Germany sits at the intersection of Europe's most demanding supervisory tradition and the EU's emerging MiCA (Markets in Crypto-Assets Regulation) passporting regime. For any business that wants to operate a crypto exchange, provide custody, or issue digital assets with German clients in scope, the question is not whether BaFin applies – it is which authorisation track the business falls onto, and how the German layer interacts with what the operator already holds or is building elsewhere.
Operating without the correct authorisation in Germany exposes a business to enforcement action, account termination and reputational harm that can follow the founders across other licence applications. That risk is not hypothetical. BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) has a consistent record of issuing cease-and-desist orders against unlicensed crypto operators targeting German residents. The structural question – which authorisation, at what legal entity, for which activity – must be answered before a product goes live, not after.
This page covers the BaFin supervisory perimeter, the principal licence categories available to digital-asset businesses, the cross-border reality for inbound operators, and the practical considerations that shape the authorisation path. Where specific capital thresholds, fees or timelines are not yet confirmed in the verified facts we rely on, we say so clearly and write qualitatively – because invented figures mislead more than they help.
Who Is BaFin, and Why Does It Set the Standard?
BaFin is the German federal financial supervisory authority, responsible for banking, securities, insurance and – since the adoption of the Crypto Assets Act provisions that brought crypto custody and trading into the German Banking Act perimeter – digital-asset businesses. It supervises from its Frankfurt and Bonn offices and is known across the EU for granular application reviews and a strong enforcement posture.
Germany was among the first major EU member states to classify crypto custody as a regulated financial service in its own right. That early-mover decision created a licensing environment that is detailed and demanding, but also one that carries weight. A BaFin authorisation signals to institutional counterparties, banks and custodians that a business has cleared a high supervisory bar. Operators we advise routinely find that a BaFin authorisation shortens the conversation with correspondent banking partners and accelerates onboarding with institutional clients who require regulated-entity status from their service providers.
Under MiCA, ESMA and the national competent authorities – BaFin among them – form the supervisory network through which CASP (crypto-asset service provider) authorisations are issued. Germany's NCA role means that a German CASP authorisation will carry EU-wide passporting rights, making the jurisdiction a structurally important choice for operators targeting the EU market from a single legal entity.
What Activity Falls Inside the German Regulatory Perimeter?
The regulated perimeter in Germany is broad and has been extended progressively to cover the activities that define a digital-asset business. Crypto custody – holding private keys or controlling access to digital assets on behalf of clients – became a regulated financial service under the German Banking Act before MiCA came into force, giving BaFin early and explicit jurisdiction over custodians. That position is now reinforced and extended by MiCA's CASP framework.
The activities that currently require authorisation or registration under the German regime, or under MiCA as implemented, include: operating a crypto-asset trading platform; providing exchange services (crypto-to-fiat and crypto-to-crypto); custody and administration of crypto assets on behalf of third parties; placing or underwriting crypto-asset offerings; and providing advice in connection with crypto assets. Stablecoin issuance – particularly issuance of asset-referenced tokens (ARTs) and e-money tokens (EMTs) as defined under MiCA – carries its own authorisation obligations that sit above the baseline CASP requirement.
The perimeter also captures businesses incorporated outside Germany that actively solicit or serve German residents. BaFin applies an effects-based analysis: if the service reaches German clients through active marketing, localised platforms or German-language onboarding, the activity is in scope regardless of where the legal entity is incorporated. This is the cross-border fact pattern that most frequently surprises operators who assumed their offshore licence was sufficient.
A common assumption is that a single offshore licence covers all markets. It does not. Offshore registration in a tier-2 jurisdiction addresses AML/CFT compliance for the registering state. It does not constitute authorisation to provide regulated financial services in Germany, the EU or any other jurisdiction where a substantive licence is required. Operators we advise who relied on an offshore registration to enter the German market have subsequently had to retrofit a BaFin-compliant structure at considerably greater cost and delay than if the German authorisation had been obtained first.
What Are the Principal Licence Categories for Digital-Asset Businesses?
Germany's digital-asset authorisation architecture sits across two overlapping regimes: the existing German Banking Act (KWG) and related financial services law, and the MiCA CASP framework now in its implementation phase. The categories that matter most to an inbound operator are as follows.
Crypto custody services – safeguarding and administration of crypto assets – require a dedicated authorisation that BaFin has treated as a distinct regulated activity since its introduction into the Banking Act. This is not a light-touch registration; BaFin expects a material presence, a qualified management team with demonstrable relevant experience, and documented operational and risk management frameworks before it will grant the licence.
Exchange and brokerage services require a securities trading licence or equivalent financial services authorisation where the assets meet the definition of financial instruments, and will require a CASP authorisation under MiCA for activities involving crypto assets that fall under that regulation's scope. The line between financial-instrument-based activity (FCA territory in the traditional sense, and BaFin under German law) and MiCA-based activity turns on the nature of the asset – a question BaFin analyses on a case-by-case basis and one where legal pre-classification is essential before filing.
Stablecoin issuers face the most demanding authorisation track. ART issuers require prior authorisation from BaFin as the competent NCA, with detailed reserve, governance and redemption requirements flowing from MiCA. EMT issuers must hold a German banking licence or e-money institution licence. Neither route is quick or inexpensive, and both require significant operational and financial substance before an application is credible.
For operators whose activity falls below the full CASP authorisation threshold – for example, certain token-offering advisory services or infrastructure providers – a registration or notification regime may apply, but BaFin's analysis of these borderline cases is fact-specific, and the consequences of misclassifying the activity as exempt are severe.
To get a scoped assessment of which authorisation category applies to your activity, contact OBOLUS at info@oboluslaw.com. The process above describes the standard categories. Your facts – the asset types, the client base, the technology stack, the entity structure – change the analysis materially. Map your options.
How Does the BaFin Application Process Work?
The BaFin authorisation process is document-intensive and sequential: BaFin will not begin substantive review of an application until it considers the file complete, and it applies completeness standards rigorously. This makes pre-application preparation – aligning the corporate structure, the AML programme, the governance framework and the personnel qualifications before submission – the most important phase of the process.
A typical application requires a detailed business plan, evidence of the required capital base, a full description of the IT and custody infrastructure, an AML/KYC programme that meets both the German AML Act and the broader FATF Recommendations (including the Travel Rule – the obligation to pass originator and beneficiary data with each virtual-asset transfer), fit-and-proper documentation for each member of the management team, and a qualified-personnel showing for the specific regulated activity.
BaFin is known for issuing supplementary information requests after the initial submission. In our cross-border practice, we have seen applications stall at the completeness stage when the AML programme lacks granularity on Travel Rule compliance for cross-border transfers, or when the management team cannot demonstrate direct experience in the regulated activity being applied for rather than analogous financial services experience generally. These are correctable issues, but they add materially to the timeline if they are discovered after filing rather than addressed in preparation.
Timeline varies by licence category and by the volume of applications pending at BaFin at the time of submission. BaFin is not among the faster EU supervisors on processing time; operators should plan for a process measured in months, not weeks, and build that into their go-to-market schedule accordingly. Attempting to operate during the review period – before the licence is granted – is a regulatory violation with consequences for the application itself.
In a recent licensing matter, a digital-asset exchange incorporated in an EU member state sought to establish a German subsidiary to operate a custody and trading service for institutional clients. We identified that the intended activity split across two separate authorisation tracks – a financial services licence under the Banking Act for the securities-related activity and a CASP pre-authorisation filing for the crypto-specific services. We restructured the entity plan and prepared a consolidated application that addressed both tracks concurrently, reducing the total supervisory engagement timeline and avoiding a sequential filing that would have delayed launch by a further two quarters.
AML, the Travel Rule, and BaFin's Supervisory Expectations
Germany's AML regime for digital-asset businesses is among the most developed in Europe, reflecting the country's position as a major FATF member state and its early legislative engagement with crypto as a financial service. BaFin supervises compliance with the German AML Act as it applies to VASPs and crypto custodians, and its expectations track FATF Recommendation 15 and the associated Travel Rule guidance closely.
The Travel Rule requires that originator and beneficiary data travel with every covered virtual-asset transfer. BaFin expects licensed entities to have a functioning Travel Rule implementation – not a plan to implement one post-licence – as a condition of authorisation. Specifically, this means operating a Travel Rule solution that can exchange the required data with counterparty VASPs, handle the sunrise-problem scenarios (transfers to or from jurisdictions without Travel Rule implementation), and produce records for supervisory review. Absent a satisfactory answer to each of these questions in the application, BaFin will request further information or decline to progress the file.
KYC expectations at BaFin follow the European AML Directive structure as transposed into German law, with enhanced due diligence obligations applying to higher-risk clients and products. Wallet screening, transaction monitoring and suspicious activity reporting are baseline requirements. BaFin has conducted thematic reviews of AML controls at licensed entities, and operators we advise treat those supervisory findings as a practical guide to the standard BaFin expects, not merely a post-licence compliance exercise.
Cross-border AML complexity is a particular pressure point for Germany-licensed entities serving clients across the EU and beyond. Where a German-licensed exchange transfers assets to or from a client using a non-custodial wallet, BaFin expects a documented risk assessment and, where appropriate, enhanced due diligence measures. The regulator's approach to unhosted wallets has become progressively more detailed, and operators need a written policy that reflects current BaFin guidance before they file.
If a prior application stalled on AML completeness grounds or your Travel Rule implementation was flagged, a second review of the programme can identify the structural gap. Write to info@oboluslaw.com to start that conversation, or map your options with us directly.
How Does Germany Fit Into the MiCA Transition for EU Operators?
MiCA establishes a single EU-wide authorisation regime for crypto-asset service providers. A CASP authorisation issued by BaFin allows the holder to passport its services across the EU and EEA without seeking separate authorisation in each member state – a structurally significant benefit for an operator whose target market is continental Europe as a whole.
Germany entered the MiCA transition period with an existing body of national crypto regulation. Businesses already holding BaFin licences under the prior national framework benefit from a transitional period under which existing authorisations are treated as equivalent, subject to the operator completing the formal CASP authorisation process. New entrants must file directly under the MiCA CASP framework, with BaFin as the supervising NCA.
The choice of Germany as the EU passporting base involves a genuine trade-off. BaFin is demanding – its application process requires more substance, more documentation and more senior management engagement than several other EU NCAs. The payoff is supervisory credibility. Institutional counterparties, prime brokers and tier-one banking partners treat a BaFin-authorised entity differently from a CASP authorised by a smaller NCA. For operators targeting institutional clients or building infrastructure products for regulated entities, that credibility differential is a commercial consideration, not merely a regulatory one.
Operators considering whether to base their EU CASP in Germany or in an alternative member state – Lithuania or Malta are common comparators – should weigh the application burden against the target market, the banking relationships required, and the long-term supervisory relationship they want with their NCA. In our cross-border practice, we map that trade-off against the specific business model before recommending a jurisdiction, because the right answer is not the same for a retail exchange, a custody provider and an ART issuer.
How Do Banking and Tax Interact With a BaFin Licence?
Obtaining a BaFin licence solves the regulatory authorisation question. It does not automatically solve the banking question, which remains one of the most practically constraining issues in digital-asset business. German banks operate under their own AML and business-acceptance policies, and while a BaFin authorisation significantly improves a business's banking prospects, it does not guarantee account access.
Operators we advise pursue banking in parallel with the licence application. The practical approach is to identify banking partners with a demonstrated appetite for regulated digital-asset businesses, provide them with the application filing confirmation and the draft compliance programme, and work toward conditional account opening that closes when the licence is granted. Attempting to source banking after the licence is in hand typically adds months to the operational launch timeline.
On the tax side, Germany applies its general corporate and income tax regime to digital-asset businesses, with specific guidance from the German Federal Central Tax Office on the treatment of crypto transactions. The VAT treatment of exchange and brokerage services has been addressed in German tax authority guidance, but the position for newer products – token issuance, staking, DeFi-adjacent services – involves fact-specific analysis. Cross-border tax structuring for a German-licensed entity – particularly where the group includes holding companies in other jurisdictions – requires dedicated counsel, and BaFin will expect that the tax structure does not create regulatory arbitrage or obscure the substance of the regulated activity in Germany. Specific tax rates and thresholds vary and should be confirmed with current legislation and qualified tax advice before any structure is committed.
How Does Germany Compare for an Inbound Operator?
Germany is a demanding but commercially compelling licensing jurisdiction for an inbound digital-asset operator. The demand side is clear: Germany is the largest economy in Europe, with a sophisticated institutional investor base, deep capital markets infrastructure, and a growing retail appetite for regulated digital-asset products. An operator that can serve German clients from a BaFin-authorised entity is positioned to serve the full EU market via MiCA passporting.
The supply side – the cost and complexity of achieving BaFin authorisation – is equally real. The application process is not accessible to undercapitalised or under-resourced operators. BaFin expects a management team with relevant regulated-financial-services experience, an operational infrastructure that can support a supervised entity, and an AML programme that is complete, documented and tested before the file is submitted. Operators who meet those requirements and commit the time and resource to the process typically find BaFin to be a predictable regulator – rigorous, but not arbitrary.
For comparison, an operator whose primary market is retail EU clients but whose management team is new to European regulation may find Lithuania or Malta a more accessible first entry point under MiCA, with a subsequent passporting notification covering Germany without a full German application. For an operator whose target client base is institutional – funds, banks, regulated entities that require their service providers to hold substantive supervisory authorisations – starting with BaFin is often the commercially correct decision, even if it takes longer and costs more. Allied counsel in the relevant jurisdiction can provide a current comparative read on NCA appetite and processing timelines where that comparison matters to the decision.
A digital-asset fund seeking a custodian for its German institutional clients engaged us in the early stages of its European structuring. The fund had been advised by its corporate lawyers to register in a lighter-touch jurisdiction and passport. We identified that its institutional LP base – primarily German pension-adjacent vehicles – required their service providers to be BaFin-authorised, not merely MiCA-passported from another NCA. We redirected the structure toward a German entity as the primary licensed vehicle, which resolved the counterparty requirement before the fund held its first close.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we scope and manage the full licence stack across operating, custody and payment layers.
- Lithuania vs Malta: Where to License a Crypto Business – a comparative analysis of two leading EU CASP jurisdictions for operators weighing their entry point.
- DeFi Protocol Legal Structuring in Kazakhstan (AIFC) – for operators building in the AIFC common-law zone and managing cross-border regulatory exposure.
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and by licence category. BaFin is among the more thorough EU supervisors; operators should plan for a process measured in months from a complete application submission, not weeks. Pre-application preparation – aligning governance, AML documentation, capital and personnel – is the phase that most directly shortens the overall timeline, because BaFin will not begin substantive review until the file is complete. Lighter-touch EU jurisdictions can be faster, but carry different trade-offs against supervisory credibility and institutional counterparty acceptance.
Which jurisdiction is best for licensing my crypto business?
There is no single correct answer. The right jurisdiction turns on the target market, the client profile, the activity being regulated, the banking relationships needed, and the operator's capacity to meet the supervisory substance requirements of the chosen regime. For EU-market access, Germany offers BaFin credibility and full MiCA passporting; Lithuania and Malta offer accessible entry under the same MiCA framework. For businesses targeting global institutional clients, the substance expectations of a demanding NCA are often a commercial asset, not just a regulatory cost. We map that decision against the specific business model before recommending a path.
Do I need a separate custody licence?
In Germany, crypto custody – safeguarding and administration of digital assets on behalf of clients – has been a separately regulated financial service since its introduction into the Banking Act, and BaFin treats it as a distinct authorisation obligation. An exchange licence does not automatically cover custody. Under MiCA, custody and administration of crypto assets on behalf of third parties is one of the defined CASP activities requiring explicit authorisation. Whether a separate application or a combined multi-activity CASP authorisation is the appropriate route depends on the scope of the business; this is a pre-filing classification question that should be resolved with legal counsel before the application is structured.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit to a structure – so the authorisation question is answered before the product goes live, not after. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and cross-border digital-asset authorisation strategy, with a focus on BaFin, MiCA and multi-hub licence structuring for exchanges and custodians.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.