MiCA License 2026: Complete Guide to EU CASP Authorisation

If you want to operate a crypto exchange, custody platform, broker, crypto transfer business or other crypto-asset service in the European Union, the regulatory position changed decisively under MiCA. As at August 2026, the transitional periods have ended. A firm providing in-scope crypto-asset services to EU customers now generally needs authorisation as a Crypto-Asset Service Provider, or CASP, unless it is an already regulated financial institution using the MiCA notification route or another narrow exception genuinely applies.
For a founder, the important point is that a MiCA licence is not simply a replacement for the old VASP registration. It is a full operating authorisation. The regulator will assess the business model, services, management, ownership, capital, custody arrangements, client assets, conflicts, complaints, outsourcing, technology, operational resilience, AML controls and the ability of the company to run as a supervised financial business.
The commercial benefit is significant. Once a CASP is authorised in its EU home Member State, it can use the MiCA passporting framework to provide the authorised services across the EU without applying for a separate crypto licence in each country. The challenge is that the home-state application must be strong enough to support a genuinely regulated European operation.
What is a MiCA licence?
The term "MiCA licence" is widely used in the market. Legally, the relevant permission is authorisation as a crypto-asset service provider under Regulation (EU) 2023/1114 on Markets in Crypto-Assets. MiCA created a single EU framework for crypto-asset services that previously sat under different national registration regimes.
MiCA has applied fully since 30 December 2024. Member States were permitted to provide transitional arrangements for existing firms, but the maximum grandfathering period expired on 1 July 2026. In Spain, the CNMV has confirmed that only MiCA-authorised providers, or providers authorised elsewhere in the EU and properly passported into Spain, can now operate under the MiCA framework.
Who needs a MiCA CASP licence?
A business needs to assess MiCA if it provides one or more regulated crypto-asset services professionally to clients in the EU. The key question is not whether the company describes itself as a crypto exchange, wallet, broker or infrastructure platform. It is whether the activities fall within the services listed in MiCA.
Custody and administration of crypto-assets on behalf of clients.
Operation of a trading platform for crypto-assets.
Exchange of crypto-assets for funds.
Exchange of crypto-assets for other crypto-assets.
Execution of orders for crypto-assets on behalf of clients.
Placement of crypto-assets.
Reception and transmission of orders for crypto-assets.
Providing advice on crypto-assets.
Providing portfolio management on crypto-assets.
Providing transfer services for crypto-assets on behalf of clients.
A company can require several of these permissions at the same time. For example, a retail crypto platform might provide custody, exchange and transfer services. An OTC broker might receive and transmit orders and execute transactions. A crypto wealth platform might require advice or portfolio management permissions. The licence scope should match the product that customers will actually use.
What does a MiCA licence allow you to do?
The authorisation allows the CASP to provide the crypto-asset services included in its permission and, after the required cross-border notification process, to provide those services across the EU. This is one of MiCA's main commercial advantages. A business can build one regulated EU entity rather than obtaining a separate national crypto registration in every Member State.
The authorisation does not automatically cover activities regulated under another financial services regime. If a token is a financial instrument, MiFID II may apply rather than MiCA. If the model includes payment services involving funds or e-money tokens, payment services regulation can also become relevant. If the company issues an asset-referenced token or e-money token, separate issuer requirements apply. A CASP licence should therefore be treated as one part of the perimeter analysis, not a blanket permission for every crypto-related activity.
Can a non-EU crypto company obtain a MiCA licence?
Yes, but the regulated CASP needs to be established in the European Union. MiCA requires the applicant to have a registered office in an EU Member State and its effective management in the EU. At least one director must be resident in the EU. In practice, national regulators will look beyond formal incorporation and assess whether the licensed entity has enough management, governance and operational substance to be supervised properly.
A global crypto group can therefore create an EU subsidiary, but that subsidiary needs to be more than a contractual shell. The application should show what decisions are taken by the EU entity, which people are responsible for regulated functions, what is outsourced to the wider group and how the CASP remains in control of those arrangements.
Which EU country should you choose for a MiCA licence?
There is no universally "best" MiCA jurisdiction. The Regulation is common across the EU, so shopping purely for the regulator perceived to be easiest is the wrong starting point. The better question is which Member State fits the substance and commercial plan of the business.
A founder should compare where the group already has management, staff and customers, the regulator's application process, language, availability of experienced compliance staff, banking and payment infrastructure, tax and corporate structure, local operating costs and the credibility of the proposed substance. A licence in a country where the company has no genuine management or commercial reason to operate can create more difficulty than it saves.
MiCA is designed to produce supervisory convergence. The regulator in the home Member State still decides the application, but ESMA has been actively driving a consistent standard across national competent authorities. A weak business model should not be expected to become acceptable simply by moving the application to another country.
How much capital does a MiCA CASP need?
MiCA divides CASPs into three capital classes according to the services provided. The permanent minimum capital requirement is:
EUR 50,000: for Class 1 services, including execution of orders, placing, transfer services, reception and transmission of orders, advice and portfolio management.
EUR 125,000: where the CASP also provides custody and administration, exchange of crypto-assets for funds or exchange of crypto-assets for other crypto-assets.
EUR 150,000: where the CASP operates a trading platform for crypto-assets.
The minimum amount is not necessarily the amount the firm must maintain. MiCA requires prudential safeguards equal to at least the higher of the applicable permanent minimum capital requirement and one quarter of the firm's fixed overheads for the preceding year. A new firm uses projected fixed overheads for its first 12 months. Prudential planning therefore needs to be built into the financial model rather than treated as a one-off share capital payment.
What do you need before applying?
A founder should expect the following to be substantially settled before a serious CASP application is submitted:
The EU legal entity and ownership structure.
The exact MiCA services being requested.
A clear product description and client journey.
A three-year business plan and financial projections.
Management with appropriate crypto, compliance, risk and operational experience.
The capital and prudential safeguard structure.
AML, KYC, sanctions and Travel Rule controls.
Custody and client asset arrangements where relevant.
Client funds arrangements where fiat money is received.
Conflicts of interest, complaints and conduct procedures.
ICT, cyber, business continuity and DORA controls.
Outsourcing and intra-group service arrangements.
A wind-down plan capable of protecting clients if the business stops operating.
The MiCA application process
1. Define the regulated services. Map every part of the product to the MiCA service list and identify any overlap with payments, e-money, securities or other financial regulation.
2. Choose the home Member State. Base the decision on genuine substance, management, banking and the commercial structure of the group.
3. Establish the applicant and governance. Put the legal entity, board, controllers and senior management in place and define who is responsible for the regulated business.
4. Prepare the business plan and financial model. Explain customers, geographies, products, revenue, volumes, staffing, capital, outsourcing and the path to profitability.
5. Build the compliance and risk framework. This includes AML, sanctions, Travel Rule, conflicts, complaints, conduct, custody, client assets, outsourcing and market-abuse related controls where relevant.
6. Build the ICT and resilience framework. MiCA CASPs are also subject to DORA. Technology governance, incident management, continuity, third-party risk and testing need to be operationally credible.
7. Prepare the formal application. The information should be consistent across the application form, business plan, policies, organisation chart, financial model and technical documentation.
8. Manage regulator questions. Treat the information request process as part of the authorisation assessment. Answers should be complete and should not unintentionally change the business model.
9. Complete passporting and launch readiness. Once authorised, complete the required notification process for other EU Member States and make sure systems, people and client documentation are ready for live business.
How long does a MiCA licence take?
MiCA sets a formal assessment structure. The competent authority acknowledges the application within five working days, assesses completeness within 25 working days and, once the application is complete, has 40 working days to assess whether the applicant meets the MiCA requirements and grant or refuse authorisation. Requests for further information can affect the timetable, including a permitted suspension of the assessment period in specified circumstances.
That statutory timetable is not the same as the total project timetable. A founder still needs to build the company, management, policies, technology, capital structure and evidence before the application can be considered complete. In practice, the quality of preparation and the complexity of the services are major drivers of the end-to-end timetable.
AML, KYC and the Travel Rule
MiCA authorisation sits alongside the EU anti-money laundering framework. A CASP needs a customer and transaction risk framework capable of handling the specific risks created by crypto-assets, including source of funds, beneficial ownership, sanctions, higher-risk jurisdictions, transaction monitoring and suspicious activity escalation.
The EU Transfer of Funds Regulation extends the Travel Rule to qualifying crypto-asset transfers. CASPs therefore need systems and procedures for collecting, transmitting and validating required originator and beneficiary information. This should be designed into the transaction flow and technology architecture rather than added after the licence has been granted.
Custody and protection of client crypto-assets
Custody is one of the areas where the licence becomes operationally demanding. A CASP providing custody and administration needs arrangements for segregation, record keeping, access controls, wallet governance, key management, incident response and the return of client assets. The legal and technical custody model should make clear what the CASP controls and how client ownership is evidenced.
A founder should also understand the operational consequence of outsourcing custody technology. Using an institutional wallet provider can strengthen the control environment, but it does not transfer the CASP's regulatory responsibility. The licensed entity must understand the provider, oversee it and retain sufficient control over the service offered to clients.
DORA and technology requirements
A MiCA licence is now inseparable from digital operational resilience. CASPs are within the DORA framework and need proportionate governance for ICT risk, incident handling, resilience testing, business continuity and third-party technology risk. A crypto company that has focused heavily on product development but has no formal technology control framework will need to close that gap during the application project.
This is especially important for businesses relying on cloud infrastructure, wallet providers, liquidity venues, trading technology, identity providers and blockchain analytics vendors. The regulator will want to understand which services are critical, how failures are managed and whether the CASP can continue or wind down safely if a provider fails.
Can a UK or US crypto company serve EU customers without MiCA?
A third-country company should not assume that it can continue actively marketing to EU customers from outside the Union. MiCA contains a narrow client-initiative concept often referred to as reverse solicitation, but it is not a general route for avoiding authorisation. Where a firm solicits, promotes or markets services to EU clients, the exemption is unlikely to provide a reliable business model.
For a company that wants the EU to be a genuine target market, the strategic decision is normally whether to establish an EU CASP or partner with an authorised provider. Building a business around aggressive use of reverse solicitation creates regulatory and commercial fragility.
MiCA and stablecoin payments
Stablecoin businesses need additional care because MiCA, payments regulation and e-money rules can overlap. E-money tokens are a specific category under MiCA, but a service involving the transfer or use of EMTs can also raise payment services questions. In March 2026, the Banco de España specifically highlighted the need to consider PSD2 authorisation where CASPs provide payment services involving EMTs.
A founder building stablecoin payments should therefore avoid assuming that a MiCA CASP licence is the only permission required. The transaction flow needs to be analysed across MiCA, payment services and e-money rules before the licensing strategy is fixed.
Common MiCA application mistakes
Treating the old VASP registration standard as sufficient for MiCA authorisation.
Choosing the home Member State before deciding where the company will have genuine management and substance.
Requesting every CASP permission even though the product does not need them.
Underestimating the prudential requirement by looking only at the minimum capital class.
Using generic AML policies that do not reflect the crypto transaction model.
Failing to map payment services or e-money overlaps.
Outsourcing custody or technology without showing how the CASP remains responsible.
Treating DORA as a post-licence technology project.
Using reverse solicitation as a planned distribution strategy for EU customers.
Submitting an application while ownership, products or senior management are still materially changing.
Frequently asked questions
Is a MiCA licence valid across the whole EU?
A CASP authorised in one EU Member State can use the MiCA cross-border framework to provide its authorised services in other EU Member States after the required notification process. It does not need to obtain a separate CASP licence in each country. Local conduct, AML and other applicable requirements still need to be managed properly.
Is MiCA authorisation now mandatory in 2026?
For in-scope CASPs serving the EU, the grandfathering period is now over. The maximum MiCA transitional period expired on 1 July 2026. A firm that wants to provide regulated crypto-asset services in the EU should therefore have the appropriate MiCA authorisation, use the financial-entity notification route where available, or fall within a genuine exclusion or narrow third-country client-initiative scenario.
How much capital do I need for a MiCA licence?
The permanent minimum is EUR 50,000, EUR 125,000 or EUR 150,000 depending on the services. The actual prudential safeguard must be at least the higher of that minimum and one quarter of the relevant fixed overheads. The financial model should therefore calculate the real requirement rather than assume the licence can be operated with the headline minimum.
Do I need local staff in the country where I apply?
MiCA requires the CASP to be established in the EU with effective management in the Union, and at least one director must be EU resident. National regulators will assess whether the applicant has enough real governance and operational substance to be supervised effectively. The precise staffing model depends on the services, size and outsourcing structure.
Can an existing bank, EMI or investment firm provide crypto services without a separate CASP application?
Certain already regulated financial entities can use the MiCA notification route for crypto-asset services equivalent to activities they are permitted to perform, subject to the conditions in Article 60. This is not a general exemption for every regulated company. The existing licence and proposed crypto service need to be matched carefully.
Does MiCA cover token issuance as well as crypto services?
MiCA covers both service providers and different categories of crypto-asset issuance, but the legal routes are different. A CASP licence is not itself an authorisation to issue every type of token. Asset-referenced tokens, e-money tokens and other crypto-assets have separate issuer and white-paper requirements, and financial instruments fall outside MiCA into securities regulation.
Can I apply in the cheapest EU country and operate everywhere else?
Cost should not be the primary jurisdiction decision. The regulator needs to supervise a real business with appropriate management and substance. A home state that fits the company's people, banking, operating model and commercial footprint is usually more defensible than a jurisdiction selected only because an adviser advertises a low setup cost.
How long should a founder budget for the whole MiCA project?
The Regulation contains a 25-working-day completeness review and a 40-working-day assessment once the application is complete, but the total project begins earlier. Governance, policies, technology, capital, AML, DORA and evidence all need to be built before or during the application. More complex custody, exchange and group structures will usually require more preparation than a narrow advisory or transfer model.
Can I buy a company that already has a MiCA licence?
A CASP can be acquired, but the licence is attached to the regulated legal entity and its approved business, people and controls. Changes in qualifying holdings and management can require regulatory assessment. Due diligence should cover the permission scope, regulator correspondence, capital, client assets, AML, outsourcing, technology, complaints and whether the intended new business fits the existing authorisation.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has advised payment, e-money, crypto and regulated financial businesses since 2013. We support founders and financial groups with MiCA perimeter analysis, EU jurisdiction strategy, CASP permission mapping, business plans, financial projections, governance, AML frameworks, DORA readiness, outsourcing, application documentation and regulator engagement.
The first step is normally to establish which crypto-asset services the business will provide, whether any payment, e-money or securities permissions also apply and which EU home state is commercially and operationally credible. We then build the licensing project around the real business rather than a generic CASP template. Contact Buckingham Capital Consulting to discuss a MiCA authorisation or EU crypto market-entry project.



