CASP Authorisation Under MiCA in Luxembourg
Operating a digital-asset business in the European Union without the correct authorisation now carries real enforcement risk. Under MiCA (the Markets in Crypto-Assets Regulation), any business providing crypto-asset services to EU clients must hold a CASP authorisation (Crypto-Asset Service Provider authorisation) granted by a competent authority in a member state. Luxembourg, supervised by the Commission de Surveillance du Secteur Financier (CSSF), has emerged as a credible EU entry point for inbound operators — combining a well-developed financial-services infrastructure, an established fund and payments regulatory tradition, and the passporting rights that MiCA confers across the EU and EEA. This page sets out the regulated basis, the application process, the cross-border interactions that shape the decision, and the common mistakes we see when businesses approach CASP authorisation without adequate preparation.
The Regulated Basis: MiCA, the CSSF, and What Triggers Authorisation
A business triggers the MiCA CASP authorisation requirement as soon as it provides one or more of the regulated crypto-asset services listed in the regulation to clients located in the EU, regardless of where the legal entity is incorporated. The CSSF is Luxembourg's designated national competent authority under MiCA, sitting within a tradition of supervising sophisticated financial institutions — including some of the largest fund administrators and payment institutions in the EU. That supervisory culture sets the baseline for what the CSSF expects from a CASP applicant.
The regulated services under MiCA are activity-based. They include custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for fiat or for other crypto-assets, execution of orders, placing of crypto-assets, reception and transmission of orders, providing advice, and portfolio management. A business need only provide one of these services to require authorisation. In our practice, the most common positions are custody-plus-exchange or exchange-plus-order-execution, both of which engage multiple regulated categories simultaneously.
The MiCA regime also draws a hard line on token classification. An operator must assess whether the assets it handles are asset-referenced tokens (ARTs), e-money tokens (EMTs), or "other" crypto-assets — the ordinary CASP activities attach primarily to the last category, while ARTs and EMTs carry additional issuer-authorisation requirements. Getting that classification wrong at the outset distorts the entire application. We see businesses regularly underestimate the ART/EMT exposure when they offer stablecoin-denominated products.
The passporting mechanism under MiCA is the structural advantage of authorising in Luxembourg. A CASP authorised by the CSSF may notify other EU and EEA member-state competent authorities and begin providing services in those jurisdictions without a fresh authorisation. For a business whose commercial model spans France, Germany, the Netherlands and Spain — a common configuration for a retail exchange or a B2B custody provider — the single-authorisation-plus-passport path is materially more efficient than applying jurisdiction by jurisdiction.
Who Needs CASP Authorisation in Luxembourg?
Any entity that (a) is incorporated in Luxembourg and provides covered services, or (b) intends to use Luxembourg as its EU base for a cross-border MiCA-passported operation, needs CASP authorisation from the CSSF. There is a limited transitional period for entities that were providing crypto-asset services in Luxembourg before MiCA's authorisation provisions applied — those businesses may continue operating for a defined period under that transitional protection, but it does not extend indefinitely, and planning the authorisation application as if the deadline is imminent is the correct posture.
A branch of a non-EU parent is not the same as a separately authorised EU entity under MiCA. Operators who believe a branch structure side-steps the authorisation requirement are mistaken. The MiCA regime requires a legal entity established in a member state, with genuine substance — governance, compliance, risk management and qualified personnel — present there. The CSSF applies a substance test that reflects its general supervisory culture: Luxembourg entities must be more than letterboxes.
Third-country firms wishing to serve EU clients may rely on the reverse solicitation exemption — where the client approached the service provider exclusively on the client's own initiative — but that exemption is narrow. ESMA has signalled that it expects member-state competent authorities to apply it restrictively. Operators who rely on reverse solicitation as a primary commercial strategy rather than a genuine exception are building on uncertain ground.
CTA #1
If you are assessing whether your business model triggers CASP authorisation in Luxembourg, the analysis turns on your activity mix, your token types and your user-base geography. These are fact-specific questions. The process above describes the standard path — your entity structure, your user base and your banking arrangements change the analysis. Map your options with our licensing desk before you commit to a structure.
What Does the CASP Application Process in Luxembourg Involve?
A complete CASP application to the CSSF is a substantial document set, and the quality of preparation is the primary determinant of how smoothly the review proceeds. The application covers the legal, governance, operational and financial dimensions of the business — the CSSF expects a realistic operating model, not a set of aspirational statements.
The core components of a Luxembourg CASP application include: a detailed description of the services to be provided and the assets to be covered; the corporate documents of the applicant entity; a programme of operations showing projected activity, client types and volumes; governance arrangements including the composition and qualifications of the management body; internal controls — covering AML/CFT, risk management, IT security and business continuity; capital and own-funds evidence demonstrating compliance with the minimum capital requirements set by MiCA for the relevant service category; and a description of the safeguarding arrangements for client assets where custody is involved.
The governance standard is not merely formal. The CSSF will assess the fitness and propriety of directors and senior managers individually. Criminal records checks, professional background verification and competency assessments in financial services or digital assets are standard. A management body composed entirely of individuals without relevant financial services experience is likely to face challenge — the CSSF expects at minimum a meaningful representation of regulated-sector expertise at board level.
AML/CFT readiness is assessed with particular scrutiny. Luxembourg operates a strong AML supervisory tradition, and the CSSF expects a CASP applicant to demonstrate a risk-based AML/CFT framework that is already operable, not merely planned. The Travel Rule (the obligation under FATF Recommendation 15 and its EU transposition to pass originator and beneficiary data with a virtual-asset transfer) must be addressed explicitly — including the technology solution the applicant will use for Travel Rule compliance. We have seen applications delayed significantly because the Travel Rule solution was described in generic terms rather than implemented and tested.
In terms of timing, the CSSF operates within the statutory review windows established under MiCA, though the practical elapsed time from submission to decision depends heavily on the completeness of the initial filing. Incomplete applications generate questions; each exchange of correspondence resets or extends the clock. A well-prepared filing, with all required annexes and a clear programme of operations, moves materially faster than one submitted in draft form. We advise clients to treat the completeness of the initial submission as a primary project objective — not the submission date.
Capital Requirements and Ongoing Supervisory Obligations
MiCA sets minimum own-funds requirements by service category, and in Luxembourg these apply as set out in the regulation — the CSSF does not currently impose additional capital add-ons specific to Luxembourg above the MiCA floor, though supervisory discretion exists. The capital threshold varies by service type: operators providing only advisory services face a lower minimum than those operating a trading platform or providing custody. A business offering multiple services must satisfy the highest applicable threshold across its regulated activities.
Ongoing obligations after authorisation are substantial. A Luxembourg-authorised CASP must report to the CSSF on a periodic basis, maintain the substance requirements continuously — not merely at the point of authorisation — notify the CSSF promptly of material changes to the business, and comply with the MiCA conduct-of-business rules. These include fair, clear and non-misleading marketing, conflict-of-interest management, best-execution obligations where relevant, and the requirements around the content and format of the white paper for the crypto-assets the CASP handles.
Client asset safeguarding is one of the most operationally demanding ongoing requirements. A CASP holding client crypto-assets must maintain those assets separately from its own assets, reconcile client positions regularly, and ensure that in an insolvency scenario client assets are ring-fenced. The operational model for this — which typically involves cold-storage architecture, reconciliation software and an agreed insolvency protocol — must be designed before authorisation and documented in the application.
How Do Tax and Banking Interact With a Luxembourg CASP Structure?
The legal authorisation is only one layer of a viable operating structure. Banking and tax must be resolved in parallel — an authorised CASP that cannot open a corporate account is commercially stranded, and a structure that creates unintended tax exposure erodes the commercial rationale.
Luxembourg has a developed banking sector with genuine experience in financial-institution and fund-administration client relationships, and several banks have demonstrated willingness to onboard regulated financial entities in the digital-asset space. That willingness is, however, selective. Banks conduct their own AML/CFT risk assessment of a CASP applicant separately from the CSSF's regulatory review. A business whose transaction volumes, client geography or asset types sit at the higher end of the risk spectrum may face prolonged banking due diligence regardless of the strength of its regulatory application. We advise clients to initiate banking conversations early in the project timeline — not after authorisation is granted.
The cross-border dimension complicates the banking picture further. A Luxembourg entity passporting into multiple EU jurisdictions may have clients, settlement counterparties and banking relationships spanning several countries. Correspondent-banking chains, SEPA eligibility and the interaction between fiat on/off ramps and the CASP's regulated services all require mapping. We regularly advise on the full stack — entity, licence, bank, settlement layer — rather than the authorisation in isolation.
On tax, Luxembourg offers a relatively efficient corporate tax environment for holding and operating structures within the EU. However, the tax treatment of crypto-asset revenues — whether fees are characterized as financial-service income, the VAT position on services to retail versus professional clients, and the treatment of staking or yield-bearing products — is jurisdiction-specific and evolving. The interaction between a Luxembourg operating entity and any non-EU holding or treasury structure adds complexity that is best addressed by tax counsel specializing in digital assets before the entity is incorporated. Generic structuring advice that does not account for the specific revenue streams of the CASP model can create exposure that is expensive to unwind later.
A Recent Authorisation Matter: Cross-Border Custody and Exchange
In a recent licensing engagement, a payments company with an existing EU payment institution licence sought to expand into crypto-asset custody and exchange services targeting professional clients across the EU. The business had assumed its existing regulatory status would provide a head-start in the CASP authorisation process. In practice, the CSSF assessed the CASP application on its own merits — the prior licence provided credibility on governance, but the technical requirements for crypto custody, including cold-storage architecture and the Travel Rule solution, were entirely new obligations the business had not previously encountered. We assisted the business in redesigning its operational model, preparing the programme of operations with realistic volume assumptions, and navigating the substance and fit-and-proper requirements for the additional management appointments required for the crypto activities. Authorisation was obtained, and the business subsequently passported its CASP status into four additional EU member states using the MiCA notification mechanism.
Which Operator Profile Should Authorise in Luxembourg?
Luxembourg is not the right CASP jurisdiction for every business. The choice of EU authorisation jurisdiction involves a trade-off between regulatory tradition, operational cost, banking access and commercial proximity to the target market. The matrix below describes the profiles we most commonly see.
Profile A — Institutional B2B operator (custody provider, prime brokerage, settlement infrastructure): Luxembourg is well-suited. The CSSF's institutional supervision tradition, the depth of the banking sector and the EU passport value are aligned with this model. The application complexity and substance requirement are a reasonable fit for a business that already has institutional-grade governance and controls.
Profile B — Retail exchange with pan-EU ambition: Luxembourg is viable but demands significant local substance. A business whose commercial centre of gravity is, for example, Germany or France may find that the operational cost of genuine Luxembourg substance sits uncomfortably against the alternative of authorising in a member state closer to its primary market. The passport is equally available from any member state, so proximity to the market and CSSF supervision costs both matter in the analysis.
Profile C — Early-stage operator with limited capital: Luxembourg is unlikely to be the most efficient entry point. The minimum capital requirements under MiCA, combined with the CSSF's substance expectations and the professional costs of a complete authorisation application, represent a material commitment. An operator not yet at the scale to justify that investment should consider whether a transitional or lighter-touch EU registration in another member state is a better first step.
Profile D — Non-EU parent seeking an EU CASP subsidiary: Luxembourg is a strong candidate. The jurisdiction's position as an EU financial-services hub, its treaty network and its familiarity with group structures make it operationally convenient. The critical issue is demonstrating genuine substance — that the Luxembourg entity is not merely a regulatory shell for a business whose real operation sits outside the EU. The CSSF will probe this.
CTA #2
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Operators who have previously engaged with the CSSF or another competent authority and hit difficulty often benefit from an independent review of the application file before re-engagement. Map your options with our licensing team.
A Common Assumption Worth Correcting
A common assumption among inbound operators is that a single offshore licence — whether from a Caribbean or Pacific jurisdiction — is sufficient to serve EU clients. That position was always legally uncertain, and under MiCA it is clearly incorrect. MiCA requires an entity established in a member state with an active CASP authorisation from a competent authority. Third-country firms may rely on the reverse-solicitation exemption in limited circumstances, but ESMA has been explicit that the exemption does not apply where the service provider takes any active marketing step toward EU clients. A business relying on an offshore licence as its primary basis for EU service provision faces enforcement risk, banking closure and reputational damage — all of which are materially harder to resolve after the fact than before.
The corollary is that the authorisation process, while demanding, is the durable solution. A Luxembourg CASP authorisation is an EU-wide operating licence. It creates the regulated foundation that institutional counterparties, banking partners and sophisticated clients expect, and it positions the business correctly for the increasingly enforcement-focused EU supervisory environment. The cost of getting it right the first time is lower than the cost of remediation after an enforcement finding.
Related at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – end-to-end CASP, VASP and exchange licensing across 70+ jurisdictions
- Digital-Asset Licensing in Estonia – EU VASP and MiCA transition analysis for another leading EU entry point
- Tax Treatment of Tokens: Practical Lessons for Boards – structuring insight on token revenue, VAT and corporate tax interactions
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the CSSF operates within statutory review windows set by the regulation, but the practical elapsed time varies with application completeness. A fully prepared filing — covering governance, capital, AML/CFT, Travel Rule compliance and the programme of operations — moves materially faster than an iterative submission. In our experience, incomplete initial filings are the primary cause of extended timelines. Businesses should budget for a process measured in months, not weeks, and begin preparation well in advance of any commercial launch date.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right EU home depends on your service mix, client geography, capital position, banking relationships and operational footprint. Luxembourg suits institutional and B2B operators well; other member states may be better suited to retail-focused or early-stage businesses. For non-EU operations, the analysis extends to Singapore, Dubai, Hong Kong and other leading hubs. We map the full decision matrix across the licence, banking and tax layers before recommending a path.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated service. If your business holds client assets — even as an ancillary activity to exchange or advisory services — that activity triggers the custody authorisation requirement separately. A business providing both exchange and custody services must ensure its CASP authorisation explicitly covers both. Structural separation of the custody function into a dedicated legal entity is sometimes considered for operational and risk-management reasons, and that decision has implications for the authorisation, capital and banking architecture.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the entirety of our practice — we act for businesses, not retail clients. We map the licence, banking and tax stack across operating, custody and payment layers before you commit, because the structure you build now determines the options you have later. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in EU MiCA CASP authorisation, VARA licensing and multi-jurisdictional regulatory entry strategy for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.