EST · MMXXVI
Home/Jurisdictions/United States/CASP authorisation under mica in United States (federal + state MTL)
Licensing & Registration

CASP authorisation under mica in United States (federal + state MTL)

Casp authorisation under mica in United States (federal + state MTL). Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

A US-domiciled token issuer scaling into European markets faces an immediate question: does its existing federal and state authorization travel, or does it need a fresh CASP authorisation (the licence category created by the EU's Markets in Crypto-Assets Regulation, known as MiCA) before it can legally serve EU customers? The answer is that US licensing and MiCA authorisation operate on entirely separate legal tracks. No existing money-transmitter licence, no BitLicense, and no federal registration with FinCEN substitutes for a MiCA CASP authorisation issued by an EU national competent authority. For a US business with EU ambitions – or an EU-authorised CASP expanding into the United States – the licence, banking and compliance stack must be built in parallel, not in sequence. This page maps both tracks and the interaction between them.

The US Federal and State Regime at a Glance

The United States regulates digital-asset businesses through a layered system: federal agencies set the substantive rules, and states issue the licences that permit the actual transmission of value. At the federal level, the SEC, CFTC and FinCEN each claim jurisdiction over a slice of the digital-asset environment. FinCEN treats most exchanges and custodians as money-services businesses under the Bank Secrecy Act, requiring registration and a full AML program. The SEC treats tokens that meet the definition of a security as securities, subjecting their issuers and trading venues to broker-dealer and exchange registration requirements. The CFTC asserts jurisdiction over derivatives and, increasingly, spot commodity markets. These three federal agencies can each act independently and have done so in high-profile enforcement matters.

Below the federal layer, a business that moves value on behalf of customers must hold a money-transmitter licence (MTL) in each state where it operates. The NYDFS BitLicense adds a separate layer for New York-nexus activity. In our cross-border practice, we consistently advise US-entry clients that the state MTL stack – often requiring licences in the majority of commercially significant states before a launch is viable – represents both the longest lead time and the highest ongoing compliance cost in the US market. There is no federal passport; each state applies its own criteria, capital requirements and renewal cycles. The practical implication is that a business treating the United States as a single jurisdiction will encounter serious friction.

The SEC, CFTC, FinCEN and NYDFS together form the primary federal and New York-state regulatory perimeter for any digital-asset business with a US nexus. Understanding which agency governs which activity is the first analytical step, because a misclassification drives the entire compliance architecture in the wrong direction.

To map the federal and state licensing stack for your specific activity, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the token type, the user base, the transfer flows – change the analysis materially.

What Is MiCA and What Does a CASP Authorisation Cover?

MiCA is the EU-wide regulation that created a single, passportable authorisation for crypto-asset service providers operating across EU and EEA member states. A CASP authorisation grants the right to provide defined crypto-asset services – including custody, exchange against fiat, trading-platform operation, transfer services, and advisory – to EU customers under a single licence issued by one national competent authority, supervised by ESMA at the EU level. Once authorised in one member state, the CASP may passport its services across the bloc without seeking separate authorisation in each country.

MiCA also introduces parallel regimes for asset-referenced tokens (ARTs) and e-money tokens (EMTs). Issuers of those instruments face their own authorisation and whitepaper obligations, which are distinct from – and additional to – any CASP authorisation covering secondary-market services. A US stablecoin issuer distributing into the EU therefore faces the issuer track and potentially the CASP track simultaneously.

The regulation applies on the basis of where the customer is located, not where the provider is incorporated. A Delaware-domiciled exchange serving EU retail customers is, under MiCA's reach, subject to its obligations. Regulators in the leading EU hubs have signalled that offshore provision without authorisation will be treated as a breach, with consequences that include public censure, trading suspension orders directed at EU intermediaries, and referrals to member-state criminal enforcement. Operating without the right authorisation is, in the MiCA framework, not a technical oversight – it is a regulatory violation with enforcement consequences that can freeze access to EU banking and payment rails.

Does a US Licence Satisfy MiCA Requirements?

No US federal or state authorisation – including a FinCEN MSB registration, a NYDFS BitLicense, SEC broker-dealer registration or CFTC registration – substitutes for a MiCA CASP authorisation, and MiCA contains no equivalence or mutual-recognition mechanism that would allow a US-licensed entity to serve EU customers under its US credentials alone. The two regimes are legally independent. This is a structural feature of MiCA, not a transitional gap.

The MiCA passporting mechanism operates only within the EU/EEA. A CASP authorised in, say, an EU member state may operate across all member states without additional licensing; a US entity cannot access that passport at all unless it first establishes and authorises a legal entity within the EU. The practical consequence is that a US business seeking EU market access must create a European operating entity, select a home-member-state regulator, and proceed through the CASP authorisation process in that member state.

We regularly advise US businesses at exactly this decision point. The home-member-state selection is strategic: it affects the speed of authorisation, the regulatory dialogue style, ongoing supervision costs, and the credibility of the CASP with EU institutional counterparties. Lithuania, Malta and other member states each offer different profiles – Lithuania for speed, Malta for its established VFA-to-MiCA transition infrastructure. Neither choice is cost-free, and we have seen businesses make the selection on superficial criteria, only to face supervision friction that a more considered choice would have avoided.

How Does the MiCA CASP Authorisation Process Work for a US Applicant?

A US applicant pursuing MiCA CASP authorisation must first establish a legal entity in the chosen EU member state. That entity must be genuinely operational – substance requirements under MiCA mean that a mailbox entity will not satisfy the national competent authority. The applicant then files a detailed authorisation application with the NCA, covering governance and management body composition, AML/CFT policies, capital adequacy, IT and cybersecurity arrangements, safeguarding of client assets, and a description of each intended crypto-asset service. The NCA has a defined review period under MiCA; ESMA monitors consistency across member states.

For a US parent group, two practical issues dominate. First, the parent's existing compliance infrastructure – built for SEC, FINRA or FinCEN purposes – does not automatically satisfy MiCA's requirements, which follow a different analytical structure and require EU-specific documentation. The group will need to produce MiCA-formatted policies, not simply translate its US compliance manual. Second, the management body of the EU entity must include individuals who are assessed as fit and proper by the NCA. An all-US leadership team in which no member has EU regulatory experience will face difficult questions. Appointing an experienced EU-based independent director early in the process removes a predictable obstacle.

The Travel Rule (the obligation under FATF Recommendation 15 and its EU implementation to pass originator and beneficiary data with crypto-asset transfers above the applicable threshold) applies to CASPs. A US business accustomed to FinCEN's Travel Rule implementation will find the EU version structurally similar but with differences in scope, threshold and data fields. Building a single Travel Rule solution that satisfies both regimes simultaneously is achievable but requires planning at the architecture stage, not as an afterthought.

In our practice, we map the application timeline at the outset and identify the critical-path items – substance, governance, AML documentation – before the application is filed. That sequencing discipline is the difference between an authorisation that moves at the NCA's pace and one that stalls in a clarification loop.

What Does the Parallel US Compliance Stack Require?

While the EU entity pursues CASP authorisation, the US operations face their own timeline and workload. A business operating an exchange or custody service in the United States must, at minimum, maintain its FinCEN MSB registration, operate a BSA-compliant AML program, and hold state MTLs in the states where it has customers. The MTL process is state-by-state: some states process applications in a matter of months; others take considerably longer. Several states impose ongoing capital requirements that must be maintained in addition to any MiCA capital adequacy obligations in the EU entity.

The NYDFS BitLicense remains one of the most demanding state-level authorisations in the world. Its application requirements – including a cybersecurity program, a comprehensive AML/KYC framework, consumer-protection policies and a detailed business plan – are closer in depth to a full licensing process than to a registration. A US business that holds a BitLicense and is simultaneously pursuing MiCA CASP authorisation is running two demanding processes in parallel, each with its own document set, timetable and regulator dialogue. We have seen businesses underestimate this workload severely.

The combined US federal and state compliance obligation – FinCEN registration, state MTLs and, where applicable, NYDFS BitLicense – represents a sustained multi-year investment, not a one-time filing. Budget, personnel and legal resources must be sized accordingly.

How Do Banking and Tax Interact Across the US-EU Stack?

Banking access is the constraint that most often determines the viability of a cross-border US-EU structure. A US-licensed digital-asset business seeking to open EU accounts for its European CASP entity will typically find that EU banks require sight of the EU authorisation before they will open operational accounts. The sequencing problem – the business needs accounts to operate, but needs to operate to satisfy the NCA – is real and must be managed actively, often through specialist payment institutions or e-money institutions that serve the CASP during the authorisation period, transitioning to full banking relationships post-authorisation.

On the tax side, the US-EU structure creates transfer-pricing obligations. The EU CASP and the US parent will engage in intercompany transactions – technology licensing, shared services, management fees – that must be documented at arm's length. The OECD's base-erosion guidance applies; substance in the EU entity is essential both for MiCA compliance and for sustaining the tax position. A structure that concentrates profit in a low-substance EU entity will attract scrutiny from both the EU NCA and tax authorities. We work alongside tax specialists – whether our allied counsel or the client's existing advisers – to align the regulatory and fiscal structures from day one.

Operators we advise routinely discover that the most expensive restructuring is one done after banking accounts are frozen or after a tax authority challenges intercompany pricing. Early structural alignment is the cost-effective path.

A Decision Matrix for US Businesses Considering EU Market Access

Different operator profiles reach different conclusions on the right sequencing and structure.

A US exchange with an established MTL stack and a growing EU customer base faces an immediate compliance gap. Its EU customers are receiving services from an entity without MiCA authorisation. The priority action is to establish a European entity, begin the home-member-state selection process, and implement geo-blocking for EU customers pending authorisation. Failing to do so transforms a business-development question into an enforcement exposure.

A US token issuer distributing a stablecoin into EU markets faces the ART or EMT issuer track under MiCA, which is distinct from and more onerous than the CASP track. The issuer must assess whether the token qualifies as an ART or EMT, produce a compliant whitepaper, and seek authorisation from the relevant NCA. The timeline for issuer authorisation is measured in months. A parallel US filing – if the token has characteristics that engage SEC jurisdiction – may run concurrently. We structure these processes so that EU documentation does not inadvertently create admissions for US purposes.

A US custodian seeking to offer custody services to EU institutional clients can, in many cases, limit the MiCA obligation to a targeted CASP authorisation covering custody only, without immediately building out a full-service offering. This minimum-viable-authorisation approach reduces initial cost and complexity, with the option to expand the authorisation scope once the EU entity is established and operational.

A start-up with no existing US licence stack and EU ambitions should consider whether to lead with EU authorisation under MiCA, establishing a EU-domiciled CASP first and managing US access separately, or to build the US MTL stack first and add EU authorisation later. The answer depends on where the initial customer base is concentrated, the nature of the services offered, and the capital available for parallel regulatory processes. There is no universally correct answer, but there is always a more cost-efficient sequence for a given set of facts.

Common Mistakes in the US-EU Cross-Border Licensing Process

A common assumption is that holding a US licence, or being registered with FinCEN, provides a credibility foundation that accelerates MiCA authorisation. It does not. EU NCAs conduct their own review; they do not defer to US regulatory determinations. A US compliance record is useful background, but it is not a substitute for EU-format governance, policies and substance. Presenting a US compliance manual as an EU AML policy is among the most frequent errors we see from US applicants in the MiCA process.

A second frequent error is treating the home-member-state selection as an administrative choice rather than a strategic one. The NCA that authorises the CASP will supervise it for the life of the licence. A business that chooses a jurisdiction based on perceived speed without evaluating the NCA's supervision style, language capability and track record with complex applicants may find that the post-authorisation relationship is more burdensome than anticipated.

Third, businesses regularly underestimate the substance requirements. An EU operating entity that is visibly a conduit for a US parent – where all decisions are made in New York, all compliance staff are in San Francisco, and the EU office is a registered address – will struggle to satisfy both the NCA on fit-and-proper grounds and the tax authority on substance. Building genuine EU operational capacity early is both a regulatory requirement and a competitive differentiator.

In a recent cross-border matter, a US payments company had been serving EU customers under a FinCEN registration for over a year before engaging us. The company had received informal inquiries from a national regulator and was uncertain whether its existing structure constituted unauthorised provision of crypto-asset services under the applicable MiCA transition rules. We assessed the exposure, structured an immediate geo-restriction protocol to halt further unlicensed EU-customer onboarding, identified a suitable home-member-state, and began the entity establishment and pre-authorisation dialogue with the NCA. The company avoided a formal investigation and is now in the authorisation process with a clean compliance posture.

If a prior application stalled or your EU access is currently unstructured, a scoped review can identify the risk and the route forward. Contact OBOLUS at info@oboluslaw.com. We have seen the patterns that cause applications to stall, and we bring that pattern recognition to the initial assessment.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction and licence type. A MiCA CASP authorisation in an EU member state typically takes a matter of months from a complete application, though complex applicants or those requiring NCA clarification rounds can expect a longer process. US state MTL timelines vary by state; some process applications within a few months, while others take considerably longer. Running parallel US and EU processes requires realistic resourcing for both timelines simultaneously.

Which jurisdiction is best for licensing my crypto business?

There is no universally optimal jurisdiction. The right choice depends on where your customers are, what services you offer, your capital position, and your banking relationships. A US exchange with EU ambitions needs both tracks. A business focused on EU institutional clients may prioritise a MiCA CASP authorisation in a member state with a strong institutional supervision record. We assess the full stack – operating, custody and payment layers – before recommending a jurisdictional sequence.

Do I need a separate custody licence?

In most leading regimes, custody of digital assets is a separately regulated activity that requires its own authorisation or the specific inclusion of custody services within a broader licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service category. In the United States, custody obligations interact with both state money-transmission frameworks and, where securities are involved, SEC requirements. Whether a single authorisation covers all your custody activity depends on the jurisdictions involved and the asset types held.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit, so that structure decisions are made with a full picture of the cross-border obligations. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in cross-border CASP authorisation strategy and US-EU digital-asset licensing structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours