
In This Guide
- Map the activity before choosing a licence
- Build an application the supervisor can test
- Passport the authorised perimeter
- Separate CASP, stablecoin, and disclosure rules
- Protect client assets through the full operating chain
- Treat reverse solicitation as a narrow exception
- Work a launch from product map to controls
- Frequently Asked Questions
- Sources Used in This Guide
Map the activity before choosing a licence
MiCA does not license "crypto companies" as a single category. It regulates defined crypto-asset services, token offers and admissions to trading, and the issuance of asset-referenced tokens (ARTs) and e-money tokens (EMTs). A product map comes first. The binding starting point is Regulation (EU) 2023/1114, read with its delegated acts and the applicable national process.
Regulatory position checked to 23 July 2026. "Binding law" below means MiCA or another directly applicable EU regulation. "Guidance" means regulator expectations or interpretation. A "practical inference" is an implementation conclusion, not a rule quoted from legislation.
| Product activity | MiCA service question | Evidence to map |
|---|---|---|
| Control client tokens or private keys | Custody and administration | Key control, recovery rights, wallet terms, insolvency treatment |
| Bring together multiple third-party buying and selling interests | Operation of a trading platform | Matching rules, order book, admission rules, settlement |
| Buy or sell to clients using the firm's capital | Exchange for funds or other crypto-assets | Principal capacity, pricing method, balance-sheet exposure |
| Receive and route orders, or conclude transactions for clients | Reception and transmission, or execution of orders | Contractual role, routing logic, venue and best-execution process |
| Give personalised recommendations or manage a mandate | Advice or portfolio management | Personalisation, discretion, suitability process, staff competence |
| Move tokens between addresses for a client | Transfer service | Who instructs, who signs, and whether the firm acts for the client |
| Market tokens for an offeror | Placing of crypto-assets | Issuer mandate, compensation, target purchasers |
| Publish software without an intermediary | Fact-sensitive perimeter analysis | Control, fees, governance, upgrades, interface and client relationship |

MiCA lists ten services and defines each one. Labels such as "broker," "protocol," "non-custodial," or "technology provider" do not decide the result. Fully decentralised services without an intermediary can fall outside MiCA, but a decentralisation claim does not answer who controls the interface, routes orders, holds keys, charges clients, or changes the system.
Also test whether the token is a financial instrument or otherwise covered by existing EU financial-services law. MiCA generally targets crypto-assets not already regulated by that law, a boundary reflected in ESMA's classification work. Record the legal conclusion for every service-token pair; one platform can have different answers for different assets and functions.
Build an application the supervisor can test
Under binding MiCA Articles 59 and 62, a new applicant normally applies to the national competent authority (NCA) of its home Member State. It needs an EU registered office, effective management in the Union, at least one EU-resident director, and real activity in the home state. Certain already-regulated financial entities can use the Article 60 notification route only for the services MiCA permits them to provide; that is not a general exemption.
The authorization workflow is:
- Classify every token and service, then freeze the requested scope.
- Select the home Member State based on actual management and operations, not a mailbox.
- Meet the NCA before filing and confirm its portal, forms, language, fees, and local fit-and-proper process.
- Submit the Article 62 package: programme of operations, marketing plan, governance, owners, prudential proof, AML risk controls, ICT and security, business continuity, segregation, complaints, and service-specific policies.
- Answer completeness questions with controlled versions and a single evidence index.
- Complete the merits review, register the authorization, then file any cross-border notification.

The statutory clock is useful but not a launch date. The NCA acknowledges receipt within five working days, checks completeness within 25 working days, and decides within 40 working days after the file is complete. A permitted information request can suspend that merits period for up to 20 working days. Missing evidence before completeness and operational remediation outside the formal clock can extend the real process.
| Authorised service class | Permanent minimum | Typical evidence focus |
|---|---|---|
| Class 1: execution, placing, transfer, order reception/transmission, advice, portfolio management | EUR 50,000 | Client journey, competence, execution, suitability and transfer controls |
| Class 2: Class 1 plus custody or exchange | EUR 125,000 | Key management, segregation, pricing, safeguarding and loss response |
| Class 3: Class 2 plus a trading platform | EUR 150,000 | Admission, market surveillance, order books, resilience and conflicts |
The binding prudential requirement is the higher of the Annex IV minimum and one quarter of the previous year's fixed overheads, reviewed annually. A new firm uses its projected first 12 months. Safeguards can take permitted forms under Article 67; confirm the proposed mix with the NCA.
Management must be reputable, collectively knowledgeable and experienced, and able to commit enough time. Qualifying holders are also assessed. ESMA's supervisory briefing summary is guidance, not new legislation, but it tells applicants what NCAs are expected to test: autonomous EU operations, sufficient in-country staff, controlled outsourcing, and executive knowledge of crypto markets. A thin local board supervising an offshore operating company is therefore a poor factual fit.
Passport the authorised perimeter
A CASP authorization can support services across the Union. Article 65 requires the firm to tell its home NCA the host states, services, planned start date, and non-MiCA activities. The home NCA has ten working days to send the notice to host-state contact points, ESMA, and EBA. The CASP can start when informed of that transmission or, at the latest, on the fifteenth calendar day after submission.

The passport covers only the crypto-asset services named in the authorization. It does not authorize payment services, token issuance, lending, securities business, or any other activity outside that perimeter. Nor does it erase host-state powers. MiCA itself gives the authority where marketing is disseminated a role in policing communications, while consumer, data, sanctions, employment, and tax rules can attach on their own terms. The safe implementation rule is to keep a host-state obligations matrix even when MiCA does not require a local branch.
Grandfathering is no longer a market-entry strategy at this article's cutoff. Binding Article 143 allowed eligible pre-MiCA providers to continue only until authorization or refusal, and never beyond 1 July 2026; Member States could shorten or disapply that period. Official examples show the former differences: France ran its transition to 1 July 2026, while Ireland used a 12-month period ending 30 December 2025. National registrations did not create an EU passport during those transitions.
The home NCA remains the first operating touchpoint. The AMF's MiCA page identifies its French CASP route and the separate ACPR role for stablecoin issuers. The Central Bank of Ireland's MiCAR hub publishes its authorization, notification, AML, market-abuse and own-funds materials. Use the current NCA channel, not an application pack copied from another Member State.
Separate CASP, stablecoin, and disclosure rules
A CASP permission answers who may provide a service. It does not authorize the firm to issue a stablecoin. MiCA's ART and EMT regimes applied before the general CASP regime, as the European Commission's crypto-assets overview explains.
| Issue | Asset-referenced token | E-money token |
|---|---|---|
| Reference | Another value, right, or combination, including currencies | One official currency |
| Issuer gate | EU-established authorised issuer or qualifying credit institution | Credit institution or electronic money institution |
| White paper | Approved as part of the applicable issuer route | Notified to the NCA and published |
| Core holder protection | Reserve, governance, own funds, custody and redemption duties | Claim on issuer, issue and redemption at par, e-money safeguarding |
| Interest | No interest linked to holding the ART | No interest linked to holding the EMT |

The EBA's ART and EMT implementation hub collects the standards on authorization, reserve assets, redemption, governance and reporting. Significant tokens can bring additional requirements and EBA supervision. A CASP that lists, exchanges, transfers or safeguards a stablecoin still needs its service controls; the token's issuer status is a separate due-diligence item.
For a public offer or admission to trading of a crypto-asset other than an ART or EMT, MiCA generally requires a white paper to be drawn up, notified, published and kept current, subject to stated exemptions. The NCA does not pre-approve these Title II white papers. MiCA requires notification at least 20 working days before publication, together with the classification explanation and host-state list. The current ESMA MiCA register expressly warns that listed non-ART/EMT white papers have not been reviewed or approved.
Marketing must be identifiable, fair, clear, not misleading, and consistent with the white paper. Where a white paper is required, marketing cannot precede its publication. ART and EMT communications have their own Title III and IV requirements. A compliant white paper is disclosure, not a licence, and it does not cure an unauthorised service.
Protect client assets through the full operating chain
Client protection has to survive insolvency, incidents, vendors and daily reconciliation. Under MiCA Articles 70 and 75, a custodian needs a written client agreement, a per-client position register, a custody policy, operational and legal segregation, quarterly statements, return procedures, and controls for rights created by ledger events. Liability applies to loss attributable to the custodian, capped at the lost asset's market value when the loss occurred.
Client funds other than EMTs must be placed with a credit institution or central bank by the end of the next business day and held in separately identifiable accounts. A custody provider that sub-custodies to another provider may use only a MiCA-authorised custodian and must tell clients. Complaints must be free, prompt, fair, recorded and supported by a published procedure and template.
Outsourcing does not move the regulatory obligation. Binding Article 73 keeps the CASP fully responsible and requires supervisory access, retained expertise, direct information access, EU data-protection standards, written termination rights, contingency plans and exit strategies. The practical inference is to maintain an outsourcing register that links each vendor to data, keys, service levels, incident escalation, concentration risk and a tested exit.

MiCA authorization also does not replace AML or sanctions compliance. Article 62 requires the applicant's AML risk controls, and the NCA can consult AML authorities. The binding EU Transfer of Funds Regulation requires CASPs to obtain and transmit originator and beneficiary information before, simultaneously with, or concurrently with a covered crypto transfer. The beneficiary CASP needs risk-based procedures to request information or reject, return or suspend incomplete transfers.
The travel rule covers transfers to or from self-hosted addresses when a CASP is involved. Above EUR 1,000, the relevant CASP must take adequate measures to assess whether its client owns or controls the address. That threshold is not a general exemption below EUR 1,000. Record retention, suspicious-transaction reporting, sanctions screening, data protection and national AML implementation remain separate control streams.
Treat reverse solicitation as a narrow exception
A third-country firm has no general MiCA passport or equivalence route. Binding Article 61 removes the authorization requirement only where an EU client initiates the specific service at the client's own exclusive initiative. Solicitation by the firm, an agent, or a closely linked entity through any communication channel defeats the exception. A contract clause saying otherwise has no effect.
The firm also cannot use that relationship to market new types of crypto-assets or services. ESMA's final guidelines are Level 3 guidance, and ESMA has described the exception as very narrowly framed. It is an evidence-based exception for an individual client interaction, not a business model for the EU.
Consider an offshore exchange that geofences paid EU ads but sponsors an EU-language podcast, pays affiliates for EU sign-ups, and lets those users click an "I approached you" box. Those facts show solicitation; the checkbox does not repair them. If an existing EU customer independently asks for one service, the firm must preserve the inbound request, pre-request marketing history, scope and timing, and avoid promoting a new token or service. A third-country group planning repeat EU revenue usually needs an authorised EU operator with its own substance and controls.
Work a launch from product map to controls
NovaX is a hypothetical US group planning an EU app with a spot order book, principal exchange, hosted wallets and token transfers. It wants to list a euro EMT issued by an unrelated bank. It will use a cloud provider and a specialist wallet vendor.
| Launch decision | Regulatory result | Required evidence |
|---|---|---|
| Order book, exchange, custody and transfers | Class 3 CASP scope; minimum EUR 150,000 or one quarter of fixed overheads, whichever is higher | Service map, platform rules, pricing, custody, transfer and market-abuse controls |
| Unrelated euro EMT | NovaX is not the issuer merely because it lists the token; CASP and token due diligence still apply | Issuer authorization, white paper, register status, redemption and restriction process |
| Cloud and wallet vendors | Outsourcing is permitted but NovaX remains responsible | Risk assessment, audit and access rights, EU data terms, contingency and exit tests |
| EU-wide launch | Home-state authorization first, then Article 65 notifications | Substantive EU management, NCA decision, host list and launch controls |
| Pre-launch campaign | Cannot rely on reverse solicitation for resulting customers | Marketing approvals, territory controls, white-paper links and retained campaigns |
NovaX should not choose its home state by the shortest rumoured queue. ESMA guidance and national practice test whether the EU entity can run the authorised business. The Central Bank of Ireland's industry briefing, for example, stresses substance, governance, risk frameworks, financial resilience, recoverability and client interests. Those are supervisory expectations, but they show what a paper organisation will struggle to prove.
Before approving launch, the board should close this checklist:
- Every product function and token is mapped to a signed perimeter opinion.
- The EU entity has real decision-makers, staff, financial resources and vendor oversight.
- The requested services, capital calculation and NCA application match the live product.
- Custody, client-money, complaints, conflicts, pricing and wind-down controls are tested.
- AML, sanctions and travel-rule data work across CASPs and self-hosted addresses.
- White papers, token status and marketing claims are controlled by named owners.
- Passport notifications are complete and host-state obligations are recorded.
- Privacy, consumer, employment and tax reviews cover each operating country.
MiCA is not tax law. A CASP authorization does not determine corporate residence, VAT, payroll, permanent establishment, withholding, or the tax treatment of tokens and fees. It also does not displace AML, sanctions, consumer, data, employment or other financial-services duties. That is a practical boundary of the authorization, and it should appear in the launch memo rather than in a footnote after the product is live.
Frequently Asked Questions
Does every crypto company need CASP authorization?
No. The answer turns on the defined services performed for clients and the tokens involved. Issuing a token, providing software, trading for a firm's own treasury and providing a service to clients are different analyses. Map the facts against MiCA Article 3 and other EU financial-services law.
How much capital does a CASP need?
The prudential safeguard is the higher of the applicable EUR 50,000, EUR 125,000 or EUR 150,000 service-class minimum and one quarter of fixed overheads. A new firm uses projected first-year overheads. The form of the safeguard must also comply with Article 67.
Does one authorization allow immediate EU-wide service?
It creates the MiCA basis for cross-border service, but the CASP must complete the Article 65 home-NCA notification. The passport covers only authorised MiCA services and does not remove host-state or non-MiCA duties.
Can a third-country firm rely on an EU customer's checkbox?
No. A disclaimer cannot create the client's own exclusive initiative. The firm needs evidence that the client independently initiated the specific service and that neither the firm nor a connected person solicited that client in the Union.
Does MiCA replace AML, sanctions or tax rules?
No. MiCA authorization sits alongside AML and travel-rule controls, sanctions, data and consumer law, employment duties, tax, and any payment or securities permissions triggered by the business.
Sources Used in This Guide
- EUR-Lex: Regulation (EU) 2023/1114 on markets in crypto-assets
- EUR-Lex: Regulation (EU) 2023/1113 on transfer information
- European Commission: Crypto-assets and MiCA
- European Commission: MiCA implementing and delegated acts
- ESMA: Markets in Crypto-Assets Regulation hub and register
- ESMA: Guidelines on reverse solicitation under MiCA
- ESMA: MiCA authorization supervisory briefing summary
- ESMA: Final MiCA conflict-of-interest rules
- EBA: Asset-referenced and e-money tokens
- EBA: ART issuer authorization information standards
- AMF: MiCA implementation, CASP and issuer requirements
- AMF: End of the French MiCA transition
- Central Bank of Ireland: MiCAR regulatory hub
- Central Bank of Ireland: MiCAR frequently asked questions
- Central Bank of Ireland: Impact of MiCAR on VASPs
- Central Bank of Ireland: MiCAR industry briefing