CASP Authorisation Under MiCA for Institutional Clients
Operating a digital-asset business in the European Union without a CASP authorisation (the licence issued to a Crypto-Asset Service Provider under the Markets in Crypto-Assets Regulation) is no longer a calculated risk — it is an enforcement event waiting to happen. For institutional operators, the consequences compound: regulators suspend activities, banking counterparties close accounts, and institutional clients exit. The question for a business planning EU access is not whether to obtain authorisation but which member state, which activity scope, and how to structure the entity before the application lands.
This page maps the CASP authorisation process under MiCA for institutional clients — exchanges, custodians, issuers and asset managers — covering the regulated perimeter, the application mechanics, the cross-border realities that most operators underestimate, and the structural mistakes that stall or sink applications.
What Does MiCA Actually Regulate — and Who Is Caught?
MiCA, supervised by ESMA and implemented by national competent authorities across EU member states, establishes a harmonised licence for entities providing crypto-asset services to clients in the EU, regardless of where the operator is formally domiciled. The regulated perimeter is activity-based. Trading platform operation, order execution, exchange against fiat or other crypto-assets, custody and administration, portfolio management, advice, transfer services, placing, and reception and transmission of orders — each is a regulated activity. Institutional operators frequently run several simultaneously.
The reach of MiCA matters enormously for cross-border structures. An entity outside the EU that actively solicits EU institutional clients is exposed to the regime even without a physical establishment. ESMA and the national competent authorities have been explicit: reverse solicitation is a narrow exception, not a structural alternative. Operators in London, Singapore or Dubai serving EU funds, family offices or exchanges need to assess their EU nexus with care.
The token dimension adds a second layer. MiCA distinguishes between asset-referenced tokens (ARTs), e-money tokens (EMTs) and other crypto-assets. Issuers of ARTs and EMTs face additional authorisation requirements, whitepaper obligations and reserve-management rules that sit on top of the CASP layer. An institutional client building a stablecoin-adjacent product must plan for both regimes from day one.
CTA #1 — The scope analysis above describes the standard perimeter. Your facts — your entity structure, your EU user base, your product mix — change the analysis materially. Map your options with OBOLUS before you assume the regime does not apply.
How Does the CASP Authorisation Process Work Under MiCA?
The CASP authorisation process under MiCA follows a structured sequence: entity establishment in a member state, engagement of a VFA agent equivalent or local representative (where required), preparation of the application dossier, submission to the national competent authority, and a formal review period. The process is governed by MiCA directly, but each NCA adds its own documentation requirements and communication protocols.
The application dossier for an institutional operator is substantial. Regulators expect detailed business-plan documentation, governance arrangements that satisfy MiCA's management-body requirements, policies covering conflicts of interest, custody and safeguarding, prudential own-funds or capital, IT security and business continuity, and an AML/CFT programme that satisfies both MiCA and the applicable anti-money laundering directives. For exchanges and custodians, the technical documentation — covering order matching, safeguarding infrastructure and key management — is a significant deliverable in its own right.
MiCA provides that the NCA must assess the application within a defined period after it is declared complete. The operative word is "complete" — regulators issue completeness requests, which pause the clock, and an under-prepared dossier can extend the practical timeline considerably beyond the statutory window. In our practice, we see the gap between first submission and authorisation grant depend almost entirely on preparation quality, not on regulatory goodwill.
Passporting is the prize. A CASP authorised in any EU member state may passport its services across the EU/EEA without a second authorisation in each target country. For an institutional operator serving clients across Germany, France, the Netherlands and the Nordics, a single authorisation in a well-resourced member state can unlock the entire EU market — provided the activity scope in the authorisation covers every service being offered.
Which EU Member State Should You Choose for CASP Authorisation?
The choice of authorisation jurisdiction is a strategic decision, not an administrative formality. Member states differ in NCA capacity, supervisory approach, local substance requirements, banking access and the speed with which they process complete applications. An institutional client with a complex product mix — exchange, custody and transfer services stacked together — faces different constraints than a single-service operator.
Lithuania has historically processed EU crypto registrations quickly and built a strong pipeline of crypto-supervised entities. Under MiCA, the Bank of Lithuania supervises the transition to CASP status, and entities already registered in Lithuania are navigating the MiCA conversion. Malta's MFSA has administered the VFA framework — itself a CASP precursor — and is managing the MiCA transition for its existing supervised population. Other member states, including those with larger financial-sector NCAs, are building dedicated CASP teams.
For institutional clients, the substance question often drives the decision. A regulator will look at where genuine management functions are performed, not just where a registered office sits. Board composition, local senior management, and the location of core operational decisions are all examined. A shell entity with an address and a nominee director will not survive MiCA scrutiny.
The banking layer compounds this. An EU entity without access to stable euro settlement banking is commercially inoperable. Banking access for crypto-asset businesses varies significantly by member state — some jurisdictions have developed pragmatic banking relationships for supervised CASPs; others have not. OBOLUS maps the licence, the substance and the banking access together, because a licence without a bank account solves nothing.
What Makes CASP Authorisation Different for Institutional Clients?
Institutional operators face CASP requirements at a different level of intensity than early-stage or retail-focused businesses. The volume and complexity of their activities, the counterparty profile — other regulated entities, funds, family offices, sovereign wealth managers — and the reputational stakes all drive regulators to apply enhanced scrutiny.
Custody is the most consequential activity layer. MiCA imposes detailed safeguarding obligations on custodians: segregation of client assets, the liability framework for loss, the reconciliation cadence, and the operational resilience of the key-management infrastructure. Institutional custodians are held to a standard that mirrors, and in some respects exceeds, the expectations applied to traditional asset managers and depositaries. The policy documentation required is not generic — regulators read it and push back.
Portfolio management and advice under MiCA also carry specific governance requirements. An entity providing discretionary management of crypto-asset portfolios to institutional clients — family offices, alternative funds — must demonstrate that its investment process, conflicts management, and client-reporting framework are built for a regulated environment. The MiCA requirements here align with, but do not wholly replicate, the MiFID II standards that institutional clients already expect.
A practical note from our cross-border practice: institutional clients frequently discover that their proposed group structure creates a problem. A custody function sitting in an offshore entity — a BVI special-purpose vehicle, a Cayman fund vehicle — that feeds an EU-facing CASP creates regulatory perimeter questions that the NCA will raise during review. Solving the structure before submission is faster and cheaper than restructuring under regulatory pressure.
How Does CASP Authorisation Interact With Licences in Other Jurisdictions?
A CASP authorisation addresses EU access; it does not resolve the operator's regulatory position in every market where its institutional clients sit. A CASP with EU authorisation still needs to consider its position under the FCA regime in the UK, its obligations under MAS in Singapore if it has institutional clients there, and its obligations under VARA or ADGM/FSRA if it operates from or into the UAE.
The cross-border interaction is not merely additive. Some jurisdictions accept EU-authorised status as a reference point for their own review; others conduct a wholly independent assessment. The Travel Rule — the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a transfer — applies across jurisdictions but with varying data thresholds. A CASP that operates cross-border must build its compliance architecture to satisfy the most demanding regime in its footprint, not just MiCA.
Tax interacts with the jurisdiction stack in ways institutional clients increasingly raise with us. A CASP entity in an EU member state generates taxable income in that jurisdiction. If the group holds intellectual property, runs treasury or books certain transaction types offshore, transfer-pricing rules apply, and the substance standard that the tax authority examines is not materially different from the substance standard the VASP regulator applies. Building the compliance structure and the tax structure in parallel — rather than retrofitting one to the other — avoids the single most common and costly mistake we see in institutional MiCA projects.
CTA #2 — If a prior application stalled, a banking relationship closed, or a cross-border structure ran into regulatory resistance, a structured second read can surface the root cause and the route forward. Engage the OBOLUS licensing desk for a scoped assessment.
What Are the Most Common Mistakes in the CASP Application Process?
The most common mistake is treating the CASP application as a documentation exercise rather than a regulatory relationship. National competent authorities read governance documents looking for internal consistency — an AML policy that references a risk appetite the business plan contradicts, a conflicts-of-interest policy that does not map to the activity scope, a custody policy that assumes infrastructure the entity does not yet have. These inconsistencies generate completeness requests that pause the clock and signal to the regulator that the application is not ready.
A second pattern: underestimating the management-body requirements. MiCA requires that members of the management body have appropriate good repute and knowledge, skills and experience. For an institutional operator, the regulator will scrutinise the biographical profiles in detail. CVs that demonstrate crypto-specific operational or compliance experience matter. A board composed entirely of professionals from adjacent financial sectors — without anyone who has operated in the digital-asset environment — raises questions that the narrative sections of the application must proactively address.
Third: scope mismatches. Operators frequently request authorisation for a narrower activity set than they actually intend to run — either to reduce the capital requirement or to shorten the preparation timeline. When the business subsequently adds a custody service or a portfolio-management capability, it triggers a variation process that is more disruptive than building the full scope into the original application.
In a recent licensing project, an institutional operator submitted a CASP dossier for exchange and order-execution services without including a custody activity scope, on the assumption that its third-party custodian arrangement eliminated the need. The NCA identified that the operator's contractual arrangement with the custodian placed operational control of certain key-management functions with the operator's own staff — effectively constituting a regulated custody activity. We restructured the dossier to include the custody scope, supported by a revised safeguarding policy and updated own-funds calculation. The application proceeded to grant at the next assessment cycle.
Which CASP Profile Fits Your Business?
Institutional operators span a range of profiles. The authorisation strategy should reflect the specific business model, not a generic approach.
An established institutional exchange migrating from an EU VASP registration to MiCA CASP status should approach the process as a conversion project — auditing existing policies against MiCA's enhanced standards, upgrading governance where gaps exist, and preparing a narrative that frames the business's regulatory history as an asset. The timeline for a conversion from a clean pre-existing registration is generally shorter than a greenfield application, provided the NCA's records are consistent with the entity's self-assessment. Capital requirements vary by activity scope and must be confirmed with current published guidance.
A custodian entering the EU for the first time — perhaps an operator already regulated under MAS, the ADGM/FSRA or the SFC — should anticipate a more extended process. The NCA will have no existing file, the entity must establish substance in the member state, and the safeguarding documentation must be built from first principles. The timeline for a greenfield institutional custodian application under MiCA is typically measured in months, not weeks. Operators should plan banking access, hiring and tech infrastructure around that reality.
An EU-facing token issuer that also operates a secondary trading venue faces the most complex profile: ART or EMT issuer obligations stacked with CASP exchange authorisation. These are separate regulatory tracks under MiCA. The whitepaper notification, the issuer authorisation, and the CASP authorisation each have their own procedures and review periods. Running them in parallel requires careful sequencing — and a regulator that is willing to coordinate across its own internal teams.
A self-assessment checklist: Does your EU entity have genuine management functions on the ground? Does your activity scope in the application reflect every service you intend to offer at launch? Has your AML/CFT programme been reviewed against MiCA's specific requirements — not just the prior VASP standard? Is your custody infrastructure documented to safeguarding-policy standard? Have you confirmed euro banking access in the target member state? If any of those answers is uncertain, the application is not yet ready.
Is a Single Offshore Licence Enough to Serve EU Institutional Clients?
A common assumption is that an existing licence from a well-regarded offshore centre — the Cayman Islands, the BVI, or a Dubai VARA licence — satisfies institutional clients' expectations and covers EU regulatory exposure. It does not. MiCA establishes a direct access requirement: entities serving EU clients in regulated activities must hold EU authorisation or fall within a narrow exemption. The reverse-solicitation carve-out is deliberately narrow, and ESMA has published supervisory guidance indicating that regulators will scrutinise the commercial reality of how EU clients are acquired and serviced.
Institutional clients — regulated funds, family offices, corporate treasuries — are themselves under increasing regulatory and fiduciary pressure to deal only with properly authorised counterparties. A custodian or exchange holding only an offshore licence will find that EU-regulated fund clients ask for the MiCA authorisation number as a routine onboarding condition. The commercial cost of the gap is not theoretical: it is the institutional mandate that the operator cannot service.
Offshore licences serve a genuine purpose in the licence stack — for non-EU users, for certain product structures, and as part of a group holding structure. The error is treating any single licence as a global pass. We regularly advise institutional operators who discover this gap at the point of a client onboarding refusal rather than at the planning stage. That is an avoidable problem.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the OBOLUS practice overview covering the full jurisdictional licensing regime for digital-asset operators worldwide.
- Licence Renewal and Variation in El Salvador – process and strategy guidance for varying or renewing a digital-asset licence in El Salvador.
- CASP Authorisation Under MiCA for Early-Stage Founders – the founding-team perspective on MiCA CASP applications, covering entity structure and minimum viable compliance.
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the national competent authority must assess a complete CASP application within a statutory window — but the practical timeline depends on preparation quality. Completeness requests pause the review clock; an under-prepared dossier can extend the process significantly beyond the statutory period. For institutional operators, a well-prepared greenfield application typically takes several months from submission to authorisation. Timelines for conversion from existing VASP registrations are generally shorter. Registry-specific timelines vary by member state and should be confirmed with current NCA guidance.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The optimal EU member state for CASP authorisation depends on your activity scope, the substance you can deploy, the NCA's sectoral experience, and — critically — banking access in that jurisdiction. Lithuania and Malta have established track records with crypto supervision; other member states are expanding capacity. For non-EU activity, Singapore's Payment Services Act, VARA in Dubai, and the ADGM/FSRA regime in Abu Dhabi serve different operator profiles. OBOLUS maps the licence, substance, banking and tax stack for each client's specific situation before advising on a primary jurisdiction.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a separately defined CASP activity. If your business holds client assets — directly or through arrangements that place operational key-management control with your staff — you need the custody activity scope in your authorisation. Running custody under a third-party arrangement does not automatically eliminate the regulatory perimeter question: the structure must be reviewed carefully. In several member states, custody also triggers additional safeguarding and capital requirements on top of the base CASP obligations. We advise mapping this before the application is drafted, not after the NCA raises the question.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and institutional operators on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice. We map the licence, custody, and payment stack before you commit to a structure — because a licence without banking or without the right activity scope does not solve the commercial problem. To discuss a CASP authorisation project, contact us at info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialises in CASP authorisation strategy and cross-border licence stacking for institutional digital-asset operators across EU and non-EU hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.