EST · MMXXVI
Home/Jurisdictions/Eu Mica/CASP authorisation under mica in European Union (MiCA)
Licensing & Registration

CASP authorisation under mica in European Union (MiCA)

Casp authorisation under mica in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

As regulators across the European Union converge on a unified licensing regime for crypto-asset businesses, operating without the right authorisation is no longer a manageable risk — it is an enforcement trigger. A CASP (crypto-asset service provider) authorisation under MiCA (the Markets in Crypto-Assets Regulation) is now the baseline licence for any business offering regulated crypto-asset services to clients in the EU or EEA. Without it, the business faces blocked banking, frozen payment rails and, increasingly, formal supervisory action by ESMA (the European Securities and Markets Authority) or a national competent authority.

This page sets out what CASP authorisation requires, how the process runs in practice, where the cross-border complexity enters, and the decision points an inbound operator needs to resolve before filing.

What is CASP authorisation under MiCA and who needs it?

CASP authorisation is the mandatory licence for businesses providing regulated crypto-asset services within the EU under the MiCA regime. The regulated perimeter is broad. It covers exchange, custody, brokerage, portfolio management, advisory, transfer and other defined activities carried out on a professional basis. If your business touches EU or EEA clients through any of those activities — regardless of where the entity sits — the question of MiCA compliance is live from day one.

The threshold is activity-based, not entity-based. A Cayman-incorporated exchange routing order flow to German retail clients is inside the perimeter. A US custodian holding digital assets for an Amsterdam fund is potentially inside it. The reverse solicitation carve-out — the narrow exemption for services initiated entirely at the client's request — is interpreted strictly by national competent authorities, and regulators have made clear they will not allow it to swallow the rule.

MiCA distinguishes between three principal token categories: ARTs (asset-referenced tokens, pegged to multiple assets), EMTs (e-money tokens, pegged to a single fiat currency) and all other crypto-assets. Each carries different obligations. An operator issuing an EMT needs a separate authorisation beyond the CASP licence itself. A business dealing only in the third category — utility tokens, exchange tokens, most altcoins — works primarily through the CASP authorisation track.

In our licensing practice, the first conversation we have with an inbound EU operator is about scope: which activities trigger which authorisations, and whether any of the existing exemptions apply. Getting that boundary wrong at the outset costs months.

Which competent authority issues the CASP licence?

Authorisation is granted by the national competent authority (NCA) of the EU member state in which the applicant is established — not by ESMA directly. ESMA coordinates and publishes technical standards, but the licensing decision sits with the NCA. Once a CASP licence is granted in one member state, the business may passport that authorisation across the entire EU and EEA without re-applying in each country.

Passporting is the central commercial logic of the MiCA regime. It is also the primary driver of member-state selection. Lithuania, Malta, Ireland and Luxembourg have all received significant volumes of inbound applications. Each NCA has its own processing culture, staffing depth and familiarity with crypto-specific business models. The choice of home member state is as much a practical question as a legal one.

The MFSA in Malta, the Bank of Lithuania and the relevant Irish and Luxembourg authorities are all working through an expanding application pipeline. Timelines vary — and the system prompt discipline here is important: we describe timelines qualitatively, because each NCA has its own published guidance and pipeline, and figures change. What operators consistently find is that thorough pre-application engagement with the NCA materially shortens the formal review clock.

For a scoped assessment of your EU licensing strategy, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity structure, the user base, the banking position — change the analysis, and the earlier we map that, the fewer surprises the application generates.

What does the CASP application process actually require?

A MiCA CASP application is a structured submission to the NCA covering legal, governance, operational and AML/CFT dimensions simultaneously. There is no sequential gateway — the NCA reviews the full package, and gaps in any part of it trigger requests for information that reset the clock.

The submission set typically includes: a detailed business plan and financial projections; a governance structure showing senior management fitness and propriety; evidence of own-funds compliance for the relevant licence category; a technology and security assessment; client asset safeguarding arrangements; and a full AML/CFT programme meeting the obligations of the FATF Recommendations as implemented under EU anti-money-laundering law, including the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer).

The MiCA whitepaper obligation sits alongside the CASP authorisation for many operators. Businesses issuing crypto-assets to the public must produce a compliant whitepaper and notify the NCA before publication. This is not the same document as the application file, and conflating the two timelines is a common structural error.

Governance depth is one area where applications consistently fall short. MiCA requires that at least two natural persons effectively direct the business, that they meet fit-and-proper standards, and that the legal entity is genuinely established in the home member state — not merely a letterbox. NCAs are applying substance tests with increasing rigour. A registered address and one part-time director do not clear the threshold.

In our practice, we work through the governance architecture before anything else. If the entity structure cannot support a substance showing in the chosen member state, the application is not ready — and submitting it prematurely costs the applicant time and credibility with the NCA.

How does MiCA interact with banking and payment rails for a CASP?

Banking is the other half of the CASP problem — and it is the half that most licensing plans underweight. Holding a MiCA authorisation does not, by itself, open a bank account. EU-licensed crypto businesses still face significant friction with correspondent and retail banking, and that friction is structural, not incidental.

The client asset safeguarding rules under MiCA require a CASP to segregate client funds — either in a credit institution account or, in some cases, through alternative safeguarding structures. This means the business must resolve banking before it can operationally comply with the licence it holds. It is a circular problem for businesses that enter the EU without a banking relationship already established.

The cross-border dimension adds further complexity. An operator headquartered in Dubai with a MiCA licence faces the question of whether its VARA (Virtual Assets Regulatory Authority) authorisation in the UAE provides any banking comfort in Europe. Generally, it does not. Each jurisdiction's banking relationships are managed separately, and EU correspondent banks apply their own AML/CFT due diligence regardless of offshore licences held.

For businesses operating between the EU and a non-EU hub — say, a Singapore-licensed MAS DPT service provider that also wants EU passporting — the banking map must be drawn at the outset, not treated as a downstream problem. We have seen applications stall for a year because the entity could not demonstrate a compliant safeguarding structure to the NCA. That is a banking problem dressed as a licensing problem.

What are the AML and Travel Rule obligations for CASPs under MiCA?

MiCA authorisation sits alongside, not instead of, the EU's AML/CFT regime — and for VASP-category businesses, compliance with the Travel Rule is a condition of operation, not a future obligation. The Travel Rule requires a CASP to collect, verify and transmit originator and beneficiary information with every virtual-asset transfer above the applicable threshold. Regulators across the EU expect working Travel Rule solutions at the point of authorisation, not post-licensing.

The AML programme required for a MiCA application is substantive. It must reflect the specific risk profile of the business: the assets traded, the customer base, the geographies served and the on-chain transaction types processed. A generic financial institution AML policy repurposed for a crypto application is one of the most reliable ways to generate an NCA request for information — and therefore a delay.

FATF Recommendation 15 anchors the international baseline. Its implementation into EU law means the obligations apply with direct effect across all member states, and the incoming EU AML Authority (AMLA) will add further convergence of supervisory standards over the coming years. Businesses building a MiCA compliance programme today should design it to accommodate that trajectory, not merely to pass the current authorisation file review.

In a recent licensing matter, a payments company seeking CASP authorisation had a strong technology stack but a Travel Rule implementation that covered only VASP-to-VASP transfers — missing the unhosted-wallet screening obligations. We restructured the AML programme before submission, and the NCA's review proceeded without a material information request on AML grounds. That is the kind of pre-submission work that turns a twelve-month process into a manageable one.

How does MiCA interact with tax and cross-border structuring?

The choice of home member state for CASP authorisation creates a tax residence decision that most operators treat as secondary — and should not. Corporate tax rates, the availability of IP or innovation regimes, the treatment of staking income and token disposals, and the presence of a VAT/GST exemption for financial services all vary across the EU. Passporting the licence into other member states does not change the home-state tax base.

A business that selects Lithuania for its fast-entry profile and lower operational cost may find that its effective tax position diverges materially from one that selects Ireland for its broader network of double-tax treaties. Neither answer is universally correct. The right answer depends on where the group's economic activity sits, where the principals are resident, and what the entity's downstream fundraising or exit profile looks like.

Token issuance adds another dimension. If the business issues an EMT or ART alongside its CASP services, the reserve requirements and redemption obligations under MiCA interact with the entity's balance sheet in ways that need to be modelled before the licence is granted — not after. We regularly advise on the capital and reserve architecture for issuers who need both the CASP authorisation and the token issuance permissions to be operative at launch.

The DAC8 directive — the EU's tax reporting framework for crypto-asset operators — further expands the compliance footprint of a MiCA-authorised entity. CASPs must report client transaction data to relevant tax authorities. Building that reporting infrastructure costs time and money. Operators who plan for it in the initial technology build absorb the cost more efficiently than those who retrofit it.

To map the licence, banking and tax stack for your EU build, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship fell through, a second read of the structure often surfaces the cause and the route back.

Which operator profile should choose MiCA CASP authorisation — and which should not?

The decision matrix for MiCA CASP is cleaner than for most offshore regimes, because the EU market access question is binary: either you have the authorisation, or you are excluded from serving EU clients professionally. The real decision is not whether to pursue MiCA, but which entity structure, home member state and licence scope are right for the business.

Profile A — the EU-focused exchange or brokerage. An operator whose primary market is EU retail or institutional clients, with a single-entity structure, should pursue CASP authorisation directly. The passport delivers access to all twenty-seven member states, and the NCA of a smaller, crypto-experienced member state offers a realistic timeline. Own-funds compliance, governance substance and a working AML programme are the key gating items.

Profile B — the global platform adding EU access. A business already licensed under MAS, SFC, VARA or the FCA seeking to add EU market access faces a more complex build. It will typically need a separate EU entity — established with genuine substance in the chosen member state — that holds the CASP authorisation, while the group structure manages intra-group agreements, transfer pricing and interoperability between the regimes. The risk here is regulatory arbitrage scrutiny: NCAs are attentive to applicants that use EU entities as thin wrappers for non-EU operations.

Profile C — the token issuer. A business issuing ARTs or EMTs needs the CASP authorisation for its service activities and a separate authorisation (or notification) track for the token itself. The two processes run in parallel but are reviewed by the NCA as a combined picture of the operator's regulatory fitness. Launching the token ahead of authorisation is a common and costly mistake.

A common assumption among operators new to the EU market is that a single offshore licence — a BVI registration, a Cayman exemption, or a VASP registration in a jurisdiction outside the EU — is sufficient to serve EU clients. It is not. MiCA's reach is explicit: services directed at EU clients require EU authorisation. The regulatory and reputational cost of enforcement action far exceeds the cost of a properly structured CASP application.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline for CASP authorisation under MiCA varies by the chosen national competent authority and the completeness of the submission. NCAs with established crypto-licensing capacity and a well-prepared application typically process within a number of months, while complex or incomplete submissions can take considerably longer. Operators should factor in pre-application engagement time, which materially reduces the formal review period. We recommend building at least six to twelve months of runway before a target commercial launch date.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on your target market, entity structure, banking relationships, governance capacity and tax position. For EU market access, MiCA CASP authorisation in a crypto-experienced member state delivers the broadest reach via passporting. For businesses targeting Asia-Pacific, MAS or SFC authorisation may be more relevant. For lighter-touch offshore structuring, VARA, ADGM or Cayman structures serve different purposes. OBOLUS maps the full stack against your specific profile before recommending a path.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated CASP activity. If your business holds client assets — whether as a primary service or incidental to another activity such as exchange or lending — the custody permission must be included in your CASP authorisation. Operating custody without that permission is a breach of the authorisation terms. Some structures separate the custody entity from the trading entity, each holding its own authorisation, for liability management and regulatory clarity reasons. The right structure depends on the business model.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — so the authorisation your business holds matches the services it actually provides. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when assets are at risk. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialises in MiCA CASP authorisation, EU regulatory structuring and multi-hub licensing strategy for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours