IVYASCENT

For a crypto business, MiCA is not simply another compliance project to place on the legal team’s desk. It changes who can serve EU clients, how client assets must be protected and whether a promising platform can expand across the European market with regulatory credibility. So, what are MiCA CASP requirements? They are the authorisation, governance, prudential, conduct and operational standards that a crypto-asset service provider must meet to operate lawfully under the EU’s Markets in Crypto-Assets Regulation.

The commercial opportunity is substantial. A properly authorised CASP can generally passport its services across the EU rather than pursuing a separate licence in every Member State. But the authorisation is not a box-ticking exercise. Regulators expect a real business with a clear operating model, capable management, credible financial resources and controls that work beyond the application stage.

What Are MiCA CASP Requirements in Practice?

MiCA applies to businesses providing crypto-asset services in the EU on a professional basis. The first question is therefore not whether your company calls itself an exchange, wallet provider or fintech. It is what it actually does.

Services within the CASP perimeter include custody and administration of crypto-assets for clients; operating a trading platform; exchanging crypto-assets for funds or other crypto-assets; executing, receiving and transmitting client orders; placing crypto-assets; portfolio management; crypto-asset advice; and transfer services on behalf of clients.

A business may provide one service or several. That distinction matters because the application, capital threshold, policies, staffing and technology controls must match the exact permissions sought. An operator planning custody, fiat conversion and execution has a materially different risk profile from a firm providing advisory services only.

The rules also need to be assessed against the real customer journey. A business may believe it is only a software provider, yet fall within the CASP regime where it controls private keys, intermediates orders, receives client funds or plays an active role in arranging transactions. Getting the perimeter wrong at the structuring stage can create avoidable launch delays, banking friction and regulatory exposure later.

Establishment and Authorisation Requirements

A CASP applicant must be a legal person with its registered office in an EU Member State and its place of effective management in the EU. This is a substance requirement, not a paper exercise. The regulator will expect to see where strategic decisions are made, who makes them and how the firm is genuinely run.

The authorisation application is made to the competent authority in the Member State of establishment. It must explain the business model, the crypto-asset services requested, the intended markets, ownership structure and operational arrangements. It also needs to identify the people directing the business and demonstrate that the firm can comply on an ongoing basis.

For founders using international structures, this is where good design becomes commercially valuable. An EU-authorised operating company can sit within a wider group that includes holding, technology, intellectual property or non-EU commercial entities. However, the regulated entity cannot be hollowed out. Decision-making, oversight, core risk management and sufficient operational capacity must remain where the licence sits.

Cyprus can be a compelling base for businesses seeking an EU presence, but it is not automatically right for every model. The appropriate jurisdiction depends on the firm’s service mix, leadership location, target markets, staffing plan, investor expectations and wider tax and group structure.

Capital and Prudential Safeguards

MiCA requires CASPs to maintain prudential safeguards. Depending on the service category, the permanent minimum capital requirement is generally EUR 50,000, EUR 125,000 or EUR 150,000. The applicable amount is linked to the activities performed and may be affected where a firm combines services.

That figure is not always the full answer. A CASP must maintain own funds at least equal to the higher of its applicable permanent minimum capital and one quarter of its fixed overheads from the previous year. For a growing business, forecasts, hiring plans, technology costs and outsourced functions can therefore affect the capital position faster than founders expect.

The safeguards may take the form of own funds, an insurance policy or a comparable guarantee, subject to the applicable requirements. The strategic point is straightforward: the financial plan needs to support the actual operating model, not merely the lowest possible threshold in the rulebook.

A credible application will show how the business remains adequately funded during launch, lower-volume periods and stress events. Regulators are unlikely to be persuaded by optimistic trading projections without clear assumptions, committed resources and a realistic contingency plan.

Governance, Management and Ownership

MiCA places serious weight on the people behind the applicant. Members of the management body must be of sufficiently good repute and possess the knowledge, skills and experience to manage the CASP. They must also be able to commit sufficient time to their responsibilities.

This usually requires more than submitting CVs. The firm needs to articulate how senior management understands the business, risk profile, client-asset exposure, market-abuse risks and regulatory duties. It should also show who owns compliance, risk, complaints, outsourcing oversight, information security and financial control.

Shareholders and qualifying holders are scrutinised too. The regulator will consider whether the ownership structure is transparent and whether proposed owners are suitable, financially sound and unlikely to prevent prudent management of the CASP. Complex offshore chains are not prohibited simply because they are international, but opacity, unexplained funding or unclear control rights will attract questions.

Governance should be proportionate, but it cannot be performative. A smaller firm may have leaner committees and fewer layers of management. It still needs clear reporting lines, documented decisions, conflicts procedures and effective oversight. Copying a policy suite from a larger institution without building it into daily operations is a common and expensive mistake.

Client Asset Protection and Conduct Rules

Where a CASP holds client crypto-assets or client funds, safeguarding is central. The business must make arrangements to protect clients’ ownership rights, keep records and systems that distinguish client holdings from the CASP’s own assets, and prevent unauthorised use of client assets.

Custody providers face particularly demanding expectations around wallet architecture, private-key management, reconciliation, access controls, incident response and the handling of forks or protocol events. The legal terms must also be clear about custody arrangements, rights and liabilities. Technology design and legal design need to align from day one.

All CASPs must act honestly, fairly and professionally in clients’ best interests. They must provide information that is fair, clear and not misleading, identify and manage conflicts of interest, operate an effective complaints process and apply transparent pricing and disclosure practices.

For trading platforms and firms executing or placing orders, the conduct framework extends to orderly trading, fair access and market integrity. CASPs also need systems to detect and address potential market abuse. Commercial pressure to grow volumes cannot override controls around suspicious behaviour, token promotion or conflicts created by proprietary activity.

AML, ICT Resilience and Outsourcing

MiCA does not replace anti-money laundering obligations. CASPs are within the EU anti-money laundering framework and must build controls around customer due diligence, beneficial ownership, sanctions screening, transaction monitoring, suspicious activity reporting and record keeping. The Transfer of Funds rules also create information obligations for certain crypto-asset transfers.

A strong AML framework is not just a regulatory requirement. It is often decisive for banking, payment-rail access and institutional counterparties. A licence application that treats AML as an outsourced compliance document, rather than a live operational function, can undermine the wider commercial case.

Digital operational resilience is equally important. CASPs are subject to the EU’s Digital Operational Resilience Act, known as DORA. Firms must manage ICT risk, test resilience, report serious incidents where required and control risks arising from third-party technology providers.

Outsourcing cloud hosting, custody technology, onboarding tools or transaction-monitoring systems does not transfer regulatory accountability. The CASP must carry out due diligence, document the arrangement, retain oversight, maintain exit planning and ensure that outsourcing does not impair supervision or service continuity.

The Transition Period and the Route to Market

MiCA’s CASP rules have applied since 30 December 2024. Some Member States allow existing crypto businesses operating under national law before that date to continue temporarily while moving towards MiCA authorisation, potentially until 1 July 2026. The exact transitional position depends on the relevant Member State and national measures, so it should never be assumed.

For a new entrant, the right approach is to build the licence strategy into the business plan before technology, marketing and customer acquisition become difficult to unwind. Define the regulated services, select the appropriate EU base, map the group structure, appoint credible leadership and prepare policies that reflect the actual product.

MiCA rewards firms that treat regulation as operating infrastructure rather than a barrier at the gate. With the right authorisation strategy, governance and group structure, a CASP licence can become the foundation for safer expansion, stronger counterparties and a business built to stay in the European market.

3 Responses

Leave a Reply

Your email address will not be published. Required fields are marked *