EU financial regulation, citation-grounded
Answers from EU financial regulation, down to the exact paragraph.
Ask MiCA, DORA, MiFID II, the AML package, the AI Act and the wider EU financial rulebook. Every answer is drawn from primary legislation, and behind each citation is the verbatim provision, checked word-for-word.
Obligation · MiCA / CASP readiness
Q · Does a business providing custody of crypto-assets for clients need a licence in the EU, and what must it hold?
Providing custody and administration of crypto-assets for clients requires authorisation as a crypto-asset service provider before you operate in the Union1. The competent authority grants that authorisation only after assessing the application and adopting a reasoned decision2. Once authorised, the provider must hold prudential safeguards at all times3.
Source · primary law
A person shall not provide crypto-asset services, within the Union, unless that person is a legal person or other undertaking that has been authorised as crypto-asset service provider in accordance with Article 63.
Competent authorities shall assess whether the applicant crypto-asset service provider complies with this Title and shall adopt a fully reasoned decision granting or refusing an authorisation as a crypto-asset service provider.
Crypto-asset service providers shall, at all times, have in place prudential safeguards equal to an amount of at least the higher of the following.
How it works
From what you’re building to a cited scoping note.
Map which EU regimes apply to what you’re building, get the exact governing articles, and export a source-backed scoping note.
Your build
The corpus
The EU financial rulebook, as primary law.
Browse the acts Compass covers, grouped by domain. Open any one to see what it governs, who it applies to, and its exact citation.
Crypto-assets
Regulation (EU) 2023/1114
Creates an EU framework for issuing and trading crypto-assets not covered by existing financial law, including stablecoins, crypto-asset service providers and market-abuse rules.
Applies to: Crypto-asset issuers, offerors, trading platforms, custodians, exchanges and other CASPs.
In force: 2024-12-30 (stablecoin titles from 2024-06-30)
Regulation (EU) 2022/858
Creates a temporary EU pilot regime for DLT market infrastructures trading and settling tokenised financial instruments, with targeted exemptions from existing market rules.
Applies to: Operators of DLT MTFs, DLT settlement systems, DLT trading-and-settlement systems and supervisors.
In force: 2023-03-23
Markets
Directive 2014/65/EU
Sets the EU framework for investment services and regulated markets, including authorisation, conduct of business, investor protection, trading venues and transparency rules.
Applies to: Investment firms, trading venues, data reporting services, clients and supervisors.
In force: 2018-01-03
Regulation (EU) No 600/2014
Sets directly applicable market transparency, transaction-reporting, trading-obligation and access rules for financial instruments, complementing MiFID II’s authorisation and conduct regime.
Applies to: Investment firms, trading venues, systematic internalisers, data reporters and market operators.
In force: 2018-01-03
Regulation (EU) No 648/2012
Regulates OTC derivatives, central counterparties and trade repositories, including clearing, risk-mitigation, reporting and CCP supervision.
Applies to: Financial and non-financial counterparties, CCPs, clearing members, trade repositories and supervisors.
In force: 2012-08-16 (requirements phased by technical standards)
Regulation (EU) No 596/2014
Creates EU market-abuse rules covering insider dealing, unlawful disclosure of inside information, market manipulation, disclosure controls, insider lists and managers’ transactions.
Applies to: Issuers, market participants, trading venues, investment firms and persons discharging managerial responsibilities.
In force: 2016-07-03
Regulation (EU) 2016/1011
Regulates benchmark administrators, contributors and supervised users to improve benchmark accuracy, governance and integrity for financial instruments, contracts and investment funds.
Applies to: Benchmark administrators, supervised contributors, supervised users and benchmark users.
In force: 2018-01-01 (selected provisions from 2016-06-30; amended regime from 2026)
Regulation (EU) No 236/2012
Sets transparency and restriction rules for short selling and certain credit default swaps, including position reporting, uncovered-short-selling limits and emergency intervention powers.
Applies to: Investors, investment firms, trading venues, sovereign CDS users and supervisors.
In force: 2012-11-01
Payments
Directive (EU) 2015/2366
Harmonises EU payment-services rules, including payment-institution licensing, transparency, user rights, strong customer authentication and regulated access to payment-account data.
Applies to: Payment service providers, account providers, payment users and open-banking providers.
In force: 2018-01-13 (PSD3/PSR successor proposals pending)
Directive 2009/110/EC
Sets EU rules for taking up, operating and supervising electronic-money institutions, including issuance, redeemability and prudential requirements.
Applies to: Electronic-money issuers and institutions, payment groups, and supervisors.
In force: 2009-10-30; transposition by 2011-04-30
Banking
Regulation (EU) No 575/2013
Sets directly applicable prudential requirements for banks and investment firms, including own funds, liquidity, leverage, large exposures and public disclosure.
Applies to: Credit institutions, certain investment firms, financial holding companies and supervisors.
In force: 2014-01-01 (amendments phased, including 2025 CRR III changes)
Directive 2013/36/EU
Sets EU rules for access to banking business, prudential supervision, governance, capital buffers, supervisory review and sanctions for credit institutions and some investment firms.
Applies to: Credit institutions, relevant investment firms, holding companies and banking supervisors.
In force: 2014-01-01 (national transposition by 2013-12-31)
Directive 2014/59/EU
Sets an EU framework for the recovery and resolution of failing banks and investment firms, including recovery and resolution planning, early intervention, resolution tools and the bail-in of creditors.
Applies to: Credit institutions, certain investment firms, resolution authorities and supervisors.
In force: 2015-01-01 (bail-in tool from 2016-01-01; transposition by 2014-12-31)
Securities
Regulation (EU) No 909/2014
Harmonises EU securities settlement and central securities depository rules, including CSD authorisation, settlement discipline, internalised settlement reporting and cross-border services.
Applies to: Central securities depositories, settlement participants, trading venues, issuers and supervisors.
In force: 2014-09-17 (settlement discipline later phased)
Regulation (EU) 2017/1129
Sets requirements for drawing up, approving and publishing prospectuses for securities offered to the public or admitted to regulated markets, with exemptions and simplified disclosures.
Applies to: Issuers, offerors, admission applicants, intermediaries, investors and securities supervisors.
In force: 2019-07-21 (main regime; selected provisions earlier)
Regulation (EU) 2015/2365
Improves transparency of securities financing transactions and reuse by requiring trade reporting, investor disclosures and safeguards around collateral reuse.
Applies to: SFT counterparties, UCITS managers, AIFMs, trade repositories and investors.
In force: 2016-01-12 (reporting and disclosure phased)
Regulation (EU) 2020/1503
Creates a single EU regime for authorised crowdfunding service providers offering business funding through loan-based or investment-based crowdfunding up to specified thresholds.
Applies to: Crowdfunding service providers, project owners, investors and national competent authorities.
In force: 2021-11-10
Regulation (EU) No 1286/2014
Requires a standard key information document for packaged retail and insurance-based investment products so retail investors can compare risks, costs and performance scenarios.
Applies to: PRIIP manufacturers and persons advising on or selling PRIIPs to retail investors.
In force: 2018-01-01
Regulation (EU) 2017/2402
Lays down a general framework for securitisation and a specific regime for simple, transparent and standardised (STS) securitisation, with due-diligence, risk-retention and transparency requirements.
Applies to: Originators, sponsors, original lenders, securitisation special purpose entities and institutional investors.
In force: 2019-01-01
Funds
Directive 2009/65/EC
Harmonises rules for open-ended retail investment funds (UCITS), covering fund authorisation, the management-company passport, eligible assets, investor disclosure and depositary duties.
Applies to: UCITS funds, management companies, depositaries, retail investors and supervisors.
In force: 2011-07-01 (transposition of the recast regime)
Directive 2011/61/EU
Regulates managers of alternative investment funds such as hedge, private-equity and real-estate funds, covering authorisation, capital, conduct, valuation, depositaries, leverage and the marketing passport.
Applies to: Alternative investment fund managers, the AIFs they manage, depositaries and supervisors.
In force: 2013-07-22 (transposition deadline)
Insurance
Directive 2009/138/EC
Sets the EU prudential framework for insurers and reinsurers, including risk-based capital requirements, governance and risk management, own-funds rules and a three-pillar supervisory review.
Applies to: Insurance and reinsurance undertakings, insurance groups and their supervisors.
In force: 2016-01-01
Supervision
Regulation (EU) No 1095/2010
Establishes ESMA, the EU authority for securities markets, with powers to draft technical standards, promote supervisory convergence, issue guidelines and act in specified emergency situations.
Applies to: ESMA, national securities regulators and market participants under EU securities law.
In force: 2011-01-01 (authority operational; regulation in force 2010-12-16)
Regulation (EU) No 1093/2010
Establishes the EBA, the EU authority for banking, with powers to develop the single rulebook through technical standards, promote supervisory convergence and run EU-wide stress tests.
Applies to: EBA, national banking supervisors, credit institutions and relevant investment firms.
In force: 2011-01-01 (authority operational; regulation in force 2010-12-16)
Regulation (EU) No 1094/2010
Establishes EIOPA, the EU authority for insurance and occupational pensions, with powers to draft technical standards, foster supervisory convergence and support policyholder protection.
Applies to: EIOPA, national insurance and pension supervisors, insurers and pension providers.
In force: 2011-01-01 (authority operational; regulation in force 2010-12-16)
AML/CFT
Regulation (EU) 2024/1624
Creates a directly applicable EU AML/CFT rulebook for customer due diligence, beneficial ownership, internal controls and high-risk situations, replacing much of the prior directive-based framework.
Applies to: Obliged entities, including financial firms, crypto-asset providers and selected non-financial businesses.
In force: 2027-07-10 (football clubs and agents from 2029-07-10)
Directive (EU) 2024/1640
Sets Member State AML/CFT institutional duties, including supervisory powers, beneficial-ownership registers, bank-account registers and financial intelligence unit cooperation, replacing AMLD4/5 architecture alongside the AMLR.
Applies to: Member States, FIUs, supervisors and entities accessing AML registers.
In force: 2027-07-10 (selected register provisions phased from 2026 and 2029)
Regulation (EU) 2024/1620
Establishes the EU Anti-Money Laundering Authority, giving it coordination, supervisory, convergence and direct-supervision tasks for selected high-risk financial-sector obliged entities.
Applies to: AMLA, national AML/CFT supervisors, FIUs and selected obliged entities.
In force: 2025-07-01 (selected provisions earlier and later)
Operational resilience
Regulation (EU) 2022/2554
Creates a harmonised operational-resilience framework for financial entities, covering ICT risk management, incident reporting, resilience testing and oversight of critical third-party ICT providers.
Applies to: Financial entities and critical ICT third-party service providers.
In force: 2025-01-17
AI
Regulation (EU) 2024/1689
Creates horizontal EU rules for AI systems, banning specified practices, imposing risk-based duties, and setting transparency and governance rules including for general-purpose AI.
Applies to: AI providers, deployers, importers, distributors, product manufacturers and public authorities.
In force: 2026-08-02 (phased: bans 2025-02-02; GPAI 2025-08-02)
Data & digital
Regulation (EU) 2016/679
Sets EU personal-data protection rules, including lawful processing, data-subject rights, controller and processor duties, international transfers, supervision and administrative fines.
Applies to: Controllers, processors, data subjects, supervisory authorities and EU-facing non-EU businesses.
In force: 2018-05-25
Regulation (EU) 2022/2065
Sets EU rules for intermediary services, including notice-and-action, transparency, trader traceability, platform governance and systemic-risk duties for very large platforms and search engines.
Applies to: Online intermediaries, hosting services, online platforms, marketplaces and very large platforms.
In force: 2024-02-17 (some VLOP/VLOSE rules from 2022-11-16)
Regulation (EU) 2022/1925
Regulates designated digital gatekeepers, imposing conduct rules to keep core platform services contestable and fair for business users and end users.
Applies to: Designated gatekeepers providing core platform services, plus affected business users and end users.
In force: 2023-05-02 (gatekeeper obligations generally after designation)
Directive (EU) 2022/2555
Updates EU cybersecurity rules for essential and important entities, national strategies, incident reporting, supply-chain security and coordinated supervision across Member States.
Applies to: Essential and important entities, digital infrastructure providers, public administrations and cybersecurity authorities.
In force: 2024-10-18 (national transposition by 2024-10-17)
Regulation (EU) 2023/2854
Sets rules for access to and use of data from connected products and related services, business-to-government data sharing and cloud-switching safeguards.
Applies to: Connected-product users, data holders, service providers, public bodies and cloud providers.
In force: 2025-09-12 (some provisions phased to 2026-2027)
Identity
Regulation (EU) No 910/2014
Sets EU rules for electronic identification, trust services and electronic transactions, now expanded to European Digital Identity Wallets and additional trust services.
Applies to: Trust service providers, wallet providers, relying parties, public bodies and electronic-identification schemes.
In force: 2016-07-01 (eIDAS 2.0 amendments phased from 2024)
Who uses it
Map which EU regimes (MiCA, DORA, the AML package) apply to what you're building, before you pay counsel or freeze the roadmap.
Scope a new feature or market against the rulebook, with the exact articles, so you know what changes before you ship.
Get a source-backed first pass on your obligations before you can justify a compliance hire or a law firm.
Accelerate first-pass client triage; build an issue map from primary law, article-cited.
Scope your build.
Map which EU regimes apply and get your obligation register, each cited to the article.