Know Which Crypto Regulations Apply Before They Become a Problem.
Determine which U.S. and EU crypto regulations may apply to your business and identify your highest-priority compliance gaps. Answer honestly — this is for your own visibility, not a test.
Which rules may reach your business?
Six short gates capture the facts regulators look at — where you operate, what role you play, who your customers are, what the assets are, who holds the keys and which financial activities you perform — then seven questions on the programme that would have to satisfy them. You get a MyCISO Partner Readiness Indicator, the regimes that may apply and why, and your highest-priority gaps.
Important: this assessment produces a readiness indicator from your own answers. It does not determine whether any law, regulation or licensing requirement applies to you, it does not classify any token, and it is not legal advice. Regulatory scope depends on facts and interpretation that only qualified counsel can assess. Nothing here states or implies that you are compliant with any regulation.
See your full results
Enter your email to unlock your readiness indicator, the regulations that may apply, your gate-by-gate scores, priority gaps and recommended next steps.
- MyCISO Partner Readiness Indicator and tier
- U.S. and EU regimes that may apply, with the reason for each
- Scores for the six gates and your compliance programme
- Your highest-priority compliance gaps
- Questions to take to counsel, and an email copy
Your MyCISO Partner Readiness Indicator
Regulations that may apply to you
Derived only from your gate answers. "May apply" means your answers match the facts a regime looks at — not that it does apply, and not that any licence or registration is required. Each entry is a question for counsel, not a conclusion.
Gate and programme scores
Weighted: Compliance programme 40% · the six applicability gates 10% each. A gate scores high when you have no exposure there, or when the exposure is already being managed with counsel. Expand a section to see the contributing questions and your answers.
Your highest-priority compliance gaps
Recommended next steps
Assessment methodology: the six gates follow the fact patterns used by the U.S. federal regulators (FinCEN's Bank Secrecy Act rules for money services businesses, the SEC and CFTC's asset-classification approaches, OFAC sanctions obligations, the 2025 federal payment stablecoin law) and state money-transmission and virtual-currency licensing regimes, and by the EU's Markets in Crypto-Assets Regulation (MiCA), Transfer of Funds Regulation, anti-money-laundering framework, GDPR, DORA and NIS2. Regulatory status changes; the platform edition of this assessment records, for each requirement, the date it was last verified against its authoritative source.
Legal disclaimer: My CISO Partner is a cybersecurity and compliance advisory firm, not a law firm, and this assessment is not legal advice. The result is a MyCISO Partner Readiness Indicator based solely on your responses. It does not determine whether any regulation applies to you, whether any asset is a security, commodity, payment stablecoin or other regulated instrument, or whether any licence, registration or authorisation is required. It does not state that you are compliant with any regulation. Confirm applicability, classification and licensing questions with qualified legal counsel in each jurisdiction where you operate.
Want the full picture?
The platform edition maps your business to every requirement of each regime, separates what is in force today from what is proposed, routes legal questions to counsel and tracks evidence, remediation and deadlines. 30 minutes. No obligation. No sales pitch.