CASP Authorisation under MiCA from a Cross-border Perspective
A crypto exchange, custodian or token-services business preparing to serve European users faces a binary choice: obtain a CASP authorisation (the Crypto-Asset Service Provider licence created by the Markets in Crypto-Assets Regulation, MiCA) or exit the market. For operators headquartered outside the EU – in Dubai, Singapore, the BVI or the United States – the choice is rarely that clean. The entity structure, the user's location, the banking jurisdiction and the custody layer each trigger different obligations. Getting one element wrong exposes the business to enforcement action, account termination and the loss of the EU revenue stream entirely. This page sets out the regulated basis for CASP authorisation under MiCA, the practical application process, the cross-border complications that trip up otherwise well-advised businesses, and the decision framework we apply when advising inbound operators.
Why MiCA Matters for Every Operator Serving European Users
MiCA establishes a single, passportable authorisation for crypto-asset service providers operating within the EU and EEA, replacing the fragmented national VASP registration regimes that previously applied across member states. Any business – wherever incorporated – that actively markets or provides regulated crypto-asset services to users in the EU requires either a CASP authorisation from a competent national authority or, where transitional provisions apply, a compliant path toward one. The regulation is supervised at the European level by ESMA, with day-to-day authorisation conducted by the relevant national competent authority (NCA) in the chosen member state.
This matters for cross-border operators for a straightforward reason. A business licensed under the VARA regime in Dubai, the Payment Services Act in Singapore or the VASP Act in the BVI carries no automatic right to serve EU retail or professional clients. Each of those licences is jurisdictionally bounded. MiCA does not provide a third-country equivalence decision that bypasses local authorisation. The practical consequence is that an operator with a strong offshore licence still needs a MiCA-compliant entity in the EU or EEA if its user base includes European accounts.
The passporting right is among MiCA's most commercially significant features. A CASP authorised by a single NCA – for example, the Bank of Lithuania or the MFSA in Malta – may passport that authorisation across all EU/EEA member states without a separate application in each. For a business serving clients across Germany, France, the Netherlands and Spain, one well-chosen home-member-state authorisation covers the regulatory position across those markets simultaneously.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking – change the analysis. For a scoped assessment of your EU licensing position, contact OBOLUS at info@oboluslaw.com.
What Services Require CASP Authorisation under MiCA?
MiCA defines a list of regulated crypto-asset services; providing any of them to clients on a professional basis within the EU requires authorisation. The regulated services include: operating a trading platform for crypto-assets, exchanging crypto-assets for fiat or for other crypto-assets, executing orders on behalf of clients, providing portfolio management in crypto-assets, offering advice on crypto-assets, transferring crypto-assets on behalf of clients, and receiving and transmitting orders. Custody and administration of crypto-assets on behalf of third parties is also a regulated service under the regime.
Token issuers face parallel obligations. Issuers of ART (asset-referenced tokens) and EMT (e-money tokens) are subject to authorisation and whitepaper requirements under MiCA that are distinct from – and in addition to – the CASP authorisation for service providers. A business that both issues a stablecoin and operates a trading platform for it may therefore need to satisfy both regimes concurrently. In our practice, we see issuers frequently underestimate the compliance build required for the issuer authorisation track when they are focused on the service-provider side.
The regulation also captures certain token-related marketing activities. Offering crypto-assets to the public in the EU requires a published crypto-asset whitepaper, with defined content requirements, even where the issuer is based outside the union. The whitepaper notification must be made to the NCA in the relevant member state. This is a threshold obligation – a compliance step that precedes, rather than substitutes for, CASP authorisation.
How Do You Choose the Right Home Member State?
The choice of home member state for CASP authorisation is a strategic decision, not a formality. It determines the NCA that supervises the business, the supervisory culture the business will work within, the practical timeline to authorisation, and the ongoing regulatory relationship that will govern everything from product changes to enforcement escalation. Operators we advise regularly treat this choice as interchangeable; in practice, it is not.
The relevant variables include the NCA's existing familiarity with crypto-asset business models, the presence of local substance requirements (a common point of friction for offshore groups seeking a "brass-plate" EU entity), the local banking environment for regulated CASPs, and the NCA's published or de-facto processing timelines. Historically, Lithuania attracted a high volume of VASP registrations under the pre-MiCA regime because the Bank of Lithuania was operationally efficient and the local environment was commercially workable. Under MiCA, the authorisation standard is materially higher across all member states, and the differentiating factor is increasingly the NCA's supervisory capacity and the depth of the local compliance and banking infrastructure available to the applicant.
Malta, through the MFSA, brings experience with the prior VFA framework and a body of regulated crypto businesses already operating under MFSA supervision. For an operator that already has a VFA-licensed entity in Malta, the transition path to MiCA CASP authorisation is a distinct process from a new application, but the existing regulatory relationship with the MFSA has practical value. For a business with no prior EU presence, a greenfield choice between member states requires analysis of substance, banking, staffing and supervisory culture simultaneously. A decision driven solely by anticipated processing speed tends to produce applications that stall precisely because the substance requirements were underweighted at the outset.
What Does the CASP Application Process Involve?
The CASP authorisation application is a structured submission to the chosen NCA, covering the business model, the governance framework, the ownership and control structure, the AML/CFT programme, the technology and security arrangements, the custody and segregation model, the prudential capital position, and the policies that govern each regulated service the applicant intends to provide. The NCA has a defined assessment period under MiCA, running from acknowledgement of a complete application, though the practical timeline from initial engagement to authorisation decision varies by NCA, by business-model complexity and by the completeness of the application as submitted.
Incompleteness is the primary driver of delay. An NCA that receives an application missing key governance documentation or with an AML programme that does not address the specific risks of the applicant's business model will issue a completeness objection, which resets or pauses the assessment clock. In our experience, the businesses that move through the process most efficiently are those that invest in a pre-submission gap analysis and resolve structural issues – entity substance, board composition, the custody layer – before the application is filed, not during the NCA's review.
The governance and fit-and-proper requirements deserve particular attention for cross-border groups. MiCA requires that a CASP applicant demonstrate effective management from within the EU in a meaningful sense. The application must identify members of management with genuine responsibility for the EU operations and with appropriate competence. For a group whose operational management sits in Dubai, Singapore or New York, the task is designing a governance structure that satisfies the home-member-state NCA without creating tax-residency or regulatory complications in the offshore headquarters jurisdiction. We regularly advise groups on this layered structuring problem as a standalone engagement before the application is even drafted.
What Cross-border Complications Arise in Practice?
A business operating across multiple jurisdictions – a holding company in the BVI, an operating entity seeking CASP authorisation in the EU, a banking relationship in Switzerland or the UK, and a user base that spans North America, Asia and Europe – is not filing a single application. It is managing a stack of regulatory interactions that influence each other in ways that are not always visible from within any one jurisdiction's regulatory regime.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer, derived from FATF Recommendation 15) applies under MiCA and requires the CASP to have both the technical infrastructure to collect and transmit that data and the contractual arrangements with counterparty VASPs to receive it. A CASP operating across the EU and also processing transfers to or from counterparties in the US (FinCEN Travel Rule), Singapore (MAS), or the UK (FCA) faces a multi-standard Travel Rule compliance build. The technical implementation is manageable but requires early planning.
Banking is a persistent structural challenge. Regulated CASPs in the EU require access to euro-denominated settlement accounts. The banking environment for regulated crypto businesses is improving but remains selective. A CASP that holds its VASP licence in a jurisdiction where the banking environment is thin – or where the licence category does not map cleanly onto what an EU correspondent bank recognises – will find that the EU authorisation is a necessary but not sufficient condition for operational capacity. In our cross-border practice, we assess the banking layer in parallel with the licensing layer, because a CASP authorisation without a workable banking arrangement is commercially inert.
Tax interaction is the third dimension. A group that creates a new EU CASP entity generates a new tax presence. The transfer pricing arrangements between the EU entity and the offshore group must reflect the substance of the EU operations; an NCA that sees genuine substance in the EU entity expects a tax profile that is consistent with that substance. Groups that create a minimal EU presence to satisfy the NCA's letter while keeping all economic activity offshore create a structural inconsistency that eventually attracts scrutiny from both the NCA and the relevant tax authority.
If a prior application stalled, or banking access was declined, the structural reason is usually identifiable. To assess your current position and map a compliant path forward, contact OBOLUS at info@oboluslaw.com.
Common Mistakes in the CASP Authorisation Process
A common assumption in the market is that a single offshore licence – a VASP registration in the BVI, a licence under the VARA regime in Dubai, or a Payment Services Act authorisation from MAS in Singapore – is sufficient to serve European users at scale. That assumption is incorrect under MiCA. Each of those licences carries authority within its own regulatory perimeter; none carries EU passporting rights. Businesses that rely on that assumption and delay their EU authorisation process face a progressively narrowing window as NCAs build their CASP supervisory caseloads and transitional provisions expire.
The second structural mistake is treating the CASP authorisation as an isolated legal project rather than as a business redesign. The application requires the business to have, not merely to describe, a compliant governance structure, a functioning AML programme, a custody model that meets MiCA's segregation expectations, and capital that is sufficient and demonstrably accessible. Applicants that arrive at the application stage having not resolved these questions find that the process is materially slower and more expensive than a pre-application build would have been.
Third, and specific to cross-border groups: failing to resolve the substance question before filing. NCAs are alive to the risk of licence-shopping – the phenomenon of a business with no genuine EU footprint obtaining an EU authorisation for its commercial value while conducting its actual operations elsewhere. An application that cannot demonstrate genuine EU substance in management, operations and staffing is unlikely to succeed in most member states, regardless of the quality of the documentation otherwise submitted.
Finally, operators underestimate the ongoing compliance burden. A CASP authorisation is not a one-time achievement. It creates a continuing regulatory relationship with the home NCA, with annual reporting, change-of-control notifications, product-change notifications and ongoing capital adequacy monitoring. A business that is not staffed and structured to meet those ongoing obligations creates a compliance liability that may threaten the authorisation itself after it has been obtained.
Decision Matrix: Which Profile Needs What
The right authorisation path depends on the operator's profile. A brief decision framework applies across the four common archetypes we advise.
A non-EU exchange with a material EU user base and no existing EU presence requires a new EU/EEA entity, CASP authorisation in a chosen home member state, and a Travel-Rule-compliant infrastructure build. The timeline from strategic decision to operable authorisation is a matter of months and depends heavily on how much of the compliance build is completed before filing. The key risk is delay caused by substance or governance deficiencies identified during NCA review.
A group with an existing EU VASP registration under the pre-MiCA national regime – such as a Lithuanian registration or a Malta VFA licence – faces a transition to MiCA CASP authorisation. The transition involves upgrading the governance, compliance and capital position to the MiCA standard, filing for authorisation under the new regime, and managing the transitional window during which the existing registration remains valid. The key risk is underestimating the gap between the old registration standard and the MiCA authorisation standard.
A token issuer planning an ART or EMT launch in the EU requires issuer authorisation and a whitepaper regime compliance process that is separate from – but potentially concurrent with – any CASP authorisation for associated service activities. The key risk is conflating the two tracks and missing the whitepaper notification timeline.
A DeFi protocol seeking to understand its MiCA exposure needs a regulatory analysis of whether its activities, governance structure and user interaction model bring it within the CASP perimeter at all, and in which member states. The analysis is fact-specific and depends on how the protocol's services are structured and presented. We do not generalise on DeFi exposure; we assess each protocol on its own architecture.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build serves the regulatory environment it enters. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where disputes arise. To discuss your CASP authorisation or cross-border licensing situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the practice overview covering all major licensing tracks and jurisdictions
- VARA Licence Application – a jurisdiction-specific guide to the VARA licensing process for operators in or targeting the UAE
- Smart Contract Dispute Resolution under Heightened Scrutiny – how disputes arising from on-chain arrangements are handled across leading forums
FAQ
How long does a crypto licence take to obtain?
The timeline for CASP authorisation under MiCA varies by national competent authority, the complexity of the business model and the completeness of the application as submitted. An application that arrives at the NCA with substance, governance and AML questions unresolved will take substantially longer than one that addresses those issues before filing. Indicative timelines are jurisdiction-specific; we assess the realistic path for each applicant based on its specific circumstances and the current supervisory posture of the relevant NCA.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The optimal jurisdiction depends on the services offered, the user base, the banking environment, the capital position, the group structure and the management team's location. For EU market access, the passporting right under MiCA makes home-member-state selection a strategic choice. For offshore operations, the VARA regime in Dubai, MAS in Singapore and the VASP Act in the BVI each serve different operator profiles. We conduct a multi-axis assessment before recommending a jurisdiction, because a misaligned licence creates compliance liability rather than resolving it.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of third parties is a regulated service that requires CASP authorisation. A business that both operates a trading platform and holds client assets in custody must be authorised for both service categories. Whether a separate legal entity is required for the custody function depends on the group structure, the applicable capital requirements for each service category and the NCA's expectations for operational separation. This is a structuring question that should be resolved before the application is drafted, not during NCA review.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, home-member-state selection and cross-border licence-stack design for inbound operators entering the EU market.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.