Direct answer: a standard crypto company applies under Articles 62 and 63 to the authority in its EU home state. The CASP license covers only the approved services. After notification, the firm can passport those services across the EU. The firm remains supervised and must continue to meet MiCA’s capital, governance, conduct, custody and resilience rules.
Who needs a CASP license?
A legal person or other undertaking needs authorisation when it professionally provides a MiCA crypto-asset service in the EU. Retail customers do not need provider authorisation. Certain regulated financial entities can notify equivalent services under Article 60 instead of applying through the standard Article 63 route. An old national VASP or AML registration does not automatically become a MiCA authorisation. The VASP-to-CASP transition guide explains which evidence and controls firms must add. The Saint Vincent and the Grenadines (SVG) registration comparison shows why a third-country registration gives no MiCA authorisation or EEA passport.
Authorisation, then passporting
A crypto firm applies to one national competent authority in its home state. Its registered office must be in that member state. Its effective management must be in the EU, and at least one director must be an EU resident. Once authorised, the firm can passport its approved services into other EU member states through the Article 65 notification. The firm does not need a second CASP licence. Customers should verify the authorised legal entity, service scope and licensing country. For applicants, the home-state choice affects the regulator, filing route and supervision. Compare the routes in the MiCA licence by country guide.
The 10 regulated services
A CASP authorisation covers one or more of these services. The licence covers only the services that the authority approved:
- Custody and administration of crypto-assets
- Operation of a trading platform
- Exchange of crypto-assets for funds
- Exchange of crypto-assets for other crypto-assets
- Execution of orders for clients
- Placing of crypto-assets
- Reception and transmission of orders
- Advice on crypto-assets
- Portfolio management
- Transfer services
CASP license requirements
Article 62 lists the information that an applicant must submit. Other parts of MiCA Title V set the operating rules. The services and business model determine the exact evidence, but a complete application must cover these areas:
- Describe the requested services, products, customers, countries, delivery channels and marketing approach in the programme of operations.
- Document the ownership structure and qualifying holdings. Show the reputation, competence, experience and time commitment of the management body.
- Define decision rights, compliance, risk management, internal controls, record keeping, conflicts of interest and complaints handling.
- Provide clear disclosures and fee information. Document custody controls and the segregation of client assets and funds where applicable.
- Document customer due diligence, transaction monitoring, sanctions controls and suspicious-activity procedures under the applicable AML law.
- Document DORA-aligned security, incident response, business continuity, disaster recovery and oversight of outsourced functions.
- Prepare an orderly wind-down plan that protects clients. The plan must allow the firm to return or transfer crypto-assets and funds if services cease.
For an Article 63 CASP applicant, the minimum prudential safeguard is €50,000, €125,000 or €150,000 depending on the service class. Article 67 then applies the higher of that floor or one quarter of fixed overheads. A firm without a full operating year uses projected fixed overheads for its first 12 months under Article 67(2). Eligible Article 60 financial entities follow their existing sectoral prudential regime because Article 60(10) disapplies Article 67 to that route. The licence cost guide explains why regulatory capital is only one part of the budget.
Application process and statutory timeline
- Confirm the EU home state, legal route and crypto-asset services in scope.
- Establish the entity, management team, governance and technical controls.
- Submit the Article 62 information and the authority’s current forms.
- Answer completeness questions and provide consistent supporting evidence.
- Complete approval formalities and make any cross-border notification.
The authority acknowledges receipt within five working days and has 25 working days to assess whether the application is complete. The authority then has 40 working days to grant or refuse authorisation after receiving a complete file. The authority must notify the applicant of the decision within five working days. The statutory periods cover regulatory review only. The periods exclude drafting and remediation, and regulator questions can extend the total process.
Renewal, extensions and withdrawal
A MiCA CASP authorisation has no routine annual renewal date. The authorisation remains valid only while the provider continues to meet its conditions. A CASP that wants to add services must request an extension and update the Article 62 information.
Under Article 64, the authority must withdraw authorisation in defined cases. The cases include when the authorisation is unused for 12 months, when the provider offers no services for nine consecutive months, or when it was obtained through irregular means. Withdrawal is also required when the provider no longer meets the conditions and fails to correct the problem. Check current register status and service scope before relying on an old licence announcement.
Common questions
What is a CASP license?
A CASP license is an authorisation under the EU Markets in Crypto-Assets Regulation (MiCA) to provide one or more regulated crypto-asset services. CASP stands for Crypto-Asset Service Provider.
What are the main CASP license requirements?
The applicant must have real EU operations, suitable owners and managers, and sufficient prudential safeguards. The application must also document the programme of operations, governance and risk controls. The application must cover client-asset protection, complaint and conflict procedures, AML controls, ICT resilience and an orderly wind-down plan. The services requested determine the detailed requirements.
How long does a MiCA CASP application take?
MiCA allows 25 working days for the completeness check and 40 working days to assess a complete application. The statutory periods exclude preparation. Missing information and regulator questions can extend the total process.
Does a CASP license expire or need renewal?
MiCA does not set a routine annual renewal date for an Article 63 CASP authorisation. The provider must continuously meet the authorisation conditions. Adding services requires an extension, and the authority can restrict or withdraw the licence on the grounds in Article 64.
Where exchanges get licensed
As of 31 July 2026, ESMA's snapshot contains 323 source records grouped into 318 current legal-entity entries. The largest current home-state hubs are: