top of page
Search

EU Crypto Licensing Roadmap for CASPs in 2026

  • Writer: NUR Legal
    NUR Legal
  • 9 hours ago
  • 6 min read

The final MiCA transition deadlines are no longer a distant regulatory event. For many firms, 2026 is the point at which legacy national registrations stop being a viable route to market. An EU crypto licensing roadmap for CASPs must therefore answer a commercial question first: can the business obtain and maintain MiCA authorisation in time to serve the EU without disrupting customers, banking, technology or fundraising?

MiCA has replaced a fragmented licensing landscape with a single authorisation framework for crypto-asset service providers. That does not mean every application is the same, or that choosing any EU member state produces the same outcome. Regulatory practice, application capacity, supervisory expectations and the strength of the local operating substance still affect speed and risk.

EU crypto licensing roadmap for CASPs: start with the actual service model

The first task is to map the business against MiCA's defined crypto-asset services. A firm may provide custody and administration, operate a trading platform, exchange crypto-assets for funds or other crypto-assets, execute orders, place crypto-assets, receive and transmit orders, provide advice, manage portfolios or offer transfer services.

This classification drives the application scope, capital requirement, internal controls and the experience expected from senior management. It also exposes a common problem: many businesses describe themselves as an exchange or wallet provider, while their real product combines several regulated services. A custody wallet with swap functionality, fiat on-ramp partners, client order handling and token listings needs to be assessed as an integrated model, not through its marketing label.

Before choosing a jurisdiction, prepare a written service map covering the customer journey, asset flows, revenue model, counterparties, technology stack and countries served. Identify which activities the applicant will perform itself and which will be outsourced. A vague model creates regulator questions late in the process, when changes cost time and credibility.

Do not confuse licensing with token issuance

CASP authorisation concerns the services provided to clients. Issuing, offering or seeking admission to trading of a crypto-asset can create separate MiCA obligations, including crypto-asset white paper requirements. Asset-referenced tokens and e-money tokens are subject to more restrictive regimes and may require an issuer with the appropriate authorisation.

A platform can therefore be compliant as a CASP while still creating exposure through its listing process, proprietary token, stablecoin offering or promotional materials. The licensing workstream must include product and token analysis from the outset.

Choose the home member state on execution, not headline cost

A MiCA authorisation is granted by the competent authority in one EU member state and can then support passporting of authorised services across the EU. This makes the initial jurisdiction decision commercially significant. It determines the authority reviewing the application, the local substance expected, the pace of engagement and the firm’s first supervisory relationship.

There is no universally best jurisdiction. A founder-led business entering its first regulated market may prioritise an authority with a clear application process and an ecosystem that supports compliance hiring, banking and audit. A larger group may place more weight on governance infrastructure, tax position, group operations and the ability to locate meaningful management locally.

The cheapest incorporation option is often the most expensive licensing decision. A low-cost structure with nominee leadership, little local control and an untested compliance function is difficult to defend when an authority asks who makes decisions, monitors outsourced providers or owns risk. A credible application needs substance that matches the scale and risk of the proposed service.

For existing virtual asset providers, transitional arrangements require particular care. Member states have been able to apply national grandfathering periods, but these cannot extend beyond 1 July 2026. The precise route depends on the jurisdiction and the firm’s prior status. New entrants should not assume a legacy registration offers a shortcut to launch. Confirm the local position before relying on any transition period in a commercial plan.

Build the application as an operating file

MiCA applications are assessed on evidence, not aspirations. Regulators want to see that the applicant can operate safely on day one, not that it intends to hire a compliance team after approval.

The core file normally includes the programme of operations, business plan, governance arrangements, ownership information, financial projections, safeguarding and custody arrangements where relevant, ICT documentation, outsourcing controls, complaints handling and policies for conflicts of interest, market abuse, client communications and business continuity. Directors and key function holders must be fit and proper, with sufficient knowledge, time commitment and a defensible division of responsibilities.

AML is not a side document. The firm needs a risk assessment tailored to its customers, geographies, products, transaction patterns and distribution channels. It should lead directly to practical controls: customer due diligence, source of funds and source of wealth escalation, sanctions screening, transaction monitoring, suspicious activity reporting, record retention and staff training.

Generic policies are a frequent cause of weak applications. An authority can quickly identify a template that says one thing while the product design does another. If customers can self-custody assets, transact through high-risk addresses or use third-party payment providers, those facts need to appear in the risk assessment and operating procedures.

Treat DORA and the Travel Rule as launch requirements

A CASP licence cannot be planned in isolation from the wider EU regulatory framework. The Transfer of Funds Regulation extends Travel Rule obligations to crypto-asset transfers. Firms need processes to collect, transmit, verify where required and manage missing originator and beneficiary information. This affects wallet design, transfers to self-hosted addresses, vendor selection and customer communications.

DORA adds another operational layer. CASPs need governance over ICT risk, incident management, business continuity, testing and third-party technology arrangements. For a crypto business relying on cloud infrastructure, custody technology, blockchain analytics, transaction monitoring and identity verification suppliers, this is material rather than administrative.

Outsourcing does not transfer accountability. The applicant must understand its suppliers, document contractual rights, monitor performance and maintain exit planning. A technology provider’s standard contract rarely meets every regulatory expectation without review and amendment.

Capital, safeguarding and financial resilience

MiCA requires prudential safeguards, with the applicable initial capital threshold depending on the services offered. The firm must also maintain own funds at the required level. Financial projections should be realistic about compliance staffing, external audit, insurance where appropriate, legal support, systems costs and the runway required before revenue stabilises.

For custodians and trading platforms, client asset protection is central. Operational arrangements should make it clear how client crypto-assets and funds are identified, protected, reconciled and returned if the business fails. A polished corporate structure will not compensate for unclear asset segregation or weak wallet-control procedures.

Plan the approval timetable around dependencies

The statutory assessment process is only one part of the timeline. A complete application requires a legal entity, appropriate directors, local substance, bank or payment arrangements, capital funding, technology architecture, policies, vendor agreements and a mature control framework. Delays usually arise where these dependencies are treated as separate projects.

A practical programme begins with a gap assessment and jurisdiction decision, then converts the target operating model into governance, policy and evidence workstreams. Senior appointments and shareholder information should be resolved early, particularly where a group has complex ownership or overseas controllers. The application should be internally reviewed as a regulator would review it: does every statement match the product, contracts, system configuration and budget?

Engagement with the competent authority should be disciplined. Answer questions directly, preserve consistency across documents and avoid changing the business model during review unless the change is necessary and properly explained. A rushed filing can create more delay than a controlled pre-application build.

Decide whether to build or acquire

For some operators, a fresh MiCA authorisation is the correct route because it gives full control over the entity, governance and operating model. For others, acquiring a pre-structured or already regulated business may reduce time to market. The second route is not automatically faster.

A target must be examined for the scope and status of its permissions, its regulatory history, ownership restrictions, client liabilities, technology contracts, AML files, financial position and change-of-control requirements. Buying a company with an attractive licence but weak operational records can import the very risk the acquisition was intended to avoid.

The better choice depends on urgency, available management capacity, appetite for integration risk and the true cost of delay. NUR Legal approaches this as an execution decision: align the legal route, compliance build and transaction timetable before committing capital.

A credible MiCA programme is not a stack of policies prepared for submission. It is the operating foundation that lets a CASP show regulators, banks, counterparties and customers that it is ready to trade responsibly. Start with the real business model, fund the controls needed to support it, and make every document capable of surviving regulatory scrutiny.

 
 
 

Comments


Contact

NUR Legal OÜ

Registry code: 17142784

VAT nr. EE102815012

+37258339358

  • Facebook
  • Телеграмма
  • Linkedin
  • Instagram
NUR Legal map_edited.jpg

Thanks for submitting!

JURISFIN Verification Badge

News & Articles •  Terms of UsePrivacy Policy
© 2026 NUR Legal All rights reserved.

bottom of page