EST · MMXXVI
Home/Insights/Tax/CASP authorisation under mica: Where the Legal Lines Are Drawn
Licensing & Registration

CASP authorisation under mica: Where the Legal Lines Are Drawn

Casp authorisation under mica: Where the Legal Lines Are Drawn. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Tal

CASP Authorisation Under MiCA: Where the Legal Lines Are Drawn

Operating a crypto-asset service provider (CASP) business in or into the European Union without MiCA (the Markets in Crypto-Assets Regulation) authorisation is not a calculated risk – it is a structural failure waiting to surface. Enforcement action, frozen payment rails and lost correspondent banking are the documented consequences regulators across the EU are increasingly prepared to impose. With ESMA and national competent authorities (NCAs) tightening their supervisory posture as MiCA's full application date has passed, the question for any digital-asset business touching EU clients is no longer whether to comply but how to structure the authorisation stack before the window closes.

This analysis maps the legal perimeter of CASP authorisation under MiCA, dissects where the regulatory lines actually fall, and addresses the cross-border complexity that most legal summaries understate. It is written for general counsel, founders and CFOs who already understand crypto mechanics and need the legal answer.

Who Needs CASP Authorisation – and Who Is Surprised to Learn They Do?

Any entity providing regulated crypto-asset services on a professional basis to clients within the EU requires a CASP authorisation granted by the relevant NCA – or it must passport an existing authorisation from another member state. The regime covers a defined list of activities: custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for funds or for other crypto-assets, execution of orders, placing of crypto-assets, reception and transmission of orders, portfolio management, advice, and transfer services. The breadth of that list is where operators consistently underestimate their exposure.

A token issuer that also manages client wallets post-issuance is providing custody services. A DeFi front-end that routes orders to an underlying protocol may be caught as an order-reception and transmission service. A non-EU exchange with EU resident clients – regardless of where the entity is domiciled – triggers the territorial scope provisions. In our cross-border practice, we regularly advise businesses that assumed their offshore structure placed them beyond MiCA's reach, only to discover that the client-location test is the primary axis, not the entity-registration test.

The exemptions are narrow. Truly decentralised protocols with no intermediary, issuers making their tokens available without ongoing service provision, and certain intra-group transactions may fall outside the perimeter. Each exemption requires a fact-specific analysis. A label does not confer the exemption; the economic substance of the activity does.

The process above describes the standard perimeter analysis. Your facts – the entity structure, the user base, the service layer – change the analysis materially. For a scoped assessment of where your business sits relative to the CASP perimeter, contact OBOLUS at Map your options.

The Three Token Regimes: Why Classification Changes Everything

MiCA establishes three distinct regulatory tracks, and misclassifying a token at the outset creates cascading downstream problems for the CASP authorisation itself. The first track covers asset-referenced tokens (ARTs) – tokens that maintain a stable value by referencing multiple currencies, commodities or crypto-assets. The second covers e-money tokens (EMTs) – tokens pegged to a single fiat currency and functioning as a digital analogue of e-money. The third is the residual category: all other crypto-assets not qualifying as ARTs, EMTs or financial instruments under existing EU law.

Why does this matter for CASP authorisation? Because the obligations imposed on the CASP differ by the type of asset it handles. An entity providing custody or exchange services for ARTs faces issuer-interaction requirements and reserve-related disclosure obligations that do not apply to a CASP handling only residual crypto-assets. An EMT, meanwhile, may only be issued by a credit institution or an e-money institution – a constraint that affects the custody and exchange services layered on top of it.

The classification question is also the entry point for the financial-instrument boundary. If a token confers rights equivalent to a transferable security – profit participation, voting, or a debt claim – it may fall under MiFID II rather than MiCA. ESMA has published guidance on the test, but its application to hybrid tokens remains genuinely contested. We have seen businesses structure token features in good faith, only to have a competent authority take a different view during the pre-application phase. That reclassification delays the entire licensing timeline and, in some cases, requires a separate MiFID authorisation.

The practical lesson: classification is not a whitepaper disclosure exercise. It is a legal opinion that underpins every subsequent regulatory decision – the applicable authorisation track, the capital requirements, the disclosure regime and the ongoing compliance obligations. It must be resolved before the application is filed, not during it.

How Does MiCA's Passporting Mechanism Work in Practice?

MiCA's passporting regime is one of its most commercially significant features. A CASP authorised in one EU member state may provide services across the entire EU and EEA without separate authorisation in each target market, subject to a notification procedure. This creates a genuine single-market opportunity that has no equivalent in the prior fragmented VASP-registration environment.

The mechanics require the CASP to notify its home-state NCA of its intention to provide services in another member state, specifying the services and the jurisdictions. The home NCA then notifies the host-state NCA. The CASP may commence services in the host state after the notification period has elapsed – or earlier if the home NCA confirms the notification has been transmitted. Host-state NCAs retain supervisory powers over conduct rules and AML/CFT compliance in their territory, even after passporting.

In practice, the choice of home-state NCA is a material commercial decision, not an administrative formality. NCAs differ in their processing pace, the depth of their pre-application engagement, their approach to novel business models, and their institutional familiarity with crypto-asset services. An NCA that has reviewed hundreds of CASP applications approaches a custody-plus-exchange model differently from one encountering it for the first time. In our cross-border practice, we advise clients to assess NCA temperament alongside capital and fee considerations when selecting the authorisation domicile.

The passporting mechanism does not eliminate host-state risk. If the CASP establishes a branch in a host state – rather than providing services on a cross-border basis – the branch is subject to additional notification requirements and the host NCA's oversight of the branch's operations. The distinction between cross-border service provision and the establishment of a branch is a fact-specific question that regulators in the leading hubs are scrutinising closely.

What Are the Practical Steps in a CASP Authorisation Application?

A CASP authorisation application under MiCA is a substantive regulatory submission, not a registration form. The application must demonstrate governance, capital, operational resilience, AML/CFT controls, safeguarding arrangements and a compliant service description – across every regulated activity for which authorisation is sought. Underestimating the documentation burden is the single most common cause of delay in the applications we have reviewed.

The process, at a high level, unfolds in four phases. First, pre-application engagement: most NCAs expect – and in some cases require – a meeting or structured pre-submission exchange before the formal file is lodged. This is the moment to surface classification questions, governance gaps and any business-model features that require bespoke regulatory treatment. Second, formal submission: the application package typically includes the programme of operations, the business plan, the governance structure, the internal control framework, the AML/CFT policies, the safeguarding documentation and the personal questionnaires for key persons. Third, NCA assessment: the NCA reviews the file, issues requests for additional information and, where required, convenes meetings with management. Fourth, decision: authorisation, refusal or conditional authorisation with remediation conditions attached.

Timeline varies by NCA and by the complexity of the business model. MiCA sets maximum assessment periods, but the clock typically stops – sometimes repeatedly – while the NCA awaits responses to information requests. An application with unresolved classification issues or governance gaps can extend well beyond the statutory maximum. Operators that have engaged pre-application and resolved the hard questions before submission consistently achieve faster decisions. Those that treat the pre-application phase as optional consistently do not.

If a prior application stalled or an account was closed, a second structural read can surface the underlying reason and the route forward. Write to OBOLUS at Map your options.

The Cross-Border Reality: Where MiCA's Perimeter Meets Third-Country Operators

MiCA's treatment of third-country firms – entities incorporated outside the EU seeking to serve EU clients – is one of the regime's most consequential and least-discussed dimensions. The general position is clear: third-country firms may not provide CASP services to EU clients on a solicitation basis without authorisation. The reverse-solicitation carve-out is narrow and heavily conditioned; it applies only where the EU client initiates the approach entirely on its own initiative, and it does not permit the firm to market or solicit in the EU.

For a business sitting between, say, a Dubai-licensed entity and an EU client base, the legal question turns on the substance of the client relationship and how that relationship was initiated. A VARA-licensed exchange in Dubai operating a geo-fenced platform with no EU-directed marketing is in a materially different position from one that maintains EU-language websites, onboards EU nationals and processes EUR transfers. ESMA's guidance on the reverse-solicitation exception makes clear that regulators will look through form to economic substance.

This creates a specific structuring problem for multi-jurisdictional operators. A group with a UAE operating entity, a BVI holding company and a Lithuanian VASP registration – a structure common in the 2021–2023 period – may find that none of its existing licences satisfies the post-MiCA EU requirement. The Lithuanian registration, issued under the prior AML-only VASP regime, does not constitute a MiCA CASP authorisation. The transition provisions granted existing EU-registered VASPs a runway to seek CASP authorisation, but that runway is not indefinite.

Allied counsel in the relevant jurisdiction can map the interaction between a home-country licence and the MiCA passporting requirement. In our practice, we map the full licence stack – the operating layer, the custody layer, the payment layer – before recommending a jurisdictional home for the CASP authorisation, because the choice of NCA affects the speed, the cost and the regulatory relationship for the life of the licence.

Common Mistakes Operators Make Before and During CASP Authorisation

The most damaging mistakes in a CASP authorisation process are made before the application is filed. By the time they surface during NCA review, they are significantly harder and more expensive to remedy.

The first is token misclassification. An issuer that characterised its token as a utility token for whitepaper purposes, without a formal legal opinion, may face reclassification by the NCA as an ART or a financial instrument during the CASP application review. The downstream consequences – revised capital requirements, issuer authorisation obligations, or an entirely different regulatory track – can derail an application that was otherwise well-prepared.

The second is governance structure that does not satisfy the fit and proper standard for key persons. MiCA imposes substantive requirements on the management body of a CASP – experience, time commitment, independence and the absence of disqualifying factors. A structure built for operational convenience, with nominee directors and absent management, will not pass scrutiny. NCAs interview key persons and assess the substance behind the governance chart.

The third is inadequate safeguarding documentation. A CASP holding client crypto-assets must demonstrate that client assets are segregated, that the safeguarding model is resilient to insolvency and that the operational controls supporting segregation are documented and auditable. Vague commitments to segregation without operational substance will generate information requests – and delay.

The fourth is the AML/CFT programme. The Travel Rule – the obligation to pass originator and beneficiary data alongside a transfer – applies to CASPs under both MiCA and the applicable EU Transfer of Funds Regulation provisions. An AML programme that does not address Travel Rule compliance, virtual-asset-specific risk factors and transaction monitoring at the level NCAs now expect will be returned for revision. We have seen applications that were substantively complete in every other respect delayed by AML programmes drafted to a prior-generation standard.

Decision Matrix: Which CASP Profile Should Choose Which Authorisation Path?

Not every digital-asset business faces the same CASP authorisation calculus. The right approach depends on the operator's activity scope, geographic footprint, capital base and growth timeline. A single-activity CASP – for example, a custody-only provider with a defined EU institutional client base – presents a simpler authorisation case than a multi-activity exchange offering custody, trading and portfolio management across all EU member states.

Profile A is the EU-native start-up seeking full-scope CASP authorisation from inception. The right strategy here is early NCA selection – choosing a home NCA with demonstrated crypto-asset experience and a clear pre-application process – followed by an application that resolves token classification, governance and AML before submission. The risk at this profile is under-investment in the pre-application phase, which extends the timeline and may result in conditional authorisation with remediation conditions.

Profile B is the non-EU operator with an existing VARA, MAS or FSRA licence, seeking to add EU access via CASP authorisation. This operator typically has developed governance infrastructure and AML controls – but those controls were built to a different standard. Mapping the gap between, for example, the VARA rulebook and MiCA's CASP requirements is a structured exercise. The risk at this profile is assuming that an existing robust licence translates directly. It does not. Capital adequacy, safeguarding, key-person governance and the Travel Rule implementation may all require adjustment.

Profile C is the EU VASP holding a transitional registration from the pre-MiCA period. This operator benefits from a transitional runway but faces a hard deadline. The risk is treating the transition period as an extension of business as usual rather than as a window to file a complete CASP application. NCAs are not required to grant authorisation to transitional registrants; the application is assessed on its merits.

Profile D is the group with a complex multi-entity structure – an operating entity in one jurisdiction, a custody entity in another and a payment processing entity in a third. This profile requires a licence-stack analysis before any individual application is filed. Adding a CASP authorisation to a group structure without mapping the interactions between MiCA, the applicable payment-services regime and the custody framework can create regulatory gaps that are harder to close after the fact.

In each profile, the cross-border angle is not optional context. It is the central variable that determines which NCA to approach, which activities to include in scope and how to structure the group for ongoing supervision.

A Note on AML, FATF and the Travel Rule Under MiCA's CASP Regime

MiCA does not operate as a standalone regime. It sits alongside the EU's AML/CFT framework, the Transfer of Funds Regulation and the FATF Recommendations – specifically Recommendation 15, which extends AML obligations to virtual asset service providers. For CASP authorisation purposes, demonstrating AML/CFT compliance is not a box-ticking exercise; it is a substantive component of the application that NCAs assess with increasing granularity.

The Travel Rule is the provision that most frequently catches operators unprepared. Under the applicable EU Transfer of Funds Regulation provisions, CASPs must collect and transmit originator and beneficiary information alongside every qualifying transfer. The practical challenge is that many transfers involve unhosted wallets or counterpart VASPs in jurisdictions that have not yet implemented Travel Rule standards. NCAs expect CASPs to have a documented policy for handling these scenarios – not a commitment to develop one post-authorisation.

FATF's evolving guidance on virtual assets, updated periodically, informs how NCAs interpret their domestic AML/CFT rules in the crypto-asset context. A CASP that monitors its AML obligations against the FATF framework – including the risk-based approach, the virtual-asset-specific risk factors and the controls for high-risk counterparties – is better positioned in the NCA assessment than one that applies a generic financial-services AML template to a crypto-asset business.

In a recent authorisation-support matter, a payments company holding a transitional EU VASP registration engaged us to prepare its CASP application in advance of the transition deadline. The AML programme required a complete rebuild: the existing policies did not address Travel Rule counterparty scenarios, virtual-asset-specific risk factors or the transaction monitoring parameters NCAs in the relevant jurisdiction had indicated they would test. We rebuilt the programme, conducted a gap analysis against the applicable FATF guidance and resubmitted to the NCA with a significantly stronger file. The application proceeded to the assessment phase without an AML-related information request – a material difference in timeline.

The Objection: "A Single Offshore Licence Is Enough"

A common assumption among digital-asset operators is that a well-regarded offshore registration – in the Cayman Islands, the BVI or a similar jurisdiction – satisfies the licensing requirement for global operations. It does not. The Cayman Islands Monetary Authority (CIMA) and the BVI Financial Services Commission each administer VASP registration regimes that confer legitimacy within their own jurisdictions and provide a degree of institutional credibility. Neither regime confers the right to provide services to EU clients under MiCA, to hold a US money-transmitter licence or to access correspondent banking in jurisdictions that require local licensing as a condition of banking relationship.

The offshore-only structure was a workable model in a pre-MiCA, pre-Travel-Rule environment. It is increasingly untenable. Payment rails that previously accommodated offshore-licensed crypto businesses are withdrawing access as banking compliance teams apply stricter scrutiny to client licensing status. EU banks and payment institutions that process EUR transfers for crypto businesses are themselves subject to MiCA's AML perimeter and are increasingly unwilling to service unlicensed CASPs or entities with only an offshore registration.

The practical consequence is that a business operating on an offshore-only licence faces compounding risk: regulatory exposure in the markets it is actually serving, deteriorating banking access and a competitive disadvantage relative to MiCA-authorised peers that can demonstrate regulatory status to institutional counterparties. The licensing decision is not merely a compliance question. It is a commercial sustainability question.

We map the licence, banking and tax stack for your build before you commit to a structure. To begin that analysis, write to OBOLUS at Map your options.

When to Engage Counsel on CASP Authorisation

The answer is earlier than most operators do. By the time an NCA issues a formal information request or a bank withdraws access, the cost of addressing structural deficiencies has multiplied. The pre-application phase – before a file is lodged – is the highest-leverage point for legal input.

Specifically, counsel should be engaged at three moments. First, at the token-design stage, before the whitepaper is finalised and before the token's features are fixed. Classification at this stage is still malleable; after public issuance, it is not. Second, at the entity-structuring stage, before the group architecture is established. The choice of holding jurisdiction, operating entity and custody arrangement has direct consequences for the CASP authorisation path, the capital treatment and the supervisory relationship. Third, before the NCA is approached, whether for pre-application engagement or formal submission. The pre-application meeting with a well-prepared file sets the tone of the regulatory relationship; an underprepared meeting can disadvantage an application before it is formally filed.

We regularly advise businesses across all three stages. The engagement model is a scoped, fixed-fee analysis at each stage – not an open-ended retainer – so the client knows exactly what the assessment covers and what the output is before committing.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the NCA has a statutory maximum period to assess a CASP application, but the clock pauses each time the NCA issues an information request – which can happen multiple times. In practice, timeline depends heavily on the complexity of the business model, the quality of the application file and the pace of the chosen NCA. A well-prepared, complete application to an NCA experienced in crypto-asset services proceeds materially faster than an incomplete one. Operators should plan for a process measured in months, not weeks, and engage pre-application to minimise information-request cycles.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on your target markets, service scope, capital base and banking requirements. Within the EU, the home-NCA choice under MiCA determines your passporting route and your supervisory relationship. For non-EU operators, regimes such as VARA in Dubai, MAS in Singapore or FSRA in Abu Dhabi offer alternatives – but none substitutes for CASP authorisation where EU clients are being served. We advise clients to assess the full licence stack – operating, custody and payment – before selecting a domicile.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated CASP activity. A business that holds client crypto-assets – even incidentally to another service – must be authorised for that activity or must engage an authorised sub-custodian. In some jurisdictions outside the EU, custody is separately licensed. In the AIFC, for example, the AFSA applies specific custody authorisation requirements. Whether a separate custody authorisation is required depends on the structure of the service and the applicable regime – a question that must be resolved at the design stage.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is the one that survives regulatory scrutiny. To discuss your situation, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border licensing structure, token classification and the tax and regulatory stack for EU and multi-jurisdictional CASP authorisation mandates.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours