Skip to content
Insights

Reference · MiCAR

CASP authorisation under MiCAR

The question most teams actually have is not how to get authorised. It is whether they need to be.

Regulation
(EU) 2023/1114
Authority (DE)
BaFin
CASP rules apply
30 December 2024
Scope
EU-wide, passportable

What CASP actually means

A Crypto-Asset Service Provider is not a category you fall into by touching crypto. It is defined by service. MiCAR enumerates a closed list: custody and administration on behalf of clients, operating a trading platform, exchanging crypto for funds or for other crypto, executing orders, placing crypto-assets, receiving and transmitting orders, advice, portfolio management, and transfer services on behalf of clients. Provide one of those in the EU on a professional basis and you need authorisation. Provide none of them and the label does not apply, however much crypto your product touches.

The distinction that decides it: custody

In practice one question separates most products: do you hold the keys? Custody and administration on behalf of clients means controlling the means of access to someone else's assets. Software that generates and stores a key on the user's own device, where the provider cannot move funds and cannot restore access, is not holding anything on the user's behalf. Our own consumer product is built that way, which is why it is not a CASP — the fiat purchase inside it is routed through a licensed partner that is one. That structure is a deliberate consequence of the regulation, not a workaround of it.

CASP is not the only regime

Issuing a token is governed separately from providing a service. MiCAR splits issuance into e-money tokens, which reference a single official currency, and asset-referenced tokens, which reference anything else or a basket. Both carry their own authorisation and reserve requirements, and both applied from 30 June 2024, six months before the CASP rules. A team that issues a euro stablecoin and also runs an exchange is looking at two separate regimes, not one.

What authorisation costs you, structurally

The capital requirement is the smallest part and scales with the service class: the lowest tier applies to advice and order transmission, the middle to custody and exchange, the highest to operating a trading platform. Minimum own funds are the floor, not the number — you hold the higher of that floor or a quarter of the prior year's fixed overheads. The parts that take longer are governance: fit-and-proper management, a complaints procedure, segregation of client assets from your own, ICT resilience, and a business continuity plan you can actually evidence. Firms usually underestimate the last three.

Checking who is actually authorised

Authorisation is granted nationally and passports across the EU, which means a firm licensed in one member state can serve all of them — and means the claim "MiCA licensed" on a website is worth exactly nothing until you check it against the register ESMA maintains. We built BlockchainView because we needed that lookup ourselves: every authorised CASP, EMT issuer and ART issuer in one place, rather than in twenty-seven national lists. If you are doing diligence on a counterparty, start there rather than with their marketing.

Transitional periods end unevenly

MiCAR let member states grandfather firms that were already operating under national rules, for up to eighteen months. Crucially, states chose different lengths. A provider legally serving customers in one country under a transitional regime may already be unauthorised in another. If your counterparty's status matters to you, the question is not whether they are grandfathered but where, and until when.

Common questions

Does a non-custodial wallet need a CASP authorisation?

Providing wallet software alone is not one of the enumerated services, because the provider is not holding or administering assets on behalf of a client. The moment the product also exchanges crypto for funds, executes orders, or takes control of keys, that changes — and most consumer wallets add exactly those features through partners. The safe reading is that the software may be outside scope while a specific feature inside it is not.

Is a MiCA licence the same as a CASP authorisation?

"MiCA licence" is marketing shorthand, not a term the regulation uses. MiCAR grants authorisation for a defined set of services, or for issuing a specific token type. Asking which services a firm is authorised for is a more useful question than asking whether it is licensed, because the answer is a list rather than a yes.

Do we need an entity inside the EU?

Yes. Authorisation requires a registered office in a member state and management actually located there. Serving EU customers from outside without authorisation is what the reverse-solicitation exemption is sometimes claimed for, and supervisors have been explicit that they read that exemption narrowly.

How long does authorisation take?

The statutory assessment clock is measured in months once the file is complete, and completeness is where time is actually lost. The governance evidence — policies, continuity plans, segregation arrangements — is what firms are still writing when they thought they were submitting. Budget for the preparation, not the review.

Does MiCAR cover DeFi and NFTs?

Only partly, and the boundary is unsettled. Services provided in a fully decentralised manner without any intermediary are outside the regulation's stated scope, but very little in practice is fully decentralised in that sense — a front-end, a fee switch or a governance key can each pull a protocol back in. Unique, non-fungible tokens are excluded, but issuing a large series of near-identical ones is treated as fungible in substance rather than by label.

Where does DORA fit in?

Alongside, not underneath. DORA sets ICT risk and third-party oversight requirements for financial entities, and authorised CASPs are in its scope. Teams that treat MiCAR authorisation as the finish line usually meet DORA for the first time immediately afterwards, which is an expensive order to do it in.

This is not legal advice

We are engineers who build regulated products, not a law firm. This page reflects how we read the regulation for our own work. Where the answer decides whether you can operate, take it to counsel — and take the specific service list with you, because that is what the answer turns on.

Building something that falls under this?

We build wallets, settlement flows and dashboards for teams operating under European rules, and we audit the protocols underneath them. Two sentences about what you are building is enough to start.