MiCA / CASP Authorisation
Token classification drives everything — so that’s where this guide starts. ~12 min for crypto & digital-asset firms.
The EU’s crypto regime is in force and the transitional windows for unlicensed firms are closing through 2026. This guide walks the path to authorisation — starting, as MiCA does, with what your token actually is.
Dossier
- For
- Crypto exchanges, token issuers, stablecoin and tokenisation projects, and digital-asset firms operating in the EU.
- Covers
- Scope · token classification · CASP application · jurisdiction · financial-crime alignment.
- Why now
- MiCA is in force; transitional cut-offs for unlicensed firms are closing across member states through 2026.
- Starts with
- Token classification — it drives the entire compliance path, so it comes first.
Are you in scope?
MiCA generally requires authorisation as a crypto-asset service provider (CASP) if you provide crypto-asset services to EU customers — trading, custody, exchange, advice, and more. As with the other EU regimes, serving European users from abroad doesn’t put you outside it by default.
So the first question is simple to ask and consequential to answer: do your activities fall within MiCA’s defined services, and for EU customers? Confirm this before anything else, because it determines whether the rest of the path applies to you at all.
Classify your token — it drives everything
MiCA’s whole compliance path branches off how your asset is classified, so this is where the work starts — not where it ends. Get it wrong and you build toward the wrong regime entirely.
- Utility token — provides access to a good or service on your platform.
- Asset-referenced token (ART) — aims to hold value by referencing several assets, currencies, or a basket.
- E-money token (EMT) — references a single official currency; the stablecoin-style category.
- Financial instrument — some assets fall under existing financial-markets rules instead of MiCA, with a different rulebook altogether.
Build the CASP application
Authorisation as a CASP is a substantive application, assessed against requirements that mirror other regulated-firm regimes. The core areas supervisors scrutinise:
- Governance — a sound structure with people genuinely accountable for the firm.
- Capital — meeting the prudential requirements that attach to your services.
- Custody — how client assets are held, segregated, and protected.
- The submission pack — assembled and evidenced the way your chosen authority expects.
Tailor it to your business type. The shape of the application differs by what you are. Exchanges and trading platforms, token issuers running a launch, and RWA / tokenisation platforms each carry their own emphasis and their own pressure points — a one-size pack doesn’t survive review.
Align your financial-crime controls
CASP authorisation runs alongside AML obligations, including the Travel Rule for crypto transfers. These can’t be bolted on at the end — supervisors expect a credible financial-crime framework as part of the application, and it has to match how your product actually moves value.
Treat AML and Travel-Rule controls as part of the authorisation workstream from the start, coordinated with the rest of your compliance build rather than run as a separate, later project.
Mind the 2026 deadlines
MiCA is already in force, and the transitional windows that let unlicensed firms keep operating are closing across member states through 2026 — with some national cut-offs already set. Firms that pass their deadline without authorisation risk having to stop EU activity.
That makes timing as important as substance. Because classification, the application build, and financial-crime alignment all take real time, the firms that move early are the ones that stay live through the transition. Working backwards from the cut-off that binds you is the difference between a planned authorisation and a forced pause.
Get licensed before the window closes
Want it done for you? See our Digital Asset Licensing solution, explore the Fintech Licensing Hub, or try Compass (our MiCA assistant) and Navigator (our token classifier).
More from the journal
See allFATF Publishes Targeted Report on DeFi Regulatory Challenges, 21 July 2026
On 21 July 2026, the Financial Action Task Force published its Targeted Report on Regulatory Challenges from Decentralised Finance. The report finds that 93% of surveyed jurisdictions have not implemented FATF Recommendation 15 as it applies to qualifying DeFi arrangements, and only two jurisdictions have licensed or registered a DeFi arrangement. The FATF issues recommendations to jurisdictions and DeFi operators to close identified regulatory gaps and reduce illicit finance risk.
EU Digital Omnibus Regulation 2026/1744 Enters Into Force, Extending AI Act Compliance Timelines
Regulation (EU) 2026/1744 (the AI Digital Omnibus) entered into force on 27 July 2026, amending the EU AI Act to extend compliance timelines for high-risk AI systems. Operators covering Annex III sectors have until 2 December 2027 to meet Chapter III obligations. AI systems embedded in Annex I products have until 2 August 2028. The Omnibus cites CEN and CENELEC standardisation delays as justification for both extensions.
EU AI Act Article 50 Transparency Obligations Apply from 2 August 2026
Article 50 of Regulation (EU) 2024/1689 (the EU AI Act) takes general application on 2 August 2026. Providers of interactive AI systems must notify users they are communicating with an AI and embed machine-readable marks in AI-generated content. Deployers must inform individuals exposed to deep fakes and AI-generated public-interest content published without human review. The European Commission published final implementation guidelines on 20 July 2026.
Where to go from here
Try Licentium AI
Licentium's AI workspace for regulatory questions. Web3 and AI teams shipping fast.
Browse the Fintech Licensing Hub
Jurisdiction-by-jurisdiction guides on licensing pathways, timelines, and costs.
Talk to us
Book a 30-minute consultation. We'll map your path and tell you what's required.