CASP authorisation is the licence that lets a firm provide crypto-asset services anywhere in the EU. Under MiCA it is no longer optional, no longer national, and no longer available through the transitional arrangements that carried existing businesses through 2025 — the grandfathering has expired.
This guide covers what the application contains, the statutory clock, the capital tiers, passporting, and where applications actually fail.

What CASP authorisation covers
A crypto-asset service provider is a firm providing one or more of MiCA’s listed services: custody and administration on behalf of clients, operation of a trading platform, exchange of crypto-assets for funds or for other crypto-assets, execution of orders, placing, reception and transmission of orders, advice, portfolio management, and transfer services.
CASP authorisation is granted for the specific services you apply for, and the requirements scale with them. Adding a service later means varying the authorisation, so scope the application against the business you will actually run in the next two years rather than the one on the pitch deck.
The CASP authorisation clock
| Stage | Period |
|---|---|
| Completeness check by the competent authority | 25 working days from receipt |
| Substantive assessment and reasoned decision | 40 working days from a complete application |
| Passporting notification once authorised | Notify the home authority; services may follow across the EU |
Those figures mislead people. The clock only starts when the file is complete, and the elapsed time from first contact to licence is commonly several months to a year, because incomplete submissions restart the completeness stage. Treat the 40 working days as the regulator’s promise, not your project plan.
What the application file has to contain
- The firm. Legal form, registered office and effective management inside the EU, ownership structure, and identification of qualifying shareholders.
- Fit and proper people. Management body members assessed on repute, knowledge, skills and experience, individually and collectively, with time commitment evidenced.
- Programme of operations. Each service described concretely — the client journey, the systems, the counterparties, the jurisdictions.
- Prudential safeguards. Own funds meeting the class threshold for the services provided, or the alternative fixed overheads calculation, plus an insurance policy where permitted.
- Governance and control functions. Risk management, compliance, internal audit and outsourcing arrangements, proportionate but real.
- ICT and operational resilience. Business continuity, incident handling and the DORA obligations that now apply to authorised CASPs.
- Client asset protection. Segregation, custody policy, and how client crypto-assets are kept separate from the firm’s own.
- Financial crime. AML and CFT arrangements, and compliance with the transfer-of-funds rules for crypto transfers.
- Complaints, conflicts and disclosure. Procedures the authority can read and test.
Capital and the class you fall into
Minimum own funds for CASP authorisation are set by the type of service, with a higher floor for trading platform operators than for advice or order reception. Whichever class you sit in, the requirement is the higher of the fixed minimum and a quarter of the previous year’s fixed overheads — so a firm that grows its cost base grows its capital requirement with it.
Passporting, and why the home state matters
One authorisation covers the EU. Once licensed, the firm notifies its home authority of the member states it intends to serve, and the services may be provided cross-border without a second licence. That makes the choice of home state a real strategic decision: authorities differ in throughput, in the depth of pre-application engagement they offer, and in how they read the same requirements.
Our guide to MiCA after grandfathering covers the transitional position, and the crypto-asset white paper covers the separate obligation that attaches to offering assets rather than services.
Where CASP authorisation applications fail
The completeness loop. Missing annexes and unsigned policies push the file back to the start. The single best investment is a submission checklist against the authority’s own published requirements before filing.
Substance on paper only. Effective management has to be in the member state. A board that meets remotely from outside the EU with a local director for form is the pattern authorities are explicitly looking for.
Generic policies. Templates that do not describe the firm’s actual flows, custody model or counterparties get read as evidence that nobody has thought about the business.
Underestimating DORA and AML. Both are separate regimes landing on the same firm, and both have to be real at the point of authorisation rather than promised.
Frequently asked questions
How long does CASP authorisation take?
The statutory assessment is 40 working days from a complete application, after a 25 working day completeness check. In practice, expect several months to a year from first engagement.
Can we keep operating while the application is pending?
The MiCA transitional arrangements have ended. Operating without authorisation where it is required is unlawful — check your national position before relying on any grace.
Does one licence cover the whole EU?
Yes, through passporting, once you notify your home authority of the member states you intend to serve.
Do we need a white paper as well?
Only if you offer crypto-assets to the public or seek admission to trading. Providing services and offering assets are separate obligations.
What capital do we need?
It depends on the services, with the requirement set as the higher of a fixed minimum for your class and a quarter of the prior year’s fixed overheads.
Where this leaves you
Scope the CASP authorisation to the services you will really provide, pick the home state deliberately, and put the effort into a genuinely complete first submission — the statutory clock is short but it does not start until the file is accepted. Build real substance in the member state, write policies that describe your flows rather than a template’s, and stand up DORA and AML arrangements before you file rather than promising them in the covering letter.
References
- ESMA — Markets in Crypto-Assets Regulation — the technical standards and guidance behind the authorisation process.
- Regulation (EU) 2023/1114 (MiCA) — the regulation itself, including the authorisation articles.
More on crypto and financial services compliance
- CASP authorisation — you are here
- MiCA after the grandfathering period
- The crypto-asset white paper
- DORA requirements
Application templates, governance policies and the control set are in the MiCA Toolkit, or start with the free ISO templates.