CASP Authorisation under MiCA for Regulated Entities
Operating a crypto-asset business inside the European Union without a CASP authorisation (Crypto-Asset Service Provider authorisation under MiCA, the Markets in Crypto-Assets Regulation) is no longer a viable posture. Since MiCA entered full application, the EU's unified regulatory regime has replaced the patchwork of national VASP registration and crypto licence frameworks that many operators exploited for speed and flexibility. The question for any regulated entity is not whether to obtain CASP authorisation under MiCA – it is how to structure the process, which national competent authority to use, and how the EU licence interacts with the operator's wider cross-border stack.
CASP authorisation under MiCA grants a single passportable regulatory authorisation across every EU and EEA member state. A business authorised in one member state may passport its services across the bloc without a separate regulatory authorisation in each country it enters. That is the gain. The cost is a materially more demanding application process than the legacy VASP registration regimes, with capital and organisational requirements calibrated to the class of crypto-asset service the entity intends to provide.
This page maps the regulated basis, the application process, the cross-border implications, the most common points of failure, and a decision guide for different operator profiles.
What Is the Regulated Basis for CASP Authorisation under MiCA?
MiCA defines a CASP as any legal person or other undertaking that provides one or more crypto-asset services on a professional basis, and it sets out a closed list of regulated activities – custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for fiat, exchange of one crypto-asset for another, execution of orders, placing of crypto-assets, reception and transmission of orders, provision of transfer services, and advice on crypto-assets. Each of these activities, offered to clients in the EU, triggers the CASP authorisation requirement.
The regime is built on substance over label. ESMA and the national competent authorities assess what the entity actually does, not what it calls itself. An operator that characterises its exchange function as a "technology layer" or a "bilateral matching service" will face scrutiny against the defined activities. In our practice, we have seen applicants arrive with structures built on label-management rather than genuine activity analysis. Those structures require remediation before the application can proceed.
The authorisation requirement applies to entities established in the EU offering services to EU clients, and – through a more nuanced read – to non-EU entities soliciting EU clients. The latter category sits at the intersection of MiCA's extraterritorial reach and the general prohibition on operating without authorisation. The risk for non-EU operators who continue to serve EU users without a CASP authorisation is enforcement action coordinated between ESMA and the relevant national competent authority.
What Licence Classes and Capital Requirements Apply?
The CASP authorisation framework tiers its capital and organisational requirements by the nature and scale of the services provided. Three class thresholds apply under MiCA, calibrated to the scope of permitted activities. The specific minimum own-funds figures are set in the regulation itself and vary by class – an operator providing only advice or reception and transmission services sits in a lower tier than one operating a full trading platform or custody function. Capital requirements are a matter of current legislation and the authorising national competent authority's assessment of the application; operators should confirm the applicable threshold directly with counsel before submitting.
Beyond minimum capital, the organisational requirements are substantive. A CASP must demonstrate a registered office and genuine operational presence in the EU member state of authorisation, at least two persons directing the business who meet the fit-and-proper standard, and adequate AML/CFT systems aligned to the Travel Rule (the FATF obligation to pass originator and beneficiary data with a crypto-asset transfer). Governance documentation, conflict-of-interest policies, custody safeguarding procedures and a business continuity plan are all required components of the application file.
How Does the CASP Application Process Work?
The CASP application process under MiCA follows a defined sequence: pre-engagement with the national competent authority, submission of a complete application file, the authority's completeness check, substantive review, and a decision within a regulated timeframe set by the legislation. The precise timelines vary by member state and by the authority's current caseload – applicants who treat the published maximum as a planning assumption routinely underestimate actual elapsed time.
The application file is the centrepiece. It must address, at minimum: the business plan with a three-year financial projection, the governance and ownership structure, the fit-and-proper documentation for management, the AML/CFT programme, the technology and security assessment, the client-asset safeguarding model, and the complaints-handling procedure. Many applicants submit an incomplete file and receive a stop-the-clock notice from the authority, resetting the timeline. In our practice, we draft the file holistically – from ownership charts to AML policy to governance minutes – to avoid that reset.
Passporting notification is a post-authorisation step, not a concurrent process. Once the home-member-state authorisation is granted, the CASP notifies the authority of its intent to passport into a host member state. The host authority has a defined period to object. Operators who plan their EU expansion should map both the authorisation timeline and the passporting notification timeline before committing a product launch date to investors or partners.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships and the specific activities you plan to offer – change the analysis materially. For a scoped assessment of your application position, contact OBOLUS at info@oboluslaw.com.
Which EU Member State Should You Use for CASP Authorisation?
Selecting the home member state for CASP authorisation is a strategic decision, not an administrative one. The national competent authority in each member state processes applications under MiCA's harmonised standards, but the practical experience of dealing with each authority – their communication style, their queuing approach, their interpretation of the substance-of-presence requirement – differs materially.
Operators who built their EU presence under the prior regime in Lithuania, through the Bank of Lithuania's historically accessible VASP registration framework, or in Malta under the MFSA's VFA framework, must now migrate to full CASP authorisation. That migration involves the same substantive file as a new application; the prior registration is not a fast-track to CASP status. What does count is the established local presence – a genuine office, local staff, a banking relationship – which the operator may already hold from the prior registration period.
For a new market entrant, the authority's typical processing pace, the maturity of its digital-asset supervision unit, the jurisdiction's banking infrastructure for VASPs, and the local corporate compliance cost all form part of the selection matrix. Operators with a strong German, French or Spanish user base may also factor proximity to their primary market into the decision. There is no single correct answer; the right member state is the one that fits the operator's timeline, budget, substance capacity and growth map.
The cross-border dimension extends beyond the EU. An entity seeking CASP authorisation while also holding, or planning to hold, a VARA licence in Dubai, an MAS DPT service licence in Singapore, or an AFSA licence within the AIFC in Kazakhstan will face questions about which entity holds which licence, how intragroup service agreements are structured, and how the regimes interact at the level of AML/CFT obligations, including Travel Rule data-sharing across jurisdictional boundaries. We address that multi-regime stack as a unified design problem, not as a series of separate engagements.
What Is the Cross-Border Reality for CASP-Authorised Operators?
A CASP authorisation solves the EU regulatory problem. It does not, by itself, solve the global regulatory problem for a business with users in multiple jurisdictions. The general-counsel question that follows authorisation is always the same: does our EU CASP authorisation passport to any non-EU market, and if not, what else do we need?
The answer is that MiCA passporting operates entirely within the EU/EEA perimeter. A CASP authorised in Lithuania cannot rely on that authorisation to serve clients in the UK, where the FCA's MLR registration and the financial-promotion rules for crypto marketing apply separately, or in Singapore, where MAS applies its Payment Services Act Digital Payment Token licensing regime to platforms serving Singapore users, or in the UAE, where VARA's activity-based licensing covers operators active in Dubai.
For many operators, the practical consequence is a multi-licence structure: a CASP-authorised EU entity, a UK-registered entity, and one or more non-EU entity structures depending on the geographic footprint. The banking and custody layer complicates this further. An EU-licensed CASP may still find it difficult to open euro accounts in certain member states if its beneficial ownership structure, the nature of its crypto activities, or its history of operating without a licence raises questions for correspondent banks. We map the licence, banking and custody stack as a connected set of decisions.
In a recent matter, a digital-asset exchange operating across multiple EU jurisdictions under legacy VASP registrations engaged us as MiCA approached full application. The business had a Malta VFA licence, a Lithuania VASP registration, and a VARA advisory engagement in Dubai. We structured a single CASP application in one EU member state that consolidated the EU regulatory footprint, coordinated the Malta and Lithuania transition notifications, and separated the Dubai activities into a VARA-authorised entity using allied counsel in the UAE. The result was a single passportable EU authorisation covering the bloc, with a compliant non-EU structure for the Gulf operations. The process took several months from initial file design to authorisation grant.
What Are the Most Common CASP Application Mistakes?
Applications fail – or stall for months – for a predictable set of reasons. The five patterns we see most frequently in practice are worth stating directly.
First, incomplete substance. The authority expects a genuine operational presence in the home member state: local management with decision-making authority, not a letterbox. Applicants who rely on a nominee director structure or a remote management team routinely receive a request for information that delays the process by weeks or longer.
Second, underdeveloped AML/CFT documentation. The Travel Rule compliance programme, the transaction monitoring policy and the customer due diligence procedures must be tailored to the applicant's specific activity mix. A generic AML policy lifted from a template raises questions in every review.
Third, a mismatch between the business plan and the licence scope applied for. An operator applying for the minimum activity class while describing revenue streams that require a broader authorisation creates a material inconsistency in the file.
Fourth, inadequate technology documentation. The security assessment, the custody safeguarding model and the business continuity plan are technical documents. Authorities increasingly expect specificity – not general assurances of "industry-standard" security.
Fifth, ignoring the banking question until after authorisation. A CASP that holds its EU licence but cannot open a euro account to serve EU clients is commercially stranded. The banking due-diligence process runs in parallel with the application process, not after it.
If a prior application stalled, or if a banking relationship was closed while an application was pending, a second structural read can identify the root cause and the route back. Contact OBOLUS at info@oboluslaw.com or reach us at t.me/oboluslaw.
Decision Matrix: Which Profile Matches Which Approach?
Operator profiles diverge significantly, and the right approach to CASP authorisation depends on where the business sits today.
Profile A – established EU operator migrating from a legacy registration. This operator holds a Lithuania VASP registration or a Malta VFA licence and must transition to CASP authorisation. The priority is a gap-analysis against the full CASP file requirements, a decision on whether to maintain the existing home member state or shift to a better-positioned authority, and a transition timeline that avoids a gap in authorised status. The key risk is assuming that historical regulatory engagement substitutes for a complete new application file.
Profile B – non-EU operator entering the EU for the first time. This operator needs both entity establishment and CASP authorisation, and the substance-of-presence requirement means the entity must be genuine from day one. The priority is selecting the home member state, building the local management and governance structure, and running the banking outreach concurrently with the application. The key risk is underestimating the local substance cost or choosing a member state whose authority lacks a mature digital-asset supervision unit.
Profile C – multi-jurisdictional operator adding the EU to an existing licence stack. This operator already holds licences in one or more non-EU jurisdictions – Dubai, Singapore, Hong Kong, Switzerland or the AIFC – and is adding a CASP authorisation for EU market access. The priority is structuring the intragroup relationships correctly, managing AML/CFT obligations that span multiple regimes, and ensuring the EU entity's governance is genuinely independent from the non-EU parent for supervisory purposes. The key risk is regulatory arbitrage characterisation – building a structure that looks like a pass-through to a non-EU entity rather than a genuine EU-present CASP.
Profile D – token issuer seeking a CASP authorisation to support token issuance and secondary trading. This operator sits at the intersection of the CASP authorisation and MiCA's whitepaper obligations for token issuers. Whitepaper preparation, disclosure obligations and the regulatory notification process run alongside, but distinctly from, the CASP application itself. The key risk is conflating the token-issuance notification track with the CASP authorisation track and missing the distinct procedural requirements of each.
A Common Assumption: Is an Offshore Licence Enough?
A common assumption among operators approaching the EU market is that an offshore or non-EU licence – a BVI VASP Act registration, a Cayman CIMA VASP licence, or a registration in a lower-scrutiny jurisdiction – provides a workable substitute for CASP authorisation when serving EU clients. It does not.
MiCA's prohibition on providing crypto-asset services without authorisation applies to the activity in the EU – that is, to any entity soliciting or serving EU-resident clients – regardless of where that entity is incorporated or registered. The location of the operating entity outside the EU does not disapply the authorisation requirement for the activity directed at EU users. Regulators in the leading hubs increasingly share information and coordinate enforcement; an offshore structure designed to sidestep EU authorisation requirements is a liability, not a solution.
The practical answer for operators who want both EU market access and a lean offshore holding structure is an EU-present CASP-authorised operating entity combined with an appropriate offshore holding or treasury structure. The two are not incompatible – but each layer must be designed for its purpose, not pressed into service to do the other's job.
Related at OBOLUS
- Licensing and Registration for Digital Asset Businesses – the full licensing practice overview across 70+ jurisdictions and all major regulatory regimes.
- Crypto Exchange Setup in Kazakhstan – AIFC – AFSA licensing under the AIFC regime, a common non-EU complement to a CASP-authorised EU structure.
- Tax Regime for Digital Assets in Abu Dhabi Global Market (ADGM) – the FSRA and ADGM tax environment for operators combining EU and UAE structures.
FAQ
How long does a crypto licence take to obtain?
Timelines for CASP authorisation under MiCA vary by member state, the completeness of the application file, and the national competent authority's current caseload. An incomplete application triggers a stop-the-clock notice and resets the review period. In our practice, well-prepared applications in experienced EU jurisdictions typically take several months from submission to decision; operators should plan for longer where substance-of-presence questions arise or where the authority requests additional information.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction turns on the operator's specific activity mix, its geographic user base, its banking requirements, its existing entity structure and its timeline. For EU market access, MiCA's CASP authorisation is the mandatory path regardless of the home member state chosen. For operations outside the EU – Dubai, Singapore, Kazakhstan's AIFC, Hong Kong – each regime has its own requirements. We map the full jurisdiction stack against the operator's commercial profile before any recommendation is made.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined crypto-asset service. An entity performing that function requires a CASP authorisation covering that specific activity class. A CASP authorised only for exchange or trading services cannot lawfully provide custody services to EU clients without extending its authorisation. Operators who bundle custody into their platform offering – as most exchanges effectively do – need to ensure their CASP application covers every activity they perform, not just the headline function.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before clients commit to a structure – work that has consistently identified gaps that internal teams and generalist advisers missed. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU CASP authorisation, multi-jurisdiction licence stack design, and regulatory transition strategies for digital-asset operators across the EU, UAE and Asia-Pacific.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.