CASP Authorisation under MiCA in Bermuda
A digital-asset business domiciled in Bermuda and serving European users faces a structural question that no single offshore registration can answer: does operating into the EU require a CASP (Crypto-Asset Service Provider) authorisation under the MiCA (Markets in Crypto-Assets Regulation) regime, and if so, what does Bermuda's own licensing framework contribute to that stack? The answer turns on where your users sit, not where your server or company is incorporated. For operators building from Bermuda toward European markets, that distinction carries real regulatory and commercial weight.
MiCA, administered by ESMA (the European Securities and Markets Authority) and national competent authorities across EU member states, imposes a mandatory CASP authorisation requirement on any business providing crypto-asset services to EU clients on a professional basis. Bermuda's own Digital Asset Business Act (DABA) regime – supervised by the Bermuda Monetary Authority – addresses local and international activity from an island domicile, but it does not substitute for MiCA authorisation when EU users are in scope. The two regimes operate in parallel, not in succession.
This page maps the intersection: what MiCA demands of an inbound business, how Bermuda's regulatory posture interacts with that demand, and where the structural decisions lie for an operator choosing Bermuda as a domicile while serving European markets.
What Is Bermuda's Regulatory Posture for Digital-Asset Businesses?
Bermuda licenses digital-asset businesses under the Digital Asset Business Act, with the Bermuda Monetary Authority acting as supervisor – making it one of the few offshore jurisdictions with a purpose-built statutory regime rather than a general financial-services overlay. The DABA regime covers exchange, custody, issuance, payment and related digital-asset activities, and it applies to businesses incorporated in or operating from Bermuda. For operators structuring from the island, DABA authorisation establishes a regulated baseline: AML/CFT controls, capital requirements and ongoing supervisory engagement with the BMA are standard expectations of the licence.
That baseline matters for banking and correspondent relationships. In our cross-border practice, we have seen Bermuda-licensed entities access banking infrastructure more readily than their unlicensed peers, because institutional counterparties treat BMA authorisation as a credible compliance signal. The DABA regime also incorporates FATF Recommendation 15 obligations – including the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) – aligning Bermuda's AML posture broadly with the standards EU counterparties expect.
What DABA does not do is extend EU market access. Bermuda is a third country for MiCA purposes. A DABA-licensed firm serving EU retail or professional clients at scale must address the EU leg of its business separately.
What Does MiCA Require of an Inbound Business from Bermuda?
MiCA's CASP authorisation requirement applies when a business provides regulated crypto-asset services to persons located in the EU, regardless of where that business is incorporated. The regulated activities span exchange services, custody and administration, transfer services, trading platform operation, portfolio management, advice, and order reception and transmission. A Bermuda-based exchange routing order flow from EU clients falls squarely within that perimeter; the BMA licence does not constitute an exemption.
ESMA coordinates the framework at the EU level, but the authorisation itself is granted by a national competent authority – meaning the operator must select an EU or EEA member state in which to establish the entity that holds the CASP licence. That entity then benefits from MiCA passporting: a CASP authorised in one member state may passport across the EU/EEA without separate authorisation in each. This is the structural logic that makes EU-market entry viable at scale.
The authorisation process requires a legal entity in the chosen member state, a formal application to the relevant NCA, a detailed programme of operations covering each regulated activity, governance and management arrangements, capital and own-funds documentation, an AML/CFT framework, and – where applicable – white-paper compliance for the crypto-assets the business deals in. Timelines are set by the MiCA provisions and vary in practice by NCA workload, application completeness and the complexity of the service model. Operators we advise typically budget several months from formal submission to decision, with pre-application engagement extending that horizon.
CTA: The process above describes the standard path. Your facts – the entity structure, the user base geography and the Bermuda corporate layer – change the analysis materially. Map your options with OBOLUS.
How Does the Bermuda-MiCA Structure Actually Work?
Operators based in Bermuda pursuing EU market access typically face a binary structural decision: establish a dedicated EU-licensed CASP subsidiary, or restructure the existing group so that the EU-facing entity sits in a MiCA-compliant member state while the Bermuda entity serves non-EU markets. Both models are workable; the right choice turns on where the business generates most of its revenue, the complexity of the existing corporate stack, and the operator's appetite for dual regulatory engagement.
In the first model – a dedicated EU subsidiary – the Bermuda parent retains its DABA licence and continues to operate outside the EU. The EU subsidiary, typically in a member state with an accessible NCA and established crypto-supervisory capacity, applies for CASP authorisation independently. Intercompany arrangements (technology services, compliance outsourcing, capital support) require careful structuring to satisfy the NCA that the EU entity has genuine substance and is not merely a shell referencing offshore infrastructure.
In the second model – restructuring the group's licensing geography – the question is whether Bermuda continues to serve any regulated purpose in the post-MiCA architecture. For businesses primarily serving EU clients, the answer is sometimes no: the Bermuda entity becomes a holding structure while operational licensing migrates to the EU. In our cross-border practice, we have seen both outcomes. The decision is commercial as much as it is legal.
A third route – reverse engineering EU access through a third-country equivalence or mutual-recognition mechanism – is not currently available under MiCA for Bermuda. MiCA's third-country provisions are limited in scope, and no equivalence decision covering Bermuda has been made. Operators should not plan around that route without explicit regulatory guidance.
What Does the CASP Application Process Involve in Practice?
A CASP application under MiCA follows a structured process set by the applicable regulatory provisions, with the NCA of the chosen member state as the decision-maker. The practical sequence unfolds across several distinct phases, and getting the pre-application phase right materially affects the timeline and outcome of the formal submission.
The first phase is jurisdictional selection and entity establishment. The choice of member state affects not only the application itself but the supervisory relationship going forward, the local substance requirements and the banking environment. Lithuania, Malta and several other member states have supervised VASP populations through their pre-MiCA regimes; their NCAs have institutional familiarity with crypto-service providers. Pre-application engagement – a scoping meeting with the NCA before submitting a full application – is expected or strongly encouraged in most member states and should be built into the project timeline.
The second phase is document preparation. The application package includes a programme of operations, financial projections, IT security and business-continuity documentation, AML/CFT policies and procedures, governance arrangements (including fit-and-proper assessments of management and shareholders), and – where the business operates as a trading platform or issues its own tokens – whitepaper documentation. For a Bermuda-based operator, the group structure chart and the intercompany arrangements also require disclosure and explanation.
The third phase is the formal review period. MiCA sets a review period that begins from the date the NCA confirms the application is complete. In practice, completeness checks add time before the clock starts. NCAs may issue requests for information during the review period, each of which pauses and restarts the clock. Operators that have not resolved their corporate structure, management team or AML framework before submitting routinely experience extended timelines.
The fourth phase is authorisation and passporting. Once the NCA grants CASP authorisation, the entity must notify ESMA and the NCAs of each member state it intends to operate in. Passporting is largely administrative after authorisation, but it is not automatic without the notification step.
How Does the Cross-Border Tax and Banking Layer Interact?
A Bermuda parent with an EU-licensed CASP subsidiary creates a cross-border corporate structure that has tax, banking and compliance dimensions beyond the regulatory authorisation itself. Each layer deserves independent analysis before the structure is committed.
On the tax side, Bermuda's well-known position as a low-tax domicile does not automatically insulate group profits from EU tax exposure. Where the EU subsidiary is genuinely operational and staff and decision-making are located there, local corporate tax in the member state of authorisation applies to that entity's profits. Transfer pricing rules govern intercompany arrangements – technology fees, compliance services, management charges – and NCAs increasingly expect that the EU entity's cost base reflects genuine local substance rather than paper arrangements. EU member states that are actively developing their CASP supervisory frameworks also apply their own economic-substance expectations.
On the banking side, the EU-licensed CASP subsidiary will require banking in the member state of authorisation or in a jurisdiction with correspondent coverage of that market. Bermuda-based operators sometimes assume that their existing banking relationships will extend to the EU entity; in practice, EU institutional banking for crypto-licensed entities requires its own onboarding process, and the timeline for that process should be built into the project plan rather than treated as an afterthought. We have seen deals delayed by weeks because banking was not addressed in parallel with the licence application.
AML compliance runs across both entities. The Travel Rule applies in the EU under the applicable provisions of the MiCA and associated regulatory frameworks; the BMA's Travel Rule expectations apply in Bermuda. An operator with entities in both jurisdictions needs a unified transaction-monitoring and data-passing architecture that satisfies both supervisors simultaneously. This is an area where infrastructure decisions made at the Bermuda level directly affect compliance posture in the EU.
CTA: If a prior application stalled, or if your banking or tax structure has not been mapped against the EU entity's requirements, a second read of the structure can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com.
What Are the Most Common Structural Mistakes for Bermuda-Based Operators?
The most persistent mistake we see is treating the Bermuda DABA licence as a global regulatory solution when the business has already outgrown its original geographic scope. An operator that began serving a non-EU user base and gradually acquired EU clients may be operating into the EU on an unlicensed basis without having made a deliberate decision to do so. By the time the question surfaces – often during a banking review or an investor due-diligence process – the unlicensed period may extend back months or years. Remediating that position is significantly more complex than addressing it before EU operations begin.
A second common error is underestimating the substance requirements attached to the EU CASP entity. NCA reviewers are attentive to arrangements where the EU entity has authorisation but the real business – technology, compliance, key personnel – sits entirely offshore. The MiCA provisions and their associated guidelines set minimum expectations for management presence and operational decision-making within the authorised entity. An application that cannot credibly demonstrate those arrangements will not succeed, regardless of the quality of the Bermuda structure.
A third mistake is sequential planning: addressing the CASP application first and the tax and banking questions later. The three workstreams interact. The choice of member state for authorisation affects corporate tax exposure in the EU. The banking environment in that member state affects the speed of operational launch. The intercompany arrangements affect both the substance assessment and the transfer-pricing position. Separating them creates gaps that cost time and money to close.
A Cross-Border Licensing Mandate in Practice
In a recent mandate, a digital-asset exchange incorporated in Bermuda under the DABA regime sought to expand into EU retail markets following a period of growth in non-EU jurisdictions. The group had a strong BMA-supervisory record but no EU legal presence. We mapped the group structure against MiCA's CASP perimeter, identified the EU activities already in scope, and advised on the selection of a member state for the EU entity. Working alongside allied counsel in the chosen jurisdiction, we coordinated the pre-application engagement with the national competent authority, structured the intercompany arrangements to address substance expectations, and ran the banking onboarding process in parallel with the formal application. Authorisation was achieved within the operator's target window, and the entity passported into the additional member states in the operator's commercial plan within weeks of the initial grant.
Which Bermuda-Based Operator Profile Should Choose Which Approach?
Not every Bermuda-based crypto business needs a EU CASP licence, and not every operator that needs one should pursue the same structural route. The decision turns on a small number of commercial and regulatory variables.
An operator whose EU user base is incidental – a small share of overall revenue, no active marketing into the EU – may be able to implement geo-blocking and traffic controls that keep EU persons outside the CASP perimeter, at least while the business matures. That position requires ongoing monitoring and legal review as the business grows. It is a deferral, not a solution.
An operator with meaningful EU revenue and institutional counterparties – prime brokers, custodians, payment processors – who require regulatory documentation will need a CASP authorisation. For that operator, the decision is which member state and which structural model. A smaller business, or one that is primarily exchange-focused, may find that a single EU entity with passporting coverage meets the full commercial need. A larger or more complex operator – one offering custody, lending and advisory services across multiple product lines – may need to consider whether a single CASP entity can hold all regulated activities or whether a multi-entity EU structure is required.
An operator that is primarily non-EU in focus but has EU institutional investors – a fund or a lending platform, for instance – will need legal analysis of whether the investor-facing activity triggers CASP obligations or falls under other EU financial-services regimes. MiCA is not the only relevant regime for all digital-asset activities; MiFID II and AIFMD may also apply depending on the product structure.
In every case, the Bermuda DABA licence remains relevant: it is a credible, purpose-built authorisation that supports banking, institutional relationships and FATF-compliant AML infrastructure. The question is never whether to abandon it but whether to complement it with EU authorisation as the business grows.
Is a Single Offshore Licence Enough to Serve Clients Globally?
A common assumption among early-stage operators is that a well-regarded offshore licence – Bermuda, the BVI or the Cayman Islands – covers the global regulatory position for the business. It does not. MiCA's CASP authorisation requirement applies based on where your users are located, not where your company is incorporated. The same is true in Singapore under the Payment Services Act, in Hong Kong under the SFC's VASP licensing regime, and in the United Kingdom under the FCA's financial-promotion and registration rules. Each jurisdiction with a developed digital-asset regulatory regime has its own access conditions for inbound operators.
A Bermuda DABA licence is a strong foundation for a non-EU, non-Asia-Pacific business. It is not a passport into those markets. Operators that treat it as one expose themselves to enforcement risk, banking termination and investor-relations difficulty when the gap is identified. In our cross-border practice, we map the licence stack across operating, custody and payment layers before operators commit to a structure, precisely because the cost of correction after the fact consistently exceeds the cost of getting it right at the outset.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full spectrum of CASP, VASP and exchange licensing across 70+ jurisdictions
- VARA Licence Application in Singapore – how the MAS Payment Services Act regime works for inbound operators and where it intersects with offshore structures
- Legal Design of On-Chain Treasuries and Multisig Control – governance and custody legal considerations for operators managing on-chain assets
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and application complexity. Under MiCA, the formal NCA review period runs from the date an application is confirmed complete, but pre-application engagement and completeness checks extend the overall horizon. Operators we advise typically plan for a process measured in months rather than weeks, with simpler single-activity applications in accessible member states taking less time than multi-service or multi-entity applications. Bermuda's BMA process follows its own schedule under the DABA regime. In either case, building banking and substance arrangements in parallel with the application shortens the operational launch timeline materially.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your users are, what activities you conduct, your banking needs, your tax position and your operational capacity for regulatory engagement. For EU-facing businesses, MiCA CASP authorisation in a member state with established crypto-supervisory capacity is the relevant benchmark. For broader international operations, Bermuda, Singapore and other purpose-built regimes each offer different combinations of regulatory credibility, banking access and operational flexibility. The choice is a structuring decision requiring analysis of the full stack – licence, banking, tax and compliance – not a standalone regulatory question.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a separately defined regulated activity within the CASP authorisation regime. A business that holds client assets alongside exchange or transfer services must ensure its CASP authorisation covers custody explicitly. In Bermuda, the DABA regime similarly treats custody as a regulated activity that requires specific authorisation. Whether a structurally separate entity is needed for custody – rather than a combined authorisation – depends on the service model, the member state or jurisdiction chosen, and regulatory expectations around segregation and operational risk. This is a design decision that should be made at the outset of the licensing mandate.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, cross-border licensing structures and the interaction between offshore domiciles and EU/Asia-Pacific regulatory access requirements.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.