational execution. Compliance leaders should treat organisational weakness as a measurable exposure, not a vague governance concern.

What this signals

Penalty methodology changes the compliance incentive structure. Once enforcement can account for seriousness, duration, and financial strength, teams need more than a policy library. They need evidence that supervisory obligations are monitored, escalated, and resolved as part of normal operations.

Passporting and disclosure readiness should be managed as one control domain. The article shows that the practical risk is not only being out of compliance, but being unable to continue operating if the regulator sees organisational weakness. That makes readiness testing a standing governance activity, not a deadline-only exercise.


For practitioners

  • Map MiCA obligations to accountable owners Document which senior leaders own passporting, disclosure, and issuer compliance decisions so regulatory failures cannot be treated as anonymous process drift.
  • Build evidence for enforcement factors Retain records that show seriousness, duration, intent, negligence, and remediation timing so the organisation can explain control performance under a penalty review.
  • Test organisational readiness before deadlines Run readiness checks for disclosure quality, supervisory reporting, and operating conditions that could trigger halts or sanctions if the regulator reviews them now.

Key takeaways

  • The EBA’s draft MiCA fines framework turns compliance failures into measurable enforcement outcomes for significant ART and EMT issuers.
  • Penalty calculations can reflect seriousness, duration, intent, financial strength, and mitigating or aggravating circumstances.
  • Crypto firms should treat passporting, disclosures, and management accountability as operating controls that must be demonstrable under scrutiny.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while PCI DSS v4.0 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe article is about regulator-scored compliance risk and enforcement posture.
GV.OV-01 — Oversight and AccountabilityManagement body accountability is central to the draft fines framework.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsOrganisational controls and passporting readiness depend on governed authorisation paths.
Recommendation — Align MiCA compliance evidence to governance records that show how regulatory risk is identified and managed. Document oversight decisions so management accountability is clear in the event of an enforcement review. Review authorisation governance where compliance actions rely on controlled approvals and sign-off.
PCI DSS v4.012.1 — Roles and responsibilities for securityThe article emphasises accountability and governance ownership for regulated obligations.
Recommendation — Assign clear responsibility for regulated obligations so enforcement gaps do not sit with undefined owners.

Key terms

  • Administrative Fine Methodology: A formal way of calculating penalties based on the facts of a violation rather than applying a flat sanction. In this article’s context, it means the regulator can weigh seriousness, duration, intent, and mitigating factors when deciding the final amount.
  • Regulatory Passporting: Regulatory passporting is the permission a firm needs to operate across jurisdictions under a common rule set. In practice, it depends on accurate filings, ongoing supervision, and continued compliance with the obligations attached to the permission.
  • Management Body Accountability: Management body accountability is the principle that senior decision-makers can be held responsible for intentional or negligent governance failures. It matters because delegated authority does not remove the need for traceable oversight, documented approval, and evidence of review.
  • Organisational Failure: A breakdown in the control environment that goes beyond a single missed task or isolated error. It usually reflects weak processes, poor escalation, or inadequate oversight, and it can become directly relevant to enforcement when regulators assess how the failure emerged.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org