EU MiCA License and CASP Authorization for Crypto Businesses

The Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114, replaced the patchwork of national crypto rules with one framework covering all 27 EU states plus Iceland, Liechtenstein and Norway. ECOVIS ProventusLaw guides crypto businesses through the authorization process from first assessment to license.

What Is a MiCA License?

A MiCA license is the authorization that a Crypto-Asset Service Provider (CASP) needs to operate in the European Union. A firm authorized in one member state can provide its services across the entire EU and European Economic Area (EEA) without applying separately in each country.

Who Needs a MiCA License?

Any business that provides one or more of the ten regulated crypto-asset services on a professional basis within the EU needs a CASP authorization. In practical terms: if a business holds client private keys, operates a matching engine, or handles the conversion between crypto-assets and fiat currency, it falls within MiCA’s scope.

How ECOVIS Helps You Get a MiCA License

ECOVIS ProventusLaw has completed more than 40 end-to-end FinTech licensing projects and has advised crypto and blockchain businesses since 2014. Our FinTech team is top-ranked by international legal directories: Chambers & Partners, IFLR1000 and The Legal 500.

We take crypto-asset businesses through the full authorization process:

  • MiCA readiness assessment and gap analysis
  • Choosing the right jurisdiction
  • CASP authorization application, fully prepared and submitted
  • Token classification (ART, EMT or other) and legal opinions
  • White paper drafting and regulator submission
  • AML and KYC policies and internal procedures
  • DORA and operational resilience frameworks
  • Local substance setup: office, director, management
  • Ongoing compliance and regulatory support

Contact us for a free initial consultation.

Crypto-Asset Service Providers (CASPs): Authorization

CASPs must hold authorization to operate in the EU. The ten regulated crypto-asset services under MiCA are:

  • Providing custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders for crypto-assets on behalf of clients
  • Providing advice on crypto-assets
  • Providing portfolio management on crypto-assets
  • Providing transfer services for crypto-assets on behalf of clients

The services a firm applies for determine its capital class, its reporting obligations and the intensity of ongoing supervision.

Capital Requirements for CASPs

MiCA Article 67 sets EU-wide minimum capital requirements. These are the same in every member state. Own funds must at all times be the higher of the fixed floor for the applicable service class or one quarter of the previous year’s fixed overheads.

  • Class 1 (EUR 50,000): advice, portfolio management, reception and transmission of orders, execution of orders, placing, transfer services.
  • Class 2 (EUR 125,000): custody and administration, exchange for funds, exchange for other crypto-assets.
  • Class 3 (EUR 150,000): operation of a trading platform.

A firm providing services across multiple classes must meet the highest applicable floor. Capital must be maintained continuously, not just at the point of application.

Passporting a MiCA License

Once authorized in one EU member state, a CASP can operate across all 30 EEA countries. Under MiCA Article 65, the home regulator notifies host state authorities. Host states do not need to approve the expansion. The right to serve clients in each additional country flows directly from the home authorization.

How Long Does a MiCA License Take?

The statutory review runs 25 working days for the completeness check and 40 working days for the substantive assessment. In practice, timelines vary by regulator. Latvia is currently the fastest route, with the Bank of Latvia indicating around three months average.

Requirements for Authorized CASPs

AML and KYC compliance. All authorized CASPs must implement identity verification for every customer, maintain ongoing transaction monitoring, and report suspicious transactions to the national financial intelligence unit.

Travel Rule. The Transfer of Funds Regulation (Regulation (EU) 2023/1113) requires CASPs to collect and transmit originator and beneficiary information for every qualifying crypto-asset transfer. Unlike traditional wire transfers, there is no minimum amount threshold. Transfers involving self-hosted wallets carry additional verification requirements.

Risk management. CASPs must maintain documented risk management, conflicts-of-interest policies, outsourcing controls, and business continuity and wind-down planning.

Operational resilience. Since 17 January 2025, CASPs have been subject to the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554). This requires a functioning IT risk management framework, incident classification and reporting, resilience testing, and oversight of critical technology suppliers from the date of authorization.

Governance and substance. Management must meet fit-and-proper requirements covering competence, reputation and financial soundness. The company needs a registered office in the EU member state where it provides services, a place of effective management in the EU, and at least one EU-resident director. The applicant must demonstrate genuine substance and effective management in the authorizing member state. A mailbox-only structure is unlikely to satisfy supervisory expectations.

Ownership screening. Beneficial owners, shareholders and directors are screened for sanctions exposure. EU sanctions law prohibits Russian nationals and residents of Russia, and Belarusian nationals and residents, from owning, controlling, or holding governing-body positions in an EU crypto-asset service provider. The restrictions do not apply to persons who also hold EU, EEA or Swiss nationality, or a valid residence permit in one of those states.

Conduct and disclosure. CASPs must act in clients’ best interests, communicate clearly and fairly, maintain a complaints-handling process, and comply with service-specific rules covering order execution, custody agreements and trading platform operations.

Segregation of client assets. Client crypto-assets and funds must be kept separate from the firm’s own assets, held so that client rights are protected in insolvency, and not re-used without the client’s explicit consent. Custody arrangements, key management and storage architecture are reviewed at authorization and remain under ongoing supervision.

When Is a Payment License Also Needed?

A MiCA CASP authorization covers crypto-asset services, but not fiat payment processing. If a CASP handles euro or other fiat currency flows as part of its operations (for example, receiving client deposits in euros, processing fiat withdrawals, or facilitating euro-denominated settlements), those activities may fall under the Payment Services Directive (PSD2) and require a separate Payment Institution or Electronic Money Institution license.

This is a common issue in practice. Many crypto businesses that exchange crypto for fiat need both a CASP authorization for the crypto side and a payment or e-money license for the fiat side.

Two Sides of MiCA: Issuers and Service Providers

MiCA applies to two different roles, and it helps to know which one you are.

On the supply side are the businesses that create and offer tokens. For ordinary tokens, this is the offeror or the party seeking to list the token for trading, who does not have to be a formal “issuer.” For ARTs and EMTs, this is the issuer, who must meet stricter conditions before offering the token.

On the service side are Crypto-Asset Service Providers (CASPs), businesses that handle crypto on behalf of clients rather than creating it. This is the group that needs a CASP license, covered above.l

Token Types Under MiCA and Who Can Issue Them

MiCA divides crypto-assets into three types. Each type has its own rules on who may issue it and how its white paper, the token’s official disclosure document, is handled.

Asset-referenced tokens (ARTs) hold their value steady by tracking something other than a single currency, for example a mix of currencies, a commodity such as gold, or a basket of assets. They are not electronic money. An ART may be issued either by a company based in the European Union licensed by its national regulator, or by a credit institution (a licensed bank) that meets the conditions in the regulation. The regulator must approve the white paper before the token goes on sale.

A lighter rule applies to small or private ART offerings. Authorization is not required where, over 12 months, the average outstanding value of the token, calculated at the end of each calendar day, never exceeds EUR 5 million and the issuer is not linked to a network of other exempt issuers. The same applies where the offer is addressed solely to qualified investors and the token can be held only by such investors. A white paper is still required and must be notified to the competent authority. Other issuer obligations may still apply.

Electronic money tokens (EMTs) hold their value steady by tracking one official currency, such as the euro or the dollar. The law treats them as a digital form of that money. An EMT may only be issued by a credit institution or a licensed electronic money institution. No separate crypto license is needed, but the issuer must send its white paper to the regulator before launch. The regulator is informed. It does not approve.

All other crypto-assets make up the third, catch-all type, covering utility tokens and most ordinary tokens. Any company may issue them. No license is needed. The issuer prepares a white paper, sends it to the regulator, and publishes it before the sale begins.

Whatever the type, the white paper must explain the same core things: who is issuing the token and running the project, the terms of the offer, what the token is and what rights come with it, the technology behind it, the risks involved, and the environmental impact of the system that keeps the token running.

What Is Outside MiCA, and What Is Only Partly Exempt

Two situations look similar but are not the same, and the difference matters.

Completely outside MiCA. Some assets fall under other financial laws instead: anything that already counts as a financial instrument, a bank deposit, a fund, insurance, or a pension product. Genuinely one-of-a-kind digital collectibles, often called non-fungible tokens (NFTs), are also outside, but only if they are truly unique in substance. Issuing thousands of near-identical items, or splitting one collectible into tradable fractions, makes them ordinary tokens again. Closed systems such as shop loyalty points sit outside too, as do services run with no middleman and certain public bodies such as central banks.

Inside MiCA, but excused from the white paper. Here the token is still covered by MiCA and the service rules can still apply. Only the white paper is waived. This covers tokens given away for free (though it is not “free” if you collect the person’s data or charge any fee), tokens created automatically as a reward for running the network, utility tokens for a product that already works, and small or private sales: fewer than 150 buyers per country, under one million euros raised in a year, or qualified investors only.

This exemption disappears the moment the token is listed for trading.

Need help classifying a token or preparing a white paper? See our MiCA compliance and token services.

Our Recent MiCA Licensing and Authorization Cases

  • Trek Technologies SIA (Backpack EU). Guided the firm to a Bank of Latvia crypto-asset license covering custody, both exchange types, order execution and transfers, including the MiCA/PSD2 line on e-money tokens and a five-jurisdiction group folded into one EU model.
  • Trek Labs, UAB (Backpack Token). Took the Backpack token white paper from classification through to notification at the Bank of Lithuania, clearing the way for an EU-wide offering.
  • Match Networks Ltd. Secured one of the EU’s first MiCA white paper approvals, picking Ireland as the filing route and steering the token through Central Bank review to a regulated EU-wide offering.
  • Proof Space Pte. Ltd. Cleared one of the Bank of Lithuania’s first MiCA white paper notifications for admission to trading, opening the token to EU markets.
  • Aethir Network Foundation Company. Cleared a technically complex token through Central Bank of Ireland white paper approval with no amendments requested, opening EU-wide offering and distribution.