Skip to main content
logo
Ru

MiCA CASP License

EU authorization for crypto-asset service providers: 8 jurisdictions, one team
50+

Successful cases
to resolve problems with banks, stock exchanges and tax authorities

12years

Finance
and banking

>10MEUR

Returned to customers or saved
with our help

5years

Payment systems
and international transaction business

How it works

01

Jurisdiction selection

Review of business model, markets, team, tax position against current practice of 8 EU regulators

02

Gap analysis

Benchmark existing AML, governance, custody, IT security against MiCA Level 1/2/3

03

Filing preparation

Program of operations, AML/CFT policy, conflicts, custody, prudential safeguards, ICT risk (DORA), BCP

04

Regulator dialogue

Respond to RFIs, attend meetings, manage the review back-and-forth until authorization

05

Post-authorization

Transaction monitoring, market abuse surveillance, regulatory reporting, passporting

MiCA CASP authorization at a glance

MiCA (Markets in Crypto-Assets Regulation) is the single EU rulebook for crypto-asset services. It has applied to crypto-asset service providers since December 30, 2024. Any company that exchanges, holds, transfers, or trades crypto-assets for EU clients needs a CASP authorization from one member state regulator. That single authorization can then be passported to all 27 EU member states.

The short version for a founder or compliance officer planning the move:

  • One license covers the whole EU through passporting.
  • Initial capital starts at EUR 50,000 and rises to EUR 150,000 depending on the services you provide.
  • A realistic end-to-end timeline is 6 to 12 months, driven mostly by application quality and the regulator you choose.
  • National crypto regimes (Estonian FIU registrations, Lithuanian FNTT registrations, French PSAN, German crypto custody permissions) are being wound down and replaced by CASP authorization.
  • Real substance in the home member state is mandatory. Mailbox setups are rejected.

What counts as a CASP under MiCA

A crypto-asset service provider is any legal person whose occupation or business is providing one or more crypto-asset services to clients on a professional basis. MiCA lists the regulated services exhaustively:

  • custody and administration of crypto-assets on behalf of clients;
  • operation of a trading platform for crypto-assets;
  • exchange of crypto-assets for funds or for other crypto-assets;
  • execution of orders for crypto-assets on behalf of clients;
  • placing of crypto-assets;
  • reception and transmission of orders;
  • advice on crypto-assets and portfolio management of crypto-assets;
  • transfer services for crypto-assets on behalf of clients.

If your business model touches any of these for EU clients, you fall in scope. That covers centralized exchanges, brokers, OTC desks, custodians and wallet providers with control over client keys, and payment-adjacent models that move crypto-assets for customers. It also covers non-EU companies that actively solicit EU clients: reverse solicitation is a narrow exception, not a business model.

Stablecoin issuance sits in a separate part of MiCA (asset-referenced and e-money tokens) with its own regime. If your plans include issuing an e-money token, the analysis overlaps with the EMI licensing track and should be scoped together.

Capital requirements: Class 1, Class 2, Class 3

MiCA sets initial capital by service class, and the comparison table on this page shows the split. Class 1 (EUR 50,000) covers advisory and order-handling services. Class 2 (EUR 125,000) covers exchange, execution, custody, placing, and transfer services. Class 3 (EUR 150,000) applies to operating a trading platform.

Two rules matter in practice. First, if you combine services from different classes, the highest applicable class sets your minimum. An exchange that also holds client assets is priced as Class 2; add a trading venue and you are at Class 3. Second, initial capital is only the floor: ongoing own funds must stay at the higher of the class minimum and one quarter of the previous year's fixed overheads.

The capital must actually be paid in and evidenced at filing. Regulators check the source of funds of shareholders as part of the fit-and-proper review, so the funding structure should be clean and documentable before you file, not after.

The authorization process, step by step

The five stages above reflect how we run applications in practice. The center of gravity is the application file itself. A CASP filing is a full prudential dossier, not a form:

  • a program of operations describing every service you will provide and how;
  • AML/CFT policies and procedures aligned with EU AML rules;
  • governance arrangements, including fit-and-proper documentation for management and qualifying shareholders;
  • custody policy with segregation of client assets and key-management design;
  • ICT risk management under DORA, including incident response and business continuity;
  • conflict-of-interest, complaints-handling, and market-abuse prevention procedures;
  • prudential safeguards evidencing the capital position.

Once the file is submitted, the regulator first checks completeness, then runs the substantive assessment. In practice, plan for 6 to 12 months end to end. The single biggest driver of the timeline is the quality of the first submission: files that trigger long RFI (request for information) cycles lose months.

Grandfathering and national deadlines

MiCA gave existing nationally registered providers a transitional period during which they could keep operating under their old registration while applying for CASP authorization. Member states were allowed to shorten it, and most did.

As of mid-2026, the practical picture is this: the transitional window has closed or is closing in the member states that mattered for crypto operators, and national regimes such as the Estonian FIU registration or the French PSAN status no longer serve as a standalone basis for serving EU clients. An operator that missed its national cut-off without a filed CASP application is not grandfathered; it needs a fresh authorization and, until it is granted, has no clean legal basis to onboard EU customers.

For teams still on a national license, the sequencing question is no longer whether to move to MiCA but where to file and how fast the chosen regulator can process. That is a jurisdiction-selection exercise, and it is where the comparison below earns its place.

How to choose your jurisdiction

All 27 member states issue the same authorization with the same passporting rights, so the choice comes down to regulator practice, not the license itself. The factors that actually move the decision:

  • Speed and predictability. Lithuania has processed crypto applications faster than most large regulators, and filings run in English. See our Lithuania crypto license page for the local specifics.
  • Language of proceedings. Germany and Poland expect the file and regulator dialogue in the local language, which adds cost and time. Malta, Ireland, Lithuania, the Netherlands, and Luxembourg work in English. Details for Malta are on the Malta crypto license page, and for Poland on the Poland crypto license page.
  • Regulator posture. BaFin and the Central Bank of Ireland run institutional-grade reviews suited to well-capitalized applicants; smaller regulators are more accessible for lean teams.
  • Transition credit. If you already hold a Maltese VFA license or a French PSAN registration, the local conversion path is usually faster than filing cold elsewhere.
  • Banking and infrastructure. Access to SEPA rails and crypto-friendly banking varies by country and often decides the shortlist as much as the regulator does.
  • Tax and substance economics. Corporate tax matters less than people cost: MiCA requires management to actually run the business from the home state, so the salary market and talent pool of the chosen country become a recurring line item.

Outside the EU, national regimes continue to exist and can complement an EU setup for non-EU markets. Our crypto licensing hub covers those options, including the Czech Republic and Estonia pages for teams comparing their legacy registrations with the MiCA path.

Passporting across the EU

Once authorized, a CASP notifies its home regulator of the member states where it intends to provide services. The home regulator forwards the notification, and the CASP can operate cross-border on a freedom-of-services basis or through branches. There is no second review by host states and no per-country license fee structure to maintain, which is the core economic argument for MiCA over a patchwork of national permissions.

Passporting covers the services listed in the authorization. If you later add a service from a higher capital class, that is an extension of the authorization with the home regulator, not a new license.

Where CASP applications fail

Recurring weak points we see in files that stall:

  • No real local substance. Directors who live elsewhere and fly in quarterly do not satisfy the effective-direction requirement.
  • ICT risk treated as an afterthought. DORA compliance is assessed inside the CASP review; a thin IT security chapter generates the longest RFI cycles.
  • Custody design gaps. Regulators drill into key management, segregation of client assets, and what happens on insolvency. Marketing language does not survive this review.
  • Shareholder opacity. Every qualifying holder is vetted; unresolved source-of-funds questions freeze the file.
  • Copy-paste policies. Reviewers read hundreds of files and recognize template AML manuals that do not match the declared business model.

What changes compared with a national VASP registration

Most national crypto regimes were AML registrations: the regulator checked the beneficial owners and the AML officer and left the rest of the business largely alone. CASP authorization is a prudential license, closer to an investment-firm regime, and the day-to-day obligations reflect that:

  • conduct-of-business rules, including acting in the client's best interest, disclosure of costs, and marketing standards;
  • a full custody liability framework: CASPs are liable to clients for the loss of crypto-assets held in custody, with limited carve-outs;
  • the EU market-abuse regime for crypto-assets, with surveillance and reporting duties for trading venues and order handlers;
  • complaints handling with tracked response deadlines;
  • ongoing prudential and statistical reporting to the home regulator;
  • outsourcing rules and DORA-grade oversight of critical IT vendors.

Budgeting only for the application misses this second half. The compliance function that satisfies the regulator on day one has to keep running after authorization, and supervisors examine live CASPs, not just applicants.

Cost structure beyond initial capital

Initial capital is the visible number, and it is refundable in the sense that it stays on your balance sheet. The spending that leaves the company is elsewhere:

  • regulator application and supervision fees, which vary by member state and by service scope;
  • local substance: salaries of resident directors, the compliance officer, and the MLRO, which are recurring and set by the local labor market;
  • drafting and legal support for the filing package;
  • audit and financial reporting from year one;
  • ICT and monitoring tooling needed to meet DORA and market-abuse obligations.

We deliberately publish no fee figures on this page: regulators revise their schedules, and a stale number on a licensing page costs more trust than it earns. We price the full path for your specific service set during scoping.

How Incluence runs your application

We take the application from jurisdiction scoping to post-authorization operations: shortlisting regulators against your business model, running the gap analysis, drafting the full filing package, handling regulator dialogue and RFIs, and setting up the compliance routines you will be examined on after approval. Our team has filed with the regulators in the comparison table above and knows their current review practice, not just the statute.

If you are weighing MiCA against staying on a national license, or choosing between two member states, a short scoping call is usually enough to map the realistic options for your case.

Jurisdictions compared

CountryRegulatorTimelineLanguageBest for
LithuaniaBank of Lithuania4–6 monthsEnglishSpeed + CENTROlink SEPA
MaltaMFSA6–9 monthsEnglishVFA-to-MiCA transition
IrelandCentral Bank of Ireland9–12 monthsEnglishUS-parent entities, 12.5% tax
NetherlandsAFM + DNB6–9 monthsEnglishStrong fintech ecosystem
GermanyBaFin9–12 monthsGermanInstitutional reputation
FranceAMF + ACPR4–6* / 9–12 monthsFrenchPSAN-to-CASP transition
PolandKNF6–9 monthsPolishLarge domestic market
LuxembourgCSSF9–12 monthsEnglishInstitutional/fund-adjacent
Lithuania
RegulatorBank of Lithuania
Timeline4–6 months
LanguageEnglish
Best forSpeed + CENTROlink SEPA
Malta
RegulatorMFSA
Timeline6–9 months
LanguageEnglish
Best forVFA-to-MiCA transition
Ireland
RegulatorCentral Bank of Ireland
Timeline9–12 months
LanguageEnglish
Best forUS-parent entities, 12.5% tax
Netherlands
RegulatorAFM + DNB
Timeline6–9 months
LanguageEnglish
Best forStrong fintech ecosystem
Germany
RegulatorBaFin
Timeline9–12 months
LanguageGerman
Best forInstitutional reputation
France
RegulatorAMF + ACPR
Timeline4–6* / 9–12 months
LanguageFrench
Best forPSAN-to-CASP transition
Poland
RegulatorKNF
Timeline6–9 months
LanguagePolish
Best forLarge domestic market
Luxembourg
RegulatorCSSF
Timeline9–12 months
LanguageEnglish
Best forInstitutional/fund-adjacent

Capital requirements

Class 1€50,000
  • Reception/transmission of orders
  • Investment advice
  • Portfolio management
Class 2€125,000
  • Custody & administration
  • Exchange of crypto for funds/crypto
  • Execution of orders
  • Placing of crypto-assets
Class 3€150,000
  • Operation of a trading platform

Frequently Asked Questions:

MiCA's CASP provisions apply from 30 December 2024. The national transitional period under Article 143(3) allowed existing VASP registrants to keep operating while their CASP application was in process, but it expired on 1 July 2026 at the latest, and most member states closed their windows earlier. Since then, only a CASP authorization provides a legal basis for serving EU clients.

Yes. A CASP authorization granted by any EU competent authority grants the right to provide the listed services in all 27 member states on a freedom-of-services or branch basis, subject to notification.

Under Article 63 of MiCA, the regulator has 25 working days to check the application for completeness and 40 working days to assess a complete application and issue a reasoned decision; a request for additional information can suspend the assessment by up to 20 working days. In practice, first-time CASP applications run 6 to 12 months end-to-end depending on member state and application quality.

Yes. MiCA requires effective direction from within the Union — at least two management body members must actually run the business from the home member state. Mailbox setups are rejected.

National regimes have been repealed. Registrations under them remained valid only during the transitional period, which has now ended in all member states. Only a CASP authorization allows you to serve EU clients legally.

Consultation