Skip to content
European regulation

What is a MiCA CASP authorisation and who needs one?

The services in scope, the passport it carries, and why a national VASP registration is not the same thing.

Last updated:
By Ciarán Hynes · 11 min read

A MiCA CASP authorisation permits a firm to provide defined crypto-asset services across the EEA under a single licence, passported from one competent authority. It covers custody, exchange, execution, placement, transfer, advice and portfolio management. A national VASP registration is an anti-money-laundering registration only. It carries no passport and no authorisation to provide those services.

What is a MiCA CASP authorisation?

It is the authorisation under Regulation (EU) 2023/1114 that permits a firm to provide crypto-asset services in the European Union. It is granted by the competent authority of the member state where the firm has its registered office, and it passports across the EEA, so one authorisation covers all member states for the services it names.

MiCA has been fully applicable since 30 December 2024. Before it, crypto-asset businesses operated under a patchwork of national regimes of very different depth — some prudential, most anti-money-laundering only. MiCA replaced that with a single authorisation standard carrying prudential, governance, conduct and client-asset obligations.

Two scope points decide whether it is the right licence at all. MiCA excludes crypto-assets that qualify as financial instruments under MiFID II by Article 2(4), so a firm dealing in tokenized securities needs MiFID II permissions instead. And the authorisation attaches to a legal entity and to named services, not to a brand or a group.

Substance is part of the test rather than a formality. A registered office in the Union, at least one director resident in the Union, and effective management exercised from within it are expected. Letterbox structures are the specific pattern supervisors have spent two years learning to identify, and the assessment reflects that.

Which services are in scope?

Ten, and an authorisation covers only those the firm applied and was assessed for. A firm authorised to exchange crypto-assets is not thereby permitted to hold them for clients. This is the distinction most often blurred in marketing material, and it is visible on the register.

Crypto-asset services under MiCA. An authorisation names which of these it covers.
ServiceWhat it involvesTypical own-funds class
Custody and administration of crypto-assets on behalf of clientsHolding client crypto-assets or the means of access, with segregation, a position register and liability for lossClass 2
Operation of a crypto-asset trading platformRunning a venue matching buyers and sellersClass 3
Exchange of crypto-assets for fundsDealing against fiat currencyClass 2
Exchange of crypto-assets for other crypto-assetsDealing between crypto-assetsClass 2
Execution of orders on behalf of clientsActing on client instructionsClass 2
Placing of crypto-assetsMarketing and placing on behalf of an offerorClass 2
Reception and transmission of ordersPassing orders to another party for executionClass 1
Advice on crypto-assetsPersonal recommendationsClass 1
Portfolio management of crypto-assetsDiscretionary management of client portfoliosClass 1
Transfer services on behalf of clientsMoving crypto-assets between addresses for clientsClass 1

Alongside the service permissions come obligations applying to every CASP: fit-and-proper management, governance and conflicts arrangements, complaints handling, outsourcing oversight, ICT and operational resilience, safekeeping of client funds and assets, and disclosure to clients.

Map services rather than projects. A single tokenized issuance can touch a MiFID II permission for placement, a MiCA permission for custody of any crypto-assets held, and a payment or e-money authorisation for the cash leg — three permissions across three entities, which is normal and needs documenting.

What passport does it carry across the EEA?

A full services passport for the activities named in the authorisation. A CASP authorised in one member state may provide those services to clients in any other, either cross-border or through a branch, after notifying its home authority, which informs the host. There is no second authorisation and no host-state approval.

That is the commercial point of MiCA and the reason the effort is concentrated rather than repeated. Before MiCA, serving twenty-seven markets meant assessing twenty-seven national regimes; now it means one authorisation and a notification process, with supervision remaining primarily with the home authority.

Two limits are worth stating. The passport covers only the services in the authorisation — adding a service requires an extension, assessed like a new application. And it does not extend to financial instruments: no MiCA passport permits the issuance, placement or trading of tokenized securities, which is MiFID II territory with its own passport.

Reverse solicitation is not a substitute for the passport, and it is narrowing. A firm outside the EU serving EU clients on the basis that they approached it first is relying on a limited exemption that supervisors interpret strictly. Read which regime applies to your instrument in the first place.

Why is a national VASP registration not the same thing?

Because a VASP registration is anti-money-laundering supervision, not permission to provide a service. It records that a firm conducting virtual-asset business is subject to AML obligations under national law implementing FATF standards. It carries no prudential requirement, no client-asset regime, no conduct rules and no passport.

VASP registration and MiCA CASP authorisation compared.
VASP registrationMiCA CASP authorisation
Legal basisNational AML legislation, derived from FATF standardsRegulation (EU) 2023/1114
What it permitsNothing in itselfThe specific services named in the authorisation
Own fundsNone as suchBy service class, plus governance and resilience obligations
Client-asset protectionNot its subjectSegregation, position register, liability for loss
Conduct obligationsAML onlyFull conduct, disclosure and complaints regime
PassportNoYes, across the EEA
SupervisorNational AML supervisorNational competent authority under MiCA

Applied to ourselves

Fortuna is registered as a Virtual Asset Service Provider with the Central Bank of Ireland (register ref C459043, under s.106A of the Criminal Justice (Money Laundering and Terrorist Financing) Acts), with MiCA CASP authorisation in process and not yet effective. Until that authorisation is granted, Fortuna is not authorised to provide MiCA crypto-asset services, and nothing in our material should be read as saying otherwise.

We publish it in those words deliberately. This is the distinction most often softened in this market, and a firm that explains it clearly and then applies a flattering version of it to itself has explained nothing. A pending authorisation is an application under assessment by a supervisor whose decision is not ours to predict. The correct description is "in process, not yet effective" — and the group’s live regulated capability for tokenized securities is issuance and placement through Black Manta Capital Partners, which is BaFin-licensed under MiFID II.

What are the capital and governance requirements?

Own funds are set by service class: €50,000, €125,000 or €150,000 depending on the services provided, or one quarter of the preceding year’s fixed overheads, whichever is higher. In absolute terms the capital is modest. It is not what makes authorisation hard.

Own-funds requirements by class, per Regulation (EU) 2023/1114. Confirm against the current consolidated text before relying on these figures.
ClassIndicative servicesMinimum own funds
Class 1Reception and transmission of orders, advice, portfolio management, transfer services€50,000
Class 2Custody and administration, exchange, execution of orders, placing€125,000
Class 3Operation of a crypto-asset trading platform€150,000
All classesAlternative floor applying in every caseOne quarter of the preceding year’s fixed overheads, if higher

What the assessment actually turns on is the operation. Fit-and-proper and collective-competence assessment of the management body. Suitability of qualifying shareholders and a clear group structure. Governance, conflicts and complaints arrangements. Client-asset segregation and position registers. ICT and operational resilience aligned with the EU framework. AML systems and controls, including transfer-of-funds information requirements. And a business plan that survives scrutiny with capital evidenced.

The pattern in slow and failed applications is consistent: firms that describe an intended operation rather than an existing one. Supervisors are assessing a functioning firm, so the sequence that works is to build the controls, run them, document them as they operate, then apply.

How long does authorisation take, and which jurisdiction should you choose?

Nine to eighteen months from serious preparation to authorisation is realistic, of which the statutory assessment is the shorter part. The authority checks completeness within a short defined window and then assesses substance within a set period, but the clock stops whenever information is requested, and it is requested.

Choose on supervisory fit and the ability to staff real substance, not on perceived speed. Every CASP authorisation passports identically, so the licence is the same wherever granted; what differs is the authority’s expectations, its familiarity with your model, the local talent pool and the cost of maintaining genuine management presence.

Six common jurisdictions. Characterisations are COSIMO Digital’s own from public regulator material and market practice as of July 2026, and are not legal advice; timelines are indicative and vary with application quality.
JurisdictionCompetent authorityIndicative timelineCapital requirementNotable authorisations grantedPractical notes
IrelandCentral Bank of Ireland12–18 monthsClass-based, per MiCAAuthorisations granted to payments-adjacent and institutional firmsDocumentation-heavy; strong emphasis on governance, substance and AML; extensive pre-application engagement expected
LuxembourgCSSF12–18 monthsClass-based, per MiCAAuthorisations granted to fund-servicing and institutional firmsFund-industry oriented and precise; suits firms serving asset managers; fund-industry cost levels
GermanyBaFin12–18 monthsClass-based, per MiCAAuthorisations granted to trading and custody firms; also DLT Pilot Regime permissionsRigorous and technically deep; experience with crypto securities and DLT infrastructure; parts of the process in German
MaltaMFSA9–15 monthsClass-based, per MiCAAuthorisations granted to exchanges migrating from the earlier national VFA regimeLong-standing crypto-specific experience predating MiCA; some counterparties apply extra jurisdictional scrutiny
LithuaniaBank of Lithuania9–15 monthsClass-based, per MiCAAuthorisations granted to payments-adjacent and smaller-balance-sheet firmsPragmatic and used to fintech volume; substance expectations have tightened materially since 2024
NetherlandsAFM (with DNB for prudential aspects)12–18 monthsClass-based, per MiCAAuthorisations granted to established trading and brokerage firmsExperienced supervisor with a large pre-MiCA registered population; expects mature control frameworks

Two selection criteria matter more than any table. Has this authority authorised a firm doing what you intend to do — a supervisor with a comparable precedent asks better questions and decides faster. And can you place real substance there: a resident director, effective management, and control functions physically present.

What are the alternatives to applying yourself?

Three, each with an honest cost. Rely on an existing authorisation if you hold one that covers the services — credit institutions and certain other authorised firms may provide some crypto-asset services under their existing licence with notification rather than a full CASP application. Restrict scope so no in-scope service is provided. Or partner with an authorised entity.

Partnering is common and legitimate, and it should be described plainly rather than sold. The authorised firm performs the regulated service and carries the regulatory responsibility; you perform what is not regulated, under a written agreement allocating activities. The trade is time and cost against control: you reach the market without an application, and the permission stays with the other firm. Outsourcing rules apply to that firm’s reliance on you, and regulators expect the division to be real.

Restricting scope is underrated. Many business models touch only one in-scope service, and removing it — by routing custody to an authorised custodian, for instance — can take a firm outside the perimeter entirely while it decides whether to apply.

The decision rule: if crypto-asset services are your business, apply, because the licence is the asset. If they are adjacent, partner or restrict, and revisit when volumes justify the build. Read how many firms actually hold an authorisation, which custody permission applies to your instrument, or the EU regulatory stack for tokenized securities.

Related
Sources
  • Regulation (EU) 2023/1114 (MiCA): crypto-asset services, authorisation, passporting, own funds by class, EU Official Journal, 2023. Fully applicable from 30 December 2024.
  • Directive 2014/65/EU (MiFID II), Annex I Section C, EU Official Journal, 2014.
  • ESMA and national competent authority registers of authorised crypto-asset service providers.
  • Regulator materials from the Central Bank of Ireland, CSSF, BaFin, MFSA, Bank of Lithuania, AFM and DNB.
  • Jurisdiction characterisations and timelines are COSIMO Digital’s own assessment as of July 2026 and are not legal advice.
  • COSIMO Digital regulatory authorisations, described as of 28 July 2026. Pending authorisations are not effective until granted.

This page is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorisations are described as of the date stated; pending authorisations are not effective until granted.

← All Learn articles