Head of International Corporate Law and Fintech Practice
Expert in fintech, crypto, and international corporate law with over 20 years of experience. Specializes in crypto licensing (VASP/CASP), iGaming business support, and international structuring, asset protection, and OSINT analytics for risk assessment and due diligence.
Obtaining a MiCA license for CASP in the EU
We provide end-to-end support for obtaining Crypto-Asset Service Provider (CASP) authorisation under MiCA — from the legal classification of the product and establishment of an EU structure to preparation of the complete regulatory dossier, responses to the regulator and implementation of the post-authorisation compliance framework.
- Define the regulatory perimeter: MiCA, MiFID II, PSD2, EMI/PI, ART/EMT and related regimes
- Design the EU substance: group structure, management body, MLRO/compliance and allocation of functions
- Prepare the CASP dossier: business plan, governance, AML/CFT, safeguarding, DORA/ICT and service-specific policies
- Manage the authorisation process: pre-application, filing, regulator Q&A, revisions and passporting
Assess your project’s MiCA readiness
Important: “MiCA licence” is a commonly used commercial term. Legally, the procedure concerns authorisation of a company as a crypto-asset service provider (CASP) under Regulation (EU) 2023/1114.
Who needs MiCA CASP authorisation
Authorisation is required for companies that professionally provide one or more regulated crypto-asset services in the EU, including:
- custody and administration of crypto-assets or the means of access to them;
- exchange of crypto-assets for funds or other crypto-assets;
- operation of a trading platform for crypto-assets;
- execution, reception and transmission of client orders;
- placing of crypto-assets;
- providing advice on crypto-assets or portfolio management;
- transfer services for crypto-assets on behalf of clients.
Separate regulatory analysis is required for crypto payments, stablecoin models, tokenised financial instruments, DeFi, NFTs, staking, lending, copy trading and products that may simultaneously fall within MiCA, MiFID II, PSD2 or the electronic money regime.
For non-EU businesses: a Ukrainian, UK, US or other non-EU company cannot obtain CASP authorisation directly. An EU subsidiary is normally established for this purpose. Foreign owners may retain 100% ownership, but the EU company must have genuine management, resources and operational control in the EU; at least one director must reside in the EU. Individual Member States may impose stricter practical local-presence requirements.
MiCA CASP is not a formal registration
The regulator assesses not only whether the documents are complete, but also whether the company is genuinely ready to implement the procedures described in its application. Template policies without a competent team, working technology, provider agreements and a clear operating model normally lead to additional information requests and delays.
1. Governance and substance
The regulator determines who actually manages the CASP, where decisions are made and whether the team is capable of controlling the business.
• fit & proper assessment of directors, UBOs and qualifying shareholders;
• experience, reputation and sufficient time commitment;
• independence of the MLRO, compliance and risk functions;
• genuine presence and clear allocation of responsibilities.
2. AML/CFT and flow of funds
The AML documentation must reflect the actual product, clients, jurisdictions, transaction scenarios and level of risk.
• KYC/KYB, UBO, source of funds and source of wealth;
• sanctions and blockchain screening;
• the Travel Rule and unhosted wallets;
• alerts, investigations, escalation and STR/SAR reporting.
3. DORA, ICT and client assets
For custody, exchange and trading models, demonstrating technical and operational readiness for launch is particularly important.
• ICT risk management and cybersecurity;
• business continuity, backup and incident response;
• wallet architecture and key management;
• segregation, safeguarding and reconciliation.
CASP capital and prudential requirements
The minimum prudential safeguard depends on the services provided. The applicable amount is the higher of the MiCA minimum set out below or one quarter of the company’s fixed overheads.
| Class | Minimum | Typical scope |
|---|---|---|
| Class 1 | €50,000 | Services not falling under Class 2 or Class 3, including execution, reception and transmission of orders, placing, advice, portfolio management and transfer services. |
| Class 2 | €125,000 | Custody and administration, crypto-to-fiat and crypto-to-crypto exchange; other services where included in the requested scope. |
| Class 3 | €150,000 | Operation of a trading platform for crypto-assets; other services where included in the requested scope. |
Capital is not a licence fee. It consists of own funds or another permitted prudential mechanism that the CASP must maintain. Government fees, legal support, personnel, office, audit, technology and AML systems are budgeted separately.
MiCA CASP authorisation process: 8 stages
1. Regulatory scoping of the business model
We map the product, the role of each participant, fiat and crypto flows, custody chain, client agreements, countries of operation and client-acquisition channels. We determine:
- which crypto-asset services the company provides;
- the required class and scope of CASP authorisation;
- whether additional MiFID II, PSD2, EMI/PI or ART/EMT requirements arise;
- which operations must be modified before approaching the regulator.
2. Jurisdiction selection and pre-application
We compare not only taxes and government fees but also the approach of each NCA: requirements regarding local management, MLRO/compliance, office, outsourcing, document language, safeguarding and banking infrastructure. Where possible, we engage with the regulator in advance regarding the business model and requested services.
3. EU company, ownership and fit & proper
We establish or adapt an EU legal entity, disclose the corporate chain up to the ultimate beneficial owners and form the management body. We prepare individual files for directors, key function holders and qualifying shareholders, including CVs and evidence of experience, reputation, source of funds, absence of conflicts and sufficient time commitment.
4. Governance, personnel and outsourcing
We build an organisational model with clear reporting lines, a decision matrix and three lines of defence. We define the functions of the board, CEO, MLRO, compliance, risk, ICT/security and internal audit. For each outsourced function, we prepare the outsourcing framework, SLA, provider oversight, access and exit arrangements. Ultimate responsibility and effective control must remain with the CASP.
5. Preparation of the complete CASP dossier
The exact application package depends on the requested services but normally includes:
- programme of operations and a three-year business plan;
- financial model and evidence of prudential safeguards;
- governance, internal controls, risk management and conflicts of interest;
- AML/CFT risk assessment, KYC/KYB, monitoring, sanctions and the Travel Rule;
- business continuity, outsourcing and wind-down arrangements;
- DORA/ICT risk framework, security and incident management;
- segregation and safeguarding of client funds and crypto-assets;
- complaints handling and client protection;
- custody policy, execution policy, commercial policy or trading-platform rules, depending on the scope;
- fit & proper files for management and qualifying shareholders.
6. Operational readiness before filing
We align every provision of the policies with the actual operation: the onboarding interface, AML-system settings, wallet flows, access rights, agreements with banks and custody/technology providers, and the team’s procedures. We conduct a gap analysis and mock regulatory interview. The application is filed when the company can not only describe but also demonstrate its key controls.
7. Filing and regulatory information requests
We prepare the application index, verify consistency across the documents and submit the dossier to the competent authority. During the assessment, we:
- coordinate responses to regulatory information requests;
- update documents and financial calculations;
- prepare management and key personnel for meetings and interviews;
- address comments concerning governance, AML, ICT and outsourcing;
- maintain version control to ensure that amendments to one document do not contradict other parts of the application.
8. Authorisation, passporting and launch
Following a positive decision, we help satisfy any pre-launch conditions, file notifications for the provision of services in other EU countries, and implement the regulatory calendar, reporting, training, periodic reviews, audit and business-model change controls.
Request a CASP authorisation roadmap
How long does MiCA CASP authorisation take?
Once an application is deemed complete, MiCA sets regulatory time limits for its assessment. In practice, the overall project takes longer because preparation of the company, team, technology and documentation precedes formal review, while the regulator may request additional information during the assessment.
| Stage | Indicative timeframe | Key factors |
|---|---|---|
| Scoping, structure and gap analysis | 2–6 weeks | Complexity of the product, group and token classification |
| Team, substance and documentation | 3–6+ months | Availability of directors, MLRO, ICT, providers and a functioning product |
| Completeness assessment | up to 25 working days | Completeness of the application package |
| Assessment of the complete application | normally up to 40 working days | Additional information requests, interviews and required changes to the model |
A realistic overall estimate is approximately 6–12 months. A complex custody, exchange or trading-platform project may take longer. The statutory time limits only begin to operate fully after the application has been confirmed as complete and do not include the preparatory stage.
What you receive as part of our support
Regulatory roadmap
Classification of services, licensing perimeter, jurisdiction, group structure, budget, team and launch sequence.
CASP application package
A consistent regulatory dossier tailored to the product, technology, risks and supervisory practice of the selected NCA.
Governance and fit & proper
Organisational structure, job descriptions, decision matrix and individual files for directors and shareholders.
AML and technology readiness
Practical implementation of controls from onboarding and transaction monitoring to DORA, custody and incident response.
Regulator engagement
Meeting preparation, responses to comments, dossier revisions and coordination of all project participants.
Launch and passporting
Launch conditions, EU passporting, regulatory calendar, reporting, team training and ongoing compliance.
Legal framework
- Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA) — CASP authorisation and operations.
- Regulation (EU) 2022/2554 (DORA) — digital operational resilience and ICT risk.
- Regulation (EU) 2023/1113 — information accompanying transfers of funds and crypto-assets, including the Travel Rule.
- ESMA materials on MiCA — technical standards, guidelines and supervisory materials.
Why Prikhodko & Partners

Our extensive practical experience in crypto predates the implementation of MiCA and covers exchanges, custodians, fintech and Web3 projects. We understand the regulatory rationale and the specific features of crypto business models in the EU.

Our policies and procedures are prepared by certified AML/CFT specialists with practical experience in implementing a risk-based approach, KYC, transaction monitoring and internal controls.

We advise international structures with complex geographical footprints and flows of funds that attract enhanced regulatory scrutiny. We prepare legal opinion letters to substantiate the legal model and compliance rationale of the business.

We prepare companies for account opening and cooperation with PSPs with the involvement of in-house professionals who have banking-sector experience. We structure the documents and operating model around real bank-compliance expectations.
Recognition
![]() |
![]() |
![]() |
![]() |
![]() |
Calculate the cost of services
1 question
Do you already have a registered company in the EU?
2 question
Does your company plan to work with client funds?
3 question
Has your company previously received a VASP or other crypto license?
4 question
Do you plan to open a bank account or work with payment services?
Can a non-EU company obtain CASP authorisation?
No. The applicant must be a legal person or another eligible undertaking established in the EU. A non-EU company may act as the parent company or shareholder of an EU CASP, but the licensed operating company must be an EU-established entity.
Is preparing a set of policies sufficient?
No. The regulator assesses the company’s management, ownership structure, capital, product, ICT systems, AML framework, safeguarding arrangements, outsourcing and actual ability to implement the stated procedures. The documentation must correspond to the company’s real systems, agreements and allocation of responsibilities.
Can compliance, IT or custody functions be outsourced?
Individual functions may be outsourced subject to proper provider assessment, contractual arrangements, ongoing oversight and an appropriate exit plan. A CASP cannot transfer its regulatory responsibility to external providers or become an empty shell without its own management and operational control.
Does CASP authorisation apply throughout the EU?
Yes. Once authorised, a CASP may provide its authorised services in other EU Member States through the passporting procedure. Passporting does not expand the scope of authorised services or remove applicable requirements relating to local marketing, AML compliance and consumer protection.
You may also need:
call back
during the day






