For years, European crypto companies talked about getting a “VASP license.”
The problem was that there was never one harmonised EU VASP licence. Firms registered under national regimes, requirements differed between Member States, and a registration in one country did not automatically create a right to serve the entire European market.
MiCA changed that structure.
The Markets in Crypto-Assets Regulation introduced the Crypto-Asset Service Provider, or CASP, as the EU regulatory category for businesses professionally providing specified crypto-asset services. It also created a harmonised authorisation regime and a mechanism for providing those services across Member States.
And as of July 2026, the maximum MiCA transitional period for legacy providers has ended.
That makes the VASP vs CASP distinction much more than a change in terminology.
What is a virtual asset service provider?
A virtual asset service provider, usually shortened to VASP, is fundamentally an international AML/CFT concept.
The Financial Action Task Force, or FATF, defines a virtual asset service provider by the activities it performs on behalf of another person. These include exchanging virtual assets for fiat currency, exchanging one virtual asset for another, transferring virtual assets, safeguarding or administering them, and participating in financial services connected with an issuer’s offer or sale of a virtual asset.
FATF requires jurisdictions to regulate VASPs for anti-money laundering and counter-terrorist financing purposes and to subject them to licensing or registration and effective supervision.
Before MiCA, EU Member States implemented crypto-related AML obligations through national regimes, but those regimes were not fully harmonised. The terminology also varied.
Under the previous EU AML framework, the EU-level rules specifically covered custodial wallet providers and providers exchanging virtual currencies for fiat currencies. National legislation could go further.
This is why asking “what is a VASP license?” historically produced different answers depending on the country.
The virtual asset service provider concept therefore remains important internationally, particularly in AML discussions, but it is no longer the main authorisation category for MiCA-covered crypto services inside the EU.
What is a CASP under MiCA?
MiCA defines a crypto-asset service provider as a legal person or other qualifying undertaking whose business is the professional provision of one or more crypto-asset services to clients and that is permitted to provide those services under MiCA.
The Regulation identifies ten crypto-asset services:
custody and administration of crypto-assets;
operation of a crypto-asset trading platform;
exchange of crypto-assets for funds;
exchange of crypto-assets for other crypto-assets;
execution of orders;
placing of crypto-assets;
reception and transmission of orders;
advice on crypto-assets;
portfolio management;
transfer services for crypto-assets on behalf of clients.
The key provision is Article 59. A person generally cannot provide those crypto-asset services in the Union unless it has been authorised as a CASP or is one of the already regulated financial entities permitted to provide relevant services through the Article 60 notification route.
That is a significantly different regulatory model from the fragmented national landscape that existed before MiCA.
VASP vs CASP: what actually changed?
The easiest way to understand the change is to separate four concepts: terminology, regulatory purpose, authorisation and cross-border access.
A VASP is primarily a FATF concept used to identify businesses that should fall within AML/CFT regulation because of the virtual-asset activities they perform.
A CASP is a legal category established directly by MiCA for the EU market.
A national VASP registration historically demonstrated compliance with the applicable domestic framework. It did not create an EU-wide MiCA authorisation.
A CASP authorisation does.
MiCA also goes considerably beyond AML registration. CASPs are subject to requirements covering governance, prudential safeguards, client protection, conflicts of interest, safeguarding, outsourcing and other operational obligations.
Article 67, for example, requires CASPs to maintain prudential safeguards equal to at least the higher of the applicable minimum capital amount or one quarter of the previous year’s fixed overheads. Depending on the services authorised, the permanent minimum capital requirement is EUR 50,000, EUR 125,000 or EUR 150,000.
The transition therefore was not simply a process of changing “VASP” to “CASP” on company documents.
For many businesses, it required a substantially more developed regulatory operating model.
Do you still need a VASP license in the EU?
For businesses providing MiCA-defined crypto-asset services in the EU, a legacy national VASP registration is no longer a substitute for the authorisation required by MiCA.
Article 143 allowed providers that were legally operating before 30 December 2024 to continue under national law until 1 July 2026 at the latest, or until their CASP application was granted or refused, whichever happened first. Member States were permitted to shorten the period or not apply the transitional regime at all.
That maximum period has now expired.
ESMA reiterated before the deadline that unauthorised providers should wind down MiCA services and that clients should verify authorisation through the ESMA register.
There are still situations where the answer is not simply “you need a CASP licence.” Certain already regulated financial institutions can provide specified crypto services through the Article 60 regime. Some activities may fall outside the definition of a crypto-asset service altogether. Third-country firms also face a narrow reverse-solicitation exception where an EU client acts exclusively on its own initiative, but MiCA expressly restricts the use of that exception as a way of soliciting EU business.
The correct answer therefore starts with the actual services and clients, not the company’s preferred regulatory label.
Legal expert insight - Peter Merc
One of the most common misconceptions in the VASP-to-CASP transition is treating MiCA authorisation as an administrative conversion of an old registration. In practice, the business needs to reassess its services, governance, AML framework and operating model from the ground up.
What happened during the VASP-to-CASP transition?
MiCA became generally applicable on 30 December 2024, but legislators recognised that existing providers could not all move into the new regime overnight.
Article 143 therefore created a grandfathering mechanism.
The maximum grandfathering period ran until 1 July 2026. Individual Member States could adopt shorter periods, meaning businesses had to check the rules in both their home jurisdiction and any markets they intended to serve.
There was another important limitation: grandfathered VASPs did not receive a MiCA passport.
ESMA specifically clarified that a firm continuing under a national transitional regime could not rely on that status as a harmonised right to provide services throughout the EU. Cross-border activity during grandfathering remained dependent on the relevant national rules in both the home and host Member States.
Once authorised under MiCA, the position changes.
Article 65 allows a CASP to notify its home competent authority of the Member States in which it intends to provide services. Following the prescribed notification process, the CASP can begin providing those authorised services cross-border without obtaining a separate CASP authorisation in every Member State.
That EU passport is one of the most commercially important differences between the old national landscape and MiCA.
What does CASP authorization require in practice?
A CASP application is not simply an AML registration form with more attachments.
Article 62 requires information covering the applicant’s legal identity and structure, programme of operations, intended crypto-asset services and other aspects of the proposed business. The wider MiCA framework adds requirements around governance, management, prudential safeguards, client assets, policies and operational controls.
The statutory assessment process also needs to be understood correctly.
Under Article 63, the competent authority has 25 working days after receiving an application to assess whether it is complete. Once the application is complete, the authority has 40 working days to assess compliance and decide whether to grant or refuse authorisation. The assessment clock can be suspended where additional information is requested.
Those statutory periods should not be confused with a guaranteed end-to-end project timeline.
Before an application can be called complete, a business may need significant work on corporate structure, policies, governance, management arrangements, financial projections, outsourcing, technology, AML/CFT controls and service-specific documentation.
Anyone promising a guaranteed CASP approval within a fixed number of days is therefore ignoring how the process actually works.
Which businesses are most affected?
The clearest cases are businesses operating exchanges, custodial platforms, broker-style services, crypto transfer services or trading platforms.
But borderline business models still require proper analysis.
For example, ESMA has clarified that dealing purely on own account generally does not involve providing a service to a client and therefore does not automatically constitute CASP activity.
In a separate 2026 clarification, the European Commission confirmed through ESMA’s Q&A process that an issuer transferring newly issued tokens directly to purchasers from the issuance smart contract is not necessarily providing custody or transfer services “on behalf of” another person.
These examples matter because MiCA authorisation follows the substance of the activity.
A project’s website may describe it as an “exchange,” “protocol,” “broker,” “wallet,” “platform” or something entirely new. None of those labels answers the regulatory question by itself.
The correct analysis maps every service and contractual relationship against MiCA’s definitions before determining the authorisation perimeter.
What should founders do before applying for CASP authorization?
The first step should be a regulatory-perimeter analysis, not drafting the licence application.
Founders should establish exactly which crypto-asset services the company intends to provide, which entity will provide them and in which markets.
Next comes the home Member State. MiCA is harmonised EU law, but the application is still handled by the competent authority of the applicant’s home jurisdiction. The corporate structure, management location and operational substance therefore matter.
The business should then prepare for the wider compliance stack. CASP authorisation does not replace AML/CFT obligations or the Transfer of Funds Regulation. The latter has applied to crypto-asset transfers since 30 December 2024 and extends information requirements to crypto transfers within its scope.
Governance, safeguarding, prudential requirements and operational resilience also need to be considered as part of the same operating model rather than as separate boxes to tick later.
For founders moving from an old virtual asset service provider structure, this is usually the critical shift: analyse the business as it will operate under MiCA, not as it was registered under the previous national regime.
The terminology changed, but so did the regulatory model
VASP and CASP are not interchangeable labels.
The virtual asset service provider concept remains part of the global FATF vocabulary and continues to matter for AML/CFT analysis. CASP, however, is now the central MiCA category for professional crypto-asset services in the EU.
The practical change is substantial.
The old landscape of differing national registrations has been replaced, for MiCA-covered services, by a harmonised authorisation framework with governance, prudential, conduct and operational requirements, together with an EU cross-border mechanism.
And the transition is no longer theoretical. The maximum grandfathering deadline expired on 1 July 2026.
For a founder entering the European market now, the right question is therefore no longer simply, “Where can I get a VASP licence?”
It is: “What services are we actually providing, do they fall within MiCA, and what authorisation and compliance structure do we need to operate them properly?”
