The Spanish transitional regime ended on 1 July 2026. Since that date, crypto-asset services can only be provided in Spain by firms authorised by the CNMV or passporting in from another Member State. Regulation (EU) 2023/1114 is no longer on the horizon: it is the condition for operating.
Where cybersecurity sits in a MiCA file
MiCA is not just a licensing formality. Much of what the authority reviews — and then supervises — is demonstrable technical and organisational capability:
Custody and safeguarding of client crypto-assets and funds: segregation, key management, signing procedures, privileged access control and traceability of every operation.
ICT security systems and protocols proportionate to volume and risk, with evidenced business continuity and recovery.
Governance: a management body with sufficient knowledge, control functions and conflict-of-interest management.
Incident and complaint handling, with written and rehearsed procedures.
DORA in parallel: authorised crypto-asset service providers fall within the scope of the digital operational resilience regulation. These are two files worth running together, because they share half the evidence.
We have worked with exchanges. The difference between a file that moves and one that stalls is almost never the wording of the policies: it is whether technical evidence exists to back up what those policies promise.
What we do
Phase 1
Gap analysis
We measure the real distance between what the regulation demands and what you have today, control by control. No generic checklists: we review evidence, not statements of intent.
Phase 2
Action plan
Every gap becomes a task with an owner, an effort estimate and a priority based on risk. You decide what comes first knowing what protects you most.
Phase 3
Remediation
We work alongside you through delivery: policies, procedures, technical controls and evidence, until compliance holds up in front of an auditor.
Scope of work
Gap analysis of the technical and organisational requirements applicable to the service or services you provide.
Review of the custody architecture: key lifecycle management, hot and cold wallets, multi-signature schemes, environment segregation and dual authorisation controls.
Technical audit of the platform: web application, API, cloud infrastructure and third-party integrations.
Review of smart contracts and the deployment process, where they form part of the service.
Continuity and recovery: impact analysis, recovery objectives and a real test of the plan.
Alignment with DORA, so the same work is not done twice.
How we work
1
Service and obligation mapping
Which of the services listed in the regulation you provide and what each one drags along. The scope of the file depends on this.
2
Technical and organisational gap analysis
Requirements tested against evidence: configurations, custody procedures, access logs, previous test reports.
3
Action plan
Prioritised by what blocks authorisation and by what most exposes client funds, with owners and effort estimates.
4
Remediation
Support through implementation and through drafting the technical documentation that backs the file.
5
Verification
Technical testing to confirm that what was implemented holds. An independent pentest report supports a file far better than a self-declaration.
What you get
Gap analysis by requirement, with maturity level and linked evidence.
Technical report on the custody architecture and its single points of failure.
Action plan, separating what blocks authorisation from what can follow later.
Supporting technical documentation, written to be read by a supervisor.
Penetration test report covering platform and infrastructure, with retesting of the fixes.
MiCA–DORA overlap matrix so evidence can be reused.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Do you handle the CNMV authorisation file?
No. The file is run by your legal and financial advisers; we cover cybersecurity, technical custody and resilience, which is the part that usually falls short. We work alongside your firm, not instead of it.
We already passport from another Member State. Does this affect us?
The passport lets you operate, but it does not exempt you from evidencing the same technical requirements to your home authority, or from answering to the CNMV in supervision. And DORA applies to you all the same.
Our custody is with a third party. Does that remove the problem?
It transfers it, it does not remove it. It becomes third-party risk: the custodian must be assessed, the contract must carry the right clauses and there must be an exit strategy. DORA requires this explicitly.
Do you review smart contracts?
Yes, where they form part of the service: logic, access control, deployment key management and the upgrade process. Reviewing the code alone is not enough if anyone can deploy a new version unchecked.
Talk to people who have audited exchanges
Half an hour with an auditor to review what is missing on the technical side of your file and how to align it with DORA without duplicating work.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

