CASP Authorisation under MiCA in Panama: Legal Requirements for Businesses
A digital-asset business structured in Panama and serving European clients faces a structural problem that enforcement is already resolving. MiCA (the Markets in Crypto-Assets Regulation, the EU's primary crypto-asset regulatory regime) requires any entity providing crypto-asset services to EU-based clients to hold a CASP authorisation (Crypto-Asset Service Provider authorisation) issued by an EU member-state competent authority, regardless of where the provider is incorporated. Panama has no bilateral equivalence arrangement with the EU under MiCA, and no domestic crypto-asset regime currently recognised as equivalent. That means a Panamanian-incorporated entity seeking to serve EU clients cannot rely on its local structure alone – it must either obtain a CASP authorisation through an EU presence or restructure the distribution model before European user onboarding begins.
This page maps the legal requirements, the path to authorisation, the cross-border interaction with tax and banking, and the decision points that matter for a business currently operating from Panama or considering Panama as part of a multi-jurisdictional build.
Why MiCA Reaches a Panama-Incorporated Business
MiCA's scope is determined by where the service is provided, not where the provider is incorporated. If a CASP offers trading, custody, exchange, transfer or advisory services to persons located in the EU, the regulation applies. A Panama company with no EU establishment is not automatically exempt. ESMA (the European Securities and Markets Authority) and national competent authorities have consistently signalled that the "reverse solicitation" exemption – the narrow carve-out for purely client-initiated contact – is to be read strictly and does not cover systematic or commercial outreach to EU clients.
Panama itself currently lacks a comprehensive crypto-asset licensing regime aligned with FATF's virtual-asset standards to a degree that would support EU equivalence recognition. The country has made legislative progress on AML obligations for virtual asset service providers, but that progress does not produce the passport or equivalence that a MiCA-supervised entity holds. For a business built in Panama, the question is therefore not whether MiCA applies – it is which entity in the group will hold the CASP authorisation, and in which member state.
In our cross-border practice, we regularly advise founders who assumed their offshore structure created a clean perimeter around EU exposure. In almost every case, user geolocation data, payment flows or marketing practices dissolve that perimeter well before a regulator opens a file.
For a scoped assessment of your EU exposure and the most efficient authorisation path for your Panama structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard position. Your facts – the entity, the user base, the banking – change the analysis. Map your options
What Does CASP Authorisation Actually Require?
CASP authorisation under MiCA is activity-scoped: a business applies for the specific services it intends to offer, and the authorisation covers only those activities. The regulated services include, among others, operation of a trading platform for crypto-assets, exchange of crypto-assets for fiat or other crypto-assets, execution of orders, custody and administration on behalf of clients, placing of crypto-assets, and providing advice or portfolio management over crypto-assets.
The applicant entity must be legally established in an EU or EEA member state. For a Panamanian group, that means incorporating – or repurposing an existing subsidiary – in a member state before the application can be filed. The choice of member state matters. Some competent authorities are known for thorough but efficient review processes; others have longer queues or more conservative interpretations of certain activity categories. The authorisation then passports across the entire EU/EEA under MiCA's passporting mechanism, which allows a CASP authorised in one member state to provide services in all others without separate local authorisation.
The application itself requires, at minimum, a programme of operations, a business plan with financial projections, a governance structure with clearly identified management body members, an AML/CFT compliance programme aligned with the Travel Rule (the obligation to pass originator and beneficiary data with each virtual-asset transfer) and FATF standards, internal controls documentation, a description of safeguarding arrangements, and a consumer-protection and complaints-handling framework. Many competent authorities also conduct fit-and-proper assessments of beneficial owners and senior management.
Own-funds requirements vary by service category. The minimum capital thresholds are set by MiCA and differ by the class of services offered; a business offering only advice faces a lower requirement than one operating a trading platform or providing custody. These thresholds are defined in the regulation and should be confirmed against current official guidance before structuring, as technical standards from ESMA continue to develop.
Which EU Member State Should a Panama Business Choose for CASP Authorisation?
The passporting model makes member-state selection a strategic question, not merely an administrative one. Several factors drive the analysis for a Panamanian group seeking an EU foothold.
Regulatory culture and timeline vary meaningfully across the bloc. Some national competent authorities processed VASP registrations efficiently under pre-MiCA regimes and are building on that infrastructure. Lithuania, historically a fast EU market-entry point under the prior VASP registration model, is now transitioning to the full CASP authorisation framework under the Bank of Lithuania's supervision. Malta, through the MFSA, is similarly transitioning its prior VFA (Virtual Financial Asset) framework cohort to MiCA compliance. Each has a developed supervisory apparatus, but the effective timeline from application submission to authorisation decision varies and should not be assumed to be uniform. Generally, authorisation timelines under MiCA run to several months after a complete application is accepted as admissible; competent authorities have defined statutory review periods, though pre-application engagement can affect the total elapsed time materially.
Substance requirements are a second determinant. Most competent authorities expect that the authorised entity has genuine operational substance in the member state: management presence, key-function personnel on the ground, and decision-making that demonstrably occurs within the jurisdiction. A shell EU entity managed entirely from Panama is unlikely to satisfy the governance expectations of a rigorous competent authority and creates passporting risk if the arrangement is later challenged.
Banking access is a third, frequently underestimated factor. A newly authorised CASP requires a euro-denominated bank account for client-money segregation and own operations. Many EU banks remain cautious about new crypto-asset business clients. Selecting a member state with a comparatively accessible banking environment – often one of the smaller member states with a history of fintech-friendly commercial banking – can meaningfully reduce time to operational readiness after authorisation.
How Does the Panama Structure Interact with Tax and Banking?
Running an EU CASP alongside a Panama holding company creates a multi-layer structure that demands careful transfer-pricing and substance analysis. Panama operates a territorial tax system: income earned from sources outside Panama is generally not subject to Panamanian income tax. That is, on its face, an efficient characteristic for a holding company receiving dividends or royalties from an EU operating subsidiary. However, the EU's economic substance expectations for the CASP entity, combined with the transfer-pricing rules applicable in the member state of authorisation, mean that the profit-allocation model must be coherent and defensible.
Arrangements that park the CASP authorisation in an EU entity while routing all real economic activity and profit back to Panama are likely to face scrutiny under the EU entity's local transfer-pricing rules, the member state's controlled-foreign-company provisions, and, depending on the structure, the EU's parent-subsidiary or anti-tax-avoidance directives. The OECD's Pillar Two framework, now being implemented across EU member states, adds a global minimum tax dimension that affects groups with significant turnover. A tax-efficient structure is achievable; it requires alignment between the licensing strategy and the tax architecture from the outset, not retrofitted after authorisation.
Banking at the Panama level – for treasury, payroll and group liquidity – presents its own challenges. Panama remains on monitoring lists maintained by international bodies focused on AML and tax transparency. Correspondent banking for Panama-domiciled entities can be constrained, and some international banks apply enhanced due diligence or decline to provide services altogether. Operators we advise routinely underestimate the banking friction at the Panama level and discover it only after the licence is granted. Planning for this before the structure is set avoids the more painful remediation work that follows.
What Are the AML and Travel Rule Obligations for a Panama-Based CASP?
A CASP authorised under MiCA is subject to the full force of EU AML/CFT requirements, including the Travel Rule as implemented in EU law – the obligation to collect, verify and transmit originator and beneficiary information alongside each crypto-asset transfer above the applicable threshold. These obligations attach to the EU-authorised entity, regardless of where the group's parent sits.
From a Panamanian perspective, Panama has enacted legislative measures imposing AML registration and compliance requirements on virtual asset service providers operating in or from Panama under the FATF Recommendation 15 framework. A business that operates both a Panamanian entity and an EU CASP must therefore manage two distinct compliance regimes simultaneously. The risk of inconsistency between the two – different customer-due-diligence standards, different Travel Rule counterparty networks, different suspicious-transaction reporting thresholds – is material and frequently overlooked in the initial build.
Competent authorities reviewing a CASP application will scrutinise the group-wide AML policy. If the Panamanian parent operates a laxer compliance posture than the EU subsidiary, examiners may treat the group structure itself as an AML risk. We have seen authorisation timelines extended significantly because the applicant's group AML framework did not meet the EU entity's required standards at the point of application.
A Closer Look: Panama-Group Restructuring for EU Access
In a recent licensing matter, a mid-sized exchange operating from Panama approached us after discovering that a meaningful share of its user base was resident in EU member states. The business had been operating on the assumption that its Panama domicile and an operational ToS restricting EU access were sufficient. A forensic review of payment flows and KYC records indicated otherwise. We structured a two-entity approach: a newly incorporated EU subsidiary in a member state with an accessible banking environment and an established CASP review process, and a revised group AML policy that brought the Panamanian parent's compliance framework into alignment with EU expectations. The EU entity filed a complete CASP application within a defined programme of operations covering exchange, custody and transfer services. The Panamanian parent was repositioned as a holding company with clearly documented management-body separation. The matter illustrated that the restructuring timeline – from initial review to application filing – was the dominant variable, not the competent authority's review period.
Decision Matrix: Which Profile Should Choose Which Path?
Not every business with a Panama nexus faces the same decision. The right path depends on the operator's profile, the services it intends to provide and the user base it is targeting.
Profile A – a Panama-domiciled exchange serving a global retail user base that includes EU clients: This profile almost certainly requires CASP authorisation in an EU member state before the EU client population can be formally served. The authorisation vehicle should be a substance-bearing subsidiary with management presence in the chosen member state. The Panama entity may remain as a holding or treasury vehicle, but it cannot be the licensed face of EU operations. Timeline to operational readiness, including entity incorporation, application preparation, competent authority review and banking onboarding, typically spans many months and should not be compressed in the planning budget.
Profile B – a Panama-domiciled business that genuinely serves no EU clients and has no intention of doing so: This profile may not require a CASP authorisation, but the "no EU clients" position must be demonstrable and technically enforced, not merely asserted in terms of service. Geofencing, payment-rail restrictions and KYC-country screening must all point in the same direction. The risk of inadvertent EU user onboarding – particularly for decentralised or wallet-based services – is real and should be assessed specifically.
Profile C – a Panama-domiciled token issuer seeking to offer crypto-assets to EU investors or list on EU platforms: This profile triggers MiCA's whitepaper and, depending on the token classification, ART or EMT obligations. The issuer may need authorisation or, at minimum, must comply with the applicable whitepaper regime before EU distribution. The interaction with Panamanian securities law and the absence of a domestic equivalence framework means the structure must be assessed in both directions.
If a prior application stalled or an account was closed, a second structural read can identify the root cause and the route forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options
Common Mistakes Panama-Based Operators Make When Approaching CASP Authorisation
A common assumption among operators is that a single offshore licence – whether in Panama or another non-EU jurisdiction – is sufficient to serve clients globally, including in the EU. This is incorrect under MiCA, and acting on that assumption exposes the business to enforcement by the competent authority of the member state where the EU clients are located, potential suspension of services, frozen payment rails and the reputational cost of a public order.
A second frequent error is treating the CASP application as a documentation exercise rather than a substance exercise. Competent authorities reviewing applications under MiCA are not checking boxes; they are assessing whether the applicant has a genuine, governable business. An application submitted without a resident compliance officer, without a credible programme of operations, or with a management body that cannot demonstrate independent decision-making from the parent group will stall or be rejected. The cost of a rejected application – lost time, reputational signal to the competent authority and the need to address the underlying deficiencies – is substantially higher than the cost of building the structure correctly from the outset.
A third mistake is sequencing the banking search after the licence is granted. Banking for a newly authorised CASP is not guaranteed, even in EU member states with active fintech ecosystems. Operators we advise who begin the banking relationship process in parallel with the licence application – through a formal pre-application engagement with one or more EMIs or banks – consistently reach operational readiness faster than those who treat banking as a post-authorisation task.
Related at OBOLUS
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full practice overview covering 70+ licensing jurisdictions and the authorisation process end to end.
- VARA licence application for institutional clients – guidance on Dubai's VARA activity-based licensing regime for institutions seeking a regulated UAE presence.
- Stablecoin issuance authorisation for early-stage founders – the MiCA ART and EMT authorisation path for issuers at any stage of build.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the structure works in practice, not just on paper. Digital assets are the whole of our practice. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in multi-jurisdictional CASP authorisation strategy and EU market-entry structuring for non-EU digital-asset businesses.
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, licence category and the completeness of the application at filing. Under MiCA, competent authorities have statutory review periods that run from the point an application is accepted as admissible, which itself follows a completeness check. Total elapsed time from initial engagement to authorisation decision typically spans several months. Pre-application engagement with the competent authority and early preparation of governance and AML documentation materially reduce the total timeline.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction; the right choice turns on the services offered, the target client geography, the banking environment needed, the substance the business can deploy and the tax architecture of the group. For EU client access, a MiCA CASP authorisation in a member state with an efficient competent authority and accessible banking is typically the anchoring licence. Other regulated activities – custody, stablecoin issuance, institutional trading – may require additional authorisations in other jurisdictions alongside the EU licence.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated service that must be specifically included within the CASP authorisation. A business authorised only for exchange or transfer services cannot provide custody without extending its authorisation. In other jurisdictions – including VARA in Dubai and the Payment Services Act regime in Singapore – custody is similarly a distinct regulated activity requiring explicit authorisation. Whether a separate custody vehicle is needed depends on the group structure and the jurisdictions in which clients are located.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.