As regulatory regimes across the major financial hubs converge on the MiCA (Markets in Crypto-Assets Regulation) model, an exchange operator considering European market access faces a concrete legal question: which authorisation is required, in which member state, and what does the process actually involve? Operating without the right licence risks enforcement action, disrupted banking relationships and frozen payment rails – consequences that arrive faster than most operators expect and are expensive to unwind.
Setting up a crypto exchange in the European Union under MiCA requires a CASP authorisation (Crypto-Asset Service Provider authorisation) issued by a national competent authority in a chosen member state, conferring an EU-wide passport. The authorisation covers the specific crypto-asset services an operator intends to provide – exchange against fiat, exchange against other crypto-assets, execution of orders, operation of a trading platform, or a combination. The regime is administered jointly by ESMA and the relevant national competent authorities, with ESMA maintaining a public register of authorised CASPs. This page maps the regulated basis, the application process for an inbound business, the cross-border interactions that shape where and how to set up, and the decision points that determine whether MiCA is the right primary domicile for your exchange.
What is the regulatory basis for running a crypto exchange in the EU?
Running a crypto exchange in the European Union is a regulated activity under MiCA, and any operator serving EU clients – whether established inside or outside the bloc – must either hold a CASP authorisation or rely on an applicable transitional arrangement. The applicable regime is administered by national competent authorities designated under MiCA, with ESMA exercising a supervisory convergence role across the single market. The regulated perimeter is defined by the services provided, not merely by where the legal entity sits; an exchange incorporated outside the EU that actively solicits or onboards EU retail clients is within scope.
MiCA distinguishes three categories of crypto-asset that determine what obligations apply to issuers and service providers: asset-referenced tokens (ARTs), e-money tokens (EMTs), and all other crypto-assets. For a crypto exchange, the critical category is "other crypto-assets," which covers most utility tokens and pure payment tokens. If the exchange lists ARTs or EMTs, the issuer-side obligations under MiCA become relevant to the listing diligence process. The service-provider side – running the order book and executing trades – requires a CASP authorisation regardless of which token categories are listed.
The passporting mechanism is the strategic value of the MiCA regime. A CASP authorised in one member state may provide its regulated services across all EU and EEA member states without seeking separate national authorisations. This replaces the prior patchwork of national VASP registration regimes – which varied significantly in scope, cost and timeline – with a single, portable licence. For an exchange targeting a genuinely pan-European user base, this is the defining structural advantage.
CTA #1 — For a first read of the authorisation path
The regulated perimeter above defines the standard case. Your specific facts – the services you intend to offer, the member state you are considering, the corporate structure and the user base geography – will materially affect which national authority is the right counterpart and how the application is structured. For a scoped assessment of your situation, contact OBOLUS at info@oboluslaw.com or map your options.
What does the CASP application process involve under MiCA?
A CASP application under MiCA is a structured dossier submitted to the chosen member state's national competent authority, covering the business plan, governance, capital adequacy, AML/CFT programme, custody arrangements and management suitability. The process is sequential – application submission, completeness check, substantive review, a decision – and the timeline varies by national authority. ESMA's supervisory convergence work is narrowing the variation across member states, but in our practice we consistently see meaningful differences in review pace, depth of initial queries and documentation standards between the busier and less-trafficked NCAs.
The dossier components that most commonly drive delays or rejections are not the headline capital or governance figures. They are the AML/CFT programme – which must demonstrate a credible, operationally deployed compliance function, not a theoretical policy document – and the management-suitability assessments, which require sufficient time to prepare properly. Regulators increasingly expect the people named in the application to be available for direct engagement. An application filed on behalf of a management team that is entirely based outside the jurisdiction of the chosen NCA will receive closer scrutiny.
The Travel Rule (the obligation, under FATF Recommendation 15 and its MiCA-aligned implementation, to pass originator and beneficiary data with each crypto-asset transfer) must be addressed in the application as an operational matter, not an aspirational one. An exchange that cannot demonstrate Travel Rule compliance as a live operational capability at the point of application is unlikely to complete the process cleanly.
Whitepaper obligations apply to token issuers listing through the exchange. The exchange operator's own obligations are on the service side, but due diligence on tokens listed for trading is part of the MiCA compliance picture. Operators that plan to list a broad range of tokens should address the listing review process in their business plan from the outset.
How do you choose the right member state for your CASP authorisation?
The choice of member state for a CASP authorisation turns on several factors that interact: the relative pace and predictability of the national competent authority, the corporate law environment, the availability of banking relationships, the tax regime for the operating entity and the practical cost of building a compliant local presence. No single member state is optimal for every operator profile.
Lithuania, historically a fast EU entry point under the prior VASP notification regime administered by the Bank of Lithuania, has transitioned to the MiCA CASP framework. The Bank of Lithuania is the national competent authority. Operators that built Lithuanian structures under the old regime must assess whether those structures satisfy the CASP authorisation requirements – the threshold is materially higher. For new entrants, Lithuania remains a considered option where the operator can demonstrate a credible local presence and operational deployment.
Malta's MFSA administers a VFA framework that is transitioning to MiCA CASP authorisation. Malta's prior regime introduced the concept of a VFA agent – an MFSA-licensed intermediary that prepares and files applications – and this structural feature persists in the transition period. Operators with existing Maltese structures should map the transition timeline carefully.
In our cross-border practice, we regularly advise operators to evaluate member state selection not on the basis of perceived regulatory leniency – a standard that has no legal content under a harmonised regime – but on the basis of NCA responsiveness, the depth of the local legal and compliance market, and the banking environment. An authorisation from a member state whose banks will not open accounts for crypto businesses has limited practical value.
What are the cross-border tax and banking interactions?
The tax and banking dimensions of a MiCA CASP structure are, in practice, as consequential as the regulatory authorisation itself. An exchange entity that holds a CASP authorisation but cannot access stable banking rails is operationally constrained in ways that affect client money handling, fiat on/off ramp capability and the ability to pay operational costs.
Banking for crypto exchanges in the EU is available but not uniform. The number of EU-regulated credit institutions willing to provide transaction banking to a CASP-authorised exchange has grown as the MiCA regime has matured, but willingness varies significantly by member state, by the exchange's business model (retail versus institutional, the range of tokens listed) and by the volume and provenance of client fiat flows. An application supported by a documented banking relationship – or by a credible roadmap to one – is received differently than one that treats banking as a post-authorisation problem.
On the tax side, the corporate tax treatment of crypto-asset trading profits, the VAT/GST treatment of exchange fees and the treatment of token transfers vary across member states. MiCA harmonises the regulatory perimeter; it does not harmonise tax. An exchange operator choosing a member state for its CASP authorisation is simultaneously choosing a corporate tax domicile, and the two decisions should be made together. In jurisdictions where the exchange entity will also custody client assets, the interaction between custody obligations under MiCA and the local accounting and tax treatment of client asset segregation is a structural point that benefits from early-stage advice.
For operators with a non-EU parent or a parallel offshore structure – a Cayman fund, a BVI holding company, a Singapore entity – the cross-border interaction between the EU CASP entity and the wider group raises questions of intra-group service arrangements, transfer pricing and the substance requirements of both the EU member state and the offshore domicile. The EU's CASP authorisation requirements for management and control are specific enough that a purely nominee local presence is unlikely to survive supervisory review.
What are the most common mistakes operators make in EU crypto exchange setup?
Operating a crypto exchange in the EU without the right authorisation is the foundational mistake – and it is more common than the headline enforcement actions suggest, because many operators are not certain whether their model falls within the MiCA perimeter until a regulator tells them it does. Uncertainty is not a defence. The obligation to seek authorisation arises when the regulated activity commences, not when the operator decides it is ready to apply.
The second most common mistake is misreading the scope of passporting. A CASP authorised in member state A does not automatically become compliant with every national-level requirement in member state B simply by virtue of the passport. Local AML/CFT reporting obligations, local advertising rules and – critically – local language and disclosure obligations may apply. Operators that treat the passport as a wholesale exemption from local engagement tend to surface compliance gaps at the worst possible moment.
A third structural error is the failure to separate the operating entity (the CASP) from the custody function. MiCA treats the custody and administration of crypto-assets on behalf of clients as a distinct regulated service. An exchange that also holds client assets in its own wallets may be providing both exchange services and custody services. If the custody function is not properly scoped in the CASP authorisation and operationally separated, the compliance picture is incomplete. We regularly advise on the restructuring of exchange architectures to address exactly this point – typically after an initial application has surfaced the question and the operator needs a clean structural answer before resubmitting.
A common assumption is that a single offshore VASP registration – a BVI or Cayman entry, for instance – is sufficient to serve EU clients legally. It is not. MiCA applies to operators that actively target EU clients regardless of where the corporate entity is incorporated. The reverse solicitation exemption is narrow and is not a reliable business model for any exchange that markets its services into the EU in any systematic way.
How does this look in practice?
In a recent licensing matter, a payments-adjacent operator – structured around a non-EU holding company with an EU user base – approached us after the relevant national competent authority had raised concerns about the substance of the local entity named in the draft application. The core issue was that the proposed local directors lacked demonstrable familiarity with the exchange's operational model. We worked through a restructured management presentation, supported by updated AML/CFT documentation that tied the compliance function to the local entity's governance rather than to group-level policies. The application was resubmitted with a materially stronger management case, and the competent authority's subsequent queries were limited to points of operational clarification rather than structural suitability. The matter resolved within the expected review window.
Which operator profile should choose the EU MiCA route?
The MiCA CASP authorisation is the right primary licence for an operator whose target market is genuinely pan-European and whose business model requires the credibility signal of EU authorisation with institutional counterparties, banking partners and token issuers. The process is demanding and the compliance ongoing cost is real. The value – a single passport across the largest regulated digital-asset market in the world by population – justifies the investment for an operator that intends to build a durable European franchise.
Profile A is the operator entering the EU from a non-EU base – a US, Singapore or Middle Eastern exchange seeking a regulated European presence. The MiCA CASP route is typically right. The member state selection and the structure of the local entity are the key decision variables. Allied counsel in the relevant EU jurisdiction will be engaged alongside OBOLUS for the NCA interaction and the local corporate and banking work.
Profile B is the operator already holding a national VASP registration from before MiCA's application date and now assessing whether to convert or apply fresh. The transition timeline differs by member state, and the conversion process is not automatic – it involves a substantive CASP application in most jurisdictions. Early engagement is advisable; transitional operating permissions are time-limited.
Profile C is the operator whose target market is primarily outside the EU – a global retail exchange with incidental EU users. MiCA authorisation may not be the primary regulatory investment, but the question of whether EU users constitute "active solicitation" must be answered on the facts. Getting that analysis wrong creates retroactive exposure.
CTA #2 — For operators who have already attempted and hit an obstacle
If a prior CASP application stalled, or if an existing structure was built under a pre-MiCA VASP regime and the transition path is unclear, a structured second read of the application or the corporate architecture can identify the specific gap. To map the licence, banking and tax stack for your EU build, write to OBOLUS at info@oboluslaw.com or map your options.
Self-assessment: is your exchange structure MiCA-ready?
Before committing capital to a member state structure, an operator should be able to answer the following questions affirmatively. If any of them produces uncertainty, the uncertain point is where legal advice is needed before the application is filed.
- Is the corporate entity to be authorised genuinely established in the chosen member state, with substance in management, personnel and governance – not merely a registered address?
- Are the proposed management and supervisory body members able to demonstrate competence and fitness under the NCA's suitability assessment criteria?
- Is there a deployed AML/CFT programme – not a policy document – that addresses Travel Rule compliance as an operational matter?
- Has the scope of regulated services been defined with sufficient precision to capture custody and transfer services as well as exchange services, where those are intended?
- Is there a credible banking relationship – or a documented roadmap to one – in place before the application is filed?
- Has the cross-border tax structure been reviewed to confirm that the operating entity's corporate tax domicile is consistent with the member state chosen for authorisation?
- If the operator has a non-EU parent or group structure, has the intra-group arrangement been reviewed for substance and transfer-pricing consistency?
An exchange that can answer each of these points clearly is substantially better placed than one that treats them as post-authorisation considerations.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full scope of OBOLUS licensing practice across 70+ jurisdictions
- Economic substance for licensed VASPs in the Isle of Man – substance requirements for offshore-licensed digital-asset operators
- Real-world asset tokenization in Singapore – MAS regulatory framework for tokenized-asset structures
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the CASP authorisation timeline is set by the national competent authority following submission of a complete application. The formal review period is fixed by the regulation, but the time from initial preparation to a complete, submittable dossier typically adds weeks to months depending on the complexity of the structure and the applicant's prior compliance maturity. Practically, operators should plan for a process measured in months, not weeks. Member state choice affects pace, as NCA processing capacity varies.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right domicile depends on the target market, the business model, the banking environment, the operator's existing structure and the ongoing compliance cost the business can sustain. For EU market access, MiCA CASP authorisation from a member state with a responsive NCA and a workable banking environment is the standard answer. For global operators, the licence stack typically involves a primary EU authorisation alongside registrations or authorisations in Singapore, the UAE or other hubs where the user base sits.
Do I need a separate custody licence?
Under MiCA, the custody and administration of crypto-assets on behalf of clients is a distinct regulated service within the CASP authorisation. An exchange that holds client assets in its own wallets is providing custody services and must ensure that activity is within the scope of its CASP authorisation and operationally separated in accordance with the safeguarding requirements. Whether this requires a separately scoped authorisation or is addressed within a combined CASP application depends on the operational model and the national competent authority's practice. Early structural clarity is advisable.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so structural gaps surface before they become enforcement problems. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy and member state selection under MiCA for inbound exchange operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.