Executive Summary
This guide is for founders, CEOs, compliance officers, in-house counsel, and investors seeking to understand and secure a MiCA CASP authorisation in Sweden through Finansinspektionen (FI). It sets out the legal framework, application requirements, realistic timelines, fees, and post-authorisation obligations including EU/EEA passporting so that applicants can plan and execute a fully aligned submission before the critical transitional deadline. Every factual claim is grounded in the primary EU legislation, FI’s published guidance, and ESMA supervisory statements.
Introduction Why This Matters Now
The Markets in Crypto-Assets Regulation Regulation (EU) 2023/1114 (MiCA) established, for the first time, a single EU-wide licensing regime for crypto-asset service providers (CASPs). Level-2 regulatory technical standards, including the Commission Delegated Regulation (EU) 2025/305, were adopted during 2024–2025 and now prescribe in granular detail the content and format of CASP authorisation applications.
The urgency is acute. ESMA and national competent authorities have confirmed an EU-wide transitional cut-off of 1 July 2026, after which any CASP operating without authorisation must cease offering services to EU clients. This has triggered a surge in applications across the bloc and a corresponding demand for expert, jurisdiction-specific application support.
For businesses choosing Sweden as their home member state, the advantages are significant:
- EU/EEA passporting potential: A Swedish MiCA CASP authorisation opens access to the entire single market through a streamlined notification procedure.
- Nordic credibility: Finansinspektionen’s rigorous supervisory reputation functions as a trust signal for institutional counterparties and end-users.
- Clear regulatory guidance: FI publishes detailed, English-language application guidance aligned with Article 62 of MiCA and Delegated Regulation (EU) 2025/305.
Key regulatory data point: MiCA (EU Reg. 2023/1114) and the CASP authorisation RTS (Commission Delegated Reg. 2025/305) together define the complete application content, timelines, and supervisory decision framework for every CASP applicant in the EU. Last checked: 18 August 2026.
Why Choose Sweden and Finansinspektionen
Nordic Credibility and Supervisory Approach
Sweden’s financial supervisory framework is among the most respected in Europe. Finansinspektionen combines robust scrutiny with a reputation for proportionality and transparency, making it a credible home-state regulator for crypto businesses seeking to establish institutional-grade operations. For CASPs that intend to serve professional clients, custody providers, or institutional markets, an FI-supervised licence carries tangible reputational weight.
Home-State Advantages for EU/EEA Passporting
Under MiCA, a CASP authorised in one member state can passport its services across the EU and EEA by notifying host-state NCAs. Sweden’s position within the Nordic financial ecosystem combined with strong bilateral supervisory cooperation agreements means that passporting from Stockholm can be operationally seamless. English-language proficiency across the Swedish business environment further reduces friction for multinational compliance and founding teams.
FI’s Operational Approach and Published Guidance
Finansinspektionen’s cryptoasset services page sets out the application content expectations, fee structure, and procedural steps in detail. FI explicitly references Article 62 of MiCA and the Delegated Regulation (EU) 2025/305 as the governing standards for application content. Applicants benefit from:
- Published templates and forms: FI provides application forms and document lists aligned with the RTS.
- Pre-submission engagement: Supervisory pre-notification meetings are available to validate the applicant’s approach before formal submission.
- Fintech ecosystem: Sweden’s mature fintech landscape home to global payment and banking innovators provides deep pools of compliance, legal, and technology talent.
- Corporate set-up considerations: FI expects the applicant to be a Swedish legal entity with its place of effective management in Sweden, including board-level residency and operational substance.
What Is a MiCA CASP Scope and Services Covered
Definition
Under MiCA Articles 59, 62, and 63, a crypto-asset service provider (CASP) is any legal person that provides one or more crypto-asset services to third parties on a professional basis. No person may provide such services within the EU without being duly authorised by the competent authority of its home member state in Sweden, that is Finansinspektionen.
Typical Services Requiring CASP Authorisation
MiCA defines the following categories of crypto-asset services (broadly mapped to Article 3(1)(16)):
- Custody and administration: Safekeeping or controlling crypto-assets on behalf of clients.
- Operation of a trading platform: Managing a multilateral system for crypto-asset trading.
- Exchange of crypto-assets for funds or other crypto-assets: Operating conversion services.
- Execution of orders: Concluding agreements to buy or sell crypto-assets on behalf of clients.
- Placing of crypto-assets: Marketing newly issued crypto-assets to buyers.
- Reception and transmission of orders: Routing client orders to third-party execution venues.
- Advice on crypto-assets: Providing personalised recommendations.
- Portfolio management: Managing portfolios of crypto-assets on a discretionary basis.
- Transfer services: Transferring crypto-assets on behalf of clients.
When Authorisation Is Not Required
Certain entities including credit institutions, investment firms, e-money institutions, and UCITS management companies already authorised under relevant EU legislation may be able to provide specific crypto-asset services under their existing licence, subject to a notification procedure. Article 60 of MiCA sets out the conditions under which these exemptions apply.
FI Authorisation Checklist What to Prepare
Applicants must submit a comprehensive dossier under Article 62 of MiCA and the detailed requirements of Delegated Regulation (EU) 2025/305. FI’s published guidance confirms that it assesses applications against both the primary regulation and the RTS. The checklist below reflects the grouped requirements that every MiCA CASP Sweden applicant must address.
- Legal form and registration: A Swedish legal entity (typically an aktiebolag) with articles of association, certificate of registration, and national identification numbers (organisationsnummer) must be established before submission.
- Governance and suitability: Detailed CVs, fit-and-proper declarations, criminal-record checks, and skills-matrix evidence for all members of the management body. Internal-control frameworks, conflict-of-interest policies, and documented organisational charts must demonstrate that the entity’s governance meets MiCA standards. Board-level residency in Sweden is a practical expectation.
- Capital and prudential requirements: Initial own-funds calculations proportional to the crypto-asset services offered. Capital buffers differ significantly between, for example, custody-only and full exchange/trading models. Applicants must demonstrate they hold the relevant minimum capital on an ongoing basis.
- Prudential reporting and liquidity: Liquidity management policies, stress-testing frameworks, and capital projections form part of the three-year programme of operations required under Article 62.
- Custody and asset segregation: Detailed descriptions of cold-storage and hot-storage architectures, proof of control over client assets, reconciliation procedures, and insurance arrangements (where applicable) are mandatory for applicants offering custody services.
- AML/CFT compliance: Risk assessments aligned with Directive (EU) 2015/849, know-your-customer (KYC) procedures, ongoing transaction-monitoring systems, suspicious-activity reporting workflows, and enhanced due diligence measures for high-risk third countries.
- IT resilience, operational resilience, and outsourcing: DORA-aligned expectations for IT risk management, incident reporting, third-party risk assessments, and outsourcing contract templates. Penetration testing and vulnerability-assessment evidence should be included.
- Risk management and compliance functions: Appointment of a dedicated compliance officer and money-laundering reporting officer (MLRO), documented internal audit scope, and business continuity and disaster recovery plans.
- Consumer protection and disclosures: Complaints-handling procedures, terms and conditions, pre-contractual disclosures, and where relevant white-paper or offer documentation for crypto-asset issuances.
- Programme of operations / business plan: Three-year financial projections, a detailed client-onboarding plan for EU markets, and a migration or wind-down plan (particularly important in the transitional context for firms migrating from national registrations to MiCA authorisation).
Documentation Pack Folder Summary
The following documents should be assembled as part of the submission package:
- FI application form (available from Finansinspektionen)
- Governance documents: Board charters, organisational charts, delegation-of-authority matrix
- Policies: AML/CFT manual, conflict-of-interest policy, complaints-handling policy, outsourcing policy
- Technical architecture diagram: Wallet infrastructure, key-management, reconciliation systems
- Proof of capital: Audited accounts, bank confirmations, capital-adequacy calculations
- Third-party service agreements: Outsourcing contracts, SLAs, cloud-provider arrangements
- Insurance certificates: Professional indemnity, cyber-risk, custodial-loss coverage
- Sample customer contracts and terms
- Test evidence: External audit reports, penetration-test results, vulnerability-assessment summaries
Data callout: Finansinspektionen explicitly refers to Article 62 and Delegated Regulation (EU) 2025/305 as the governing standards for required application contents. Applicants are strongly advised to cross-reference FI’s published document list against the RTS annexes before submission. A downloadable MiCA CASP application checklist is available for further reference.
Step-by-Step Application Timeline and Realistic 2026 Expectations
Below is a numbered process guide to the CASP authorisation Sweden pathway, incorporating the statutory timelines mandated by MiCA and realistic expectations based on FI’s supervisory practice.
- Preparation (4–12 weeks): Collect and prepare all documentation, governance frameworks, technical architecture evidence, AML/CFT policies, capital proofs, and third-party contracts. Gap remediation is critical at this stage incomplete packs cause the most significant delays later in the process.
- Pre-engagement with FI (optional, 2–4 weeks): Schedule supervisory pre-notification meetings or informal consultations to validate the applicant’s approach, discuss the scope of services, and address any threshold questions about corporate structure or governance.
- Submission: File the complete application dossier via FI’s designated channels. Under Article 63 of MiCA, FI must acknowledge receipt within 5 working days.
- Completeness check (up to 25 working days): FI assesses whether the dossier is formally complete. If the application is incomplete, the applicant typically has up to 20 working days to supplement the filing. Statutory suspension rules apply during this period.
- Substantive review (3–6+ months): FI conducts a detailed assessment of the application on its merits, evaluating governance, capital adequacy, operational resilience, AML controls, and consumer-protection arrangements. Expect iterative rounds of clarifying questions. FI’s practice includes specific notification markers for example, 60-working-day review windows for certain notifications such as white-paper assessments.
- Decision and ESMA notification: Upon granting authorisation, FI notifies ESMA, which adds the CASP to the public register. Communication timelines are defined under MiCA.
- Post-decision steps: Set up supervisory reporting channels, pay ongoing supervisory fees, update customer contracts, and commence passporting notifications to host-state NCAs if cross-border services are planned.
2026 Realistic Expectations
The 1 July 2026 transitional deadline has driven a significant spike in application volumes across all EU NCAs. Industry observers expect FI review cycles to lengthen for submissions that are incomplete or misaligned with the RTS. Applicants can mitigate this risk by submitting fully RTS-aligned documentation packs and engaging in pre-submission completeness checks with experienced advisers.
Process KPIs (statutory/practical):
- FI receipt acknowledgement: Within 5 working days
- Completeness check: Within 25 working days
- Overall FI review: Typically 3–6 months (varies with complexity and applicant responsiveness)
Last checked: 18 August 2026.
Fees and Costs What to Budget
FI’s application fees are set under the Fees for Finansinspektionen (Assessment) Ordinance (2001:911). As FI’s published guidance states, the fee for each application is determined by FI’s assessed handling time meaning that fees vary on a case-by-case basis depending on the complexity of the CASP’s proposed activities. Applicants should budget for the following cost buckets:
- FI application/processing fee: Payable directly to Finansinspektionen upon submission; amount set by assessed handling time under Ordinance 2001:911.
- Annual supervisory fee: Ongoing fee levied by FI for post-authorisation supervision; recalculated periodically.
- Capital and liquidity carrying costs: Own-funds requirements must be maintained on a continuous basis; the carrying cost depends on the services offered and business model.
- External professional fees: Legal advisers, compliance consultants, technical auditors, and project-managed application support. For many applicants, these project fees represent the single largest external expenditure.
Note: Applicants should confirm the latest fee tables directly with FI prior to submission, as figures may be updated. Last checked: 18 August 2026.
Post-Authorisation Obligations and Passporting Process
Ongoing Supervisory Reporting, Audit, and AML/CFT Monitoring
Once authorised, Swedish CASPs are subject to continuous supervisory obligations. These include periodic prudential reporting to FI, annual external audits, ongoing AML/CFT compliance monitoring (including transaction-monitoring system reviews and suspicious-activity reporting), and adherence to conduct-of-business rules. FI may require periodic supervisory returns and will levy annual supervisory fees.
Notification Process for Passporting
A Swedish CASP wishing to offer services in another EU/EEA member state must follow the notification procedure defined in MiCA. The home-state NCA (FI) transmits the notification including details of the services to be provided and the host member state(s) to the relevant host-state NCA(s). ESMA maintains a public register of all authorised CASPs and the member states in which they are entitled to operate. EU passporting for CASPs is a core benefit of Sweden-based authorisation.
Typical Post-Authorisation Checks
Authorised CASPs should expect ongoing supervisory attention in areas including IT incident reporting (aligned with DORA), periodic AML audits, conduct and conflicts-of-interest monitoring, and consumer-complaints data submissions. Operational readiness including internal reporting dashboards and compliance-function staffing should be established before passporting begins.
Comparison: Sweden vs Other EU Hubs
| Feature |
Sweden (FI) |
Germany (BaFin) |
Luxembourg (CSSF) |
Ireland (Central Bank) |
| Supervisory profile |
Strong Nordic fintech credibility; robust scrutiny with clear, published English-language guidance |
Highly prescriptive and compliance-focused; detailed regulatory expectations |
Established fund and asset-management expertise; attractive for cross-border operations |
English-language processes; attractive for multinational teams and US-linked groups |
| Typical timeline |
Completeness check within 25 working days; substantive review 3–6+ months (varies by complexity) |
Often longer for complex models; detailed documentation expectations |
Can be faster for established fund structures with existing CSSF relationships |
Competitive; English-language regulator; timeline varies case-by-case |
| Fees |
Statutory; set under Ordinance 2001:911 (varies by assessed handling time) |
Variable; can be high for complex reviews |
Variable; fee models differ from Nordic approach |
Variable; supervisory levy applies |
| Fintech ecosystem |
Deep talent pool; global payment innovators headquartered in Stockholm |
Strong banking and institutional infrastructure |
Fund services and cross-border structuring expertise |
Growing tech hub; strong links to US and UK markets |
| Passporting |
Full EU/EEA passporting via MiCA notification |
Full EU/EEA passporting via MiCA notification |
Full EU/EEA passporting via MiCA notification |
Full EU/EEA passporting via MiCA notification |
Commentary: All four jurisdictions offer identical MiCA passporting rights, so the choice of home state turns on practical factors: supervisory culture, speed, ecosystem support, and language. Sweden’s combination of Nordic credibility, a mature fintech talent market, and FI’s transparent, English-language guidance positions it as a strong choice for founders who want rigorous supervision that also serves as a trust signal without the longer review cycles sometimes associated with the largest continental regulators.
Case Study Timeline Example
The following anonymised scenario illustrates a realistic project timeline for a mid-sized exchange seeking Finansinspektionen CASP authorisation for custody, exchange, and order-execution services in Sweden.
- Weeks 0–8 (Preparation): Gap analysis against Article 62 and Delegated Reg. 2025/305. Remediation of governance documentation, AML/CFT policies, IT architecture diagrams, and capital-adequacy calculations. Appointment of compliance officer and MLRO. Drafting of three-year programme of operations.
- Week 9 (Submission): Complete dossier filed with FI. Acknowledgement of receipt received within 5 working days, as required by Article 63.
- Weeks 9–13 (Completeness review): FI assessed the application for completeness within 25 working days. Minor supplementary information requested and provided within the statutory response window.
- Months 4–7 (Substantive review): FI conducted a detailed merits-based review, issuing two rounds of clarifying questions focused on custody segregation arrangements and IT resilience testing. The applicant responded within two weeks per round.
- Month 8 (Authorisation granted): FI issued the authorisation decision and notified ESMA. The CASP was added to the public register and commenced passporting notifications to three target EEA host states.
Three practical lessons from this timeline:
- Submit a fully RTS-aligned pack from day one. Incomplete filings trigger suspension rules that can add months to the process.
- Proactive governance evidence pays off. Pre-assembled fit-and-proper packages and board-level documentation significantly reduce FI’s query cycles.
- Reserve 6–9 months for the full project. From initial gap analysis to authorisation and first passporting notifications, the end-to-end timeline for a MiCA CASP Sweden application is substantial planning for it is essential.
Sources