CASP Authorisation Under MiCA: The Compliance Burden in Practice
CASP authorisation under MiCA – the CASP (crypto-asset service provider) licence created by the Markets in Crypto-Assets Regulation – is now the primary gateway for any business offering crypto-asset services across the European Union. The regime applies to exchanges, custodians, brokers, portfolio managers, transfer agents and advisers alike, and it carries a compliance burden that routinely surprises operators who sized it against the prior national VASP registration regimes it supersedes. Failure to complete the process before commencing services exposes the business to enforcement action, account termination and the kind of reputational event that takes years to repair. This analysis maps the authorisation path, surfaces the pressure points that slow applications, and identifies the cross-border decisions every operator must resolve before filing.
What MiCA Actually Requires of a CASP Applicant
MiCA requires every business that provides crypto-asset services to EU clients on a commercial basis to hold a CASP authorisation from a national competent authority in an EU member state before it commences those services. The obligation is activity-based. It does not matter where the entity is incorporated outside the EU; if it actively solicits or serves EU-resident clients, the authorisation requirement is engaged. The regulated activities under MiCA span nine categories – custody, operation of a trading platform, exchange, peer-to-peer facilitation, execution of orders, portfolio management, reception and transmission, advice, and transfer services – and an entity providing more than one must ensure its authorisation covers each in scope.
The licensing requirements under the regulation are materially heavier than those that characterised the registration regimes that preceded it in Lithuania, Malta and other early-mover member states. Those regimes imposed AML/KYC compliance obligations but generally did not mandate organisational requirements, prudential capital, governance structures or product-level disclosures of the depth MiCA now demands. In our practice we regularly advise operators who built their EU access on a Lithuanian or Maltese VASP registration and are now recalibrating their entire compliance architecture to meet the CASP standard.
The authorisation dossier that a national competent authority expects is substantial. It covers: a detailed description of the applicant's business plan and service scope; the organisational structure, including governance, internal controls and risk management; identification of all qualifying shareholders and members of the management body, each subject to a fit-and-proper assessment; the prudential basis (own-funds calculation or insurance equivalent); a description of the custody and safeguarding arrangements for client assets; the complaints-handling procedure; and the AML/CFT programme consistent with the FATF Recommendations and applicable EU directives. Assembling that dossier with the precision a competent authority expects is the first bottleneck.
Why the Cross-Border Reality Complicates Every Application
The single most consequential feature of MiCA for a business with a global footprint is the mismatch between where the regulated entity sits, where its users are located and where its operational infrastructure – banking, custody, technology – resides. Each of those three axes generates a distinct compliance obligation, and those obligations do not always align neatly under a single NCA's supervisory expectations.
An operator licensed under VARA in Dubai, for example, may believe that a Dubai authorisation covers its EU user base. It does not. MiCA's passporting mechanism operates exclusively within EU/EEA member states; authorisation in one member state permits cross-border service provision to the remaining member states without a separate filing, but that benefit is unavailable to a non-EU entity relying on a foreign licence. The third-country regime under MiCA is narrow: reverse solicitation is available only where the client approaches the provider on its own exclusive initiative, a standard regulators in several member states have indicated they will interpret strictly.
For operators serving both EU and non-EU markets, the structural question becomes which entity holds the CASP authorisation, how that entity relates to the wider group, and whether intra-group arrangements – technology sharing, order routing, liquidity provision – trigger their own regulatory authorisation requirements. We have seen structures collapse at this stage because the applicant had not anticipated that the EU entity's reliance on group infrastructure could constitute a regulated service in its own right.
Banking is the third dimension. European banks remain selective about servicing crypto businesses even where those businesses hold a CASP authorisation. The regulatory authorisation itself does not guarantee correspondent banking access, and an operator that files its CASP application before securing a credible banking arrangement may find the practical utility of the licence severely limited even after it is granted.
For a scoped assessment of your EU market access structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis materially. Map your options before the application is filed.
How to Structure the Compliance Architecture Before Filing
Building the compliance architecture before the application is filed is not a preparatory nicety – it is the single variable most predictive of whether the authorisation moves through the NCA's review in a single assessment cycle or bounces back for supplementation. Operators who treat the CASP application as a documentation exercise tend to encounter precisely that outcome; the NCA's queries identify gaps in the underlying compliance system, not merely gaps in the dossier.
The architecture work runs along four parallel tracks. First, the governance design: the management body must meet the NCA's composition and time-commitment expectations, and each member must clear a fit-and-proper review that in practice requires a professional biography, a criminal record certificate and often a regulatory reference from any prior regulated role. The fit-and-proper assessment is a genuine gating requirement, not a formality; we advise clients to begin it at the earliest opportunity because third-party documentation collection is slow.
Second, the prudential track: the own-funds requirement under MiCA is graduated by the categories of service the entity provides, and operators offering a combination of high-risk services – exchange operation plus custody, for instance – carry a materially higher capital floor than a pure advisory firm. The calculation requires a qualified assessment of each service against the applicable own-funds class. Writing this qualitatively because the precise thresholds are the subject of ongoing technical implementation standards rather than fixed values published at the time of this analysis: expect the own-funds requirement to be in a range that makes sense for the scale of services but to require documented monthly verification once the licence is live.
Third, the AML/CFT programme. The Travel Rule – the FATF obligation to pass originator and beneficiary data with each virtual-asset transfer – applies to CASPs under MiCA's framework and requires technical integration with a VASP-to-VASP messaging protocol, a compliant onboarding process for unhosted-wallet transfers and a documented sunset procedure for transfers that cannot be enriched. NCAs in the leading member states have indicated that Travel Rule compliance is a live authorisation criterion, not a post-licensing deliverable.
Fourth, the white-paper obligation. For service providers that also issue or offer crypto-assets, the white-paper regime under MiCA runs parallel to the CASP authorisation and carries its own notification or approval timeline. Conflating the two processes – or assuming that a CASP authorisation covers white-paper obligations – is a structural error that delays both tracks.
Which NCA Should You File With – and Why It Matters
The choice of member state for a CASP authorisation is a strategic decision with long-term operational consequences, and it should not be made on the basis of speed alone. The EU passporting mechanism means that authorisation in any member state carries the right to passport to the others, so the operative question is not which NCA grants a licence most quickly, but which NCA's supervisory posture, institutional capacity and jurisprudential environment best matches the applicant's business model and risk profile.
Member states that built early infrastructure for VASP registration – Lithuania and Malta in particular – developed technical familiarity with crypto-asset business models before MiCA entered into force. The Bank of Lithuania and the MFSA have supervisory teams with experience across the cycle of application, supervision and enforcement that newer entrants to the supervisory environment may not yet have matched. For an operator whose business model is well-understood and whose application is clean, a jurisdiction with institutional depth may process more predictably than one whose NCA is processing CASP applications for the first time at scale.
Conversely, an operator with a complex business model – a combination of exchange, custody and transfer services, with an international group structure – may benefit from early engagement with the NCA through the pre-application process that several member states offer. That process allows the applicant to clarify scope questions before committing to a full dossier, reducing the risk of a fundamental application error that triggers a rejection rather than a request for supplementation.
The cross-border dimension also affects NCA choice in a less obvious way: the member state in which the CASP is authorised is the state of supervision for the group's EU operations. Operators that have existing relationships with banks, custodians or infrastructure providers in a particular member state may find that operational coherence weighs in favour of filing there, irrespective of headline processing timelines.
What Goes Wrong: Common Points of Application Failure
Application failures at the CASP authorisation stage concentrate around a small number of recurring structural and documentary issues. Identifying them in advance is material to the outcome.
The most common failure mode is the incomplete or inconsistent governance disclosure. NCAs reviewing CASP applications expect a complete and internally consistent picture of the entity's ownership and management. Where the group structure is complex – multiple holding layers, nominee arrangements, a mixture of natural and legal persons in the ownership chain – the fit-and-proper documentation must trace every qualifying holder. An NCA that identifies inconsistencies between the ownership disclosure, the corporate registry extract and the management body declarations will issue a comprehensive supplementation request that pauses the clock on the assessment period. In our practice we routinely see this add several weeks to an otherwise straightforward process.
The second failure mode is the thin AML/CFT programme. A programme that reproduces the FATF Recommendations in generic terms without demonstrating how the applicant's specific product, customer base and transaction flows translate into concrete controls will not satisfy a competent NCA. The programme needs to reflect the actual risk vectors of the business: geographic exposure, customer type, product risk, transaction velocity and the specific Travel Rule implementation the applicant has adopted.
Third, the custody and safeguarding section frequently understates the operational specificity the NCA expects. For an applicant that holds client assets – whether as a trading platform that pools customer funds or as a standalone custodian – the description of the safeguarding model, including the cold/warm/hot wallet architecture, the key management protocol and the insurance or capital backing for safeguarded assets, must be granular. Generic assertions that "assets will be segregated" without operational detail will generate supplementation requests.
A micro-matter that illustrates the point: in a recent authorisation engagement, a payments business that had previously operated under an MSB registration in North America attempted to adapt its existing AML/CFT documentation directly for a MiCA CASP filing in a central European member state. The NCA's initial review identified that the programme did not address the Travel Rule, used thresholds calibrated to the MSB regime rather than the EU's, and contained no explicit policy for unhosted-wallet counterparty risk. We rebuilt the programme from the risk assessment level and re-filed; the supplementation response was accepted on first review and the authorisation was granted within the statutory assessment window.
Decision Matrix: Which Profile Should Choose Which Path
Not every operator approaches the CASP authorisation process from the same position. The most effective strategy varies significantly by business profile, and a matrix that maps profile to path is more useful than a single prescriptive answer.
Profile A – Early-stage exchange with EU user base, single-jurisdiction footprint. The clean-sheet operator that is building its compliance architecture from inception has the most flexibility. The strategic priority is NCA selection that aligns supervisory experience with business model, followed by parallel-track governance build and AML programme development. The own-funds requirement is likely at the lower end of the graduated scale if the service scope is limited. Timeline: the authorisation process from complete dossier submission to grant is measured in months; the pre-filing compliance build typically adds further months before the application is ready. Starting early matters.
Profile B – Established operator transitioning from a VASP registration to CASP. The operator who built EU market access under a pre-MiCA regime faces a gap analysis exercise rather than a clean build. The prior registration confirmed AML compliance at a lighter standard; the CASP dossier requires a substantially upgraded programme, a governance overlay that may require new or retooled management body members, and a capital demonstration that the registration regime did not demand. The transition deadline is a hard constraint. Operating on a registration beyond the applicable transition period exposes the business to enforcement by the NCA even if the CASP application is pending.
Profile C – Multi-jurisdiction operator adding EU access to an existing licensed structure. The most complex profile. The operator must resolve the entity structure question before filing: which legal entity will hold the CASP, what its relationship is to the non-EU operating entities, and how intra-group dependencies are characterised for regulatory purposes. Allied counsel in the relevant jurisdiction may be required for each non-EU element. The CASP application itself is no more complex than Profile A's, but the pre-filing structural work is materially longer. The passport, once obtained, is a significant commercial asset: it covers all EU/EEA member states from a single authorised entity.
Profile D – Token issuer who also operates secondary market infrastructure. This profile triggers both the white-paper regime and the CASP authorisation, and the two tracks must be managed as a combined programme. The sequencing decision – whether to obtain CASP authorisation before launching the secondary market, or to run both applications in parallel – depends on the NCA's expectations and the operator's timeline. Running them in parallel is faster but requires more resources and tighter project management. Running them sequentially is safer but may delay market access by a significant period.
If a prior application stalled or a banking relationship was lost during the process, a second read often surfaces the structural reason and the route back. Write to info@oboluslaw.com – or map your options directly.
Ongoing Obligations After Authorisation: The Compliance Burden Does Not End at Grant
The grant of a CASP authorisation is not the end of the compliance burden – it is the beginning of a sustained supervisory relationship that carries ongoing obligations the operator must build into its operating model from day one. Treating authorisation as a one-time project rather than a permanent operational state is a reliable predictor of supervisory difficulty within the first licensing cycle.
The ongoing obligations fall into several categories. The NCA expects notification of any material change to the information on which the authorisation was granted: changes to the management body, changes to the ownership structure, new service lines and significant changes to the AML/CFT programme all require advance notification and, in many cases, formal NCA approval before implementation. An operator that adds a custody service to an existing exchange authorisation without notifying the NCA is operating outside the scope of its licence from the date the new service commences.
The prudential reporting regime requires the CASP to demonstrate ongoing compliance with its own-funds requirement at regular intervals. Where the entity's financial position deteriorates, the NCA must be notified and a remediation plan presented. Operators whose business model generates variable fee income – which describes most crypto exchanges – need a capital buffer strategy that anticipates revenue volatility, not merely a point-in-time own-funds calculation at the time of application.
The AML/CFT programme must be maintained as a living document, reviewed against supervisory guidance and updated when FATF standards or EU-level directives change. The Travel Rule in particular is a moving target: the technical standards governing data formats, inter-VASP messaging and unhosted-wallet treatment continue to develop, and a programme that was compliant at authorisation may require updating within months. We advise CASPs to build a quarterly programme review into their compliance calendar as a standing item.
Cross-border operators face an additional ongoing obligation: monitoring regulatory developments in each member state to which they passport services. While the CASP authorisation provides EU-wide access, individual member states retain supervisory competences in areas that MiCA does not fully harmonise, including certain aspects of AML/CFT supervision and the treatment of specific product types. An operator passporting into a member state that has adopted a stricter local AML posture needs to reflect that posture in its programme for services rendered to clients in that state.
A Common Assumption About MiCA That Leads Operators into Difficulty
A common assumption in the market is that a well-established offshore licence – a VARA authorisation from Dubai, an FSC registration from the BVI, or a Payment Services Act licence from Singapore – provides sufficient regulatory cover for a business that also serves EU clients, provided the business does not maintain a physical presence in the EU. That assumption is incorrect, and regulators in multiple EU member states have made clear they will not accept it.
MiCA's scope is determined by service provision to EU-resident clients, not by the physical location of the provider. The reverse-solicitation carve-out that existed under MiFID II – an approach on which many non-EU operators historically relied – is preserved in MiCA but interpreted narrowly. It requires that the client approached the provider on its own exclusive initiative, with no prior marketing, targeting or outreach by the provider directed at EU clients. Where a business operates a publicly accessible platform, maintains social media accounts or advertising visible in the EU, or actively engages EU users in any marketing channel, the exclusive-initiative standard is very difficult to meet.
In our cross-border practice, we have seen this assumption lead operators into a situation where they are simultaneously managing an enforcement inquiry in an EU member state and an application for CASP authorisation that was triggered by that inquiry – a position that is structurally weaker than an application filed in the ordinary course. The cost of that sequence is always higher than the cost of filing on a planned timeline.
The multi-jurisdiction reality of digital-asset business means that a sound licensing architecture requires mapping every jurisdiction in which clients are served, every jurisdiction in which the entity or its group holds assets, and every jurisdiction whose banking system the operator relies on. A single offshore licence is rarely sufficient to cover that map.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – how we scope the full licence stack across operating, custody and payment layers
- EMI licensing for crypto firms under MiCA – the e-money institution route and how it interacts with CASP authorisation
- Correspondent banking access in Liechtenstein – managing the banking dimension for EU-adjacent licensed entities
FAQ
How long does a crypto licence take to obtain?
The timeline for a CASP authorisation under MiCA depends on the member state chosen, the completeness of the application dossier and the complexity of the business model. The regulation sets a statutory assessment window for NCAs, but the clock does not run during the period the NCA is awaiting supplementation from the applicant. In practice, from the start of pre-filing compliance build to the grant of authorisation, operators should expect a process measured in several months at minimum. Simple, single-service models with a well-prepared dossier typically move faster than multi-service or complex-structure applications.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction: the optimal choice depends on the services offered, the client base, the group structure, the banking relationships available and the supervisory posture that best fits the business model. Within the EU, member states with established crypto supervisory experience – including Lithuania and Malta – offer institutional familiarity that can be valuable for a straightforward application. For a business also serving non-EU markets, the choice of CASP member state must sit within a broader multi-jurisdiction licensing architecture that may involve VARA, MAS, SFC or other regimes alongside MiCA.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated CASP activity. An operator that holds client assets as part of a broader exchange or transfer service must ensure its CASP authorisation explicitly covers the custody activity; it cannot rely on the exchange authorisation to cover incidental asset-holding. Where custody is the primary service, the operator's own-funds requirement and safeguarding obligations will reflect the custody-specific category. Operators providing custody to other CASPs or to institutional clients as a standalone service should treat the authorisation scope question as a day-one structural decision.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the authorisation you file reflects your actual structure, not a simplified version of it. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums for clients who need rapid action. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in CASP and VASP authorisation strategy across EU and multi-jurisdiction licensing engagements.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.