Head of International Corporate Law and Fintech Practice
Expert in fintech, crypto, and international corporate law with over 20 years of experience. Specializes in crypto licensing (VASP/CASP), iGaming business support, and international structuring, asset protection, and OSINT analytics for risk assessment and due diligence.
MiCA CASP License in the EU: End-to-End Legal Support
We support Crypto-Asset Service Provider (CASP) authorisation under MiCA, from legal classification of your product and structuring your EU operations to preparing the full regulatory dossier, responding to regulator requests and establishing post-authorisation compliance.
- Define the regulatory perimeter: MiCA, MiFID II, PSD2, EMI/PI, ART/EMT and related regimes
- Design your EU substance: group structure, management, MLRO/compliance and responsibility allocation
- Prepare the CASP dossier: business plan, governance, AML/CFT, safeguarding, DORA/ICT and service policies
- Manage the authorisation process: pre-application engagement, filing, regulator Q&A, revisions and passporting
70% of our fee is payable after CASP authorisation
You pay only 30% before the application is submitted. We receive the largest part of our fee when the regulator grants your authorisation.
15% before work begins · 15% when the documents are ready for filing · 70% after authorisation.
View packages and payment terms
Important: A “MiCA licence” is a common commercial term. Legally, this means authorisation of a company as a crypto-asset service provider (CASP) under Regulation (EU) 2023/1114.
Who needs MiCA CASP authorisation?
Authorisation is required for companies professionally providing one or more regulated crypto-asset services in the EU, including:
- custody and administration of crypto-assets or the means of access to them;
- exchange of crypto-assets for funds or other crypto-assets;
- operation of a trading platform for crypto-assets;
- execution, reception and transmission of client orders;
- placing of crypto-assets;
- providing advice on crypto-assets or portfolio management of crypto-assets;
- transfer of crypto-assets on behalf of clients.
Crypto payments, stablecoin models, tokenised financial instruments, DeFi, NFTs, staking, lending, copy trading and products potentially subject to MiCA, MiFID II, PSD2 or electronic money rules at the same time require separate analysis.
For non-EU businesses: a Ukrainian, UK, US or other non-EU company cannot obtain CASP authorisation directly. Typically, it establishes a subsidiary in an EU Member State. Foreign owners may retain 100% ownership, but the EU company must have effective management, resources and operational control in the EU; at least one director must reside in the EU. Individual countries may impose stricter practical requirements for local presence.
MiCA CASP is more than a registration
The regulator assesses both the completeness of the documents and the company’s actual readiness to implement its stated procedures. Template policies without a team, technology, provider agreements and a clear operating model usually lead to further requests and delays.
1. Governance and substance
The regulator examines who actually manages the CASP, where decisions are made and whether the team can control the business.
• fit and proper assessment of directors, UBOs and qualifying shareholders;
• experience, reputation and sufficient time commitment;
• independence of MLRO, compliance and risk functions;
• genuine presence and allocation of responsibilities.
2. AML/CFT and funds flows
AML documentation must reflect the actual product, clients, geographic footprint, transaction scenarios and risk level.
• KYC/KYB, UBOs, source of funds and source of wealth;
• sanctions and blockchain screening;
• Travel Rule and unhosted wallets;
• alerts, investigations, escalation and STR/SAR reporting.
3. DORA, ICT and client assets
For custody, exchange and trading models, demonstrating technical and operational readiness is especially important.
• ICT risk management and cybersecurity;
• business continuity, backup and incident response;
• wallet architecture and key management;
• segregation, safeguarding and reconciliation.
CASP capital and prudential requirements
The minimum prudential safeguards depend on the services provided. The higher of two amounts applies: the MiCA minimum or one quarter of the company’s fixed overheads.
| Class | Minimum | Typical scope |
|---|---|---|
| Class 1 | €50 000 | Services outside Class 2 and Class 3, including execution, reception and transmission of orders, placing, advice, portfolio management and transfer services. |
| Class 2 | €125 000 | Custody and administration, exchange of crypto-assets for funds or other crypto-assets; other services if included in the proposed scope. |
| Class 3 | €150 000 | Operation of a trading platform for crypto-assets; other services if included in the proposed scope. |
Capital is not a licence fee. These are own funds or another permitted prudential arrangement that the CASP must maintain. Government fees, legal support, staff, office space, audit, technology and AML systems are budgeted separately.
MiCA CASP authorisation process: 8 stages
1. Regulatory scoping of the business model
We map the product, the role of each participant, fiat and crypto flows, the custody chain, client agreements, countries of operation and customer acquisition channels. We determine:
- which crypto-asset services the company provides;
- which class and scope of CASP authorisation it needs;
- whether additional MiFID II, PSD2, EMI/PI or ART/EMT requirements apply;
- which operations need to change before approaching the regulator.
2. Jurisdiction selection and pre-application engagement
We compare not only taxes and government fees but also the practice of the relevant national competent authority (NCA): requirements for local management, MLRO/compliance, office space, outsourcing, document language, safeguarding and banking infrastructure. Where possible, we discuss the model and proposed services with the regulator in advance.
3. EU company, ownership and fit and proper assessments
We establish or adapt an EU legal entity, disclose the ownership chain to the ultimate beneficial owners and assemble the management body. We prepare documentation for directors, key function holders and qualifying shareholders: CVs and evidence of experience, reputation, source of funds, absence of conflicts and sufficient time to perform their duties.
4. Governance, personnel and outsourcing
We build an organisational model with clear reporting lines, a decision matrix and three lines of control. We define the responsibilities of the board, CEO, MLRO, compliance, risk, ICT/security and internal audit. For each outsourced function, we prepare an outsourcing framework, SLA, provider oversight, access rights and exit arrangements. Ultimate responsibility and effective control must remain with the CASP.
5. Preparation of the full CASP dossier
The contents depend on the services, but typically include:
- a programme of operations and a three-year business plan;
- a financial model and evidence of prudential safeguards;
- governance, internal controls, risk management and conflicts of interest;
- AML/CFT risk assessment, KYC/KYB, monitoring, sanctions and Travel Rule;
- business continuity, outsourcing and wind-down arrangements;
- a DORA/ICT risk framework, security and incident management;
- segregation and safeguarding of clients’ funds and crypto-assets;
- complaints handling and client protection;
- a custody policy, execution policy, commercial policy or trading platform rules, depending on the scope;
- fit and proper files for management and qualifying shareholders.
6. Operational readiness before filing
We match every policy provision to an actual operation: onboarding interfaces, AML system settings, wallet flows, access rights, bank agreements, custody and technology providers and team procedures. We conduct a gap analysis and a mock regulatory interview. The application is filed when the company can both describe and demonstrate its key controls.
7. Filing and responding to regulator requests
We compile the application index, check the documents for consistency and submit the dossier to the competent authority. During the review, we:
- coordinate responses to regulator requests;
- update documents and financial calculations;
- prepare managers and key specialists for meetings and interviews;
- address comments on governance, AML, ICT and outsourcing;
- maintain version control so that changes to one document do not conflict with other parts of the application.
8. Authorisation, passporting and launch
After a positive decision, we help satisfy any conditions before launch, submit notifications for services in other EU countries, and set up the regulatory calendar, reporting, training, periodic reviews, audits and controls over business model changes.
Get your CASP authorisation roadmap
How long does MiCA CASP authorisation take?
MiCA sets regulatory review periods once an application is deemed complete. In practice, the overall project takes longer because the company, team, technology and documentation must be prepared before formal review, and the regulator may request additional material during its assessment.
| Stage | Estimated time | What affects the timeline |
|---|---|---|
| Scoping, structuring and gap analysis | 2–6 weeks | Complexity of the product, group and token classification |
| Team, substance and documentation | 3–6+ months | Availability of directors, MLRO, ICT, providers and a working product |
| Completeness check | up to 25 working days | Completeness of the application package |
| Assessment of a complete application | normally up to 40 working days | Additional requests, interviews and changes to the model |
A realistic overall estimate is approximately 6–10 months. Complex custody, exchange or trading platform projects may take longer. The statutory review periods begin to apply fully only once the application is confirmed as complete and do not include preparation time.
MiCA CASP support fees
We offer three packages based on the complexity of the business model, number of services, ownership structure and preparation needed before filing. We define the precise scope of work and project boundaries after assessing your model.
CASP Basic — €35 000
For a relatively straightforward model with a limited number of services, a transparent ownership structure, an EU-based team, and no complex custody architecture or extensive outsourcing.
• Assessment of the model and its MiCA regulatory perimeter.
• Review of the corporate structure, governance and baseline management requirements.
• Preparation of the core documentation package: business plan, AML/KYC, risk management, internal controls, ICT, outsourcing and protection of client assets as required by the proposed services.
• Legal review of the application, support with filing and responses to standard regulator requests.
CASP Standard — €60 000
For a company planning long-term operations in the EU market and seeking a comprehensive regulatory strategy.
• Everything in Basic
• Comparison of jurisdictions based on regulatory approach, substance, team and infrastructure requirements and ongoing costs.
• Detailed structuring of the business model and scope of CASP services.
• Full regulatory dossier: ownership, business plan, governance, AML/CFT, risk, client protection, safeguarding and outsourcing.
• Legal and regulatory coordination of ICT/DORA requirements with the client’s technical team.
CASP Full — €90 000
For exchanges, custody businesses, trading platforms, international groups and projects involving multiple services, complex outsourcing or banking and payment flows.
• Everything in Standard
• In-depth structuring of the group, EU entity, governance and operational presence.
• Preparation for regulator meetings, extended support with requests and iterative application revisions.
• Banking and payment infrastructure strategy, safeguarding and crypto-to-fiat flows.
• Enhanced AML procedures, transaction monitoring, sanctions controls and Travel Rule implementation.
The main payment follows the result
You pay 15% at the start of the project and another 15% when the documentation is ready for filing. The remaining 70% becomes payable only after CASP authorisation is granted. This ties the majority of our fee to your primary objective.
| Package | 15% before work begins | 15% when documents are ready, before filing | 70% after authorisation |
|---|---|---|---|
| Basic — €35 000 | €5 250 | €5 250 | €24 500 |
| Standard — €60 000 | €9 000 | €9 000 | €42 000 |
| Full — €90 000 | €13 500 | €13 500 | €63 000 |
The prices shown are legal support fees; VAT is added where applicable. Regulatory fees, share capital, company formation, office space, directors’ and compliance team remuneration, audits, technology and other external costs are payable separately. The agreement sets out the specific scope of work, stages and terms. The regulator decides whether to grant authorisation; we cannot guarantee a positive decision or a particular timeline.
Discuss your package and project budget
What you receive with our support
The deliverables and depth of work depend on the selected package and proposed CASP services.
Regulatory roadmap
Service classification, regulatory perimeter, jurisdiction, group structure, budget, team and launch sequence.
CASP application package
A coherent regulatory dossier tailored to the product, technology, risks and practice of the selected NCA.
Governance and fit and proper
Organisational chart, job descriptions, decision matrix and individual documentation for directors and owners.
AML and technology readiness
Practical implementation of controls, from onboarding and transaction monitoring to DORA, custody and incident response.
Regulator engagement
Meeting preparation, responses to comments, dossier revisions and coordination of all project participants.
Launch and passporting
Launch conditions, EU passporting, regulatory calendar, reporting, team training and ongoing compliance.
Legal basis
- Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA) — CASP authorisation and operations.
- Regulation (EU) 2022/2554 (DORA) — digital operational resilience and ICT risks.
- Regulation (EU) 2023/1113 — information accompanying transfers of funds and crypto-assets, including the Travel Rule.
- ESMA materials on MiCA — technical standards, guidelines and supervisory materials.
Why Prikhodko&Partners

Our extensive practical experience in crypto predates MiCA and spans exchanges, custodians, fintech and Web3 projects. We understand the regulatory rationale and the specifics of crypto business models in the EU.

Policies and procedures are developed by certified AML/CFT specialists with practical experience implementing a risk-based approach, KYC, transaction monitoring and internal controls.

We support international structures with complex geographic footprints and funds flows under heightened regulatory scrutiny. We prepare legal opinion letters to substantiate the business’s legal model and compliance rationale.

We prepare companies to open accounts and work with PSPs, drawing on in-house banking experience. We develop documents and operational processes that reflect real bank compliance requirements.
Calculate the cost of services
1 question
Do you already have an EU company through which you plan to apply?
2 question
Do you plan to hold clients’ crypto-assets in custody or operate a trading platform?
3 question
Does your business model involve exchanging crypto-assets for fiat currency?
4 question
Has your company previously received a VASP or other crypto license?
5 question
Do you plan to open a bank account or work with payment services?
Can a non-EU company obtain CASP authorisation?
No. The applicant must be a legal person or another eligible undertaking established in the EU. A non-EU company may act as the parent company or shareholder of an EU CASP, but the licensed operating company must be an EU-established entity.
Is a set of policies enough to obtain authorisation?
No. The regulator assesses whether the documents reflect how the company actually operates, including its team, technology, provider agreements and internal controls.
Can compliance, IT or custody functions be outsourced?
Individual functions may be outsourced subject to proper provider assessment, contractual arrangements, ongoing oversight and an appropriate exit plan. A CASP cannot transfer its regulatory responsibility to external providers or become an empty shell without its own management and operational control.
Does CASP authorisation also cover payment services?
Not automatically. If the business model includes separately regulated payment services, the applicable requirements must be assessed in addition to MiCA.
Can a CASP serve clients in other EU countries after authorisation?
Yes. Once authorised, a CASP may provide its authorised services in other EU Member States through the passporting procedure. Passporting does not expand the scope of authorised services or remove applicable requirements relating to local marketing, AML compliance and consumer protection.
You may also need:
call back
during the day

