A Brazilian digital-asset business expanding into the European Union quickly encounters a structural mismatch: Brazil operates under its own domestic crypto regime, but serving EU-resident users – or holding EU-facing assets – triggers obligations under MiCA (the EU Markets in Crypto-Assets Regulation) that no Brazilian licence alone can satisfy. The question is not whether MiCA applies; the question is how a Brazilian-origin operator structures its EU presence to obtain CASP authorisation (Crypto-Asset Service Provider authorisation) while keeping the Brazilian operating entity commercially and legally coherent. Operating without that authorisation, once the MiCA transition window closes, exposes the business to enforcement, loss of payment rails and frozen banking relationships across every EU member state simultaneously.
This page sets out the regulated basis, the inbound-business path for a Brazilian-connected group, the cross-border interaction with tax and banking, and the decision points that matter before you commit capital to an EU authorisation.
What MiCA CASP authorisation means for a Brazilian business
MiCA CASP authorisation is an EU-wide licence that permits a single legal entity, established in an EU or EEA member state, to provide crypto-asset services to clients across the entire single market under a passporting mechanism. Brazil has no reciprocal equivalence arrangement with the EU under MiCA. That means a Brazilian company cannot passively rely on its domestic licence to serve EU users. It must establish a regulated EU entity – or accept that EU-resident clients are off-limits until it does.
ESMA (the European Securities and Markets Authority), working alongside national competent authorities, supervises the CASP regime. ESMA sets binding technical standards; the national competent authority in the chosen member state grants the authorisation and remains the primary supervisor. The authorisation covers a defined menu of activities: exchange services, custody, brokerage, portfolio management, transfer services, advisory and others enumerated under MiCA. A Brazilian group must identify exactly which activities its EU entity will perform, because the capital and governance requirements scale with the activity category.
For operators with Brazilian parent structures, the cross-border dimension is immediate. The EU entity will need a local board presence, substance in the member state, and – critically – a banking relationship in the EU. Brazilian banking counterparties do not satisfy EU safeguarding expectations for client funds. The structural separation between the Brazilian operating entity and the EU CASP entity is not optional; it is the condition on which authorisation proceeds.
Reach OBOLUS before you choose your EU member state. The member-state choice affects timeline, capital requirements, supervisory culture and the ease of opening EU banking. To map the right entry point for your Brazilian group, contact OBOLUS at Map your options.
Does MiCA apply to Brazil-connected operators at all?
MiCA applies on the basis of where services are provided, not where the provider is incorporated. A Brazilian company actively marketing to, or onboarding, EU-resident users is providing services into the EU regardless of the contractual choice of law or the server location. The reverse-solicitation exemption under MiCA is narrow: it covers only situations where the EU client initiates contact entirely on their own initiative, without any direct or indirect solicitation by the service provider. Regulators across the EU have signalled that they will read this exemption strictly.
Brazil's own domestic crypto regime – supervised by the Banco Central do Brasil and the CVM (Comissão de Valores Mobiliários) following the 2023 legislative reforms – covers Brazilian-resident user activity and certain token classifications under Brazilian law. The two regimes operate in parallel. A Brazilian business serving both Brazilian and EU clients must satisfy both simultaneously. We regularly advise groups that discover this duality late in their expansion planning, when the cost of restructuring is already elevated.
The practical test is this: if your go-to-market materials are available in any EU language, if your onboarding flow accepts EU-resident identity documents without a hard geo-block, or if you have EU-based business development staff, you are almost certainly within MiCA's reach. The reverse-solicitation defence will not protect you in those circumstances.
How does the MiCA CASP application process work for an inbound operator?
A Brazilian-origin group seeking CASP authorisation must first incorporate a legal entity in an EU or EEA member state and establish genuine substance there before the national competent authority will accept an application. The application itself requires a detailed regulatory business plan, governance and internal-control documentation, AML/CFT policies calibrated to the FATF Travel Rule (the FATF obligation requiring that originator and beneficiary data travel with a transfer), key-person approvals, capital evidence, and a custody and safeguarding framework if custody services are included.
ESMA and the national competent authorities have published guidance on the content requirements; the process is document-intensive and the quality of the submission directly affects timeline. In our cross-border practice, applications with well-prepared initial submissions move materially faster through the completeness review than those that require multiple rounds of supplemental requests. The national competent authority clock does not start until it has declared the application complete.
Member-state selection matters for a Brazilian group in ways that go beyond headline processing time. Some member states have dedicated digital-asset supervisory teams and published guidance on cross-border ownership structures; others are still building capacity. The supervisory culture in the chosen state will shape post-authorisation obligations – reporting cycles, inspection frequency and the practical burden of ongoing compliance. A member state with a well-developed VASP supervisory track record under the pre-MiCA registration regime is generally a more predictable environment for a first EU authorisation.
The authorisation, once granted, is valid across all EU and EEA member states. The group then formally notifies the competent authority in each additional member state where it intends to operate – a passporting procedure that is administrative rather than a new licence application. For a Brazilian group with EU ambitions across multiple markets, this passporting mechanism is the commercial prize that makes the initial authorisation cost worthwhile.
Which EU member state should a Brazilian operator choose for CASP authorisation?
No single member state is optimal for every operator profile. The right choice depends on the specific activity set, the corporate structure, the realistic timeline, and the operator's capacity to establish substance. Three considerations are consistently determinative in practice.
First, supervisory readiness: member states that transitioned active VASP registrations under the pre-MiCA AML regime have established supervisory processes and experienced examiners. The Bank of Lithuania, for instance, supervised a large VASP population under the pre-MiCA regime and has institutional experience with inbound non-EU applicants. Malta's MFSA is transitioning its VFA framework to the CASP model, bringing accumulated experience with complex token-business structures. Neither carries a guarantee of speed – application quality remains the primary variable – but both offer a known supervisory environment.
Second, the banking dimension: EU authorisation is only as useful as the banking relationships that support it. Some member states have resident banks that are actively building crypto-business banking programmes; others have not. A CASP authorisation that cannot support a EUR settlement account and a client-money safeguarding arrangement is commercially inert. We have seen operators choose a member state on regulatory grounds only to discover that the banking environment is unreceptive, requiring a costly entity restructure after authorisation.
Third, substance requirements: the member state supervisory authority will assess whether the EU entity is genuinely managed and controlled from that jurisdiction. For a Brazilian group with its operational centre in São Paulo, demonstrating that the EU entity has real decision-making capacity – not just a registered address – requires thoughtful planning of board composition, senior-manager residency and operational infrastructure.
In our practice, the member-state decision is best treated as a combined regulatory-banking-substance exercise, not a regulatory exercise in isolation. Operators who treat it as purely a licensing question routinely encounter avoidable delays.
If a prior application stalled or an EU banking relationship was closed, the structural reason is usually identifiable. A second read often surfaces the route forward. Contact OBOLUS at Map your options.
What are the AML and Travel Rule requirements under MiCA for a Brazilian CASP applicant?
AML and Travel Rule compliance is not a post-authorisation project – the competent authority assesses the AML/CFT framework as part of the authorisation decision. A Brazilian-origin applicant must demonstrate that its EU entity has policies, controls and technology in place to meet FATF Recommendation 15 standards and the Travel Rule obligations as implemented under EU law, before the application can be approved.
The Travel Rule requires that originator and beneficiary identification data accompanies every qualifying crypto-asset transfer. The EU has implemented this through the Transfer of Funds Regulation (TFR), which applies to CASPs. For a Brazilian operator, this creates a specific challenge: transfers between the Brazilian entity and the EU entity – for example, internal treasury movements or customer fund flows routed through the Brazilian parent – are within scope. The EU CASP must have a compliant Travel Rule solution that covers both inbound transfers from non-EU VASPs and outbound transfers to them, including transfers to or from Brazilian counterparties.
ESMA and national competent authorities have emphasized that Travel Rule compliance for inbound operators requires operational integration, not just a policy document. That means a deployed technical solution, tested data flows and a process for handling transfers where the counterparty VASP does not return compliant data. In our cross-border practice, the Travel Rule gap is among the most common causes of application delay for non-EU groups; the technology procurement and integration cycle is longer than most applicants expect.
How do tax and banking interact with MiCA authorisation for a Brazil-EU structure?
A Brazilian group operating an EU CASP entity sits within a two-jurisdiction tax structure that requires coordinated analysis. The EU entity will generate revenues from EU-resident clients; the transfer-pricing relationship between the EU entity and the Brazilian parent – for services, technology licences, management fees and capital allocation – is immediately in scope for both Brazilian transfer-pricing rules and the tax rules of the EU member state.
Brazil's transfer-pricing regime, which has been reforming toward OECD alignment, applies to transactions between Brazilian entities and related foreign parties. The EU entity's revenues cannot be structured to minimise Brazilian tax without a defensible arm's-length analysis. Conversely, the EU member state will apply its own corporate tax rules to the EU entity's locally-sourced profits. The combined effective rate, and the withholding tax treatment of dividends and royalties, depends on whether Brazil and the chosen EU member state have a double-taxation treaty in force. Treaty coverage varies across member states.
On banking, the EU CASP entity requires EU-resident banking for three purposes: a EUR operational account, client-fund safeguarding accounts (if custody services are in scope), and correspondent banking for fiat on/off ramps. Brazilian parent-company banking does not satisfy any of these requirements. EU banks with active crypto-business programmes assess prospective CASP clients on the quality of the authorisation, the AML framework and the ownership structure. A Brazilian ultimate beneficial owner (UBO) structure is not inherently problematic, but it requires complete and documented UBO disclosure to the EU bank's compliance team, typically before the account opening process can proceed.
In practice, the banking timeline often runs in parallel with the authorisation process. Some operators attempt to sequence banking after authorisation, which creates a gap: the authorisation is granted but the entity cannot commence operations because the banking is not in place. We map the banking and authorisation tracks simultaneously for the groups we advise.
A recent structuring instruction: Brazil-origin exchange, EU authorisation
In a recent matter, a Brazilian crypto exchange seeking to expand into EU markets approached us after an initial EU member state application had been returned as incomplete. The group had incorporated an EU subsidiary but had not established genuine substance, had not resolved the banking structure, and had submitted an AML policy that replicated the Brazilian regulatory framework rather than the EU TFR requirements. We restructured the EU entity's governance, placed a resident director with appropriate qualifications in the chosen member state, identified an EU banking partner receptive to the group's UBO profile, and redrafted the AML and Travel Rule framework to reflect EU requirements. The restated application was accepted as complete by the national competent authority within weeks of resubmission. The group commenced EU-passported services in the following quarter.
Decision matrix: which Brazilian operator profile needs CASP authorisation?
Not every Brazilian digital-asset business needs a CASP authorisation immediately. The decision turns on three variables: the EU-resident user base, the specific services offered, and the timeline for EU commercial launch.
A Brazilian exchange that currently has no EU-resident users and applies a hard geo-block to EU jurisdictions does not yet need a CASP authorisation. It should, however, plan for one if EU expansion is on a two-to-three-year horizon, because the establishment and authorisation process takes time that is difficult to compress.
A Brazilian custodian that holds assets for EU-resident institutional clients – even if those clients were originally onboarded in Brazil and have since relocated – is almost certainly providing a custody service within MiCA's scope. The activity follows the client's residency, not the original onboarding location. This is a scenario we have seen regulators focus on as enforcement capacity matures.
A Brazilian token issuer offering tokens to EU-resident investors must assess whether the offering falls within MiCA's whitepaper and authorisation obligations or within the securities regime of the relevant EU member state. The classification analysis is fact-specific and turns on the rights conferred by the token, not the label applied to it.
A Brazilian fintech integrating crypto payment services into an existing EU-facing product must determine whether it is operating as a CASP, a payment institution, or both – and whether the EU member state's national competent authority or the payments regulator is the primary supervisor. The overlap between MiCA and the EU payment services regime is a live regulatory question in several member states.
Across all profiles, the common thread is that a Brazilian parent structure does not insulate the group from EU regulatory reach once EU-resident users are in scope.
Common mistakes Brazilian operators make when approaching MiCA CASP authorisation
A common assumption among Brazilian operators is that a single offshore licence – whether from a Caribbean jurisdiction or a less-supervised EU member state – is enough to serve EU clients globally. MiCA forecloses that assumption. The passporting mechanism is available only to entities authorised under MiCA itself, not to entities authorised under third-country regimes, however respected.
Three other mistakes appear with regularity in our practice. The first is underestimating substance requirements. A registered address and a nominee director do not constitute the genuine management and control that EU supervisors now examine. Post-MiCA, competent authorities are conducting on-site assessments and reviewing board meeting records to verify that key decisions are actually made in the authorised jurisdiction.
The second is treating Travel Rule compliance as a documentation exercise. Supervisors assess whether the technology is deployed and the processes are operational, not merely whether a policy document exists. Applicants who have not yet selected and integrated a Travel Rule solution are not ready to file.
The third is failing to resolve the banking structure before filing. An authorisation application that cannot demonstrate a credible path to EU client-money safeguarding will generate supervisory questions that delay the process. Identifying and commencing a banking relationship in parallel with the application is standard practice in the operations we advise on.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – how OBOLUS maps the full licence stack across operating, custody and payment layers
- VASP licensing in the United States: federal and state MTL – federal and state money-transmission requirements for cross-border operators
- Token legal classification in Singapore – how Singapore's MAS classifies digital tokens and the licensing consequences
FAQ
How long does a crypto licence take to obtain?
Timeline varies materially by jurisdiction, activity category and application quality. Under MiCA, the national competent authority's review period begins only once the application is declared complete; pre-filing preparation – incorporating the EU entity, establishing substance, resolving banking and building the AML/Travel Rule framework – typically takes several months before any formal clock starts. Operators who arrive at the filing stage with complete documentation move through the process significantly faster than those who do not.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on the specific services, the target user base, the ownership structure and the banking environment. For EU market access, MiCA CASP authorisation in a well-resourced member state is generally the correct structure. For other markets, MAS in Singapore, the SFC in Hong Kong, VARA in Dubai and the FSRA in Abu Dhabi each serve distinct operator profiles. The member-state or jurisdiction selection should be a combined regulatory, banking and substance analysis, not a regulatory exercise alone.
Do I need a separate custody licence?
Under MiCA, custody of crypto-assets is a distinct regulated service requiring specific authorisation and capital. An operator authorised only for exchange or brokerage services cannot provide custody services under that authorisation. Whether a Brazilian-origin group needs a custody authorisation depends on whether it actually holds client assets – directly or through a controlled sub-custodian. Groups that plan to offer custody as an ancillary feature of an exchange or wallet product should assess the boundary carefully before filing, because misclassification at the application stage creates downstream enforcement exposure.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before clients commit capital – a discipline that consistently surfaces structural issues before they become enforcement problems. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound digital-asset authorisation strategy for non-EU groups seeking EU market access under MiCA.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.