[codicts-css-switcher id=”346″]

Global Law Experts Logo
mica casp italy

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

How to Get Mica CASP Authorisation in Italy (CONSOB + Banca D'italia)

By Jonathon Richards
– posted 1 hour ago

A practical, step-by-step guide to MiCA CASP Italy authorisation covering the dual-authority process (CONSOB and Banca d’Italia), post-transitional deadlines, application documents, AML/governance requirements, fees, timelines, and common pitfalls. Everything founders, compliance officers, and in-house counsel need to prepare a successful application.

Introduction Quick Orientation

Regulation (EU) 2023/1114 the Markets in Crypto-Assets Regulation, universally known as MiCA created a single EU authorisation framework for Crypto-Asset Service Providers (CASPs). Rather than relying on fragmented national registrations, firms that offer custody, exchange, transfer, portfolio management, advisory, or placement services for crypto-assets now require a harmonised licence. In Italy, the national implementation was enacted through Legislative Decree No. 129 of 5 September 2024 (D.lgs. 129/2024), which assigned supervisory competences between CONSOB and Banca d’Italia.

The practical effect for any firm seeking to serve Italian clients is unambiguous. Italy’s transitional period ended on 1 July 2026, as confirmed in the joint statement issued by CONSOB and Banca d’Italia on 30 June 2026. Firms that previously relied on OAM (Organismo Agenti e Mediatori) VASP registrations must now hold a full MiCA CASP authorisation, benefit from an EU passport granted by another Member State’s competent authority, or cease providing crypto-asset services to Italian customers. The commercial stakes and the demand for expert guidance are significant.

Quick Summary: Who Authorises What in Italy

Italy’s dual-authority model is a distinctive feature of its MiCA implementation. Understanding CONSOB crypto authorisation versus Bank of Italy MiCA responsibilities is the essential first step for any applicant.

Competent Authority Allocation

Entity Type Competent Authority Role
Specialised CASPs (new entrants with no prior financial licence) CONSOB Full authorisation (with Banca d’Italia opinion where required)
SIMs (investment firms non-class 1) providing crypto-asset services CONSOB Notification / authorisation
Banks, e-money institutions (EMIs), payment institutions (PIs) Banca d’Italia Notification or authorisation for certain non-notifiable services
Central securities depositories, market operators CONSOB (notification receipt) Notification receipt and supervisory coordination

The two authorities operate under a cooperation protocol that governs information exchange, joint assessments, and cross-authority opinions. In practice, an applicant filing with CONSOB should expect Banca d’Italia involvement in the assessment of prudential, AML and operational-resilience elements, and vice versa.

Timeline and Post-Transitional Status

Understanding the critical dates in Italy’s MiCA CASP transition is essential for compliance planning and market-access verification.

Key Dates

  • 29 June 2023: MiCA published in the Official Journal of the European Union; staggered entry into force begins.
  • 30 June 2024: Title III (asset-referenced tokens) and Title IV (e-money tokens) provisions apply EU-wide.
  • 14 September 2024: D.lgs. 129/2024 enters into force, assigning competences between CONSOB and Banca d’Italia and establishing national transitional arrangements.
  • 30 December 2024: Full MiCA application (Titles V and VI, covering CASP authorisation and market-abuse rules).
  • 30 December 2025: Deadline for OAM-registered VASPs to file a MiCA CASP application to benefit from grandfathering provisions allowing continued operations through the transitional period.
  • 1 July 2026: Transitional period ends. Only MiCA-authorised or passported firms may provide crypto-asset services in Italy.

OAM VASP Transition Practical Implications

Legacy OAM-registered operators that filed a complete application by the 30 December 2025 cutoff were permitted to continue operating under grandfathering conditions until 30 June 2026, or until their application was determined whichever came first. Firms that missed the deadline, or whose applications were refused, were required to wind down MiCA-regulated activities. Industry observers expect enforcement actions against non-compliant operators to intensify in the months following the July 2026 deadline.

Procedural Timeline (From Filing to Decision)

Once an application is submitted, the procedural clock runs as follows:

  1. Completeness check: ≤ 25 working days from receipt of the application.
  2. Requests for information (if any): suspends the clock; maximum suspension of 20 working days.
  3. Substantive decision: 40 working days from the date the file is deemed complete.

In total, applicants should budget 3–6 months or more from pre-engagement to a final authorisation decision, depending on the complexity of their business model and the quality of their initial submission.

Step-by-Step Application Checklist for CASP Authorisation in Italy

The following numbered steps provide a practical roadmap for a CASP authorisation Italy application. Each step is designed to be actionable for compliance teams and legal advisors preparing a submission.

Step 1 Pre-Engagement and Gap Analysis

Before engaging with the regulators, confirm your firm meets baseline eligibility: EU establishment as a legal person, place of effective management within the Member State of authorisation, and initial readiness across AML/CFT controls, minimum capital, ICT security, and governance. Conduct a thorough gap analysis to identify shortcomings before formal filing. This early investment dramatically reduces the risk of incompleteness findings and clock suspensions.

Step 2 Choose Your Home Member State

Determine whether Italy will be your home Member State (direct CONSOB authorisation) or whether you will seek authorisation in another EU jurisdiction and passport into Italy. This strategic decision should weigh factors such as local presence requirements, supervisory intensity, market proximity, and time-to-decision. (See the comparison table below.)

Step 3 Prepare the Application Dossier

Compile your application using the Commission’s RTS-compliant templates (including those specified in Commission Delegated Regulation (EU) 2025/305) and any supplementary national modules required by CONSOB or Banca d’Italia. The dossier must include governance documentation, a three-year business plan, capital planning, outsourcing registers, and technical/cybersecurity arrangements.

Step 4 AML/CFT Readiness

Ensure full compliance with Italy’s AML framework. This includes registering with the UIF (Unità di Informazione Finanziaria) where applicable, appointing an AML officer and MLRO, implementing KYC/CDD procedures, transaction monitoring systems, PEP and sanctions screening, and a documented AML risk assessment. Regulators will scrutinise this area intensively.

Step 5 Submit the Formal Application

File your completed application via PEC (Posta Elettronica Certificata) to the designated address at CONSOB (for specialised CASPs) or Banca d’Italia (for banks, EMIs, and PIs). Include proof of payment for any required fees and supervisory contributions. The PEC submission requirement and relevant contact details are published on the Banca d’Italia CASP procedures page.

Step 6 Regulatory Assessment

The authorities will conduct a completeness check within 25 working days. If additional information is required, the clock is suspended (maximum 20 working days). Once the file is complete, the substantive assessment begins, during which authorities may conduct fit-and-proper checks on senior managers, request additional evidence, or even undertake on-site inspections. The final decision is issued within 40 working days of the file being deemed complete.

Step 7 Post-Authorisation Obligations

Upon authorisation, your firm will be entered into the ESMA register of authorised CASPs. If you plan to offer services in other EU Member States, initiate the passporting notification process under MiCA Articles 60/62. Ongoing obligations include periodic reporting, maintaining minimum capital, continuous AML compliance, and incident notification.

Key Sub-Checklists

  • Board & Governance: Board composition, fit-and-proper dossiers, organisational chart, compliance function independence, risk committee terms of reference.
  • ICT & Cybersecurity: Security policy, incident response plan, penetration testing schedule, critical third-party provider controls, business continuity plan.
  • Client Asset Protection: Segregation arrangements, custodian contracts, reconciliation procedures, insolvency-remote structures.
  • Outsourcing Register: Full register of outsourced functions, SLAs, exit strategies, vendor due diligence documentation.
  • Accounting & Prudential: Auditor appointment, capital adequacy calculations, stress-test summaries, projected P&L and balance sheet.

Comparison: National Authorisation (Italy) vs EU Passport from Another Member State

The following table helps decision-makers evaluate the strategic choice between obtaining a direct MiCA CASP authorisation in Italy versus seeking authorisation in another EU jurisdiction and passporting into the Italian market.

Feature National CONSOB Authorisation (Italy) EU Passport (Home Member State Authorisation)
Home Regulator CONSOB (with Banca d’Italia opinion where applicable) Home Member State NCA (e.g., AMF, BaFin, FMA)
Time to Decision (Typical) 40 working days from complete file (Italian procedural rules) Varies by NCA; check local RTS timelines and ESMA guidance
Local Presence Requirement Strong emphasis on effective management in Italy; physical presence expectations enforced Same MiCA standard applies, but supervisory intensity varies by NCA
Enforcement Risk in Italy Direct: CONSOB/Banca d’Italia can act against non-authorised firms operating in Italy Indirect: passport notifications required Italian authorities may act if no valid notification
Ongoing Supervision Direct CONSOB/Banca d’Italia supervision; local reporting obligations Home NCA supervises; host NCA (CONSOB) has limited product-intervention and consumer-protection powers

Key Requirements and Eligibility for an Italy Crypto Licence

MiCA and D.lgs. 129/2024 set out clear eligibility criteria for firms seeking CASP authorisation in Italy.

  • EU Establishment: The applicant must be a legal person established in an EU Member State with its registered office and place of effective management in the Member State of authorisation. Italy enforces strong physical-presence expectations a letterbox entity will not suffice.
  • Board Composition: At least one director must be resident in the EU. Senior management must collectively possess adequate knowledge, skills, and experience, and each individual must pass fit-and-proper assessments.
  • Minimum Capital / Prudential Requirements: MiCA prescribes minimum own-funds requirements that vary by service type (from €50,000 to €150,000), plus ongoing own-funds obligations. Detailed calculations follow the relevant RTS provisions.
  • Technical Operations: Robust ICT security arrangements, business-continuity planning, and critical-third-party controls are mandatory. The Commission’s delegated acts on continuity and ICT set the benchmark.
  • Client Asset Protection: Safeguarding obligations require the segregation of client crypto-assets and funds, with documented custodial and reconciliation arrangements.
  • Complaint Handling: Firms must implement transparent complaint-handling procedures accessible to clients at no charge.

Entities with close links that could impede effective supervision, or those subject to supervisory impediments identified by CONSOB or Banca d’Italia, may be refused authorisation.

Required Documents for a MiCA CASP Application

The following list summarises the documentation applicants must compile. Each item maps to fields specified in the Commission’s RTS on application content.

  • Cover Letter and Entity Details: Corporate documents, statutes, certificate of incorporation, and a full ownership chart (including ultimate beneficial owners).
  • Business Plan: Three-year business plan with projected profit-and-loss, balance sheet, capital plan, and stress-test summary.
  • Governance Documents: Board CVs, organisational chart, fit-and-proper dossiers (KYP) for all senior managers, heads of control functions, and qualifying shareholders.
  • ICT and Compliance Documentation: Information security policy, incident-response plan, penetration-testing reports, and details of outsourcing arrangements (including SLAs and exit plans for critical third-party providers).
  • AML/CFT Procedures: Complete AML manual, transaction-monitoring methodology, KYC/CDD policies, names and credentials of the AML officer and MLRO, record-retention protocols.
  • Capital and Custodian Arrangements: Proof of capital (audited statements), contracts with custodians, details of safeguarding mechanisms, and auditor appointment confirmation.
  • Effective Management Evidence: Residence details of key executives, office lease agreements, documentation of executive presence and decision-making in Italy.

All documents must be submitted via PEC using the official templates published by CONSOB and Banca d’Italia. Applicants should reference the national guidance pages and the relevant Commission delegated and implementing acts for exact template specifications.

AML/CFT and Governance Requirements

MiCA does not replace Italy’s existing AML/CFT framework it layers additional obligations on top. CASPs must integrate MiCA-specific requirements with Italy’s national AML regime, including obligations under Legislative Decree 231/2007 (as amended) and UIF guidance.

  • Transaction Monitoring and Sanctions Screening: Automated, risk-based transaction monitoring with real-time sanctions and PEP screening. Systems must be calibrated for the specific risk profile of crypto-asset transactions, including chain-analysis capabilities.
  • Suspicious Activity Reporting: Firms must report suspicious transactions to the UIF without delay, maintaining complete audit trails.
  • AML Risk Assessment: A documented, enterprise-wide AML risk assessment must be maintained and updated at least annually, covering customer, product, geographic, and delivery-channel risks.

On the governance side, MiCA and the delegated acts on continuity and ICT require:

  • Compliance Function Independence: The compliance function must operate independently from revenue-generating business lines, with direct reporting access to the board.
  • Risk Committee: A formal risk committee (or equivalent arrangement proportionate to the firm’s size) must oversee operational, financial, and cyber risks.
  • Periodic Audits: Internal and external audits of AML controls, ICT systems, and governance arrangements at defined intervals.
  • Business Continuity and ICT Controls: Documented business-continuity plans, disaster-recovery procedures, and critical-third-party oversight arrangements, tested at least annually.

Fee and Timing Expectations

Transparency on costs is critical for budgeting. CONSOB has published fee resolutions covering supervisory contributions for the crypto sector. As an illustration, CONSOB’s contribution framework has referenced a €5,000 contribution per supervised-entity element for certain categories though applicants should consult the latest resolution for exact figures applicable to their specific service profile.

Beyond regulatory fees, firms should budget for:

  • Legal and advisory fees: Engaging local Italian counsel experienced in MiCA CASP applications is strongly recommended.
  • Capital deployment: Meeting minimum own-funds requirements and maintaining ongoing capital buffers.
  • Technology and compliance infrastructure: Transaction-monitoring platforms, custody solutions, ICT security hardening, and penetration testing.

In terms of the regulatory timeline, the procedural clock from submission to decision spans roughly 65+ working days in a best-case scenario (25 working days for completeness plus 40 working days for the substantive assessment). However, clock suspensions for additional information requests, combined with pre-engagement preparation time, mean that a realistic end-to-end timeline from initial project kick-off to live authorisation is typically 3–6 months or more.

Common Pitfalls and How to Avoid Them

Based on emerging supervisory practice and publicly available guidance, the most frequent causes of application deferrals or rejections include:

  • Incomplete AML/KYC Documentation: Missing or generic AML manuals, inadequate transaction-monitoring specifications, or failure to name and credential the AML officer.
  • Insufficient Proof of Effective Management: Reliance on nominee directors or the absence of demonstrable executive presence in Italy.
  • Weak Governance: Board members lacking relevant experience, missing fit-and-proper dossiers, or an inadequately resourced compliance function.
  • Unclear Outsourcing and Custody Arrangements: Missing or incomplete contracts with technology providers, custodians, or cloud-service suppliers especially for critical third-party providers.
  • Economic Substance Concerns: Insufficient evidence that the firm genuinely operates from Italy (office leases, local staff, decision-making records).
  • Poor Capital Planning: Unaudited financial statements, unrealistic projections, or failure to demonstrate stress-test resilience.

Mitigations: Conduct a thorough pre-submission gap analysis with experienced MiCA counsel. Prepare documented board minutes confirming executive presence and decision-making authority in the EU. Submit audited capital statements from the outset. Compile a complete vendor due-diligence pack for all outsourced functions.

Currently Authorised CASPs in Italy and Next Steps

CONSOB, in coordination with Banca d’Italia, began granting MiCA CASP authorisations in 2026. The first authorisation was granted to CheckSig S.r.l. in May 2026, marking a significant milestone in Italy’s MiCA implementation. Additional authorisations are expected as the pipeline of applications is processed.

For the latest authoritative list of authorised CASPs, consult the ESMA CASP register and CONSOB’s official announcements. (Last verified: 9 August 2026)

EU Passporting Next Steps

Once authorised, CASPs intending to offer services cross-border within the EU must follow the passporting notification process under MiCA Articles 60 and 62. This involves notifying the home NCA, which then communicates with the host Member State authorities. ESMA has published Q&As on passporting procedures to assist firms in preparing their notifications. Key practical steps include compiling national-specific attachments and confirming that the services to be passported fall within the scope of the original authorisation.

Sources

FAQs

Who grants MiCA CASP authorisation in Italy?
CONSOB and Banca d’Italia share responsibilities. CONSOB handles CASP authorisations for specialised CASPs and certain SIMs (with a Banca d’Italia opinion where required), while Banca d’Italia handles notifications and authorisations for banks, electronic money institutions, and payment institutions, as set out in D.lgs. 129/2024.
Prepare a RTS-compliant application using the Commission templates and submit via PEC (certified email) to CONSOB’s designated address. The authorities conduct a completeness check within 25 working days and issue a substantive decision within 40 working days from the date the file is deemed complete.
Corporate documents and ownership chart, a three-year business plan, governance CVs and fit-and-proper dossiers, capital proof, AML/CFT manual, ICT/security policy, outsourcing contracts, and other items specified in the Commission’s delegated and implementing acts on CASP application content. National templates published by CONSOB should be used.
Only if they filed a MiCA CASP application by the relevant deadline (30 December 2025 in Italy) and are operating under the grandfathering conditions. Firms that did not comply must cease providing MiCA-regulated services after 1 July 2026. The Banca d’Italia FAQ provides further specifics on transitional eligibility.
Italy’s transitional arrangements closed on 1 July 2026. Firms needed to file their applications by 30 December 2025 to benefit from grandfathering provisions. After 1 July 2026, only MiCA-authorised or EU-passported firms may provide crypto-asset services to Italian customers.
The authoritative, up-to-date list is maintained by CONSOB (via national announcements) and the ESMA interim MiCA register. As of publication, CONSOB had authorised CheckSig S.r.l. (May 2026) as the first Italian MiCA CASP, with additional authorisations in the pipeline. Consult the ESMA register and CONSOB press releases for the current list.

Our Expert

Jonathon Richards

Global Law Experts

Annulment vs divorce UAE
By Global Law Experts

posted 5 hours ago

mica casp spain
By Jonathon Richards

posted 5 hours ago

can a director be liable
By Global Law Experts

posted 6 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Get Mica CASP Authorisation in Italy (CONSOB + Banca D'italia)

Send welcome message

Custom Message