What Does MiCA Actually Regulate – and Who Falls Inside It?
MiCA – the Markets in Crypto-Assets Regulation – establishes the EU-wide regulatory regime for crypto-asset service providers and token issuers, replacing the patchwork of national virtual-asset frameworks that previously governed the sector across the bloc. Any business offering regulated crypto-asset services to clients in the EU must operate under a CASP authorisation (crypto-asset service provider authorisation) granted by a national competent authority, or it faces the full weight of supervisory enforcement. The regime sits alongside ESMA oversight at the European level, and its passporting mechanism means one authorisation can cover the entire single market.
For an exchange, custodian, token issuer or portfolio manager with EU users, the central question is not whether MiCA applies – in almost every case it does – but how to structure the authorisation efficiently and without the errors that cause applications to stall or banking relationships to collapse before the licence is granted.
The sections below walk through the regulated perimeter, the licence categories, the application process, the cross-border realities and the common mistakes we see. This page is the hub for all OBOLUS guidance on EU digital-asset regulation.
The Regulator, the Architecture and Why Both Matter
MiCA creates a two-layer supervisory structure: ESMA (the European Securities and Markets Authority) sets binding technical standards and coordinates convergence, while national competent authorities (NCAs) – such as the AFM in the Netherlands, the BaFin in Germany, the Bank of Lithuania or the MFSA in Malta – grant the authorisation itself and handle ongoing supervision. For most applicants, the practical relationship is with the NCA of the chosen member state. But ESMA's role is not ceremonial: its regulatory technical standards set the disclosure, organisational and conduct requirements that every NCA applies.
The regime covers three distinct regulatory layers. First, token issuance: issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) must be authorised before offering their tokens to the public, and whitepaper obligations apply across all crypto-asset classes. Second, service provision: the CASP authorisation covers a defined list of activities – custody, operation of a trading platform, exchange against fiat, exchange against other crypto-assets, execution of orders, placing, reception and transmission of orders, providing advice and portfolio management. Third, stablecoin issuance: ARTs and EMTs carry additional reserve, redemption and – for significant token designations – direct ESMA supervision requirements.
A business offering more than one of these services needs authorisation for each. Many operators underestimate the breadth of activities that fall within the definition of "exchange against fiat" or "custody." In our advisory practice, we frequently encounter structures where a business is performing three or four regulated activities under a single product but has scoped its authorisation application for only one.
Who Needs a CASP Authorisation – and Who Is Exempt?
The threshold for requiring a CASP authorisation under MiCA is set by the nature of the service, not the scale of the business. A startup offering crypto-to-fiat exchange to a single EU country needs the same class of authorisation as a major exchange serving the entire bloc. Size affects the capital requirement tier and the supervisory intensity; it does not create an exemption.
Certain entities benefit from transitional arrangements that allow them to continue operating under national rules for a defined period while applying for CASP authorisation. The length of those transitional windows varies by member state, and a number of the larger EU markets have already signalled that they will apply the shortest permissible runway. Businesses that treated the MiCA transition as a distant compliance project are now finding the window materially shorter than they assumed.
Genuine exemptions are narrow. The regime does not apply to pure peer-to-peer transactions with no service provider intermediary, to certain intra-group services, or to entities already regulated under existing EU financial-services law for functionally equivalent services. But the "already regulated" carve-out is more limited than it first appears. A payment institution holding an EMI licence, for example, may still need separate CASP authorisation if it wants to offer custody or trading services beyond its payment authorisation.
The question of whether a token constitutes a financial instrument – and therefore falls under MiFID rather than MiCA – remains one of the most consequential classification decisions a token issuer can face. The answer turns on the rights conferred by the token, not its marketing label. We advise clients to conduct a documented classification analysis before any public offering, because the choice of regime determines the disclosure format, the authorisation type and the ongoing conduct obligations.
For a scoped assessment of where your business sits within the MiCA perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the token structure, the banking – change the analysis. Map your options.
What Are the CASP Licence Categories and What Do They Cover?
MiCA defines nine regulated crypto-asset services, each requiring explicit authorisation; a CASP wishing to offer multiple services applies for all relevant permissions in a single application, but each service class has its own capital and organisational requirements. The nine services are: custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for fiat currency; exchange of crypto-assets for other crypto-assets; execution of orders on behalf of clients; placing of crypto-assets; reception and transmission of orders; providing advice; and portfolio management.
Capital requirements are calibrated by service class. The regime sets minimum own-funds levels that scale with the complexity and risk of the activity – custody and trading platform operation carry the highest capital floors, while advisory and reception/transmission services carry the lowest. Because all capital figures are subject to the verification process and vary by member state implementation, operators should obtain a current capital schedule from their intended NCA or from counsel before committing to a domicile. What the registry confirms is the structure: tiered own-funds requirements with a floor set by the relevant MiCA provisions, applied consistently across all NCAs.
For token issuers, the ART and EMT authorisation tracks are separate from the CASP track. An entity that both issues a stablecoin and operates a trading platform must hold both authorisations – from the same NCA if the member state permits, or potentially from separate regulators if the structures are separated. We have seen first-time applicants conflate the two tracks, resulting in incomplete applications and extended review periods.
How Does the CASP Application Process Work – and How Long Does It Take?
The CASP application process follows a defined statutory pathway under MiCA: submission to the NCA of the chosen member state, a completeness check, a substantive review period, and a determination – with appeals available under national administrative law. The substantive review period is set by the regulation and applies uniformly across all NCAs, though individual NCAs retain discretion over their pre-application engagement processes, which can materially affect how long the overall process takes in practice.
In our practice, the most significant variable is not the statutory clock but the quality of the application at the point of submission. An incomplete application restarts the review period. The NCA's completeness check is the first gate; a deficiency notice at that stage can add weeks or months to the overall timeline. The substantive review then assesses the fitness and propriety of management, the adequacy of the organisational framework, the robustness of AML/CFT controls, the soundness of the business plan and the satisfaction of capital requirements.
The cross-border reality adds a further layer. Most crypto businesses do not serve a single member state. The MiCA passporting mechanism allows a CASP authorised in one member state to provide services across the EU/EEA by notification – but the passporting right attaches to the specific services for which authorisation was granted. A business that under-scopes its initial authorisation and then wants to add services in a second member state may need a variation, not just a passport notification. Planning the activity scope at the outset is consistently more efficient than amending after the fact.
Operators should also plan for the operational substance requirements that NCAs increasingly scrutinise. A "brass plate" structure – a registered office, a director with no genuine local function, and all real operations elsewhere – will not pass the fitness review at most major EU NCAs. MiCA expects genuine operational substance: senior management with day-to-day decision authority in the authorised entity, proportionate local staffing, and local systems access where operationally relevant. The level of substance expected scales with the scope and complexity of the authorised services.
What AML and Travel Rule Obligations Apply Under MiCA?
A CASP authorised under MiCA is simultaneously subject to the EU's Anti-Money Laundering Directive framework and the Transfer of Funds Regulation – the EU's implementation of the FATF Travel Rule for crypto-asset transfers. The two regimes operate in parallel: a business can satisfy its MiCA authorisation requirements and still face supervisory action under the AML framework for inadequate transaction monitoring or deficient Travel Rule compliance.
The Travel Rule – the obligation to collect and transmit originator and beneficiary information with a crypto-asset transfer – applies to CASPs above the threshold set in the Transfer of Funds Regulation. The precise de minimis threshold is a [VERIFY] figure that varies by transaction type; operators should confirm the current threshold with counsel or the applicable NCA. What the registry confirms as principle is the obligation itself: CASPs must screen, collect and transmit the required data, and they must have technical and operational systems in place to do so before going live.
Customer due diligence, beneficial ownership identification, suspicious transaction reporting and the maintenance of adequate records are all required under the AML framework as applied to CASPs. For a business onboarding clients across multiple EU member states, the AML supervisory function typically sits with the NCA of the authorised entity's home member state, but host-state authorities retain enforcement rights for breaches occurring in their territory.
One area we flag consistently in our advisory work is the intersection between Travel Rule compliance and the unhosted-wallet policy. MiCA does not prohibit transfers to and from unhosted wallets, but it does require CASPs to apply enhanced due diligence to such transfers above defined thresholds. Businesses that have not built this into their compliance architecture before authorisation tend to find it a significant remediation project after the fact.
If a prior application stalled or your compliance architecture needs a second read before submission, write to OBOLUS at info@oboluslaw.com. A structural review can surface the specific gap and the route forward. Map your options.
How Does MiCA Interact With Cross-Border Structuring and Banking?
For a digital-asset business operating across multiple jurisdictions, MiCA authorisation is one layer of a wider legal and operational stack – not a standalone solution. The EU CASP licence covers service delivery to EU/EEA clients; it does not resolve the regulatory position in the UK, Switzerland, the UAE, Singapore or any other market where the business also has users or counterparties. Each of those jurisdictions has its own VASP registration or licensing requirement, and the EU passport does not travel beyond the EEA border.
Banking is the second pressure point. EU-licensed crypto businesses face material difficulty obtaining and retaining bank accounts, even after CASP authorisation. The authorisation establishes legal legitimacy but does not compel a credit institution to onboard a crypto client. In our experience advising businesses through this process, the most effective approach is to prepare a banking package in parallel with the licence application – not sequentially. A detailed compliance manual, a clear counterparty policy, a documented AML framework and a business plan written for a risk-averse compliance officer, rather than for a regulator, materially improve the probability of a banking relationship.
Tax interaction is a further cross-border variable. The MiCA regime does not harmonise the tax treatment of crypto-asset transactions across the EU: VAT treatment, corporate tax treatment of token issuance proceeds and the characterisation of staking and lending income all vary by member state. A business that is tax-resident in one member state but passporting services into others must analyse the permanent-establishment risk and the withholding-tax exposure in each host state. We advise clients to map the tax stack alongside the regulatory stack, not after it.
For businesses sitting between an EU hub and a third-country operating centre – for example, a group with a CASP entity in Lithuania or Malta and a technology company in a non-EU jurisdiction – the question of intra-group service agreements, transfer pricing and the regulatory boundary of the licensed entity is a live structuring issue. Regulators increasingly scrutinise the contractual and economic substance of intra-group arrangements, particularly where the licensed entity books revenue but the economic activity sits elsewhere.
Which Profile Should Choose Which Approach to EU MiCA Authorisation?
The right entry point into MiCA depends on the operator's activity scope, user base, timeline and existing structure. There is no single correct answer, and any adviser who offers one without reviewing the facts is working from assumption rather than analysis.
A business offering only custody services, with a defined EU user base and sufficient management substance, is typically the cleanest CASP applicant: the activity scope is discrete, the capital requirement is calibrated to custody, and the organisational framework is well-established across major NCAs. The challenge is banking and the timeline from application to authorisation. Operators in this profile should budget adequate runway before their target go-live date.
A business combining exchange, custody and payment functions – a common profile for crypto platforms – faces the broadest authorisation scope and the most complex capital calculation. For this profile, the choice of NCA home state is a meaningful decision: not all NCAs have equal experience with complex multi-service CASP applications, and the quality of pre-application engagement varies. We advise clients in this profile to select their home NCA based on regulatory track record and familiarity with the business model, not solely on perceived speed.
A stablecoin issuer – particularly one seeking to issue an EMT denominated in euros or another EU-currency peg – faces the most demanding authorisation track. The EMT issuer must typically hold an e-money institution authorisation in addition to satisfying the MiCA-specific requirements, and reserve composition, redemption rights and marketing restrictions all apply from day one of issuance. For this profile, the structuring analysis must begin well before the application, because the product itself must be designed to meet the regulatory requirements.
A non-EU business seeking to onboard EU clients without establishing a CASP entity faces the reverse solicitation question. MiCA provides a narrow reverse solicitation carve-out – a third-country operator may service an EU client who approaches it on the client's own initiative without CASP authorisation – but the carve-out is interpreted strictly, and marketing activity directed at EU residents, including social-media activity, website accessibility and paid distribution, is generally incompatible with a reverse solicitation claim. Businesses relying on this carve-out as a business model are exposed.
What Are the Most Common Mistakes in EU MiCA Applications?
In our cross-border practice, the mistakes that most consistently cause delay or refusal in CASP applications fall into a predictable set. Identifying them at the planning stage is materially less costly than rectifying them mid-process.
The first and most frequent is activity-scope underestimation. Applicants frequently map only their primary product function to the MiCA service list and overlook ancillary activities that independently trigger regulated status. A business that holds client funds pending settlement is performing custody, even if it does not market itself as a custodian. A business that executes client orders at its own discretion on a discretionary basis is performing portfolio management. The application scope must reflect all services actually performed.
The second is substance planning left too late. NCA fitness reviews are increasingly granular on the questions of where management decisions are actually made, which individuals have authority to bind the entity, and whether the licensed entity's systems and controls are genuinely operational in the home member state. A business that plans to satisfy substance requirements by hiring a local compliance officer and a part-time director, while all real management sits in a third country, is unlikely to satisfy a diligent NCA review.
The third is the whitepaper trap. Token issuers frequently treat the MiCA whitepaper as a disclosure document to be prepared once and filed. In practice, the whitepaper is a living regulatory document: material changes to the token structure, the rights of holders or the issuer's business model may require a revised whitepaper and fresh notification. Businesses that modify their product post-launch without reassessing whitepaper accuracy face ongoing liability under the false-statement provisions of the regulation.
A recent matter illustrates the application timeline issue clearly. An EU-facing exchange operator engaged us in the early stages of a CASP application in a mid-size EU member state. The initial scope identified two regulated services. Our review of the product architecture identified four additional services that the platform was already performing in beta. Rescoping the application before submission added several weeks to the preparation phase but avoided what would likely have been a deficiency notice and a multi-month delay after filing.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – our practice-wide approach to regulatory authorisation across 70+ jurisdictions.
- Licence Renewal and Variation in Georgia – how licensing maintenance works in a comparable emerging VASP regime.
- Staking Service Legal Framework Under Heightened Scrutiny – regulatory treatment of staking within and beyond the MiCA environment.
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the statutory review period runs from the point a complete application is accepted by the national competent authority. In practice, the total elapsed time from initial preparation to authorisation – accounting for pre-application engagement, document preparation and the NCA's review period – typically spans several months and can extend further depending on the complexity of the application and the NCA's current workload. Selecting a well-prepared application and an NCA with relevant experience materially reduces the risk of avoidable delay.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The optimal EU home member state depends on the business model, the services offered, the management substance available, the banking environment and the NCA's track record with comparable applications. Lithuania, Malta, the Netherlands and Germany each offer distinct advantages and trade-offs. The right choice is made after mapping the activity scope, the capital position and the operational timeline – not by reference to a general reputation for speed or leniency.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated service requiring explicit authorisation. If your business holds client assets – even temporarily, or as an ancillary function of a trading or payment service – the custody permission must be included in your CASP authorisation. A business authorised only for exchange or order execution that also holds client assets without a custody authorisation is operating outside its licence scope. The analysis requires a factual review of how assets flow through the platform.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is the one that works when regulators look at it. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy and multi-jurisdiction licence stacking for digital-asset businesses entering EU-regulated markets.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.