EST · MMXXVI
Home/Services/Licensing Registration/CASP authorisation under mica: Legal Counsel for Digital-Asset Firms
Licensing & Registration

CASP authorisation under mica: Legal Counsel for Digital-Asset Firms

Casp authorisation under mica: Legal Counsel for Digital-Asset Firms. Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

CASP Authorisation Under MiCA: Legal Counsel for Digital-Asset Firms

Operating a crypto-asset business in or into the European Union without the correct authorisation is no longer a calculated risk – it is an enforcement exposure. Under the Markets in Crypto-Assets Regulation (MiCA), any firm providing crypto-asset services to EU clients must hold a CASP authorisation (Crypto-Asset Service Provider authorisation) granted by a competent authority in a member state. The regime, supervised at the European level by ESMA (the European Securities and Markets Authority) and enforced by national competent authorities, applies regardless of where the firm is incorporated. A single passportable CASP authorisation unlocks the entire EU and EEA market. Getting the structure wrong at the outset delays that access by months and can trigger regulatory action in the interim.

This page sets out what the CASP authorisation process involves, where the structural and documentary pitfalls lie, and how OBOLUS advises digital-asset firms through the application from scoping to submission to post-authorisation compliance.

What Is CASP Authorisation Under MiCA – and Who Needs One?

CASP authorisation is the mandatory licence for firms providing any regulated crypto-asset service within the EU, including exchange, brokerage, custody, portfolio management, transfer services and advice. The CASP regime under MiCA replaces the patchwork of national VASP registration regimes that previously varied sharply across member states. Under MiCA, a firm is a regulated entity from the moment it provides a service to a client in the EU – not from the moment it applies. That distinction matters for businesses serving European retail or professional clients from outside the bloc.

The regulated perimeter is defined by the services offered, not by the asset class alone. A firm advising on crypto-asset portfolios is in scope. A firm providing custody for client assets is in scope. A firm operating an exchange or a peer-to-peer platform for EU users is in scope. Token issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) carry additional obligations – separate whitepaper notification and, in the case of significant issuers, direct ESMA oversight – but those are structurally distinct from the CASP layer.

Firms already registered as VASPs under pre-MiCA national regimes in member states such as Lithuania or Malta benefit from a transition period, but that grace period is finite. Operators relying on transitional provisions should be mapping their full MiCA application now, not waiting for the deadline.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your MiCA authorisation requirement, contact OBOLUS at info@oboluslaw.com.

Which Crypto-Asset Services Are Regulated Under MiCA?

MiCA enumerates a defined list of regulated crypto-asset services, and each one requires a specific authorisation scope. The breadth of the list catches more operators than expect it. Custody and administration of crypto-assets on behalf of clients is regulated. Operating a trading platform – whether centralized, partially decentralized or order-book based – is regulated. Exchanging crypto-assets for fiat or for other crypto-assets, placing crypto-assets, receiving and transmitting orders, providing transfer services and providing advice on crypto-assets are all individually enumerated.

A firm should map every function it performs against the MiCA service list before filing anything with a national competent authority. In our practice, the most common scoping error is underestimating the service list. A business that considers itself a technology provider discovers that it is executing orders on behalf of clients. A firm that considers itself a custodian is also advising on allocation. Each additional service in scope requires that the application reflects it – and that the firm's governance, capital and operational infrastructure supports it.

The firm's cross-border user base compounds this. MiCA applies where the service is provided to an EU-based client. Geoblocking policies that are not technically enforced are generally not sufficient. Firms with global user bases must assess each active market separately and ensure that the CASP authorisation scope covers every service provided to EU clients.

What Does the CASP Application Process Involve?

The CASP application is a structured, document-intensive process submitted to the national competent authority of the member state in which the firm is – or intends to be – established. ESMA has published regulatory technical standards that define the information requirements, and national competent authorities apply those standards within their own procedural frameworks.

The core application package typically includes a legal entity description and group structure; a programme of operations setting out all services to be provided; governance and management arrangements, including fit-and-proper assessments for key executives and board members; own-funds evidence meeting the capital requirements applicable to each service category; an AML/CFT framework aligned with the applicable FATF-derived EU rules; a conflicts-of-interest policy; a complaints-handling procedure; a business continuity plan; and, for firms managing client assets, safeguarding and segregation arrangements.

For firms offering custody, segregation requirements are substantive. For firms operating trading platforms, pre- and post-trade transparency obligations and order execution policies are assessed at the application stage. The competent authority reviews completeness first – an incomplete application is returned, resetting the assessment clock.

Assessment timelines are set under MiCA and run from the point the application is declared complete. In our experience, the largest cause of delay is not the regulatory clock but the preparation phase: governance documents that do not address the MiCA-specific requirements, capital calculations that do not match the approved methodology, or AML frameworks borrowed from other regimes without adaptation to the crypto-specific risk factors MiCA and the applicable anti-money-laundering regulation require.

We have seen firms present applications built on generic compliance templates that were materially non-compliant with MiCA's CASP-specific requirements. The competent authority returned them as incomplete within weeks. A correctly scoped, MiCA-native application avoids that cycle entirely.

How Do You Choose the Right Member State for Your CASP Application?

Passporting under MiCA means the choice of home member state is a long-term structural decision, not a filing convenience. Once authorised, a CASP may provide services across all EU and EEA member states by notification – it does not need separate authorisation in each country it enters. The competent authority of the home state remains the primary supervisor and the firm's ongoing regulatory relationship is with that authority.

Member state selection turns on several factors that interact: the sophistication and processing capacity of the national competent authority; the jurisdiction's existing AML infrastructure and willingness to accept crypto-native business models; the depth of the local banking market for crypto businesses; the corporate tax regime; and the cost and speed of establishing a qualifying legal entity. Lithuania and Malta built their early reputations as entry points precisely because their regulators processed VASP registrations efficiently and their corporate ecosystems were low-friction. Under MiCA, those same regulators are among the first to publish CASP authorisation guidance.

For a firm with no existing EU presence, the member state selection question is answered alongside the corporate structuring question. The entity must be genuinely established – a letterbox company does not satisfy MiCA's substance requirements. Real management, real governance and real operations in the chosen state are expected. Operators we advise regularly underestimate the substance threshold until they review the governance assessment criteria in detail.

For a firm with an existing EU presence – perhaps a technology subsidiary in one member state and a commercial operation in another – the question is which entity should apply and whether restructuring is needed before filing. That analysis is tax and corporate as well as regulatory.

What Are the Cross-Border Implications of Operating Under a MiCA CASP Licence?

A MiCA CASP authorisation governs service provision within the EU. It does not automatically resolve the regulatory position in other markets a firm serves. A CASP authorised in Lithuania that also serves clients in Singapore, the UAE and the UK operates under four distinct regulatory regimes simultaneously. MAS in Singapore, VARA in Dubai and the FCA in the UK each maintain independent licensing or registration requirements. Passporting stops at the EU border.

Banking is the other cross-border constraint that firms consistently underweight. EU-authorised CASPs still face significant friction in opening and maintaining fiat accounts. Some EU banks remain cautious about crypto-business clients regardless of regulatory status. The banking solution may sit in a different jurisdiction from the CASP authorisation – which creates its own AML and transfer-pricing questions.

The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies under MiCA and must be implemented operationally before a CASP begins providing transfer services. The technical standard for Travel Rule data transmission varies across jurisdictions, and a firm operating into markets with different de-minimis thresholds must implement a solution that covers all of them.

In a recent matter, a custodian seeking EU authorisation had structured its entity in one member state but held its primary client assets – and its banking – in a third-country arrangement. We identified at the pre-application stage that the custody segregation model did not meet the applicable MiCA safeguarding requirements and that the banking arrangement created a conflict with the firm's proposed AML framework. Restructuring before filing avoided a material application failure.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To map the licence, banking and compliance stack across your operating jurisdictions, write to OBOLUS at info@oboluslaw.com.

What Are the Most Common Mistakes in CASP Applications?

Most CASP application failures are preventable. The errors we see most frequently fall into four categories. First, scope errors: the firm applies for fewer services than it provides, either because it misread the service list or because it intentionally sought to simplify. The competent authority's assessment will probe the programme of operations, and a mismatch between stated services and actual operations is a ground for refusal. Second, governance gaps: key management personnel fail the fit-and-proper assessment because the documentation is incomplete, their backgrounds were not pre-screened, or the governance structure does not demonstrate adequate senior accountability for each regulated function. Third, AML framework deficiencies: the firm presents a generic AML policy rather than a crypto-asset-native risk assessment that addresses the specific typologies – mixing services, chain-hopping, privacy tokens – that MiCA's competent authorities expect to see addressed. Fourth, capital miscalculation: the firm presents own-funds evidence calculated against the wrong service category or without accounting for the combined-services floor.

A common assumption in the market is that the application process is primarily a documentation exercise – that with enough paperwork, any structure will pass. That is a misconception. The competent authority is assessing the genuine operational readiness of the firm to perform the services it is applying to provide. Governance, capital and compliance infrastructure must be in place, not merely described. Our role is to close the gap between where a firm is and where it needs to be before the application is filed.

Which Firm Profile Should File Where and How?

Different operator profiles face different application paths under MiCA. Understanding which profile fits a given business helps calibrate the effort, timeline and structural requirements involved.

A firm already registered as a VASP in an EU member state under the pre-MiCA national regime needs to assess whether its current structure, governance and capital base meet the CASP standard. The transition period provides time; it does not provide exemption from the requirements. Such a firm should begin a gap analysis against the MiCA CASP standard immediately and use the transition window to remediate, not to delay.

A third-country firm – incorporated outside the EU – that currently serves EU clients faces the most urgent timeline pressure. Without an EU-established entity and a CASP authorisation in progress, it is providing regulated services without authorisation. The path involves selecting a member state, incorporating a qualifying entity with genuine substance, building the governance and compliance architecture and filing. The full timeline from decision to authorisation, where the application is well-prepared and the competent authority's queue is manageable, is measured in months. It is not measured in weeks.

A firm building a new digital-asset business that intends to serve the EU market has the advantage of designing for MiCA compliance from inception. Entity formation, governance appointment and compliance infrastructure can be built to specification rather than retrofitted. That firm should decide on its member state before incorporating, not after. The capital, substance and governance requirements differ enough between member states that the choice of jurisdiction belongs at the beginning of the design process.

A token issuer considering whether to issue ARTs or EMTs alongside a service provision business faces a layered analysis. The token-level obligations – whitepaper content, reserve requirements, redemption rights – sit alongside the CASP-level service authorisation. A firm that issues and also exchanges its own token needs both the issuer compliance layer and the CASP authorisation layer to be coherent.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the competent authority's assessment period runs from the date the application is declared complete. The larger variable is preparation time: a well-structured application with compliant governance, capital and AML documentation reaches completeness faster than one requiring multiple rounds of supplemental information. From the decision to apply to receiving a CASP authorisation, firms should plan for a process measured in several months, not weeks. Member state, service scope and the firm's existing compliance maturity all affect the actual timeline.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction – the right member state for a CASP authorisation depends on the firm's service scope, user base, existing EU presence, banking requirements and long-term supervisory relationship preference. Lithuania and Malta offer established crypto-regulatory infrastructure and active competent authorities. Other member states offer different commercial and tax profiles. A sound jurisdiction selection requires analysing the regulatory, corporate and banking dimensions together. OBOLUS maps this across all relevant member states before a firm commits to any one path.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the enumerated regulated services. A CASP authorisation that includes custody as a permitted service covers that activity. However, if a firm provides custody alongside other financial services regulated outside MiCA – for example, securities custody – a separate authorisation under the applicable securities framework may be required in addition. The interaction between MiCA custody and traditional financial services regulation is jurisdiction-specific and should be assessed on the firm's full product set.

About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before a client commits to any structure. Digital assets are the entirety of our practice, and we act only for businesses – not for retail investors. To discuss your CASP authorisation or broader licensing strategy, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP and VASP authorisation strategy across the EU and leading offshore hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours