top of page
Search

MiCA Authorisation Versus VASP Registration

  • Writer: NUR Legal
    NUR Legal
  • Jul 15
  • 6 min read

A legacy VASP registration may have allowed a crypto business to open locally and meet anti-money laundering obligations. It does not, by itself, prove that the business is ready to operate under MiCA. The practical question behind MiCA authorisation versus VASP registration is whether your operating model, governance, capital and controls can withstand full EU regulatory scrutiny - not whether you already hold a national registration.

For founders and operators planning EU activity, treating MiCA as a simple licence replacement is a costly mistake. The change affects where you establish, which services you can provide, how you safeguard client assets, who sits on the management body and how quickly you can expand across the EEA.

MiCA authorisation versus VASP registration: the fundamental difference

VASP registration developed under the EU’s anti-money laundering framework, particularly the Fifth Anti-Money Laundering Directive. Each Member State implemented that framework differently. Some regimes required a relatively focused registration with the financial intelligence unit or national supervisor; others imposed more detailed local licensing conditions. The central purpose was to bring virtual asset businesses into the AML and counter-terrorist financing perimeter.

MiCA authorisation is broader. It regulates crypto-asset service providers, or CASPs, as financial-market participants. A successful application must show that the applicant has an appropriate legal and operational structure, effective governance, adequate own funds, complaint-handling arrangements, conflict management, ICT security, continuity planning and controls appropriate to the services offered.

This is why a previously registered VASP can still face a substantial MiCA implementation project. The authority will assess the complete business, rather than only its AML policies and beneficial ownership information. A registration may be useful evidence of operational history, but it is not a shortcut through the authorisation process.

What MiCA changes for the operating model

MiCA captures a defined range of crypto-asset services. These include custody and administration of crypto-assets for clients, operation of a trading platform, exchange of crypto-assets for funds or other crypto-assets, execution and reception of orders, placing, transfer services, advice and portfolio management.

The exact permission set matters. A business offering hosted wallets, for example, may require custody authorisation, while an exchange model can involve separate exchange and order-execution permissions. Adding staking, lending, fiat payments, token issuance or a white-label structure can introduce additional regulatory analysis outside MiCA. A licence strategy built around broad marketing language rather than the actual customer journey often creates avoidable gaps.

MiCA also changes the commercial value of an EU authorisation. Once authorised in its home Member State, a CASP can generally passport relevant services across the EEA through the notification process. A national VASP registration was not designed to deliver that outcome. It commonly left operators assessing country-by-country obligations, local marketing rules and different supervisory expectations before entering each market.

Passporting is powerful, but it is not a reason to choose a home jurisdiction purely on speed. Your registered office, central administration and real operational substance must align with the selected Member State. Supervisors will examine whether senior decision-making, compliance oversight and outsourced functions are genuinely controlled from the proposed home state.

Governance is now an application issue, not a post-launch task

Under MiCA, the management body must be sufficiently reputable and competent to run the proposed crypto business. This requires more than appointing directors shortly before filing. The applicant needs a credible organisation chart, clear division of responsibility, documented fitness and propriety assessments, and evidence that key people understand the services, risks and regulatory duties involved.

Outsourcing can support an efficient model, particularly for AML screening, custody technology, cybersecurity or internal audit. It does not transfer responsibility to the provider. The CASP must retain oversight, monitor performance and preserve access to data, records and business continuity arrangements. A thin local entity with every meaningful function outsourced is likely to attract difficult questions.

Operational resilience deserves the same early attention. DORA applies to CASPs and requires disciplined ICT risk management, incident handling, testing, third-party risk controls and governance. A MiCA application supported by generic security statements but no tested operational framework is unlikely to inspire regulator confidence.

Capital, client assets and conduct obligations

MiCA imposes initial capital requirements that vary according to the services provided. The relevant thresholds are generally EUR 50,000, EUR 125,000 or EUR 150,000, with ongoing own-funds requirements also linked to the nature and scale of the business. Capital should be assessed early because it affects funding plans, group structure and the credibility of financial projections.

The more commercially sensitive requirements often concern client protection. Custody providers need clear arrangements for safeguarding clients’ rights to crypto-assets, maintaining records and separating client holdings from proprietary assets. Trading platforms and execution businesses need transparent rules, fair and orderly trading controls, and effective procedures for conflicts of interest, complaints and market-abuse monitoring.

These obligations are not paperwork for a compliance folder. They determine how wallets are configured, how reconciliation occurs, who can approve transfers, what happens when a client disputes a transaction, and how the business responds to an incident. If the technology and legal framework are designed separately, remediation later is usually slower and more expensive.

Transitional arrangements: do not rely on an expired VASP route

MiCA allowed Member States to apply transitional arrangements for certain existing crypto businesses. Those arrangements were never identical across the EU, and national authorities could set earlier deadlines or impose local conditions. The general MiCA transitional period ended on 1 July 2026, although an application filed within the applicable national framework could have affected the position of a qualifying incumbent while its file was being considered.

For businesses still relying on a VASP registration, the immediate task is to confirm the position in the relevant Member State rather than assume a historic registration remains sufficient. The answer depends on the activities actually provided, the local transitional rules applied, whether a MiCA application was made correctly and the authority’s current status of that application.

A business operating without the required authorisation risks more than an enforcement issue. Banking partners, payment institutions, institutional clients, token counterparties and prospective acquirers increasingly ask for evidence of MiCA readiness. Weaknesses in licensing status can delay commercial onboarding or reduce transaction value long before a regulator takes formal action.

How to prepare a credible MiCA application

The strongest applications are built from the operating model outward. Start by mapping every service, customer type, token flow, revenue stream and outsourcing relationship. This identifies the correct authorisation perimeter and exposes activities that require separate analysis, such as payment services or regulated financial instruments.

Next, select the home Member State on evidence rather than reputation. Compare regulatory practice, substance requirements, expected supervisory engagement, staffing availability, corporate and tax considerations, banking access and the realistic timing of implementation. The fastest-looking jurisdiction is not always the fastest route to approval if the business cannot establish credible local management and operations there.

The legal, compliance and technical workstreams should then move together. Corporate documents, programme of operations, financial forecasts, governance policies, AML controls, custody procedures, ICT documentation and outsourcing agreements must describe the same business. Inconsistencies between the application narrative, contracts and product design are a common source of regulator questions.

Finally, prepare the people who will meet the supervisor. Directors, compliance officers and operational leads should be able to explain the model, key risks, escalation routes and controls in practical terms. Regulators assess whether the applicant can operate safely after approval, not merely whether it can submit a well-formatted file.

When a VASP registration may still matter

A VASP registration can still be relevant as part of the business history, AML record and transition analysis. It may also remain relevant for services or structures that sit outside MiCA’s scope, but that assessment is fact-specific. Unique non-fungible tokens, decentralised arrangements, group services and activities involving financial instruments cannot be classified safely using labels alone.

Nor should firms rely on a narrow interpretation of reverse solicitation to serve EU clients from outside the EEA. This exemption is limited and does not support an active EU acquisition strategy. Marketing, affiliate arrangements, local language campaigns and product adaptation can all undermine the argument that a client approached the provider exclusively on their own initiative.

For acquisition-minded founders, a ready-made entity should be assessed with equal care. The value lies not simply in a company’s age or historic registration, but in its current regulatory status, substance, ownership history, records, contractual position and ability to meet the intended MiCA permission scope. Buying the wrong vehicle can create inherited risk without delivering speed.

MiCA has moved EU crypto market entry from registration-led compliance to authorisation-led execution. The businesses that progress efficiently are those that make the licence perimeter, jurisdiction, governance and product controls agree before the application reaches the regulator. Contact NUR Legal to identify the route that supports your launch plan without building avoidable regulatory debt into the business.

 
 
 

Comments


Contact

NUR Legal OÜ

Registry code: 17142784

VAT nr. EE102815012

+37258339358

  • Facebook
  • Телеграмма
  • Linkedin
  • Instagram
NUR Legal map_edited.jpg

Thanks for submitting!

JURISFIN Verification Badge

News & Articles •  Terms of UsePrivacy Policy
© 2026 NUR Legal All rights reserved.

bottom of page