EST · MMXXVI
Home/Jurisdictions/Cayman/CASP authorisation under mica in Cayman Islands
Licensing & Registration

CASP authorisation under mica in Cayman Islands

Casp authorisation under mica in Cayman Islands. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

CASP Authorisation Under MiCA in Cayman Islands

A Cayman-domiciled digital-asset business that wants to serve European Union clients faces a structurally distinct problem: the Cayman Islands sits outside the MiCA (Markets in Crypto-Assets Regulation) territorial perimeter, yet its operators are frequently caught by MiCA's reverse-solicitation limits and the EU's crypto-asset service-provider authorisation requirements. The business question is not simply whether to get a Cayman VASP (virtual asset service provider) registration under the Cayman Islands Monetary Authority – it is whether the Cayman entity alone can sustain EU-facing activity, or whether a parallel EU CASP (crypto-asset service provider) authorisation through a MiCA-compliant member state is the durable answer. Getting this wrong costs banking relationships, exposes leadership to enforcement and, in the most acute cases, shuts down operations mid-cycle. This page maps the regulated basis for each path, the practical process, and where the two regimes interact.

What MiCA Actually Requires for a Cayman Operator

MiCA applies to any entity offering crypto-asset services to clients in the EU, regardless of where that entity is incorporated. A Cayman structure does not, by itself, exempt an operator from MiCA's reach. ESMA and the national competent authorities of member states have made clear that the reverse-solicitation carve-out – permitting non-EU entities to serve EU clients who approach them exclusively on the client's own initiative – is narrow and cannot be engineered. An operator that markets, advertises or otherwise promotes its services to EU-resident persons is likely providing services on a cross-border basis that requires CASP authorisation under MiCA within a member state.

The practical upshot for a Cayman operator is stark. Continued EU activity through the Cayman entity without a licensed EU nexus risks regulatory action from multiple competent authorities simultaneously. In our practice, we regularly advise Cayman-domiciled funds and exchanges that have relied informally on the reverse-solicitation framing, only to find that their onboarding materials, referral programs or marketing campaigns have eroded the very passivity that makes the carve-out work.

The answer for an operator that genuinely needs EU access is to pair the Cayman holding and operational entity with a CASP-authorised subsidiary in a MiCA member state. The Cayman entity continues to serve non-EU markets under the CIMA regime. The EU entity – authorised as a CASP and, where needed, passported across the EEA – holds the regulatory permission for EU clients.

Operating without the right licence across this boundary risks enforcement, frozen banking rails and loss of institutional counterparty access. The cost of remediation after a supervisory inquiry consistently exceeds the cost of structuring correctly at the outset.

For a scoped assessment of your Cayman-EU structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

Cayman VASP Registration Under CIMA: The Base Layer

The Cayman Islands Monetary Authority (CIMA) administers VASP registration under the Virtual Asset (Service Providers) Act – commonly called the VASP Act – which establishes registration and, for higher-risk activities, full licensing tracks for virtual-asset businesses operating in or from the Cayman Islands. The VASP Act creates a tiered structure: certain activities require only registration, while others – including operating a virtual-asset trading platform or providing custody at scale – require a CIMA licence. Both tracks impose AML/CFT obligations aligned to FATF standards, including the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), record-keeping requirements and governance expectations.

For a Cayman entity, the CIMA framework provides a credible regulatory foundation for non-EU activity. Institutional counterparties, prime brokers and custodian banks increasingly expect documented VASP status. The registration or licence also signals that the entity operates within a supervised regime, which supports banking access in the Cayman Islands and in correspondent jurisdictions.

Timelines for CIMA registration and licensing vary by activity complexity and the completeness of the application. The regulator's published guidance describes application requirements, and in our experience incomplete documentation is the single most common cause of delay. A well-prepared submission – with a clear business model description, an AML/CFT framework that satisfies CIMA's expectations and a governance structure that meets the fit-and-proper threshold – materially reduces the review period.

What the Cayman VASP registration does not do, however, is grant any right to provide crypto-asset services to EU-resident clients within the scope of MiCA. The two regimes operate independently. Holding a CIMA registration or licence is necessary for the Cayman layer; it is not a substitute for CASP authorisation in a MiCA member state for the EU layer.

CASP Authorisation: The EU Layer the Cayman Entity Cannot Replace

CASP authorisation under MiCA is granted by the national competent authority of a chosen member state and, once issued, carries passporting rights across all EU and EEA member states – meaning a single authorisation in, say, Lithuania, Malta or another MiCA-aligned jurisdiction enables services to clients in every member state without a separate application in each. ESMA coordinates supervisory convergence and issues guidelines that national competent authorities apply, so the substantive requirements – capital adequacy, governance, AML/CFT, prudential safeguarding for client assets – are broadly consistent across the EU, even as procedural timelines differ by jurisdiction.

The choice of member state for CASP authorisation is a commercial and operational decision with long-term consequences. Factors that we weigh with clients include: the competent authority's published timelines and processing capacity; the jurisdiction's track record with crypto-specific applications; the availability of banking infrastructure for the entity; and the tax treatment of crypto income and intra-group arrangements. A Cayman parent licensing an EU CASP subsidiary must also think through the group-level capital and governance obligations that flow from the MiCA framework's requirements for subsidiaries of third-country entities.

For operators who built their initial structure in Lithuania under the pre-MiCA VASP regime, the transition to CASP authorisation involves additional steps: existing registrations do not automatically convert, and competent authorities expect grandfathering applicants to meet the full MiCA capital and organisational requirements. The Bank of Lithuania has published transition guidance that applies to entities in this position.

The Malta Financial Services Authority – MFSA – offers a parallel route for operators with an existing presence or a preference for a common-law-adjacent EU jurisdiction with an established crypto practice. Malta's prior VFA framework is transitioning to the MiCA CASP regime, and MFSA has published its own supervisory expectations for applicants moving through the transition.

If a prior application stalled or a banking relationship was closed in the EU entity context, a second-read analysis can surface the structural reason and the route back. Write to info@oboluslaw.com or t.me/oboluslaw. Map your options.

How Do the Two Regimes Interact for a Cayman-EU Group?

For a group with a Cayman holding entity and an EU CASP subsidiary, the interaction between CIMA supervision and MiCA supervision is the central structural challenge. The EU subsidiary will be regulated by its home-state competent authority and by ESMA's convergence framework. The Cayman parent will be subject to CIMA oversight. Both regulators will look at the group structure and ask whether substance, governance and capital are distributed appropriately between the entities – or whether the regulated entity is a shell that routes risk back to an unsupervised parent.

Substance requirements matter acutely here. The EU CASP entity must have genuine decision-making authority, qualified senior management resident in or readily accessible from the member state, and sufficient own resources. An entity whose CEO and risk function sit exclusively in the Cayman Islands will face questions during the authorisation process and ongoing supervisory reviews. In our practice, we have seen applications delayed or withdrawn because the EU applicant could not demonstrate the requisite local substance at the time of submission.

Banking is a parallel constraint. The EU entity needs euro-denominated banking, which in practice means either a credit institution in the member state of authorisation or one of the specialist fintech banks operating across the EEA. The Cayman entity needs banking that accepts a supervised VASP as a client. These two banking relationships must be structured in a way that does not create regulatory arbitrage that either regulator will identify as a concern.

Tax interaction is the third axis. The Cayman Islands has no corporate income tax, which creates an obvious incentive to concentrate profits in the Cayman parent. However, EU transfer-pricing rules, the arm's-length standard, and the OECD Pillar Two framework (for groups meeting the relevant revenue threshold) all constrain the degree to which value can be shifted away from the EU entity. Any intra-group fee arrangement between the Cayman parent and the EU CASP subsidiary must reflect genuine economic substance and be supportable under both EU and Cayman standards. We always recommend that the tax and licensing analysis run concurrently, not sequentially.

Application Process: What an Inbound Operator Must Prepare

A well-structured CASP application under MiCA requires substantive preparation across four workstreams: the regulatory filing, the AML/CFT framework, the governance documentation and the capital/prudential package. Operators that approach the application as a forms exercise – rather than a regulatory engagement – invariably encounter requests for further information that extend the timeline significantly.

The regulatory filing itself covers the business model, the services to be licensed, the technology infrastructure, the safeguarding arrangements for client assets and the conflicts-of-interest framework. For a Cayman group, it also requires disclosure of the group structure, the ultimate beneficial owners and the governance links between entities. National competent authorities under MiCA apply a substance-over-form standard: the filing must describe the entity as it will actually operate, not an idealised version.

The AML/CFT framework must be tailored to the MiCA regime's requirements and to any additional national-level requirements in the chosen member state. It must address the Travel Rule in the specific form adopted in that jurisdiction, because Travel Rule data thresholds and implementation detail vary across EU member states even within the common MiCA framework. A Cayman entity that already operates a mature AML program under CIMA supervision has a head start, but the program must be adapted for the EU entity and reviewed by counsel familiar with the relevant national transposition.

Governance documentation includes the fitness-and-properness evidence for proposed senior managers and controllers, the organisational chart, the board composition and the internal governance policies. For a group where key personnel currently sit in the Cayman Islands, a transition plan showing how the EU entity will achieve independent governance is often required.

Capital adequacy evidence at the time of filing – not projected capital, but demonstrated capital – is a standard competent authority requirement. The precise own-funds threshold depends on the CASP category applied for and the scale of the business; these figures vary by licence class under MiCA and should be confirmed against current regulatory guidance at the time of application.

Decision Matrix: Which Operator Profile Needs What?

Not every Cayman operator needs a CASP authorisation. The right structure depends on the operator's actual user base and service model.

Profile A – Cayman operator, no EU clients, institutional-only non-EU focus. This operator needs robust CIMA registration or licensing for the activity being conducted. MiCA CASP authorisation is not required. The operative risk is ensuring that the reverse-solicitation boundary is documented and enforced operationally – that no marketing, onboarding or solicitation activity directed at EU-resident persons occurs. The timeline to CIMA registration or licensing varies by activity type; a clean application with complete documentation materially reduces the review period. Key risk: scope creep in the client base over time, without a corresponding EU regulatory structure.

Profile B – Cayman operator with EU clients, or aspirations to serve EU retail or professional investors. This operator needs a CASP-authorised EU subsidiary, passported across the relevant member states, alongside the Cayman entity. The authorisation timeline varies by member state and application quality; operators should plan for a multi-month process in the best case. Key risk: attempting to rely on the reverse-solicitation carve-out at scale, which creates regulatory exposure in multiple EU member states simultaneously.

Profile C – Cayman fund or investment vehicle with EU investor exposure. This profile sits at the intersection of MiCA and the relevant EU fund-management regime. The fund itself may not require CASP authorisation, but the manager or advisor providing crypto-asset services to the fund may. The analysis requires a concurrent review of both the VASP/CASP question and the fund-management regulatory position in the relevant member state. Timeline and capital requirements vary by structure.

In all three profiles, the banking and tax structuring must be resolved in parallel with the regulatory filing. A licence without a banking relationship is operationally incomplete. A cross-border structure without a defensible transfer-pricing model creates a tax and regulatory risk that surfaces in due diligence and supervisory review.

A Recent Instruction: Cayman-EU Restructure Under MiCA

In a recent structuring matter, a Cayman-incorporated exchange had been operating for several years under a CIMA registration, serving a mixed user base that included European retail clients onboarded through a referral program operated by a European marketing partner. The arrangement had been structured as a reverse-solicitation model, but the referral fees, co-branded marketing materials and dedicated EU-language onboarding flows had effectively eroded that characterisation. We were engaged when the operator received informal supervisory inquiries from two EU member-state competent authorities simultaneously. We mapped the regulatory exposure across the relevant MiCA jurisdictions, advised on the most defensible EU member state for CASP authorisation given the group's existing substance and banking position, and drafted the restructuring plan that separated EU-facing activity into a newly incorporated EU subsidiary. The Cayman entity retained its CIMA registration for non-EU institutional business. The EU subsidiary was established with appropriate local governance before the CASP application was filed. The matter was resolved without formal enforcement action.

A Common Assumption We Regularly Correct

A common assumption among operators building from a Cayman base is that a single offshore licence – whether CIMA registration, a BVI FSC VASP registration or a comparable offshore authorisation – is sufficient to serve clients globally, including EU clients, provided the entity does not have a physical presence in the EU. This assumption is incorrect under MiCA, and it has become increasingly untenable across other major jurisdictions as well. The ESMA position on the reverse-solicitation carve-out is that it applies only where the EU-resident client independently approaches the service provider without any prior solicitation, inducement or marketing. Virtually every commercial operator that serves EU clients at scale will fail this test at some point in its onboarding or marketing chain.

The parallel myth is that getting a CASP authorisation in one EU member state is an end-state. It is, in fact, the beginning of a sustained supervisory relationship. MiCA introduces ongoing capital adequacy reporting, periodic regulatory returns, AML/CFT audits and, for certain token issuers, significant reserve and redemption obligations. An operator that enters the CASP authorisation process without counsel experienced in post-authorisation compliance will find the ongoing cost and complexity of the licence higher than anticipated.

We map the full stack – Cayman VASP, EU CASP, banking and tax – before a client commits to a structure. That upfront analysis consistently delivers a lower total cost of compliance than retrofitting a structure built on incomplete information.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction, licence category and the quality of the application filed. In leading EU member states under MiCA, a CASP authorisation process runs over several months from submission of a complete application; national competent authorities differ in processing speed and volume of applications in their pipeline. Cayman CIMA registration and licensing timelines similarly depend on activity type and application completeness. A well-prepared submission with complete documentation, a mature AML/CFT framework and credible governance evidence consistently produces shorter timelines than an iterative, incomplete filing.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction depends on where your clients are located, what services you provide, where you can achieve genuine corporate substance, and your banking and tax constraints. EU-facing businesses require a MiCA CASP authorisation in a member state, with passporting for cross-border EU activity. Businesses focused on non-EU institutional or professional markets often build from offshore-friendly jurisdictions such as the Cayman Islands, paired with jurisdiction-specific registrations or licences for each material market. We map these trade-offs systematically before any commitment is made.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated CASP service, and an entity providing custody requires authorisation to do so. Whether a separate entity is required – rather than a single CASP entity authorised for both trading and custody – depends on the structure chosen and the risk appetite of the operator. Some groups prefer to separate custody into a dedicated entity for liability and governance reasons. Under the Cayman VASP Act, custody at scale triggers licensing obligations distinct from registration. In both regimes, the custody layer must satisfy specific safeguarding, segregation and operational resilience requirements.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is required. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, offshore-to-EU group structuring and multi-hub licence stacking for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours