[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto licence germany

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Do I Need a Crypto Licence in Germany? Bafin vs Mica Explained

By Jonathon Richards
– posted 12 hours ago

If you are planning to offer crypto-asset services in or from Germany, the first question you must answer is whether you need a crypto licence Germany requires under its national framework, under the EU-wide MiCA regime, or under both. The short answer: most commercial activities involving crypto-assets custody, exchange, brokerage, ATM operation, token issuance do trigger a licensing obligation. Operating without authorisation exposes founders and directors to personal liability, enforcement action, and potential criminal sanctions. This guide gives founders, general counsel, compliance officers, and fintech product leads a structured decision tree, an activity-by-activity trigger matrix, a side-by-side comparison of BaFin (KWG) authorisation and MiCA CASP licensing, realistic cost and timeline estimates, and a practical next-steps playbook. Throughout, every legal claim is grounded in the primary legislation and regulator guidance listed in the sources below.

Last reviewed: July 2026. This page will be updated when material changes to MiCA delegated acts or BaFin guidance are published.

Quick decision tree where to start

Before engaging counsel or preparing a dossier, run your business model through the four gateway questions below. Each “yes” leads to a licensing trigger; a “no” across all four suggests but does not guarantee that authorisation may not be required.

  1. Are you holding, storing, or managing private cryptographic keys on behalf of clients? → Yes: custody licence trigger (KWG § 1 Abs. 1a Satz 2 Nr. 6 / MiCA CASP custody service).
  2. Are you operating an exchange, trading venue, or order-book platform or running fiat on/off-ramp services? → Yes: exchange / trading-platform licence trigger (KWG financial services / MiCA CASP).
  3. Are you issuing tokens (utility, asset-referenced, or e-money tokens) to the public? → Yes: prospectus or MiCA issuer obligations, potentially including a whitepaper approval.
  4. Do you provide only incidental, purely technical, non-custodial infrastructure (e.g., open-source node software)? → Possibly no licence required but narrow exemptions must be confirmed case-by-case.

[Placeholder: hero decision-tree image (SVG/PNG). Alt text: “Decision tree: Do I need a crypto licence in Germany? (BaFin vs MiCA)”. Asset to be produced by design team.]

If any of the first three nodes applies to your business, you should proceed to the detailed activity analysis below and begin planning your authorisation strategy.

Activity-by-activity: does this trigger BaFin authorisation or a MiCA CASP licence?

Crypto custody (holding private keys)

Crypto custody defined as the safekeeping, administration, or securing of crypto-assets or private cryptographic keys on behalf of clients is classified as a financial service under the German Banking Act (KWG). Any entity performing this activity on a commercial basis in Germany needs BaFin authorisation. Under MiCA, custody and administration of crypto-assets on behalf of clients is a designated CASP service that likewise requires authorisation. BaFin expects custody licence applicants to demonstrate robust key-management procedures, segregation of client assets from proprietary holdings, and insolvency-remote structures. Cold-wallet architecture, multi-signature controls, and documented disaster-recovery plans are standard compliance modules.

Exchanges, trading venues and order-book platforms

Operating a platform that matches buy and sell orders for crypto-assets whether through a central order book, an automated market maker, or a peer-to-peer matching engine triggers authorisation. Under the KWG framework, this can fall under multilateral trading or proprietary trading classifications depending on the platform’s role. Under MiCA (Regulation (EU) 2023/1114), operating a trading platform for crypto-assets is a distinct CASP service. Fiat on-ramp and off-ramp services (exchange of crypto-assets for fiat currency and vice versa) equally require authorisation, whether structured as proprietary dealing or agency execution.

Broker / brokerage and execution-on-behalf

Receiving and transmitting orders in crypto-assets, or executing orders on behalf of clients, constitutes a financial service under both KWG and MiCA. Brokers who route client orders to third-party exchanges without ever taking custody of assets still require authorisation because the intermediation itself is a regulated activity. MiCA explicitly lists “reception and transmission of orders for crypto-assets on behalf of clients” and “execution of orders for crypto-assets on behalf of clients” as licensable CASP services.

Crypto ATMs (buy/sell devices)

Crypto-ATM operators are a frequent enforcement target. BaFin’s 2024 annual report documents significant enforcement actions against ATM operators, including device seizures, for conducting unauthorised financial services and breaching anti-money-laundering obligations. Operating a device that enables the public to buy or sell crypto-assets for cash typically constitutes exchange services (and may qualify as payment services or proprietary trading), requiring authorisation. ATMs also present heightened AML/CFT risk due to anonymity and cash handling, triggering additional obligations under the German Money Laundering Act (GwG).

Token issuance and whitepapers

Issuing tokens to the public can trigger multiple regulatory obligations. Under MiCA, issuers of asset-referenced tokens (ARTs) must obtain BaFin authorisation and maintain reserve assets; issuers of e-money tokens (EMTs) must hold an e-money institution licence. Utility-token issuers must publish a MiCA-compliant crypto-asset whitepaper and notify the competent authority. Depending on the token’s characteristics, German securities law (WpPG / EU Prospectus Regulation) may also apply if the token qualifies as a transferable security.

Custody-as-a-service (B2B) and hosted wallets

Providing custody infrastructure to other businesses for example, white-labelling wallet technology where the provider holds or controls private keys remains a licensable activity if the provider exercises factual control over client assets. The decisive criterion is whether the service provider, rather than the end-user, controls access to the cryptographic keys. Hosted wallets where the platform generates, stores, and manages keys on behalf of users constitute custody regardless of the B2B or B2C label. Purely non-custodial infrastructure where the user alone controls their keys may fall outside the licence perimeter, but this assessment is highly fact-specific.

Staking, lending, and yield services

Staking services where the provider takes possession of client tokens and delegates them to a proof-of-stake protocol may combine custody triggers with investment-service characteristics. Crypto lending accepting deposits of crypto-assets and lending them to third parties in return for yield raises additional concerns about deposit-taking (a banking activity under KWG) and may also fall under MiCA or national securities regulation depending on how the yield obligation is structured. Industry observers expect regulatory scrutiny of DeFi-adjacent yield products to intensify as BaFin refines its guidance on these service models.

How to get authorised in Germany step-by-step

  1. Map business activities to legal triggers. List every service your platform offers (custody, exchange, brokerage, issuance, staking) and cross-reference each against the KWG definitions and MiCA CASP service catalogue. Assign an internal owner typically the head of compliance or general counsel to document the analysis. Use the activity-by-activity matrix above as a starting framework.
  2. Decide jurisdiction and regime. If you intend to operate solely in Germany with no EU passporting needs, a BaFin KWG authorisation may be the fastest path. If you plan to serve clients across the EU from a single licence, a MiCA CASP authorisation which BaFin will process as the national competent authority for Germany-based applicants enables passporting. Where transitional rules allow firms already authorised under KWG to continue operating, evaluate whether to convert to a MiCA CASP licence or apply fresh. Decision criteria include: target markets, capital efficiency, timeline, and long-term product roadmap.
  3. Prepare documentation. Assemble a comprehensive application dossier including: detailed business plan with financial projections; corporate documents (articles of association, group-ownership chart, beneficial-owner register); fit-and-proper evidence for directors and qualifying shareholders; AML/CFT framework compliant with the GwG (policies, procedures, risk assessment, MLRO appointment); IT security and operational resilience documentation (penetration-test reports, key-management architecture, incident-response plan); custody-process descriptions; outsourcing agreements and due-diligence reports; and capital and solvency evidence.
  4. Engage BaFin pre-filing. BaFin offers pre-filing consultations for complex applications. Use this step to validate your activity classification, clarify documentation expectations, and identify potential objections early. If AML registration is a separate requirement for your structure, initiate it in parallel.
  5. Submit application and manage dialogue. After filing, expect multiple rounds of follow-up questions from BaFin’s specialist teams. Assign a dedicated project manager internally to coordinate responses across legal, compliance, IT, and finance functions. Response times directly affect the overall approval timeline.
  6. Meet post-authorisation obligations. Once authorised, ongoing obligations include: periodic regulatory reporting; annual audits; AML transaction monitoring and suspicious-activity reporting; consumer-disclosure requirements; and for token issuers maintenance and update of MiCA whitepapers. Build these into your operational calendar from day one.

At a glance BaFin (KWG) vs MiCA (CASP)

The table below compares the two principal regimes under which a crypto licence Germany applicants will need to operate. Note that for Germany-based firms, BaFin serves as the national competent authority for both KWG authorisations and MiCA CASP applications.

Criterion BaFin authorisation (KWG) MiCA CASP (EU)
When it applies (trigger) Activities qualifying as financial services or banking business under the KWG (e.g., crypto custody, proprietary trading, exchange services depending on structure). Crypto-asset services as defined by MiCA (custody, trading-platform operation, exchange, order reception/transmission, placing, advice, portfolio management, transfer services).
Minimum capital / prudential Varies by licence type; capital and organisational requirements applied by BaFin on a case-by-case basis. Expect at minimum €125,000 for pure financial-services licences, higher for banking licences. MiCA sets specific prudential floors depending on the CASP service category (ranging from €50,000 to €150,000 own-funds requirements); detailed rules in ESMA delegated acts.
Passporting National. BaFin authorisation does not automatically confer EU-wide operating rights (limited passporting for certain harmonised MiFID services only). Full EU passporting: once authorised by one member-state competent authority, the CASP may provide services across all EU/EEA member states.
Typical approval timeline (estimate) 6–12 months for straightforward custody or exchange applications; complex or remediation-heavy cases may take longer. 4–9 months from submission of a complete dossier; depends on national competent-authority processes and ESMA coordination.
Key obligations KWG compliance, MaRisk (operational risk), GwG (AML/CFT), local reporting, governance requirements, fit-and-proper assessment for directors. MiCA conduct and prudential rules, consumer disclosures, custody safeguards, whitepaper requirements for issuers, AML coordination under EU AML framework.

Important overlap and transitional notes:

  • Dual-regime overlap: Certain activities (notably crypto custody) are regulated under both KWG and MiCA. Firms already holding a KWG crypto-custody licence benefit from transitional provisions that allow continued operation while transitioning to MiCA CASP authorisation but deadlines apply and firms must actively manage the conversion.
  • Transitional grandfathering: MiCA provides transitional periods for firms authorised under national law before MiCA’s application dates. The duration and conditions of grandfathering depend on individual member-state implementation; BaFin has published guidance on the applicable German transitional regime.
  • Confirmation of regime: Where doubt exists about whether a specific service triggers KWG, MiCA, or both, firms should seek written confirmation from BaFin or obtain formal legal analysis before launch.

Key requirements and documents BaFin / MiCA will expect

Whether you pursue a BaFin KWG authorisation or a MiCA CASP licence, regulators will expect a comprehensive, professionally prepared dossier. The following checklist covers the core categories. Internal project teams should assign an owner and target completion date for each item.

  • Corporate documents: Certificate of incorporation, current articles of association, commercial-register excerpt, group-ownership chart (including ultimate beneficial owners), and shareholder agreements.
  • Fit-and-proper evidence: CVs, criminal-background checks, financial-standing declarations, and competence assessments for all directors, managing directors, and qualifying shareholders (10%+ holders).
  • Business plan: Detailed description of proposed services, target markets, revenue model, three-year financial projections, operational-scaling strategy, and competitive analysis.
  • AML/CFT framework: KYC/CDD policies and procedures compliant with the GwG, risk assessment, transaction-monitoring rules, suspicious-activity reporting protocols, and MLRO appointment letter with evidence of suitability.
  • IT security and custody controls: Key-management architecture, cold/hot wallet split rationale, multi-signature procedures, penetration-testing reports, disaster-recovery and business-continuity plans, and incident-response procedures.
  • Internal governance: Organisational chart, compliance-function mandate, risk-management framework, internal-audit arrangements, outsourcing register, and conflict-of-interest policy.
  • Financial and capital evidence: Audited financial statements, capital-adequacy calculation, proof of own funds (bank statements, shareholder-loan agreements), and professional-indemnity insurance arrangements where applicable.
  • MiCA-specific requirements (where applicable): Crypto-asset whitepaper (for issuers), reserve-asset documentation (for ART/EMT issuers), client-disclosure templates, and marketing-material compliance review.

[Download: GLE_Crypto_Licence_Germany_Checklist.pdf comprehensive application-readiness checklist. Asset to be produced and linked by the editorial team.]

Estimated costs and timelines what to budget for

Costs for obtaining a crypto licence in Germany span three categories: regulatory fees, professional advisory costs, and internal operational build-out.

  • Regulatory filing fees: BaFin charges administrative fees for licence applications based on the type of authorisation and the complexity of the case. Current fee schedules are published on BaFin’s website. Fees for crypto-custody or financial-services applications typically range from several thousand euros to low five figures.
  • Professional costs: Legal counsel, audit firms, AML-framework consultants, IT-security assessors, and compliance-programme architects. Budget ranges vary widely for a straightforward custody-only application, industry observers report total professional costs from €100,000 to €300,000+, depending on the firm’s starting maturity.
  • Operational build-out: Hiring or contracting a qualified MLRO, compliance officer, and IT-security lead; procuring custody infrastructure and monitoring tools; establishing audit trails and reporting systems. These costs are ongoing.
  • Capital requirements: As outlined in the comparison table, own-funds requirements range from €50,000 (certain MiCA CASP categories) to €125,000+ (KWG financial-services licences), with higher thresholds for banking-type activities.

Timeline estimates: BaFin KWG authorisation typically takes 6–12 months from submission of a substantially complete application. MiCA CASP authorisation is estimated at 4–9 months from a complete dossier, though early applications may face longer processing as competent authorities establish new workflows. Incomplete submissions, remediation requests, and heightened AML concerns routinely extend timelines by several months.

Common pitfalls

  • Underestimating AML obligations: Treating AML as a checkbox exercise rather than a core operational function leads to remediation demands and delays.
  • Misclassifying hosted wallets: Assuming that a hosted wallet is “not custody” because users see a login screen if the provider controls the keys, it is custody.
  • Incomplete beneficial-ownership documentation: Missing or inconsistent information about control persons, qualifying shareholders, or complex holding structures is a top cause of supplementary information requests.
  • Insufficient operational resilience: Weak disaster-recovery plans, lack of penetration-testing evidence, and inadequate audit trails regularly trigger supervisory objections.

Exemptions, borderline cases and recent enforcement (what to watch)

True exemptions from crypto licensing in Germany are narrow. Purely technical, non-custodial services for example, providing open-source wallet software where the user alone generates and controls their private keys generally do not trigger licensing, provided the provider never has access to or control over client assets. However, BaFin interprets these boundaries strictly, and the burden of proof lies with the operator.

ATM enforcement: In one of the most visible enforcement campaigns, BaFin seized crypto-ATMs across Germany in 2024 for operating without authorisation and breaching AML controls, as documented in the BaFin 2024 annual report. Operators had assumed that ATM placement fell outside the regulated perimeter BaFin disagreed, classifying the activity as unauthorised financial services.

Hosted-wallet providers: Several hosted-wallet platforms have received BaFin cease-and-desist orders after launching in Germany without custody authorisation. The providers argued they were offering “technology services,” but BaFin’s functional analysis focused on who controls the cryptographic keys resulted in classification as custody.

Token issuers: Issuers who conducted unregistered token offerings have faced BaFin publication of enforcement notices and orders to unwind sales. Practical guidance: if you are structuring operations near the boundary of a licensing trigger, obtain a formal legal opinion and consider a pre-filing dialogue with BaFin before launch. Clear client-asset segregation, transparent custody architecture, and robust AML onboarding substantially reduce enforcement risk.

What to do next (for founders / compliance / G.C.)

The following five-step playbook provides a practical starting framework for teams evaluating whether they need a crypto licence in Germany and preparing for authorisation.

  1. Map activities (Week 1–2): Catalogue every service your platform offers or plans to offer. Cross-reference each against KWG and MiCA trigger definitions. Owner: General Counsel or Head of Compliance.
  2. Run an internal gap analysis (Week 3–4): Assess current policies, procedures, governance structures, and technical controls against BaFin/MiCA requirements. Identify gaps. Owner: Compliance Lead + CTO.
  3. Appoint key roles (Week 4–6): Designate or hire an MLRO (Anti-Money Laundering Reporting Officer), a compliance officer, and a technical security lead. These roles are non-negotiable for authorisation. Owner: CEO/COO.
  4. Seek a pre-filing meeting (Week 6–8): Engage BaFin’s Innovation Hub or authorisation team for a preliminary discussion. Clarify activity classification, documentation expectations, and any BaFin-specific concerns. Owner: General Counsel.
  5. Prepare the dossier and engage professional advisers (Week 8+): Compile the full application package (business plan, governance documents, AML framework, IT security documentation, capital evidence). Engage external counsel, auditors, and specialist consultants as needed. Owner: Project Manager with cross-functional support.

For an MVP approach that avoids authorisation risk while the application is pending, consider structuring initial operations to avoid triggering custody or exchange triggers for example, by using a white-label arrangement with an already-authorised entity while the full licence application is in progress.

Files and downloads

  • Decision Tree (SVG/PNG): Visual flowchart “Do I need a crypto licence in Germany?” [Asset to be produced by design team.]
  • GLE Crypto Licence Germany Checklist (PDF): Comprehensive application-readiness checklist covering all document categories. [File: GLE_Crypto_Licence_Germany_Checklist.pdf to be produced.]
  • Application Dossier Template (Word): Structured template for assembling BaFin/MiCA licence application documentation. [Asset to be produced.]

Sources

FAQs

Do I need a crypto licence to operate in Germany?
Yes, in most cases. If your business involves holding cryptographic keys on behalf of clients, operating an exchange or trading platform, running crypto ATMs, or issuing tokens to the public, you will need either a BaFin authorisation under the KWG or a MiCA CASP licence (or both). Use the decision tree above to identify your specific triggers.
Activities classified as financial services or banking business under the KWG require BaFin authorisation. For crypto, the most common triggers are: crypto custody (safekeeping private keys), operating exchange platforms, brokerage/order execution, crypto-ATM operation, and certain staking or lending models. See the activity-by-activity section above for detailed analysis.
MiCA creates an EU-wide CASP authorisation framework with passporting rights. For services that fall within MiCA’s scope, the MiCA CASP licence will become the primary authorisation. However, BaFin remains the national competent authority for Germany-based applicants and continues to supervise compliance. Firms already authorised under KWG benefit from transitional provisions but must convert to MiCA CASP authorisation within the prescribed deadlines.
Total costs depend on the licence type and application complexity. BaFin filing fees range from several thousand euros to low five figures. Professional advisory costs (legal, audit, IT security, AML consulting) typically add €100,000–€300,000 or more. Capital requirements start at €50,000 for certain MiCA CASP categories and €125,000+ for KWG financial-services licences. See the costs and timelines section for a detailed breakdown.
BaFin KWG authorisation typically takes 6–12 months from a substantially complete submission. MiCA CASP authorisation is estimated at 4–9 months from a complete dossier. Incomplete applications, remediation requests, and AML concerns can extend timelines significantly. Early pre-filing engagement with BaFin is strongly recommended.
No. BaFin has made clear — through enforcement actions including ATM seizures — that operating crypto ATMs or providing custody services without authorisation constitutes illegal financial services. Penalties include cease-and-desist orders, asset seizures, and potential criminal prosecution.

Our Expert

Jonathon Richards

Global Law Experts

crypto licensing dubai
By Jonathon Richards

posted 22 minutes ago

crypto money transmitter license us
By Jonathon Richards

posted 4 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Do I Need a Crypto Licence in Germany? Bafin vs Mica Explained

Send welcome message

Custom Message