Get MiCA-ready and stay compliant.
Onboarding, monitoring, tax reporting and ICT resilience, four permanent obligations that start the day your licence lands. We run the infrastructure that carries them, live today.



100+ platforms file with Supplied.

Trusted by businesses of all sizes
"We’ve saved at least 65% in costs compared to similar tools, and the additional features like automated onboarding made it a no-brainer!"

Hannah
Onboarding Specialist at Brenger
Built for MiCA, not guesswork.
Every report is reviewed by you and validated by us before it reaches a tax authority.

Nothing is filed without your sign-off
You review every report before it is submitted. No surprises.

Validated against ESMA and national competent authority specs
Every submission is checked against the correct format before it leaves the platform.

Fewer rejected filings than manual submission
Governance, custody, and disclosure data are cross-checked automatically before anything is sent.

Fix and resubmit without restarting
If a regulator flags an error, correct it inside Supplied and resubmit.
GDPR
Compliant
ISO 27001
Certified
SOC 2 Type II
Certified
Building a crypto business in Europe?
Then this should sound familiar...
1
The licence is only the beginning, four permanent obligations start the day it's granted.
2
Compliance staff manually check every customer, and the queue grows with every signup.
3
DAC8 and CARF land in scope automatically, and the data sits across chains and exchanges.
4
DORA arrives alongside MiCA, and nobody owns the ICT evidence a supervisor will ask for.
That's what Supplied fixes.
Four obligations, four products, all live today, all running off one model of your customers, wallets and transactions.
Onboarding
KYC & KYB onboarding
MiCA requires you to establish who each customer is and keep that file current. We parse the documents, check live registers, resolve ownership through holding layers and screen against sanctions, PEP and adverse media, so only genuine exceptions reach your team.

TAX REPORTING
DAC8 & CARF reporting
Every CASP is automatically in scope, and the data is scattered across chains, wallets and exchange accounts. We sync networks and exchange APIs directly, attribute wallets to verified customers, value each disposal, and file the right schema with proof of receipt.
MONITORING
AML transaction monitoring
Your AML duty doesn't end at onboarding, and a quarterly review won't satisfy a supervisor. Every movement is scored against your rules, the customer's baseline and on-chain counterparty risk, then routed into a case with narrative, evidence and a filed SAR.
RESILIENCE
DORA ICT compliance
DORA arrives alongside MiCA and captures every licensed CASP. We keep your register of ICT third parties, log and classify incidents, and maintain resilience-testing evidence in a form your supervisor can review on request.
We can help you get and stay compliant with MiCA
Supplied automates the entire onboarding, monitoring, tax reporting, and resilience process to achieve full MiCA compliance. Saving you time and reducing the risk of fines.



100k+ users already saving costs
Who it's for
Built for firms operating under a licence.
Whether you're mid-application or already authorised, the obligations are the same, and so is the infrastructure that carries them.
Crypto exchanges & brokers
High customer volume and constant transaction flow. Onboarding and monitoring have to be automated or headcount becomes the bottleneck.
Custody & wallet providers
Fewer customers, heavier scrutiny. Wallet attribution and DORA resilience evidence carry most of the supervisory weight.
Fintechs adding crypto
Existing licences and controls, new crypto obligations. DAC8, CARF and on-chain monitoring bolt onto what you already run.

Supplied helps product, finance, and compliance teams work better together in one platform.
How the engagement works
Two different jobs. Both of them covered.
Getting authorised is legal work. Staying compliant is engineering work. We're explicit about which half we build, and our licensing partner runs the other as part of the same programme.
Managed by our licensing partner
Getting authorised.
Specialist legal and regulatory work, run end to end and finished when the licence lands. Delivered by our partner, coordinated alongside your build.
✓Jurisdiction selection and regulator strategy
✓Capital adequacy and own-funds structuring
✓Application drafting and submission dossier
✓Governance, fit-and-proper and board design
✓Regulator Q&A through to authorisation
Delivered by our partner, coordinated alongside your build.
SUPPLIED
Staying compliant.
Built and run by us, deploy before authorisation so you go live compliant. Start the plumbing before the licence lands.
✓KYC / KYB onboarding with UBO detection taxonomy autocomplete and validation
✓Continuous AML and transaction monitoring
✓DAC8 and CARF reporting, filed for you
✓DORA register, incidents and testing evidence
✓One audit trail across every obligation
Built and run by us. Deploy before authorisation, so you go live compliant.
Firms that wait until authorisation spend their first licensed quarter building systems instead of taking customers.
How we compare
Feature | Licensing Consultancy | Point Compliance Tool | Supplied |
|---|---|---|---|
Application drafting & regulator dialogue | Yes | No | Managed via partner |
KYC / KYB onboarding with UBO resolution | Advice only | Identity only | Full intake, automated |
Continuous AML transaction monitoring | No | Rules, no reporting | Monitoring to filed UTR |
DAC8 / CARF reporting and filing | No | Export only | Generated & filed |
DORA register, incidents and testing | Policy templates | No | Operational evidence |
Engagement shape | Ends at authorisation | One obligation | The licence's whole life |
Frequently asked questions
MiCA, questions answered.
Still wondering?
Yes, through our licensing partner, who manages the authorisation end to end: capital structuring, application drafting, governance design and regulator dialogue. We don't do that legal work ourselves, and we think it's more honest to say so than to blur it. What we build and run is the operational infrastructure that carries your obligations once you're licensed. Engage both halves as one programme, or just ours if you already have counsel.
Before, if you can. Supervisors increasingly want to see that your systems and controls actually exist rather than that you've described them, and firms that wait until the licence lands spend their first quarter building instead of onboarding. Standing the platform up during preparation also strengthens the operational sections of your application.
They're the same idea at different levels: CARF is the OECD crypto-asset reporting framework, DAC8 is the EU directive that brings it into Member State law. In practice you may owe both, to different authorities, from one dataset. We hold the data once and render whichever schema each recipient requires.
Trusted by businesses of all sizes
Security & Trust
Your data is always protected
RA sign-off, Authority filings, Auditor support, all through one API.






