The Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) has created a single, harmonised licensing framework for Crypto-Asset Service Providers (CASPs) across the European Union. For businesses choosing Denmark as their home Member State, the national competent authority is Finanstilsynet the Danish Financial Supervisory Authority which handles every stage of the MiCA CASP Denmark authorisation process, from pre-filing engagement through to final decision. With supervisory standards tightening across the EU in 2026, applicants face elevated scrutiny of governance, real presence, AML controls and outsourcing arrangements. This guide, published by Global Law Experts drawing on a 17-year cross-border network and regulatory compliance experience sets out the eligibility criteria, step-by-step application process, timelines, capital requirements and passporting strategy that every applicant needs to understand before filing with Finanstilsynet.
MiCA defines a closed list of crypto-asset services. Any entity performing one or more of the following on a professional basis within the EU requires authorisation:
Applicants should map their business model to one of the three prudential classes set out in MiCA Annex IV. In general: Class 1 (€50,000) covers advice, order reception/transmission, and placing; Class 2 (€125,000) covers exchange, execution and transfer services; Class 3 (€150,000) covers custody and trading-platform operation. Hybrid models offering services across classes must satisfy the highest applicable capital threshold.
Some business models particularly those combining fiat-currency payment services with crypto may trigger parallel licensing under the Payment Services Directive (PSD2) or the Electronic Money Directive. Where crypto-asset instruments qualify as financial instruments, MiFID authorisation may be required instead of, or in addition to, MiCA. Applicants should conduct a regulatory perimeter analysis before filing.
Finanstilsynet acts as the home-state national competent authority for any CASP whose registered office is in Denmark. It is responsible for receiving and assessing all authorisation applications, conducting fit-and-proper evaluations, and once authorisation is granted ongoing supervision. Finanstilsynet’s dedicated MiCA page provides the statutory basis and practical guidance for applicants.
Two practical routes exist, depending on the applicant’s history:
For cross-border services only (i.e., providing services into Denmark from another Member State), the entity’s home NCA handles the notification; Finanstilsynet then acts as host authority.
Industry observers note that engaging with Finanstilsynet before formal filing significantly reduces completeness-check delays. Recommended pre-filing steps include: setting up portal access, preparing a draft business plan for informal discussion, and identifying the specific CASP services for which authorisation is sought.
Before any documentation is drafted, clearly define which of the nine MiCA crypto-asset services you intend to offer. This determines your prudential class, governance requirements and the documentation scope.
The applicant must be a legal person incorporated in an EU Member State. If using Denmark as the home state, this typically means establishing a Danish ApS or A/S, with a registered office, articles of association and a complete shareholder register. Non-EU founders should plan for local directorship and resident agent arrangements.
ESMA’s supervisory briefing on CASP authorisation emphasises that NCAs must rigorously assess the collective competence, experience and integrity of the management body. Prepare: detailed CVs for all board members and senior managers; criminal record certificates (not older than six months); declarations of conflicts of interest; and a collective competence matrix demonstrating the board’s combined expertise in technology, compliance, finance and crypto markets.
Applicants must demonstrate initial capital at or above the MiCA Annex IV thresholds (Class 1: €50,000; Class 2: €125,000; Class 3: €150,000). Additionally, own funds must at all times equal or exceed one quarter of the preceding year’s fixed overheads. Evidence takes the form of bank confirmations, audited accounts or auditor-certified financial projections.
The application must include a comprehensive AML/KYC policy aligned with both MiCA and the Danish Anti-Money Laundering Act. This covers customer due diligence procedures, ongoing monitoring, suspicious transaction reporting, record-keeping obligations and a documented ML/TF risk assessment specific to the applicant’s service scope and client base.
CASPs are subject to ICT resilience requirements under MiCA, increasingly reinforced by the Digital Operational Resilience Act (DORA). Applicants must provide: an ICT security policy, business continuity and disaster recovery plans, incident reporting procedures, and evidence of penetration testing. Finanstilsynet expects documentation to be specific, not generic templates.
The ESMA supervisory briefing devotes significant attention to outsourcing. Finanstilsynet will verify that the applicant retains effective control over outsourced functions, that outsourcing does not hollow out local substance, and that contractual safeguards (audit rights, termination clauses, data protection) are in place. Poorly controlled outsourcing has been cited in recent Danish refusals.
Prepare evidence of: custody segregation policies, client onboarding flows, complaints-handling procedures, and market-abuse detection (where the applicant operates a trading platform). Finanstilsynet reviews these for practical adequacy, not merely formal compliance.
The full Article 62 documentation package must include:
A comprehensive Finanstilsynet CASP checklist and CASP documentation templates can help applicants ensure nothing is omitted from the documentation bundle.
MiCA itself does not prescribe a single EU-wide “substance test,” but it empowers NCAs to verify that the applicant has adequate arrangements for the services proposed. Finanstilsynet has interpreted this requirement with increasing rigour. In a published April 2026 refusal, the authority rejected a CASP application citing among other grounds insufficient documented presence in Denmark, excessive outsourcing and a lack of effective local decision-making control. This decision serves as an important signal for all applicants considering Denmark as a home state.
Guidance on how to demonstrate real presence in Denmark for a MiCA licence can assist firms in structuring their local operations to satisfy Finanstilsynet’s expectations.
Criminal record certificates must be recent (within six months). CVs should detail relevant supervisory and industry experience. Any prior regulatory sanctions, investigations or supervisory restrictions must be disclosed. Structuring submissions clearly and pre-empting queries saves significant time.
Under MiCA Articles 62–63, the process follows a defined cadence: acknowledgement of receipt, a 25-working-day completeness check, and a final decision within 40 working days of the application being deemed complete. Finanstilsynet may suspend the decision clock to request additional information and in practice, complex applications frequently trigger at least one suspension.
For entities transitioning from prior VASP registration, Finanstilsynet has published a 60-day processing note applicable during the transition period. New applications outside the transitional window should anticipate total elapsed time of three to six months, accounting for preparation, completeness queries and remediation rounds.
Finanstilsynet’s application fees are set by Danish statutory instruments and are modest relative to total project cost. The significant cost drivers are: external legal and compliance advisory fees, technical remediation (ICT policies, penetration testing), capital set-up and operational infrastructure (office, staff, banking). Typical commercial estimates for a full MiCA CASP authorisation project in Denmark range from €100,000 to €300,000 depending on complexity and service scope these are estimates only and vary significantly by applicant.
Based on published Finanstilsynet decisions including the April 2026 refusal the most common grounds for refusal include:
Once authorised as a CASP in Denmark, Article 65 of MiCA permits the firm to provide services cross-border throughout the EEA via a notification procedure. The home NCA (Finanstilsynet) receives the notification and forwards it to the host Member State NCA. There is no separate host-state authorisation though host NCAs retain certain supervisory powers over conduct-of-business rules.
| Item | Denmark (Finanstilsynet) | Estonia | Malta |
|---|---|---|---|
| Supervisory tone | Strict emphasis on substance and documented local presence | Moderate-to-strict tightened since 2024 | Moderate established crypto framework but increasing scrutiny |
| Language of service | Danish / English accepted for most documentation | Estonian / English | English widely used |
| Time to first decision (typical) | 3–6 months (preparation + statutory period) | 3–6 months | 4–8 months |
| Presence test emphasis | High recent refusals cite insufficient local control | High tightened post-2022 | Moderate-to-high |
| Initial capital (MiCA Annex IV) | EU-wide: Class 1 €50k / Class 2 €125k / Class 3 €150k enforcement emphasis on capital adequacy may vary by NCA | ||
Note: Capital thresholds are set by MiCA Annex IV and apply uniformly across the EU. Supervisory emphasis on presence and outsourcing varies by NCA, as highlighted in the ESMA supervisory briefing.
Denmark offers a credible supervisory reputation, access to Nordic banking relationships, and a regulator experienced in fintech supervision. Strategic considerations include: the quality of local banking partnerships (important for fiat on/off-ramps), the regulatory language environment, and proximity to key target markets. Industry observers note that Denmark’s stricter approach may ultimately benefit licence holders through higher credibility with counterparties and banking partners.
Detailed guidance on the EU passporting process under MiCA is available for firms planning multi-jurisdictional rollouts.
A European fintech startup offering crypto exchange and custody services selected Denmark as its home Member State, attracted by the country’s reputation for regulatory credibility and strong Nordic banking relationships. During the pre-filing review, significant gaps were identified: the management body was entirely based outside Denmark, critical compliance and IT functions were outsourced to a non-EU provider without adequate contractual controls, and the AML risk assessment was based on a generic template not tailored to the firm’s service scope.
The remediation plan involved: appointing two Denmark-resident senior managers with direct supervisory experience; establishing a Copenhagen office with local compliance and IT oversight staff; renegotiating the outsourcing agreement to include audit rights, termination provisions and Danish-law governing clauses; and commissioning a bespoke ML/TF risk assessment. After a four-month preparation phase and a clean submission, the application cleared the completeness check without suspension. Finanstilsynet issued authorisation within the statutory 40-working-day window. The case illustrates that proactive remediation particularly around presence and outsourcing control is the single most effective way to avoid the refusal patterns seen in 2026 enforcement decisions.
posted 20 seconds ago
posted 11 minutes ago
posted 17 minutes ago
posted 1 hour ago
posted 5 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message