EST · MMXXVI
Home/Insights/Guides/How to Prepare a CASP Application Under MiCA
Licensing & Registration

How to Prepare a CASP Application Under MiCA

How to Prepare a CASP Application Under MiCA. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business without the correct regulatory authorisation is not a calculated risk — it is an accelerating liability. Under MiCA (the Markets in Crypto-Assets Regulation), the EU's unified regime for crypto-asset service providers, any firm offering services to clients in the European Economic Area must hold a CASP authorisation (crypto-asset service provider authorisation) from a competent national authority, unless a specific exemption applies. The passporting mechanism built into MiCA means that authorisation in one member state opens the entire EU/EEA market — but the application itself is demanding, and a poorly prepared file will stall, not speed, the process.

This guide walks through every material step, from entity positioning through to ongoing compliance readiness. At each stage we identify the regulated basis under MiCA as administered by ESMA and the relevant national competent authority, the cross-border considerations that most applicants underestimate, and the specific mistake that most commonly derails a file at that step.

Step 1: Confirm Whether You Need a CASP Authorisation

The first question is whether MiCA applies to your business at all — and the answer turns on the services you provide, the assets involved and where your clients are located. MiCA covers a defined list of crypto-asset services: operating a trading platform, executing orders, providing advice, portfolio management, custody and administration of crypto-assets on behalf of clients, and related activities. If your business touches any of those services for clients in the EEA, a CASP authorisation is the required instrument.

Two carve-outs are worth examining carefully. Persons providing CASP services on a purely incidental basis within a regulated professional activity may fall under a limited exemption. Firms already authorised under sector-specific EU financial directives — MiFID investment firms, credit institutions — may provide certain crypto-asset services under a notification rather than a fresh CASP application, subject to conditions. Neither exemption is broad, and regulators have signalled they will scrutinise self-assessments closely.

The cross-border reality adds a layer most operators miss. MiCA applies where clients are located, not only where the entity is incorporated. A business incorporated outside the EU but actively soliciting EEA users sits within scope. Reverse-solicitation arguments — that the client approached the firm — are narrow and fact-specific; they are not a general licence substitute. In our practice we have seen founders bank on a reverse-solicitation position that collapsed the moment the regulator reviewed the firm's marketing materials.

Common mistake at this step: assuming that a non-EU entity with an EU user base is outside scope because it has no EU office. The activity test under MiCA is service- and client-facing, not solely entity-based.

Step 2: Choose the Right Member State and Competent Authority

The choice of home member state is a structuring decision with long-term regulatory, operational and banking consequences. ESMA coordinates the CASP regime, but each national competent authority sets its own procedural expectations, staffing depth and practical processing culture. A well-resourced authority in a crypto-literate jurisdiction often moves faster than one that is processing CASP applications as a novel category.

Several factors drive the selection: the jurisdiction's existing VASP registration infrastructure and transition arrangements under MiCA, the regulator's published guidance on application completeness, the availability of local qualified staff (some authorities require on-the-ground personnel), and the banking environment for licensed entities. An authorisation that cannot be banked is a licence with limited utility.

Lithuania, for example, built a large early VASP registration base under its prior regime and is navigating the MiCA transition with that institutional history behind it. Malta's MFSA is transitioning entities previously authorised under the VFA framework. Each path has its own procedural legacy. Selecting a member state solely on perceived ease of application — without modelling the banking and tax implications — is one of the most common structural errors we encounter.

Cross-border note: Once you hold a CASP authorisation, you notify the home NCA before passporting to another member state. The notification procedure is MiCA-defined. Build the intended passport footprint into the initial application design — the services listed in your authorisation must match the services you intend to passport.

Common mistake at this step: choosing a member state for its historic light-touch reputation without confirming that the same authority is resourced for MiCA-standard processing or that local banking is viable for your business model.

To pressure-test your member-state selection before you commit, write to us at info@oboluslaw.com. The entity, the banking and the intended service scope all affect the answer — and they interact in ways a checklist does not capture. Map your options

A CASP application is a legal-entity-level submission: the competent authority is authorising the specific EU-incorporated entity, not the group. The entity must satisfy the requirements on registered office, place of effective management, and the seniority of management body members — all requirements that ESMA has articulated in its guidance on CASP applications.

Governance documentation is among the most heavily scrutinised components of a CASP file. The competent authority will expect to see: a clearly drawn organisational chart showing reporting lines; documented delegation of authority; evidence that the management body has collective competence across the firm's risk profile; written policies for conflicts of interest; and a credible succession framework. For groups with ultimate beneficial owners outside the EU, the source-of-funds and ownership tracing chain must be documented to a standard that satisfies both the CASP application and the AML due-diligence requirements that sit alongside it.

The MiCA regime does not operate in isolation from the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying crypto-asset transfer). AML and Travel Rule compliance documentation will be assessed as part of the overall authorisation file, either within the CASP application itself or in parallel. Regulators increasingly regard AML substance as a threshold question, not an afterthought.

Common mistake at this step: submitting an organisational chart that accurately describes the holding structure but does not identify the management body of the applying entity with clarity. Reviewers escalate files where it is unclear who is actually responsible for risk at the regulated entity level.

Step 4: Draft the Programme of Operations

The programme of operations is the spine of the CASP application file. It describes what the business does, how it does it, to whom and in which markets — in enough detail that the competent authority can assess regulatory fit without needing to ask supplemental questions. Under MiCA's application requirements as developed by ESMA, the programme must address the specific services for which authorisation is sought, the types of crypto-assets covered, the jurisdictions where services will be offered, and the business model underpinning each activity.

Operators authorised under MiCA to provide custody services are subject to specific safeguarding and segregation obligations. The programme of operations must reflect those obligations in its description of custody processes. For trading platforms, the technical and operational requirements governing order matching, market integrity and settlement are significant. Each service type carries its own ESMA-defined set of organisational requirements that the programme must substantively address — not merely acknowledge.

The cross-border element is embedded in the programme itself. If you intend to serve clients outside the EU — in Singapore, in the UK, in the Gulf — those activities must be mapped. Services to non-EEA clients may sit outside MiCA's perimeter but within the scope of those other regimes. The programme of operations cannot pretend that the business stops at the EU border.

Common mistake at this step: drafting a programme that describes the intended business at a high level but does not map specific services to specific CASP categories. An authority reviewing a vague programme will issue queries; each query round adds time to the process.

Step 5: Build the Prudential and Risk Framework

MiCA imposes own-funds requirements that vary by CASP category and the scale of the business. The specific thresholds are set at the regulatory level and subject to change — confirm current figures directly with the relevant national competent authority or through counsel before structuring capital. What is fixed in the regulation is the principle: a CASP must maintain own funds at all times in specified instruments, above a category-defined floor, and must demonstrate that it will continue to do so across the business plan horizon.

Beyond the headline capital figure, the prudential chapter of a CASP application covers business continuity planning, ICT risk management and outsourcing governance. The Digital Operational Resilience Act (DORA) applies to CASPs in scope, and competent authorities will expect the application to reflect DORA-aligned ICT risk policies. Outsourcing of critical functions — including cloud infrastructure, custody technology and AML screening tooling — requires documented oversight frameworks, not mere vendor contracts.

Operators with a group structure must also address intra-group outsourcing on arm's-length terms and demonstrate that the EU entity is not a shell dependent on a non-EU parent for all operational substance. Regulators have grown notably sceptical of arrangements where the regulated entity lacks operational autonomy.

Cross-border note: If the CASP relies on technology infrastructure or operational functions located outside the EU, document the oversight chain from the EU entity to each third-country service provider. Post-Brexit, UK-based group entities no longer benefit from EU passporting and must be treated as third-country counterparties in the outsourcing framework.

Common mistake at this step: treating the prudential chapter as a formality and attaching generic policy templates. Competent authorities can identify templated policies quickly and will ask for evidence that the policies have been adopted, tested and are operationally embedded.

If your application has stalled or a prior attempt was queried on governance or prudential grounds, our licensing desk can diagnose the file. Write to info@oboluslaw.com or reach us at t.me/oboluslaw. A second read often identifies structural gaps that are straightforward to address. Map your options

Step 6: Prepare the AML/CFT and Travel Rule Documentation

AML/CFT compliance documentation is assessed in parallel with — and often treated as a prerequisite to — a successful CASP authorisation. The applicable standard is the EU's AML regime as it applies to crypto-asset businesses, informed by FATF Recommendation 15 on virtual assets. A CASP must demonstrate a complete AML/CFT framework: a current business-wide risk assessment; customer due-diligence procedures covering onboarding, ongoing monitoring and enhanced due diligence for higher-risk relationships; a transaction monitoring framework calibrated to the firm's risk profile; and a suspicious-transaction reporting chain from front-line staff to the designated money-laundering reporting officer.

The Travel Rule — the obligation to transmit originator and beneficiary information with qualifying crypto-asset transfers — requires a technical implementation as well as a documented policy. The technical solution must be capable of communicating with counterparty VASPs in other jurisdictions. Where a counterparty VASP is located in a jurisdiction without a Travel Rule regime, the operator must have a documented policy for unhosted wallet interactions and for sunrise-issue situations where a compliant counterparty cannot be identified. The threshold for Travel Rule obligations varies by jurisdiction; confirm the applicable threshold in each market where you operate before the application is filed.

Common mistake at this step: providing an AML policy that reads as complete on paper but lacks the jurisdictional mapping for Travel Rule interactions with non-EU VASPs. Reviewers in AML-focused authorities flag this gap consistently.

Step 7: Self-Assessment Checklist Before Submission

Before submitting to the competent authority, a well-prepared applicant runs a structured completeness review against the regulatory framework. The following elements must be present and internally consistent across the file.

  • Legal entity documents: current certificate of incorporation, constitutional documents, share register, UBO register extract.
  • Management body: full personal questionnaires and fitness-and-propriety materials for each member; no material gaps or unresolved adverse history.
  • Programme of operations: service-by-service description aligned to MiCA CASP categories; geographic scope; product descriptions.
  • Own-funds evidence: current balance sheet; capital commitment letter from shareholders if initial capitalisation is pending; three-year financial projections.
  • Governance policies: conflict-of-interest policy; remuneration policy; complaints-handling procedure; business continuity and ICT risk framework; DORA-aligned ICT governance documentation.
  • AML/CFT framework: business-wide risk assessment; CDD procedures; transaction monitoring policy; MLRO appointment; Travel Rule technical solution and policy.
  • Custody documentation (if applicable): client asset segregation framework; reconciliation procedures; safeguarding policies.
  • Outsourcing register: all critical and important function outsourcing documented with oversight frameworks.

Internal consistency matters as much as completeness. The programme of operations must align with the own-funds section, which must align with the financial projections, which must align with the governance structure. A regulator reviewing a file where the programme describes a large-scale exchange but the capital table reflects a small pilot operation will query the gap. Anticipate and address those tensions in the narrative before submission.

In a recent licensing matter, a crypto exchange operator had assembled a substantially complete file but submitted it with two service categories listed in the programme that were not reflected in the own-funds calculation. The competent authority issued a formal query, suspending the clock. We were engaged to reconcile the file; the correction was straightforward, but it added several weeks to the process. The lesson is structural: every column of the application file must tell the same story.

Step 8: Manage the Authorisation Process and Post-Authorisation Obligations

Once the file is submitted, the competent authority has a defined period under MiCA to assess completeness and then to reach a determination on the application. The specific assessment and decision timelines are set in the regulation; confirm current processing benchmarks with the relevant NCA or through counsel, as practical timelines vary by authority and by current volume. If the authority issues a query, the clock typically pauses until a complete response is received — making the quality of query responses as important as the initial submission.

Post-authorisation obligations begin on the first day of operation. A CASP must notify its home NCA before material changes to its programme of operations, governance structure or ownership. Passporting notifications must be filed before commencing services in a new member state. Ongoing prudential reporting, AML reporting to the financial intelligence unit, and incident reporting under DORA are all standing obligations.

The cross-border obligation stack does not end with the CASP authorisation. Serving clients in Singapore, Hong Kong, the UAE or the UK requires analysis under each of those regimes — the MAS Payment Services Act regime, the SFC VASP licensing requirements, the VARA activity-based licences in Dubai, and the FCA's MLR registration and financial-promotion rules. A CASP authorisation under MiCA is the EU credential; it is not a global licence. Operators who proceed on the assumption that EU authorisation satisfies non-EU regulators consistently encounter difficulty at the point of client onboarding or banking in those markets.

Common mistake at this step: treating the CASP authorisation as the end of the regulatory programme. In practice, authorisation is the starting point for a standing compliance and reporting obligation set that must be resourced and managed continuously.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the competent national authority has a defined regulatory period to assess a complete CASP application and reach a determination. In practice, elapsed time varies significantly by authority, by current application volume and — critically — by the quality of the submitted file. A complete, internally consistent application moves faster than one that generates queries. An authority clock pauses when it issues a query; each query round adds weeks. Planning for a process measured in months, not weeks, is prudent.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The optimal home member state for a CASP authorisation turns on the services you provide, the jurisdictions where your clients are located, the banking environment for licensed entities in each candidate jurisdiction, the regulator's processing capacity under MiCA and the tax treatment of the operating entity. Some operators prioritise established crypto-regulatory infrastructure; others weight banking relationships or the cost of maintaining local substance. We map those axes for each client structure before a selection is made.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is itself a CASP service category. If your business model includes holding client assets — whether as a standalone custodian or as an ancillary function of an exchange or fund platform — that service must be within the scope of your CASP authorisation. A CASP authorised only for trading-platform operations cannot lawfully provide custody services without expanding its authorisation. Additionally, serving clients in non-EU jurisdictions such as Singapore, Hong Kong or Dubai may require separate custody authorisation under those local regimes.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — so the structure you build is one that regulators, banks and counterparties accept. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in CASP authorisation strategy, VASP registration and multi-jurisdiction licence design for digital-asset businesses entering the EU and other regulated markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours