- What should current owners of VASP licenses in Europe do?
- New capital requirements for obtaining a CASP license
- Main requirements for a CASP License
- Company registration and legal form
- Office and management in the EU
- Reliable internal control system (AML/CFT)
- Protection of assets and personal data of clients
- Insurance and financial guarantees
- Business continuity plan
- Consumer protection and information disclosure
- Management of conflicts of interest
- Complete and reliable license application
- Comprehensive approach to MiCA compliance
- Record-keeping
- Preparing to Apply for a MiCA CASP License
- CASP Licensing Process
- Preparation of documents (stage 1)
- Choosing a jurisdiction for licensing (stage 2)
- Submission of the application (stage 3)
- Verification and assessment of documents (stage 4)
- Obtaining a license and providing services (stage 5)
- Ongoing compliance after obtaining the license (stage 6)
- Provision of Crypto-Asset Services from Abroad
- Ban on hidden customer acquisition
- The exception applies only to a specific service
- Official Sources & Primary Legislation (MiCA / CASP)
Obtaining crypto licenses, white label consulting,
ICO/STO, supporting NFT marketplaces, drafting policies
for crypto projects, DAOs, and gamify projects
The CASP (Crypto-Asset Service Provider) license is a mandatory authorization, introduced by the MiCA (Markets in Crypto-Assets) regulation, for companies that provide services related to crypto-assets.
It covers a wide spectrum of activities, in particular:
- operation of crypto exchanges;
- storage of crypto-assets (custodial wallets);
- management of crypto portfolios;
- consulting services regarding crypto-assets.
The main advantage of the CASP license consists in the fact that it allows working immediately in all 27 countries of the European Union within a single regulatory system. Thanks to the “passporting” mechanism, a company, having received a license in one EU member state, can provide its services throughout the Union without the need to undergo separate licensing in each country.
The MiCA regulation was adopted in 2023 to replace various national VASP (Virtual Asset Service Provider) licensing regimes with uniform rules for the entire EU. This became an important step toward greater transparency, security, and stability of the European market of digital assets.
How MiCA is implemented
The MiCA regulation enters into force in stages.
The first stage, which started on June 30, 2024, introduced rules for issuers of stablecoins.
The second stage, which began on December 30, 2024, extended the requirements to crypto service providers (CASPs) — crypto exchanges, brokers, custodial services, and other market participants.
For companies that already had a national VASP license, a transition period is provided. During this time, they can continue activity under the current license, but must obtain CASP status before the completion of the established deadline.
In most EU countries, the transition period lasts until December 31, 2025, although individual jurisdictions took advantage of the maximum permitted period and extended it until July 1, 2026.
After the completion of this period, only companies that received a CASP license in accordance with MiCA requirements will be able to work on the European market.
In fact, today the CASP license is the key to legal activity, customer trust, and business scaling across the entire territory of the EU.
What should current owners of VASP licenses in Europe do?
If a company already operates under a national VASP license, it is necessary to prepare in advance for the transition to the CASP regime.
Until the completion of the transition period, activity under the current VASP license is permitted. However, before its end, it is necessary to obtain a CASP license, otherwise the company will lose the right to legally provide crypto services.
The exact deadlines depend on the country. In many EU states, the transition period ends at the end of 2025, while individual countries extended it until the middle of 2026. For this very reason, it is important to check the requirements of your jurisdiction and submit a CASP application in advance — in most cases, still during 2025.
Let’s explore the main steps for the transition from VASP to CASP.
Bring capital into compliance with the new requirements
MiCA establishes a minimum size of authorized capital depending on the type of activity — up to €150,000.
If the current capital does not meet the new requirements, it is worth increasing it even before submitting the application. This will help avoid delays during licensing.
Strengthen AML/CTF procedures and internal control
MiCA establishes significantly stricter requirements for:
- anti-money laundering (AML);
- countering the financing of terrorism (CTF);
- risk management;
- customer verification (KYC);
- transaction monitoring;
- protection of client funds;
- cybersecurity and data protection.
Companies need to update internal policies, regularly assess risks, and bring all procedures into compliance with the new MiCA standards.
Provide real presence in the EU
To obtain a CASP license, it is not enough just to register a company.
MiCA requires the presence of:
- a physical office in one of the EU countries;
- effective management from the territory of the European Union;
- at least one manager or director who permanently resides in the EU;
- a local AML officer (for example, MLRO).
Regulators assess the actual activity of the company, so a formal or “nominal” presence will not meet the requirements.
Do not delay submitting the application
In most EU countries, the acceptance of applications for obtaining a CASP license opened at the beginning of 2025.
Due to the large number of applications, consideration can last several months or even longer. If you start the process too late, there is a risk of not having time to complete the licensing before the completion of the transition period, which will mean the need to suspend activity.
Companies that begin preparation in advance will be able to continuously continue work, strengthen the trust of clients and banking partners, and will get the opportunity to provide their services in all EU countries thanks to the “passporting” mechanism.
New capital requirements for obtaining a CASP license
The MiCA regulation introduces a three-level system of capital requirements depending on the list of services provided by the company and the level of associated risks.
CASP licenses are divided into three classes.
| CASP Class | Minimum paid-in capital | Covered services |
|---|---|---|
| Class 1 | €50,000 | Execution of client orders; placement of crypto-assets; transfer of crypto-assets on behalf of clients; receipt and transmission of orders; advice on crypto-assets; management of crypto portfolios. |
| Class 2 | €125,000 | All Class 1 services, as well as custody and administration of crypto-assets; exchange of crypto-assets for fiat funds; exchange of some crypto-assets for others. |
| Class 3 | €150,000 | All Class 2 services plus operation of a trading platform (crypto exchange). |
The CASP class is determined by the most risky type of activity that the company carries out.
For example, if a company provides consultations and also manages a crypto exchange, it needs to meet Class 3 requirements.
Minimum capital must be fully formed and available to support the financial stability of the company and protect clients from possible operational risks.
Additional financial requirements
In addition to minimum capital, MiCA provides for other financial requirements as well.
In particular, each CASP must have at least one bank account in the EU to work with client funds.
Also, regulators may require the presence of insurance coverage or reserves to compensate for possible losses related to cyberattacks, technical failures, or operational errors.
Companies that already have a license VASP, recommended to bring capital into compliance with the new requirements in advance. This will allow avoiding interruptions in activity and painlessly transitioning to the MiCA regulatory regime.
Main requirements for a CASP License
The transition from VASP to CASP status in accordance with MiCA is not just a formal change. The company must meet a wide spectrum of legal, organizational, and operational requirements. Below are the key conditions that must be met to obtain and maintain a CASP license.
Company registration and legal form
The company must be registered as a legal entity in one of the EU member states. Its corporate structure must be transparent, provide protection for customer interests, and comply with MiCA requirements. In practice, this usually means establishing a local company (for example, an LLC or another similar form) with a clear ownership and management structure.
Office and management in the EU
A CASP must have a registered office in the country where it receives the license and conduct real economic activity there. Effective management must also be carried out from the territory of the EU. The management must include at least one director who permanently resides in the European Union. In many countries, it is also required that certain key officers (for example, the CEO or compliance officer) work directly in the licensing country.
Reliable internal control system (AML/CFT)
A licensed CASP must implement an effective system of internal control and risk management. Special attention is paid to measures against money laundering and terrorist financing (AML/CFT). The company must:
- verify the identity of customers;
- monitor suspicious transactions and report them;
- assess the risks of money laundering and terrorist financing;
- have documented policies regarding the prevention of financial crimes, as well as the management of operational, legal, and IT risks.
Protection of assets and personal data of clients
CASP is obliged to provide reliable protection of clients’ funds and their personal data. For this, it is necessary to apply a complex of technical and organizational measures, in particular:
- segregate client assets from the company’s own funds;
- limit access to confidential information;
- use data encryption;
- regularly conduct information security audits.
The goal of these requirements is to guarantee the confidentiality, integrity, and availability of information and assets of clients.
Insurance and financial guarantees
The company must confirm that it has sufficient financial resources to cover possible risks and liability to clients. Although MiCA does not explicitly require mandatory insurance, the regulation provides for the availability of sufficient insurance coverage or financial reserves that will allow compensating for losses in the event of operational errors, security breaches, or client claims. The regulator will assess how capable such mechanisms are of covering potential risks.
Business continuity plan
MiCA requires that a CASP have a documented business continuity and disaster recovery plan. The company must be ready to maintain or quickly restore critical processes in the event of technical failures, cyberattacks, or other emergencies. Such a plan usually includes:
- data backup;
- alternative business processes;
- crisis response procedures;
- measures to ensure the continuity of service provision.
Consumer protection and information disclosure
Licensed CASPs must have a clear procedure for reviewing customer complaints and resolving disputes. Customers must be informed about the procedure for submitting a complaint, and all appeals must be reviewed promptly, objectively, and fairly. In addition, MiCA establishes high standards of consumer protection. In particular, companies must:
- transparently disclose all fees;
- warn about the risks of products and services;
- provide clients with complete and clear information before concluding contracts.
Management of conflicts of interest
A CASP must timely identify, prevent, and resolve conflicts of interest (both within the company and in relationships with clients). For example, if the company or its employees can obtain personal benefit at the expense of clients (trading against own clients, priority service for certain individuals, etc.), it is necessary to implement internal policies that minimize such risks and ensure their proper disclosure. Fairness and transparency of work are one of the basic principles of MiCA regulation.
Complete and reliable license application
To obtain a license, the company must submit to the regulator a complete package of documents with reliable information about:
- types of activity;
- ownership structure;
- management;
- internal processes and control systems.
All provided information must be complete, up-to-date, and true. After obtaining the license, a CASP can operate on the territory of the entire European Union without the need to obtain separate national permits. At the same time, significant changes in activity (for example, the launch of new services or the appointment of new management) usually require notification of the regulator or its prior approval.
Comprehensive approach to MiCA compliance
Fulfilling these requirements is a complex and multi-stage process. The European Union actually applies standards to crypto companies that are close to those in force for traditional financial institutions. Therefore, future CASPs should consider compliance not only as the preparation of necessary documents, but as building an effective system of corporate governance, risk control, and internal procedures. It is this approach that helps not only to meet the requirements of the regulator, but also to strengthen the trust of clients, partners, and investors.
Record-keeping
Accurate, complete and accessible record-keeping — one of the key requirements of MiCA. Crypto-asset service providers (CASPs) must keep detailed records of all their services, operations, client orders and transactions. This is necessary so that regulators can monitor the activity of companies and, if necessary, quickly establish what exactly happened.
Let’s break down the main requirements for record-keeping.
Full accounting of all operations
CASPs must record every important action: executed deals, storage of crypto-assets, transfers on behalf of clients, received and executed orders, etc. In other words, any service or operation must be documented in such detail that its course can be fully reconstructed from the records.
Uniform standards of data storage
MiCA along with ESMA recommendations determines in which format and by what rules companies must keep records. For example, these requirements are detailed by the Commission Delegated Regulation (EU) 2025/1140 of February 27, 2025, which supplements Regulation (EU) 2023/1114 and establishes technical standards regarding record-keeping of all crypto services, operations, orders and transactions.
Storage period
Documentation must be stored for at least 5 years. If this is required by the national regulator, the period can be extended up to 7 years, for example, if an investigation is ongoing or measures of influence are applied. Therefore, CASPs must use reliable data storage systems that protect information from loss or unauthorized changes.
Client access to information
MiCA also provides for the right of clients to receive information relating to their operations. In practice, this means that the company must be ready to provide transaction history or account information at the request of the client — of course, with compliance with requirements regarding the protection of personal data.
Quality record-keeping — this is not only fulfillment of legal requirements. It helps the company to work more transparently, faster resolve dispute situations, respond to client requests, conduct internal audit and without problems pass regulatory checks. Exactly because of this, many CASPs invest in modern IT systems that automatically register all operations and safely archive data.
Preparing to Apply for a MiCA CASP License
| Application review period | By law — about 3–4 months; taking into account preparation, the whole process usually takes 6–9 months. | Corporate governance | An effective management system is necessary: qualified leadership, a clear organizational structure and internal control mechanisms. |
|---|---|---|---|
| State fee | Depends on the country in which the license is issued. | Local staff | At least one EU-resident director is needed, as well as an MLRO or Compliance Officer with actual management of the company in the EU. |
| Authorized capital | From 50,000 to 150,000 euros depending on the type of services or, if this amount is greater, not less than a quarter of fixed operating expenses for the previous financial year. | Physical office | Obligatorily must be registered in the EU member state where the license is obtained. |
| Corporate tax | Determined by the legislation of the specific country. | Annual fee | Also depends on the country of licensing. |
Important. Under MiCA, the regulator checks the completeness of documents within 25 working days, and a decision regarding a full application usually takes about 40 working days (this period can be extended). In practice, the review itself often lasts 3–6 months, and together with preparation, the whole project takes 6–9 months.
How to prepare for submitting an application
Obtaining a CASP license begins long before the official submission of documents. To successfully pass authorization under MiCA, it is worth it for a company to go through several important stages.
Study MiCA requirements
First of all, it is necessary to thoroughly familiarize oneself with the provisions of the MiCA regulation and the recommendations of European regulators — ESMA and EBA. This will help to understand which types of crypto services fall under regulation, what requirements are put forward for corporate governance and what technical standards need to be fulfilled. The better a company understands the requirements of the legislation, the easier it will be to organize further preparation.
Determine which services the company will provide
It is necessary to clearly establish to which categories of CASP the business will belong. This determines the type of license and the list of requirements that will have to be fulfilled.
For example, a company can operate as:
- a crypto exchange;
- a custodial provider;
- a broker or intermediary for the execution of orders;
- a consultant regarding crypto-assets;
- a platform for conducting ICO or IDO;
- or provide several types of services at the same time.
Both the requirements for capital and the list of documents that need to be submitted will depend on this.
Conduct an internal audit
Before submitting an application, it is worth evaluating how much the current activity of the company corresponds to MiCA requirements.
Such an audit must cover:
- the corporate governance system;
- information security;
- AML/KYC procedures;
- financial stability;
- internal control;
- risk management.
For example, it is necessary to make sure that IT systems allow tracking all transactions, KYC procedures meet modern requirements, and key positions (Compliance Officer, MLRO, Risk Officer) are already occupied by qualified specialists.
Choose a country for licensing
Although MiCA operates identically on the entire territory of the EU, each country has its own regulator and specifics of the licensing procedure.
During the choice of jurisdiction, it is worth taking into account:
- the reputation and work practice of the regulator;
- the timelines for reviewing applications;
- administrative costs;
- requirements regarding the local presence of the company;
- the tax burden;
- the level of development of the crypto- and fintech ecosystem.
In some countries, the procedure can be faster or more predictable, so this choice should be made at the initial stage.
Prepare a package of documents
Most of the time usually is taken by the preparation of documentation itself.
To the package of documents, as a rule, belong:
- a detailed program of activity with a description of services and business model;
- information about owners, beneficiaries, directors and other key persons;
- a scheme of the organizational structure of the company;
- internal AML/CFT policies;
- risk management policy;
- description of IT infrastructure, cybersecurity measures, data protection and business continuity plans;
- financial forecasts;
- confirmation of the presence of the necessary capital;
- documents regarding insurance or reserves (if this is provided for).
A full package of documents often takes several hundred pages.
If necessary, involve specialists
Since MiCA is a new regulatory framework, the help of lawyers and consultants who specialize in financial regulation can significantly simplify the process. They will help to correctly interpret requirements, check documents, prepare the company for communication with the regulator and avoid mistakes that can lead to delay or refusal to issue a license.
Successful obtaining of a CASP license to a large extent depends on how thoroughly the company prepares even before the official submission of the application. Factually, this stage can be compared with a “general preparation”: it is necessary to bring into order corporate governance, financial indicators, internal procedures, security systems and documentation. The regulator will attentively check all these aspects, therefore investments of time and resources into preparation are not just desirable, but often decisive for the successful obtaining of a license.
CASP Licensing Process
Obtaining a CASP license in accordance with MiCA requirements consists of several stages. In general, the procedure looks like this (although individual details may differ depending on the country).
Preparation of documents (stage 1)
The first step is to prepare a full package of documents required for submitting an application. It includes:
- business plan;
- operational program;
- risk management and compliance policies;
- AML/CFT procedures (anti-money laundering and countering the financing of terrorism);
- description of IT infrastructure and cybersecurity measures;
- information about the company’s management and its owners.
All statements specified in the application must be confirmed by relevant internal documents, policies, or procedures.
In practice, this stage almost always involves several rounds of finalizing documents — after discussions with the team, lawyers, or consultants.
Before submission, it is worth checking once again that all documents meet MiCA requirements. For example, the risk management policy must cover all risks defined by the regulation, and the description of IT systems must contain information about data encryption, access control, backup, and other measures expected by the regulator.
Choosing a jurisdiction for licensing (stage 2)
In parallel with the preparation of documents, it is necessary to decide in which EU country to submit the application.
Although MiCA establishes uniform rules for the entire European Union, national regulators may have their own procedural requirements or use different document formats.
For example:
- in one country they may require a separate Fit & Proper questionnaire for each director;
- in another, this information is already included in the main application;
- somewhere it is necessary to submit documents in the official language, while other regulators accept English.
When choosing a jurisdiction, it is worth considering:
- compliance of the country with your business model;
- expected timeframes for reviewing the application;
- the amount of state fees;
- the cost of subsequent supervision;
- features of corporate and tax legislation;
- language requirements for documents.
Many crypto companies choose jurisdictions such as Lithuania, Estonia, and other countries that actively develop the fintech sector and have experience working with CASP applications. At the same time, the optimal choice always depends on the specific business.
Submission of the application (stage 3)
After completing the preparation of documents, the company submits an official application to the National Competent Authority (NCA) of the chosen country.
Usually, an electronic portal or a special procedure defined by the local regulator is used for this.
Together with the application, all prepared documents are submitted and official forms with general information about the company are filled out.
The regulator, as a rule, requests the following information.
Company information
It includes:
- full name;
- organizational and legal form (for example, LLC or PLC);
- legal address;
- contact details.
List of services
It is necessary to clearly describe exactly which crypto-asset services the company plans to provide:
- exchange of crypto-assets;
- custodial storage;
- consulting services;
- other types of activity.
It is this list that determines the type of license and the MiCA requirements that will apply to the company.
AML/CFT program
It is necessary to describe the system for countering money laundering and the financing of terrorism, in particular:
- client identification procedures (KYC);
- monitoring of operations;
- detection of suspicious activity;
- the procedure for submitting notifications to competent authorities.
Business continuity and information security
The company must explain how it will ensure:
- uninterrupted operation of services;
- emergency response;
- backup copying;
- protection of information and IT systems.
Risk management and internal control
The application must contain a description of how the company:
- identifies risks;
- assesses them;
- minimizes possible consequences;
- organizes internal control, audit, and compliance.
Information About Management and Owners
It is necessary to provide information about directors, managers, and shareholders, as well as, if necessary:
- resumes (CV);
- certificates of no criminal record;
- declarations regarding financial status;
- other documents confirming their professional suitability and flawless business reputation.
In most countries, it is also required to pay a state fee for reviewing the application. Its amount depends on the specific jurisdiction.
After receiving the documents, the regulator confirms their receipt and notifies if any materials are missing already at the initial stage.
Verification and assessment of documents (stage 4)
At this stage, the regulator analyzes all submitted information in detail and checks its compliance with MiCA requirements.
In particular, the following aspects are assessed.
Compliance of internal policies
The regulator checks whether the company’s policies comply with European requirements.
For example:
- whether the AML/CFT policy fully covers the requirements of EU legislation;
- whether cybersecurity and information protection measures are described in sufficient detail.
Financial capacity
The following is checked:
- availability of minimum authorized capital;
- confirmation of the origin of funds;
- realism of financial forecasts.
In some cases, it is necessary to provide confirmation of the availability of funds in a bank account.
Verification of management and owners
Directors, managers, and owners undergo a Fit & Proper assessment.
The regulator may check:
- presence of criminal records;
- facts of bankruptcy;
- previous sanctions or violations;
- professional experience;
- business reputation;
- the ability to effectively manage a crypto-financial company.
Organizational readiness
It is assessed whether the company has sufficient resources to conduct the declared activity.
For example, if the applicant plans to launch a large crypto exchange, but only two people work on the staff, this will almost certainly cause additional questions.
The presence of qualified specialists in compliance, risk management, and information security is also checked.
Completeness of documents
If any documents are missing or certain information requires clarification, the regulator sends a request for additional information.
For most applicants, this is a normal part of the process. It is not uncommon for several rounds of correspondence with questions and answers to take place between the company and the regulator.
Prompt and full responses help avoid delays and speed up the review of the application.
Review periods
MiCA establishes clear timeframes for reviewing applications.
Within 25 working days after submission, the regulator checks the completeness of the documents and notifies if anything is missing.
After the package of documents is recognized as complete, the decision to issue or refuse to issue a license must be made within three months.
However, in practice, the process often takes longer. Additional requests, a complex business structure, or a significant workload on the regulator can increase the review period to six months or more.
Therefore, the successful passage of this stage largely depends on the quality of document preparation, timely responses to the regulator’s requests, and careful compliance with all procedural requirements.
Obtaining a license and providing services (stage 5)
If the regulator is convinced that the company meets all requirements, it officially issues the CASP license. After that, the company acquires the status of an authorized provider of services related to crypto-assets.
Usually, after obtaining the license, the company is entered into the open register of licensed CASPs, and an official document (a license or a decision on its granting) is also issued.
The status of a licensed CASP gives the right to immediately start or continue to provide those crypto-services that were specified in the application. Moreover, it is possible to work throughout the territory of the European Union.
This is possible thanks to the passporting mechanism provided for by MiCA. If a company has obtained a license in one EU member state, it can provide services in other countries of the Union without issuing separate licenses. Usually, it is enough to notify the local regulator of the intention to operate in its market — additional approval is not required.
Precisely the possibility of passporting is one of the main advantages of the CASP regime, because it opens access to the entire European market within a single regulatory system.
At the same time, after obtaining the license, the regulator may establish certain additional conditions. For example, to grant a license with separate restrictions or recommendations or to appoint a repeated audit in a year. However, in most cases, the company can fully scale the business, launch new products, and promote its services throughout the EU, if it acts within the limits of the obtained permission and complies with the requirements of the legislation.
Terms of Obtaining a License. The law provides that the consideration of the application and the making of a decision should last approximately 3–4 months. In practice, however, the process may take more time. Companies should target a general timeframe of about 6–9 months from the moment of submitting documents to obtaining the license, taking into account the preparation stage and possible delays during consideration. At the same time, those who obtain a license at an early stage of MiCA implementation gain a competitive advantage in the new regulated market.
Ongoing compliance after obtaining the license (stage 6)
Obtaining a license is only the beginning. MiCA establishes for CASPs a number of ongoing requirements that must be complied with throughout the entire time of operation.
After the issuance of the license, the company passes under the continuous supervision of the regulator, which controls the fulfillment of all requirements of the legislation.
Below are the main obligations.
Regular reporting
A CASP must comply with ongoing regulatory obligations and provide information to the national competent authority (NCA) when required. These obligations may include maintaining records, demonstrating compliance with legislative requirements, and submitting mandatory notifications where applicable.
In addition, serious incidents (for example, cyberattacks, data leaks, or technical failures) must be reported to the regulator without delay.
Continuous compliance with AML/CTF requirements
Requirements regarding the fight against money laundering and terrorist financing operate continuously.
The company must:
- maintain the relevance of information about clients;
- constantly monitor transactions for suspicious activity;
- if necessary, submit reports on suspicious transactions (Suspicious Transaction Reports, STR) to the financial intelligence unit.
Regulators can regularly check the effectiveness of AML procedures, and employees must systematically undergo training on AML and fraud prevention issues.
Storage of information and protection of personal data
A CASP is obliged to constantly store documents and records provided for by legislation.
Simultaneously, it is necessary to provide full compliance with the requirements of legislation on personal data protection, in particular GDPR. This applies to the secure storage of client information, its confidentiality, and proper protection during processing.
Also expected is a regular assessment of the level of cybersecurity and timely updates of IT infrastructure.
Compliance with capital requirements
The company must constantly maintain the minimum size of own capital established by MiCA.
If the business actively develops or the risk level increases, the regulator may require an increase in capital or the creation of additional liquidity reserves.
In case of a significant deterioration of the financial condition, the company must notify the regulator about this and, if necessary, take measures to restore compliance with standards.
In the future, individual CASPs may also undergo financial audits or stress testing.
Notification of changes
The regulator must be notified of a number of important changes, and in individual cases — receive its prior approval.
This applies, in particular, to:
- expansion of the list of services;
- entry into new markets;
- changes in the ownership structure;
- appointment of new managers;
- other corporate changes.
For example, if a new investor acquires a qualifying holding in a CASP (more than 10%), such a change may require a separate approval from the regulator. Similarly, the appointment of a new CEO or head of the compliance function may also be subject to verification by the supervisory authority.
Timely fulfillment of these requirements helps to avoid violation of license conditions.
Compliance with conduct of business standards
MiCA also establishes requirements for the company’s behavior in the market.
The CASP must:
- act in good faith towards clients;
- avoid conflicts of interest;
- prevent market manipulation and other forms of abuse.
Any signs of bad faith behavior (for example, insider trading or misleading clients with promotional materials) can become grounds for inspections, sanctions, or even revocation of the license.
Thus, obtaining a CASP license is an important stage in a company’s development, but its preservation requires constant attention to legislative requirements. For successful market participants, compliance becomes an integral part of daily activities. Instead, the company receives the opportunity to operate in a stable and transparent regulatory environment, and also strengthens the trust of clients who know that its activities are under state supervision.
Provision of Crypto-Asset Services from Abroad
One question that arises is whether a company based outside the EU can service EU clients without a CASP license. MiCA does address this scenario through what is essentially a “reverse solicitation” exemption. According to MiCA, a service provider from abroad does not need to obtain a CASP license if the crypto-asset service is provided at the exclusive initiative of the client in the EU. In other words, if an EU customer on their own accord seeks out a foreign crypto service provider (without any solicitation or advertising targeting them), the foreign provider can serve that client without being licensed in the EU for that specific service.
However, this exception applies very limitedly.
Ban on hidden customer acquisition
A company cannot use reverse solicitation as a way to bypass MiCA requirements.
If the client was attracted through advertising, marketing campaigns, affiliate programs, or other actions of the company itself or persons associated with it, it is no longer possible to refer to this exception.
For example, if a crypto exchange from outside the EU advertises its services to European users or uses partners to attract clients from the EU, it has no right to claim that clients approached it exclusively on their own initiative.
The exception applies only to a specific service
Reverse solicitation covers only that service regarding which the client approached independently.
For example, if an EU user himself asked to execute a one-time transaction with crypto-assets, a foreign company can provide precisely this service without a CASP license.
However, if after this the company begins to offer the client other services (for example, custodial storage of assets or staking), such services will no longer be considered as provided at the initiative of the client. For their legal provision, appropriate authorization will be required.
In other words, the initial approach of the client cannot be used as a pretext for the subsequent promotion of other products or services.
Thus, the MiCA provision on providing services from outside the EU is intended to prevent a situation where foreign companies actually operate on the European market without complying with European rules.
The exception allows serving only those cases where the client truly independently approached the foreign provider. If, however, the company’s activity indicates a systematic promotion of services on the territory of the EU, it falls under MiCA regulation.
Therefore, from a practical point of view, reverse solicitation cannot be the basis of a long-term business model for working on the European market. Companies planning to actively work with clients in the EU will eventually have to either obtain a CASP license or cooperate with a licensed European provider.
Official Sources & Primary Legislation (MiCA / CASP)
Primary EU Acts
- Regulation (EU) 2023/1114 — Markets in Crypto-Assets (MiCA) (full text, EUR-Lex)
- Regulation (EU) 2023/1113 — Transfer of Funds Regulation (crypto “Travel Rule”) (full text, EUR-Lex)
ESMA — MiCA & CASPs
European Commission — MiCA Level-2 (examples)
- Commission Delegated Regulation (EU) 2025/1140 — CASP record-keeping (Art. 68) (EUR-Lex)
- Commission Delegated Regulation (EU) 2025/1144 — Order book / trading transparency (EUR-Lex)
National Competent Authorities (Application Portals — examples)
Pages
- Company
- Contact information
- Cookie Policy
- FAQ
- GDPR
- Home
- Newsroom
- Our services
- Company formation
- Crypto
- Crypto licenses
- Crypto license in Africa
- Crypto license in Asia
- Crypto License in Australia
- Crypto License in Canada
- Crypto license in Europe
- Crypto license in Bosnia
and Herzegovina - Crypto license in Bulgaria
- Crypto license in Czech Republic
- Crypto license in Estonia
- Crypto license in Georgia
- Crypto license in Italy
- Crypto license in Lithuania
- Crypto license in Poland
- Crypto license in Portugal
- Crypto license in Slovakia
- Crypto license in Switzerland
- Crypto license in the UK
- Crypto license in Bosnia
- Crypto License in New Zealand
- Latam crypto license
- Offshore crypto license
- MiCA license
- Registration of a physical exchange office
- CASP License
- DAO in the UAE
- Drafting policies
for crypto projects - EU AI Act
- Registration DAO in Marshals
- VASP License
- White label consulting
- AML/KYC for Crypto
- Cryptoconsulting
- Tokenization
- Crypto licenses
- FinTech
- Investments
- AML/CTF for investment
- Asset management License
- Forex licenses
- Botswana Forex license
- Forex License in Anjouan
- Forex license in Costa Rica
- Forex license in Cyprus
- Forex License in Labuan
- Forex license in Mauritius
- Forex license in Saint Lucia
- Forex License in Saint Vincent
and Grenadines - Forex license in Seychelles
- Forex License in South Africa
- Forex license in the Comoros Islands
- Forex license in Vanuatu
- Registration of an investment fund
- Connecting the MetaTrader platform
- Crowdfunding
- Invest Consulting
- Online Gaming
- Gambling licenses
- Betting License
- Gambling license in Australia
- Gambling License in El Salvador
- Gambling license in Gibraltar
- Gambling license in India
- Gambling License in Liberia (NLA)
- Gambling license in Malta
- Gambling License in Panama
- Gambling License in Romania
- Gambling license in Tobique
- Nevis Gaming License
- Vanuatu gambling license
- Gambling license in Great Britain
- Gambling license in Estonia
- Gambling license in Isle Of Man
- Curacao Gaming License
- Gaming License in Ontario
- Kenya Gambling License
- Costa Rica Gambling License
- Anjouan Gambling License (Comoros)
- Alderney Gambling License
- Gambling license in Brazil
- Gambling license in Kahnawake
- Crypto Casino License
- Gambling license in South Africa
- Gambling license in Sweden
- Gambling license in the Philippines
- Turnkey Online Casino Solution
- White Label Casino License
- AML/KYC for gambling
- Gambling consulting
- Drafting policies for gambling projects
- Gambling licenses
- Opening Accounts
- Privacy Policy
- Return & Refund Policy
- Reviews
- Sitemap
- Terms and Conditions
Get in touch with us

Daria Lysenko
Senior lawyer

Valeriia Kozel
Customer manager
You can be interested in following articles

What ESMA’s Statement Means for Crypto Companies in Europe: Practical Tips for Compliance

Crypto License in Latin America (2026): A Practical Guide for Launching in El Salvador, Brazil, Argentina & Panama

SRO License in Switzerland (2026): Requirements, Costs and How to Obtain

How Much Does a Gambling License Cost in 2026?

Why Operators are Turning to Liberia for iGaming Licensing: A Competitive Alternative to Curacao

MiCA Regulation: New Rules and Outlook for 2026

US Crypto Regulations

The Beginner’s Guide to Online Gambling Licences: Everything You Need to Know

Top 5 Crypto-Friendly Jurisdictions for 2025-2026: Expert Guide by SBSB FinTech Lawyers

Seychelles vs Mauritius Forex Licenses: Costs, Benefits, and Licensing Process

Sweden Amends Gambling Act to Crack Down on Unlicensed Operators

The Future Of Stablecoins In Europe
Customer reviews