All requirements must be met before the ASF application is submitted. ASF does not process incomplete applications, and missing documentation or a deficient governance structure at submission will delay the process or result in rejection. The requirements span four areas: corporate structure and capital, the 0.5% ASF regulatory fee compliance readiness, ADR and ICI technical pre-clearances, and governance, AML, and substance obligations.
Corporate Structure and Capital Requirements
Romania CASP applicants must incorporate a Romanian legal entity before submitting to ASF. The two most common structures are the Societate cu Raspundere Limitata (SRL) and the Societate pe Actiuni (SA). The SRL is preferred by startups and smaller platforms because it requires lower formation costs and simpler governance. The SA is better suited to larger platforms or those raising institutional capital, as it accommodates share capital structures required by some investors and provides a more familiar framework for regulated financial entities.
At least one EU-resident board member is required. The entity must have a genuine presence in Romania: a registered office, operational substance, and personnel capable of managing compliance and governance from within the country.
Capital requirements by service category:
One critical planning point: own funds must also cover at least one quarter of prior-year fixed overheads, regardless of where the minimum capital threshold sits. Founders targeting rapid growth should plan capital reserves well above the regulatory minimums to avoid breaching the ongoing own-funds requirement as revenues and cost bases scale.
The 0.5% ASF Regulatory Tax
Romania imposes a monthly supervisory fee equal to 0.5% of a CASP’s operating income. This fee is payable to ASF by the 15th day of the month following the month in which the income was earned. The fee applies to all licensed CASPs operating in Romania, regardless of whether they are incorporated locally or passporting in from another EU jurisdiction.
This charge is unique to Romania among EU MiCA jurisdictions and has no direct equivalent in Malta, Lithuania, Poland, or Estonia. It must be factored into operating models from the outset. Founders comparing the Romania CASP license against other MiCA jurisdictions should model the 0.5% fee against projected operating income before committing to Romania as their MiCA home jurisdiction.
Technical Pre-Clearances: ADR and ICI
Romania requires mandatory IT system pre-clearance from the Authority for the Digitisation of Romania (ADR) before the main ASF application can be submitted. This pre-clearance step is specific to Romania and is not required under MiCA in most other EU member states. It is also one of the most commonly overlooked steps by applicants approaching Romanian licensing without local expertise, making it a critical planning item.
What ADR reviews: The ADR assessment evaluates the CASP’s cybersecurity architecture, operational resilience frameworks, system continuity plans, and alignment with the Digital Operational Resilience Act (DORA). Applicants must submit detailed technical documentation covering infrastructure design, security controls, incident response procedures, and data protection measures. Underprepared submissions will delay clearance and, by extension, the entire licensing timeline.
The ADR clearance process typically takes 2 to 4 weeks for well-prepared applicants. A complete and professionally assembled technical submission is the single most reliable way to keep this stage within its expected duration.
ICI clearance for crypto ATMs: CASPs operating physical crypto ATMs in Romania must obtain an additional hardware approval from the National Institute for Informatics (ICI) in addition to the standard ADR IT clearance. This hardware pre-clearance requirement applies specifically to ATM infrastructure and does not affect software-only CASP operations.
Governance, AML, and Substance Requirements
Capital and IT clearance represent only part of the authorisation picture. ASF also evaluates governance quality, AML program adequacy, and organisational substance as part of the CASP application review. These areas are underrepresented in most published guides on Romanian crypto licensing but are assessed with the same rigour as capital and technical requirements.
Governance requirements:
- Local director: At least one board member with EU residency and relevant professional experience. Fit-and-proper assessments apply to all key function holders;
- Governance documentation: Board charters, conflict of interest policies, remuneration policies, and clear delegation of authority structures are required;
- Cybersecurity policies: ASF expects documented cybersecurity governance aligned with DORA requirements, which overlap with but are distinct from the ADR pre-clearance review.
AML/CFT requirements:
- An AML compliance program fully aligned with Law 129/2019, which treats CASPs as financial institutions subject to the same due diligence and monitoring obligations as banks and payment institutions;
- Detailed KYC policies covering customer identification, beneficial ownership determination, enhanced due diligence for high-risk customers, and procedures for unhosted wallet interactions;
- A designated AML compliance officer with documented responsibilities and reporting lines to the board;
- Transaction monitoring framework with defined alert thresholds, escalation procedures, and STR filing protocols with ONPCSB.