Operating a crypto exchange (a platform that buys, sells or exchanges digital assets for clients) in Germany without BaFin authorisation is not a gap in compliance – it is a criminal exposure. The Federal Financial Supervisory Authority (BaFin) treats exchange activity as a regulated financial service under German law, and the transition to the EU-wide MiCA (Markets in Crypto-Assets Regulation) regime does not eliminate that domestic obligation: it reshapes it. Any inbound operator – whether building from scratch or relocating an existing structure – must understand that Germany's licensing posture is among the most demanding in the EU, and that MiCA passporting, while real, does not arrive without cost or preparation.
This page sets out the regulated perimeter, the application process, the cross-border tax and banking realities, and the decision point an operator faces when weighing Germany against alternative EU entry routes.
What activities trigger BaFin authorisation?
The threshold for BaFin oversight is broad: any entity conducting crypto custody, crypto brokerage, proprietary dealing or multilateral exchange services in or from Germany requires authorisation. Under the pre-MiCA domestic regime, crypto assets were designated as financial instruments under the German Banking Act, drawing Germany's exchange and custody operators squarely into a full-authorisation track rather than a lighter registration model.
The MiCA transition changes the label – CASP authorisation (Crypto-Asset Service Provider) replaces the bespoke German instrument – but BaFin remains the competent national authority and retains its supervisory culture. BaFin has historically applied its full supervisory toolkit to digital-asset applicants, including detailed business-plan scrutiny, fit-and-proper assessments of management and significant shareholders, and minimum own-funds requirements that vary by the scope of licensed activity. Those requirements carry over into MiCA's CASP framework, where own-funds thresholds are set by activity class. None of those thresholds can be quoted here as fixed figures – they depend on the specific service combination and must be confirmed against current ESMA and BaFin guidance at the time of application.
Two activity combinations warrant particular attention. An operator running both trading and custody functions will face dual-layer authorisation obligations: the exchange service and the crypto custody service are treated as distinct regulated activities, each with its own capital and operational requirements. Secondly, if the platform handles fiat-to-crypto conversion as a primary function, payment services regulation may apply in parallel, adding a third authorisation dimension.
The regulated perimeter under MiCA covers the full service stack: trading platform operation, order matching, custody and administration of crypto assets on behalf of third parties, reception and transmission of orders, and exchange of crypto assets for funds or other crypto assets. An operator offering any one of these services to German users – even from a legal entity domiciled outside Germany – may be caught if the service is directed at the German market.
How does MiCA change the German licensing picture?
MiCA is already in force, and its full CASP authorisation framework is operative across the EU. For Germany, MiCA does not displace BaFin – it gives BaFin a harmonised rulebook to apply. An entity authorised as a CASP in Germany may passport that authorisation across the EU/EEA, which is the core commercial argument for the Germany route: one supervised structure, thirty-plus markets.
However, the passporting benefit has a practical ceiling. MiCA authorisation is granted at the legal entity level; the entity must have genuine substance in Germany. BaFin has been explicit in its expectations: a letter-box operation with a nominal registered address and management located elsewhere will not satisfy the requirement. The managing directors responsible for the German entity must be resident in or accessible to Germany, must pass individual fit-and-proper vetting, and must be able to demonstrate day-to-day responsibility for the licensed activities.
MiCA also introduces specific obligations for token issuers. If the exchange platform lists or offers asset-referenced tokens (ARTs) or e-money tokens (EMTs), the platform operator must assess whether whitepaper obligations or separate issuer authorisations apply. This is a due-diligence step, not an assumption. In our cross-border practice, we have seen operators underestimate the MiCA whitepaper perimeter when building listing pipelines – a gap that creates regulatory risk for the platform as well as the issuer.
The transition also carries a timing dimension. Operators that held a prior German authorisation under the domestic banking-act instrument have a defined transition window under MiCA. New entrants without any prior German licence apply directly for CASP authorisation. Both tracks converge on the same BaFin application process, but the documentation and evidence burden differs.
What does the BaFin CASP application process involve?
A BaFin CASP application is a structured documentary process with no shortcut. BaFin assesses the application in sequence: completeness check, substantive review, fit-and-proper interviews with key individuals, and determination. The substantive review alone typically takes several months. An applicant who submits an incomplete or internally inconsistent file will receive a deficiency notice and the clock effectively resets.
The application file must cover: corporate structure and ownership chain up to the ultimate beneficial owner; business plan with financial projections; organisational chart and description of internal governance; IT and cybersecurity architecture; AML/CFT policies and procedures; description of the custody and client-asset safeguarding model; a complaints and conflict-of-interest policy; and personal questionnaires for all management board members and qualifying shareholders. BaFin reserves the right to request additional information at any stage. Gaps in the AML documentation are the single most common reason for delay in the applications we have reviewed.
Minimum capital must be available and demonstrable from day one of the application – not just at the point of authorisation. The amount varies by the specific services applied for, and BaFin requires that own funds be held in a form it considers liquid and unencumbered. An applicant relying on a shareholder-loan structure or on cryptocurrency holdings to meet its capital requirement will need to work through those issues with counsel before filing.
The overall timeline from filing a complete application to receiving authorisation is measured in months rather than weeks. Operators we advise on comparable EU applications routinely build a planning horizon of six to twelve months for a well-prepared file, sometimes longer where BaFin issues multiple rounds of queries. Germany is not the fastest EU licensing route, and an operator with an urgent commercial timeline may need to consider whether a parallel jurisdiction provides an interim solution while the German structure is being built.
Process transparency note: BaFin publishes a register of authorised CASPs. Operating before authorisation is granted – even in beta or test mode with real client assets – is a regulatory breach and may constitute an administrative or criminal offence under German law.
CTA: The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking and capital position – change the analysis materially. Map your options with OBOLUS before you file, not after a deficiency notice arrives.
How does Germany fit into a cross-border digital-asset structure?
A Germany-domiciled CASP is rarely a standalone entity. In our cross-border practice, the typical inbound operator builds Germany into a group structure where the licensed EU entity operates the exchange, a separate holding company (often in a common-law jurisdiction) holds intellectual property and management functions, and banking relationships span multiple countries. Each layer of that structure has its own regulatory and tax footprint.
The cross-border note on banking is direct: German banks remain cautious toward crypto-exchange clients, particularly where the client book is global and includes high-velocity transaction profiles. A BaFin-authorised CASP is not guaranteed a banking relationship simply by virtue of its licence. Operators we advise approach banking as a parallel workstream to licensing – identifying the EU credit institutions willing to onboard exchange operators before the licence is granted, so that the infrastructure is ready to operate on day one of authorisation.
On the tax side, a German-resident entity operating an exchange generates taxable income in Germany. Corporate tax applies to net trading revenue, and the interaction with VAT on financial services (which are generally exempt in the EU, but the perimeter for crypto services is not always settled) must be mapped carefully. Withholding tax obligations on certain cross-border payments, thin-capitalisation rules on intra-group debt, and transfer pricing on services provided to or by non-German affiliates all require advance structuring. Germany's tax authority (Bundeszentrale für Steuern / Finanzamt) has been active in issuing guidance on crypto taxation, though specifics change and must be confirmed against current guidance at the time of structuring.
The AML/Travel Rule obligation applies in full. Germany has implemented the FATF Travel Rule – the obligation to pass originator and beneficiary identification data with each qualifying transfer – and BaFin expects exchange operators to demonstrate compliant transaction monitoring from day one. The de-minimis threshold below which the Travel Rule does not apply must be confirmed against current German transposition measures. Non-compliance at this layer has produced enforcement action against EU operators in recent supervisory cycles.
What should an inbound operator assess before choosing Germany?
The decision to licence in Germany rather than in another EU member state turns on a defined set of commercial and operational factors. Germany offers depth – a large domestic user base, a sophisticated institutional client pool, strong legal infrastructure and a globally recognised supervisory name that carries weight with banking and institutional counterparties. It does not offer speed or low cost of entry.
An operator should assess four decision axes before committing to Germany as the primary EU licensing hub.
First, substance requirements. Does the operator have – or can it build – genuine management presence in Germany? Remote-managed EU shells are a known BaFin concern, and a structure that fails the substance test will not receive authorisation regardless of the quality of the application documentation.
Second, capital availability. The minimum capital threshold for a full exchange operation with custody is meaningful. An operator whose equity position does not comfortably exceed the minimum – allowing for operational burn during the application period – is under-capitalised for the German market and should assess whether a narrower licence scope or a lighter jurisdiction is the right first step.
Third, timeline tolerance. A six-to-twelve-month licensing horizon is incompatible with a business model that needs live EU users within the next quarter. An operator in that position should consider whether an interim structure in a jurisdiction with a faster initial authorisation timeline – and a path to German passporting subsequently – serves the business better.
Fourth, product scope. An operator running only spot trading and custody has a more predictable path than one adding derivatives, staking yield products or complex structured tokens. The latter profile will face additional product-level regulatory analysis and may require separate regulatory conversations before the CASP application is even submitted.
Operators we advise on EU entry routinely work through these four axes before selecting a primary jurisdiction. Germany is the right answer for a significant subset of operator profiles – but not for all of them, and the cost of getting that decision wrong after committing resources to a German structure is high.
An illustrative cross-border application
In a recent licensing engagement, a payments technology company expanding from an Asian hub sought to establish a regulated EU exchange operation. The operator had an existing AML programme built for its home market and assumed it could be adapted for the German filing with modest amendment. Our review identified structural gaps in the custody safeguarding model and a capital plan that conflated shareholder loans with own funds. We restructured the application file – rebuilding the custody description, converting the capital structure to eligible instruments and reconfiguring the AML/Travel Rule documentation to meet BaFin's specific expectations. The application was filed complete on first submission. BaFin's substantive questions focused on IT architecture rather than AML – a materially better outcome than a deficiency notice on capital or custody, which would have added months to the process.
A common assumption about EU licensing needs correction
A common assumption among operators entering the EU for the first time is that a single offshore authorisation – whether from a Caribbean jurisdiction, an Asian hub or even a lighter EU member state – is sufficient to serve clients across all EU markets without further authorisation. That is not correct under MiCA. An operator serving German users with regulated CASP activities must hold either a MiCA CASP authorisation from a EU member state or demonstrate clearly that it falls within a defined exemption. Offshore licences, however reputable in their home market, do not constitute a MiCA authorisation. Enforcement of this boundary is an active supervisory priority across EU member states, including Germany.
The related assumption – that a holding structure in a low-regulation jurisdiction insulates the operating entity from BaFin's reach – is similarly unreliable. BaFin applies a substance-and-direction analysis: if the platform's commercial decision-making, IT infrastructure or client-facing operations are directed from Germany, the German licensing obligation may attach regardless of where the legal entity is registered.
If a prior application stalled or you are navigating a BaFin query on an existing structure, a second read of the facts frequently surfaces the structural issue and the route forward. Reach OBOLUS at info@oboluslaw.com to schedule an assessment under NDA.
Self-assessment: are you ready to file with BaFin?
Before engaging in formal pre-application discussions with BaFin or submitting an application, an operator should be able to answer affirmatively to each of the following.
- The legal entity is incorporated in Germany (or in an EU member state with a genuine establishment in Germany) and has a defined corporate governance structure.
- All managing directors and qualifying shareholders have been identified; personal questionnaires are prepared and no fit-and-proper issues are anticipated.
- Minimum own funds are available in eligible form and are not dependent on uncleared shareholder loans or crypto holdings.
- A complete AML/CFT policy suite is in place, including Travel Rule procedures calibrated to BaFin's transposition requirements.
- The IT and custody architecture has been documented in sufficient technical detail for a BaFin reviewer with no prior knowledge of the platform.
- The business plan includes financial projections for at least three years and identifies the specific CASP activities for which authorisation is sought.
- Banking relationships for the licensed entity have been scoped, even if not yet formalised.
An operator who cannot answer affirmatively to all seven points is not ready to file. Filing prematurely consumes BaFin review capacity, triggers a deficiency notice, and signals to the regulator that the applicant lacks the organisational maturity the licence requires. Regulators in leading hubs increasingly view a well-prepared first submission as evidence of the governance culture they are assessing.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full OBOLUS approach to mapping the licence stack across operating, custody and payment layers.
- VASP licensing in Malta – how Malta's MFSA regime and MiCA transition compares for operators weighing EU entry routes.
- Worldwide freezing orders: where the legal lines are drawn – cross-border enforcement and asset-recovery options for digital-asset businesses.
FAQ
How long does a crypto licence take to obtain?
Timeline depends on jurisdiction and application quality. A BaFin CASP authorisation in Germany typically requires several months from submission of a complete file – commonly six to twelve months in well-prepared cases, and longer where BaFin issues multiple information requests. Lighter EU regimes and offshore VASP registrations operate on shorter timelines. Filing prematurely extends the process; a complete, internally consistent application is the single most important timing variable within an applicant's control.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on the operator's service scope, user geography, capital position, substance capacity and commercial timeline. Germany via BaFin offers EU passporting and reputational depth but requires genuine local substance and significant lead time. Other EU member states, Singapore, the UAE and offshore common-law jurisdictions each serve different operator profiles. We map those options against the specific facts before recommending a primary licensing hub.
Do I need a separate custody licence?
In Germany and across the MiCA regime, custody and administration of crypto assets on behalf of third parties is a distinct regulated activity. An exchange operator that also holds client assets – whether hot wallets, cold storage or both – will generally need the custody service included in its CASP authorisation. Operating combined exchange and custody functions under a single CASP authorisation is possible, but each activity adds its own capital and operational requirements. The precise scope must be assessed against the specific service architecture before filing.
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the full operating, custody and payment layer before you commit. We regularly advise inbound operators on EU entry structures and on managing BaFin's expectations across the application cycle. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in regulated entry for digital-asset operators across EU and multi-jurisdictional licensing mandates, with a focus on BaFin, MiCA CASP authorisation and cross-border structure design.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.