Operating an exchange, custody platform or brokerage across the European Union without the right authorisation exposes the business to enforcement action, frozen payment rails and the loss of banking relationships that can take years to rebuild. Under MiCA (the Markets in Crypto-Assets Regulation), any firm providing crypto-asset services to EU clients must hold a CASP (crypto-asset service provider) authorisation issued by a national competent authority and recognised by ESMA. The page below sets out the regulated basis, the application process, the cross-border interactions that affect structure and banking, and the decision points a general counsel should resolve before committing to a jurisdiction.
What MiCA Requires of a Crypto-Asset Service Provider
MiCA establishes a single authorisation regime across all EU member states, replacing the patchwork of national VASP registrations that preceded it. A business providing any of the regulated crypto-asset services – operating a trading platform, executing orders, exchanging crypto-assets for funds, custody and administration, reception and transmission of orders, portfolio management, advice, or transfer services – must obtain a CASP authorisation before serving EU clients. The regulatory authorisation is issued by the national competent authority of the member state where the applicant is established.
The key architectural feature of MiCA is its passporting mechanism. A CASP authorised in one member state may notify ESMA and passport that authorisation across the entire EU and EEA. That single regulatory clearance covers a market of over 440 million people. The commercial logic is therefore clear: the jurisdiction choice at authorisation stage determines the supervisory relationship, the fee structure and the ongoing compliance burden for the life of the business.
MiCA also distinguishes between service authorisation and token-specific obligations. Issuers of ARTs (asset-referenced tokens) and EMTs (e-money tokens) face separate authorisation requirements, whitepaper obligations and reserve rules. A platform that lists but does not issue these tokens still faces due-diligence obligations in respect of the tokens it admits to trading. These are distinct regulatory tracks, though they frequently interact for vertically integrated businesses.
Who Needs CASP Authorisation – and Who Is Exempt?
Most professional crypto-asset businesses operating in or toward EU clients need CASP authorisation; the exemptions are narrow and operationally limited. MiCA carves out certain intra-group activities, peer-to-peer transfers with no intermediary, and, for a transitional period, businesses already registered under pre-MiCA national VASP regimes. The transitional window is finite. Businesses relying on transitional exemptions need to track the member-state-specific end-dates to avoid an inadvertent gap in their authorised status.
An entity established outside the EU has no direct route to a MiCA CASP authorisation. EU-facing activity must be channelled through an EU-established entity. This is the central structural question for any US, UAE, Singapore or UK operator looking at the EU market: either authorise a local subsidiary or accept a genuinely passive-business posture that keeps solicitation out of the EU. In our practice, the passive-business argument is almost always stress-tested by regulators when the platform is accessible in the local language, accepts SEPA payments or runs EU-targeted marketing. The safe course is full CASP authorisation.
Which Member State Should You Choose?
The member-state selection is the single most consequential early decision in a MiCA authorisation process. ESMA coordinates standards, but each national competent authority applies them with different operational priorities, staffing levels and supervisory cultures. Factors that drive the choice include the speed and predictability of the authorisation process, the depth of the supervisory dialogue, the availability of qualified local compliance staff, and the banking access the jurisdiction can realistically offer a crypto business.
Lithuania's Bank of Lithuania built a well-developed VASP registration track prior to MiCA and is transitioning that infrastructure to CASP authorisation. The Bank of Lithuania has handled a significant volume of crypto-business applications and maintains a structured, documented process. For businesses that need EU market access quickly and have the operational infrastructure to support a Lithuanian entity, this remains a leading choice.
Malta's MFSA administered the VFA (Virtual Financial Assets) framework, which is now transitioning to MiCA's CASP regime. Malta's supervisory staff have sector-specific experience, and the MFSA has published detailed guidance on the transition pathway for VFA licensees. New applicants can approach the MFSA directly for CASP authorisation without passing through the legacy VFA track.
Other member states – including Ireland, Luxembourg, Germany and the Netherlands – have their own authorisation processes and supervisory postures. The right choice depends on the business model, the management team's physical location and the banking relationships already in place. A multi-jurisdiction analysis before filing is not optional; it is the work that determines whether the application succeeds on a realistic timeline.
To map the member-state options against your business model and banking position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base and existing banking relationships change the analysis significantly. Map your options.
What Does the CASP Application Process Look Like?
The CASP authorisation process follows a structured sequence, and the quality of the application file is the primary determinant of timeline. ESMA has published regulatory technical standards that define the information requirements. A complete application covers governance and fitness of management, the business plan, capital adequacy, internal controls, AML/CFT procedures, IT and security, safeguarding arrangements for client assets, and – where the business operates a trading platform – market integrity and order-book management procedures.
The national competent authority has a defined period under MiCA to assess the application and request supplementary information. In practice, the clock stops when the authority raises queries. Businesses that submit incomplete files effectively extend their own timelines. In our cross-border practice, we have seen applications stall for months at preliminary assessment because governance documentation did not reflect the actual decision-making structure or because the AML framework described a different business model than the one in the business plan. Coherence across the file is not a stylistic point – it is the mechanical precondition for a successful application.
Realistic timelines vary by member state and by the complexity of the business model. A straightforward custody or advisory application in a jurisdiction with a functional CASP track may be processed faster than a trading platform with a complex token-listing policy and a cross-border settlement layer. Applicants should plan for a multi-month process from initial engagement with the regulator to authorisation. Building in contingency is prudent; launching marketing before authorisation is issued is not.
Cross-Border Structure, Tax and Banking – the Three Layers
A CASP authorisation solves the regulatory layer; it does not automatically solve the tax or banking layers. Operators we advise routinely encounter a three-way mismatch: the licensed entity sits in one member state, the technical infrastructure runs through a third-country group entity, and the banking relationship is in a jurisdiction that has its own expectations about the source of funds and the regulatory status of crypto businesses.
On the tax side, the EU entity will be subject to the corporate tax regime of its member state. The location of management and control, the substance of operations and the transfer pricing arrangements between group entities all affect where profits are taxed. MiCA authorisation does not, in itself, create a tax-efficient structure. For businesses running a group with entities in the UAE, Singapore or the UK alongside the EU subsidiary, a coherent inter-company services and fee arrangement is essential before the entity goes live.
On the banking side, the reality for crypto businesses in the EU remains challenging. Many EU retail banks decline to open accounts for VASPs and CASPs, citing their own AML risk appetite. Specialist payment institutions and e-money institutions licensed under the Payment Services Directive provide an alternative, but they impose their own onboarding requirements. Operators should expect to demonstrate CASP authorisation status, AML programme quality and the identity of beneficial owners. The banking conversation is significantly easier once MiCA authorisation is in place – it signals regulatory compliance to a counterparty that must itself manage its own supervisory risk.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies across the EU under MiCA and the relevant fund-transfer regulations. CASP authorisation does not discharge the Travel Rule obligation; it presupposes a functioning Travel Rule infrastructure as a condition of the licence. Businesses must select and integrate a compliant Travel Rule solution before the application is filed, not after authorisation is granted.
AML, Compliance and the Ongoing Supervisory Relationship
MiCA and the EU's AML framework impose ongoing obligations that begin before the first client is onboarded, not after the business reaches scale. The CASP must implement a risk-based AML/CFT programme aligned with the relevant EU AML directives and the FATF Recommendations, including Recommendation 15 which addresses virtual assets specifically. The national competent authority and, depending on the business model, the national financial intelligence unit will both have supervisory access to the business.
Key compliance requirements include a compliant KYC programme, transaction monitoring calibrated to the risk profile of the client base, sanctions screening against EU and UN lists, periodic AML risk assessments and an annual AML officer report to the board. In our experience, regulators in the leading EU hubs increasingly expect to see a compliance function that is genuinely operational – not a paper programme housed in an offshore parent with a nominal local officer. Substance matters.
The ongoing supervisory relationship with the national competent authority is not a one-time event. CASPs should expect periodic reporting obligations, supervisory visits and – as ESMA develops its own supervisory convergence toolbox – increasing coordination between national authorities. Businesses that treat compliance as a cost centre to be minimised typically find that the regulatory relationship deteriorates before they realise it.
If your application has stalled or an existing registration is under review, a second assessment can identify the structural issue and the route forward. Contact OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options.
Decision Matrix – Which Profile Should Pursue Which Path
Not every business is at the same stage, and the right entry point into the MiCA authorisation process depends on the operator's profile.
A non-EU operator seeking EU market access should first assess whether the business model requires CASP authorisation or whether a narrower passporting-ready structure is appropriate. A custody-only business has a different capital profile and compliance infrastructure requirement than a full trading platform. The analysis begins with the service list, not the entity structure. Timeline is typically longer for this profile because the entity establishment and substance-building run in parallel with the application preparation.
A business already registered under a pre-MiCA national VASP regime – for example, under Lithuania's prior AML-based VASP registration or Malta's VFA framework – faces a transition to CASP authorisation. The transitional period provides breathing room, but the upgrade to CASP standards requires additional governance, capital and compliance infrastructure. The risk in this profile is complacency: assuming that historical registration automatically converts without substantive work.
An early-stage operator building from scratch has the advantage of designing the structure, governance and compliance framework from the outset. The disadvantage is time: a start-up that needs to generate revenue while building a team and filing a CASP application faces a resource-constrained timeline. For this profile, a staged approach – beginning with a narrower service scope that can be expanded post-authorisation – is often more realistic than a full-service application from day one.
In a recent matter, an operator expanding from a third-country hub into the EU engaged us ahead of the entity establishment phase. We identified that the proposed service scope required two separate regulatory authorisations – a CASP licence for the exchange activity and a separate authorisation for the payment leg – and that the initial governance structure did not meet the fitness and propriety expectations of the target member state. We restructured the governance, scoped the application to the core exchange service and coordinated with allied counsel in the relevant member state for the supervisory dialogue. The application proceeded on a cleaner timeline than the original plan would have allowed.
What Are the Most Common Mistakes in a MiCA CASP Application?
Application quality is the single variable most within the applicant's control, yet it is the most common source of delay. The mistakes we see most frequently follow a pattern.
First, mischaracterising the service scope. A business that describes itself as a "platform" in the business plan but runs order-book matching in the technical architecture is providing an exchange service, which attracts a different authorisation track and capital requirement than an OTC desk. The regulator will identify the mismatch; it is better to address it in the drafting stage.
Second, governance structures that do not reflect reality. A CASP authorisation requires the management body to be genuinely in control. Nominee directors, hollow local boards and management functions exercised from outside the member state are scrutinised. The regulator applies a substance-over-form analysis that mirrors the tax authority's permanent-establishment inquiry.
Third, AML programmes drafted for a different business. A compliance manual copied from a prior registration or downloaded from a template library and not calibrated to the actual client risk profile and transaction flow will fail assessment. The AML framework must describe the business that is actually being built.
Fourth, treating the application as a one-time filing rather than a supervisory relationship. The regulators in the leading EU jurisdictions will have questions. The businesses that succeed are the ones that treat the supervisory dialogue as a professional engagement, not an adversarial proceeding.
A Common Assumption – and Why It Is Costly
A common assumption among operators expanding into Europe is that a single offshore registration – a BVI VASP registration, a Cayman filing, or a pre-MiCA Lithuanian AML registration – is sufficient to serve EU clients on a cross-border basis. This assumption is incorrect and carries material regulatory risk.
MiCA applies to services provided to clients located in the EU, regardless of where the service provider is established. An offshore entity soliciting EU clients without CASP authorisation is operating unlicensed in the EU. The enforcement consequences include supervisory orders, fines and – in the most serious cases – criminal referrals under national implementation law. The banking risk is compounded: EU-based payment institutions are themselves obligated to conduct due diligence on their clients' regulatory status, and an unlicensed crypto business will find banking relationships withdrawn when the compliance team identifies the issue.
The reverse is also relevant. A CASP authorised in the EU does not automatically have licence coverage in Singapore, Hong Kong, the UAE or the UK. Each of those jurisdictions has its own VASP regime, and EU passporting has no extra-territorial effect. A business with global clients needs a global licence map, not a single filing.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview covering all major jurisdictions and licence categories
- Digital-Asset Custody Licensing for Early-Stage Founders – custody-specific authorisation requirements and founder-stage structuring
- Oracle and Data-Feed Liability in Guernsey – cross-border liability analysis for infrastructure operators in a leading offshore centre
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the national competent authority has a defined assessment period once it confirms an application is complete. In practice, preparation – building the governance structure, drafting the AML programme, establishing the entity and engaging with the regulator – takes place before the formal clock starts. End-to-end, a well-prepared CASP application in an operationally developed member state typically takes several months to over a year, depending on business complexity and the authority's current workload.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right member state for a MiCA CASP authorisation depends on the service scope, the management team's location, the existing banking relationships and the supervisory culture of the authority. Lithuania and Malta have deep VASP experience and structured processes. Ireland, Luxembourg and the Netherlands suit different business profiles. A comparative analysis across three or four member states – factoring in timeline, capital, banking access and ongoing compliance costs – is the starting point, not the conclusion.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is itself a regulated crypto-asset service. A business that holds client assets must include custody in its CASP authorisation scope. A business that provides custody only may apply for a custody-scoped authorisation, which carries its own capital and safeguarding requirements. Whether custody is bundled into a broader application or pursued as a standalone filing depends on the overall service architecture and the timeline for going live.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is the one that survives regulatory scrutiny. Our disputes team also coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is the priority. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in MiCA CASP authorisation strategy, member-state selection and cross-border VASP regulatory structuring for inbound EU market entrants.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.