Operating a digital-asset business without confirming which regulatory regime governs your clients, your entity and your banking is one of the costliest mistakes a founder can make. The consequences are concrete: enforcement actions, frozen payment rails and the loss of banking relationships that took months to build. For businesses asking whether a CASP authorisation (Crypto-Asset Service Provider licence under the EU's Markets in Crypto-Assets Regulation, known as MiCA) can be paired with a Bahamas operational base, the answer requires a precise cross-border analysis — not a shortcut assumption.
MiCA is an EU/EEA regime. The Bahamas is a sovereign offshore jurisdiction with its own digital-assets legislation. These two regimes do not overlap by default. A business that conflates them — or assumes that a Bahamas registration substitutes for MiCA authorisation when serving EU users — faces a serious and avoidable compliance gap. This page sets out the regulated perimeter for each regime, how they interact in practice, and the structural decisions an inbound operator must make before committing to a Bahamas domicile.
Two Distinct Regimes: What MiCA and the Bahamas Each Cover
MiCA authorisation and Bahamas digital-asset registration are separate legal instruments governed by entirely separate regulators — understanding both is the starting point for any sound licensing strategy. MiCA is administered by ESMA and the relevant national competent authority of whichever EU/EEA member state an operator chooses for its CASP authorisation. It regulates the provision of crypto-asset services to clients within the EU/EEA, regardless of where the service provider is incorporated. The Bahamas, by contrast, operates the Digital Assets and Registered Exchanges Act (DARE Act) regime, supervised by the Securities Commission of the Bahamas (SCB).
These regimes address different questions. MiCA asks: are you providing crypto-asset services to EU/EEA clients? The Bahamas DARE Act asks: are you carrying on digital-asset business from within the Bahamas? A business incorporated in the Bahamas that serves EU retail users will almost certainly need a MiCA-compliant CASP authorisation in an EU member state, in addition to — not instead of — its SCB registration. That layered requirement is the point most operators miss.
In our practice, we regularly advise businesses that arrive with a Bahamas structure already in place and a growing EU user base. The structural question is almost always the same: which EU/EEA member state should hold the CASP authorisation, and how does the Bahamas entity sit in relation to that authorised entity?
Who Needs CASP Authorisation Under MiCA?
Any legal entity providing crypto-asset services to clients located in the EU or EEA requires a CASP authorisation under MiCA, issued by a national competent authority in a chosen EU/EEA member state. The services caught are broad: exchange services, order execution, portfolio management, advice, transfer services, custody and administration of crypto-assets on behalf of clients, and the operation of a trading platform. If a Bahamas-incorporated business provides any of these services to EU/EEA users — even remotely, even without a physical EU presence — the MiCA obligation is triggered.
The passporting mechanism is one of MiCA's most significant structural features. A CASP authorised in one member state may passport its services across all EU/EEA member states without a separate local licence in each. That means the strategic choice is not whether to get MiCA authorisation but which jurisdiction to use as the authorisation hub. Lithuania, Malta and several other member states have developed reputations as accessible entry points for crypto businesses seeking EU-wide reach. Each involves different timelines, capital expectations and supervisory styles.
Bahamas-domiciled groups typically structure a separate EU subsidiary to hold the CASP authorisation. That subsidiary is the regulated entity under MiCA. The Bahamas entity may handle non-EU business, institutional flows or treasury functions — but it cannot be the entity holding the EU regulatory permission.
The Bahamas DARE Act: What It Does and Does Not Cover
The Bahamas DARE Act establishes a registration and licensing regime for digital-asset businesses operating from or within the Bahamas, supervised by the Securities Commission of the Bahamas. The regime covers digital-asset exchanges, custodians, broker-dealers and marketplace operators. Registration is required before commencing business; the SCB assesses fit-and-proper criteria, AML/CFT controls and operational standards.
The DARE Act does not grant any form of recognition or passporting into the EU/EEA. Holding an SCB registration tells EU regulators nothing about your compliance with MiCA. Conversely, a MiCA CASP authorisation issued by, say, the Bank of Lithuania does not authorise you to operate a digital-asset exchange from Nassau. These are parallel, non-substitutable permissions.
For operators choosing the Bahamas as their non-EU operational base, the DARE Act framework is well-regarded for its clarity and the SCB's engagement with industry. The jurisdiction offers political stability, a common-law legal system, and proximity to US time zones. It does not offer a path into the EU regulatory perimeter — that path runs exclusively through an EU/EEA national competent authority under MiCA.
For a scoped assessment of your entity structure and which licences apply to your user base, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis materially.
How to Obtain CASP Authorisation in an EU Member State: The Process
Obtaining a MiCA CASP authorisation requires an application to the national competent authority of the chosen EU/EEA member state, typically supported by a local subsidiary, a fit-and-proper management team, an AML/CFT compliance programme, a business plan, capital documentation and — where relevant — a crypto-asset whitepaper. The process is standardised under MiCA's provisions, but each NCA retains discretion over the depth of its assessment and the pace of review.
The application sequence, broadly, is: entity formation in the chosen member state; appointment of a locally resident compliance officer or management body member; preparation of the regulatory application file (business plan, AML/CFT framework, governance documentation, IT security policies, whitepaper if applicable); submission to the NCA; assessment period; and authorisation or rejection with reasons. Timeline varies by NCA. Some process applications within a few months; others take considerably longer. MiCA sets a maximum review period, but NCAs frequently use the full allowance.
Capital requirements also vary by the class of service being provided. Advice and order reception sit at the lower end of the capital spectrum. Operating a trading platform or providing custody services at scale attracts meaningfully higher own-funds requirements. These figures are set in the MiCA regulation itself and should be reviewed against current official ESMA guidance rather than assumed from secondary sources.
For a Bahamas-based group, the practical challenge is governance: MiCA expects the EU subsidiary to have genuine substance. A letterbox entity with no local decision-makers is unlikely to satisfy an NCA's assessment of effective management and control. Operators we advise routinely underestimate the substance requirements — particularly around board composition and the location of senior management.
Cross-Border Tax and Banking: The Stack That Surrounds the Licence
A CASP authorisation is necessary but not sufficient — the banking and tax structure around it will determine whether the business actually functions. Bahamas-incorporated entities benefit from the jurisdiction's tax neutrality on offshore income, but this advantage is eroded if the group's economic substance is demonstrably located in the EU subsidiary. Transfer pricing, the allocation of profits between the EU and Bahamas entities, and the treatment of management fees all require deliberate structuring.
Banking for crypto businesses remains difficult across most jurisdictions. EU subsidiaries holding CASP authorisations can sometimes access EU payment institution accounts, but crypto-specific banking remains selective. The Bahamas entity's banking will depend on its activity type and the correspondent banking relationships available through Bahamian banks — a position that varies year to year and is heavily influenced by the entity's AML posture and client base.
The interaction between the EU MiCA regime and the Bahamas' own AML/CFT obligations — aligned with FATF Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) — means that both entities in the group will carry compliance costs. Designing a group that satisfies both regimes efficiently, rather than running duplicate compliance programmes independently, is one of the clearest sources of structural saving for a multi-entity group.
We have seen businesses spend significantly on licensing only to discover that the banking relationship they assumed was available was conditional on a licence in a different jurisdiction entirely. The licensing decision and the banking decision must be made together.
A Cross-Border Licensing Matter
In a recent licensing mandate, a digital-asset exchange incorporated in the Bahamas had grown its EU retail user base substantially and faced a regulatory review by a European national competent authority. The business had a valid SCB registration but no EU-authorised entity. We mapped the relevant MiCA service categories against the platform's actual activities, identified the optimal EU member state for a CASP application based on timeline and capital calibration, and managed the subsidiary formation and application file in parallel with a revised AML/CFT framework that satisfied both the NCA and the SCB. The platform obtained its CASP authorisation within the expected window and retained its EU user base without interruption to operations.
What Offshore Operators Get Wrong About MiCA Compliance
A common assumption in the offshore licensing market is that a single registration in a well-regarded jurisdiction is sufficient to serve clients globally — including EU clients. This assumption is incorrect and increasingly costly as MiCA enforcement matures. MiCA applies based on where clients are located, not where the service provider is registered. An SCB registration provides no MiCA equivalence.
A second frequent error is conflating VASP registration (an AML/CFT compliance measure) with CASP authorisation (a conduct-of-business permission). In the EU, the two are now integrated under MiCA: a CASP authorisation subsumes the AML registration obligation for the EU entity. But the Bahamas SCB registration addresses Bahamian law, not EU law. Operating EU-facing services on the basis of an offshore VASP registration exposes the business to enforcement by EU regulators — and, increasingly, by payment service providers and banks that now conduct their own MiCA-compliance checks before onboarding crypto clients.
A third mistake is deferring the EU licensing decision until EU user volumes become material. By that point, the business may already be in technical breach of MiCA. The licensing clock should start when the business decides to accept EU users — not after.
If a prior application stalled or your EU access is at risk, a structural review can identify the precise gap and the fastest route to compliance. Contact OBOLUS to discuss.
Decision Matrix: Which Structure Fits Your Profile?
The right structure depends on where revenue is generated, who your clients are and what your operational model looks like. Three broad operator profiles emerge in our cross-border practice.
Profile A — Bahamas-centric, institutional focus: The operator primarily serves institutional clients outside the EU (US, LATAM, Asia) and uses the Bahamas for its tax neutrality, common-law system and SCB oversight. EU retail exposure is minimal or zero. This operator needs the SCB DARE Act registration but may not need MiCA authorisation at all. The risk is scope creep: as EU users grow, the MiCA threshold is crossed without a structure in place to accommodate it.
Profile B — Dual-base operator (Bahamas + EU): The operator wants to serve both EU retail and institutional markets. It maintains the Bahamas entity for non-EU operations and establishes an EU subsidiary — typically in Lithuania, Malta or another accessible member state — to hold the CASP authorisation. The passporting right then covers the full EU/EEA. This is the most common structure for mid-sized exchanges with ambitions across both markets. Governance and substance requirements in the EU entity are the primary execution risk.
Profile C — EU-first, Bahamas as treasury/holding layer: The operator's primary commercial activity is EU-facing. The Bahamas entity is used for holding, treasury or IP ownership. The EU subsidiary holds the CASP authorisation and carries the operational weight. Substance and transfer pricing discipline are critical; this structure requires careful management of the EU entity's independence from the Bahamian parent to satisfy MiCA governance expectations.
Each profile carries different capital obligations, timeline exposures and banking implications. None of them is inherently superior — the choice turns on the actual facts of the business.
When to Engage Counsel on CASP Authorisation
The earlier the better — and specifically before committing to a corporate structure that cannot easily be unwound. The most expensive licensing engagements we handle are those where a business has already formed a Bahamas entity, opened banking and built a compliance programme around the wrong regulatory assumption. Restructuring after the fact costs more in time, money and regulatory goodwill than getting the structure right at the outset.
The inflection points that typically bring operators to us are: a decision to accept EU users; a banking or payment-provider request for a MiCA licence as a condition of onboarding; a regulatory enquiry from an EU national competent authority; or a pending fundraising round in which institutional investors have flagged the licensing gap as a condition of closing.
In each case, the first step is a licensing map — a documented analysis of which services are being provided, to whom, from where, and which regulatory permissions those activities require across every relevant jurisdiction. That map is the foundation on which the application strategy, entity structure, banking relationships and compliance programme are built.
Regulators in the leading hubs increasingly expect applicants to arrive with a clear and coherent narrative of their business model. An application file that does not explain the cross-border structure — the relationship between the EU entity and the Bahamas parent — will attract questions. Anticipating those questions before submission is the difference between a clean process and a protracted review.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we structure multi-jurisdiction licence stacks for exchanges, custodians and token issuers
- VASP Licence Application in Australia – AUSTRAC – AUSTRAC registration requirements and process for inbound digital-asset operators
- Smart Contract Dispute Resolution for Early-Stage Founders – on-chain dispute resolution options and the legal remedies available when smart contracts go wrong
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and licence type. A MiCA CASP authorisation in an EU member state can take anywhere from a few months to well over a year depending on the chosen national competent authority, the completeness of the application file and the complexity of the business model. Bahamas SCB registration under the DARE Act typically moves faster. In our cross-border practice, we build timeline projections from the NCA's published expectations and recent market experience rather than from generic estimates.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The right jurisdiction depends on your user base geography, the services you provide, the capital you can deploy, your banking requirements and your growth plans. A business serving EU retail clients needs a MiCA CASP authorisation regardless of where it is incorporated. For the offshore operational layer, the Bahamas offers real advantages — but only if the global licensing stack is designed correctly around it. We map the full stack before making a recommendation.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated service that requires inclusion within a CASP authorisation. If custody is a separate business line or operated through a distinct entity, that entity needs its own authorisation. The Bahamas DARE Act similarly treats custody as a regulated activity requiring SCB registration. A group running custody and exchange services through separate subsidiaries must ensure both entities hold the correct permissions in every jurisdiction where they operate.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit — structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in cross-border CASP and VASP authorisation strategy for digital-asset businesses operating across EU and offshore hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.