Solutions
The MiCA transitional period ran out on 1 July 2026 at the latest, earlier in many member states.
Digital Asset Licensing (MiCA / CASP)
The transition is over. MiCA is now simply what operating in the EU means — and the licence is the beginning, not the finish line.
The grandfathering era is over
For eighteen months, crypto firms in Europe lived in a transitional twilight: MiCA applied, but firms already operating under national regimes could keep going while their applications were pending. That twilight has ended. Under the regulation's own terms, the transitional period ran out on 1 July 2026 at the latest — and many member states closed their windows earlier. Today, providing crypto-asset services to EU customers means holding a CASP authorisation, full stop. Firms that didn't make the window have had to stop, restructure, or watch competitors with licences take their users.
Which puts everyone reading this page in one of three positions:
You're not licensed and you serve (or want to serve) EU customers. The transitional route is gone, but the front door is open: authorisation can be applied for at any time, and one licence passports across the entire Union. What's changed is that there is no longer a lawful way to operate while you wait.
You're a non-EU firm eyeing the EU market. The perimeter is real. "Reverse solicitation" — waiting for EU clients to come to you — is construed narrowly by the European supervisors and is not a market-entry strategy. Serving the EU means an EU-authorised entity.
You're licensed. Congratulations — now the operating obligations run forever, and the next regulatory waves (the AML single rulebook, potential direct EU supervision for the largest firms) are already scheduled. The licence was the entry ticket; staying licensed is the job.
We work all three lanes: getting the authorisation, structuring the entry, and running the licensed reality.
Classification first: everything follows from what the token is
MiCA's compliance paths are sorted by asset type, so classification is where every engagement starts — and where mistakes are most expensive:
The default MiCA category. Public offers generally require a white paper — drafted to the prescribed content and notified to the regulator, not pre-approved — plus the marketing and conduct rules.
Tokens stabilised against a basket of values. Issuance requires authorisation, reserve backing, and ongoing prudential obligations — the heavyweight route.
Tokens referencing a single fiat currency — functionally, regulated stablecoins. Here MiCA makes a structural choice: only credit institutions and e-money institutions may issue EMTs. For a non-bank, the EMI licence is the gateway to stablecoin issuance — which is why we plan EMT projects together with the payments licensing workstream, not after it.
Some tokens aren't in MiCA at all — they're securities, and MiFID's world applies instead. Getting this boundary wrong in either direction is the classic classification failure.
And the genuine out-of-scope cases — truly unique NFTs, fully decentralised services with no intermediary — exist but are narrower than founders hope, and fractionalisation or de-facto centralisation pulls them back in. Classification is a legal analysis of what your asset does, not of what the website calls it.
(For token issuers who want to self-navigate first: our Navigator tool walks through classification and the obligations that follow — and this engagement picks up where it ends.)
The CASP licence: what it covers, what it costs in capital
A CASP authorisation covers the crypto-asset services you're approved for — MiCA lists ten, and your application is built around your actual set:
- custody and administration
- operation of a trading platform
- exchange of crypto-assets for funds
- exchange of crypto-assets for other crypto-assets
- execution of orders
- placing
- reception and transmission of orders
- advice
- portfolio management
- transfer services
Initial capital scales with the service class under the regulation:
- CLASS 1€50,000advisory and order-handling services
- CLASS 2€125,000including custody and exchange services
- CLASS 3€150,000operating a trading platform
Ongoing own funds must be the higher of that floor or a quarter of the previous year's fixed overheads. One authorisation, granted by one national regulator, passports the approved services across every EU member state.
The application: what the regulator actually reads
A CASP application is a dossier describing a real, operable firm. The recurring skeleton, from the regulation and the European supervisors' standards:
- Programme of operations — which of the ten services, precisely mapped to your product
- Governance: management body, fit-and-proper for directors and qualifying shareholders
- Prudential: initial capital evidence and own-funds maintenance
- Custody policy — segregation of clients' crypto-assets and funds, wallet architecture, access controls
- ICT and operational resilience — DORA applies to CASPs since January 2025: ICT risk management, incident reporting, resilience testing, third-party (cloud/custody tech) risk
- AML/CFT programme — the financial-crime package, built in, not bolted on
- Complaints handling, conflicts of interest, outsourcing arrangements
- Market-abuse prevention arrangements for trading venues
- White papers and marketing-communication compliance where you issue or promote
Regulators grade whether the documents describe an institution that actually exists and runs. That's the standard we draft to — and why our applications are built with the operating team, not delivered to them.
The stablecoin lane
ARTs and EMTs carry their own supervisory weight: reserve assets, redemption rights at par, issuance limits monitoring — and significant tokens graduate to supervision involving the European Banking Authority. If your roadmap includes a fiat-referenced token, the sequencing question (EMI first? which member state? issuer entity vs. operating entity?) is a structure decision with long consequences — one we design together with the incorporation and payments workstreams.
After the licence: the waves already scheduled
The authorisation is not the end-state; it's admission to a regime that keeps moving:
- Since December 2024LIVEThe Travel Rule already applies: originator/beneficiary information on crypto transfers, no minimum threshold, self-hosted address procedures.
- Since January 2025LIVEDORA applies to CASPs: ICT risk management, incident reporting, resilience testing, third-party (cloud/custody tech) risk.
- 10 July 2027AHEADThe AML single rulebook (AMLR) applies from 10 July 2027 — CASPs are obliged entities EU-wide, with customer due diligence for occasional transactions from €1,000 and prohibitions on anonymity-enhancing instruments.
- 2028AHEADAMLA, the new EU AML authority, begins direct supervision in 2028 — and the selection criteria (cross-border footprint, risk profile) put large CASPs squarely in the candidate pool.
- Marketing rules bind every campaign — fair, clear, not misleading, consistent with your white paper. (Screening your marketing against exactly these expectations is what our Atlas tool does.)
- And the rulebook itself keeps landing — technical standards and supervisory guidance continue to arrive; tracking them is what Horizon is for.
Licensed clients keep us for precisely this layer: the licence as a living thing, not a framed certificate.
The UK side Serving UK clients? MiCA doesn't reach the UK — the FCA's authorisation gateway runs 30 Sep 2026 – 28 Feb 2027, with the mandatory regime from 25 Oct 2027 and no conversion for MLR-registered firms. Read the guide →
Our approach
- 1Scope and classification.What your assets and services are in MiCA's terms — token taxonomy, service mapping against the ten, and the honest out-of-scope analysis.
- 2Route and jurisdiction strategy.Where to authorise and why: supervisory culture, speed, substance expectations, banking access — and how passporting carries the licence across the Union.
- 3CASP authorisation build.The full dossier: governance, capital, custody policy, DORA-grade ICT arrangements, conflicts, complaints, outsourcing — drafted with your operating team.
- 4Financial-crime programme.The AML/CFT package coordinated with our dedicated AML workstream — Travel Rule operations included, AMLR-ready by design.
- 5Stablecoin and issuer routes.White papers for utility offers; the ART authorisation path; the EMI-gateway plan for EMTs — sequenced with payments licensing and structure work.
- 6Through authorisation and beyond.Regulator questions and requisitions, operational readiness, and the post-licence layer: ongoing obligations, marketing compliance, and monitoring wired in.
For step two, you can set the candidate regimes side by side in the jurisdiction comparator on the Fintech Licensing Hub.
Who it's for — by business type
- Exchanges and trading platforms — Class 3 capital, market-abuse arrangements, custody at scale, DORA resilience.
- Token issuers and launches — classification, white papers, marketing rules, and the offer mechanics.
- Stablecoin projects — the EMT/ART decision, the EMI gateway, reserve and redemption design.
- RWA and tokenisation platforms — where the MiCA/MiFID boundary is the whole game.
- Custodians, wallets and transfer services — custody policy, Travel Rule operations, safeguarding client assets.
- Non-EU firms entering the EU — entity, licence and substance strategy for a lawful market entry.
FAQ
If you provide crypto-asset services to EU customers — trading, custody, exchange, advice and the rest of MiCA's ten services — you need authorisation as a crypto-asset service provider. We confirm whether your activities fall in scope, and under which service classes.
Yes — authorisation can be applied for at any time; what ended on 1 July 2026 (earlier in many member states) was the right to keep operating while unlicensed. The practical difference: you can no longer serve EU customers during the application. We structure the interim — what stops, what can lawfully continue, and the fastest credible route to authorisation.
Only in the narrowest sense. The European supervisors read the exemption strictly: it covers genuinely client-initiated contact for that service, not a business model. Marketing into the EU in any form defeats it. It is not a market-entry strategy.
MiCA distinguishes utility and other crypto-assets, asset-referenced tokens, and e-money tokens — and some assets fall under existing financial-instrument rules instead. Classification drives the entire compliance path, which is why it's where we start.
For e-money tokens — tokens referencing one fiat currency — only credit institutions and e-money institutions. For a non-bank, that makes the EMI licence the gateway; we plan it together with the payments workstream. Asset-referenced tokens have their own authorisation route, and significant tokens graduate to EBA-involved supervision.
By service class under the regulation: €50,000, €125,000, or €150,000 for trading platforms — and ongoing own funds at the higher of that floor or one quarter of fixed overheads, plus the operating capital a credible business plan shows.
Yes — crypto-asset service providers are in DORA's scope, and it has applied since January 2025: ICT risk management, incident reporting, resilience testing and third-party risk are assessed as part of your application and supervised after it.
No — it's the entry ticket. The Travel Rule already applies, the AML single rulebook arrives in July 2027, AMLA direct supervision starts in 2028 with large CASPs in the candidate pool, and technical standards keep landing. The firms that treat the licence as a living obligation — with monitoring wired in — are the ones that keep it uneventfully.
Where this fits. This engagement is the licence itself. Payment & E-Money Licensing is the gateway an EMT issuer goes through first, the financial-crime programme is built alongside the application rather than after it, and Web3 Due Diligence is the same firm read from the investor's side of the table. Where the licensed entity should sit starts at the Incorporation Hub.
Get licensed — and stay licensed
Tell us what you do and where your users are. You'll get the classification, the route, and an application built with your operating team — plus the post-licence layer that keeps it standing.
Book a ConsultationGeneral information about the EU markets-in-crypto-assets regime and the obligations that sit alongside it, not legal advice. The dates, capital figures and thresholds above are those set out in the enacted EU texts, and the detail beneath them is still being filled in by technical standards and supervisory guidance. Nothing here is a prediction of how any regulator or supervisor will decide a particular case.