Executive Summary
- A standalone applicant applies to its home Member State’s competent authority. The authorisation covers specified services. Certain already-regulated financial entities can instead use Article 60, within its service limits and notification requirements. MiCA, Articles 59–63.
- The applicant needs an eligible EU establishment, effective management in the Union and at least one EU-resident director. Its documents must substantiate the proposed business, management, ownership and operating controls. MiCA, Articles 59(2), 62 and 68.
- A standalone CASP’s prudential safeguards must meet the higher of the applicable €50,000, €125,000 or €150,000 service-class floor and one quarter of fixed overheads. These amounts are separate from application fees. MiCA, Article 67 and Annex IV.
- The regulator has 25 working days to check completeness and 40 working days to assess a complete application. Missing information, permitted suspensions and updated application information can extend the process. MiCA, Article 63; Implementing Regulation (EU) 2025/306, Article 4.
- The latest transitional period ended on 1 July 2026. An outstanding application does not authorise continued ordinary business. Following approval, cross-border provision requires the Article 65 notification procedure. MiCA, Articles 59, 65 and 143(3).
Services requiring authorisation
A business must identify its proposed services before selecting the application route. MiCA requires permission for professional provision of the services defined in Article 3(1)(16), subject to its exclusions and exceptions. The commercial label attached to a product does not determine which permission it needs. MiCA, Articles 2, 3(1)(15)–(26) and 59.
The ten service categories cover custody and administration, operating a trading platform, crypto-to-funds exchange and crypto-to-crypto exchange. They also cover order execution, placing, reception and transmission of orders, advice, portfolio management and transfers on clients’ behalf. The definitions distinguish a platform matching third-party interests from a firm exchanging against its own capital. A business combining those activities must assess each service separately. MiCA, Article 3(1)(16)–(26).
Asset classification precedes that assessment. MiCA excludes crypto-assets qualifying as financial instruments, along with other categories listed in Article 2(4). It also excludes genuinely unique, non-fungible crypto-assets and services provided exclusively within the specified parent-subsidiary relationships. A CASP application cannot replace the permissions required under legislation governing an excluded asset. MiCA, Article 2(2)(a), (3) and (4).
A specific exemption also covers custody and transfers involving crypto-assets whose public offers qualify under Article 4(3). It fails where another public offer of the same asset is non-exempt or the asset is admitted to a trading platform. The Article 4(3) exemption also does not apply where the offeror, or a person acting on its behalf, communicates an intention to seek admission to trading. The offer’s exemption therefore needs checking alongside the proposed service. MiCA, Article 4(3)–(5).
Issuing asset-referenced tokens or e-money tokens requires a separate assessment under MiCA’s issuer provisions. Permission to provide services involving those tokens does not itself satisfy the issuer requirements. The relevant service application must identify the types of crypto-assets concerned. MiCA, Articles 16, 48 and 62(2)(s).
Standalone authorisation and the financial-entity route
Subject to any applicable exemption, a business outside Article 60 must obtain authorisation before providing in-scope services. The applicant submits its application to the competent authority of its home Member State. ESMA does not grant the standalone authorisation under that procedure. MiCA, Articles 59(1)(a), 62(1) and 63(9).
Article 60 provides a different route for specified financial entities. It covers credit institutions, central securities depositories, investment firms, market operators, electronic money institutions, UCITS management companies and alternative investment fund managers. Their permitted services depend on the category and, where required, equivalence with their existing authorisation. A payment institution does not qualify for this route merely because it holds that status. MiCA, Articles 59(1)(b) and 60(1)–(6).
A qualifying entity must notify the required information at least 40 working days before first providing the services. It cannot start while its notification remains incomplete. Existing financial-sector permission therefore requires a service-by-service assessment against Article 60, followed by the applicable notification. MiCA, Article 60(1)–(9).
Third-country businesses have a narrow exception where an EU client initiates the relevant service at its own exclusive initiative. Solicitation by the firm, its agents or specified connected persons defeats that exception. Contractual disclaimers cannot change the underlying facts. The exception also does not permit subsequent marketing of new types of crypto-assets or services to that client. MiCA, Article 61(1)–(2).
The expired transition
A new application cannot rely on the former national registration transition. Article 143(3) permitted qualifying existing providers to continue until authorisation or refusal, or 1 July 2026, whichever occurred first. Member States could shorten that period. None could extend it beyond the EU deadline under that provision. MiCA, Article 143(3).
An applicant still awaiting approval after that deadline needs another valid legal basis to provide services. Filing an application, or holding a former national virtual-asset registration, does not supply one. ESMA’s June 2026 statement distinguishes limited customer-exit actions during orderly wind-down from continued ordinary business. Those supervisory expectations do not create a replacement authorisation. MiCA, Article 59(1); ESMA, Public Statement ESMA75-113276571-1710, 23 June 2026, pp. 1–2.
Home Member State and management
The applicant’s registered office must be in a Member State where it carries out at least part of its crypto-asset services. Its place of effective management must be in the Union, and at least one director must be EU-resident. These are cumulative requirements. A registered address and a resident director alone do not establish compliance with the effective-management condition. MiCA, Article 59(2).
A legal person can apply. Other undertakings qualify only where their legal form affords equivalent third-party protection and equivalent prudential supervision. The chosen entity must therefore satisfy the eligibility conditions before its owners rely on the proposed structure. MiCA, Article 59(1)(a) and (3).
ESMA’s non-binding authorisation briefing directs supervisors to examine local decision-making powers, personnel and dependence on overseas group functions. Its expectations inform how authorities assess substance; they do not replace Article 59 with a different statutory residence test. An applicant using overseas technology or management functions must explain the EU entity’s actual powers and resources. ESMA, Supervisory Briefing ESMA75-453128700-1263, 31 January 2025, section 4.
Application documents and operating arrangements
The application must substantiate the business described in the requested permission. Article 62 specifies the required information. Delegated Regulation (EU) 2025/305 supplies the detailed requirements, while Implementing Regulation (EU) 2025/306 prescribes the application form and submission procedure. An applicant must use the form with the supporting information relevant to its services. The authority must publish its designated application contact point on its website. MiCA, Article 62; Delegated Regulation 2025/305, Articles 1–17; Implementing Regulation 2025/306, Articles 1–2 and Annex.
The programme of operations covers the three years following authorisation. It identifies proposed services, crypto-asset types, target clients, jurisdictions, marketing and allocated resources. Group arrangements and outsourced functions must be explained. Financial forecasts must address the prescribed stress scenarios. Those documents must describe the same proposed operation as the service permissions requested. Delegated Regulation 2025/305, Article 2.
The applicant must identify managers and qualifying owners and supply the required suitability and reputation evidence. Managers need appropriate knowledge, skills, experience and sufficient time for their responsibilities. Qualifying holdings include direct or indirect holdings of at least 10% of capital or voting rights, or holdings permitting significant influence. Ownership below 10% therefore does not automatically escape assessment. MiCA, Articles 3(1)(36), 62(2)(g)–(h), 62(3) and 68(1)–(2).
Operational documents must address internal controls, conflicts of interest, complaints, client-asset segregation and business continuity. The required anti-money laundering material concerns the applicant’s actual risks and controls. ICT documentation must explain the systems, security arrangements and resources supporting compliance with the Digital Operational Resilience Act (DORA). MiCA, Articles 62(2)(f), (i)–(l) and 68(7)–(8); Delegated Regulation 2025/305, Articles 4–6 and 9–11.
Service-specific documents follow the intended permissions. A custodian needs its custody and administration policy. A trading-platform operator needs operating rules and market-abuse detection arrangements. Exchange providers must explain their commercial policy and pricing methodology. Execution, advice, portfolio management and transfer services require their corresponding evidence. MiCA, Article 62(2)(m)–(r); Delegated Regulation 2025/305, Articles 12–17.
Outsourcing does not transfer the applicant’s responsibilities to its supplier or parent company. The CASP must retain expertise, resources and access to information needed to supervise outsourced work. Written agreements must preserve the required rights, including termination rights, and must not obstruct regulatory supervision. MiCA, Article 73(1)–(4).
Payment services require a separate permission check. Where the proposed operation includes payment services related to its crypto-asset services, the CASP or the relevant third-party provider must hold the required payment-services authorisation. MiCA, Article 70(4).
Prudential safeguards and the capital calculation
A standalone CASP must maintain safeguards equal to at least the higher of its service-class floor and the fixed-overheads calculation. Annex IV assigns €50,000 to Class 1 services: execution, placing, transfers, reception and transmission, advice and portfolio management. MiCA, Article 67(1) and Annex IV.
The floor rises to €125,000 for Class 2, which includes custody and either form of exchange. Operating a trading platform falls within Class 3, with a €150,000 floor. An applicant offering several services applies the relevant higher class; it does not add the three floors together. MiCA, Annex IV.
The second calculation is one quarter of the preceding year’s fixed overheads, with the deductions required by Article 67(3). Firms without a full year of crypto-asset service provision use projected fixed overheads for their first 12 months of service provision. The annual review and continuing maintenance obligations prevent reliance on an unchanged launch-day figure. MiCA, Article 67(1)–(3).
Assume a proposed custody provider has €800,000 in qualifying projected annual fixed overheads. The derived overhead requirement is €800,000 × 25% = €200,000. Because €200,000 exceeds the €125,000 class floor, the required safeguards are at least €200,000. This hypothetical calculation concerns prudential coverage, without application fees or operating expenditure. MiCA, Article 67(1)–(3) and Annex IV.
The safeguards may consist of eligible own funds, qualifying insurance or a comparable guarantee, or a combination. Own funds must satisfy Article 67(4)(a), including the required deductions. An insurance policy must satisfy the territorial, duration, cancellation, insurer and risk-coverage conditions. A general insurance certificate alone does not establish those elements. MiCA, Article 67(4)–(6).
Application fees and the launch budget
The prudential calculation does not establish the amount payable to the regulator. In the Netherlands, the AFM publishes an assessment rate of €200 per hour, capped at €100,000 for the application. It also publishes separate personal-assessment charges. The standard amounts are €700 for properness and €2,900 for suitability, with specified reductions following certain prior DNB assessments. Staatscourant 2024, 21638, Article I(A), items EU.A1.08 and EU.A8.08–EU.A8.11; AFM, Cost of licensing or notification.
The €100,000 figure is a ceiling for that Dutch application charge, not a fixed EU fee or an all-inclusive project price. Prudential resources, application charges and expenditure on staff, systems, advisers and outsourced services need separate budget treatment. The business plan must fund the operating resources described in the application, beyond paying the assessment invoice. MiCA, Article 67; Delegated Regulation 2025/305, Articles 2(1)(j)–(m) and 3.
Assessment deadlines
The regulator must acknowledge receipt within five working days and assess completeness within 25 working days of receipt. Those periods run from receipt; they are not consecutive stages totalling 30 working days. An incomplete application prompts a request for missing information and a deadline for supplying it. The authority may refuse to review a file that remains incomplete after that deadline. MiCA, Article 63(1)–(4).
The substantive assessment period is 40 working days from receipt of a complete application. The authority must adopt a reasoned decision and notify the applicant within five working days of that decision. These periods do not include the applicant’s preparation work. MiCA, Article 63(9).
During assessment, the authority may request further information no later than the twentieth working day. The resulting suspension cannot exceed 20 working days. Further requests do not create further suspensions under that provision. Separately, changes to application information must be notified without undue delay. Receipt of updated information restarts the Article 63(9) period under the implementing regulation. MiCA, Article 63(12); Implementing Regulation 2025/306, Article 4(1)–(2).
A fixed promise of approval within a stated number of calendar months therefore cannot be derived from these deadlines. The decision can be a refusal, and the clock depends on completeness, permitted suspension and updated information. MiCA, Article 63(2), (9), (10) and (12); Implementing Regulation 2025/306, Article 4(2).
Refusal and appeal
A complete file and sufficient financial safeguards do not guarantee authorisation. The authority must refuse where objective, demonstrable grounds establish the relevant management, reputation or compliance defects. Prospective failure to meet Title V requirements is itself a refusal ground. MiCA, Article 63(10).
Group structure can also prevent approval. Close links must not obstruct effective supervision. Where third-country law or difficulties enforcing it prevent the authority from supervising the applicant, the authority must refuse authorisation. An outsourcing contract cannot cure a structure that still prevents supervisory access. MiCA, Articles 63(7)–(8) and 73(1)(d).
Member States must provide a right of appeal to a court against the authority’s reasoned decision. That right also applies where a fully documented application receives no decision within six months of submission. Silence does not amount to authorisation under Article 59. MiCA, Articles 59(1) and 113(1).
Cross-border services and continuing obligations
An authorised CASP can provide its approved services across the Union through establishment or cross-border provision. Article 65 requires notification to the home authority before services begin in another Member State. The information includes the destination states, intended services and proposed start date. MiCA, Articles 59(7) and 65(1).
The home authority must communicate the information to the specified authorities within ten working days. The CASP may start when informed that communication has occurred, or at the latest 15 calendar days after submitting the required information. The 15-day period is a passporting commencement rule following authorisation. It does not replace the initial application assessment. MiCA, Article 65(2)–(4).
Permission remains limited to the authorised services, and additional services require an extension application. The CASP must continue meeting its authorisation conditions and notify relevant changes. False application statements, specified serious infringements and other statutory grounds can lead to withdrawal. MiCA, Articles 59(4), (6) and (8), and 64; Implementing Regulation 2025/306, Article 4(3).
