A firm that safeguards, exchanges or gives advice on crypto-assets for EU clients now needs a licence to do it, and the licence is not a formality. Since 30 December 2024, Title V of the Markets in Crypto-Assets Regulation (MiCA) has required a crypto-asset service provider, a CASP, to be authorised by a national competent authority. The transitional cover that let existing firms carry on under national law has now closed everywhere: the outer date was 1 July 2026, and many member states closed it earlier. This is not legal advice, and a firm weighing where to apply needs its own counsel in the member state it has in mind. What follows is the shape of the regime: which services need a licence, what capital and governance it takes, where the passport stops working, and what authorisation has looked like in practice.
Which services require authorisation
MiCA lists ten crypto-asset services, and Article 59 bars anyone from providing them in the Union without authorisation under Article 63: custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for funds; exchange of crypto-assets for other crypto-assets; execution of orders on behalf of clients; placing of crypto-assets; reception and transmission of orders; providing advice on crypto-assets; portfolio management; and transfer services. The authorisation specifies which of those services the firm may provide, so the application has to name them.
There is a second route. Article 59 also lets certain already-regulated entities, among them credit institutions and investment firms, provide crypto-asset services under Article 60 by notifying their regulator rather than seeking a separate CASP authorisation. BaFin, for example, tells credit institutions to notify it at least 40 working days before starting.
For everyone else, Article 59 sets the entry conditions: the applicant must be a legal person or other undertaking with a registered office in a member state where it carries out at least part of its crypto-asset services, its place of effective management must be in the Union, and at least one director must be resident there.
Capital requirements by service class
Article 67 requires a provider to hold prudential safeguards equal to the higher of the Annex IV permanent minimum capital or one quarter of the preceding year's fixed overheads, reviewed annually. Annex IV sets three classes:
- €50,000 for reception and transmission of orders, advice, execution of orders, placing, transfer services or portfolio management.
- €125,000 once the licence adds custody and administration, or either exchange service.
- €150,000 once it adds operation of a trading platform.
The classes are not added together: a firm licensed for both advice and custody sits in the €125,000 class, not the sum of two amounts. The safeguards can take the form of Common Equity Tier 1 own funds, or an insurance policy or comparable guarantee covering the member states where the firm provides services. The policy must cover, among other things, loss of documents, misrepresentation, breach of legal and regulatory obligations, failure to manage conflicts of interest, business disruption and system failures, and, where relevant, negligence in safeguarding clients' assets.
Governance and fit-and-proper tests
Article 68 requires the members of a CASP's management body to be of sufficiently good repute, to have the knowledge, skills and experience the role demands, and to commit enough time to it. Neither they nor any shareholder or member with a qualifying holding may have been convicted of money laundering, terrorist financing or any other offence that would affect their good repute. The European Banking Authority and ESMA published joint guidelines on 27 June 2024 setting out how national regulators should assess both groups, which is meant to make the tests broadly consistent wherever a firm applies.
Safeguarding and segregation
Article 70 requires a CASP that holds clients' crypto-assets, or the means of access to them, to protect clients' ownership rights, especially if the provider becomes insolvent, and to stop those assets being used for its own account. Client funds other than e-money tokens must be placed with a credit institution or a central bank by the end of the business day after they arrive, in an account kept separately identifiable from the provider's own.
Article 75, which governs custody and administration, goes further: holdings kept for clients must be segregated from the provider's own, legally as well as operationally, so that the provider's creditors have no recourse to them. Liability for a loss caused by an incident attributable to the provider is capped at the market value of the lost crypto-asset at the time of the loss. Article 75 also says a custodian that uses other providers for custody may only use CASPs that are themselves authorised, and must tell clients it does so. ESMA repeated the point in its statement of 23 June 2026: custody cannot be outsourced or delegated to an entity that is not authorised as a CASP, whether that entity sits inside or outside the Union.
What segregation achieves in a failure still turns on national insolvency law, which MiCA does not harmonise. Our earlier piece on custody sets out how that differs across jurisdictions: see institutional custody, who actually holds it.
The white paper and marketing rules that reach service providers
Article 66 requires the information a CASP gives clients, including marketing communications, to be fair, clear and not misleading, with marketing identified as such, and it bars a provider from misleading a client, deliberately or negligently, about the real or perceived advantages of a crypto-asset. Providers must warn clients of the risks of crypto-asset transactions, and a provider that operates a trading platform, exchanges crypto-assets, gives advice or manages portfolios must give clients hyperlinks to the white papers for the assets it services. Its pricing, costs and fees policies must sit in a prominent place on its website, alongside information on the climate and other environmental impacts of the consensus mechanism used to issue each crypto-asset it services. Writing the white paper is the job of the issuer or offeror under the regulation's token titles; the service provider's duty is to point clients to it.
Passporting, and where it stops
An authorised CASP may provide its services throughout the Union, through a branch or on a cross-border basis. Under Article 65, it tells its home regulator which member states and services it has in mind, the start date and any other activities outside MiCA. The home regulator passes that to the host states, ESMA and the EBA within ten working days, and the firm may start from the date it is told the information has gone, or at the latest 15 calendar days after submitting it. The host regulator is informed rather than asked.
The passport has one hard limit worth knowing before a firm chooses where to seek its first licence: it follows only an actual MiCA authorisation. A firm that was operating under a national transitional arrangement could only rely on it in that member state, and BaFin said as much to German firms using its simplified procedure.
The transitional period, and when it ended in practice
Article 143(3) let a firm that was providing crypto-asset services under national law before 30 December 2024 continue until 1 July 2026, or until it was granted or refused authorisation, whichever came sooner, and let member states shorten or disapply that period. Many did. According to the list ESMA compiled from national authorities, which ESMA cautioned did not always reflect enacted law, the period was six months in the Netherlands, Finland, Latvia, Hungary and Slovenia; nine months in Sweden; and twelve months in Germany, Austria, Ireland, Lithuania and Slovakia. Germany wrote its cut-off into statute as 31 December 2025, and offered a simplified procedure to firms already licensed under German law for crypto business, in which only the MiCA requirements beyond their existing licence are examined. A firm that assumed a single EU-wide deadline would have found itself unlicensed well before 1 July 2026. Our piece on the regulatory year covers the wider pattern: see what regulators actually permitted in 2026.
ESMA's statement of 23 June 2026, ahead of the final cut-off, set out what an unauthorised firm must do: immediately stop onboarding new EU clients, open no new client relationships or accounts, cease marketing and solicitation, and wind down in an orderly way while maintaining its anti-money-laundering controls.
Reverse solicitation
A third-country firm may serve an EU client without MiCA authorisation where the client, on its own exclusive initiative, asks for the service. ESMA's guidelines on this exemption are dated 26 February 2025 and apply 60 calendar days after publication in all EU languages. They read it narrowly. Solicitation through third parties counts, and ESMA gives the example of an EU-regulated entity redirecting clients to a third-country firm, whether or not the two are in the same group. Whether the client took the initiative is a question of fact, and contractual arrangements or disclaimers cannot override contrary facts. The firm may offer crypto-assets or services of the same type only in the context of the original transaction: a client who asked to buy one crypto-asset cannot be marketed further transactions in it a month later. On ESMA's reading, reverse solicitation is not a way to serve the EU market.
How the application runs in practice
An applicant files with the competent authority of its home member state. The content of the file is fixed by Commission Delegated Regulation (EU) 2025/305, covering among other things the programme of operations, prudential requirements, governance, business continuity, anti-money-laundering arrangements, management and shareholders, and ICT security. Under Article 63 the regulator has 25 working days to decide whether the application is complete and then 40 working days from receipt of a complete application to grant or refuse it, a clock that can pause for up to 20 working days while it waits for further information it has asked for. Some regulators opened early: the Autorité des marchés financiers began accepting CASP applications in France from 1 July 2024.
A few dated grants show how it has played out. Austria's Finanzmarktaufsicht authorised Bitpanda GmbH on 9 April 2025. Luxembourg for Finance reported on 19 May 2025 that Bitstamp had become the first firm in Luxembourg authorised as a CASP by the Commission de Surveillance du Secteur Financier, and the same regulator's authorisation of Coinbase was announced on 20 June 2025, with Coinbase saying it could now serve all 27 member states from its Luxembourg hub. By 22 September 2026, CASPTracker, an independent site that compiles ESMA's register, listed 349 authorised providers. Because the substantive conditions are the same wherever a firm files, choosing where to apply is largely a choice of regulator, its queue and its way of working.
Where each measure stands
- MiCA, Regulation (EU) 2023/1114: in force; its CASP rules have applied since 30 December 2024, and the Article 143(3) transitional period ended on 1 July 2026 at the latest.
- Delegated Regulation (EU) 2025/305 on the content of a CASP application (level 2): adopted 31 October 2024, published 31 March 2025, in force.
- EBA and ESMA joint guidelines on the suitability of management body members and qualifying shareholders (level 3): final, published 27 June 2024.
- ESMA guidelines on reverse solicitation (level 3): final, dated 26 February 2025, applying 60 days after publication in all EU languages.
- ESMA's statement of 23 June 2026 on the end of the transitional period: a supervisory statement, not legislation.