EST · MMXXVI
Home/Jurisdictions/Germany/CASP authorisation under mica in Germany (BaFin)
Licensing & Registration

CASP authorisation under mica in Germany (BaFin)

Casp authorisation under mica in Germany (BaFin). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto exchange, custody service or token-trading platform in Germany without the right authorisation is not a grey area. Under the Markets in Crypto-Assets Regulation (MiCA), any business providing crypto-asset services to clients in Germany requires a CASP (Crypto-Asset Service Provider) authorisation, and BaFin (the Bundesanstalt für Finanzdienstleistungsaufsicht) is the competent authority that grants, supervises and – where necessary – withdraws it. With VASP supervision tightening across every major EU hub, the cost of getting the structure wrong is measured in enforcement actions, frozen payment rails and the loss of banking relationships that took years to build. This page maps the regulated basis, the inbound-business process, the cross-border interaction with tax and banking, and the decision points a serious operator needs to work through before committing capital to a German market entry.

Who needs CASP authorisation in Germany under MiCA?

Any entity providing crypto-asset services on a professional or commercial basis to clients located in Germany must hold a CASP authorisation or rely on a valid passported authorisation from another EU member state. The MiCA regime covers a defined list of services: operating a trading platform, executing orders, receiving and transmitting orders, portfolio management over crypto-assets, providing transfer services, placing crypto-assets and providing advice on them. If your business falls within any of those categories and touches German clients or German-domiciled counterparties, the authorisation requirement applies. There is no de-minimis carve-out for size, and the test is activity-based – the legal form of the entity, its marketing language and its claim to be a "technology provider" are secondary to what the service actually does in economic substance.

BaFin has applied the activity-based approach consistently across the predecessor KWG (Kreditwesengesetz) crypto-custody regime and is expected to carry that interpretive rigour into MiCA supervision. Operators we advise who assumed that a non-EU entity marketing to German users from outside the EU fell outside scope have routinely been advised to reconsider. The key risk is not registration itself; it is operating while unregistered, which triggers criminal exposure and supervisory orders in addition to civil liability.

What does the BaFin CASP application process involve?

A CASP application to BaFin is a structured submission covering governance, capital adequacy, AML/CFT controls, IT security and the professional fitness of management. The MiCA regime specifies what the application must contain, and BaFin supplements that with its own supervisory expectations drawn from its prior experience with crypto-custody and e-money licensing. In our practice, the documentation burden is comparable to a mid-tier banking licence application – detailed, technical and unforgiving of gaps.

The core application package typically includes a programme of operations, a description of each crypto-asset service to be provided, evidence that the applicant entity meets the minimum own-funds requirement applicable to its category, governance documentation (organisational chart, internal controls, conflict-of-interest policy, outsourcing arrangements), an AML/CFT manual aligned to the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer), a business continuity plan, and fit-and-proper documentation for every member of the management body. Shareholders holding a qualifying stake must also pass BaFin's ownership vetting process.

BaFin operates within the statutory assessment period set by MiCA. The practical timeline from submission to decision – assuming the application is complete on filing – is typically a matter of months, not weeks. Incomplete applications restart the clock. In our cross-border practice, we have seen applicants lose several months because ancillary documents (IT audit reports, custody sub-custody agreements, signed management declarations) were missing at initial submission. BaFin does not informally complete an application on an applicant's behalf; it issues a request for information, which pauses the assessment period, and the burden falls entirely on the applicant to respond fully.

For a scoped assessment of your application readiness and to map the gaps before you file, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements and the services offered – change the analysis materially. Map your options.

Does a MiCA passport from another EU member state cover Germany?

A CASP authorisation granted by one EU or EEA national competent authority passports across all member states under MiCA, including Germany – meaning a business authorised in, say, Ireland or Lithuania may serve German clients without a separate BaFin authorisation, provided it follows the MiCA notification procedure for cross-border activity. This is the single most important structural decision for any inbound operator: apply directly to BaFin, or authorise in a jurisdiction with a lighter application burden and passport into Germany.

The choice is not straightforward. BaFin is one of the most experienced and, by reputation, most demanding NCAs in the EU. Its supervisory expectations are not relaxed simply because an entity holds a passport. A passported CASP that generates significant volume in Germany should expect BaFin to engage with the home-state regulator and, in some cases, to request that the entity establish a substantive presence in Germany under the anti-booking-entity rules that the European regulators – including ESMA – have applied in the investment-firm context. Operators whose revenue is predominantly German-sourced but whose registered office and management are entirely elsewhere have, in our experience, encountered friction from both BaFin and correspondent banks operating under German AML supervision.

The passport route therefore works well for operators with a genuinely diversified EU client base. It is less clean for a business that is, in substance, a German business run from a smaller jurisdiction for regulatory convenience. BaFin and ESMA have both signalled that letter-box entity structures are outside the spirit of MiCA passporting.

How do AML and the Travel Rule apply to a CASP operating in Germany?

German AML law implements the EU's anti-money laundering directives, and BaFin supervises CASPs for AML/CFT compliance alongside its prudential role. The obligations are substantial. A CASP must maintain a documented risk assessment, implement customer due-diligence procedures (standard and enhanced), screen against sanctions lists, report suspicious transactions to the Financial Intelligence Unit (FIU), and maintain records for the period specified under applicable law.

The Travel Rule – grounded in FATF Recommendation 15 and implemented in the EU through the Transfer of Funds Regulation (TFR) – applies to all transfers of crypto-assets above the applicable threshold. Under the TFR, the originator VASP must transmit originator and beneficiary information to the beneficiary VASP with the transfer, and the beneficiary VASP must verify and screen that information. BaFin expects CASPs to have technical solutions for Travel Rule compliance – typically a TRISA-protocol or inter-VASP messaging solution – in place at the point of authorisation, not as a post-authorisation project.

In our cross-border practice, Travel Rule readiness is one of the three most common points of application failure for inbound CASPs. The other two are governance documentation that does not name specific individuals with accountability for each controlled function, and AML manuals that describe processes at a policy level without specifying how they are implemented in the particular technology stack the applicant operates.

What are the cross-border tax and banking considerations for a CASP in Germany?

Germany sits at the centre of the EU's commercial banking system, and access to a German IBAN is a material competitive advantage for a crypto-asset business serving European retail and institutional clients. However, German banks subject to BaFin and Bundesbank supervision apply their own AML risk assessments to CASP customers, and a business without a completed or imminent authorisation will find correspondent banking relationships difficult to establish and to maintain.

On the tax side, Germany treats crypto-asset disposals by individuals as taxable where held for under a year, but the corporate tax treatment for a licensed CASP entity – trading book vs banking book classification, VAT position on services, transfer-pricing requirements for intra-group transactions with a parent or subsidiary in another jurisdiction – requires jurisdiction-specific analysis that goes beyond the MiCA authorisation itself. A German CASP that is part of a group structure typically has cross-border transactions: management fees, technology licences, or liquidity facilities with related entities. Each of those is a transfer-pricing risk in the hands of the German tax authorities (Finanzamt and Bundeszentralamt für Steuern). The prudent operator completes the tax structure analysis before the CASP entity is incorporated, not after BaFin approval.

Banking access is linked, in practice, to the stage of authorisation. Some German and European EMI-licensed payment institutions will bank a pre-authorisation CASP applicant during the application period, subject to enhanced due diligence; others will not open accounts until authorisation is granted. The sequencing – entity formation, bank account opening, BaFin pre-application engagement, formal submission – matters for cash flow and operational continuity. We map this sequence for every client undertaking a German licensing project.

What are the most common structural mistakes in a German CASP application?

The most frequent – and most costly – mistake is submitting an application before the governance infrastructure is genuinely complete. BaFin is not a development partner. It will not advise an applicant how to build the compliance function; it will assess whether the compliance function already exists, is adequately resourced, and is operated by individuals who can demonstrate their fitness and propriety. Applications that describe an intended structure rather than a functioning one are returned as incomplete, and the clock resets.

A second common error is underestimating the capital planning requirement. MiCA sets minimum own-funds thresholds that vary by the category of crypto-asset service provided. An entity that is capitalised only to the minimum may satisfy the static threshold but fail BaFin's dynamic assessment – the supervisory expectation that capital is adequate to cover operational risks, including regulatory fines, legal costs and technology failures, on a forward-looking basis.

Third: treating the German application as identical to a prior authorisation experience in a non-EU jurisdiction. BaFin is not BVI FSC or CIMA. The documentation standard, the management interview process and the ongoing supervisory engagement are qualitatively different from those of a registration-based offshore regime. Operators who arrived in Germany having previously registered under the BVI VASP Act 2022 or the Cayman VASP Act have, in our experience, consistently underestimated the documentation burden.

A recent CASP matter: building the application from an existing structure

In a recent licensing matter, a payments-adjacent business operating across two EU member states sought a CASP authorisation directly through BaFin rather than through a passport from its existing regulated home state, because a significant proportion of its institutional clients were German-based. The entity had an existing compliance function built for a different regulatory regime. We identified, at the gap-analysis stage, that the Travel Rule messaging solution was not interoperable with the standard inter-VASP protocols expected in the EU, and that three members of the management body lacked fit-and-proper documentation in the format BaFin uses. We restructured the governance documentation, sourced a compatible Travel Rule solution and prepared the fit-and-proper submissions before the formal application was filed. The application proceeded to assessment without a pause for a request-for-information cycle. The matter concluded in the second half of the prior year.

If your prior application stalled or a regulatory relationship has become difficult, a structured review can surface the reason and the route forward. Contact OBOLUS at info@oboluslaw.com. If you have already filed and received a request for information, the response window is not the time for improvisation. Map your options.

Which operator profile should apply directly to BaFin, and which should passport?

The decision turns on four axes: the concentration of the German client base, the operator's existing EU regulatory footprint, the availability of substance (management presence, employees, IT infrastructure) in Germany, and the timeline pressure from existing client commitments.

Profile A – Germany-first operator: a business whose primary market is Germany, whose institutional clients require a BaFin-supervised counterparty and whose management team can demonstrate presence in Germany. This operator applies directly to BaFin. The timeline is longer, the capital and governance requirements are demanding, and the supervisory relationship is permanent – but the result is a BaFin-authorised CASP that German banks and institutional clients treat as a peer entity.

Profile B – EU-broad operator with German exposure: a business serving clients across five or more EU member states, for which German clients represent a minority of revenue, and which already holds or is seeking a CASP authorisation in a jurisdiction with a developed MiCA implementation (such as an established EU financial centre). This operator passports into Germany following MiCA's notification procedure. The risk is ongoing scrutiny from BaFin if German volume grows; the structure should be reviewed against the substance expectations before that threshold is crossed.

Profile C – non-EU operator seeking EU access via Germany: a business headquartered outside the EU that wants to use a German entity as its EU CASP vehicle. This is viable but requires establishing genuine substance in Germany – not a registered address and a nominal director, but a functioning management body with accountability and decision-making capacity located in Germany. BaFin has stated publicly that it will apply substance tests consistent with ESMA's guidance on investment-firm structures. The non-EU parent will also need to consider whether it triggers any third-country service restriction under MiCA when dealing with EU clients through its non-EU entity concurrently with the German vehicle.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies significantly by jurisdiction and by the completeness of the application at filing. Under MiCA, the statutory assessment period runs from the date BaFin accepts the application as complete – not from the date of initial submission. In practice, a well-prepared application to BaFin takes a matter of months from a complete filing to a decision. Incomplete applications or those generating requests for information can extend that materially. Offshore registration-based regimes (BVI, Cayman) typically operate on shorter timelines, but the regulatory weight they carry is correspondingly lower.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on where your clients are, what services you provide, where your banking must sit and what your institutional counterparties expect from a regulated counterparty. A German BaFin CASP authorisation carries significant weight with European institutional clients and correspondent banks. A MiCA passport from a faster-to-authorise EU member state can achieve EU-wide coverage with a lighter initial burden. An offshore registration can satisfy AML obligations in certain markets but will not satisfy EU passporting requirements. We map the licence stack for each operator's specific profile before recommending a structure.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the defined CASP services – meaning it requires authorisation as part of, or in addition to, an operator's CASP authorisation. If a business provides custody as a standalone service, it must be covered by the authorisation. If custody is bundled with trading or transfer services, all activities must be within the scope of the single authorisation. BaFin will assess the custody function separately – including IT segregation, key management, safeguarding arrangements and sub-custody frameworks – regardless of whether it is licensed as a standalone or bundled service.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and tax stack across operating, custody and payment layers before a client commits – preventing the structural errors that are expensive to unwind after authorisation. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery matters arise. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and Asia-Pacific CASP/VASP authorisation processes, cross-border entity structuring and BaFin engagement strategy for inbound digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours