For a crypto business planning to operate in Europe, obtaining a MiCA license is no longer a question to postpone until after launch. Since the end of MiCA's transitional period, businesses providing regulated crypto-asset services need to establish whether they require authorization as a Crypto-Asset Service Provider, or CASP, before providing those services in the European market.
The difficult part is rarely filling in the application form. The real work happens earlier: defining exactly which regulated services the company will provide, selecting the right home jurisdiction, building governance and compliance processes that match the actual business model, and documenting those arrangements in a form the competent authority can assess.
This guide explains what a MiCA license actually is, who needs one, what the authorization process involves, how much regulatory capital is required, how long the statutory assessment takes and what EU-wide passporting means in practice.
What is a MiCA license?
“MiCA license” is the commonly used term for authorization as a Crypto-Asset Service Provider under Regulation (EU) 2023/1114 on Markets in Crypto-Assets. The formal MiCA terminology is CASP authorization.
Under Article 59 of MiCA, a person generally cannot provide regulated crypto-asset services within the EU unless it has been authorized as a CASP or is one of the regulated financial entities permitted to provide equivalent services under Article 60. An authorized CASP must have a registered office in a Member State where it conducts at least part of its crypto-asset services, its effective management must be in the EU, and at least one director must be resident in the EU.
A single authorization can cover one or several crypto-asset services. These include custody and administration of crypto-assets, operating a crypto trading platform, exchanging crypto-assets for funds or other crypto-assets, executing orders, placing crypto-assets, receiving and transmitting orders, providing crypto investment advice, portfolio management and providing transfer services.
This is why founders should determine the regulatory perimeter before structuring the application. A company that only provides advice has a materially different regulatory profile from an exchange that also holds client assets and operates a trading platform.
Who actually needs a MiCA license?
The starting point is the activity, not whether the business describes itself as an “exchange”, “wallet”, “Web3 company” or “fintech”.
If the company provides one or more crypto-asset services listed in MiCA to clients in the EU, CASP authorization may be required. The analysis becomes more complicated where the business combines crypto services with payments, investment services, electronic money, token issuance or activities that fall under another regulatory framework.
Certain already regulated financial institutions, including credit institutions, investment firms and electronic money institutions, can provide specified crypto-asset services subject to the Article 60 notification regime rather than obtaining a completely separate CASP authorization for the same activities. That exception should not be extrapolated to ordinary crypto companies.
The timing is also important in 2026. MiCA allowed existing providers operating lawfully under national regimes to benefit from transitional arrangements, but Article 143 set 1 July 2026 as the maximum EU-level end date, with Member States able to shorten or not apply that period. ESMA has confirmed that a firm still waiting for authorization after its applicable transitional period ends cannot simply continue operating until a decision arrives.
For a new market entrant, “we will obtain the license later” is therefore not a viable regulatory strategy.
How does the MiCA authorization process work?
A successful MiCA license application begins with the operating model. The regulator needs to understand not only what the company says it intends to do, but how those services will function operationally.
Start with the regulatory perimeter
Before preparing policies, identify precisely which MiCA services the company will provide and which legal entity will provide them. This affects the authorization scope, capital requirement, governance model and policies required.
It is also important to identify regulatory overlaps early. A CASP that intends to provide payment services cannot assume that CASP authorization itself covers payment activities. MiCA expressly recognises interactions with other EU financial-services regimes.
Choose the home member state and build real substance
A company cannot treat the choice of jurisdiction as a purely administrative decision. MiCA requires a registered office in a Member State where the CASP conducts at least part of its crypto-asset services and requires effective management in the Union.
The competent authority will consequently look beyond the corporate registration certificate. Governance, management, staffing, outsourcing and operational arrangements need to support the substance of the proposed business.
This is one reason jurisdiction selection should happen before the application package is drafted. The correct choice depends on the business model, management location, target markets, existing group structure and regulatory dependencies, rather than on which country is advertised as offering the “fastest crypto license”.
Build the application around the actual business
The authorization file needs to demonstrate how the proposed CASP will operate. Commission Delegated Regulation (EU) 2025/305 specifies extensive application information covering areas such as the programme of operations, governance, prudential safeguards, business continuity, AML/CFT controls, ICT arrangements, segregation of client assets and funds, complaints handling and service-specific procedures. The programme of operations is expected to explain the organizational structure, commercial strategy and operational capacity over a three-year period.
This is where weak applications tend to become visible. A policy copied from another company may look complete in isolation but contradict the applicant's actual custody model, outsourcing arrangements, management structure or customer journey.
Legal expert insight - Peter Merc, founder of Lemur Legal “The biggest red flag is rarely a missing policy. It is inconsistency. A CASP may describe one business model in its application while its governance structure, AML controls, outsourcing arrangements or technical architecture tell a different story. Regulators look at how the business will actually operate, so the documentation, decision-making responsibilities, customer flows and technology setup all need to describe the same company.”
A defensible application should therefore be built from the business inward, rather than from regulatory templates outward.
How much capital does a CASP need?
MiCA establishes three permanent minimum capital levels according to the services provided.
Class 1 CASPs require at least EUR 50,000 and cover services such as execution of orders, placing, transfer services, reception and transmission of orders, advice and portfolio management. Class 2 requires at least EUR 125,000 and additionally covers custody and administration, exchange of crypto-assets for funds and exchange of crypto-assets for other crypto-assets. Class 3 requires at least EUR 150,000 and includes operation of a crypto-asset trading platform.
These amounts are not necessarily the final prudential requirement. Under MiCA Article 67, a CASP must maintain prudential safeguards equal to at least the higher of the relevant permanent minimum capital amount or one quarter of the previous year's fixed overheads. New firms use projected overheads for their first twelve months.
This matters commercially. Founders should model the prudential requirement alongside staffing, technology, compliance and legal expenditure before deciding that a particular authorization scope is affordable.
Applying for more services than the business actually needs can create unnecessary capital and compliance obligations. Applying for too little creates the opposite problem because adding new crypto-asset services later requires an extension of the authorization.
How long does a MiCA license take?
MiCA contains statutory assessment periods, but they should not be confused with the total project timeline.
The competent authority must acknowledge receipt of an application within five working days. It then has 25 working days to assess whether the application is complete. Once an application is considered complete, the authority has 40 working days to assess compliance and grant or refuse authorization, with notification of the decision following within five working days.
Those numbers describe the regulator's formal assessment framework. They do not mean a company can begin preparing today and expect a MiCA license in 40 working days.
Preparation may involve corporate restructuring, hiring or confirming key management, mapping outsourcing relationships, documenting ICT and security architecture, establishing AML procedures, drafting client documentation and reconciling policies with the operating model. During regulatory review, requests for clarification or additional information can also affect the real calendar timeline.
The more useful question is therefore not “How fast can we file?” but “When will the company be genuinely authorization-ready?”
What is MiCA compliance after authorization?
Receiving a MiCA license is the beginning of regulated operations, not the end of the compliance project.
CASPs remain subject to ongoing requirements covering governance, prudential safeguards, client protection, conflicts of interest, complaints, outsourcing and service-specific conduct. Where they hold client crypto-assets or funds, MiCA requires arrangements protecting clients' ownership rights and, for relevant client funds, segregation from the CASP's own accounts.
Depending on the business model, MiCA also sits alongside other regulatory layers, including AML/CFT rules, the EU Transfer of Funds Regulation and DORA requirements. A policy stack that technically exists but does not reflect actual operations is unlikely to provide durable compliance.
This is why the authorization project should ideally become the foundation of the company's operating compliance framework rather than a collection of documents created only for submission.
Lemur Legal works with crypto and fintech companies on regulatory compliance and regulatory implementation, including situations where MiCA interacts with other financial-services requirements.
How does MiCA passporting work?
One of the main commercial benefits of CASP authorization is the ability to expand beyond the home jurisdiction.
Article 59 provides that authorized CASPs can provide their authorized crypto-asset services throughout the Union through establishment or the freedom to provide services, without being required to establish a physical presence in every host Member State. For cross-border services, Article 65 requires the CASP to notify its home competent authority of the Member States and services concerned. The home authority then communicates that information to the relevant authorities, ESMA and EBA within ten working days.
MiCA has also been incorporated into the EEA Agreement and is in force across the wider European Economic Area, extending the framework beyond the 27 EU Member States to the three EEA EFTA states.
Passporting does not, however, eliminate every local-law issue. Consumer law, employment, tax, marketing and other national requirements can still matter depending on how the company enters a particular market.
Which crypto exchanges have a MiCA license?
The safest answer is not a static blog list. It is the official ESMA register.
Under Article 109, ESMA maintains information on authorized CASPs, including their legal entity, competent authority, authorized crypto-asset services, host Member States and authorization date. ESMA's current MiCA register includes a dedicated dataset for authorized crypto-asset service providers.
For founders, partners and customers, the important point is to verify the exact legal entity rather than relying on a global exchange brand or a statement that a group is “MiCA compliant”. Authorization attaches to a specific entity and a defined scope of services. or a current overview, see our 2026 register of MiCA-licensed crypto exchanges.
Plan the authorization before you file
A MiCA license creates a common regulatory route into the European crypto market, but authorization depends on much more than submitting the correct forms. The service scope, jurisdiction, management structure, regulatory capital, AML framework, operational resilience and client-protection processes all need to describe the same real business.
For founders, the most efficient sequence is usually to establish the regulatory perimeter first, select the jurisdiction second, design the compliant operating structure third and only then build the application.
A well-prepared CASP application does not guarantee authorization. It does, however, give the competent authority a coherent and defensible business to assess. Where the regulatory perimeter or application strategy is uncertain, Lemur Legal can help map the requirements and structure the engagement on a fixed scope before the filing process begins.
