MiCA – the EU's Markets in Crypto-Assets Regulation – fundamentally changes the authorisation calculus for any non-EU operator that touches European users, euro-denominated stablecoins, or EU-regulated counterparties. Under the CASP (Crypto-Asset Service Provider) authorisation regime administered by ESMA and national competent authorities (NCAs), operating without the right licence now exposes a business to enforcement action, terminated banking relationships, and exclusion from the world's largest single market. This analysis maps the regime, identifies the cross-border pressure points, and sets out the strategic choices facing operators headquartered outside the EU.
What MiCA Actually Demands of a Non-EU Operator
MiCA requires any entity providing crypto-asset services to EU clients on a commercial basis to hold a CASP authorisation from an EU or EEA national competent authority. The regime does not discriminate by the operator's domicile. A Singaporean exchange, a BVI-domiciled custodian, or a US-licensed broker-dealer serving German retail customers must each assess whether they are caught. ESMA and the NCAs – the regulators of record for day-to-day supervision – have made clear that the determining factor is the location of the client, not the entity. A reverse-solicitation exemption exists, but it is narrow and actively scrutinised; a non-EU firm that runs advertising, social media campaigns, or referral arrangements targeting EU users will find the exemption unavailable.
The practical consequence is a forced structural choice. Either the operator establishes an EU-authorised entity to hold the CASP licence and passport across the single market, or it ring-fences EU business entirely and accepts the revenue loss. In our practice, we see many operators underestimating how quickly European user flows, even at modest scale, trigger the licensing threshold. The reverse-solicitation defence that worked under legacy AML registration regimes does not carry over cleanly into MiCA's activity-based perimeter.
The CASP authorisation covers eight service categories under MiCA, including custody, exchange against fiat, exchange crypto-to-crypto, execution of orders, portfolio management, reception and transmission of orders, transfer services, and placement. An operator conducting more than one of these activities needs each covered by its authorisation scope. Missing a category – even an ancillary one the operator regards as secondary – creates a regulatory gap that a well-prepared NCA examiner will identify during the supervisory review cycle.
The process above describes the standard authorisation path. Your facts – the entity, the user base, the banking – change the analysis materially. For a scoped assessment of your MiCA exposure before you commit resources, contact OBOLUS at info@oboluslaw.com.
Does MiCA Upgrade Your AML and Travel Rule Obligations?
For any non-EU operator previously operating under a lighter AML-registration regime, MiCA combined with the EU's Transfer of Funds Regulation represents a material compliance step-up, not merely a licence swap. The Travel Rule – the obligation to pass originator and beneficiary identification data with every qualifying virtual-asset transfer – applies in the EU under a standard aligned with the FATF Recommendation 15 framework. National competent authorities expect CASPs to have functioning Travel Rule compliance programs in place at authorisation, not as a post-licensing project.
In our cross-border practice, we regularly advise operators who hold FATF-compliant Travel Rule infrastructure built for a non-EU jurisdiction and assume it will satisfy MiCA supervision. The assumption is partially correct – the data elements are largely aligned – but the EU implementation introduces specific expectations around counterparty CASP verification, sunrise-period handling for transfers to unhosted wallets, and record-keeping periods that vary from what the operator has already built. A gap analysis against the EU standard, before the NCA examines the program, is significantly less expensive than a remediation order after.
KYC framework expectations are similarly elevated. MiCA-authorised CASPs are expected to operate a KYC framework (the suite of customer due diligence, enhanced due diligence, and ongoing monitoring obligations) that meets the Fourth and Fifth Anti-Money Laundering Directives, with further alignment anticipated as the EU's new AML Authority – AMLA – assumes direct supervisory responsibility over the largest CASPs in the coming years. Transaction monitoring systems must be calibrated for crypto-specific typologies, not simply adapted from a traditional-finance rulebook. Regulators in the leading hubs increasingly expect scenario libraries, alert calibration documentation, and periodic independent testing – not a static rule set.
Which Operators Are Most Exposed to MiCA Disruption?
Exposure to MiCA's authorisation requirement is not uniform. Three operator profiles face the sharpest adjustment, and each calls for a different strategic response.
First, exchanges and brokers operating under legacy EU AML registrations – most commonly from Lithuania or Malta – must transition to full CASP authorisation. A prior VASP registration with the Bank of Lithuania or the MFSA's VFA framework does not automatically convert. The operator must file a fresh CASP application, meet the elevated own-funds and governance requirements, and satisfy the NCA that its compliance program meets MiCA standards. The transition window is not indefinite, and NCAs retain the authority to revoke legacy registrations for operators that fail to progress toward authorisation.
Second, offshore-licensed operators – those holding a BVI FSC registration under the VASP Act 2022, a Cayman CIMA licence, or an AFSA authorisation in the AIFC – face the sharpest mismatch. These regimes are well-designed for their own purposes, but none confers MiCA passporting rights. A business that expanded into European markets on the logic that an offshore licence plus local AML registration was sufficient now faces a fundamental restructuring decision. The BVI and Cayman frameworks remain valuable for fund structuring and custody entities, but they cannot substitute for EU authorisation where EU client-facing services are being provided.
Third, stablecoin issuers are in a category of their own. MiCA creates two distinct token regimes – ART (asset-referenced tokens) and EMT (e-money tokens) – each with issuer authorisation requirements, reserve composition obligations, and whitepaper publication duties. A non-EU stablecoin issuer whose token circulates among EU users may be caught even if the issuer provides no other service. ESMA has signalled that the significant-token classification – which brings additional reserve and interoperability requirements – will be applied to tokens with large EU user bases regardless of the issuer's domicile. For a US-dollar-denominated stablecoin issuer, that is a material risk that many teams have not fully priced.
How Does MiCA Compare to Parallel Regulatory Regimes?
The honest answer is that MiCA is the most structurally demanding crypto-specific regime yet enacted by a major jurisdiction, but it is not the most operationally burdensome in every dimension. Understanding the comparison helps a non-EU operator calibrate where to prioritise structural investment.
Under the MAS Payment Services Act in Singapore, a Digital Payment Token service provider must meet stringent AML and technology-risk standards, and the MAS licensing process is known for its depth of scrutiny. But the Singaporean regime does not impose MiCA's passporting architecture or its token-issuer authorisation layer. An operator holding a Singapore Major Payment Institution licence is well-positioned for Southeast Asian operations; it does not acquire EU market access.
The SFC's VATP regime in Hong Kong is increasingly rigorous, with fit-and-proper standards and platform-governance requirements that rival MiCA in operational depth. Again, however, it is a Hong Kong access tool, not an EU one. Operators we advise that run a dual-hub model – Singapore for Asia, an EU member state for Europe – face the full compliance stack of both regimes simultaneously. The cost is real. The alternative – picking one hub and accepting the other market's constraints – is a business decision that the legal structure must support, not a legal decision in itself.
VARA in Dubai has positioned itself as a pragmatic alternative for businesses that want a major-hub licence without EU complexity. The activity-based VARA rulebooks and a commercially minded supervisor have attracted significant operator interest. But VARA, like Singapore, does not provide EU access. For a business with a global user base, the single-hub model carries concentration risk: if that hub's regime tightens, or if banking access narrows, the entire EU market may become unavailable at once.
The structural lesson is not that one regime is better. It is that a non-EU operator serving multiple markets needs a licence architecture that is deliberately multi-layered, not a single offshore authorisation treated as globally sufficient.
If a prior application stalled – or if your current licence stack is not covering the EU user flows it was meant to – a second read can surface the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com.
Decision Matrix: Which MiCA Entry Path Fits Your Operator Profile?
The right MiCA entry strategy turns on three variables: the scope of services the operator intends to provide, the existing entity structure, and the timeline to EU revenue. Mapping these produces distinct recommended paths.
Profile A – the operator building from scratch with a medium-to-long EU timeline. This profile has the most flexibility. A greenfield CASP applicant can select the NCA best matched to its service scope, governance capacity, and expected supervisory style. Lithuania, under the Bank of Lithuania, has historically processed applications at pace and offers passporting across the EU/EEA once authorised. Malta's MFSA brings established VFA infrastructure now transitioning to MiCA. Neither choice is wrong; both require a fully resourced compliance program, appropriate own-funds, and a management body that meets the regulator's fit-and-proper expectations. The indicative path from initial engagement to CASP authorisation – subject to the NCA's workload and the completeness of the application – is typically measured in months, not weeks. Operators who treat the application as a documentation exercise rather than a substantive compliance build will extend that timeline materially.
Profile B – the operator with an existing EU AML registration seeking to transition. This profile benefits from an existing regulatory relationship but should not assume good standing under the prior regime translates automatically. Each NCA has its own transition guidance. An operator registered with the Bank of Lithuania under the prior VASP regime must demonstrate, in its CASP application, that its compliance program has been upgraded to MiCA standards – including Travel Rule infrastructure, transaction monitoring calibration, and the governance and capital requirements MiCA adds to the prior AML-only baseline. In our practice, we have seen operators assume the transition is administrative; it is not.
Profile C – the offshore-licensed operator with existing EU user flows. This is the most urgent profile. The operator is currently providing services to EU users under a licence that does not satisfy MiCA. The options are stark: cease EU services pending a CASP application, establish a new EU entity and apply, or restructure the product such that the EU-facing offering genuinely qualifies for the reverse-solicitation exemption. The third option is the most frequently chosen and the most frequently mis-executed. A genuine reverse-solicitation exemption requires that the EU client exclusively initiates the relationship, with no advertising, no affiliate flows, and no localised marketing. For most active operators, that standard cannot be met for existing customers.
Profile D – the stablecoin issuer with EU circulation. This profile requires an ART or EMT authorisation analysis before any other step. If the token's characteristics place it in the ART or EMT category under MiCA's classification logic, the issuer must seek authorisation – or withdraw the token from EU circulation. There is no workaround through an offshore issuer entity if the token is marketed, listed, or traded by EU users at meaningful scale. The authorisation path is substantive: it requires a detailed whitepaper, reserve management disclosure, and regulatory capital matched to the significant-token framework if ESMA makes that designation.
Anonymized Case Illustration: Restructuring for MiCA Compliance
In a recent engagement, a payments company operating a crypto-exchange function under a legacy EU AML registration approached us in the second quarter of the transition period, after receiving a supervisory inquiry from its national competent authority. The company had assumed its existing compliance documentation – built originally for the prior VASP regime – satisfied MiCA requirements. It did not. The Travel Rule infrastructure was incomplete, the transaction monitoring system lacked scenario documentation, and the entity's management body did not meet MiCA's governance expectations. We conducted a gap analysis against the CASP authorisation requirements, produced a remediation roadmap, and assisted in upgrading the compliance program to the required standard. The company submitted a CASP application within the NCA's stated transition window and avoided the service interruption that a formal enforcement action would have caused. The matter illustrates a recurring pattern: the cost of a proactive compliance build is substantially lower than the cost of a supervisory-driven remediation.
A Common Assumption: One Offshore Licence Covers Global Operations
A common assumption among operators entering the crypto market is that a well-chosen offshore licence – from the BVI, the Cayman Islands, or a similarly recognised jurisdiction – provides a sufficient regulatory foundation for a globally operating business. The assumption is understandable; these regimes are legitimate, well-designed for specific purposes, and provide genuine regulatory standing in their own markets. But MiCA has made the assumption structurally incorrect for any operator with EU exposure.
The BVI VASP Act 2022 and the Cayman VASP Act establish real regulatory frameworks. CIMA and the BVI FSC are credible supervisors. None of this changes the fact that neither regime confers EU market access, EU passporting rights, or exemption from MiCA's client-location test. An operator relying on an offshore licence to serve EU clients is not in a grey area under MiCA; it is operating without authorisation in the world's largest single market, with the enforcement consequences that implies.
The practical correction is not to abandon offshore structures – they remain valuable for fund entities, treasury management, and holding structures that do not directly face EU clients. It is to layer them correctly: an offshore entity for appropriate group functions, an EU-authorised CASP for client-facing EU services, and allied counsel in each relevant jurisdiction holding the structure to account. We map the licence stack across operating, custody, and payment layers before operators commit capital to a structure that will need to be unwound.
Preparing a MiCA Application: What NCAs Examine
An NCA examining a CASP application under MiCA will focus on five core areas, and operators that treat any one of them as a formality risk delay or refusal.
Governance and management body. MiCA requires that the management body collectively holds the knowledge, skills, and experience to manage the CASP's activities, and that each member individually meets fit-and-proper standards. NCAs examine CVs, prior regulatory history, and the adequacy of the governance structure, not just the nominal appointment of compliant-looking executives. An operator whose senior management has prior regulatory sanctions in any jurisdiction – not only the EU – must address that history head-on in the application.
Compliance program and AML/KYC framework. The application must demonstrate a functioning compliance program, not a drafted one. NCAs expect to see the KYC framework, the transaction monitoring system, the Travel Rule compliance mechanism, and the MLRO appointment already in place. A program that will be built after authorisation is awarded does not meet the standard. In our cross-border practice, we regularly advise clients on the minimum viable compliance build that satisfies the NCA's threshold while remaining proportionate to the business's actual scale.
Own funds and capital. MiCA sets minimum own-funds requirements that vary by licence category and service scope. These figures are set by the regulation; a number that is not in our registry is described qualitatively here as varying by category – operators should consult the current legislative text and NCA guidance for the applicable figure before sizing the balance sheet. What we observe in practice is that NCAs examine not only the nominal capital figure but also the quality of that capital and its segregation from operational funds.
IT and security. MiCA contains specific requirements for IT systems, cybersecurity, and business continuity. NCAs will examine the operator's technology architecture, penetration-testing history, and incident-response procedures. For operators migrating from a lighter-touch registration regime, the IT governance documentation required by MiCA is often the longest single-gap item.
Whitepaper obligations. Where the CASP's activities include offering crypto-assets to the public or seeking admission to trading, a whitepaper in MiCA's prescribed form must be filed with the relevant NCA. The whitepaper is a liability document, not a marketing one; it carries the civil liability of its signatories for materially misleading content. Operators treating whitepaper preparation as a communications task rather than a legal one are creating unintended exposure.
Related at OBOLUS
- AML, KYC and Travel Rule for Digital Asset Businesses – the full compliance practice covering FATF-aligned programs across 70+ jurisdictions
- Travel Rule Compliance Under Heightened Scrutiny – practical analysis of Travel Rule builds for operators facing NCA examination
- VASP Licence Application in South Korea – parallel licensing analysis for operators building an Asia-Pacific complement to an EU structure
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – drawn from FATF Recommendation 15 and implemented with jurisdiction-specific thresholds – requires a VASP (virtual asset service provider) to collect, verify, and transmit originator and beneficiary identification data alongside every qualifying virtual-asset transfer. Under the EU regime applicable to MiCA-authorised CASPs, this obligation applies at transfer, requires counterparty VASP verification, and extends to procedures for transfers involving unhosted wallets. Operators must have a functioning Travel Rule compliance mechanism in place at authorisation, not as a post-licensing build. The specific data threshold varies by jurisdiction and should be confirmed against current NCA guidance.
Who must act as MLRO for a crypto firm?
A MLRO (Money Laundering Reporting Officer) is the senior individual within a regulated firm responsible for receiving internal suspicious-activity reports, making reports to the financial intelligence unit, and maintaining the AML compliance program. MiCA and the underlying EU AML directives require the MLRO to have sufficient seniority, independence, and competence to perform the function effectively. The individual must be approved by the NCA as part of the CASP authorisation. In practice, the MLRO must be a named natural person with verifiable expertise; a policy document alone does not satisfy the requirement. For cross-border structures, NCAs expect the MLRO to be accessible within the EU entity, not offshored to a group compliance function in another jurisdiction.
How do regulators audit crypto AML programs?
NCAs and AML supervisors examine crypto AML programs through a combination of on-site inspection, off-site document review, and thematic sweeps targeting specific risk typologies. Examiners typically request KYC framework documentation, transaction monitoring scenario libraries, alert calibration records, MLRO activity logs, independent audit reports, and Travel Rule compliance evidence. For MiCA-authorised CASPs, ESMA coordinates supervisory convergence across NCAs, meaning examination standards are tightening toward a single EU benchmark. Operators with programs built for lighter-touch regimes should conduct a gap analysis before their first supervisory cycle begins, not in response to an examiner's findings.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before clients commit. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in MiCA authorisation, CASP transition strategy, and cross-border AML compliance program design for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.