A Crypto-Asset Service Provider, or CASP, is the central authorisation category created by the Markets in Crypto-Assets Regulation (MiCA) – the EU-wide regime that replaced the patchwork of national virtual-asset frameworks across member states. Any business wishing to offer regulated crypto-asset services to clients in the European Union or European Economic Area must obtain CASP authorisation from a national competent authority, or rely on a valid passported authorisation from another member state. Operating without that authorisation exposes the business to supervisory enforcement, mandatory cessation and the loss of banking and payment-rail access that follows.
This guide explains what the CASP category covers, who is caught, how authorisation works in practice, where the cross-border complications arise and what a business should assess before committing to a licensing strategy under MiCA.
What Exactly Is a CASP, and Why Does the Definition Matter?
A CASP under MiCA is any legal person or undertaking providing one or more specified crypto-asset services on a professional basis to third parties. The definition is activity-based, not entity-based. That distinction is consequential: it means a business is caught by the regime because of what it does, not because of what it calls itself or where it is registered.
The regulated activities enumerated under MiCA include custody and administration of crypto-assets on behalf of clients, operation of a trading platform for crypto-assets, exchange of crypto-assets for fiat or other crypto-assets, execution of orders on behalf of clients, placing of crypto-assets, reception and transmission of orders, portfolio management, advice on crypto-assets and transfer services. A business providing any one of these to EU clients – even from outside the EU – is within the perimeter unless an exemption applies.
The breadth of that list is the first practical reality for any general counsel reviewing a new product line. A platform that starts as a pure peer-to-peer infrastructure and begins routing orders, or a wallet provider that begins offering staking or lending, crosses into CASP territory the moment it professionalises that activity. We regularly see operators discover mid-build that a feature they classified as ancillary in fact triggers a regulated activity under MiCA.
ESMA, the European Securities and Markets Authority, coordinates supervisory convergence across national competent authorities (NCAs) and issues guidelines on how the activity categories are interpreted. Businesses should monitor ESMA guidance alongside the text of MiCA itself, because the practical scope of each activity category continues to be refined through Q&A processes and regulatory technical standards.
The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis materially. For a scoped assessment of whether your business model falls within the CASP perimeter, contact OBOLUS at info@oboluslaw.com.
MiCA's Architecture: Token Regimes Alongside the CASP Framework
MiCA operates across two parallel tracks that interact but are legally distinct. The first is the CASP authorisation track described above. The second governs the issuance of crypto-assets themselves, dividing tokens into three categories: asset-referenced tokens (ARTs), e-money tokens (EMTs) and a residual category of "other" crypto-assets.
An issuer of ARTs or EMTs faces its own authorisation and ongoing obligations – including whitepaper requirements, reserve composition standards and redemption rights – under MiCA, separate from any CASP authorisation needed if it also provides services. A business that both issues and services crypto-assets must analyse both tracks. Conflating issuer obligations with service-provider obligations is a structural error we see in early-stage builds: the two sets of requirements are additive, not alternative.
For businesses sitting within the CASP track, the token-type classification of the assets they handle remains relevant. Custody or trading of EMTs, for example, draws in the EMT issuer's regulatory environment alongside the CASP's own obligations. A CASP supporting a stablecoin ecosystem needs to map its counterparty regulatory position, not only its own licence.
The residual "other crypto-assets" category – which covers the majority of utility and payment tokens not qualifying as ARTs or EMTs – requires a crypto-asset whitepaper for public offers above a defined threshold, but the issuer does not need prior authorisation in the same way ART/EMT issuers do. That asymmetry shapes structuring decisions for token projects using a CASP to distribute their asset.
Who Needs CASP Authorisation, and What Are the Exemptions?
Any legal person established in the EU providing regulated crypto-asset services on a professional basis needs CASP authorisation. Third-country firms serving EU clients on a reverse-solicitation basis may fall outside the mandatory authorisation requirement under certain conditions, but the reverse-solicitation exemption under MiCA is narrow and has been interpreted restrictively by supervisors.
The exemption requires that the client in the EU initiated contact with the third-country firm exclusively on their own initiative, without any prior solicitation from the firm, and that the resulting service stays within the scope of that unsolicited approach. Marketing, onboarding flows, app-store listings directed at EU users and affiliate referral programmes all compromise the exemption. ESMA has signalled that it expects NCAs to scrutinise reverse-solicitation claims closely. A business relying on this exemption for any material portion of its EU revenue is carrying regulatory risk that is difficult to quantify and almost impossible to manage reactively.
Certain limited exemptions also apply to persons providing crypto-asset services solely within a group (intragroup services), and to certain limited-network schemes. These are narrow carve-outs that require careful legal analysis before reliance.
Natural persons and very small undertakings below a defined threshold may have access to a lighter regime depending on the member state, but a business operating at commercial scale – an exchange, a custodian, a transfer service, a fund – will not benefit from those carve-outs. The practical presumption for any institutionally oriented crypto business is that MiCA applies and that authorisation is required.
How Does the CASP Authorisation Process Work in Practice?
CASP authorisation is granted by the NCA of the member state in which the applicant is established. The application requires a programme of operations, governance and ownership structure documentation, a business plan, internal control and AML/CFT policies, safeguarding arrangements for client assets, IT and cybersecurity assessments, and details of management fitness and propriety. Minimum own-funds requirements vary by the class of service being applied for; numeric figures are set in MiCA and should be verified against current implementing technical standards before any capitalisation decision.
Timeline to authorisation varies by member state, the complexity of the application and the NCA's own processing capacity. In our cross-border practice, the realistic window from a complete filing to a decision has varied considerably across the EU. Applicants frequently underestimate the time needed to prepare a complete filing – incomplete applications restart the clock and consume regulatory goodwill. We have seen operators budget three months for an application that, because of back-and-forth on governance documentation, stretched well beyond that.
The choice of member state matters significantly. The regulatory approach, processing speed, supervisory philosophy and practical engagement culture differ across NCAs. Jurisdictions with dedicated fintech or crypto supervisory units tend to process applications more efficiently. Malta's MFSA, which administered the prior VFA framework and is now transitioning to MiCA CASP authorisation, brings deep institutional knowledge of crypto-business models. Lithuania's Bank of Lithuania built capacity during the earlier VASP registration era. Other member states are still scaling their supervisory infrastructure.
Once authorised, the CASP must notify its home NCA before passporting services into another member state. The notification process is administrative rather than a new full authorisation, which is MiCA's principal structural advantage over the pre-MiCA patchwork where each member state required separate registration. In practice, the notification window and any local supervisory requirements in the host state still need to be managed proactively.
In a recent authorisation matter, a payment technology company sought CASP authorisation for a crypto-to-fiat exchange service across the EU. The application was filed in a member state with an established supervisory track record. We identified a gap in the applicant's safeguarding policy that the NCA would likely have queried; remedying it before filing avoided a request for information that would have extended the timeline by several months. The service launched on schedule.
What Is the Cross-Border Reality for Operators Outside the EU?
MiCA creates a clear EU authorisation path, but the typical digital-asset business does not operate in the EU alone. Exchanges and custodians commonly have an EU entity, a non-EU holding structure, a custody or technology entity in a separate jurisdiction and banking across three or more countries. MiCA governs the EU service-provision layer; it does not affect what the non-EU entities are required to do under their own regimes.
That multi-layer structure is both the design and the complication. A business with its operational entity in Dubai under VARA (the Virtual Assets Regulatory Authority) and its EU-facing entity seeking CASP authorisation is managing two parallel regulatory regimes simultaneously. The obligations overlap in places – both require AML/CFT programmes, governance structures and prudential capital – but the specifics differ. A compliance framework built for one does not automatically satisfy the other.
For businesses with a Singapore presence under MAS licensing, or a Hong Kong VATP authorisation under the SFC regime, the same dual-track dynamic applies. The EU CASP layer serves EU users; the non-EU licence layer serves the rest. Group-level compliance needs to be mapped against each regime's specific requirements, not designed to a single lowest-common-denominator standard.
Banking access is a persistent cross-border variable. MiCA authorisation improves – but does not guarantee – banking relationships in EU jurisdictions. Banks conducting their own due diligence on CASP clients will examine the governance, AML programme quality and the jurisdictional footprint of the group, not only the existence of a licence. We regularly advise operators that a CASP authorisation is a necessary but not sufficient condition for stable EU banking.
The Travel Rule (the obligation to transmit originator and beneficiary data with a virtual-asset transfer) applies under MiCA in line with the EU's Transfer of Funds Regulation. A CASP's technical infrastructure must support Travel Rule compliance for transfers to and from both EU-regulated counterparties and third-country VASPs. The data-sharing standards and the handling of transfers from non-compliant counterparties remain live operational challenges, particularly for cross-border payment flows.
If a prior application stalled or a banking relationship was closed after a regulatory query, a structural review often surfaces the underlying gap. To discuss your cross-border licence and banking stack, write to OBOLUS at info@oboluslaw.com or via t.me/oboluslaw.
What AML and Ongoing Compliance Obligations Apply to a CASP?
A CASP under MiCA carries a substantial ongoing compliance burden that sits alongside – and in part derives from – the EU's anti-money laundering framework and the FATF Recommendations, including Recommendation 15 on virtual assets. The AML/CFT programme must cover customer due diligence, transaction monitoring, suspicious transaction reporting and a risk-based approach calibrated to the specific services offered.
The Travel Rule data obligation requires CASPs to collect, verify and transmit originator and beneficiary information on crypto-asset transfers above applicable thresholds. The precise threshold is set in the EU Transfer of Funds Regulation and should be verified against current implementing standards; the principle – that data must travel with the asset – is registry-established. CASPs must also have policies for handling transfers from entities in jurisdictions that do not apply equivalent Travel Rule standards, which in practice means most transactions with wallets in less-regulated markets require enhanced diligence.
Ongoing supervisory obligations include periodic reporting to the NCA, notification of material changes to the business, maintenance of governance and control standards and management of conflicts of interest. The authorisation is not a one-time filing; it creates a continuing relationship with the regulator. NCAs have the power to impose conditions, suspend activities or withdraw authorisation. A CASP that treats authorisation as a box-checking exercise and then operates without maintaining its compliance programme is carrying a regulatory risk that compounds over time.
In our cross-border practice, operators who have invested in a genuinely functional compliance infrastructure – not a paper-only AML policy but an operationally embedded risk management system – consistently have better experiences with both regulators and banking counterparties. The market signal a well-maintained compliance programme sends is distinct from the signal sent by a minimum-viable-compliance approach, and the difference shows up in banking relationship quality.
How Does MiCA CASP Authorisation Compare to Prior VASP Registration?
Before MiCA, EU member states implemented the FATF virtual-asset service provider standard through their national AML frameworks, producing a set of national registration regimes with varying rigour, different activity coverage and no passporting mechanism. Lithuania built a light-touch VASP registration that attracted a large volume of crypto businesses. Malta created the VFA framework, a substantively more demanding licence. Other member states implemented minimal or no dedicated crypto regimes.
MiCA replaces that fragmented environment with a single authorisation standard. The consequence for businesses that held pre-MiCA national registrations is a mandatory transition to full CASP authorisation – the prior registration does not grandfather full MiCA compliance. The transition period and grandfathering window vary by member state, but the direction is uniform: every crypto business serving EU clients on a professional basis must ultimately hold or passport a CASP authorisation.
The practical change is significant. A Lithuania VASP registration that cost relatively little and required limited ongoing governance now needs to be upgraded to a CASP authorisation with full governance, capital, AML and operational requirements. Businesses that structured their EU presence around a light registration regime need to reassess their approach. Delaying that reassessment until the NCA prompts it is a common mistake – one that compresses the preparation window and limits the choices available.
Relative to non-EU regimes, MiCA CASP authorisation is more demanding than BVI FSC registration under the VASP Act or CIMA registration in Cayman, which remain lighter-touch regimes suited to fund structures and holding entities rather than operationally active EU-facing service providers. It is broadly comparable in complexity to FINMA in Switzerland and the FCA MLR registration plus financial-promotion compliance regime in the UK, though the scope and detail of each regime differ. Singapore's MAS Payment Services Act licensing and Hong Kong's SFC VATP authorisation sit at a similar level of substantive complexity.
The key differentiator of MiCA is the passporting mechanism. No other jurisdiction offers a single authorisation that covers access to the entire EU internal market. For a business building a Europe-first strategy, that passporting benefit is the principal structural argument for CASP authorisation over any alternative structure.
What Are the Most Common Structural Mistakes Businesses Make Under MiCA?
The most frequent structural mistake is underestimating the scope of the CASP perimeter. A business that assumes its activity is ancillary, intragroup or covered by reverse solicitation – without a formal legal analysis – is making a decision that may look reasonable until supervisory scrutiny arrives. Activity-based perimeter analysis is the starting point, not an afterthought.
A second mistake is conflating the choice of member state with a compliance strategy. Choosing a member state perceived as "easy" without analysing how that NCA's supervisory approach evolves, how the banking environment in that state treats CASPs and whether the NCA has the supervisory capacity to process applications on a reasonable timeline can backfire. A technically complete application filed in an NCA with limited crypto supervisory capacity may wait significantly longer than one filed in a more experienced NCA.
A common assumption is that once a CASP authorisation is obtained, the compliance burden is essentially fixed. That assumption is incorrect. MiCA creates an ongoing regulatory relationship. Regulatory technical standards continue to be developed by ESMA, supervisory expectations evolve and NCAs conduct thematic and firm-specific reviews. A compliance programme needs to be maintained and updated, not archived.
A fourth mistake – one with cross-border dimensions – is failing to map the group's non-EU entities against their own applicable regimes while pursuing CASP authorisation. A group that obtains MiCA CASP authorisation without simultaneously managing its VARA, MAS or SFC obligations may find that its EU licence is in good standing while a non-EU supervisory gap creates the banking or operational problem that disrupts the business.
Finally, the reverse-solicitation exemption is frequently over-relied upon. As noted above, ESMA and NCAs have signalled that they will scrutinise this exemption closely. A business serving material EU client volumes through a third-country entity, relying on the exemption as its only regulatory basis, is carrying a position that is difficult to sustain as supervisory resources and attention increase.
A Self-Assessment: Is Your Business CASP-Ready?
Before engaging with an NCA or committing to a member state, a business should be able to answer each of the following questions with precision.
First: which specific MiCA-enumerated services does the business provide, or intend to provide, to EU-resident clients? The answer should be a list tied to the statutory activity categories, not a general description of the product.
Second: in which EU member state is – or will – the applicant entity be established, and has the choice been made on the basis of a comparative analysis of NCA supervisory approach, banking environment and processing capacity?
Third: what is the group's minimum own-funds position relative to the capital requirements applicable to its specific activity mix? Capital must be in place at authorisation; it is not sufficient to have a capitalisation plan that depends on post-authorisation revenue.
Fourth: is the AML/CFT programme operationally functional – staffed, tested, documented and integrated into the onboarding and transaction monitoring workflow – or does it exist primarily as a policy document?
Fifth: has the business mapped its cross-border obligations, so that the EU CASP authorisation process is coordinated with any parallel licensing obligations under VARA, MAS, the SFC or other applicable regimes?
A business that cannot answer all five questions confidently is not ready to file. The preparation phase is where the application is won or lost; the NCA review is the confirmation, not the analysis. We map the licence stack across operating, custody and payment layers before our clients commit to a structure.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – Our full practice overview: jurisdictions, process and the licence-stack methodology.
- Economic Substance for Licensed VASPs in Malta – What substance requirements apply to MFSA-licensed entities under MiCA transition.
- VASP Business Risk Assessment Under Heightened Scrutiny – How to structure a defensible risk assessment when regulators and banks look closely.
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and the completeness of the application. Under MiCA, NCAs have a statutory assessment window after receiving a complete application, but preparation of a complete filing – governance documents, AML policies, business plans, capital evidence – typically takes several months before submission. In our cross-border practice, the realistic end-to-end window from initial scoping to a positive decision ranges from several months to over a year depending on the member state and the complexity of the business model.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The optimal jurisdiction depends on the services offered, the geographic user base, the group structure, the banking environment and the operator's operational capacity to maintain compliance in that jurisdiction. For EU market access, CASP authorisation in a suitable member state is the only path that delivers passporting rights. For non-EU operations, regimes including VARA, MAS, the SFC and AFSA each offer distinct advantages. A comparative analysis across the licence, banking and tax stack is the starting point for any serious licensing decision.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is itself a regulated service requiring CASP authorisation. If custody is one of several services a business provides, it is covered within a single CASP authorisation covering all regulated activities. If custody is the sole service, the authorisation is still required – it is not subsumed into another provider's licence. In other regimes, such as VARA in Dubai or MAS in Singapore, custody may be a distinct licence category with its own capital and operational requirements. Cross-border groups often need separate custody authorisations in multiple jurisdictions simultaneously.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack before our clients commit – not after. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, cross-border licence stack analysis and NCA engagement across EU and non-EU digital-asset regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.