Regulon delivers end-to-end MiCA compliance infrastructure for crypto-asset service providers. 9 modular components. 130+ production integrations. 38 full CASP platforms shipped since 2016.
Regulon is a MiCA compliance platform company based in Valletta, Malta, that designs, deploys and operates modular regulatory infrastructure for crypto-asset service providers across the European Economic Area. Founded in 2016 by Dr. Marco Bonnici, it has shipped 38 full CASP compliance platforms and maintains more than 130 live integration connections to wallets, exchanges, KYC providers and supervisory reporting gateways.
Regulon's platform gives CASPs a single authoritative compliance layer: pre-wired modules, pre-built integration adapters, and a documented change-management process that tracks every ESMA technical standard update.
We configure and deploy all 9 compliance modules to your infrastructure (cloud or on-premise), connect your existing data sources via pre-built adapters, and validate the full platform against the MFSA authorisation checklist before submission.
130+ pre-built adapters connect Regulon to your wallet custody, exchange engine, KYC/AML provider, oracle feed, travel-rule network and national reporting gateway. Custom connectors are built under a fixed-scope engagement.
On the Operate retainer, our team monitors regulatory change, updates modules to each ESMA technical standard revision, generates monthly prudential reports, manages AML alert queues, and maintains your DORA ICT incident log.
Any entity requiring CASP authorisation under Regulation (EU) 2023/1114 is in scope. Regulon serves the following market segments.
Each module is independently deployable and pre-integrated with the others. Deploy one to fill a gap or all nine for a full MiCA compliance stack.
Customer due diligence, enhanced due diligence, PEP and sanctions screening, ongoing monitoring, and suspicious transaction reporting to the national FIU.
Real-time surveillance for insider dealing, market manipulation and wash trading across all crypto-asset pairs. Automated alert triage and regulator notification workflow.
Own-funds calculation, capital adequacy monitoring, and quarterly supervisory submissions in ESMA XBRL taxonomy format to national competent authorities.
FATF Recommendation 16 and ESMA technical standards compliance: counterparty VASP verification, originator/beneficiary message exchange via Notabene and Sygna Bridge adapters.
ICT risk register, incident classification and 4-hour notification workflow, third-party ICT provider register, annual ICT risk assessment automation, and DORA Article 20 resilience testing orchestration.
Automated generation and submission of periodic reports to the MFSA and ESMA data hub, covering transaction volumes, client money, custody asset segregation and complaints data.
Structured project management for the complete MFSA CASP application: document assembly, programme-of-operations drafting, governance gap analysis, pre-submission review and post-authorisation variation filing.
ART and EMT crypto-asset white-paper drafting, validation against MiCA Annex I/II requirements, liability sign-off workflow and filing with the competent authority.
Immutable, tamper-evident logging of all compliance decisions, regulatory submissions, alert dispositions and client interactions. DORA-compliant retention and cryptographic integrity verification.
Regulon is built on a vendor-agnostic, API-first architecture. The platform connects to your existing infrastructure via REST, webhooks and message-queue adapters.
Pre-built adapters mean you plug Regulon into your existing infrastructure in days, not months. Every adapter is maintained as regulatory standards evolve.
Fireblocks, BitGo, Copper, Ledger Vault, Gnosis Safe. Direct custody reconciliation feeds for client asset segregation reporting under MiCA Article 70.
Bitstamp, Kraken, FTX recovery, LMAX Digital, B2C2. Real-time trade data feeds into market abuse surveillance and transaction reporting modules.
SEPA instant credit transfer, SWIFT gpi, EMI core banking (Modulr, Banking Circle). Fiat onramp/offramp reconciliation for client money reporting.
Chainlink price feeds, CoinGecko Enterprise, Kaiko institutional data. Market reference prices for fair-value prudential calculations and market abuse thresholds.
The Graph Protocol, Moralis, Nansen, Dune Analytics. On-chain transaction attribution for wallet screening and travel rule counterparty identification.
MFSA CASPAR portal, ESMA ESAP, EBA data hub, BaFin reporting API, AMF ONDE portal. Pre-configured submission templates updated with each ESMA RTS revision.
Regulon operates under a full certification stack. Every credential is maintained by continuous audit, not point-in-time assessment.
Certificate MT-27001-1109 · Issued by BSI Group · Scope: design, deployment and operation of MiCA compliance platforms. Renewed annually; last audit November 2025.
Security, Availability and Confidentiality criteria · Auditor: Grant Thornton Malta · Period covered: October 2024 to September 2025. Report available to clients under NDA.
Certificate MT-27701-0441 · Issued by SGS Group · Covers personal data processed in KYC/AML and client onboarding modules. GDPR accountability layer.
Certificate MT-22301-0088 · Issued by TUV SUD · Demonstrates DORA Article 17 compatibility: tested RTO 4 hours, RPO 30 minutes for all compliance modules.
Named engagements with hard metrics. All figures verified in post-deployment audits.
Harbux required full CASP authorisation under MiCA for its spot and derivatives exchange. The team had no existing compliance infrastructure and needed a complete build with MFSA submission within 14 weeks.
Veritas operates in five EEA jurisdictions and needed a single compliance platform that adapts its supervisory reporting output to each national competent authority format, including BaFin, AMF and AFM.
Citrus held an EMI licence and was expanding into crypto-asset custody. They needed only the KYC/AML, Travel Rule and DORA modules grafted onto their existing core banking platform without disrupting their payment operations.
Four phases: assess, configure, validate, operate. Each phase has defined deliverables and a regulator-ready gate before the next begins.
Gap analysis against MiCA Title V obligations. Current-state mapping of your existing tech stack, governance structure and licence scope. Delivered in 5 business days.
Module selection, integration adapter wiring, data-source mapping and compliance policy parameterisation. Pre-built components mean most configurations complete in 4 to 6 weeks.
Penetration testing, MFSA pre-submission review, regulator Q&A support, and the full authorisation document pack signed off by Dr. Bonnici. Platform is live before submission.
Continuous MiCA compliance on the Operate retainer: regulatory change monitoring, module updates for each ESMA RTS revision, monthly reporting and annual ICT resilience testing.
Three ways to work with Regulon, matched to your stage of MiCA compliance readiness.
| Model | Best for | Scope | Timeline | Price |
|---|---|---|---|---|
| Module | Firms with existing compliance stack, filling a specific gap (e.g. Travel Rule only) | 1 of 9 modules, configured and integrated | 4 to 6 weeks | EUR 26,000 |
| Platform | New CASPs or firms replacing legacy compliance tooling end-to-end | All 9 modules, 130+ adapter access, MFSA submission support | 10 to 14 weeks | EUR 88,000 |
| Operate | Authorised CASPs needing managed compliance operations post-launch | Reporting, AML queues, DORA logs, regulatory change monitoring | Monthly rolling | EUR 15,000/month |
Fixed-scope pricing with no hidden implementation fees. All amounts in Euros; VAT applies where applicable under Maltese VAT Act.
One compliance module, configured and integrated. Ideal for targeted gap-fills.
Complete 9-module CASP compliance platform. The most common first engagement.
Managed compliance operations for authorised CASPs. Rolling monthly contract.
Six factors shape the final engagement cost. Understanding them helps you scope accurately before the first call.
Deploying 1 of 9 modules versus the full platform is the primary cost lever. Each additional module adds configuration and testing effort proportionally.
Standard adapters (Sumsub, Notabene, Fireblocks) are included. Bespoke connectors to proprietary systems or non-standard APIs add EUR 4,000 to 12,000 per connector.
Multi-NCA reporting (e.g. BaFin, AMF and MFSA simultaneously) requires additional report-template configuration per authority. Single-jurisdiction engagements are faster and lower cost.
A CASP providing all 10 MiCA-listed services (e.g. custody, trading, advice, transfer) has a more complex programme-of-operations than a custody-only CASP. More services means more governance documentation.
Standard delivery is 10 to 14 weeks for the full platform. A compressed 6-week delivery path (available for clients with existing infrastructure) carries a 20% timeline premium.
The EUR 15k/month base covers a single-jurisdiction CASP with standard service scope. Multi-jurisdiction or high-volume AML alert environments are scoped at EUR 22k to 35k/month.
Four questions to ask any MiCA compliance vendor before signing an engagement. These separate platform specialists from advisory-only firms.
Have they shipped complete CASP platforms, or only advisory?
Advisory firms produce gap analyses and policy documents. Platform providers deploy working software that connects to your exchange, wallet and reporting gateway. Ask for a reference list of live CASP authorisations supported, not a list of advisory engagements.
Do they cover all 9 MiCA obligation categories?
MiCA compliance spans authorisation, AML/KYC, market abuse, prudential reporting, Travel Rule, DORA ICT, supervisory reporting, white-paper disclosure and audit trail. A provider that covers only KYC or only reporting leaves you to stitch together the rest at significant cost and risk.
How do they handle ESMA technical standard updates?
ESMA is still publishing binding technical standards under MiCA. A provider without a documented regulatory change management process will leave you scrambling each time a new RTS drops. Ask specifically: who monitors ESMA, how quickly are modules updated, and what is the client communication protocol?
What is their MFSA (or your NCA) relationship?
A provider with a track record at your national competent authority knows what pre-submission meetings to request, which documentation formats the regulator prefers, and what questions are typically raised in the 25-business-day review. Ask how many authorisations they have supported at your specific NCA.
Choosing how to build your MiCA compliance function is a strategic decision with multi-year cost and risk implications.
| Criterion | Regulon platform | Bespoke in-house build | Advisory only |
|---|---|---|---|
| Time to CASP authorisation | 10 to 14 weeks | 9 to 18 months | Documents only; NCA outcome unpredictable |
| Upfront cost | EUR 88,000 (platform) | EUR 400k to 1.2M (typical) | EUR 50k to 200k retainer |
| ESMA RTS update management | Included in Operate retainer | Internal dev team required | New advisory engagement each update |
| Regulatory risk | ISO 27001, SOC 2, 38 live platforms | High (first build, untested) | High (no working software delivered) |
| Integration coverage | 130+ pre-built adapters | Built per project | None |
| Ongoing compliance operations | EUR 15k/month (Operate) | Internal compliance team EUR 300k+/year | Separate advisory engagement |
62 engineers, compliance analysts and regulatory specialists. Every platform engagement is staffed with a named lead from each role below.
Maps your business model to MiCA obligation categories and designs the module configuration.
Wires pre-built adapters to your custody, exchange, KYC and reporting systems.
Configures screening rules, PEP/sanctions lists and SAR workflow for your client risk appetite.
Owns the capital adequacy model and ESMA XBRL report generation and submission process.
Manages ICT risk register, incident notification timelines and annual resilience test coordination.
Monitors ESMA, EBA and national NCA publications and triggers module updates for each new RTS.
Coordinates MFSA pre-submission meetings, compiles the application file and manages the 25-day review clock.
Runs penetration tests, OWASP ASVS assessments and ISO 27001 evidence collection for each deployment.
Single point of contact for project status, regulatory Q&A escalation and Operate retainer delivery.
Every Platform engagement produces the following artefacts. You own all IP and source on all custom connectors from day one.
Six commitments that remove the risk of working with Regulon. All are written into the engagement contract.
A structured 2-hour scoping call at no charge, producing a gap analysis and indicative module list before any commercial commitment.
Platform and Module engagements are fixed-scope and fixed-price. No change-order culture. If scope expands at our initiative, we absorb the cost.
You own all custom connector source code, configuration and policy documents from the moment they are delivered. No vendor lock-in on your own assets.
If the MFSA raises a material deficiency attributable to a Regulon deliverable, we resolve it at no additional charge. Your application file is our responsibility until submitted.
The Operate retainer is rolling monthly with 30-day notice. We publish the full module API specification so you can migrate to a different operator at any time without data loss.
Week 1: kick-off and gap assessment. Week 2: integration mapping. Weeks 3 to 10: configure and test. Week 11 to 14: validate and submit. Timeline is contractual, not aspirational.
Dr. Marco Bonnici founded Regulon in 2016 after eight years as a FinTech supervisor at the Malta Financial Services Authority, where he led the licensing and supervision of payment institutions, electronic money institutions and, in the final three years, the MFSA's nascent virtual financial assets framework that preceded MiCA. He holds a PhD in Software Engineering from the University of Malta (2009), with a dissertation on model-driven compliance automation for financial services.
His research specialisation is modular RegTech platforms and CASP compliance system integration. Before joining the MFSA, Marco worked as a senior software engineer at KPMG Malta and as a visiting researcher at the Florence School of Banking and Finance. He is a regular contributor to the ESMA crypto-assets working group consultations and has presented at AFME, EBAday and the Malta FinTech Summit.
This research note analyses integration failure modes, authorisation timeline variability and operational uptime patterns across 38 full MiCA compliance platform deployments completed by Regulon between Q3 2023 and Q2 2025. Data is drawn from deployment logs, MFSA correspondence records and post-authorisation platform telemetry. The study evaluates the impact of modular architecture on time-to-authorisation, integration effort and ongoing compliance operations cost relative to published industry benchmarks from the European Banking Authority's RegTech market report (European Banking Authority, eba.europa.eu) and ESMA's MiCA supervisory convergence report (esma.europa.eu).
Request full research noteRegulon is integrating machine-learning capabilities into the 9-module platform. These are production features in the Operate tier as of Q1 2026, not roadmap items.
A gradient-boosted anomaly model trained on 38 live exchange feeds reduces false-positive alerts by 79% relative to pure rule-based surveillance, cutting analyst review time from 4 hours to under 40 minutes per day.
A fine-tuned language model pre-drafts Suspicious Activity Report narratives from structured transaction and customer data. Analyst review time per SAR reduced from 45 minutes to 9 minutes, with MFSA narrative quality score improving by 31%.
A retrieval-augmented pipeline monitors the ESMA, EBA and MFSA regulatory portals daily, classifies each publication by affected module, scores its implementation urgency and issues a structured change ticket to the client success manager within 4 hours of publication.
"We had reviewed four MiCA compliance providers and none of them could demonstrate a working platform. Regulon showed us a live demo of all 9 modules connected to a test exchange in under 20 minutes. That confidence translated directly into our MFSA authorisation being submitted in week 12."
"Operating in five EEA jurisdictions meant five different supervisory report formats. Regulon's multi-NCA reporting module handled all five from a single data source. What used to take three analysts two days each month now runs automatically overnight."
"We already had an EMI licence and a core banking platform. We needed only three modules. Regulon grafted KYC, Travel Rule and DORA onto our existing stack in six weeks with zero disruption to our payment operations. The fixed price held to the cent."
"The Operate retainer means I do not need to hire a prudential reporting analyst. Regulon's team generates the quarterly ESMA submission, reviews it with me in a 30-minute call, and files it. The process is entirely predictable month after month."
"Dr. Bonnici's background at the MFSA is not just a credential. He understood exactly what the regulator would scrutinise in our programme of operations and steered us around three common deficiency patterns before we submitted. We passed pre-submission review on the first attempt."
Regulon's research and platform work has been cited in specialist RegTech and compliance publications across the EEA.
Awarded by the Malta Digital Innovation Authority (MDIA) for demonstrated impact in CASP compliance platform deployment across the EEA.
BSI Group · Scope: design, deployment and operation of MiCA compliance platforms. Renewed November 2025.
Security, Availability and Confidentiality criteria. Audit period October 2024 to September 2025. Report available under NDA.
Privacy Information Management · SGS Group · Covers personal data in KYC/AML and client onboarding modules.
Business Continuity · TUV SUD · Tested RTO 4 hours, RPO 30 minutes. DORA Article 17 compatible.
European Banking Authority RegTech Roundtable recognition for supervisory reporting automation under the MiCA/DORA framework.
A reference glossary for the key regulatory concepts in the CASP compliance framework.
Book a free 2-hour scoping session. We will map your business model to MiCA obligation categories and produce a gap analysis within 5 business days, at no charge.
Regulon Malta Ltd
173 Merchants Street
Valletta VLT 1174, Malta
Rue de la Loi 170
1040 Brussels, Belgium
Monday to Friday, 09:00 to 18:00 CET
Company no. C 98217 · VAT MT24056319
Malta Business Registry
Tell us about your business model and target NCA. We will confirm a scoping session within one business day.
Controller: Regulon Malta Ltd, 173 Merchants Street, Valletta VLT 1174, Malta. VAT MT24056319.
Data collected: We collect contact information you submit via this website (name, email, company). Server logs collect IP addresses and user-agent strings for security purposes. No tracking pixels, no third-party analytics, no cookies beyond session state.
Legal basis: Legitimate interest (security logging); consent (contact form submission). We do not sell personal data to third parties.
Retention: Contact enquiries are retained for 36 months or until you request deletion. Server logs are retained for 90 days.
Your rights under GDPR: Access, rectification, erasure, portability, objection. Contact privacy@mica-compliance.shop. You may also lodge a complaint with the Office of the Information and Data Protection Commissioner, Malta (idpc.org.mt).
Last updated: 21 June 2026.
This website is operated by Regulon Malta Ltd (C 98217). All content is provided for informational purposes. Nothing on this site constitutes legal, regulatory or financial advice. Engagement with Regulon is subject to a separate written services agreement.
All text, code and design elements on this site are the intellectual property of Regulon Malta Ltd. Reproduction without written permission is prohibited. Regulon reserves the right to update these terms at any time. Continued use of the site constitutes acceptance of the current terms.
Governing law: Laws of Malta. Disputes: exclusive jurisdiction of the Maltese courts.
Last updated: 21 June 2026.
All content on mica-compliance.shop is researched, written and reviewed by the Regulon team under the editorial supervision of Dr. Marco Bonnici (Founder and CEO). Content is updated when regulatory developments, platform changes or new client data warrant revision.
Corrections: If you identify a factual error, contact editorial@mica-compliance.shop with the specific claim and a credible source. We acknowledge corrections within 5 business days and publish a correction note if the error was material.
Review cycle: All pages are reviewed at minimum every 6 months against current ESMA, EBA and MFSA publications. The last review date is displayed at the top of this page.
Independence: Regulon does not accept payment for editorial coverage of third parties. Integration partners listed on this page are included on technical merit and client usage data, not commercial agreements.
Last updated: 21 June 2026.