EST · MMXXVI
Home/Jurisdictions/Ireland/CASP authorisation under mica in Ireland
Licensing & Registration

CASP authorisation under mica in Ireland

Casp authorisation under mica in Ireland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

CASP Authorisation Under MiCA in Ireland

Operating a digital-asset business into the European Union without a valid authorisation is no longer a grey-area risk – it is an enforcement trigger. Under the Markets in Crypto-Assets Regulation (MiCA), any business providing crypto-asset services to EU clients must hold a CASP authorisation (crypto-asset service provider authorisation) issued by a national competent authority within the bloc. Ireland, supervised by the Central Bank of Ireland (CBI), is emerging as a credible EU gateway for inbound operators who want a stable common-law jurisdiction, English as the working language, and a regulator with a long track record in financial-services authorisation. This page sets out the regulated basis, the application process, the cross-border interaction with banking and tax, and the points at which an operator should engage counsel.

What MiCA Requires of a CASP in Ireland

MiCA creates a unified EU-level authorisation regime for crypto-asset service providers, and the Central Bank of Ireland acts as the national competent authority for entities incorporated in Ireland. A CASP authorisation covers a defined list of crypto-asset services: reception and transmission of orders, execution of orders, exchange services, placing of crypto-assets, operation of a trading platform, custody and administration, transfer services, portfolio management, and advice. An operator must hold authorisation for each activity it actually performs – a custody-only business does not automatically cover trading.

The passporting mechanic is among MiCA's most commercially significant features. A CASP authorised in Ireland may passport its services across all EU and EEA member states without seeking a separate licence in each. For an exchange or custodian targeting continental European users, a single Irish authorisation is operationally efficient. That efficiency only materialises, however, if the Irish entity has genuine substance – a board with competent individuals, adequate own funds, and operational infrastructure that satisfies the CBI's expectations.

MiCA also establishes distinct regimes for asset-referenced tokens (ARTs) and e-money tokens (EMTs). Issuers of those instruments face additional whitepaper obligations and reserve and redemption requirements beyond the baseline CASP regime. An operator whose business model involves issuing or dealing in ARTs or EMTs should map those obligations separately before selecting Ireland as a base.

Who Needs a CASP Authorisation in Ireland?

Any legal entity incorporated in Ireland that provides one or more of MiCA's listed crypto-asset services on a professional basis needs a CASP authorisation from the Central Bank. The test is activity-based, not label-based. A firm that calls itself a "software provider" but in practice executes orders or holds client assets will fall within the perimeter.

Inbound operators frequently ask whether an existing EU entity – a Lithuanian VASP registration, a Maltese VFA authorisation – satisfies the Irish requirement. It does not, directly. Under MiCA, authorisation is granted by the competent authority of the home member state of incorporation. An operator that wishes to use Ireland as its EU gateway must incorporate an Irish entity and apply to the CBI. Existing EU-authorised entities may passport into Ireland, but the passporting entity is the foreign CASP, not a locally incorporated subsidiary without its own authorisation.

Third-country operators – businesses incorporated outside the EU – face an additional constraint. MiCA does not provide a third-country equivalence or passporting pathway. A non-EU firm that wants to serve EU retail or professional clients at scale needs an EU-incorporated CASP. Ireland is one of the jurisdictions where that entity can be seated.

The Central Bank of Ireland has made clear through its broader supervisory posture that it will scrutinise the substance of applicants. A brass-plate entity without genuine Irish-resident governance is unlikely to satisfy the CBI's fitness and propriety standards.

What Does the CASP Application Process in Ireland Involve?

The application process under MiCA runs through the Central Bank of Ireland and follows a structured submission, review, and decision sequence whose duration reflects the complexity of the applicant's proposed activities. A complete application requires a detailed programme of operations, a governance and ownership structure, individual fitness and probity assessments for key function holders, a capital adequacy demonstration, an AML/CFT framework, a complaint-handling procedure, a safeguarding policy for client assets, and – where applicable – IT and cybersecurity documentation.

MiCA sets a statutory maximum assessment period after the competent authority receives a complete application. In practice, an application that is well-prepared and complete on first submission moves faster than one that draws rounds of questions from the CBI. Operators we advise are routinely surprised by the volume of AML-specific documentation the CBI expects upfront. Ireland's AML/CFT environment is shaped by FATF standards – including the Travel Rule (the obligation to pass originator and beneficiary data with a transfer above the applicable threshold) – and the CBI expects to see a credible, implemented programme, not a policy template.

The fitness and probity process for proposed controlled-function holders deserves particular attention. The CBI will assess each individual's qualifications, relevant experience, and any regulatory history. A key appointment that fails this process can suspend an otherwise complete application. In our cross-border practice, we have seen applications derailed at this stage because a proposed director held a position at a previously supervised entity that drew regulatory censure in another jurisdiction.

Capital adequacy under MiCA is stratified by the type of service. Own-funds requirements vary by activity class, and an operator providing multiple services must meet the applicable threshold for each layer. Because the numeric thresholds carry a [VERIFY] tag in our registry – meaning they are set by reference to the delegated acts under MiCA that remain subject to revision – we describe this requirement qualitatively: the relevant minimum is set by the applicable MiCA provisions and delegated legislation, and it must be satisfied in cash or qualifying financial instruments at the time of authorisation and maintained thereafter.

CTA: The process above describes the standard path. Your facts – the entity structure, the proposed activities, the ownership chain, the user base – change the analysis in material ways. For a scoped assessment of your Irish CASP application strategy, contact OBOLUS at info@oboluslaw.com. Or map your options with us first.

Does Substance in Ireland Actually Matter?

Substance is not a checkbox – it is the foundational condition for a credible CASP authorisation in Ireland, and the Central Bank of Ireland has the supervisory tools to assess it. MiCA requires that a CASP have its head office in the member state where it is authorised. The CBI's interpretation of that requirement follows the logic established in its post-Brexit supervisory approach for financial-services firms: mind and management must demonstrably sit in Ireland.

In our practice, we regularly advise clients on how to structure genuine Irish substance before they submit an application. That means resident directors with relevant skills and enough time to discharge their obligations, physical office presence or a credible shared-service arrangement, a compliance officer who is not simultaneously performing the same role for three other entities in three other jurisdictions, and board meeting records that reflect Irish decision-making rather than rubber-stamping of decisions made elsewhere.

The substance requirement also interacts with the fitness and probity test. A board member who is resident in Singapore and holds the same role at entities in Dubai and the Cayman Islands may struggle to demonstrate the availability and independence of judgment the CBI expects. These are not abstract concerns – they surface in the pre-application engagement that the CBI makes available, and addressing them early saves material time and cost.

For groups that are already operating across multiple jurisdictions, the Irish entity's relationship with its parent and with allied entities needs to be documented carefully. Intra-group outsourcing arrangements, shared compliance infrastructure, and group-level governance policies must all be disclosed and assessed for consistency with MiCA's requirements on outsourcing and on the primacy of the authorised entity's board.

How Does Irish CASP Authorisation Interact With Tax and Banking?

A CASP authorisation is a regulatory status, not a tax or banking solution, and operators who treat it as the end of the structuring exercise regularly discover the gap the hard way. In our cross-border practice, we structure the licensing, banking, and tax layers as a single mandate because the failure of any one layer typically blocks the others.

On the tax side, Irish corporation tax applies to profits attributable to the Irish entity, and the interaction between Ireland's tax treaties, the OECD's transfer-pricing framework, and intra-group arrangements for technology, risk, and capital deserves early-stage analysis. A CASP that books trading revenue in Ireland but has its key risk and technology functions located elsewhere may face a permanent establishment argument or a transfer-pricing adjustment. We work with specialist tax counsel to map this before the entity structure is committed.

Banking for crypto-asset businesses remains a practical constraint across the EU, including in Ireland. Irish domestic banks have varied and evolving policies toward VASP and CASP clients. At authorisation stage, a business plan that assumes smooth banking access without a credible analysis of where and how the business will hold client e-money, operational funds, and reserve assets is incomplete. Operators we advise are routinely guided to map their banking stack in parallel with the licence application, and sometimes to look at non-Irish EU payment institutions or EMIs as part of the operating model. Allied counsel in the relevant jurisdiction can assist where the banking solution requires a non-Irish counterpart relationship.

The cross-border reality for a passporting CASP is also worth flagging in this context. Passporting means the Irish authorisation is recognised in other member states. It does not mean that local AML, consumer-protection, or marketing rules in those member states are automatically displaced. A CASP passporting from Ireland into Germany, France, or the Netherlands must comply with the local rules applicable to passported firms – a fact that operators sometimes overlook until a local regulator raises the point.

CTA: If your application has stalled at the banking or structuring stage, or if a prior engagement with the CBI has raised questions you have not yet resolved, a focused second review can identify the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options.

What AML and Travel Rule Obligations Apply?

A CASP authorised in Ireland is subject to the full FATF-aligned AML/CFT regime applicable to virtual-asset service providers, implemented through EU Anti-Money Laundering Directives and the MiCA supervisory expectations of the Central Bank. The Travel Rule – FATF Recommendation 15's requirement that originators and beneficiaries of virtual-asset transfers above the applicable threshold exchange identifying information – applies to Irish CASPs for qualifying transactions.

The Travel Rule creates both a compliance infrastructure challenge and a cross-border coordination problem. An Irish CASP sending a transfer to a VASP in a third country must assess whether the counterpart VASP is Travel-Rule-capable and what the applicable threshold is in the relevant jurisdiction. The FATF's standards set a baseline, but implementation varies: some jurisdictions have set lower thresholds or applied the rule to additional instrument types.

In our practice, we have seen Travel Rule compliance treated as a technical problem – a question of choosing the right interoperability protocol – when it is equally a legal and operational problem. The applicant must demonstrate to the CBI at authorisation stage that it has a credible Travel Rule programme: written policies, a counterpart VASP due-diligence process, a technical solution for data transmission, and a procedure for handling transfers where the beneficiary VASP cannot receive Travel Rule data.

KYC and transaction monitoring expectations follow the same risk-based logic. A CASP serving professional counterparties in a small number of jurisdictions carries a different risk profile from a retail exchange serving clients across twenty countries, and the AML programme must be calibrated accordingly. The CBI has signalled in its supervisory communications that it expects AML compliance to be embedded in the business, not grafted on as a pre-application exercise.

A Recent Licensing Matter: From Third-Country Operator to Irish CASP

In a recent licensing engagement, a custody and exchange business incorporated outside the EU sought an EU gateway to serve institutional clients. The operator had previously registered under a third-country VASP regime and assumed that registration would ease the MiCA application. We advised early that the third-country registration carried no formal status under MiCA and that the CBI would assess the Irish application on its own terms. We structured a new Irish entity with three resident directors drawn from the client's existing senior team, mapped the intra-group outsourcing agreements against MiCA's outsourcing requirements, and prepared a Travel Rule programme from the ground up. The application was submitted as a substantially complete package; the CBI's first-round questions were confined to clarifications rather than substantive requests for additional documentation. The entity received authorisation within the statutory timeframe. The exercise also surfaced a banking gap that the operator had not anticipated – resolved in parallel by identifying a suitable EU-regulated payment institution as a safeguarding bank.

What Are the Most Common Mistakes in the CASP Application Process?

The most consistent failure mode in CASP applications is submitting before the entity is ready – filing a programme of operations that describes an intended business model rather than a built one. The Central Bank of Ireland expects to see that the governance, the compliance function, the AML programme, and the capital are in place or credibly committed, not projected. An application that reads as a business plan rather than an operational description will draw extended information requests.

A second frequent mistake is underestimating the fitness and probity process. Operators sometimes propose board members who are competent in their technical field but have no prior regulated-entity experience, or who are already stretched across multiple roles. Preparing each proposed key function holder with a structured briefing on the CBI's expectations and a clean, consistent biography narrative is not optional – it is a precondition for moving quickly through this phase.

A common assumption among inbound operators is that a single offshore licence – a BVI registration, a Cayman filing, or a registration in a jurisdiction outside the EU – is sufficient to serve EU clients at scale. That assumption is incorrect under MiCA. Where services are offered to EU persons on a professional basis, the MiCA perimeter applies regardless of where the service provider is incorporated. Relying on an offshore registration while serving EU clients carries enforcement risk, banking risk, and reputational risk. An Irish CASP authorisation, paired with genuine substance, is the durable solution.

Third, operators frequently underestimate the banking work. A CASP authorisation without a banking relationship for client safeguarding and operational funds is an authorisation that cannot trade. Starting the banking conversation at the same time as the licence application – not after it – is consistently one of the pieces of practical advice we give earliest.

How Does Ireland Compare to Other EU Licensing Venues?

Ireland is not the only EU jurisdiction offering a CASP authorisation pathway, and a decision to base an EU CASP in Ireland rather than elsewhere turns on a set of business-specific factors rather than a universal preference. Lithuania has historically been a faster, lower-cost entry point for smaller operators and maintains a developed VASP registration ecosystem that transitions to the MiCA CASP framework. Malta's MFSA-supervised VFA framework is similarly transitioning to MiCA, with a regulator that has extensive crypto-specific experience. The AIFC in Kazakhstan offers a common-law alternative for operators focused on Central Asian or CIS client bases, but it is not an EU regime and does not provide EU passporting.

Ireland's advantages for an inbound operator are: English as the working language and legal system; a common-law legal tradition; a well-resourced regulatory authority with a track record across financial-services sectors; an extensive double-tax treaty network; and, in practical terms, a business environment that is familiar to US, UK, and Asian operators who already have EU legal counsel or operational infrastructure in Ireland.

The CBI's standards are high. Compared to some EU NCAs, the CBI has not historically been among the fastest to grant authorisation, and its substance expectations are genuine. For an operator willing to invest in the entity properly, however, the Irish authorisation is among the more defensible EU CASPs – a factor that matters both for banking counterparties and for institutional clients who conduct their own due diligence on the regulatory status of their service providers.

For an operator profile that prioritises speed and cost over EU stature, a Lithuanian CASP or a Maltese authorisation may be more appropriate at the initial stage, with a subsequent migration or expansion to Ireland as the business scales. We regularly advise on sequenced licensing strategies of that kind.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the Central Bank of Ireland works within a statutory maximum assessment period following receipt of a complete application. In practice, timeline varies materially by the completeness of the submission and the complexity of the proposed activities. A well-prepared, complete application for a single service category moves faster than a multi-activity application with gaps. Operators should plan for the process to take a number of months from first submission to authorisation decision, and should build that window into their commercial launch planning.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on your target client base, the services you offer, your entity structure, your banking relationships, and your tax objectives. For EU market access with passporting, an Irish or Lithuanian CASP authorisation is a strong starting point. For operators focused on the MENA region, VARA or the ADGM/FSRA regime may be more appropriate. We map the full licence, banking, and tax stack before recommending a jurisdiction – the cheapest licence is often not the most commercially durable one.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated service. If your business model includes holding client assets – private keys, wallet infrastructure, or tokenised securities in custody – you need your CASP authorisation to cover that activity specifically. A CASP authorised only for exchange or order-reception services cannot lawfully provide custody. In our practice, we regularly see operators whose original licence scope does not cover a custody function they are already performing – a gap that creates both supervisory and contractual risk.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. We structure licensing, banking, and tax as one mandate rather than three disconnected workstreams – mapping the full operating, custody, and payment stack before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and cross-border CASP authorisation, MiCA transition strategy, and multi-jurisdiction licence stacking for digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours