A token issuer or exchange operator entering the European Union market faces a structural question before any application is filed: does the business need a CASP authorisation (Crypto-Asset Service Provider authorisation under MiCA), a passported licence from an existing member-state operation, or both? Getting the answer wrong means enforcement exposure, frozen payment rails and, in the most acute cases, a mandatory wind-down of EU-facing activity. The stakes are not theoretical.
Under MiCA (the Markets in Crypto-Assets Regulation), any business providing crypto-asset services to clients located in the EU must hold a CASP authorisation issued by the competent authority of an EU member state, or passport an existing authorisation across the bloc. ESMA, the European Securities and Markets Authority, coordinates supervisory convergence across the national competent authorities (NCAs) that conduct each authorisation. The regime applies regardless of where the applicant is incorporated: a non-EU entity serving EU users is caught unless it meets narrow reverse-solicitation thresholds.
This page works through the authorisation process, the cross-border dimensions that most applicants underestimate, and the decision points that determine whether a single MiCA licence covers the full business model.
Who Needs a CASP Authorisation Under MiCA?
The obligation to hold a CASP authorisation arises when a business provides one or more prescribed crypto-asset services to clients in the EU on a professional basis. The services are defined by activity, not by the technology used. They include operating a trading platform, executing orders, providing custody and administration of crypto-assets on behalf of clients, offering advice on crypto-assets, receiving and transmitting orders, and several further categories. ESMA has published convergence guidance to reduce interpretive divergence between NCAs, but the threshold question – is this activity caught? – turns on the substance of the service offered, not the label applied to it.
The reverse-solicitation exemption is narrow. It applies only where the client approaches the service provider entirely on their own initiative, with no prior solicitation, advertising or outreach targeted at EU persons. Operators we advise routinely overestimate its scope. A single EU-targeted marketing campaign, a translated website, or localised pricing is generally sufficient for an NCA to treat the operator as providing services in the EU on a professional basis, removing the exemption.
For non-EU businesses, the position is direct: if EU clients are part of the commercial plan, a CASP authorisation is the operative baseline. There is no third-country equivalence regime under MiCA that replicates what exists under MiFID II for investment firms. Operating through a branch of a non-EU entity does not substitute for authorisation. A subsidiary incorporated in a member state and authorised as a CASP is the structural answer for most inbound operators.
Operating without the required authorisation exposes the business to enforcement by the NCA, civil liability, and the loss of banking and payment relationships that financial institutions increasingly condition on regulatory status. In our cross-border practice, we have seen operators lose their EU banking access after an NCA issued a public warning, even where the underlying activity was ultimately restructured into compliance.
For a preliminary read on whether your activity is caught and which licence tier applies, contact OBOLUS at info@oboluslaw.com. The process above describes the standard framework. Your entity structure, product set and user base change the analysis materially before any form is filed.
What Are the MiCA Licence Categories?
MiCA creates three distinct token regimes and one service-provider authorisation track, and understanding which applies – or whether multiple apply – is the first structural decision of any application. The token regimes govern issuers: ART (asset-referenced tokens, which reference multiple assets or currencies) and EMT (e-money tokens, which reference a single fiat currency) each carry their own whitepaper and authorisation obligations for the issuer. "Other" crypto-assets, which include most utility tokens, require a compliant whitepaper without prior authorisation, though the whitepaper must be notified to and published through the NCA of the home member state.
The CASP authorisation track is separate and applies to service providers regardless of whether they also issue tokens. A business that both issues a stablecoin classified as an EMT and operates a trading platform therefore engages two authorisation regimes simultaneously. ESMA's regulatory technical standards under MiCA detail the organisational, capital and conduct requirements for each service category, and NCAs are expected to apply them consistently, though calibration differences between member states remain visible in practice.
Passporting is a core structural feature of the CASP regime. Once authorised by the NCA of a home member state, a CASP may passport its services across the EU and EEA without obtaining a separate authorisation in each host state. The passport is activity-specific: it covers only the services listed in the home authorisation. An operator wishing to add a service category after initial authorisation must apply for a variation in its home state. Choosing the right home member state therefore has commercial consequences that extend well beyond the initial application.
How Do You Choose the Right EU Home Member State?
Selecting the home member state is the most consequential structural decision in a MiCA application, and it cannot be undone cheaply once an authorisation is granted. The choice determines the regulatory relationship for the life of the EU operation, the supervisory posture the business will face, and – indirectly – the banking and payment infrastructure available in the home jurisdiction.
Several factors drive the decision. First, the NCA's published authorisation timelines and its track record for reviewing CASP applications: NCAs are required under MiCA to process complete applications within defined periods, but the practical timeline depends on the NCA's capacity and the complexity of the application. Second, the availability of local substance: MiCA requires that a CASP have its registered office in the member state where it is authorised and maintain genuine management and operational presence there. A letterbox entity does not satisfy the standard, and NCAs have been explicit on this point. Third, the local corporate, tax and employment environment for a functioning EU subsidiary.
Lithuania, Malta, and several other member states developed VASP registration infrastructure under the prior AML-based regime and are transitioning those registered entities toward full CASP authorisation under MiCA. Operators already holding a legacy registration in one of those states have a transition pathway that, in principle, reduces the time to authorisation relative to a fresh application. Operators building from scratch have a wider choice set but must invest in substance from the outset.
In our cross-border practice, we work through a decision matrix that maps the operator's product set, existing corporate footprint, intended user base, and banking requirements against the NCA profile and local infrastructure of the candidate member states. That matrix – not the jurisdiction with the fastest headline timeline – drives the recommendation.
What Does the CASP Authorisation Process Involve?
The CASP authorisation process under MiCA is a structured application to the home NCA, assessed against organisational, capital, conduct and fit-and-proper requirements specified in the regulation and the associated ESMA technical standards. It is not a registration or notification: it is a full authorisation, and the NCA has the power to refuse it.
The application package typically includes: a detailed programme of operations covering each service to be provided; organisational charts and governance documents; policies covering AML/CFT, cybersecurity, complaints handling, conflicts of interest, and safeguarding of client assets; evidence of minimum own funds; personal questionnaires and regulatory history for all members of the management body and qualifying shareholders; and – for platforms and custody providers – a technology assessment. The breadth of the package reflects the breadth of MiCA's conduct requirements.
NCAs assess completeness before the substantive review clock begins. An incomplete application is returned, and the assessment period does not start until all required information is in. In our cross-border practice, the most common cause of delay is not a substantive regulatory concern but an incomplete first submission – missing governance annexes, undated personal questionnaires or an AML policy that fails to address the specific risks of the crypto-asset activities being authorised.
The assessment period under MiCA runs from the date the NCA confirms the application is complete. NCAs may request additional information during the review, and such requests can pause or extend the substantive assessment. Applicants who treat the pre-submission phase as administrative rather than analytical routinely face multiple information requests and materially extended timelines. Preparing a complete, analytically coherent application from the outset is not optional.
A micro-matter from our recent practice illustrates the point. An exchange operator sought to passport MiCA services across seven EU member states from a single authorisation. The initial application package presented generic AML policies drawn from a prior offshore registration. The home NCA's completeness check identified the mismatch between the stated service scope and the depth of the governance documents in the first review cycle. We rebuilt the AML framework to address the specific risks of the exchange model, including peer-to-peer transfer exposure and high-volume retail activity, and supported the management team through personal questionnaire submissions. The revised package was accepted as complete, and the assessment period commenced without further completeness challenges.
How Do MiCA and the Travel Rule Interact for CASPs?
MiCA's authorisation requirements sit alongside – and do not replace – the AML/CFT obligations that apply to crypto-asset service providers under the Transfer of Funds Regulation and national AML legislation implementing FATF standards. For a CASP, this means the authorisation process and the ongoing compliance programme both engage the Travel Rule. The two are not sequential: a CASP that is authorised under MiCA but fails to implement the Travel Rule is in breach of its AML obligations from day one of operation.
The Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identifying information with a transfer of crypto-assets above the applicable de-minimis threshold – applies to CASPs as obliged entities. ESMA and the European Banking Authority have coordinated on the application of Transfer of Funds Regulation requirements to crypto-asset transfers, and the technical standards specify the data fields required and the treatment of transfers to and from unhosted wallets.
Unhosted wallet policy is a recurrent point of NCA scrutiny in CASP applications. An applicant must present a coherent policy for screening and, where required, collecting additional information for transfers involving wallets not held at another regulated VASP. Policies that simply prohibit unhosted wallet transfers tend to draw questions about commercial viability; policies with no controls invite concerns about AML risk appetite. The calibrated approach – risk-based thresholds, enhanced due diligence for material unhosted wallet flows, and documented decisions – is what NCAs expect to see.
What Are the Tax and Banking Realities for a MiCA-Authorised CASP?
Obtaining CASP authorisation under MiCA solves the regulatory question. It does not automatically resolve the banking and tax questions that determine whether the EU operation is commercially functional. We have seen operators treat the licence as the end of the structuring process; in practice, it is the beginning of the operational build.
On banking: EU credit institutions are required under applicable AML frameworks to conduct enhanced due diligence on crypto-asset businesses as higher-risk customers. In practice, many EU banks remain reluctant to onboard CASPs, regardless of regulatory status. The operators most successful in securing EU banking are those who can demonstrate a clean corporate history, a credible AML programme, clear transaction-monitoring architecture and management with demonstrable experience in regulated financial services. CASP authorisation is a necessary but not sufficient condition for EU banking access. Parallel EMI relationships – using a payment institution or electronic money institution licensed under the Payment Services Directive for fiat flows – are part of the operational stack for most EU CASPs we advise.
On tax: the EU does not have a harmonised crypto-asset tax regime. Each member state applies its own income, capital gains and VAT treatment to crypto-asset transactions, and the position varies materially between states. The OECD's Crypto-Asset Reporting Framework (CARF), which several EU member states are implementing alongside DAC8 – the EU directive on automatic exchange of information covering crypto-assets – means that CASPs authorised in the EU will face increasing reporting obligations with respect to user transactions. The home member state choice therefore has a direct tax reporting cost, not just a regulatory cost.
To map the licence, banking and tax stack for your EU build, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship closed following a regulatory event, a structural review can surface both the cause and the route forward.
Which Operator Profile Should Take Which Approach?
Not every business entering the EU market follows the same path to CASP authorisation, and the right structure depends on the operator's existing footprint, product set and commercial timeline.
Profile A – Non-EU exchange with an existing regulated entity elsewhere. An operator already holding a licence from a recognised jurisdiction (such as a MAS Digital Payment Token licence in Singapore, a VARA licence in Dubai or an SFC VATP approval in Hong Kong) seeking to add EU market access. The structural answer is typically a dedicated EU subsidiary incorporated in the chosen home member state, applying for CASP authorisation for exchange and custody services. The existing regulated entity provides governance precedent and documented AML infrastructure, which can accelerate the application. The key risk is underestimating the substance requirements: an EU subsidiary that is manifestly a shell for a non-EU parent will not satisfy the NCA's governance assessment. The timeline to authorisation is a function of NCA capacity and application quality.
Profile B – Token issuer seeking to issue an EMT or ART to EU users. A business planning to issue a stablecoin that qualifies as an EMT or ART under MiCA must obtain issuer authorisation from the home NCA before issuance. The CASP authorisation for any associated services is separate. If the operator also intends to operate a platform on which the token trades, both authorisations run in parallel. The capital requirements for EMT and ART issuers are distinct from CASP capital requirements and vary by token category and issuance volume. This profile often requires the most complex pre-application structuring work, including a whitepaper review, reserve architecture and redemption policy design.
Profile C – Startup or early-stage business building for the EU market from inception. For a business without an existing regulatory footprint, the choice of home member state, corporate structure, and management team composition are all live questions at the outset. The risk here is committing to a jurisdiction and corporate architecture before the product is sufficiently defined to know which CASP service categories are needed. We regularly advise early-stage operators to complete a product-regulatory mapping exercise before incorporating, to avoid a situation where the corporate structure locks in a service scope that does not match the eventual product.
What Are the Most Common Mistakes in a MiCA CASP Application?
A common assumption is that MiCA is simply a new label on the prior VASP registration regime and that an operator who sailed through a national AML-based registration will have no difficulty with CASP authorisation. That assumption is wrong in ways that matter.
VASP registration under the pre-MiCA AML regime was, in most EU member states, an administrative filing: the registrar verified that the AML programme existed, not that it was fit for the operator's specific risk profile. CASP authorisation under MiCA is a prudential and conduct assessment: the NCA evaluates governance architecture, capital adequacy, organisational soundness, fitness and propriety of management and qualifying shareholders, and the adequacy of conduct and safeguarding arrangements for each service category. An operator who prepared for registration will not have the governance documentation that authorisation requires.
The four most frequent application failures we observe:
- Governance documents drafted at a generic level, without mapping policies to the specific risks of the applicant's business model and service scope.
- Fitness and propriety questionnaires submitted without supporting documentation for prior regulatory interactions, which NCAs treat as a red flag rather than an oversight.
- Technology and security assessments that address custody or exchange mechanics at a high level, without the operational detail the NCA's technical reviewers require.
- An AML programme that references FATF standards in general terms but does not implement the Travel Rule for the specific asset classes and transaction types in scope.
Each of these failures triggers an information request, which can add weeks to the assessment period. In aggregate, they can extend a timeline by months. We map the application package against the ESMA technical standards and the home NCA's published guidance before submission, specifically to identify and address these gaps before the completeness check.
Related at OBOLUS:
- Licensing and Registration for Digital-Asset Businesses – the full-service overview of CASP, VASP and exchange licence work across 70+ jurisdictions.
- Economic Substance for Licensed VASPs in the United Kingdom – substance requirements and what they mean for EU-UK dual-licensed operators.
- EMI Onboarding for VASPs: a Cross-Border Perspective – the banking and payment layer that sits around a CASP authorisation.
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the authorisation timeline depends on the home member state's NCA and the completeness of the application. NCAs are required to confirm completeness within a defined period and then conduct a substantive assessment within a further defined period, but information requests can extend both. In our experience, a well-prepared application to an NCA with established CASP capacity proceeds materially faster than a generic submission to an NCA still building its review infrastructure. Applicants should plan for a process measured in months, not weeks, from first submission to authorisation decision.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right EU home member state for CASP authorisation depends on the operator's service scope, existing corporate footprint, banking requirements, substance capacity and management location. For operators outside the EU, the choice between a MiCA CASP, a VARA licence in Dubai, a MAS Digital Payment Token licence in Singapore or another regime turns on where the operator's users and revenue are located, and on the cross-border passporting value of each authorisation. We map those factors against a structured decision matrix before making a recommendation, rather than defaulting to the jurisdiction with the shortest headline timeline.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct service category that must be listed in the CASP authorisation. An operator authorised for exchange services only is not authorised to provide custody. If the business model involves holding client assets – even as an operational necessity of operating an exchange – the custody category must be included in the application scope. The organisational, capital and safeguarding requirements for custody are assessed separately by the NCA. Operators who add custody to an existing authorisation must apply for a variation in the home member state.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – so the structure you build is the one that survives regulatory scrutiny. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, MiCA home-state selection and cross-border licence structuring for inbound EU market entrants.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.