Before MiCA, a firm that wanted to serve crypto customers across the European Union collected registrations one country at a time. Each national regime had its own file, its own vocabulary and its own view of what counted as a regulated activity. A firm registered in one member state had no automatic right to serve customers in another. The Markets in Crypto-Assets Regulation replaced that with a single authorisation, the crypto-asset service provider licence, granted by one national competent authority and valid across the bloc.
The trade is straightforward. One licence instead of many, in exchange for a standard that looks much more like an investment firm authorisation than like the registration regimes it replaced.
Which activities pull you into scope
MiCA defines a closed list of crypto-asset services. Custody and administration on behalf of clients. Operation of a trading platform. Exchange of crypto-assets for funds, and exchange of crypto-assets for other crypto-assets. Execution of orders. Placing. Reception and transmission of orders. Providing advice, and providing portfolio management. Transfer services on behalf of clients.
Two consequences follow. First, the activity list, not the technology, determines scope. Holding client private keys is custody whether you describe yourself as a wallet, an exchange or a payments company. Second, most real businesses tick several boxes at once, and each additional service raises the prudential floor and adds requirements to the file. An exchange that also holds client assets is doing two regulated things, and the regulator will assess both.
Firms already regulated elsewhere get a shorter path in some cases. A credit institution or an authorised investment firm can generally notify rather than apply for services that sit alongside what it is already permitted to do. Everyone else applies from scratch. If you are weighing this against other routes, our comparison of crypto licence jurisdictions sets out the alternatives, and MiCA against the older VASP registrations explains what changed.
What the application file contains
The application goes to the competent authority of the member state where the firm has its registered office, and that office has to be real. A programme of operations describes each service, the target market and how the service actually runs. A governance file covers the management body, the fitness and propriety of directors and qualifying shareholders, the reporting lines and the three control functions.
Then the operational material. An ICT and cybersecurity description, which under the parallel digital operational resilience rules is not a paragraph. Custody arrangements, including segregation of client assets from the firm's own, key management, and what happens if a key holder is unavailable. A complaints handling procedure. A conflicts of interest policy. Business continuity and a wind-down plan that explains how client assets get returned if the firm stops trading. An AML and counter-terrorist financing framework, with the transfer-of-funds obligations that apply to crypto transfers built in. Our notes on the AML directives and the travel rule cover that layer.
Capital, and the two ways it is measured
MiCA sets a minimum own funds requirement by service class, with a higher floor for trading platform operation than for reception and transmission of orders. That is the headline number and it is the one everyone quotes. The requirement is actually the higher of that fixed floor and a proportion of the previous year's fixed overheads, which means a firm with a large cost base carries more capital than the table suggests.
Own funds can be substituted in part by an insurance policy meeting the conditions in the regulation. In practice most applicants hold capital, because the insurance route requires a policy with terms that satisfy the authority and those take their own negotiation. Budget for the capital to be locked before authorisation, not after first revenue.
This is a description of a regulatory regime, not legal advice. MiCA is applied by national authorities whose expectations differ in detail, and any firm considering an application should take advice in the specific member state before committing to a plan.
The clock, and why it rarely runs as written
The regulation sets out a two-stage timetable. The authority first checks whether the application is complete, within a short window, and tells the applicant what is missing. Once the file is judged complete, a longer assessment period begins, during which the authority may suspend the clock while it waits for answers. The regulator also consults counterparts in other member states where relevant.
The gap between the written timetable and the lived one comes almost entirely from completeness. A file that arrives thin gets returned, and the clock has not started. Applications that move quickly are the ones where the operating model was built before it was written down: named individuals in the control functions who actually work there, a custody procedure that reflects the wallet infrastructure the firm has already deployed, an ICT description written by whoever runs the systems. Applications that stall are the ones assembled from templates.
What you get, and what you still owe
Authorisation carries the passport. Notify the home authority of the member states you intend to serve, the notification is transmitted, and the services can be provided cross-border. That is the commercial reason to do this rather than operate from outside the bloc, since MiCA also restricts unauthorised firms from soliciting EU customers. The passporting mechanics mirror those in the investment firm regime.
Ongoing obligations start on day one. Prudential reporting, complaints records, conflicts registers, safeguarding of client assets, marketing communications that meet the fair and clear standard, and notification of material changes to the authority. Where a firm also issues tokens, the separate disclosure regime applies on top. Any change of control, any new service, any relocation of a control function is a filing. Authorisation is a supervised state rather than a certificate, and firms that treat it as a one-off project tend to discover that in their first inspection. The wider MiCA framework sets out the rest of the regime.
"Firms budget for the legal fees and forget the operating build. The regulator will ask who runs custody at three in the morning, and a name has to exist."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- MiCA replaces national crypto registrations with one CASP authorisation that passports across the EU.
- Scope follows the activity list, so holding client keys is custody regardless of what the product is called.
- Own funds are the higher of a service-class floor or a share of fixed overheads, and must be in place before authorisation.
- Timelines slip on completeness, so build the operating model before writing the application file.
Frequently Asked Questions
Does a CASP licence let me serve customers across the whole EU?
Yes, through notification. Once authorised, the firm notifies its home authority of the member states it intends to serve and the passport is transmitted, so services can be provided cross-border without a second authorisation.
Do I need a CASP licence if I only run a wallet?
If you hold or control client crypto-assets or the means of access to them, that is custody and administration on behalf of clients, which is a regulated service. A wallet where the user alone holds the keys is a different question and turns on the specific facts.
Can an existing investment firm add crypto services without a full application?
Certain already-authorised entities, including credit institutions and MiFID investment firms, can use a notification route for services that align with their existing permissions rather than applying from scratch. The conditions are specific and depend on the permissions already held.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.