Regulators across the European Union are no longer treating CASP authorisation (the licence required under the Markets in Crypto-Assets Regulation, or MiCA, for crypto-asset service providers) as a routine filing. National competent authorities, guided by ESMA, are applying elevated review standards to applicants whose business models sit at the edge of the defined activity perimeters, carry cross-border user bases, or involve complex token types. For a founder or general counsel who assumed the authorisation process would resemble a standard financial-services application, the reality is considerably more demanding.
Under the MiCA regime, a business that provides crypto-asset services in the EU – custody, exchange, transfer, advice, portfolio management, or the operation of a trading platform – must hold a CASP authorisation issued by the national competent authority of its home member state. The authorisation carries EU-wide passporting rights, meaning a single licence can unlock the entire EU and EEA market. That is the upside. The downside is that the application process, under heightened supervisory scrutiny, is longer, more document-intensive, and more technically demanding than many applicants expect. Operating without authorisation exposes the business to enforcement action, banking terminations, and the loss of the EU user base entirely – risks that arrive without advance warning.
This page maps the regulated basis, the application process, the most common structural failures, and the cross-border decisions that determine whether a CASP application succeeds or stalls.
Who Needs CASP Authorisation Under MiCA?
Any business providing a defined crypto-asset service to clients in the EU on a professional basis needs CASP authorisation – regardless of where the legal entity is incorporated. The activity test, not the domicile of the entity, determines the obligation. An exchange incorporated in the BVI but actively acquiring EU-resident users is within the MiCA perimeter. A custody provider domiciled in Singapore with a material European client book faces the same conclusion. Regulators in the leading hubs increasingly expect applicants to have worked through this analysis before they file.
The defined activities include: custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for fiat or for other crypto-assets; execution of orders; placing of crypto-assets; reception and transmission of orders; advice on crypto-assets; portfolio management; and transfer services. Most operators running a multi-product exchange are performing several of these simultaneously. Each activity must be authorised; the scope of the application must reflect all of them. A common mistake is filing for the narrowest plausible perimeter to reduce scrutiny, then discovering mid-review that the regulator has mapped the actual business and requires a broader scope.
ESMA and the national competent authorities have published detailed guidance on the activity perimeter, and regulators have demonstrated a willingness to challenge applicants whose stated scope does not match their observable product offering. Firms should conduct a formal activity mapping exercise before filing.
What Does Heightened Scrutiny Actually Mean in Practice?
Heightened scrutiny under the MiCA authorisation process means that national competent authorities are applying detailed due-diligence review to governance, technology, AML/CFT frameworks, and business model viability – not merely checking that forms are complete. This shift is observable across the EU: review timelines are extending, requests for supplemental information are arriving in multiple tranches, and regulators are rejecting applications that would have passed a lighter-touch registration process in earlier years.
In our practice, we see heightened scrutiny concentrate on four pressure points. First, governance: the regulator wants to see that the management body has demonstrable expertise in financial services, technology, and compliance – not founders with pure crypto backgrounds presenting a thin governance layer. Second, own-funds and capital adequacy: the required level varies by activity class, and the regulator will test that the own-funds calculation is accurate, not understated. Third, the AML/CFT and Travel Rule infrastructure (the obligation to pass originator and beneficiary data with a transfer, as required under FATF Recommendation 15 and the applicable EU transfer-of-funds rules): applicants must demonstrate that their technical systems can comply, not merely that they intend to comply. Fourth, conflicts of interest and custody segregation: the regulator expects policies that are operational, not aspirational.
We regularly advise applicants who arrive after a first-round rejection. The pattern is consistent: the application was technically complete but substantively thin on governance documentation, the technology risk assessment was generic, and the AML programme had not been mapped to the specific services being offered. A second application requires genuine structural remediation, not a redraft of the same documents.
For a scoped assessment of your current application position, contact OBOLUS at info@oboluslaw.com. The process described above is the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis substantially. Map your options
How Does the CASP Application Process Work Step by Step?
The CASP application process under MiCA follows a defined sequence, beginning with the selection of the home member state and ending with a passportable authorisation. The process is structured but not linear: most applicants receive multiple rounds of questions from the national competent authority before the file is declared complete.
Step one is home-state selection. The choice of authorising jurisdiction determines the supervisory relationship for the life of the licence. Member states differ in supervisory philosophy, processing capacity, language requirements, and the degree of pre-application engagement they permit. Lithuania, under the Bank of Lithuania, was historically regarded as an accessible EU entry point; under MiCA it remains a viable option for well-structured applicants, though the review depth has increased materially. Malta's MFSA brings its transition from the prior VFA framework to the MiCA CASP regime; applicants with VFA history may face a conversion process rather than a fresh application. Other member states are building supervisory capacity as MiCA becomes fully operational. The selection decision is strategic and should be made with current market intelligence, not general reputation.
Step two is the pre-application phase. Most national competent authorities permit – and many encourage – a pre-filing dialogue. This is the moment to surface structural issues before they become formal objections. We use this phase to pressure-test the governance model, confirm the activity scope, and align the AML programme with the regulator's current expectations.
Step three is the formal application file. The MiCA application package is substantial: a programme of operations, a business plan with financial projections, governance documentation, the register of management body members with fitness-and-propriety evidence, the AML/CFT policy suite, technology and security risk assessments, and – where the applicant intends to offer custody – a detailed description of the safeguarding arrangements. The file must be internally consistent: a discrepancy between the stated activity scope and the technology documentation will generate a supplemental information request.
Step four is the review period. Under MiCA, the national competent authority has a defined period to assess completeness and a further assessment window after the file is declared complete. Practically, the elapsed time from submission to authorisation varies by jurisdiction, applicant complexity, and the volume of applications the authority is processing. For operators with complex cross-border structures, timelines are typically longer. Planning should assume a multi-month process, with board and banking timelines aligned accordingly.
Step five is passporting. Once authorised, the CASP may notify its home regulator of its intention to provide services in other member states. The passporting mechanism operates through the home regulator; the host-state regulator receives notification and may raise concerns within a defined window. For operators with a pan-European product, the passporting strategy should be planned during the application phase, not after authorisation.
What Are the Most Common Structural Mistakes in CASP Applications?
The most common failure in a CASP application under heightened scrutiny is a governance structure that looks complete on paper but cannot withstand functional interrogation. Management body members are named, CVs are filed, but the regulator asks what each person actually does – and the answer reveals a thin layer of oversight over an offshore technical team. Regulators expect substance: management body members who can explain the firm's AML programme, interrogate its technology risk assessment, and exercise independent judgment on conflicts of interest.
A second structural mistake is the misclassification of token types. A business handling an asset-referenced token (an ART under MiCA, a token that references multiple currencies or assets to maintain a stable value) or an e-money token (an EMT, referencing a single official currency) faces a distinct authorisation pathway and issuer-level obligations, not merely CASP-level authorisation. Applicants who treat ARTs or EMTs as standard crypto-assets and file accordingly will encounter a fundamental objection at any point in the review.
Third: the AML programme is copied from a standard template rather than mapped to the specific services being offered. A custody-only operator has a different risk profile than a trading platform. The regulator will test whether the risk assessments are specific to the business, not generic. FATF Recommendation 15 expectations and the applicable EU transfer-of-funds framework require a system that can execute the Travel Rule operationally – documenting intent is not enough.
Fourth: the own-funds position is understated because the applicant applied the narrowest activity classification to reduce the minimum threshold. Under scrutiny, the regulator applies the correct classification and requires revised figures. This delays the application and creates a credibility issue that persists through the rest of the review.
In a recent authorisation matter, a payments-adjacent operator had filed a CASP application in an EU member state covering exchange and transfer services. The national competent authority's first supplemental information request identified that the operator's stablecoin product was classifiable as an EMT under MiCA, triggering issuer-level obligations that had not been addressed in the application. We restructured the product wrapper, separated the issuance vehicle, and rebuilt the application file around a clean CASP scope. The application was re-submitted in a later quarter and proceeded without a further structural objection.
How Does the Cross-Border Reality Affect a MiCA CASP Structure?
The cross-border reality of running a digital-asset business is that the legal entity, the user base, the banking, and the technical infrastructure rarely sit in the same jurisdiction – and MiCA does not exist in isolation from the regimes that govern those other layers. A CASP authorisation addresses the EU regulatory layer; it does not resolve the licensing question in Singapore, the FCA registration question in the UK, or the money-transmitter licensing obligations in US states where the operator has customers.
For operators with a genuinely global user base, the MiCA CASP is one layer of a multi-jurisdictional licence stack. The Monetary Authority of Singapore (MAS) requires a Digital Payment Token service licence under the Payment Services Act for operators serving Singapore users. The Financial Conduct Authority (FCA) requires cryptoasset registration under the Money Laundering Regulations for UK activity, alongside compliance with the financial-promotion rules that apply to crypto marketing in the UK. The Securities and Futures Commission (SFC) in Hong Kong operates a VASP licensing regime for virtual-asset trading platforms. These regimes overlap in their AML and Travel Rule expectations but differ in their governance, capital, and technology standards.
The banking layer is an independent constraint. EU CASPs require banking relationships that can handle fiat on-ramps and off-ramps for clients; those relationships are not automatic on authorisation. We have seen well-structured MiCA applicants find that their primary banking relationship closed during the authorisation process, or that the bank required the CASP authorisation to be in hand before it would onboard the entity. Sequencing the banking and licensing tracks is a practical necessity, not an afterthought.
Allied counsel in the relevant jurisdiction handles the local-law filing where the multi-jurisdictional stack requires simultaneous filings. For CASP applicants with parallel MAS or SFC processes, early coordination between the EU and non-EU tracks avoids inconsistencies in governance documentation that individual regulators will identify.
If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Operators we advise routinely discover that the banking closure and the application stall share a common root cause. Map your options
Which Applicant Profile Should Choose Which Approach?
Not every CASP applicant faces the same risk profile or warrants the same application strategy. The choice of home-state jurisdiction, the pre-application engagement approach, and the internal build-versus-outsource decision for the compliance programme each turn on the operator's specific circumstances.
A well-capitalized exchange group with an existing EU user base and an established AML programme should prioritize home-state selection for supervisory philosophy and passporting utility, engage in pre-application dialogue in the chosen jurisdiction, and file a full application quickly. The risk for this profile is delay, not rejection; the mitigation is substance depth in the governance and technology documentation from the outset.
An early-stage operator seeking its first EU authorisation to anchor a global licensing stack should consider which member state offers the most accessible pre-application engagement and the most predictable review timeline, given current supervisory capacity. This profile benefits from a phased approach: resolve the activity scope question, build the governance layer to the required standard before filing, and sequence the banking engagement so that a provisional relationship is in place before the licence issues.
An operator transitioning from a pre-MiCA registration or a third-country VASP structure should treat the MiCA application as a structural rebuild, not a re-registration. The prior registration does not carry forward. The review will apply the full MiCA standards, and a thin conversion file will generate the same supplemental-information cycle as a first-time application.
A token issuer that also provides custody or exchange services needs to resolve the token classification question first. If the tokens being issued are ARTs or EMTs, the issuer-level obligations under MiCA are distinct from and additive to the CASP authorisation obligations. Filing in the wrong order – CASP first, issuer question unresolved – creates a structural inconsistency that the regulator will surface.
Self-Assessment: Is Your CASP Application Ready for Heightened Review?
A CASP application is ready for submission under heightened supervisory review only when each of the following can be answered affirmatively with documented evidence in the file.
Management body composition: each member can demonstrate relevant expertise in financial services regulation, technology, or compliance; the management body as a whole covers the firm's activity scope; independence and conflict-of-interest policies are operational and documented.
Activity scope: every crypto-asset service offered to EU clients – including ancillary services – is identified and covered by the authorisation application; no services are omitted on the assumption that they are de minimis.
Token classification: the classification of every token type the firm handles has been formally assessed; ART and EMT classifications have been addressed at the issuer level before the CASP application is filed.
AML/CFT programme: the programme is specific to the firm's services and risk profile; the Travel Rule technical capability is demonstrated, not merely described; the programme has been reviewed by a qualified AML specialist against the applicable EU transfer-of-funds framework.
Own-funds: the calculation is accurate for the full activity scope; the regulator's own-funds guidance for each activity class has been applied; the figures are supportable by audited or management accounts.
Technology and security: the risk assessment covers all systems handling client assets and client data; business continuity and incident response procedures are documented and tested.
Custody arrangements: if custody is within scope, the safeguarding policy, the segregation arrangements, and the reconciliation procedures are fully documented and consistent with MiCA's custody-specific requirements.
Banking: a banking relationship capable of supporting EU fiat flows is identified and, where possible, conditionally confirmed pending authorisation.
If any item on this list generates a qualified answer, the application is not ready. Filing a thin application under heightened scrutiny produces a supplemental-information request, not a fast authorisation. We map the licence, banking, and compliance stack for operators before they commit to a filing date.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the full practice overview covering licence types, jurisdictions, and the application process across more than seventy markets
- Digital-Asset Custody Licensing in the Cayman Islands – CIMA regime, custody licence categories, and the application process for Cayman-domiciled structures
- DeFi Protocol Legal Structuring in Kazakhstan (AIFC) – AFSA regime, common-law AIFC framework, and structuring options for DeFi protocols
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the authorisation timeline depends on the home member state, the complexity of the applicant's structure, and the depth of the application file. A well-prepared application filed in a jurisdiction with adequate supervisory capacity typically takes several months from submission to authorisation. Applications that receive multiple rounds of supplemental-information requests take longer – sometimes materially so. Planning should assume a multi-month process and align banking, hiring, and commercial timelines accordingly. An experienced adviser can reduce timeline risk by identifying structural issues before they become formal objections.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right home member state for a MiCA CASP application depends on the firm's activity scope, existing EU presence, banking relationships, and strategic passporting plan. Member states differ in supervisory philosophy, pre-application engagement practices, and processing capacity. Outside the EU, the right jurisdiction for a parallel or primary licence depends on the user base, the business model, and the capital and governance requirements of the relevant regime. A jurisdiction selection decision should be made on current market intelligence and the firm's specific profile, not general reputation.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the defined CASP activities – it must be expressly within the scope of the CASP authorisation. If custody is offered alongside exchange or transfer services, all activities must be covered. Some jurisdictions outside the EU treat custody as a separately licensed activity requiring a distinct application. Whether a separate custody licence is required turns on the jurisdiction, the structure of the custodial relationship, and the nature of the assets held. A multi-jurisdictional operator should resolve this for each market individually.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers, and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking, and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody, and payment layers before you commit – and we have advised clients across the full range of digital-asset business models, from first-licence exchanges to multi-jurisdictional custodians. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy, home-state selection under MiCA, and multi-jurisdictional licence stack design for crypto exchanges and custodians.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.