MiCA Article 68 makes CASPs keep transaction-level records for five to seven years. What that covers, how DAC8 raises the stakes, and where a subledger fits.

Most of the MiCA conversation over the past two years has been about licensing. Who needs authorisation, which member state grants it, what the capital and governance conditions look like. That work sits with legal and compliance teams, and for a lot of crypto businesses it is now mostly done.
The part that lands on finance and accounting teams is quieter and lasts longer. MiCA expects a crypto-asset service provider to keep a complete, reconstructable record of everything it does, and to keep it for years after the transaction clears. A license proves you were allowed to operate. Records prove what you actually did. Those are different jobs, and the second one never really ends.
Here is what Article 68 asks for, why 2026 raised the stakes, and where a subledger does (and does not) help.
MiCA became fully applicable to crypto-asset service providers on 30 December 2024. Article 143 then gave member states room to grant a transitional period of up to 18 months for firms already operating under national law. That clock ran out on 1 July 2026. There is no extension mechanism, so from that date a firm serving EU clients either holds a MiCA authorisation or it does not. Several member states, including Germany, chose windows shorter than the full 18 months, so plenty of teams hit the wall earlier than the outer deadline.
The reason this matters for record-keeping is timing. A firm that spent 2025 and early 2026 getting authorised now has to show it kept proper records through that whole period, including the messy stretch when it was migrating tools, switching custodians, or onboarding under a new legal entity. The obligation is retroactive in effect. You cannot backfill a five-year audit trail after the fact.
Article 68(9) is the core rule. A CASP has to keep records of “all crypto-asset services, activities, orders, and transactions” it undertakes. The retention period is five years, and a competent authority can require you to hold them for up to seven if it asks before the five years are up. Clients can request their own records too.
The standard those records have to meet is reconstruction. A supervisor should be able to pick any transaction and rebuild it: what happened, when, for whom, in what asset and amount, at what value, with what fees. A monthly PDF export or a portfolio screenshot does not clear that bar. You need the underlying ledger, transaction by transaction, tied back to the wallet or venue it came from.
Article 68(10) points to the detail. The granular specification lives in Commission Delegated Regulation (EU) 2025/1140, the regulatory technical standard adopted in February 2025 that spells out exactly which records a CASP keeps. If your compliance team has not mapped your current data against that RTS, that is the gap to close first.
Sitting next to this is Article 70, which requires you to segregate client crypto-assets and funds from your own. Custodians keep a register of each client's positions and hold client assets on separate on-chain addresses. Segregation is an accounting reality as much as a legal one: your books have to show, at any moment, what belongs to clients and what belongs to the house. That is hard to prove without a subledger that tracks holdings per entity and per client.
Record-keeping under MiCA would be demanding on its own. DAC8 made it sharper.
DAC8, the EU directive that brings the OECD's Crypto-Asset Reporting Framework into European law, applies from 1 January 2026. That means 2026 is the first year reporting crypto-asset service providers collect user and transaction data for tax purposes. The first reports are due to national tax authorities by 30 September 2027, and authorities then exchange that data across borders automatically. For anyone who has followed US reporting, it is the European counterpart to the Form 1099-DA shift.
The practical effect is that your internal records and what a tax authority receives about your users now have to reconcile. If your subledger says one thing and your DAC8 submission says another, that gap is visible to a regulator who can compare both. Clean, transaction-level records stop being a nice-to-have and become the source of truth two different regimes read from. We cover the reporting mechanics in more depth in our CARF and DAC8 guide.
Directly, the obligations fall on CASPs: exchanges, custodians, brokers, and the firms issuing asset-referenced or e-money tokens. If you hold an authorisation, Article 68 is yours.
Indirectly, a wider group feels the same pressure. A company holding crypto in its treasury is not a CASP and does not file under Article 68, but it deals with the same custodians and exchanges, and it faces its own audit and tax-reporting expectations. When your venue tightens its records to satisfy MiCA, the data you receive from it changes, and your own books have to keep up. The record-keeping bar rises across the whole chain, not just at the licensed firms.
If you own the finance side of this, a short list of things worth doing before year-end:
Two things are worth being straight about.
No software makes you MiCA compliant. Authorisation, governance, client-asset segregation as a legal matter, these are decisions and controls your firm owns. A tool does not grant them.
What a subledger does is hold the records layer that Article 68 describes. A crypto subledger ingests activity across chains, exchanges, and custodians, normalises it into transaction-level entries, and keeps that history in a form you can query, reconcile, and export years later. That is the difference between “we have the data somewhere” and “we can reconstruct any transaction on request.”
This is the layer Kryptos Enterprise is built for. It syncs across chains, exchanges, and custodians, applies cost basis consistently (FIFO, LIFO, ACB, HIFO, and Shared Pool), tracks holdings per entity for segregation, and pushes reconciled journals into the accounting stack through Xero, QuickBooks, and SoftLedger. The records that MiCA asks you to keep for up to seven years are the same records DAC8 asks you to report. Keeping them in one place, rather than stitching them together at audit time, is the whole point.
If you are an accounting firm working with crypto clients, the record review moves earlier in the engagement. It is worth adding a transaction-history check to client intake so you know what you are signing up to before the audit, not during it. Our guide for accountants goes into how that fits a practice workflow.
This article is general information from an accounting and product perspective, not legal advice. Confirm your obligations with your own advisers and your national competent authority.
Five years under Article 68(9). A competent authority can extend that to up to seven years if it makes the request before the initial five years elapse. Records also have to be provided to clients on request.
Not directly. Article 68 binds authorised CASPs. But treasury holders deal with the same regulated venues and carry their own audit and DAC8-adjacent reporting expectations, so the practical record-keeping bar rises for them too.
MiCA Article 68 is the operational obligation to keep reconstructable transaction records. DAC8 is the tax-transparency layer that makes reporting CASPs report user and transaction data to tax authorities, starting with the 2026 year and first reports due by 30 September 2027. The same underlying records feed both.
Not on its own. Article 68 requires records detailed enough to reconstruct each transaction, tied to the wallet or venue it came from. A tracker that shows balances or a monthly summary does not meet that standard. You need transaction-level records, which is what a subledger produces.

FASB's August 2026 proposal on digital assets and cash equivalents, explained. What it changes, the three criteria that matter, and the November 19 comment deadline.

Ireland's DAC8 and CARF crypto reporting rules explained: who counts as an RCASP, registration and self-certification deadlines, what gets reported, and the penalties.

Australia is implementing the OECD Crypto-Asset Reporting Framework. What CARF means for offshore exchange holdings, when reporting starts, and how to prepare.
Generate an audit-ready report aligned to your jurisdiction. No credit card required.