MiCA CASP License in 2026: The Complete Guide
The most detailed 2026 MiCA Crypto-Asset Service Provider guide on the web: the ten regulated services, real capital and cost breakdowns, country-by-country grandfathering deadlines, the authorised-firms league table, top five rejection reasons, and the transition playbook from national VASP to CASP.
What a MiCA CASP licence authorises
A Crypto-Asset Service Provider (CASP) licence is the single authorisation granted under Regulation (EU) 2023/1114, better known as MiCA, that lets a firm provide regulated crypto-asset services anywhere in the European Economic Area. It replaces the patchwork of national VASP registrations (French PSAN, German BaFin crypto custody, Italian OAM, Spanish registry, Lithuanian VASP, Dutch DNB, Maltese VFA and so on) with a single rulebook supervised by home-state competent authorities in coordination with ESMA and the EBA.
By early 2026 roughly 60 CASPs have been authorised across the EU, concentrated in Germany (18), the Netherlands (14), France (6) and Malta (6). Named firms already on the ESMA register include Crypto.com (Foris DAX MT), OKX (Okcoin Europe), ZBX (Zillion Bits), Bitpanda Asset Management, MoonPay Europe and bitFlyer Europe.
Title V of MiCA defines ten regulated services. A CASP applies for any combination, and the capital class is driven by the mix.
Custody and administration
Safekeeping of crypto-assets on behalf of clients, including control of the means of access such as private keys.
Operation of a trading platform
Running a multilateral system that brings together third-party buying and selling interests in crypto-assets.
Exchange for funds
Buying and selling crypto-assets against fiat currency as a principal using own capital.
Exchange for other crypto
Crypto-to-crypto conversion as a principal, including spot swaps on a proprietary book.
Execution of orders
Concluding agreements to buy or sell crypto-assets on behalf of clients, including on external venues.
Placing of crypto-assets
Marketing newly issued crypto-assets to specified buyers on a firm-commitment or best-efforts basis.
Reception and transmission
Receiving client orders and passing them to a third party for execution without trading against them.
Advice on crypto-assets
Personal recommendations to a client about transactions in one or more crypto-assets.
Portfolio management
Managing crypto-asset portfolios on a discretionary client-by-client mandate.
Transfer services
Transferring crypto-assets from one distributed-ledger address or account to another on behalf of clients.
MiCA does not cover crypto-assets that already qualify as financial instruments under MiFID II (those stay under the investment-firm regime), deposits, pension products, insurance, securitisation, or fully decentralised services without an identifiable provider. NFTs are out of scope in principle, but regulators read "genuinely unique" narrowly: large collection issuances routinely fall back in.
Let's discuss your project and see how we can launch your MiCA-ready crypto banking product together
Request demoAm I even in scope? The five-step founder test
MiCA is activity-based and effect-based. What matters is what your users can actually do through your product, not the label on the landing page. Before you spend a euro on legal counsel, run your business through the five-step scope test.
- Corporate location. Incorporation in the EU creates a presumption of scope. Incorporation outside the EU does not automatically exempt you: if you actively serve EU users, you are in scope.
- User geography. Any active EU user base or intentional targeting of EU markets (EU-language site, EU advertising, EU payment rails) triggers MiCA, regardless of where the legal entity sits.
- Service mapping. Match product features to the ten MiCA services. Custody, trading platform operation, exchange, execution, placing, reception/transmission, advice, portfolio management and transfers are each captured separately.
- Fund control. Holding keys or controlling access to user assets tilts heavily toward custody scope. A non-custodial design does not automatically remove you from scope if you also operate exchange, execution or a trading platform.
- Monetisation. Professional provision of services (fees, subscriptions, revenue shares, spreads, maker/taker) is a regulatory signal. Free, ad-hoc or one-off activity may escape scope; fee-earning activity almost never does.
Five dangerous misconceptions founders keep making (and which regulators reject on day one of the review):
- "Non-custodial equals out of scope." False. Execution, exchange and platform operation are independent scope triggers, even when the firm never touches user keys.
- "We are only a tech provider." If users can transact in crypto through your product and your company earns revenue from it, you are a service provider, not software.
- "We are incorporated outside the EU, so we are fine." Serving or targeting EU users extends MiCA reach regardless of domicile. The ESMA register already lists enforcement notices against offshore firms.
- "We outsourced the regulated bit." Outsourcing custody, matching or KYC to a vendor does not strip you of CASP status if the service is part of your product.
- "Disclaimers will solve it." MiCA is drafted around substance over form. A banner saying "not for EU residents" does not protect you if an EU resident can sign up in 30 seconds.
Reverse solicitation exists but is genuinely narrow. An EU user must initiate contact for a truly specific service. Any marketing, SEO, referral programme or paid acquisition aimed at EU users breaks the defence.
The MiCA timeline and how the transitional period actually ends
MiCA entered into force on 29 June 2023 and applies in phased stages.
- 30 June 2024. Titles III and IV start to apply. Issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs, the MiCA name for fiat-backed stablecoins) must be authorised or be an authorised credit institution or EMI.
- 30 December 2024. Title V starts to apply. Every firm providing crypto-asset services in the EU needs a CASP authorisation, or must use the Article 60 simplified notification route available to existing MiFID firms, credit institutions, EMIs, PIs, UCITS managers or AIFMs.
- Transitional window. Firms lawfully providing crypto services under national law before 30 December 2024 may continue operating while their CASP application is processed, up to a maximum of 18 months. Each Member State chose its own window.
- 1 July 2026. Absolute EU-wide deadline. Any firm still trading without a granted CASP authorisation or simplified notification is operating unlawfully, regardless of prior national status.
The real punchline nobody prints on the homepage: for most Member States the application-submission deadline (the date by which you had to file a complete CASP file to benefit from grandfathering) has already passed. If you missed your national submission window, you are not in transition; you are in cliff-edge territory.
| Member State | Grandfathering end | Status in April 2026 |
|---|---|---|
| France | 1 July 2026 (full 18 months) | Window open. Fast-track for registered PSANs. |
| Malta | 1 July 2026 (full 18 months) | Window open. VFA-holders migrated on pre-cleared files. |
| Luxembourg | 1 July 2026 (full 18 months) | Window open. CSSF processes with English and French. |
| Italy | 1 July 2026 (full 18 months) | Window open. CONSOB and Banca d'Italia share the file. |
| Cyprus | 1 July 2026 (full 18 months) | Window open. CySEC processes in English. |
| Spain | 30 June 2026 (extended from 12 to 18 months) | Window open. CNMV updated December 2025 after cliff-edge risk. |
| Germany | 31 December 2025 | Expired. BaFin no longer grants transitional cover. |
| Ireland | 31 December 2025 | Expired. Central Bank of Ireland now requires granted CASP. |
| Austria | 31 December 2025 | Expired. FMA supervises direct. |
| Lithuania | 1 January 2026 | Expired. Bank of Lithuania registered CASPs only. |
| Netherlands | Mid-2025 | Expired. AFM licensed early movers. |
| Finland, Latvia, Hungary | Mid-2025 | Expired. |
| Poland | No national transposition yet | Presidential veto on Crypto-Asset Market Act in December 2025. No formal pathway for MiCA CASP authorisation. High uncertainty. |
| Belgium | 1 July 2026 | Window open since January 2026 after law of 11 December 2025. |
| Portugal | 1 July 2026 | Window open after Law 69/2025 (January 2026). |
Firms still unlicensed in expired jurisdictions face three options: (1) withdraw from that market, (2) passport in from a Member State where they already hold a CASP, (3) use the Article 60 simplified notification if they also hold a compatible EU licence (MiFID, EMI, PI, credit institution).
CASP vs MiFID vs national VASP vs Article 60 notification
Four regimes overlap in 2026 and founders routinely confuse them.
| Dimension | MiCA CASP | MiFID Investment Firm | National VASP (legacy) | Article 60 notification |
|---|---|---|---|---|
| Assets in scope | Crypto-assets that are not financial instruments: utility tokens, ARTs, EMTs and most payment tokens. | Tokenised transferable securities, tokenised derivatives, security tokens. | Whatever the national law covered, usually crypto-to-fiat exchange and custody. | Same as CASP, but only for the services equivalent to the firm's existing authorisation. |
| Who can use it | Any applicant. | Any applicant. | National entities only; window closing across the EU. | MiFID firms, credit institutions, EMIs, PIs, UCITS managers, AIFMs. |
| EU passport | Yes, notification through home NCA. | Yes, under MiFID II. | No. Each Member State required separate registration. | Yes, through the home licence's existing passport. |
| Initial capital | EUR 50k / 125k / 150k. | EUR 75k / 150k / 750k. | Usually nominal. | No extra capital beyond home licence (assuming sufficient for the crypto add-on). |
| Typical timeline | 4 to 12 months for a complete file. | 6 to 18 months. | Windows mostly closed by 2026. | 40 working days for the NCA to object, so effectively 2 to 3 months. |
Rule of thumb: tokenised equity or bonds go MiFID, everything else on an ordinary blockchain goes CASP. A credit institution, EMI, PI or MiFID firm adding a crypto product almost always runs the Article 60 notification route because it collapses the timeline to a few months at a fraction of the cost.
One trap worth flagging. A CASP that offers custody or transfer services for e-money tokens (MiCA EMTs) must comply simultaneously with the MiCA capital requirement in Article 67 and Annex IV and the PSD2 Article 7 initial capital requirement, because EMT custody is treated as a payment service. EBA confirmed this in 2025. Budget for the higher of the two and plan governance that satisfies both rulebooks.
Initial capital, own funds and what the NCA actually looks at
Annex IV of MiCA assigns each CASP to one of three prudential classes. Initial capital is the floor. Ongoing own funds is the higher of the class floor or one quarter of the previous year's fixed overheads. Both figures are consumed by losses and must be rebuilt within 30 days.
A CASP authorised for several services pays the highest applicable class once, not cumulatively. Capital must be paid up in cash and sit in a segregated bank account at the time of authorisation. Own funds qualify only as Common Equity Tier 1 under Articles 26 to 30 of Regulation (EU) 575/2013 after the Article 36 deductions: founders' shareholder loans or uncalled capital do not count.
Professional indemnity insurance does not substitute for capital under MiCA, but a CASP must carry PII sized to activity, client count and business model. CASPs offering custody additionally need a policy or capital set-aside covering operational and cyber risks that could cause client losses under Article 75.
The real cost of getting licensed (and staying licensed)
Most competitor guides either skip numbers or give a single range. This is what the first 18 months of a serious CASP project actually looks like.
| Cost line | Typical range | Notes |
|---|---|---|
| Initial capital paid up | EUR 50k - 150k | Class 1/2/3. Ring-fenced at authorisation. |
| Local company setup and EU director | EUR 5k - 15k setup + EUR 30k - 60k/year director cost | At least one resident director required. Nominee directors are routinely rejected. |
| Policies and documentation build | EUR 25k - 80k | Governance, AML/CFT, ICT risk, custody, outsourcing, continuity, conflicts, complaints, market-abuse surveillance. Templated policies fail completeness checks. |
| Legal counsel for the application | EUR 40k - 150k | Local firm (Malta, NL, DE, FR) for filing, plus home counsel if founders sit outside the EU. |
| Compliance officer / MLRO (year 1) | EUR 60k - 120k/year | Must be in the home Member State, full-time for anything bigger than Class 1. |
| Office rental and basic ops | EUR 5k - 40k/year | Virtual-only addresses rejected. Shared coworking can work for Class 1. |
| Technology stack (custody, ledger, KYC, Travel Rule) | EUR 150k - 600k year 1 build, or EUR 5k - 30k/month on a white-label | Buying a white-label platform (Crassula-style) collapses this line and the timeline. |
| Penetration test and ICT audit | EUR 20k - 60k | Required evidence in the file. DORA alignment expected. |
| NCA application fee | EUR 2k - 25k | Varies by jurisdiction. MFSA, BaFin and AMF are at the higher end. |
| Annual supervisory fee (post-licence) | EUR 5k - 50k/year | Scales with size and services. Germany and Ireland highest. |
Realistic first-year all-in for a credible Class 2 or Class 3 CASP: EUR 350k to EUR 900k, of which EUR 125k to EUR 150k is the locked capital you keep. Malta's public estimates put first-year costs between EUR 200k and EUR 300k for a lean setup with a white-label technology stack. Germany, France and Ireland run 2 to 3 times that for a comparable operation.
The cheapest line to discount is the technology stack. Every first-wave CASP that tried to build custody, matching, KYC and Travel Rule in-house overshot the budget and the timeline, and several withdrew their application to resubmit with a vendor stack.
The authorisation process in six phases with realistic durations
Articles 62 and 63 of MiCA set a standardised procedure across all NCAs. Differences in speed, language of procedure and flexibility mirror what you already see under PSD2.
- Phase 1 - Home Member State selection and incorporation (1 to 4 weeks). Establish the EU entity, lease a real office, appoint a resident executive director. Regulators now check Companies House, land-registry and social-security records before they meet you.
- Phase 2 - Pre-application engagement (1 to 3 weeks). Almost every NCA expects an informal meeting before filing. Bring a one-pager business model, the Class 1/2/3 scope, capital plan, custody architecture and the AML approach. Skipping this meeting is a red flag on its own.
- Phase 3 - Application package development (6 to 12 weeks). Full file: programme of operations, three-year business plan with stressed projections, structural and governance arrangements, ICT and cybersecurity framework (DORA-aligned), AML/CFT manual with Travel Rule implementation, safeguarding and custody policy, market-abuse detection procedures, outsourcing register, complaints handling and conflicts-of-interest policy, plus fit-and-proper questionnaires for every director and qualifying shareholder.
- Phase 4 - Submission and completeness check (25 working days). The NCA has 25 working days to confirm the file is complete. Missing items reset the clock. First-wave CASP files routinely failed this step because firms underestimated the depth expected on custody and ICT.
- Phase 5 - Substantive assessment (40 working days, extendable by 20). The statutory maximum is roughly five months of clock time once the file is complete. Real-world timelines in 2025 ran from 4 to 12 months depending on jurisdiction and quality of the file.
- Phase 6 - Decision and ESMA register (1 to 3 weeks). Once granted, the CASP is added to the ESMA register. The interim register is published as a weekly CSV on the ESMA website until mid-2026, when it migrates into ESMA's full IT systems.
Passporting to other Member States is a notification, not a second licence. The home NCA transmits the file to the host authorities and services can commence 15 calendar days after notification.
The five rejection reasons NCAs cite most often
Data from the first two years of CASP authorisations (ESMA peer review, Hogan Lovells 2025 analysis and published NCA decisions) shows the same five deficiencies appear in almost every rejected file. If your application doesn't cover them with the depth an inspector would recognise, expect a refusal or a two-year stop-the-clock loop.
- Weak AML/CFT with no evidence of enforcement. Regulators are not satisfied by a well-written policy: they want detection rules, rule-tuning logs, testing evidence, alert-to-SAR conversion rates and the CV of the MLRO. A templated "AML manual" used on day one is an instant flag.
- Unclear governance and fit-and-proper gaps. Directors without relevant crypto-asset experience, part-time compliance officers, opaque shareholder structures, directors serving on multiple applicants at once. The NCA runs reverse fit-and-proper checks and asks the same question of every candidate.
- Proof of capital the regulator can't trust. Capital held in a founder's personal account, foreign-currency deposits without a lock-up, shareholder loans, or uncalled capital. Capital must be paid up in cash in an EU credit institution, in the licensed entity's name, and evidenced by a bank statement at submission.
- No genuine EU substance. Virtual addresses, nominee directors, zero local staff, meetings scheduled over video with founders sitting outside the EU. MiCA requires a physical presence, a resident director, real staff, and demonstrable decision-making in the home state.
- Vague business model. Applications that can't explain how the firm makes money, who the customers are, or what exactly the product does. NCAs reject files that use marketing language instead of transaction flows, revenue lines and volume projections.
Two operational mistakes kill otherwise decent files: slow or incomplete responses to NCA RFIs, and rushing a filing in the last two months of a national grandfathering window. Both are avoidable. Treat regulator questions as the top priority of the week and file at least six months before the submission deadline.
Popular CASP jurisdictions in 2026 with real benchmarks
Every NCA applies the same regulation, but supervisory style, timelines, cost and substance expectations diverge by a factor of three. Pick the jurisdiction that fits the audience (retail, institutional, B2B), not the one with the shortest headline timeline.
| Jurisdiction | NCA | Language | Typical timeline | Licensed by early 2026 |
|---|---|---|---|---|
| Germany | BaFin | German (English accepted for annexes) | 9 to 15 months | ~18 firms, incl. Bitpanda Asset Management |
| Netherlands | AFM with DNB for prudential | English | 6 to 10 months | ~14 firms, incl. MoonPay Europe |
| France | AMF with ACPR | French (English accepted for annexes) | 5 to 9 months | ~6 firms, fast-track for ex-PSAN |
| Malta | MFSA | English | 3 to 6 months | ~6 firms, incl. Crypto.com, OKX, ZBX |
| Luxembourg | CSSF | English, French, German | 6 to 10 months | Small, incl. bitFlyer Europe |
| Ireland | Central Bank of Ireland | English | 9 to 14 months | Small, high-substance expectation |
| Lithuania | Bank of Lithuania | English | 4 to 6 months | Small. Grandfathering expired 1 Jan 2026 |
| Cyprus | CySEC | English | 6 to 9 months | Window open to 1 July 2026 |
| Poland | KNF (designation pending) | Polish | Unknown | No pathway. Veto on national law December 2025. |
Malta, the Netherlands and Lithuania dominate the "founder-friendly" bucket for Class 2 retail products. Germany and France are the tier-1 stamps for institutional-facing CASPs and listed-exchange subsidiaries. Ireland is the standard for firms that already run a MiFID or EMI there and want crypto alongside. Cyprus, Luxembourg, Czechia and Bulgaria are the next wave for cost-conscious setups.
Governance, fit-and-proper and local substance
MiCA codifies governance expectations at EU level. NCAs run the same four checks on every file.
- Management body. At least two executives of good repute, collectively covering crypto-asset services, governance, IT and AML. The board as a whole must balance strategic, risk and operational expertise. Expect each director's CV to be cross-checked against the ESMA crypto-related enforcement list before approval.
- Qualifying shareholders. Anyone with 10% or more voting rights or capital is fit-and-proper tested. Complex corporate structures are unpacked to the ultimate beneficial owner. Crypto-native cap tables with SAFTs, warrants and tokens must be translated into an orthodox cap table for the NCA.
- Local substance. At least one director resident in the home state. Real office. Local compliance officer, risk lead and head of technology. NCAs now ask for recent payroll records and video of the office. Nominee structures are uniformly rejected.
- Outsourcing. Critical functions that are outsourced (custody tech, matching engine, KYC, Travel Rule) go through an outsourcing risk assessment. The CASP remains fully responsible for the outsourced activity. DORA alignment is expected for every ICT provider.
Custody, safeguarding and the Article 75 liability rule
Custody is the single most regulated service under MiCA because client losses from hacks, mismanagement and insolvency have driven most of the public harm in the sector. A CASP offering custody and administration must:
- Segregate client holdings. Client crypto-assets cannot be commingled with the CASP's own assets on-chain or off-chain. The CASP maintains a register of positions per client reconciled at least daily.
- Apply a documented custody policy. Hot vs cold wallet usage, multi-signature and MPC design, key-ceremony procedures, withdrawal approvals, emergency access protocol and key-recovery plan. The NCA reads the policy document, the code, the access-control matrix and the audit logs.
- Be liable for losses. Article 75 makes the CASP liable up to the market value of the assets lost as a result of an incident attributable to the CASP. This is stricter than most pre-MiCA national regimes and drives capital set-asides, insurance cover and stronger operational controls.
- Avoid rehypothecation. Using client crypto-assets for the CASP's own account or lending them out requires explicit informed client consent and is banned for retail clients in several Member States.
- Safeguard client funds (fiat). Client fiat balances must be placed with an EU credit institution or the ECB by the next business day. No own-account use, no comingling, daily reconciliation, audit trail stored for five years (up to seven on request).
For trading platforms, MiCA imposes pre- and post-trade transparency, order-book integrity rules, a market-abuse framework modelled on MAR, and a duty to halt trading for a crypto-asset when a significant market event requires it. Post-trade data must be free to the public no later than 15 minutes after the transaction. Exchange-for-funds and exchange-for-other-crypto services publish firm prices and a policy for price formation.
Marketing, white papers, Travel Rule and cross-border offers
MiCA regulates not only service provision but also the offer of crypto-assets to the public. A CASP that lists, distributes or promotes tokens needs to check issuer requirements too.
- White paper for non-ART/EMT tokens. Issuers of utility tokens and other crypto-assets that are not ARTs or EMTs must publish a white paper with prescribed content, notify it to the home NCA and display it on a public-facing page before the token is offered in the EU.
- ARTs and EMTs. Asset-referenced tokens and e-money tokens have their own authorisation and prospectus-style white paper regime, supervised by the EBA once they become significant.
- Marketing communications. Must be clear, fair and not misleading, consistent with the white paper, and labelled as marketing. Social-media and influencer content is in scope. ESMA has already opened enforcement on "finfluencer" posts that mis-stated ART backing ratios.
- Travel Rule. Regulation (EU) 2023/1113 requires full originator and beneficiary data on crypto transfers, with no de minimis threshold (unlike FATF at USD 1,000). CASPs must have a Travel Rule solution live at go-live, not "later". Verification of self-hosted-wallet ownership is required above EUR 1,000. Third-party Travel Rule vendors (Notabene, Sumsub, 21 Analytics, Global Relay) are the norm; building in-house is rarely the right call.
- Cross-border sales. A CASP passported into another Member State can serve its residents remotely. Outside the EEA, reverse solicitation is possible but narrow: any active targeting of EU users, including SEO and paid marketing, breaks the defence.
ESMA and the EBA also supervise the market-abuse regime for crypto-assets admitted to trading. Insider-dealing, unlawful disclosure and market manipulation rules apply to any trading on a CASP platform.
Pick the CASP profile that matches your product
The ten services map onto a handful of product archetypes. Picking the right combination up front avoids a mid-application scope change, which almost always adds six months.
Retail wallet and on-ramp
Services: custody, exchange for funds, execution, transfer.
Class 2 capital, full AML and Travel Rule stack, consumer-facing white papers, retail suitability warnings. Typical jurisdictions: Malta, Netherlands, Lithuania.
Spot exchange or trading platform
Services: operation of a trading platform, custody, exchange, execution, reception and transmission.
Class 3 capital, pre- and post-trade transparency, market-abuse surveillance, listing-and-delisting policy, halt protocol. Typical jurisdictions: France, Germany, Malta.
Institutional custodian
Services: custody and administration, transfer.
Class 2 capital, deep cyber and operational-risk framework, segregated wallets, often paired with a MiFID licence for tokenised securities. Typical jurisdictions: Germany, Luxembourg, Switzerland (for non-EU mirror).
Advisor or portfolio manager
Services: advice, portfolio management, reception and transmission.
Class 1 capital, suitability and appropriateness assessments, inducement rules close to MiFID, strong record-keeping. Typical jurisdictions: France, Ireland, Cyprus.
Crypto-fiat on-off ramp (EMT custody)
Services: custody and transfer of e-money tokens.
Dual licence: CASP Class 2 + PSD2 safeguarding. Expect an EMI or PI alongside the CASP. Typical jurisdictions: Lithuania, Ireland, Malta.
Bank or EMI adding crypto
Services: add one or more CASP services to an existing EU licence.
Article 60 simplified notification. No fresh authorisation. 40 working days for the NCA to object. The lowest-cost route to regulated EU crypto activity.
Most neobrokers and crypto apps end up in Class 2 or Class 3. Pure advisory or introducer models land in Class 1. Add services later only after the initial authorisation: variations of licence are faster than full applications but still take months.
From national VASP to MiCA CASP: the transition playbook
Firms moving from a pre-MiCA national registration face a compressed timeline. Waiting for the transitional window to expire before acting has been the single biggest cause of service interruption in 2025 and 2026.
- Map the scope delta. Compare current national activity with the ten CASP services. Anything outside the national scope is new licensed activity under MiCA, not a renewal.
- Upgrade governance and compliance. Most national VASP regimes were AML-driven. MiCA adds conduct, market-abuse, ICT risk, outsourcing, suitability, best-execution and client-asset obligations. Policies and procedures need a full rewrite rather than a repaper.
- Top up capital. Firms that operated on nominal national capital must raise to the Class 1/2/3 floor and pre-fund a fixed-overhead buffer covering three months of run-rate spend.
- Rebuild the tech evidence pack. NCAs ask for architecture diagrams, key-management policies, penetration-test reports, data-residency statements and DORA alignment from day one of the substantive review. If your evidence is spread across Confluence, Jira and Slack, budget four to six weeks of assembly.
- File early and iterate. NCAs prioritise files that arrived in the first two quarters of the window. Late filings face queueing risk that pushes approval past the backstop.
- Plan the wind-down path. If the transitional deadline is not realistic, the fallback is a controlled withdrawal of EU activity, migration of client assets to a licensed CASP, and transparent customer communication. Continuing to serve EU clients after the national backstop creates criminal liability in several Member States.
The firms that navigated the transition successfully (OKX Europe, Bitpanda Asset Management, MoonPay Europe, bitFlyer Europe, ZBX, Crypto.com Malta) all filed in the first half of their national window with pre-MiCA infrastructure already running, not a paper project.
Ship your CASP product with Crassula's MiCA-ready platform
A CASP authorisation is the legal wrapper. The NCA will not grant it without evidence of the technology behind it: a working ledger, segregated wallet architecture, documented custody model, live KYC and Travel Rule, market-abuse surveillance, incident handling, reporting pipelines and a customer-facing product. Building that stack from scratch typically costs 18 months and a team of 30. Crassula ships it as a white-label, MiCA-ready core so founders, compliance officers and product teams can put real screenshots and architecture diagrams into the authorisation file on day one, not after launch.
The platform behind our White Label Crypto Banking, crypto exchange software, crypto wallet and crypto payment gateway products covers every operational requirement a first-wave NCA reviewer asks about.
Multi-asset ledger and wallets
Double-entry ledger, segregated client wallets, hot and cold storage, MPC key management, evidence pack the NCA expects for Class 2 custody.
KYC, AML and Travel Rule
Onboarding, sanctions and PEP screening, monitoring, Travel Rule messaging live at go-live under Regulation 2023/1113.
Exchange, RFQ and FX
Matching engine or RFQ, aggregated liquidity, FX rails, market-abuse surveillance modelled on MAR, pre- and post-trade transparency.
NCA-ready reporting
MiCA own-funds and transaction reports, reconciliation, audit trail, DORA-aligned ICT and incident handling out of the box.
For founders preparing a first filing
Put a real product in the authorisation file. Customisable web UI, mobile apps and admin back office let you run a pilot with regulators, launch partners and beta users while the file is in review.
For pre-MiCA VASPs transitioning
Plug the gaps the NCA will flag: documented custody, market-abuse surveillance, Travel Rule, suitability workflows and DORA evidence. Migrate client balances and history without downtime.
For banks, EMIs and MiFID firms
Use the Article 60 simplified notification and bolt a crypto module onto your existing licence. Crassula integrates with your core banking so custody, trading and fiat rails run in a single stack.
Teams launching with Crassula typically go live in 3 to 6 months after the CASP licence is granted, versus 12 to 18 months for an in-house build. Whether you are a crypto exchange, a custodian, a wallet app, a neobroker or a bank adding crypto, we map the platform to the exact services in your Class 1, 2 or 3 authorisation.
FAQ
It is the EU authorisation granted under Regulation (EU) 2023/1114 that lets a firm provide regulated crypto-asset services (custody, trading, exchange, execution, advice, portfolio management, placing, reception and transmission, transfers) anywhere in the EEA with a home-state licence and a single passport.
Title V on CASPs started to apply on 30 December 2024. Titles III and IV on ARTs and EMTs applied earlier, from 30 June 2024. The EU-wide backstop for transitional firms is 1 July 2026, but many Member States (Germany, Ireland, Austria, Netherlands, Lithuania, Finland, Latvia, Hungary) already closed their windows in 2025 or January 2026.
Realistic first-year all-in for a credible Class 2 or Class 3 CASP is EUR 350,000 to EUR 900,000, of which EUR 125,000 to EUR 150,000 is paid-up capital that stays in the entity. Malta runs EUR 200,000 to EUR 300,000 on the lean end with a white-label technology stack. Germany, France and Ireland run two to three times the Malta figure.
The statutory clock is 25 working days for completeness plus 40 working days for the decision, extendable by 20 working days. Real-world timelines during 2025 ran from 4 months (Malta, Lithuania) to 12 months (Germany, Ireland) depending on regulator, file quality and substance.
Around 60 CASPs are on the ESMA register as of early 2026, concentrated in Germany (18), the Netherlands (14), France (6) and Malta (6). Named authorised firms include Crypto.com (Foris DAX MT), OKX (Okcoin Europe), ZBX (Zillion Bits), Bitpanda Asset Management, MoonPay Europe and bitFlyer Europe.
Weak AML/CFT without evidence of enforcement, unclear governance or fit-and-proper gaps, unverified capital, no genuine EU substance (virtual addresses, nominee directors), and vague business models. Operational mistakes that kill files: slow RFI responses and last-minute filings at the end of a grandfathering window.
Possibly yes. Non-custodial design removes the custody trigger but leaves exchange, execution, trading-platform operation, advice and portfolio-management triggers intact. MiCA is activity-based, not architecture-based. Run the five-step scope test on every service you offer.
Reverse solicitation exists but is genuinely narrow. An EU user must initiate contact for a specific service at their own exclusive initiative. Any marketing, SEO, referrals or paid acquisition aimed at EU users breaks the defence. ESMA has already opened enforcement on firms that overclaimed reverse solicitation.
A CASP providing custody or transfer services for e-money tokens (MiCA EMTs) must comply with both MiCA Article 67/Annex IV capital and PSD2 Article 7 initial capital, because EMT custody is treated as a payment service. In practice you need a MiCA CASP plus either an EMI licence or a compatible passport into the home state.
Existing MiFID investment firms, credit institutions, EMIs, PIs, UCITS managers and AIFMs can add equivalent crypto services with a notification instead of a full CASP authorisation. The NCA has 40 working days to object. No new capital beyond the home licence's requirement. Fastest route to regulated EU crypto activity.