What CASP Authorisation Under MiCA Actually Means for an Established Operator
CASP authorisation under MiCA – the Markets in Crypto-Assets Regulation – is the single most consequential regulatory authorisation available to a digital-asset business serving European users today. For an established operator, it is not a start-up licensing exercise. It is a compliance transformation that touches governance, capital, custody, AML posture and the legal structure of every service line offered to EU clients. Operators who delay the analysis expose their banking relationships, their payment rails and their ability to continue EU operations to material regulatory risk.
MiCA creates a unified authorisation regime enforced by national competent authorities and overseen by ESMA. A CASP (crypto-asset service provider) authorised in one EU member state may passport that authorisation across the entire EU/EEA. That passporting right is the core commercial prize – but it is earned through a rigorous assessment process, not a registration checkbox. This page maps the full process, the common structural errors established operators make, and the cross-border mechanics that determine whether the authorisation holds up in practice.
The Regulated Perimeter: Which Activities Require CASP Authorisation
MiCA's regulated perimeter covers a defined set of crypto-asset services, and an established operator's first task is to map its existing activity lines against that list with precision. The regulated services under MiCA include the operation of a trading platform for crypto-assets, the exchange of crypto-assets for fiat currency or for other crypto-assets, the execution of orders, the placing of crypto-assets, the reception and transmission of orders, portfolio management, advisory services and transfer services. Custody and administration of crypto-assets on behalf of clients is separately regulated and carries its own requirements.
For an operator with multiple service lines – say, an exchange that also provides staking, lending and custody – each activity must be assessed independently. ESMA has published guidance confirming that the substance of the service, not its marketing label, determines classification. An operator that wraps a lending product inside a "yield account" feature does not escape the regulated perimeter simply by choosing a different name. We have seen operators arrive at the authorisation process with a material classification gap: activities that were already live and that required separate treatment under the MiCA regime.
The regime also draws a critical distinction between token types. Asset-referenced tokens (ARTs) and e-money tokens (EMTs) carry whitepaper and issuer-authorisation obligations that are materially heavier than those applicable to other crypto-assets. An established operator that issues or manages an ART or EMT must plan for that track separately. The CASP authorisation covers service provision; token issuance is a parallel and distinct obligation under MiCA.
How the CASP Application Process Works in Practice
The CASP application under MiCA is submitted to the national competent authority in the member state where the applicant intends to establish its registered office – and the choice of member state matters as much as the application itself. The competent authority has a defined assessment window under the MiCA regime; if it requests further information, that clock typically pauses. The practical timeline from a complete submission to a final decision varies by member state, by application complexity and by the applicant's preparedness, but operators should plan for a process measured in months rather than weeks.
The application requires a programme of operations, a business plan with financial projections, governance documentation, a description of internal controls, AML/CFT procedures aligned with FATF Recommendation 15 and the applicable Travel Rule obligations, a description of the custody arrangements, IT security documentation, and details of the persons directing the business. For an established operator, each of these elements must reflect the business as it actually operates, not as a theoretical structure. A mismatch between the submitted programme of operations and the live business is among the most frequent causes of an extended review or a request for material additional information.
In our cross-border practice, we have found that operators underestimate the governance documentation requirements. The competent authority will assess whether key function holders meet fit-and-proper standards. That assessment extends to beneficial owners. An operator with a complex holding structure – common among exchange groups that have grown through acquisition – must prepare a clear and consistent ownership map before the application is submitted, not during the review period.
To map the application scope against your current operating structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, your user base geography and your banking relationships each change the analysis in ways that matter before you choose a member state.
Which Member State Should an Established Operator Choose?
The choice of EU member state for a CASP authorisation application is a strategic decision, not an administrative one. The passporting right makes the authorisation valid across the EU/EEA regardless of which national competent authority issues it – but the application process, supervisory philosophy, timeline and ongoing compliance burden differ meaningfully between member states.
Several member states have positioned themselves as CASP-friendly entry points. Lithuania's Bank of Lithuania, the MFSA in Malta and a number of other EU regulators have prior experience supervising digital-asset businesses under transitional VASP regimes, and that institutional familiarity affects the quality and pace of the review. An operator that was registered under an existing VASP regime in a given member state will generally find the MiCA CASP transition process more predictable in that jurisdiction – but only if the prior registration was managed cleanly and the regulator has no open concerns.
The cross-border angle matters here in a way that is often overlooked. An operator whose primary user base is concentrated in one or two member states may face enhanced scrutiny from the competent authorities of those states even if the CASP authorisation is issued elsewhere. The passporting notification process, which involves the home competent authority and the host member state authority, is not purely administrative. A host authority that has concerns about an operator's conduct in its market can raise those concerns through the ESMA coordination mechanism. Operators should model this dynamic before selecting a member state.
What Established Operators Get Wrong
A common assumption is that an established operator with existing compliance infrastructure simply needs to update its documentation for MiCA. That assumption is consistently wrong. MiCA is not a documentation exercise. It is a regime with specific requirements on capital adequacy, on custody and safeguarding, on conflicts-of-interest management, on the separation of proprietary assets from client assets, and on the disclosure obligations owed to users. Each of these requirements must be implemented operationally, not merely described in a policy document.
The most recurring structural errors we see in our practice fall into four categories. First, custody arrangements that do not meet the segregation and safeguarding expectations of the MiCA regime – particularly where an operator has historically commingled its own assets with client assets for operational efficiency. Second, governance arrangements where the persons effectively directing the business do not meet the fit-and-proper threshold as assessed by the competent authority. Third, AML/CFT policies that reference the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) at a conceptual level but do not describe the operator's specific technical implementation. Fourth, business plans that project EU revenue without demonstrating that the activities generating that revenue are covered by the authorisation being sought.
There is also a sequencing error that established operators make more often than early-stage founders. An operator that has been serving EU users under a transitional grandfathering arrangement must manage the transition to CASP authorisation within the window permitted by the applicable MiCA transitional provisions. Missing that window does not result in a grace period. It results in an immediate prohibition on continuing those activities. Operators running on transitional periods should treat the expiry of that window as a hard deadline, not a soft one.
The Cross-Border Reality: Banking, Tax and the Multi-Layer Stack
A CASP authorisation answers the EU licensing question. It does not answer the banking question, the payment-rail question or the tax question – and for an established operator, those three questions are operationally as important as the licence itself.
Banking access for authorised CASPs remains structurally constrained in many EU member states. The authorisation creates the regulatory permission to operate; it does not compel a bank to open or maintain an account. Operators we advise routinely find that their banking relationships require active management alongside the authorisation process – sometimes requiring accounts across multiple jurisdictions to ensure operational continuity. That multi-jurisdiction banking strategy must itself be compliant with the AML and payment-services rules of each jurisdiction where accounts are held.
The tax position of an entity that holds a CASP authorisation in one member state but has substantial operations, employees or management functions in another is a separate analysis. Corporate residence, permanent establishment risk and the treatment of intra-group transactions between the EU licensed entity and any non-EU holding or operating entities all require specific advice. For operators with a Dubai-domiciled parent (under VARA) or an ADGM-licensed subsidiary, the interaction between the EU authorisation and the Gulf structure is a recurring planning point.
We map the licence, banking and tax stack across operating, custody and payment layers before an operator commits to a structure. To begin that mapping exercise, contact us at info@oboluslaw.com or via t.me/oboluslaw.
Decision Matrix: Which Profile Fits Which Path
Established operators approach CASP authorisation from materially different starting positions, and the right path depends on the specific profile.
Profile A – The EU-registered VASP transitioning to MiCA: An operator that holds an existing registration under a member state's pre-MiCA VASP regime is the natural candidate for a managed transition. The process involves aligning the existing compliance infrastructure with MiCA's requirements, updating governance documentation and submitting the CASP application before the transitional period expires. The primary risk is timeline compression: if the existing registration is in a member state with a high application volume, the review window may be tight relative to the transitional deadline.
Profile B – The non-EU exchange entering the EU market: An operator licensed under VARA in Dubai, under the MAS Payment Services Act in Singapore, or under the SFC regime in Hong Kong that wants EU access must establish a genuine registered presence in a member state and apply for CASP authorisation from that presence. Regulatory arbitrage – maintaining a thin EU entity while directing the business from outside the EU – is a specific supervisory concern under MiCA and will draw scrutiny from competent authorities. The operator must demonstrate substance in the EU entity.
Profile C – The multi-product operator with custody, exchange and advisory service lines: Each service line must be covered by the authorisation. An operator that omits advisory services from its programme of operations because that line contributes a small share of revenue will find, on review, that the omission creates a compliance gap for the existing revenue. The programme of operations must reflect the full activity set from day one.
In each profile, the practical timeline is measured in months, not weeks. An operator that has not begun the pre-application phase – entity structure review, governance gap analysis, AML policy alignment, fit-and-proper assessments for key personnel – should start immediately if it intends to serve EU clients under the MiCA regime.
How the Analysis Works in Practice
In a recent licensing matter, a mid-size exchange operator with an existing VASP registration in an EU member state approached us after its initial CASP application received a major information request from the competent authority. The authority had identified a discrepancy between the custody arrangements described in the application and the operator's live operational practice: client assets were held under arrangements that did not meet MiCA's segregation requirements. We worked through the structural redesign of the custody model, revised the programme of operations to reflect the corrected arrangement, and coordinated the response to the competent authority's information request. The application was resubmitted with a compliant custody structure. The operator subsequently received its authorisation and proceeded to notify four EU member states under the passporting procedure. The matter illustrated a point we return to consistently: the substance of the operation must match the application at the point of submission, not at the point of approval.
Self-Assessment: Is Your Business Ready to Apply?
Before submitting a CASP application under MiCA, an established operator should be able to answer each of the following questions with supporting documentation.
- Have all current service lines been mapped against the MiCA regulated activity list, and is each included in the proposed programme of operations?
- Do custody and safeguarding arrangements for client assets meet the segregation requirements of the MiCA regime, and is that reflected in operational procedures, not just policy documents?
- Have all persons directing the business and all qualifying beneficial owners been assessed against the fit-and-proper criteria of the intended member state's competent authority?
- Does the AML/CFT framework describe the operator's specific Travel Rule implementation, including the technical solution used for transfers above the applicable threshold?
- Is the financial projection in the business plan consistent with the capital adequacy requirements applicable to the specific combination of regulated services being authorised?
- If the operator is in a transitional period under a prior VASP registration, has the expiry date of that period been confirmed, and is the application timeline set to complete before that date?
- Has the interaction between the EU CASP authorisation and any non-EU group entities (holding companies, payment processors, technology providers) been assessed for permanent establishment and AML risk?
If any of these questions cannot be answered with confidence, that is the starting point for legal and compliance work before the application is prepared. An application submitted with unresolved gaps does not benefit from the review process – it creates a documented record of the gap for the competent authority.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – a full overview of the licence stack across operating, custody and payment layers
- Digital-asset custody licensing in Gibraltar – custody-specific authorisation requirements and process in a common-law jurisdiction
- CASP authorisation under MiCA for early-stage founders – the equivalent analysis for operators building from the ground up
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the competent authority has a defined assessment window from the date of a complete application, but that window pauses when the authority requests additional information. For an established operator, practical timelines are typically measured in months. The pre-application phase – governance alignment, entity structuring, AML documentation – adds further time before the formal submission. Operators running on a transitional period should treat this as a binding constraint on their planning.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right member state for a CASP authorisation depends on the operator's existing regulatory history, its primary user base, the supervisory environment at the relevant competent authority and the interaction with the group's non-EU entities. Several member states with established VASP oversight experience offer predictable review processes. Selecting a member state based solely on perceived speed is a recurring planning error with long-term supervisory consequences.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a separately regulated service. An operator that provides custody must include it in its programme of operations and meet the specific capital, segregation and safeguarding requirements applicable to that activity. A CASP authorisation covering exchange services does not automatically cover custody. Operators providing both must ensure each activity is expressly authorised and operationally compliant as a standalone regulated service.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance work that sits around them. We map the licence stack across operating, custody and payment layers before you commit to a structure – so you are not redesigning under regulatory pressure. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, member-state selection and the cross-border licence stack for digital-asset operators entering or consolidating within the EU regulatory regime.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.