EST · MMXXVI
Home/Jurisdictions/Eu Mica/VASP licensing in European Union (MiCA): Legal Requirements for Businesses
Licensing & Registration

VASP licensing in European Union (MiCA): Legal Requirements for Businesses

Vasp licensing in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto business in the EU without CASP authorisation (Crypto-Asset Service Provider authorisation under MiCA) is not a regulatory grey area — it is a prohibited activity that exposes the business to supervisory orders, administrative fines and, in some member states, criminal liability. MiCA (the Markets in Crypto-Assets Regulation), which applies across all EU and EEA member states under the oversight of ESMA (the European Securities and Markets Authority) and national competent authorities, establishes a unified licensing regime that supersedes the prior patchwork of national VASP registrations. Any business offering crypto-asset services to EU clients — whether headquartered in Frankfurt, Dublin or Singapore — must hold the right authorisation or face enforcement action. This page sets out the regulated perimeter, the authorisation process, the cross-border considerations and the practical decisions an inbound operator must make before committing to an EU structure.

Who Needs CASP Authorisation Under MiCA?

Any legal entity providing crypto-asset services on a professional basis to clients located in the EU requires CASP authorisation from a national competent authority in the member state where it is established. MiCA defines crypto-asset services broadly: the list covers the operation of a trading platform, the exchange of crypto-assets for fiat or other crypto-assets, the execution of orders, the placement of crypto-assets, the reception and transmission of orders, portfolio management, advice, transfer services, and custody and administration of crypto-assets on behalf of clients. The regulation does not rely on how a business labels itself. It looks at what the business actually does. A business operating an OTC desk, a custody wallet service, or a structured lending product must map its activity against the MiCA service definitions before concluding that it falls outside the perimeter.

Territorial reach is where operators frequently miscalculate. MiCA applies on the basis of where the client is located, not solely where the service provider is established. A Cayman Islands entity actively marketing exchange services to German retail clients is, in the view of ESMA and the relevant national authority, conducting a regulated activity within the EU. The enforcement risk travels with the client base. We regularly advise businesses that assumed their offshore structure insulated them from EU licensing obligations — it does not, once active solicitation of EU clients begins.

Certain entities are carved out of the MiCA perimeter: the ECB and national central banks acting in a public-interest capacity, fully decentralised protocols with no identifiable service provider, and transactions conducted entirely between professionals on a bilateral basis in some circumstances. These carve-outs are narrow and fact-specific. They should not be relied upon without a written legal assessment of the business model against the MiCA definitions.

The Three Token Regimes: What Asset Type Governs Your Filing?

MiCA creates three distinct token regimesART (asset-referenced tokens), EMT (e-money tokens) and a residual category of "other" crypto-assets — and the obligations imposed differ materially depending on which regime applies. This classification step is the first decision point for any inbound operator, and an error here carries forward through the entire licensing structure.

An ART references multiple currencies, commodities or other assets to maintain a stable value. An EMT references a single official currency and functions as electronic money. Both categories impose issuer-level authorisation requirements that are separate from, and additional to, any CASP authorisation for services built around them. A business that issues a stablecoin pegged to the euro and simultaneously operates a platform on which that token is exchanged may need two distinct authorisations: one as an EMT issuer and one as a CASP. The whitepaper requirement — a standardised disclosure document that must be filed with the relevant national competent authority before any public offer or admission to trading — applies across all three categories, with varying levels of regulatory scrutiny.

For the residual category — tokens that are neither ART nor EMT and do not qualify as financial instruments under MiFID II — the requirements are lighter at the issuer level but CASP authorisation still applies to any entity providing services in relation to those tokens. This is the category into which most utility tokens and governance tokens currently fall, though the boundary with the financial-instrument perimeter remains an area of active regulatory attention from ESMA.

How Does the MiCA Authorisation Process Work for an Inbound Business?

The MiCA authorisation process begins with the selection of a home member state — the EU jurisdiction in which the applicant will be established and from which it will passport its services. This decision has operational consequences that extend well beyond the licensing timetable. The choice of member state affects the regulatory culture the applicant will navigate, the language requirements for the application file, the supervisory approach of the national competent authority and, critically, the speed and predictability of the authorisation process.

The application itself is document-intensive. A complete file typically includes the applicant's programme of operations, a business plan, governance documentation (including the composition and fitness-and-propriety assessment of the management body), AML/CFT programme documentation, operational resilience and ICT security policies, client asset safeguarding arrangements, a conflict-of-interest policy, and evidence of the minimum own-funds requirement. The own-funds threshold varies by class of CASP — it is set in MiCA by reference to the services offered and the scale of the business, and operators should obtain current figures from the national competent authority or from counsel familiar with the applicable provisions, as these amounts are subject to change at the national level. The authorisation timeline under MiCA is set at a maximum of a defined number of months from the submission of a complete application file, but in practice the clock does not start until the competent authority confirms completeness, and pre-application engagement with the authority is strongly advisable. Operators we advise in the EU consistently report that the pre-filing dialogue with the authority is as important as the formal application itself.

Once authorised, the CASP receives the single most commercially valuable feature of MiCA: the EU-wide passport, allowing the firm to provide services across all member states without a separate local licence in each. Notification of cross-border activity to the host member state authority is required, but the passport eliminates the need for full reauthorisation in each country where clients are served. For a business building a pan-European client base, this passporting feature is the primary structural advantage of the MiCA regime over the pre-MiCA national VASP registration approach.

For a scoped assessment of your MiCA authorisation profile — entity structure, activity mapping and home-state selection — contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity type, the user base geography, the asset types involved and the banking relationships — shape the analysis in ways that a generic process overview cannot capture.

AML/CFT and the Travel Rule: What MiCA Demands in Practice

CASP authorisation under MiCA does not replace AML/CFT obligations — it operates in parallel with them, and a licensee that is compliant with MiCA's service rules but deficient in its AML programme faces supervisory action from both the financial intelligence and the crypto-asset regulators. The Travel Rule (the obligation to pass originator and beneficiary identifying information with every qualifying crypto-asset transfer) applies to CASPs under EU law, aligned with FATF Recommendation 15 and the Transfer of Funds Regulation as extended to crypto-assets. The data threshold triggering Travel Rule obligations is subject to the applicable regulatory instrument, and operators should verify current thresholds with the relevant national authority rather than relying on historic figures.

In practice, Travel Rule compliance requires the CASP to implement a data-passing infrastructure — typically through one of the interoperability protocols recognised by the industry — and to have a clear policy for handling transfers to and from unhosted wallets. The EU's position on unhosted wallet due diligence has tightened. CASPs are expected to apply risk-based measures when transacting with wallets not held at regulated counterparties. Operators building a compliance programme for EU authorisation should treat the unhosted-wallet policy as a supervisory priority, not a secondary concern.

In our cross-border practice, we have seen applications stall at the AML-programme stage because the applicant treated compliance as a checkbox document rather than an operationally implemented system. Competent authorities increasingly conduct pre-authorisation interviews, and the compliance officer is expected to demonstrate live familiarity with the firm's transaction monitoring logic, not simply to produce a policy document.

Cross-Border Tax and Banking: The Interaction MiCA Does Not Resolve

CASP authorisation solves the regulatory licensing question. It does not solve the banking and tax questions that sit around it — and for many operators, those questions are the harder ones. An EU-licensed CASP still needs a euro-denominated settlement account, a payment rails relationship and, if it handles fiat currency on behalf of clients, a relationship with an EMI (electronic money institution) or a credit institution that is willing to bank a crypto business. Banking appetite for crypto clients in the EU varies significantly by member state.

On the tax side, the EU does not impose a uniform crypto tax framework. Each member state applies its own treatment to crypto-asset gains, staking income and service revenues. For a CASP passporting into multiple member states, this creates a compliance matrix that must be managed at the group level. The DAC8 directive — which requires CASPs to report user crypto-asset transactions to tax authorities across the EU — adds a reporting obligation layer on top of the MiCA licensing regime. An inbound operator building the EU structure should model the DAC8 reporting architecture before going live, not after.

The interaction between MiCA and the home-state corporate tax regime is a further consideration for structuring decisions. A business choosing between Ireland, Luxembourg, the Netherlands or a Baltic member state as its CASP home base will encounter different effective tax rates, transfer-pricing environments and treaty networks. We map these interactions — licence, banking and tax — as a combined stack rather than treating them as separate workstreams, because the optimal home state for licensing may not be the optimal home state for holding and profit recognition.

To map the licence, banking and tax stack for your EU build, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship was declined, a second-look assessment can identify the structural reason and the route forward.

Which Profile Should Pick Which MiCA Approach?

Not every inbound operator follows the same path to EU licensing, and the right approach depends on the business model, the asset types involved and the timeline to market. The following profiles capture the principal decision branches we see in practice.

Profile A: Exchange or OTC desk seeking EU market access. This operator needs full CASP authorisation covering the operation of a trading platform or the exchange of crypto-assets for fiat. The home-state selection decision is commercially significant — some authorities have more developed pre-application engagement processes than others. The timeline from a complete application to authorisation is a matter that varies by authority, and operators should plan for a process measured in months, not weeks, including the pre-filing preparation phase. Key risk: underestimating the governance and own-funds documentation requirements, which have caused delays in applications we have reviewed.

Profile B: Custodian or wallet service provider. Custody and administration of crypto-assets on behalf of clients is a defined CASP activity under MiCA, with specific client-asset safeguarding and segregation obligations. An operator whose sole activity is custody may be able to obtain a narrower CASP authorisation than a full-service exchange, but the safeguarding and ICT resilience requirements are substantial. Key risk: conflating a technical key-management service with a custodial service — the distinction matters for the MiCA perimeter analysis.

Profile C: Stablecoin issuer seeking EU distribution. An EMT or ART issuer requires issuer-level authorisation under MiCA in addition to any CASP authorisation for associated services. The reserve requirements, redemption rights and reporting obligations for EMT and ART issuers are more prescriptive than for other CASPs. Key risk: structuring the token to avoid the EMT or ART classification without a formal legal opinion — competent authorities have signalled a substance-over-form approach.

Profile D: Non-EU operator with EU client base. This operator must decide between establishing an EU subsidiary for CASP authorisation or exiting the EU market. There is no "third country passporting" mechanism under MiCA equivalent to reverse solicitation in MiFID II, except in a very limited and narrowly interpreted scenario. Key risk: relying on a reverse-solicitation argument that the competent authority does not accept, triggering enforcement action against a business that considered itself outside the perimeter.

A Cross-Border Licensing Matter: Home-State Selection Under Pressure

In a recent licensing matter, a digital-asset exchange incorporated outside the EU had been serving European clients under a legacy national VASP registration that was no longer valid following the MiCA transition deadline. The business faced an immediate gap: it was operating in the EU without a valid authorisation, and its primary banking relationship had flagged the compliance status. We conducted an activity mapping exercise against the MiCA service definitions, identified the applicable CASP category and prepared a phased plan: an interim cessation of regulated activity for EU clients while the authorisation application was prepared, selection of a home member state based on the authority's known engagement process and the business's operational footprint, and a parallel engagement with an EU-licensed EMI to bridge the banking gap during the application period. The application was submitted within a matter of weeks of the instruction, and the authority confirmed completeness and opened the formal review period. The business resumed EU client onboarding under the provisional arrangements available to applicants during the review window.

What Are the Most Common Mistakes in MiCA Licence Applications?

The most common mistake we see is treating the MiCA application as a documentation exercise rather than a readiness exercise. A competent authority does not grant authorisation because the applicant has produced a policy document — it grants authorisation because it is satisfied that the business is operationally ready to provide the regulated service safely. The gap between those two things is where most applications encounter difficulty.

A second recurring mistake is home-state selection based on perceived regulatory leniency rather than on operational fit. ESMA has made clear through its convergence work that regulatory arbitrage within the EU is not a sustainable strategy. An authority that processes applications quickly may also supervise actively. Operators that select a home state without understanding the supervisory culture find themselves navigating ongoing engagement requirements that they had not planned for.

A third mistake is failing to model the MiCA obligations that attach after authorisation. The ongoing compliance burden — periodic reporting, incident notification, changes to the management body, modifications to the programme of operations requiring prior approval — is substantial. Businesses that plan only for the licence and not for the licensed state often find the post-authorisation phase more demanding than the application itself. In our cross-border practice, we build the post-authorisation compliance calendar into the engagement from the outset, so that the client is not surprised by the obligations that begin on day one of operating under the CASP authorisation.

Related at OBOLUS

Is a Single Offshore Licence Enough to Serve EU Clients?

A common assumption among operators building cross-border crypto businesses is that a single offshore licence — in the BVI, Cayman Islands or a comparable jurisdiction — provides adequate legal cover to serve clients anywhere in the world, including the EU. That assumption is incorrect, and it is one of the more commercially costly misunderstandings we encounter in practice.

MiCA does not recognize third-country licences as a basis for serving EU clients. The reverse-solicitation exception — which permits a non-EU firm to provide services to an EU client who has approached it on their own exclusive initiative — is narrow, operationally difficult to document at scale and is explicitly flagged by ESMA as subject to strict interpretation. A marketing campaign, a localized website, a referral program or an app-store listing targeting EU users will, in the view of most national competent authorities, defeat a reverse-solicitation argument. The enforcement consequence of getting this wrong is not merely a fine. It is the potential unwinding of the EU client relationship, the freezing of payment rails and the reputational cost of a public supervisory action.

The correct answer for a business with a meaningful EU client base is EU establishment and CASP authorisation. The cost of doing that properly is materially lower than the cost of an enforcement action that interrupts operations. We map the licence, banking and tax requirements at the outset — before the business commits to a structure — so that the decision is made on accurate information rather than on an optimistic assumption about regulatory reach.

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the national competent authority has a defined review period from the date it confirms a complete application. In practice, the timeline from initial instruction to a complete application submission typically takes several months, depending on the complexity of the business model and the state of the applicant's governance and compliance documentation. Operators should plan for a process measured in months rather than weeks, and engage with the relevant authority at the pre-application stage to manage timing expectations.

Which jurisdiction is best for licensing my crypto business?

There is no universally optimal jurisdiction. The right home state for a MiCA CASP authorisation depends on the business model, the activity categories, the banking relationships available in the jurisdiction, the supervisory culture of the national competent authority and the corporate and tax environment. For non-EU businesses, the decision also involves modeling the interaction between the EU structure and the group's existing entities. We assess these factors as a combined stack rather than treating licensing in isolation.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service category. If your business provides custody as part of a broader service offering, it will typically be covered within a CASP authorisation that includes that category. If custody is the sole regulated activity, a narrower authorisation may be available. In either case, the safeguarding, segregation and operational-resilience obligations that attach to custody are substantive requirements, not incidental ones.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit — because the cost of an incorrect structure compounds quickly in a regulated environment. To discuss your EU licensing situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in EU MiCA authorisation strategy, home-state selection and cross-border CASP structuring for inbound operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours