A crypto exchange preparing to serve EU customers faces a binary choice: obtain a CASP authorisation (a Crypto-Asset Service Provider licence under the Markets in Crypto-Assets Regulation, or MiCA) in one member state and passport across the bloc, or remain unlicensed and accept the mounting enforcement risk that regulators and correspondent banks now attach to that posture. The cost of the second path – frozen payment rails, de-platformed banking and reputational damage with institutional counterparties – is no longer theoretical. As ESMA tightens supervisory convergence across national competent authorities, the window for legacy "wait and see" positions is closing. This analysis maps the CASP authorisation process across the primary EU member-state venues, examines the cross-border interactions that shape that choice, and provides a decision matrix for operators selecting their licensing base.
What is CASP Authorisation Under MiCA, and Who Needs It?
Under MiCA, any entity wishing to provide crypto-asset services to clients within the EU must hold a valid CASP authorisation – or qualify for a narrow transitional or exemption window. The regime defines crypto-asset services broadly: exchange, brokerage, custody, portfolio management, transfer services, advice, and placement. An operator conducting any of those activities for EU-resident clients requires the licence regardless of where the entity is incorporated. That extraterritorial logic is the first structural point operators misread. Being seated in a third country does not automatically remove EU obligations if the client base is EU-domiciled.
ESMA coordinates supervisory expectations across national competent authorities, but the authorisation decision itself sits at the member-state level. A single CASP authorisation, once granted, carries a passporting right that allows the holder to provide regulated services across all EU and EEA member states without re-authorising in each one. That passporting right is the core commercial value of the licence and the main reason operators invest in the process.
Token issuers face an additional layer. MiCA distinguishes between ordinary crypto-assets, asset-referenced tokens (ARTs – instruments referencing a basket of assets), and e-money tokens (EMTs – instruments referencing a single fiat currency). ART and EMT issuers carry heavier authorisation burdens and are subject to reserve and redemption requirements beyond those applied to standard CASP activities. An exchange listing its own stablecoin may therefore need both a CASP authorisation and a separate issuer approval – a combination that changes the application timeline and the regulatory capital conversation materially.
OBOLUS maps the precise activity perimeter before any application is filed. We regularly advise clients who discover mid-process that a service line they treated as ancillary – such as an in-app swap feature or an earn product – independently triggers a CASP activity category. Identifying that early avoids amendment filings and timeline slippage.
CTA #1 – Early-stage readers
If you are assessing whether your activity model requires a CASP authorisation, the analysis turns on the specific services you provide and where your users are located. The standard path described above applies in most structures. Your entity type, user geography and product design change the analysis at the margin. Map your options with our licensing desk before the activity perimeter is fixed.
Which EU Member States Are the Primary CASP Authorisation Venues?
Not all national competent authorities are equally prepared to process CASP applications at the same pace or with the same depth of prior crypto experience. Lithuania, Malta, Ireland, Germany and the Netherlands have historically been the most active venues for digital-asset firm authorisations in the EU, and that institutional experience carries forward into the MiCA transition.
Lithuania – under the supervision of the Bank of Lithuania – built a significant pipeline of VASP registrations before MiCA's full application. The transition from the prior VASP registration model to the MiCA CASP authorisation standard is active, and firms that held a legacy Lithuanian registration are working through that upgrade process. The Bank of Lithuania has signalled a systematic approach to transitional conversions, but operators should not assume a prior registration maps cleanly to a full CASP authorisation without additional documentary and governance requirements.
Malta's MFSA administered the earlier VFA (Virtual Financial Assets) framework – one of the first bespoke EU crypto regimes – and is now managing the transition of VFA-licensed firms to MiCA CASP status. The MFSA's familiarity with crypto-specific governance questions is an advantage. However, the VFA-to-MiCA conversion process has its own procedural requirements, and firms cannot assume the prior licence passports automatically into MiCA coverage.
Germany (BaFin) and the Netherlands (AFM/DNB) represent more established, higher-scrutiny venues with experienced supervisory teams and correspondingly more detailed application reviews. For larger exchanges or custodians seeking the reputational weight of a major-economy licence, that scrutiny can be an asset. For early-stage or leaner operators, the documentation and governance threshold at those venues is meaningfully higher.
Ireland (CBI) is increasingly relevant given its established track record for financial-services authorisations and English-language process, though its crypto-specific pipeline under MiCA is still developing compared to Lithuania or Malta.
In our cross-border practice, we observe that venue selection is not purely a regulatory question. It is also a banking question. The jurisdiction of licensing shapes the correspondent banking options available to the licensed entity, the AML/KYC framework under which it operates, and the ease with which it can onboard EU institutional counterparties. Those factors often weigh as heavily as the projected authorisation timeline.
How Does the CASP Application Process Work in Practice?
A CASP application under MiCA follows a structured submission process: the applicant files with the national competent authority of the member state in which it is established, the authority conducts a completeness check, and a formal review period follows during which the NCA may request additional information. The authorisation decision must be issued within a defined statutory period – though the practical timeline from first submission to decision varies considerably by venue, application complexity and the volume of applications the NCA is managing at any given time.
The application package itself is extensive. At a minimum, it requires a programme of operations detailing each activity for which authorisation is sought, a governance framework demonstrating fitness and propriety of management and shareholders, an AML/CFT policy aligned to the applicable FATF-derived requirements, a technology and security assessment, a business continuity plan, and a capital adequacy demonstration. For firms with complex structures – holding companies, intra-group service arrangements, third-country affiliates – the disclosure requirements around group structure are particularly detailed.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer, derived from the FATF Recommendation 15 framework) features explicitly in the compliance architecture reviewers examine. An applicant that cannot demonstrate a credible Travel Rule compliance solution at the point of application is likely to face information requests that delay the process. We have seen that gap surface repeatedly in applications where the technology build and the legal process were treated as separate work-streams.
A practical point operators frequently underestimate: the NCA's completeness check is distinct from the substantive review. A file rejected at the completeness stage restarts the clock. Investing in pre-submission quality – including a dry-run review against the authority's published completeness checklist – consistently reduces elapsed time. In our practice, this front-loading is one of the clearest efficiency levers in the process.
For token issuers publishing a crypto-asset whitepaper (the MiCA disclosure document required for public offers or admission to trading), there is a separate notification and review process. The whitepaper must be notified to the NCA before publication. Depending on whether the token qualifies as an ART or EMT, prior approval – not merely notification – may be required. The timeline implications of that distinction are significant and should be mapped before the product launch schedule is set.
How Does a CASP Authorisation Compare to a Third-Country Crypto Licence for Serving EU Clients?
A third-country crypto licence – whether from VARA in Dubai, the FSRA in Abu Dhabi's ADGM, MAS in Singapore, or the SFC in Hong Kong – does not substitute for a MiCA CASP authorisation when serving EU-resident clients. MiCA's third-country provisions are strict: absent a formal equivalence determination by the European Commission, a third-country firm may not actively solicit EU clients for crypto-asset services that fall within the MiCA perimeter. The "reverse solicitation" exception is narrow and fact-specific; it applies only where the client has exclusively and at their own initiative approached the firm. Regulators and ESMA guidance treat manufactured reverse-solicitation structures with scepticism.
That does not make third-country licences irrelevant to an EU-facing operator. On the contrary, the most common structure in our cross-border practice involves a CASP-authorised EU entity operating alongside a separately licensed entity in a Gulf or Asian hub – serving different geographic client segments from the correct regulatory perch in each. The licence stack, not a single licence, is the operative answer for a globally active business. A single offshore licence is not enough to serve clients globally – that assumption is the most reliably costly mistake we encounter.
Comparing the regulatory regimes on the key axes:
Regulatory depth: MiCA is arguably the most systematically detailed crypto-asset regime in force, with full coverage of activities, token issuance and market-abuse rules. VARA and the FSRA in ADGM are activity-based and principle-driven, with evolving rulebooks. MAS under the Payment Services Act is well-developed for DPT services but narrower in perimeter. Each regime has genuine strengths; none is simply a lighter version of another.
Client geography: CASP authorisation is the only credible path for EU retail and institutional client access at scale. VARA and MAS licences are the right instruments for their respective jurisdictions and for servicing global institutional counterparties who require regulatory standing.
Speed and capital: these vary by regime and by the specific activity licence sought. We describe these qualitatively throughout this analysis because the figures are NCA-specific and change with regulatory capacity. Our licensing desk maintains current-cycle intelligence on NCA processing volumes and turnaround expectations.
AML/Travel Rule posture: all flagship regimes – EU, UAE, Singapore, Hong Kong – have implemented or are implementing FATF Recommendation 15 and Travel Rule obligations. The technical standards and de-minimis thresholds vary by jurisdiction; a multi-licensed operator needs a unified Travel Rule solution that satisfies all applicable regimes simultaneously.
In a recent cross-border structuring matter, a custodian and exchange platform operating in the Gulf sought to expand into European institutional clients. We structured the group to seat a new EU CASP applicant alongside the existing VARA-regulated entity, with a shared compliance technology layer covering both regimes' Travel Rule requirements. The dual-licence structure allowed institutional onboarding across both client pools without attempting to stretch either licence beyond its geographic scope. The application process ran concurrently with the VARA renewal cycle, minimising elapsed calendar time.
CTA #2 – Readers who have already started the process
If a prior application stalled, a regional bank declined to open an account for your licensed entity, or you are finding that your current licence does not satisfy EU institutional counterparties, a structural review can identify the gap. A second read of the licence-banking-compliance stack often surfaces the specific point of failure and the route back. Map your options with our regulatory team now.
Decision Matrix: Which Operator Profile Should Choose Which Licensing Approach?
No single answer suits every operator. The right starting point depends on the operator's existing structure, client geography, product mix and timeline constraints. The following matrix describes four common profiles in our cross-border practice.
Profile A – EU-focused retail exchange, no existing licence: the primary instrument is a CASP authorisation in a mid-tier NCA venue with established crypto capacity and reasonable processing timelines. Lithuania and Malta are the two most common starting points for this profile. The key risk is underestimating the governance and AML documentation standard; the most common failure mode is submitting a programme of operations that reads as generic rather than activity-specific. Timeline: the formal review period runs to several months at most NCA venues, with pre-submission preparation adding additional lead time. Capital: varies by activity category; confirm current NCA guidance before committing to a capital structure.
Profile B – Global institutional exchange, dual hub strategy: the primary instruments are a CASP authorisation (EU hub, typically a higher-scrutiny NCA for reputational weight) plus a VARA, FSRA or MAS licence in the relevant non-EU hub. The two applications should run concurrently where possible to compress the overall timeline. The key risk is allowing the two regulatory processes to drift out of sync, creating a window in which one entity is licensed and the other is not – exposing the group to regulatory arbitrage scrutiny. Capital: higher in both venues; plan the group capitalisation before the first filing.
Profile C – Token issuer (non-ART/EMT): a standard CASP authorisation covers the exchange and offering services; the whitepaper notification process runs in parallel. The key risk is misclassifying the token. If the token later attracts ART or EMT characterisation, the issuer faces a retroactive heavier authorisation process and potential enforcement exposure during the gap period. A pre-application token classification opinion is a cost-effective risk mitigation.
Profile D – Custodian only: custody is a defined CASP activity under MiCA. A custodian-only applicant can seek a narrower CASP authorisation limited to safekeeping and administration. Some NCAs permit a phased authorisation strategy – leading with custody and adding further activities later. The key risk is that many institutional clients require the custodian to also hold a CASP authorisation for transfer services; confirm the client requirement set before scoping the initial application.
What Are the Most Common Mistakes in CASP Authorisation Applications?
The most frequent failure mode in a CASP application is an incomplete or mismatched programme of operations. The programme must describe each activity with precision, map it to the MiCA activity definition, and demonstrate that the firm's governance and technology infrastructure is calibrated to that specific activity. A programme that lists activities in MiCA's language but fails to connect them to the actual product architecture will generate information requests and delay the process.
A second recurring issue is inadequate AML/KYC architecture at the point of application. NCAs reviewing CASP applications under MiCA expect to see a written AML/CFT policy, documented customer due-diligence procedures, a named Money Laundering Reporting Officer with appropriate experience, and a credible Travel Rule compliance solution. Firms that treat the AML component as a checkbox rather than a substantive review consistently encounter extended information-request cycles.
A third mistake is the governance gap. MiCA requires that management body members demonstrate sufficient knowledge, skills and experience relevant to the activities of the CASP. NCAs assess fitness and propriety as part of the authorisation review. Nominees who lack demonstrable crypto-relevant experience at an appropriate level of seniority will face challenge. For groups appointing local management nominees in the EU entity, ensuring those nominees have genuine operational involvement – not merely nominal directorship – is a practical prerequisite.
A fourth issue is the banking assumption. Operators frequently assume that a CASP authorisation will automatically unlock EU banking. It does not. Banking access for CASPs remains constrained at many EU banks, and the CASP authorisation is a necessary but not sufficient condition for account opening. Operators who have not pre-engaged with banking partners before the licence issues often find themselves licensed but unable to operate. We map the licence, banking and compliance stack as one integrated mandate – that integration is precisely where the most expensive surprises tend to arise.
Finally, applicants consistently underestimate the timeline. Formal statutory review periods are set, but pre-submission preparation, completeness checks and information-request cycles mean that elapsed calendar time is routinely longer than the headline statutory period suggests. Building a realistic timeline – one that accounts for the full process rather than only the formal review window – is essential for product launch planning.
How Do AML, the Travel Rule and Cross-Border Compliance Obligations Interact Under MiCA?
MiCA sits alongside, not above, the EU's AML framework. A CASP authorisation does not substitute for compliance with the applicable AML/CFT directives and regulations; it requires it. The CASP is subject to customer due-diligence obligations, suspicious-transaction reporting, record-keeping requirements and Travel Rule compliance across all transactions above the applicable threshold.
The Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – applies to EU-regulated CASPs under the Transfer of Funds Regulation as extended to crypto-asset transfers. The practical implementation challenge is significant: the receiving entity must be able to process the data, which requires technical interoperability between the sending and receiving VASP or CASP. For a CASP that also transacts with VASPs in non-EU jurisdictions, the Travel Rule compliance architecture must accommodate multiple regulatory standards simultaneously.
Operators we advise routinely face the challenge of a Travel Rule solution that satisfies the EU standard but is technically incompatible with the VASP's system in the counterparty jurisdiction. This is not a niche edge case. It is the operational reality of multi-jurisdiction digital-asset business. Selecting a Travel Rule solution provider whose protocol covers the major regulatory implementations – EU, FATF, Singapore, UAE – avoids the cost of multiple competing technology integrations.
Cross-border structuring also raises the question of which entity in the group bears the AML obligations for a given transaction. In a dual-licensed structure where an EU CASP and a non-EU VASP both touch a transaction, the applicable AML regime for each is the regime of the entity that holds the customer relationship. Clear contractual and operational delineation of which entity holds which customer relationship is therefore an essential structural design point, not an afterthought.
A Common Assumption: Is a Single Offshore Licence Enough to Serve EU Clients?
A common assumption among operators new to the EU regulatory environment is that a well-regarded offshore licence – from, say, the BVI FSC under the VASP Act 2022, or CIMA in Cayman – provides a workable basis for serving EU clients without a MiCA CASP authorisation. That assumption is incorrect as a matter of EU regulatory law, and it is increasingly costly in practice.
The offshore licence establishes regulatory standing in the issuing jurisdiction. It does not create standing to provide crypto-asset services to EU-resident clients. Under MiCA, national competent authorities are empowered to take enforcement action against unlicensed third-country firms actively marketing to EU clients. ESMA has issued guidance making clear that the reverse-solicitation exception is narrow and will be applied restrictively. Banking correspondents and institutional counterparties in the EU are also increasingly requiring MiCA CASP authorisation – or at least an application in process – as a condition for account access.
The practical consequence is that operators relying on an offshore licence for EU client access are running a time-limited position. The enforcement risk increases as the MiCA transition period closes and NCAs move from guidance to action. Restructuring into a MiCA-compliant posture under enforcement pressure is more expensive, more time-consuming and more reputationally damaging than doing so proactively. We map the licence stack across operating, custody and payment layers before operators commit, precisely to avoid that sequence.
Self-Assessment Checklist for CASP Applicants
Before engaging the formal application process, operators benefit from a structured internal review. The following questions reflect the issues that most consistently determine application readiness in our practice.
First: have you mapped every service line your platform provides against the MiCA activity definitions, and confirmed which definitions apply? Generic activity descriptions are not sufficient. Second: have you classified your token or tokens – including any future issuance plans – against the ART, EMT and other-crypto-asset taxonomy? A classification error discovered post-application is expensive to correct. Third: is your governance structure documented, with clear management-body composition, demonstrated fitness and propriety of nominees, and a clear organisational chart? Fourth: is your AML/CFT policy written, jurisdiction-specific and operational – not a template? Fifth: do you have a Travel Rule compliance solution in place or in procurement, and does it cover both EU and any non-EU jurisdictions you transact with? Sixth: have you pre-engaged with at least one EU banking partner and obtained conditional comfort on account opening? Seventh: do you have a realistic timeline that accounts for pre-submission preparation, completeness review and a potential information-request cycle?
Operators who can answer each of those questions affirmatively are typically in a strong position to file. Those who cannot are better served by addressing the gaps first. Filing with an incomplete or unready file adds calendar time rather than saving it.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – our practice overview covering the full licence-stack process across jurisdictions
- MiCA vs. the UAE Framework: Regulatory Comparison – a direct comparison of CASP authorisation and UAE licensing for globally active operators
- Tax Treatment of Tokens from a Cross-Border Perspective – how the licensing jurisdiction interacts with the token tax analysis for issuers and exchanges
FAQ
How long does a crypto licence take to obtain?
The elapsed time for a CASP authorisation under MiCA varies by national competent authority, the complexity of the application and the volume of applications the authority is managing. Statutory review periods are set, but pre-submission preparation and potential information-request cycles mean total elapsed time is typically measured in months rather than weeks. Venues with established crypto pipelines, such as Lithuania and Malta, have historically processed applications faster than higher-scrutiny venues. A realistic planning timeline should account for the full process, not only the formal review window.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right venue depends on your activity set, client geography, product design, capital position and banking needs. For EU client access, a MiCA CASP authorisation in a member state is the necessary instrument – the choice of which member state turns on processing capacity, the NCA's crypto experience, capital expectations and your banking strategy. For non-EU client access, VARA, FSRA, MAS and SFC each serve their respective markets. Most globally active operators require more than one licence; we map the correct combination before any filing begins.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets is a defined CASP activity. A firm providing only custody may seek a CASP authorisation scoped to that activity. A firm providing custody alongside exchange, brokerage or other services must cover all applicable activities within its authorisation. Some national competent authorities permit a phased authorisation approach, beginning with custody and adding activities in a subsequent variation. Whether a separate custody authorisation is needed also depends on how your group structure allocates the custody function – where custody sits in a multi-entity group, each entity holding the relevant client relationship will need the appropriate authorisation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every licence. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected work-streams – that integration is where the most avoidable costs tend to surface. To discuss your CASP authorisation or licence stack, contact info@oboluslaw.com.
To map the licence, banking and compliance stack for your EU build, write to info@oboluslaw.com or message us via t.me/oboluslaw.
By Lydia Brennan, Tax & Structuring Analyst – cross-border structuring for CASP applicants and multi-licensed digital-asset businesses operating across EU and non-EU regulatory regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.