MiCA Regulation
The Markets in Crypto-Assets Regulation (MiCA) is the EU’s comprehensive licensing and disclosure framework for crypto-asset issuers and service providers. It applies across all 27 member states and has been fully in force since December 30, 2024. LegalBison advises crypto founders, exchanges, stablecoin issuers, and payment platforms on CASP authorization, MiCA licensing, and jurisdiction selection across the EU.
This page tracks MiCA’s implementation status by member state, explains which activities fall inside and outside scope, and outlines what a complete CASP application requires.
Book a free consultation
Request a consultationBackground of the MiCA Regulation
Historical and legal basis of the Markets in Crypto Assets regulation
The MiCA regulation is the new unified set of rules prepared by the EU to manage and control the use and spread of crypto assets across all its Member States. The main objective of MiCA is to regulate all crypto-related businesses that fall into its scope according to one clearly defined rulebook. Here is what crypto business owners can expect from MiCA once it comes into force.
When was the MiCA regulation enforced?
What MiCA regulation covers and what it does not
MiCA defines its scope precisely. The distinction between in-scope and out-of-scope matters because it determines whether a business requires CASP authorization, token issuance authorization, or neither.
In scope
- Stablecoin issuers: Issuers of asset-referenced tokens (ARTs), which maintain stable value by referencing a basket of assets, fiat currencies, or commodities, and issuers of e-money tokens (EMTs), which maintain stable value by referencing a single fiat currency. Both categories carry authorization and reserve requirements under MiCA Titles III and IV;
- CASP operators****: Any legal entity providing one or more of the regulated crypto-asset services defined in MiCA Article 3(1)(16), operating on a professional basis in or to EU clients. The full CASP service categories are covered in the next section;
- Crypto-asset issuers making public offerings: Projects issuing crypto-assets other than ARTs or EMTs and offering them to the public in the EU must publish a MiCA-compliant whitepaper and comply with the disclosure obligations in MiCA Title II.
Out of scope
- Fully decentralized DeFi protocols: Where no identifiable legal entity controls the protocol or provides services on the basis of that protocol, MiCA does not apply. The decentralization threshold is not precisely defined in the regulation, and ESMA has acknowledged that most DeFi protocols have some degree of centralized governance that may bring them within scope. Each DeFi project requires legal analysis against its specific architecture;
- Most NFT platforms: MiCA excludes unique and non-fungible crypto-assets from its scope where they are not interchangeable. However, fractional NFT collections, large-batch NFT issuances, and NFT platforms that also custody or exchange fungible tokens may fall partially within scope;
- Central bank digital currencies (CBDCs): CBDCs issued by EU central banks are explicitly excluded;
- Financial instruments already regulated under MiFID II: Securities tokens and instruments that qualify as financial instruments under MiFID II are regulated under that framework, not MiCA. The boundaries between MiCA and MiFID II require careful analysis for tokenized securities and hybrid instruments.
Categories of CASP activities regulated under MiCA
MiCA authorization is activity-specific. A CASP holding authorization for one service category is not automatically authorized for others. A business operating across multiple categories must obtain authorization for each, and the authorization scope must match the actual services provided. MiCA defines the following regulated CASP activities:
- Custody and administration of crypto-assets on behalf of clients;
- Operation of a trading platform for crypto-assets;
- Exchange of crypto-assets for fiat funds;
- Exchange of crypto-assets for other crypto-assets;
- Execution of orders for crypto-assets on behalf of clients;
- Placing of crypto-assets;
- Reception and transmission of orders for crypto-assets on behalf of clients;
- Providing advice on crypto-assets;
- Providing portfolio management of crypto-assets;
- Providing transfer services for crypto-assets to clients.
Passport-eligible activities: All ten CASP service categories are passport-eligible. Authorization in one EU member state covers provision of the same authorized services across all 27 member states and the EEA, subject to standard passporting notification to the host NCA. Activities that may trigger dual licensing: Transfer services and the placing of crypto-assets can overlap with payment services regulated under PSD2. Businesses whose crypto transfer architecture involves the movement of fiat funds, the initiation of payment transactions, or the holding of client fiat balances may require an Electronic Money Institution (EMI) or Payment Institution (PI) authorization in addition to their CASP license. The dual-licensing question is business-model-specific and should be analyzed before application.
MiCA regulation tracker by country
The table below reflects the implementation status and relative positioning of key member states as of early 2026. ESMA maintains the public register of authorized CASPs at esma.europa.eu.
| Country | NCA | MiCA Adopted | Key Notes |
|---|---|---|---|
| Poland | N/A | No | High volume; English-language engagement; strong crypto licensing track record |
| Lithuania | Bank of Lithuania | Yes | Recognized fintech hub; EMI infrastructure well-developed for crypto businesses |
| Germany | BaFin | Yes | Thorough review process; established crypto custodian authorization track record pre-MiCA |
| France | AMF | Yes | PSAN regime preceded MiCA; transitioning to full CASP authorization |
| Netherlands | AFM | Yes | DNB held VASP responsibilities pre-MiCA; transition to AFM CASP authorization ongoing |
| Malta | MFSA | Yes | Early EU crypto regulator; established licensing infrastructure |
| Cyprus | CySEC | Yes | Active fintech licensing history; attractive for mid-size operators |
| Czech Republic | CNB | Yes | Pro-innovation regulator; English-language process; strong operational cost advantage |
| Estonia | EFSA | Yes | Legacy VASP regime replaced by MiCA CASP process |
| Luxembourg | CSSF | Yes | Financial center with institutional-grade infrastructure |
| Austria | FMA | Yes | Stable regulatory environment; German-language primary |
Which EU member states have issued the most CASP authorizations
Lithuania has processed the highest volumes of CASP applications in the early phases of MiCA implementation, reflecting its established fintech licensing infrastructure and English-language regulatory engagement. Germany, France, and the Netherlands follow in terms of institutional application volumes. Malta and Cyprus attract mid-size operators with established legal service ecosystems. Czech Republic and Estonia are gaining ground among early-stage applicants for whom operational cost and regulatory accessibility are primary selection criteria.
The optimal jurisdiction for any specific applicant depends on business model, target markets, operational footprint, and banking requirements. LegalBison conducts jurisdiction assessments as the first step in every CASP engagement. See crypto licensing in Europe for full jurisdiction-by-jurisdiction analysis.
MiCA defines its scope precisely. The distinction between in-scope and out-of-scope matters because it determines whether a business requires CASP authorization, token issuance authorization, or neither.
In scope
- Stablecoin issuers: Issuers of asset-referenced tokens (ARTs), which maintain stable value by referencing a basket of assets, fiat currencies, or commodities, and issuers of e-money tokens (EMTs), which maintain stable value by referencing a single fiat currency. Both categories carry authorization and reserve requirements under MiCA Titles III and IV;
- CASP operators****: Any legal entity providing one or more of the regulated crypto-asset services defined in MiCA Article 3(1)(16), operating on a professional basis in or to EU clients. The full CASP service categories are covered in the next section;
- Crypto-asset issuers making public offerings: Projects issuing crypto-assets other than ARTs or EMTs and offering them to the public in the EU must publish a MiCA-compliant whitepaper and comply with the disclosure obligations in MiCA Title II.
Out of scope
- Fully decentralized DeFi protocols: Where no identifiable legal entity controls the protocol or provides services on the basis of that protocol, MiCA does not apply. The decentralization threshold is not precisely defined in the regulation, and ESMA has acknowledged that most DeFi protocols have some degree of centralized governance that may bring them within scope. Each DeFi project requires legal analysis against its specific architecture;
- Most NFT platforms: MiCA excludes unique and non-fungible crypto-assets from its scope where they are not interchangeable. However, fractional NFT collections, large-batch NFT issuances, and NFT platforms that also custody or exchange fungible tokens may fall partially within scope;
- Central bank digital currencies (CBDCs): CBDCs issued by EU central banks are explicitly excluded;
- Financial instruments already regulated under MiFID II: Securities tokens and instruments that qualify as financial instruments under MiFID II are regulated under that framework, not MiCA. The boundaries between MiCA and MiFID II require careful analysis for tokenized securities and hybrid instruments.
MiCA authorization is activity-specific. A CASP holding authorization for one service category is not automatically authorized for others. A business operating across multiple categories must obtain authorization for each, and the authorization scope must match the actual services provided. MiCA defines the following regulated CASP activities:
- Custody and administration of crypto-assets on behalf of clients;
- Operation of a trading platform for crypto-assets;
- Exchange of crypto-assets for fiat funds;
- Exchange of crypto-assets for other crypto-assets;
- Execution of orders for crypto-assets on behalf of clients;
- Placing of crypto-assets;
- Reception and transmission of orders for crypto-assets on behalf of clients;
- Providing advice on crypto-assets;
- Providing portfolio management of crypto-assets;
- Providing transfer services for crypto-assets to clients.
Passport-eligible activities: All ten CASP service categories are passport-eligible. Authorization in one EU member state covers provision of the same authorized services across all 27 member states and the EEA, subject to standard passporting notification to the host NCA. Activities that may trigger dual licensing: Transfer services and the placing of crypto-assets can overlap with payment services regulated under PSD2. Businesses whose crypto transfer architecture involves the movement of fiat funds, the initiation of payment transactions, or the holding of client fiat balances may require an Electronic Money Institution (EMI) or Payment Institution (PI) authorization in addition to their CASP license. The dual-licensing question is business-model-specific and should be analyzed before application.
The table below reflects the implementation status and relative positioning of key member states as of early 2026. ESMA maintains the public register of authorized CASPs at esma.europa.eu.
| Country | NCA | MiCA Adopted | Key Notes |
|---|---|---|---|
| Poland | N/A | No | High volume; English-language engagement; strong crypto licensing track record |
| Lithuania | Bank of Lithuania | Yes | Recognized fintech hub; EMI infrastructure well-developed for crypto businesses |
| Germany | BaFin | Yes | Thorough review process; established crypto custodian authorization track record pre-MiCA |
| France | AMF | Yes | PSAN regime preceded MiCA; transitioning to full CASP authorization |
| Netherlands | AFM | Yes | DNB held VASP responsibilities pre-MiCA; transition to AFM CASP authorization ongoing |
| Malta | MFSA | Yes | Early EU crypto regulator; established licensing infrastructure |
| Cyprus | CySEC | Yes | Active fintech licensing history; attractive for mid-size operators |
| Czech Republic | CNB | Yes | Pro-innovation regulator; English-language process; strong operational cost advantage |
| Estonia | EFSA | Yes | Legacy VASP regime replaced by MiCA CASP process |
| Luxembourg | CSSF | Yes | Financial center with institutional-grade infrastructure |
| Austria | FMA | Yes | Stable regulatory environment; German-language primary |
Which EU member states have issued the most CASP authorizations
Lithuania has processed the highest volumes of CASP applications in the early phases of MiCA implementation, reflecting its established fintech licensing infrastructure and English-language regulatory engagement. Germany, France, and the Netherlands follow in terms of institutional application volumes. Malta and Cyprus attract mid-size operators with established legal service ecosystems. Czech Republic and Estonia are gaining ground among early-stage applicants for whom operational cost and regulatory accessibility are primary selection criteria.
The optimal jurisdiction for any specific applicant depends on business model, target markets, operational footprint, and banking requirements. LegalBison conducts jurisdiction assessments as the first step in every CASP engagement. See crypto licensing in Europe for full jurisdiction-by-jurisdiction analysis.
They reached success and shared it with us:
LegalBison assists its clients with crypto licensing
How to get a European crypto license under MiCA
A complete MiCA application is not a form submission. It is a structured dossier that addresses regulatory, governance, and financial requirements defined by both MiCA itself and ESMA’s delegated technical standards. The documents that most frequently cause delays when missing or underspecified are listed below.
Legal opinion on business model classification
Legal opinion on business model classification
Required before the NCA can assess which CASP categories apply. The opinion must map the applicant’s specific technical and commercial model, including token types, custody arrangements, and client-facing flows, to the MiCA activity definitions. Generic whitepapers do not satisfy this requirement. NCAs return applications that lack a precise classification analysis.
Minimum own funds by activity category
Minimum own funds by activity category
| Capital Tier | Min. Own Funds | Applicable CASP Activities |
|---|---|---|
| Tier 1 | EUR 50,000 | Advice on crypto-assets, reception and transmission of orders, placing of crypto-assets |
| Tier 2 | EUR 125,000 | Exchange for fiat funds, exchange for other crypto-assets, execution of orders, operation of a trading platform |
| Tier 3 | EUR 150,000 | Custody and administration, portfolio management, transfer services to clients |
Capital must be fully paid up and maintained on an ongoing basis. For businesses operating across multiple categories, the highest applicable threshold applies.
Fit and Proper assessment for key function holders
Fit and Proper assessment for key function holders
Directors, the MLRO, and beneficial owners holding more than 10% of the applicant must each be individually assessed and documented against the Fit and Proper criteria in MiCA Article 31. The assessment covers professional qualifications, regulatory history, criminal record, and reputational standing. NCAs verify these individually and any gap in the Fit and Proper package triggers a request for information that pauses the review.
AML/CFT program tailored to the business model
AML/CFT program tailored to the business model
The AML/CFT program must map to the applicant’s specific user flows, product architecture, and risk profile. A generic AML policy template does not satisfy ESMA’s technical standards. The program must address customer risk categorization, transaction monitoring thresholds, Travel Rule implementation, and the MLRO’s escalation procedures in the context of the applicant’s actual service.
Client asset safeguarding arrangements
Client asset safeguarding arrangements
CASPs that hold crypto-assets or fiat funds on behalf of clients must demonstrate segregation arrangements before authorization is granted. This includes custody agreements, sub-custody arrangements where applicable, and documented client fund reconciliation procedures. Many first-time applicants attempt to address this requirement after submission; NCAs expect it to be resolved before the application is filed.
IT security framework and DORA alignment
IT security framework and DORA alignment
From January 17, 2025, the Digital Operational Resilience Act (DORA) applies to all regulated financial entities in the EU, including licensed CASPs. The MiCA application must address ICT risk management, incident reporting procedures, third-party provider oversight, and operational resilience testing.
Business plan and three-year financial projections
Business plan and three-year financial projections
The business plan must demonstrate a credible path to regulatory capital maintenance, describe the governance structure in detail, and project financial performance over three years. Projections that assume unrealistic growth curves or revenue trajectories are flagged during review.
Legal opinion on business model classification
Required before the NCA can assess which CASP categories apply. The opinion must map the applicant’s specific technical and commercial model, including token types, custody arrangements, and client-facing flows, to the MiCA activity definitions. Generic whitepapers do not satisfy this requirement. NCAs return applications that lack a precise classification analysis.
Minimum own funds by activity category
| Capital Tier | Min. Own Funds | Applicable CASP Activities |
|---|---|---|
| Tier 1 | EUR 50,000 | Advice on crypto-assets, reception and transmission of orders, placing of crypto-assets |
| Tier 2 | EUR 125,000 | Exchange for fiat funds, exchange for other crypto-assets, execution of orders, operation of a trading platform |
| Tier 3 | EUR 150,000 | Custody and administration, portfolio management, transfer services to clients |
Capital must be fully paid up and maintained on an ongoing basis. For businesses operating across multiple categories, the highest applicable threshold applies.
Fit and Proper assessment for key function holders
Directors, the MLRO, and beneficial owners holding more than 10% of the applicant must each be individually assessed and documented against the Fit and Proper criteria in MiCA Article 31. The assessment covers professional qualifications, regulatory history, criminal record, and reputational standing. NCAs verify these individually and any gap in the Fit and Proper package triggers a request for information that pauses the review.
AML/CFT program tailored to the business model
The AML/CFT program must map to the applicant’s specific user flows, product architecture, and risk profile. A generic AML policy template does not satisfy ESMA’s technical standards. The program must address customer risk categorization, transaction monitoring thresholds, Travel Rule implementation, and the MLRO’s escalation procedures in the context of the applicant’s actual service.
Client asset safeguarding arrangements
CASPs that hold crypto-assets or fiat funds on behalf of clients must demonstrate segregation arrangements before authorization is granted. This includes custody agreements, sub-custody arrangements where applicable, and documented client fund reconciliation procedures. Many first-time applicants attempt to address this requirement after submission; NCAs expect it to be resolved before the application is filed.
IT security framework and DORA alignment
From January 17, 2025, the Digital Operational Resilience Act (DORA) applies to all regulated financial entities in the EU, including licensed CASPs. The MiCA application must address ICT risk management, incident reporting procedures, third-party provider oversight, and operational resilience testing.
Business plan and three-year financial projections
The business plan must demonstrate a credible path to regulatory capital maintenance, describe the governance structure in detail, and project financial performance over three years. Projections that assume unrealistic growth curves or revenue trajectories are flagged during review.
Common MiCA application mistakes
The following patterns consistently extend review timelines or result in rejection at the preliminary assessment stage.
Underspecified AML/CFT program
Underspecified AML/CFT program
A generic AML policy template does not satisfy ESMA’s Level 2 technical standards. The program must map directly to the applicant’s specific user flows and risk profile. An exchange serving retail clients across 15 countries with on-ramp services has a materially different risk profile from an OTC desk serving institutional counterparties. The AML documentation must reflect that difference. Submissions that arrive with the same generic framework used for a different jurisdiction or a different business type are returned.
Missing client asset safeguarding arrangements
Missing client asset safeguarding arrangements
CASPs that hold client assets must demonstrate segregation arrangements before authorization. Many first-time applicants treat this as a post-authorization operational matter. NCAs treat it as a pre-authorization documentation requirement. The result is a request for information that pauses the review clock at the point when the applicant expected approval.
Vague business model descriptions
Vague business model descriptions
The NCA cannot assess the scope without a precise technical description of the service. An application that describes the business as a crypto exchange without specifying token types, custody model, order book architecture, and client-facing fund flows gives the NCA nothing to assess against the MiCA activity definitions. The model must be described with enough precision that the authorization scope can be drawn exactly.
Mismatched capital and activity scope
Mismatched capital and activity scope
Applicants sometimes underestimate their capital requirement by excluding service categories from their activity description. If the operational reality includes custodying client assets (EUR 150,000 threshold), but the application describes the business as a simple exchange (EUR 125,000 threshold), the NCA will identify the discrepancy during review and require a revised application and capital plan.
Inadequate Fit and Proper preparation
Inadequate Fit and Proper preparation
Beneficial owners, directors, and MLROs who have not prepared their Fit and Proper documentation in advance create the most common single-point delay in MiCA applications. NCA requests for Fit and Proper supplementary information are among the slowest to resolve because they depend on individuals gathering personal documentation, sometimes across multiple jurisdictions.
Underspecified AML/CFT program
A generic AML policy template does not satisfy ESMA’s Level 2 technical standards. The program must map directly to the applicant’s specific user flows and risk profile. An exchange serving retail clients across 15 countries with on-ramp services has a materially different risk profile from an OTC desk serving institutional counterparties. The AML documentation must reflect that difference. Submissions that arrive with the same generic framework used for a different jurisdiction or a different business type are returned.
Missing client asset safeguarding arrangements
CASPs that hold client assets must demonstrate segregation arrangements before authorization. Many first-time applicants treat this as a post-authorization operational matter. NCAs treat it as a pre-authorization documentation requirement. The result is a request for information that pauses the review clock at the point when the applicant expected approval.
Vague business model descriptions
The NCA cannot assess the scope without a precise technical description of the service. An application that describes the business as a crypto exchange without specifying token types, custody model, order book architecture, and client-facing fund flows gives the NCA nothing to assess against the MiCA activity definitions. The model must be described with enough precision that the authorization scope can be drawn exactly.
Mismatched capital and activity scope
Applicants sometimes underestimate their capital requirement by excluding service categories from their activity description. If the operational reality includes custodying client assets (EUR 150,000 threshold), but the application describes the business as a simple exchange (EUR 125,000 threshold), the NCA will identify the discrepancy during review and require a revised application and capital plan.
Inadequate Fit and Proper preparation
Beneficial owners, directors, and MLROs who have not prepared their Fit and Proper documentation in advance create the most common single-point delay in MiCA applications. NCA requests for Fit and Proper supplementary information are among the slowest to resolve because they depend on individuals gathering personal documentation, sometimes across multiple jurisdictions.
How LegalBison helps your business to be MiCA-compliant
LegalBison maps each client’s business model to its specific MiCA obligations and identifies the optimal EU jurisdiction for CASP authorization before the application process begins. That upfront analysis determines the correct CASP activity categories, the applicable capital threshold, the passporting strategy, and the NCA most suited to the client’s operational profile and timeline.
The most common CASP models and their MiCA positions:
- Centralized exchange operators (CEX). Authorization for exchange for fiat funds, exchange for crypto-assets, and operation of a trading platform. Capital threshold: EUR 125,000 to EUR 150,000 depending on trading model. Optimal jurisdictions: Poland, Lithuania, Czech Republic. See crypto licensing in Europe;
- OTC desks and brokerage platforms. Authorization for exchange for fiat funds and execution of orders. Capital threshold: EUR 125,000. Dual licensing required if client fiat balances are held between settlement cycles. Related: VASP license and DASP license frameworks for non-EU jurisdictions;
- Portfolio managers. Authorization for portfolio management of crypto-assets. Capital threshold: EUR 150,000. MiCA governance obligations apply, including segregated mandate documentation and client reporting. Optimal jurisdictions: Luxembourg, Germany, France;
- Crypto payment processors and on/off-ramp providers. Authorization for transfer services, combined with EMI or PI licensing where fiat payment initiation or settlement is involved. Dual-licensing analysis is mandatory before application. Optimal jurisdictions: Lithuania, Poland, Malta;
- Token issuance projects. Public offering of crypto-assets under MiCA Title II requires a compliant whitepaper and, where the token qualifies as an ART or EMT, full stablecoin authorization. Legal classification of the token precedes any regulatory filing.
LegalBison manages the complete application lifecycle: business model classification, jurisdiction selection, legal opinion production, compliance program design, NCA engagement, application drafting, submission, and post-authorization compliance support.
For MiCA CASP authorization, stablecoin licensing, and MiCA compliance infrastructure, contact LegalBison.
FAQ about the MiCA license and regulation
Before MiCA, crypto regulation in Europe was fragmented. Each country ran its own national regime. A company could obtain a crypto exchange license, a VASP license or a DASP license in one country under relatively light requirements and use it to reach European customers, sometimes with minimal ongoing supervision. That time is over. MiCA replaces those national patchworks with one standard framework.
Aaron Glauberman
Co-Founder & Managing Partner
