Cryptoasset & Digital Asset Licence - European Union (MiCA)

Crypto-asset service providers are authorised by a national competent authority under MiCA, not by a single EU regulator.

Get in Touch

Whether you need licensing support, compliance advice or regulatory strategy, our team is ready to help. Free initial consultation - no obligation.

Get Expert Advice

Free initial consultation. No obligation.

The short answer

Regulation (EU) 2023/1114 on markets in crypto-assets creates a single authorisation framework for crypto-asset service providers across the European Union. There is no central EU licensing authority. A firm applies to the national competent authority of the member state where it has its registered office, and the authorisation then confers the right to provide the authorised services throughout the Union by notification.

The regulation covers the offering and admission to trading of crypto-assets, asset-referenced tokens and e-money tokens, and the provision of crypto-asset services. It does not cover crypto-assets that qualify as financial instruments, which remain within MiFID II, or as deposits or e-money issued under existing frameworks.

Prudential requirements are calibrated to the services provided, governance and fit and proper standards apply to the management body and qualifying shareholders, and the anti-money laundering regime applies in parallel through national implementation of the EU AML framework.

Key facts

LegislationRegulation (EU) 2023/1114 (MiCA), with delegated and implementing acts and EBA and ESMA technical standards
Authorising bodyThe national competent authority of the member state of the registered office. There is no single EU regulator
PassportingCross-border provision across the Union following notification by the home authority
Prudential floorMinimum own funds set by service class under Annex IV, from EUR 50,000 to EUR 150,000, or one quarter of the previous year's fixed overheads if higher
SubstanceRegistered office in the Union, effective management in the Union, and at least one director resident in the Union
AMLApplies in parallel under the EU anti-money laundering framework as implemented nationally
Transitional arrangementsMember state grandfathering periods differ and several have now expired. Confirm the position in the specific member state

Which services require CASP authorisation

The application defines the exact service perimeter. Adding a service later is a variation of the authorisation, so the scope should be set against the two-year business plan rather than the launch product.

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds, and exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders for crypto-assets on behalf of clients
  • Providing advice on crypto-assets and providing portfolio management of crypto-assets
  • Providing transfer services for crypto-assets on behalf of clients

Choosing the member state

Because authorisation is national but the effect is Union-wide, the choice of member state matters commercially. Relevant factors are the competent authority's throughput and published expectations, the language of the process, availability of banking, and the depth of the local talent market for the governance roles the regulation requires.

The choice must be genuine. The registered office, the effective management and the substance must all sit in the chosen member state, and competent authorities test that. A letterbox arrangement in a fast jurisdiction is a refusal risk rather than a shortcut.

What the application has to establish

  • A programme of operations covering each service, its operating model and its client base
  • Governance arrangements, an organisational chart and the suitability of the management body and qualifying shareholders
  • Prudential safeguards: own funds or insurance meeting the Annex IV requirement for the services concerned
  • Custody and segregation arrangements, and the custody policy where client crypto-assets are held
  • ICT risk management consistent with the digital operational resilience framework
  • Complaints handling, conflicts of interest, market abuse detection where a trading platform is operated, and a wind-down plan
  • An anti-money laundering framework meeting the requirements of the member state of authorisation, including the transfer of funds information requirements

Ongoing obligations

MiCA is a conduct and prudential regime with continuing obligations, not a one-off registration. Authorised providers report to the competent authority, maintain own funds against the applicable floor, keep client crypto-assets segregated and account for them, disclose complaints handling and conflicts, and notify material changes including changes to the management body and to qualifying holdings.

For firms with a UK footprint, MiCA authorisation does not extend into the United Kingdom, and a UK cryptoasset registration does not extend into the Union. The two regimes are run in parallel.

Frequently Asked Questions

No. MiCA is a single rulebook, but authorisation is granted by the national competent authority of the member state where the firm has its registered office. That authorisation is then effective across the Union through the notification procedure.

Minimum own funds are set by service class in Annex IV to MiCA and range from EUR 50,000 to EUR 150,000, or one quarter of the preceding year's fixed overheads if that is higher. Insurance can substitute in the circumstances the regulation permits.

Member states applied different grandfathering periods for firms already operating under national regimes, and several have expired. The position must be confirmed in the specific member state rather than assumed from the regulation alone.

No. Crypto-assets that qualify as financial instruments remain within MiFID II, and deposits and existing e-money frameworks are also excluded. Classifying the token correctly is the first step of any EU strategy.

No. The United Kingdom is outside the Union framework and operates its own cryptoasset registration regime, with a broader authorisation regime being introduced. Firms serving both markets need both permissions.