What is a MiCA CASP authorisation and who needs one?
The services in scope, the passport it carries, and why a national VASP registration is not the same thing.
A MiCA CASP authorisation permits a firm to provide defined crypto-asset services across the EEA under a single licence, passported from one competent authority. It covers custody, exchange, execution, placement, transfer, advice and portfolio management. A national VASP registration is an anti-money-laundering registration only. It carries no passport and no authorisation to provide those services.
What is a MiCA CASP authorisation?
It is the authorisation under Regulation (EU) 2023/1114 that permits a firm to provide crypto-asset services in the European Union. It is granted by the competent authority of the member state where the firm has its registered office, and it passports across the EEA, so one authorisation covers all member states for the services it names.
MiCA has been fully applicable since 30 December 2024. Before it, crypto-asset businesses operated under a patchwork of national regimes of very different depth — some prudential, most anti-money-laundering only. MiCA replaced that with a single authorisation standard carrying prudential, governance, conduct and client-asset obligations.
Two scope points decide whether it is the right licence at all. MiCA excludes crypto-assets that qualify as financial instruments under MiFID II by Article 2(4), so a firm dealing in tokenized securities needs MiFID II permissions instead. And the authorisation attaches to a legal entity and to named services, not to a brand or a group.
Substance is part of the test rather than a formality. A registered office in the Union, at least one director resident in the Union, and effective management exercised from within it are expected. Letterbox structures are the specific pattern supervisors have spent two years learning to identify, and the assessment reflects that.
Which services are in scope?
Ten, and an authorisation covers only those the firm applied and was assessed for. A firm authorised to exchange crypto-assets is not thereby permitted to hold them for clients. This is the distinction most often blurred in marketing material, and it is visible on the register.
| Service | What it involves | Typical own-funds class |
|---|---|---|
| Custody and administration of crypto-assets on behalf of clients | Holding client crypto-assets or the means of access, with segregation, a position register and liability for loss | Class 2 |
| Operation of a crypto-asset trading platform | Running a venue matching buyers and sellers | Class 3 |
| Exchange of crypto-assets for funds | Dealing against fiat currency | Class 2 |
| Exchange of crypto-assets for other crypto-assets | Dealing between crypto-assets | Class 2 |
| Execution of orders on behalf of clients | Acting on client instructions | Class 2 |
| Placing of crypto-assets | Marketing and placing on behalf of an offeror | Class 2 |
| Reception and transmission of orders | Passing orders to another party for execution | Class 1 |
| Advice on crypto-assets | Personal recommendations | Class 1 |
| Portfolio management of crypto-assets | Discretionary management of client portfolios | Class 1 |
| Transfer services on behalf of clients | Moving crypto-assets between addresses for clients | Class 1 |
Alongside the service permissions come obligations applying to every CASP: fit-and-proper management, governance and conflicts arrangements, complaints handling, outsourcing oversight, ICT and operational resilience, safekeeping of client funds and assets, and disclosure to clients.
Map services rather than projects. A single tokenized issuance can touch a MiFID II permission for placement, a MiCA permission for custody of any crypto-assets held, and a payment or e-money authorisation for the cash leg — three permissions across three entities, which is normal and needs documenting.
What passport does it carry across the EEA?
A full services passport for the activities named in the authorisation. A CASP authorised in one member state may provide those services to clients in any other, either cross-border or through a branch, after notifying its home authority, which informs the host. There is no second authorisation and no host-state approval.
That is the commercial point of MiCA and the reason the effort is concentrated rather than repeated. Before MiCA, serving twenty-seven markets meant assessing twenty-seven national regimes; now it means one authorisation and a notification process, with supervision remaining primarily with the home authority.
Two limits are worth stating. The passport covers only the services in the authorisation — adding a service requires an extension, assessed like a new application. And it does not extend to financial instruments: no MiCA passport permits the issuance, placement or trading of tokenized securities, which is MiFID II territory with its own passport.
Reverse solicitation is not a substitute for the passport, and it is narrowing. A firm outside the EU serving EU clients on the basis that they approached it first is relying on a limited exemption that supervisors interpret strictly. Read which regime applies to your instrument in the first place.
Why is a national VASP registration not the same thing?
Because a VASP registration is anti-money-laundering supervision, not permission to provide a service. It records that a firm conducting virtual-asset business is subject to AML obligations under national law implementing FATF standards. It carries no prudential requirement, no client-asset regime, no conduct rules and no passport.
| VASP registration | MiCA CASP authorisation | |
|---|---|---|
| Legal basis | National AML legislation, derived from FATF standards | Regulation (EU) 2023/1114 |
| What it permits | Nothing in itself | The specific services named in the authorisation |
| Own funds | None as such | By service class, plus governance and resilience obligations |
| Client-asset protection | Not its subject | Segregation, position register, liability for loss |
| Conduct obligations | AML only | Full conduct, disclosure and complaints regime |
| Passport | No | Yes, across the EEA |
| Supervisor | National AML supervisor | National competent authority under MiCA |
Applied to ourselves
Fortuna is registered as a Virtual Asset Service Provider with the Central Bank of Ireland (register ref C459043, under s.106A of the Criminal Justice (Money Laundering and Terrorist Financing) Acts), with MiCA CASP authorisation in process and not yet effective. Until that authorisation is granted, Fortuna is not authorised to provide MiCA crypto-asset services, and nothing in our material should be read as saying otherwise.
We publish it in those words deliberately. This is the distinction most often softened in this market, and a firm that explains it clearly and then applies a flattering version of it to itself has explained nothing. A pending authorisation is an application under assessment by a supervisor whose decision is not ours to predict. The correct description is "in process, not yet effective" — and the group’s live regulated capability for tokenized securities is issuance and placement through Black Manta Capital Partners, which is BaFin-licensed under MiFID II.
What are the capital and governance requirements?
Own funds are set by service class: €50,000, €125,000 or €150,000 depending on the services provided, or one quarter of the preceding year’s fixed overheads, whichever is higher. In absolute terms the capital is modest. It is not what makes authorisation hard.
| Class | Indicative services | Minimum own funds |
|---|---|---|
| Class 1 | Reception and transmission of orders, advice, portfolio management, transfer services | €50,000 |
| Class 2 | Custody and administration, exchange, execution of orders, placing | €125,000 |
| Class 3 | Operation of a crypto-asset trading platform | €150,000 |
| All classes | Alternative floor applying in every case | One quarter of the preceding year’s fixed overheads, if higher |
What the assessment actually turns on is the operation. Fit-and-proper and collective-competence assessment of the management body. Suitability of qualifying shareholders and a clear group structure. Governance, conflicts and complaints arrangements. Client-asset segregation and position registers. ICT and operational resilience aligned with the EU framework. AML systems and controls, including transfer-of-funds information requirements. And a business plan that survives scrutiny with capital evidenced.
The pattern in slow and failed applications is consistent: firms that describe an intended operation rather than an existing one. Supervisors are assessing a functioning firm, so the sequence that works is to build the controls, run them, document them as they operate, then apply.
How long does authorisation take, and which jurisdiction should you choose?
Nine to eighteen months from serious preparation to authorisation is realistic, of which the statutory assessment is the shorter part. The authority checks completeness within a short defined window and then assesses substance within a set period, but the clock stops whenever information is requested, and it is requested.
Choose on supervisory fit and the ability to staff real substance, not on perceived speed. Every CASP authorisation passports identically, so the licence is the same wherever granted; what differs is the authority’s expectations, its familiarity with your model, the local talent pool and the cost of maintaining genuine management presence.
| Jurisdiction | Competent authority | Indicative timeline | Capital requirement | Notable authorisations granted | Practical notes |
|---|---|---|---|---|---|
| Ireland | Central Bank of Ireland | 12–18 months | Class-based, per MiCA | Authorisations granted to payments-adjacent and institutional firms | Documentation-heavy; strong emphasis on governance, substance and AML; extensive pre-application engagement expected |
| Luxembourg | CSSF | 12–18 months | Class-based, per MiCA | Authorisations granted to fund-servicing and institutional firms | Fund-industry oriented and precise; suits firms serving asset managers; fund-industry cost levels |
| Germany | BaFin | 12–18 months | Class-based, per MiCA | Authorisations granted to trading and custody firms; also DLT Pilot Regime permissions | Rigorous and technically deep; experience with crypto securities and DLT infrastructure; parts of the process in German |
| Malta | MFSA | 9–15 months | Class-based, per MiCA | Authorisations granted to exchanges migrating from the earlier national VFA regime | Long-standing crypto-specific experience predating MiCA; some counterparties apply extra jurisdictional scrutiny |
| Lithuania | Bank of Lithuania | 9–15 months | Class-based, per MiCA | Authorisations granted to payments-adjacent and smaller-balance-sheet firms | Pragmatic and used to fintech volume; substance expectations have tightened materially since 2024 |
| Netherlands | AFM (with DNB for prudential aspects) | 12–18 months | Class-based, per MiCA | Authorisations granted to established trading and brokerage firms | Experienced supervisor with a large pre-MiCA registered population; expects mature control frameworks |
Two selection criteria matter more than any table. Has this authority authorised a firm doing what you intend to do — a supervisor with a comparable precedent asks better questions and decides faster. And can you place real substance there: a resident director, effective management, and control functions physically present.
What are the alternatives to applying yourself?
Three, each with an honest cost. Rely on an existing authorisation if you hold one that covers the services — credit institutions and certain other authorised firms may provide some crypto-asset services under their existing licence with notification rather than a full CASP application. Restrict scope so no in-scope service is provided. Or partner with an authorised entity.
Partnering is common and legitimate, and it should be described plainly rather than sold. The authorised firm performs the regulated service and carries the regulatory responsibility; you perform what is not regulated, under a written agreement allocating activities. The trade is time and cost against control: you reach the market without an application, and the permission stays with the other firm. Outsourcing rules apply to that firm’s reliance on you, and regulators expect the division to be real.
Restricting scope is underrated. Many business models touch only one in-scope service, and removing it — by routing custody to an authorised custodian, for instance — can take a firm outside the perimeter entirely while it decides whether to apply.
The decision rule: if crypto-asset services are your business, apply, because the licence is the asset. If they are adjacent, partner or restrict, and revisit when volumes justify the build. Read how many firms actually hold an authorisation, which custody permission applies to your instrument, or the EU regulatory stack for tokenized securities.
The cluster hub: where a CASP authorisation sits in the stack.
Why custody of an instrument is a different permission.
Roughly one in six of the pre-MiCA population.
- Regulation (EU) 2023/1114 (MiCA): crypto-asset services, authorisation, passporting, own funds by class, EU Official Journal, 2023. Fully applicable from 30 December 2024.
- Directive 2014/65/EU (MiFID II), Annex I Section C, EU Official Journal, 2014.
- ESMA and national competent authority registers of authorised crypto-asset service providers.
- Regulator materials from the Central Bank of Ireland, CSSF, BaFin, MFSA, Bank of Lithuania, AFM and DNB.
- Jurisdiction characterisations and timelines are COSIMO Digital’s own assessment as of July 2026 and are not legal advice.
- COSIMO Digital regulatory authorisations, described as of 28 July 2026. Pending authorisations are not effective until granted.
This page is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorisations are described as of the date stated; pending authorisations are not effective until granted.
← All Learn articles