A MiCA application is not a formality to be completed shortly before launch. It is the point at which your operating model, ownership structure, technology, capital, client journey and growth plans are tested as one business. Founders asking how to apply MiCA licence usually need more than a list of documents. They need a route to market that can withstand regulatory scrutiny without slowing the commercial opportunity.
For most businesses, the practical objective is authorisation as a crypto-asset service provider, or CASP, under the Markets in Crypto-Assets Regulation. Once authorised in one EU Member State, a CASP can use the MiCA passporting framework to provide approved services across the EU, subject to the required notification process. That makes the choice of home jurisdiction and the quality of the initial application strategically significant.
Start with the service perimeter, not the application pack
The first question is whether your activities fall within MiCA and, if they do, which crypto-asset services you intend to provide. This can include custody and administration of crypto-assets for clients, operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing or receiving and transmitting orders, providing advice, portfolio management and transfer services.
The answer must reflect what the business will actually do, not simply the most attractive description for a website. A platform that holds client keys, controls wallet infrastructure or intermediates settlement may trigger a different authorisation scope from a non-custodial software provider. Likewise, a group that intends to offer fiat payment accounts, cards or payment execution may need a separate payments analysis alongside MiCA.
This is where commercially ambitious businesses can create avoidable delay. Applying for too narrow a scope can constrain the launch roadmap. Applying for every possible service without a credible operating case can invite difficult questions from the regulator. The right perimeter supports your planned revenue model for the next phase of growth while remaining evidence-led and deliverable on day one.
How to apply MiCA licence with the right EU structure
A MiCA authorisation is granted by the national competent authority in the Member State where the CASP is established. The applicant must be an EU legal person with its registered office in a Member State and effective management carried out within the EU. A paper entity with all material decision-making, systems and personnel elsewhere is not a durable solution.
The jurisdiction decision should therefore be made before the application is drafted. Regulatory expectations, supervisory practice, local talent, banking access, substance costs, tax position and the group’s long-term European footprint all matter. Cyprus can be a compelling base for international founders where it fits the operational plan, but no jurisdiction should be selected solely because it appears quick or inexpensive.
A well-designed structure also separates risk intelligently. The authorised CASP should have clear control over its regulated services, governance and critical suppliers. Holding companies, intellectual-property entities and non-EU commercial operations may have a role, but they must not obscure ownership, accountability or client-asset protections. Regulators will examine the full group, including related businesses and close links, rather than treating the applicant as an isolated company.
Build the authorisation dossier around proof
The application dossier needs to show that the applicant is ready to operate compliantly, not merely ready to hire consultants after approval. National competent authorities may have their own forms and process expectations, but the core MiCA evidence is consistent.
You will generally need a detailed programme of operations explaining the proposed services, target markets, client types, distribution channels, outsourcing arrangements and financial forecasts. The business plan should connect projected activity to staffing, capital, technology and controls. Numbers that look attractive but cannot be explained operationally undermine credibility.
The file must also address governance. This includes the management body, reporting lines, decision-making arrangements, internal controls, conflicts management, complaints handling, record keeping and business continuity. Directors and senior managers must be sufficiently experienced, of good repute and able to demonstrate the time and competence required for their functions. A nominee-led board with no practical understanding of crypto operations is unlikely to satisfy that standard.
Owners of qualifying holdings will face scrutiny as well. The authority will expect a transparent ownership chart, source-of-funds and source-of-wealth evidence where appropriate, and assurance that shareholders will not impede prudent management. Founders should prepare this material early, particularly where wealth has been generated through digital assets, international trading, gaming or other higher-risk sectors that may require fuller explanation.
Treat capital, safeguarding and AML as operating decisions
MiCA imposes prudential safeguards based on the services provided. Depending on the category of CASP activity, the applicable initial capital threshold can be EUR 50,000, EUR 125,000 or EUR 150,000, with ongoing requirements assessed against the higher of the relevant threshold and a proportion of fixed overheads. Capital cannot be treated as a number inserted into a spreadsheet at the end of the process. It must be available, correctly evidenced and supported by realistic cost assumptions.
Client asset arrangements deserve the same attention. If the business will custody crypto-assets or client funds, it needs clear procedures for segregation, reconciliations, wallet governance, key management, access rights, incident response and records of client entitlements. The legal documentation, technical architecture and daily operational process must tell the same story.
Anti-money laundering and counter-terrorist financing controls should be designed around the actual customer and transaction risks. A generic policy will not resolve questions about sanctions screening, blockchain analytics, high-risk geographies, source of funds, enhanced due diligence, suspicious-activity escalation or Travel Rule implementation. For a US-facing or internationally acquired customer base, the geographic-risk assessment is especially important. The EU authorisation does not remove the need to manage restrictions in markets outside the EU.
Make technology and outsourcing defensible
A CASP application is partly a technology application, even where the applicant does not develop its platform in-house. Regulators will want to understand the systems supporting custody, execution, order handling, transaction monitoring, cyber security, data protection, access management and incident reporting.
The Digital Operational Resilience Act also shapes the standard expected of CASPs. Your ICT governance, resilience testing, incident-management procedures and third-party arrangements must be proportionate, documented and capable of being used in practice. If a cloud provider, wallet custodian, liquidity provider, identity-verification provider or blockchain analytics supplier is critical to the service, the outsourcing contract should give the CASP sufficient oversight, audit rights, continuity protection and exit options.
Outsourcing can accelerate launch. It cannot outsource accountability. The authorised entity remains responsible for the regulated service, and management must be able to challenge providers rather than simply rely on them.
Submit, respond and prepare for supervision
After submission, the authority assesses whether the application is complete and then moves into substantive review. Requests for clarification are normal. What matters is the quality and consistency of the response. Contradictions between the programme of operations, financial model, policies, supplier agreements and website copy are a common source of friction.
A disciplined response process helps: maintain one controlled version of the application, allocate each regulatory question to an accountable owner, preserve an evidence trail and assess whether an answer requires a wider change to the operating model. Fast replies are useful, but unsupported replies can create more work later.
Approval should not be treated as the finish line. Before launch, the business needs to complete onboarding controls, train staff, test reporting routes, activate governance committees, finalise client disclosures and ensure its marketing is fair, clear and not misleading. The regulator authorises a business that can be supervised over time, not a static dossier.
Passport only when the model is ready
MiCA passporting can create a powerful expansion route, but it should follow operational readiness. Before notifying cross-border services, consider local consumer expectations, language, marketing practices, tax exposure, payment availability and any rules that sit outside MiCA. A CASP passport does not automatically solve every legal question created by a new market.
The strongest applications are built as launch plans, not compliance projects. With the right regulatory perimeter, EU substance, governance and commercial structure in place, MiCA authorisation can become a foundation for protected expansion rather than a barrier to it. Ivyascent helps founders turn that foundation into an operating business designed to scale with confidence.