CASP Authorisation Under MiCA in Nigeria
A Nigerian-founded crypto exchange scaling into European user markets faces a precise legal question the moment it onboards its first EU resident: does it need a CASP authorisation (the Crypto-Asset Service Provider licence created by the EU Markets in Crypto-Assets Regulation, MiCA) before that user can legally be served? The answer is yes – and the structure that delivers it almost never sits in Lagos. MiCA authorisation requires an EU-nexus entity, a competent national authority, and a compliance architecture that integrates with Nigeria's own evolving digital-asset regime. This page sets out the regulated basis, the practical process, the cross-border interaction with Nigerian law and banking, and the decision points that determine which structure works for a Nigeria-linked operator.
What Does MiCA Actually Require of a Nigeria-Based Operator?
MiCA authorisation is mandatory for any entity providing crypto-asset services to clients located in the European Union, regardless of where the operator is incorporated or headquartered. A Nigerian company cannot self-authorise. It must establish – or act through – a legal entity incorporated in an EU or EEA member state, authorised by that state's national competent authority under the supervisory architecture coordinated by ESMA (the European Securities and Markets Authority). The Nigerian parent may own that entity entirely, but the regulated seat must be in the EU.
MiCA introduces a single CASP authorisation framework that replaces the patchwork of national registration regimes that preceded it. Activities covered include exchange services, custody, portfolio management, and order execution for crypto-assets. Each activity is a distinct regulated function. An operator offering exchange and custody services holds both permissions, not a single combined licence. The regime applies across all 27 EU member states plus the EEA, meaning a CASP authorised in, say, Lithuania or Malta can passport its services across the bloc without a fresh authorisation in each country.
For a Nigeria-linked business, this creates a two-layer legal reality. The EU subsidiary carries MiCA CASP authorisation and services European clients. The Nigerian parent or affiliate operates under the framework administered by the Securities and Exchange Commission of Nigeria (SEC Nigeria), which has its own digital-asset registration obligations under the Investments and Securities Act and associated rules for Virtual Asset Service Providers. The two regimes are distinct. Compliance with one does not satisfy the other.
How Does SEC Nigeria's VASP Framework Interact With MiCA?
SEC Nigeria has moved decisively to bring digital-asset businesses within a regulated perimeter. Under the rules issued by SEC Nigeria, entities operating as Virtual Asset Service Providers (VASPs) – including exchanges, wallet providers and token issuers targeting Nigerian users – are required to register and comply with AML/CFT obligations consistent with FATF Recommendation 15, which extends the financial-action standards to virtual asset activities.
The FATF Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual-asset transfer – applies in both directions. An EU-licensed CASP sending a transfer to a Nigerian VASP must satisfy Travel Rule requirements on the EU side. The Nigerian counterpart must satisfy them under the domestic AML framework. If the Nigerian entity is unregistered with SEC Nigeria, it will struggle to find compliant counterparties on the EU side, because MiCA-supervised CASPs are required to apply due diligence standards that include verifying the regulatory status of counterpart VASPs.
In our cross-border practice, we see Nigeria-linked operators underestimate this interdependence. They focus on obtaining the EU licence and treat Nigerian registration as a secondary task. That sequencing creates risk. EU correspondent banks and payment processors increasingly require evidence of home-country authorisation before they will clear fiat flows for a CASP, even one with a valid MiCA authorisation. The domestic registration and the EU authorisation need to advance in parallel, not sequentially.
For a scoped assessment of your Nigeria-EU regulatory stack, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity domicile, the user geography, the banking rails – change the analysis.
Which EU Jurisdiction Should a Nigeria-Linked Operator Choose for Its CASP Seat?
The choice of EU licensing jurisdiction determines the pace of authorisation, the supervisory relationship, the capital environment, and the gateway to EU banking. No single answer fits every profile, but Nigeria-linked operators consistently evaluate a small set of variables.
Lithuania has historically processed digital-asset registrations faster than most EU member states and offers a well-developed tech-company infrastructure. Under MiCA, it now operates through the Bank of Lithuania as national competent authority, with the authorisation process aligned to the CASP framework. Operators we advise have found Lithuanian counsel and compliance infrastructure accessible and commercially responsive.
Malta operated a dedicated Virtual Financial Assets framework before MiCA and retains institutional familiarity with crypto-business models at the MFSA level. Its transition to full MiCA CASP authorisation is ongoing. The historical VFA agent model – where a licensed intermediary vouches for the applicant's technical submission – still shapes how applications are structured in practice.
Czech Republic and other Central European members offer cost-competitive incorporation environments and are building supervisory capacity as CASP applications rise. For a lean-structure operator, these jurisdictions merit assessment.
The cross-border reality for a Nigeria-linked group is that the EU subsidiary needs more than a licence. It needs a corporate bank account in the EU, a compliance function that satisfies both ESMA's expectations and the national competent authority's on-site or remote supervisory posture, and a governance chain transparent enough to satisfy enhanced due diligence from EU banking counterparts who will scrutinise the Nigerian ownership structure.
What Does the MiCA CASP Application Process Involve?
The CASP application is a structured submission to the national competent authority of the chosen EU member state, covering governance, capital adequacy, operational resilience, AML/CFT controls, and service-specific requirements for each activity sought.
The core components of a complete application include: a programme of operations detailing the services and target markets; a business plan with financial projections; a description of the governance structure including the management body and its fitness-and-propriety assessment; an AML/CFT policy aligned to the applicable EU directives and FATF standards; IT and security documentation; and, for custody services, a description of the safeguarding model and how client assets are held distinct from proprietary assets.
For Nigeria-linked applicants, the ownership-and-control section of the application receives heightened scrutiny. The national competent authority will assess the Nigerian parent entity's own regulatory status, beneficial ownership chain, and AML exposure. This is where an unresolved SEC Nigeria registration gap creates direct friction – the EU regulator will ask whether the home-country entity is authorised, and a clean answer requires having addressed that question first.
Timeline for CASP authorisation varies by member state and by the complexity of the application. The MiCA text sets a maximum assessment period for a complete application, but practical timelines – accounting for completeness checks, clarification rounds, and supervisory queue depth – commonly run to a matter of months rather than weeks. We advise clients to plan for a realistic runway and to run corporate establishment, compliance buildout, and the application submission in parallel, not sequentially.
Once authorised in the chosen member state, the CASP can use the MiCA passporting mechanism to notify intent to provide services in additional EU member states without a fresh full-authorisation process. This is the structural payoff of EU-seat selection: one authorisation, bloc-wide reach.
How Do Banking and Payment Rails Work for a Nigeria-EU CASP Structure?
Banking is the operational chokepoint for most Nigeria-linked CASP structures. EU correspondent banks apply enhanced due diligence to corporate clients with ownership chains running through jurisdictions that carry elevated AML risk perception, and Nigeria features regularly on internal risk-scoring models used by European banking compliance teams.
This does not make EU banking impossible for a well-structured Nigeria-linked CASP. It makes the evidence package more demanding. A successful banking application for the EU subsidiary will typically require: a clean corporate structure with documented beneficial ownership; a clear separation between the EU CASP's client funds and the Nigerian parent's operational accounts; a credible AML/CFT programme demonstrating FATF-standard controls; and evidence of the domestic regulatory status of the Nigerian entity.
E-money institution partners and payment service providers operating under EU licences increasingly serve as a first-stage banking layer for newly authorised CASPs while the primary correspondent banking relationship is established. We regularly advise on structuring these relationships to satisfy both the CASP's operational requirements and the payment provider's own compliance obligations.
The fiat-crypto gateway – the point at which Nigerian naira or EU euros convert into digital assets for the end user – also carries distinct regulatory weight. FX controls in Nigeria, Central Bank of Nigeria policy on virtual asset transactions, and EU payment-services rules all interact at this point. A CASP serving both markets needs a transaction flow architecture that threads these requirements simultaneously.
If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com.
A Scenario From Cross-Border Practice
In a recent licensing matter, a West African payments business with a substantial Nigerian user base sought to expand into EU markets ahead of a Series A raise. The founders had assumed their offshore holding structure – established in a common-law island jurisdiction – would suffice as the regulatory seat for EU operations. It did not. We mapped the dual-regime requirement: a MiCA CASP authorisation through a purpose-built EU subsidiary and a concurrent SEC Nigeria VASP registration for the domestic operation. We identified Lithuania as the preferred EU seat based on supervisory timeline and available compliance infrastructure. The EU entity was incorporated, a compliance officer engaged, and the application submission package built in parallel with the Nigerian registration process. The group entered the Series A with a complete regulatory roadmap in place rather than a residual licensing gap that investors would have flagged in due diligence.
Which Profile Should Pursue Which Structure?
Not every Nigeria-linked operator needs the same structure. The decision turns on the user geography, the service type, and the scale of EU operations contemplated.
Profile A – Nigeria-primary exchange with EU expansion intent: Establish a dedicated EU subsidiary as the CASP-authorised entity. The EU subsidiary operates independently for EU clients. The Nigerian parent handles domestic operations under SEC Nigeria registration. This clean separation reduces cross-contamination risk for both regulators and banking counterparts. Timeline for the EU authorisation is typically measured in months; the parallel Nigerian registration process runs alongside it.
Profile B – EU-domiciled operator with Nigerian user acquisition: If the principal market is EU but the business intends to acquire Nigerian users through a local entity, the structure inverts. The MiCA CASP authorisation sits at the EU parent level; a locally registered VASP entity in Nigeria handles the domestic user relationship. AML programmes at both levels must interoperate.
Profile C – Token issuer targeting both markets: MiCA's whitepaper obligations apply to public offers of crypto-assets to EU persons regardless of issuer domicile. A Nigerian issuer making a public offer to EU investors must produce and register a MiCA-compliant whitepaper through an EU-seat entity or comply with an applicable exemption. SEC Nigeria's token-offering rules apply in parallel to any offer to Nigerian persons. Both layers require counsel before any public distribution.
What Are the Most Common Mistakes in Nigeria-EU Licensing Structures?
The most consistent error we see is treating the EU CASP authorisation as the whole answer. It is not. A CASP licence permits a business to provide services to EU persons. It does not automatically authorise services to Nigerian persons, validate the ownership structure in the eyes of EU banks, or satisfy the AML expectations of a fiat correspondent.
A second recurring mistake is building the compliance programme for the EU licence in isolation from the Nigerian AML framework. FATF standards apply in both directions. A compliance officer who understands MiCA but not the Central Bank of Nigeria's AML guidelines, or the NFIU (Nigeria's financial intelligence unit) reporting obligations, will produce a programme with structural gaps that Surface during banking due diligence.
A common assumption is that a single offshore licence – a BVI or Cayman registration, for example – is sufficient to service both EU and Nigerian clients without further authorisation. This assumption is wrong. MiCA applies based on where the client is located, not where the service provider is incorporated. An offshore-registered entity without a MiCA-authorised EU seat cannot lawfully provide CASP services to EU persons regardless of the quality of its offshore licence. SEC Nigeria's VASP rules apply by a similar logic to services provided to Nigerian persons.
The third mistake is delaying the banking conversation until after the licence is granted. Banking takes longer than the licence in most cases. It should begin in parallel, with a clean corporate structure and a credible compliance narrative in place from the start.
Related at OBOLUS
- Licensing and Registration for Digital Asset Businesses – how we scope and manage the full licence stack for exchanges, custodians and token issuers
- VARA Licence Application in Czech Republic – a worked EU-jurisdiction guide to CASP authorisation timelines and process
- Tax Treatment of Tokens in Poland – cross-border token tax analysis for operators structuring across EU member states
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and by the completeness of the application. In EU member states operating under MiCA, a CASP authorisation commonly takes several months from submission of a complete application, factoring in completeness reviews and clarification rounds. Jurisdictions with established digital-asset supervision and lower application volumes tend to process faster. Parallel workstreams – corporate establishment, compliance buildout, banking – should run from day one rather than waiting for the licence to be granted.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right seat depends on the services offered, the user geography, the ownership structure, the banking strategy, and the available supervisory timeline. For EU market access, a MiCA CASP authorisation in a member state with active supervisory capacity and accessible banking infrastructure is typically the priority. For a Nigeria-linked operator, the chosen EU seat must also satisfy the enhanced due diligence requirements of European banking counterparts reviewing a non-EU ownership chain.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated activity requiring explicit authorisation. An operator already authorised for exchange or portfolio management services and wishing to add custody must ensure that activity is covered in its CASP authorisation. Building custody capabilities into the application from the outset – with the required safeguarding model and client-asset segregation documentation – avoids a subsequent variation application and the supervisory delay that comes with it.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so clients enter regulatory processes with a complete picture, not a residual gap. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
Ready to map your Nigeria-EU licence and banking structure? The OBOLUS licensing team works on transparent fixed-scope engagements. To start the conversation, write to info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdictional CASP authorisation structures for African and emerging-market operators accessing EU and Gulf regulated markets.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.