Prepare the business before the application
APOG helps crypto-asset businesses prepare the governance, AML, operational and technology framework required for a credible MiCA and CASP authorisation process. We focus on the operating model behind the application: responsibilities, controls, procedures and evidence that the organisation must be able to apply in practice.
A CASP application is not simply a collection of policies. The documentation must reflect the services provided, the organisation’s actual structure, its risk profile and the way management, compliance, operations and technology work together. We help identify gaps early and turn regulatory requirements into an achievable implementation plan.
Current position in Poland — updated August 2026
Poland has not yet designated a national competent authority for CASP authorisation. Following the expiry of the MiCA transitional period on 1 July 2026, a domestic Polish authorisation procedure cannot be initiated until national legislation designates the competent authority.
APOG therefore does not present a KNF CASP licence application as a currently available route. We help clients assess a legally and operationally viable EU regulatory route, prepare the underlying operating model and remain ready for further developments in Poland.
What needs to be ready
01
Governance and organisation
Corporate structure, management responsibilities, programme of operations, internal control functions, conflicts of interest, outsourcing, complaints handling and decision-making arrangements.
02
AML, KYC and Travel Rule
Business-wide and customer risk assessments, KYC/KYB/EDD, sanctions and PEP screening, transaction monitoring, suspicious-activity escalation and Travel Rule controls.
03
Operations, resilience and safeguarding
Prudential safeguards, client-asset arrangements, record keeping, business continuity, ICT governance, DORA-aligned operational resilience and incident-management processes.
How the engagement works
01
Clarify the regulatory route
We review the services, group structure, intended markets, establishment and regulatory assumptions to identify the questions that must be resolved before documentation is prepared.
02
Assess readiness and gaps
We compare the current organisation, documentation and controls with the applicable MiCA, AML, Travel Rule and operational-resilience requirements.
03
Build and evidence the model
We support the development of policies, governance arrangements, controls, implementation evidence and a decision-ready document pack aligned with the selected regulatory route.
What APOG can support
- MiCA and CASP readiness assessments,
- regulatory requirements and documentation matrices,
- programme of operations and governance documentation,
- AML/CFT, KYC/KYB and customer-risk frameworks,
- Travel Rule procedures and operational controls,
- outsourcing, conflicts-of-interest and complaints procedures,
- ICT governance, business continuity and DORA-related documentation,
- prudential, safeguarding and record-keeping arrangements,
- implementation roadmaps, ownership and evidence tracking,
- management workshops and readiness challenge sessions.
Documentation must match the business
We do not begin with generic policy templates. The documentation is developed around the proposed crypto-asset services, customer types, transaction flows, jurisdictions, technology, outsourcing arrangements and the responsibilities of the management body.
Where is your MiCA project today?
Tell us which services you intend to provide, where the business will be established and which elements of the operating model already exist. We will propose the most proportionate starting point: regulatory-route assessment, readiness review or a defined implementation phase.
APOG supports regulatory readiness, AML design and operational implementation. Authorisation decisions are made exclusively by the relevant competent authority. The appropriate home Member State and regulatory route must reflect the client’s actual establishment, governance and operating model.