EST · MMXXVI
Home/Jurisdictions/Eu Mica/Digital-asset custody authorisation in European Union (MiCA)
Licensing & Registration

Digital-asset custody authorisation in European Union (MiCA)

Digital-asset custody authorisation in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

Digital-asset custody under MiCA is a regulated activity requiring formal CASP (Crypto-Asset Service Provider) authorisation before a business may hold client assets on behalf of third parties anywhere in the European Union. The Markets in Crypto-Assets Regulation (MiCA), supervised by ESMA and national competent authorities (NCAs) across member states, establishes a single authorisation gateway that, once granted, opens passporting rights across the entire EU and EEA. For an inbound operator – whether a custodian already active in Singapore, Dubai or the United States, or a startup structuring its first regulated entity – the practical question is not whether to authorise, but where, and how to build the rest of the business around the licence.

This page covers the regulated perimeter, the application process, the cross-border banking and tax reality, and the decision points that determine whether a standalone custody authorisation or a broader CASP licence better matches an operator's profile.

Who Needs Custody Authorisation Under MiCA?

Any business that holds or controls crypto-assets, private keys or the means of access to crypto-assets on behalf of clients in the EU requires CASP authorisation under MiCA for the custody and administration of crypto-assets on behalf of third parties. The test is functional, not formal: if your business model places client assets under your operational control – even temporarily, even as a sub-custodian to another platform – the custody activity is regulated.

The perimeter catches a wider set of businesses than many operators initially expect. Centralised exchanges that hold user balances, institutional custodians offering cold-storage services to funds, staking providers that control client keys during delegation, and DeFi-adjacent platforms that pool assets in smart contracts they control all fall within the definition, depending on the precise structure. ESMA and NCAs have been explicit that substance governs: labelling an arrangement as "technology provision" does not remove it from the regulated perimeter if the economic reality is custody.

Businesses providing custody only – without also operating an exchange or offering crypto-asset advisory services – may apply for a narrowly scoped CASP authorisation. That scope is reflected in the capital requirements, the ongoing compliance obligations and the supervisory reporting cycle. In our practice, we regularly advise operators to map every activity layer before choosing the authorisation scope, because adding an activity post-authorisation triggers a variation process that extends the regulatory timeline.

The MiCA passporting mechanism means that a CASP authorised in one member state may notify and passport its custody services to any other EU or EEA member state without a separate national licence. That single-authorisation, multi-market access is the central commercial rationale for EU custody authorisation and distinguishes MiCA from the patchwork of national VASP registration regimes it replaced.

OBOLUS maps the regulated perimeter across every activity layer – custody, exchange and payment – before you commit to a licence scope. The process above describes the standard path; your entity structure, user base geography and banking arrangements change the analysis materially. Map your options

Which Member State Should You Apply In?

The choice of NCA determines your timeline, your supervisory culture and, often, your banking access – so it is one of the most consequential early decisions an inbound operator makes under MiCA.

Authorisation is granted by the NCA of the member state where the CASP has its registered office. An operator incorporated in Ireland is supervised by the Central Bank of Ireland; one incorporated in Lithuania falls under the Bank of Lithuania; one in Malta under the MFSA. The ESMA-level framework is identical across all member states, but NCAs differ in their resourcing, the depth of their pre-application engagement, their appetite for novel business models and the practical length of the authorisation process. These differences are material at the business-planning stage.

Lithuania historically offered a faster entry path under the pre-MiCA VASP registration regime, and the Bank of Lithuania remains an active NCA in the MiCA transition period. Malta's MFSA brings experience from the VFA framework, including a body of practice on crypto-asset whitepaper review. Larger member states – Germany, France, the Netherlands – tend to have well-resourced NCAs but also higher supervisory expectations and, in some cases, more conservative approaches to novel custody structures.

The tax treatment of the holding entity also varies by member state, and it interacts directly with the custody authorisation. Some operators choose their NCA on regulatory grounds, then discover that the member state's corporate tax regime or withholding tax rules create friction at the treasury level. In our cross-border practice, we treat the NCA selection and the tax-holding structure as a single analysis, not two separate workstreams. The right answer for a Cayman-domiciled fund manager seeking EU custody access is often different from the right answer for a Singapore exchange building its first EU entity.

What Does the MiCA CASP Application Require?

A MiCA CASP application for custody services is a structured regulatory submission – not a registration form – and its depth should not be underestimated by operators accustomed to lighter-touch offshore registration processes.

The application must demonstrate, at a minimum: legal form compliant with the member state's company law; a registered office and genuine management presence in the member state; fit-and-proper assessment of shareholders with qualifying holdings and all senior managers; an adequate own-funds base calibrated to the custody activity; a programme of operations describing the custody model, the key-management architecture and the client asset segregation method; and governance and internal control arrangements proportionate to the scale and risk of the business.

For custody specifically, the technical substance of the application is heavy. NCAs expect a detailed description of the key-management system – whether the operator uses hardware security modules, multi-party computation, or third-party sub-custody – the wallet architecture, the segregation model at the ledger level, the disaster recovery and business continuity arrangements, and the procedures for responding to a security incident. ESMA has published guidance on the operational and security requirements that NCAs are expected to apply when assessing custody applications, and NCAs with less pre-existing digital-asset supervisory capacity may lean on that guidance closely, resulting in detailed information requests.

AML and Travel Rule compliance documentation is a parallel track. The Travel Rule (the obligation to pass originator and beneficiary data with a transfer, derived from FATF Recommendation 15) applies to CASP-to-CASP transfers above the applicable threshold. The application must show that the operator has a compliant Travel Rule solution integrated into the custody workflow – not merely planned for integration post-authorisation.

The whitepaper regime under MiCA applies to issuers of crypto-assets, not to custodians as such. However, if the custody business also intends to hold asset-referenced tokens (ARTs) or e-money tokens (EMTs) for clients, the custodian must assess whether those issuers hold the corresponding MiCA authorisation and whether any conditions apply to the eligible custodians of those token types.

How Long Does the Authorisation Process Take?

The MiCA framework sets a statutory decision period from the date an NCA declares the application complete, but the practical timeline from initial submission to authorisation is typically longer, and the gap between those two points depends almost entirely on application quality and pre-submission preparation.

NCAs have a defined period to declare an application complete or incomplete and to request supplementary information. The clock on the substantive assessment period runs from the completeness declaration. An application that arrives with gaps in the governance documentation, an under-specified key-management section or a Travel Rule solution described only in outline will generate information requests that pause the assessment clock and extend the overall process by weeks or months. In our experience, well-prepared applications at established NCAs move materially faster than the statutory maximum suggests.

Operators should plan for a multi-month process in all cases, and for a longer period when the NCA has limited prior experience with the specific custody model being proposed. Pre-application engagement with the NCA – available in most member states, though not universally – is one of the most effective tools for compressing the timeline. It surfaces the NCA's concerns before the formal clock starts, allows the operator to tailor the application, and establishes a working relationship with the supervisory team that benefits the business throughout the authorisation lifecycle.

During the authorisation period, the operator cannot lawfully provide custody services to EU clients – unless it benefits from an applicable transitional arrangement under the MiCA transition provisions. The transition provisions vary by member state and by the operator's prior registration status. Mapping the transition position is a day-one task, not an afterthought.

If your application has already been submitted and is generating detailed information requests, a technical review of the current filing can identify the structural gaps and the fastest route to a completeness declaration. Write to the OBOLUS licensing desk at info@oboluslaw.com or reach us at t.me/oboluslaw. Map your options

The Cross-Border Reality: Banking, Tax and Entity Structure

For most inbound operators, the custody authorisation is the most visible regulatory milestone – but the banking and tax structure around it determines whether the licensed entity is commercially viable.

EU CASP authorisation does not, by itself, create a banking relationship. Custodians typically require one or more accounts with EU credit institutions for fiat settlement, client money segregation and operational expenses. The correspondent banking environment for crypto-native businesses in the EU remains selective: some member states have a denser supply of crypto-friendly banking partners than others, and the choice of NCA can therefore influence the practical banking options available to the licensed entity. In our practice, we regularly map the banking environment in parallel with the NCA selection, because a licence in a member state with thin banking coverage creates a structural problem that legal work alone cannot solve.

The corporate tax position of the EU custody entity matters from incorporation. The entity will be subject to tax in its member state of residence on profits attributable to the custody business. Fee income from custody services is generally taxable at the applicable corporate rate; the treatment of crypto-assets held on behalf of clients (which are off-balance-sheet as custodial assets) is distinct from the entity's own treasury assets. In member states with favourable holding-company or IP regimes, there may be legitimate structuring options at the group level – but these must be documented and defensible under the applicable transfer pricing rules and EU anti-avoidance directives.

For operators headquartered outside the EU – in Dubai under VARA, in Singapore under MAS, in the BVI or Cayman Islands – the MiCA custody entity typically sits as a regulated subsidiary of a group structure rather than as a standalone operation. The intragroup agreements governing custody mandates, technology licensing, and back-office services must be priced at arm's length and structured to withstand both NCA and tax-authority scrutiny. We have seen group structures that were commercially rational but inadequately documented fail NCA fit-and-proper review because the intragroup dependencies were not disclosed and evidenced in the application.

What Does Ongoing Supervision Require?

MiCA custody authorisation is not a one-time approval. It initiates a continuing supervisory relationship with the NCA that carries material operational obligations.

Authorised custodians must maintain their own-funds base at or above the applicable minimum at all times, report significant changes in ownership or management to the NCA before they take effect, notify material operational incidents within defined timeframes, and submit periodic regulatory returns. The annual supervisory cycle – which includes ongoing AML supervision under the applicable EU AML directives as well as MiCA-specific oversight – requires a compliance function capable of managing the reporting calendar and responding to supervisory enquiries without delay.

Client asset protection rules under MiCA impose specific obligations on custodians: assets must be segregated from the custodian's own assets, the custody records must be reconciled at a frequency the NCA considers adequate, and clients must be informed of any sub-custody arrangements. For businesses that previously operated under lighter-touch regimes – an offshore VASP registration or a tech-platform model without a regulatory wrapper – the step up in compliance overhead is significant. Budgeting for that overhead at the business-planning stage is essential; operators who under-resource the compliance function consistently generate supervisory concern during post-authorisation inspections.

The passporting notification process requires the custodian to notify its home NCA before commencing services in another member state. The host NCA must be informed, but authorisation is not required again. In practice, passporting into member states with more interventionist supervisory cultures – or into member states where the host NCA has adopted additional national-level AML requirements – may require local legal advice before the notification is filed.

Illustrative Matter: Inbound Custodian From a Gulf Hub

In a recent licensing matter, an institutional digital-asset custodian regulated under the VARA regime in Dubai sought to expand custody services to European family offices and funds. The business had robust key-management infrastructure but had not previously operated in a passporting jurisdiction. We advised on NCA selection, structured the intragroup technology-licensing agreement between the Dubai parent and the EU subsidiary, and prepared the programme of operations with a detailed technical annex addressing the multi-party computation architecture. Pre-application engagement with the chosen NCA surfaced two additional requirements around the sub-custody disclosure model and the Travel Rule integration timeline. Both were addressed before formal submission. The application was declared complete at the first assessment stage, materially compressing the overall timeline.

Decision Point: Custody-Only or Broader CASP Scope?

The choice between a narrowly scoped custody authorisation and a broader CASP authorisation covering additional activities – exchange, advisory, portfolio management – is one of the most commercially significant decisions an operator makes at the outset.

Profile A – an institutional custodian whose only EU activity is holding client assets – is best served by a custody-only CASP scope. The own-funds requirement is calibrated to that single activity, the compliance obligations are more contained, and the NCA's assessment focuses on the technical and operational substance of the custody model. The risk is scope-creep: if the business subsequently offers any execution or advisory service to EU clients – even incidentally – it is providing an unlicensed regulated activity.

Profile B – a full-service exchange that also holds user balances, or a prime brokerage offering custody alongside financing and execution – should apply for a CASP scope that covers all regulated activities from the outset. The broader scope carries higher capital requirements and a more complex application, but it avoids the variation process that would otherwise be required when the business inevitably expands its service offering.

Profile C – a DAO treasury manager or a protocol-native entity exploring whether its custody-adjacent function falls within the MiCA perimeter – requires a regulatory analysis before any application. The regulated-perimeter question must be answered first; the authorisation question comes second. We regularly advise on perimeter analysis as a standalone engagement before clients commit to an application timeline and budget.

A common assumption is that a single offshore registration – a BVI VASP registration or a Cayman CIMA acknowledgment – is sufficient to serve EU clients without MiCA authorisation. It is not. MiCA applies on the basis of where clients are located, not where the operator is incorporated. An operator incorporated and registered in a third country that actively markets custody services to EU-domiciled clients is within the MiCA perimeter and is subject to enforcement by NCAs in the client's member state. The reverse solicitation exemption is narrow and its limits are actively patrolled by ESMA and national regulators.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the NCA has a defined statutory period to assess a complete application, but the total timeline from initial submission to authorisation varies significantly by member state and application quality. A well-prepared filing at an experienced NCA with effective pre-application engagement can move materially faster than the statutory maximum. Operators should plan for a multi-month process; complex or novel custody models, or applications submitted to less-resourced NCAs, may take considerably longer. Transition arrangements may allow continued operations in some cases while an application is pending.

Which jurisdiction is best for licensing my crypto business?

No single jurisdiction is objectively best; the right NCA depends on the operator's business model, client geography, banking requirements, corporate tax objectives and existing regulatory relationships. Within the EU, the NCA selection turns on supervisory culture, processing capacity, familiarity with the specific custody model, and the banking environment in that member state. For businesses with a global footprint, the EU custody licence is typically one layer in a multi-jurisdiction stack that also addresses the home jurisdiction of the group, the jurisdictions where users are located, and the banking domicile.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of third parties is a defined regulated activity within the CASP authorisation framework. A business that already holds a CASP authorisation for exchange or other services must confirm that custody is expressly included in its authorisation scope – it is not automatically implied. A business that provides only custody requires a CASP authorisation scoped to that activity. The practical consequence is that scope must be mapped precisely at the outset: adding custody to an existing CASP authorisation after the fact requires a formal variation, which extends the timeline.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers as one mandate – not three disconnected workstreams. To discuss your authorisation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in MiCA CASP authorisation strategy, NCA selection and inbound operator structuring across EU member states.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours