[codicts-css-switcher id=”346″]

Global Law Experts Logo
mica casp norway

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Mica CASP Authorisation in Norway, How to Obtain a Norway Crypto Licence and EEA Passport

By Jonathon Richards
– posted 44 minutes ago

Understanding mica casp norway requirements is now a strategic priority for any firm or individual planning to operate crypto-asset services from Norwegian soil. As the Markets in Crypto-Assets Regulation (MiCA) is incorporated into the European Economic Area (EEA) framework, Norway is aligning its supervisory regime, administered by the Financial Supervisory Authority of Norway (Finanstilsynet), with a harmonised, pan-European licensing model. This guide sets out the practical, legal and procedural roadmap to obtaining MiCA CASP authorisation in Norway, from establishing a legal entity to securing an EEA passport, with a focus on the readiness window culminating around 30 June 2026.

For anyone weighing whether to launch, relocate or regularise a crypto business, the message is clear: preparation cannot wait. The transition from the earlier virtual asset service provider (VASP) registration model to full crypto-asset service provider (CASP) authorisation is a substantive uplift in obligations. This page explains how to apply, what Finanstilsynet checks, how passporting works, and what compliance under MiCA demands in terms of capital, governance and AML/KYC controls.

At-a-glance, who needs authorisation and key facts

  • Who needs authorisation: Any person providing crypto-asset services (custody, exchange, trading platform operation, order execution, placement, advice, portfolio management, transfer services) to third parties on a professional basis in or from Norway.
  • Regulator: Finanstilsynet acts as the home competent authority for a norway crypto licence and supervises CASPs on an ongoing basis.
  • Legal basis: The MiCA Regulation, incorporated into the EEA framework and given effect in Norwegian law.
  • Key readiness date: Firms should target the 30 June 2026 readiness window for formal CASP authorisation and EEA passporting preparation.
  • Passporting: Once authorised, a Norwegian CASP can notify to provide services across other EEA states without a separate licence in each jurisdiction.

How to obtain MiCA CASP authorisation in Norway, step-by-step

The mica authorisation process norway follows a structured sequence. While each application is fact-specific, the ten steps below reflect the typical path from formation to ongoing supervision. Following them in order reduces the risk of an incomplete dossier, which is the most common cause of delay before Finanstilsynet.

Step 1, Establish a legal entity and local nexus

MiCA requires a CASP to be a legal person with a registered office in a Member (or EEA) State and to have its place of effective management there. In practice this means incorporating a Norwegian entity (typically an aksjeselskap, AS) or establishing a qualifying presence with genuine local substance. Postbox arrangements will not satisfy Finanstilsynet’s expectations on effective management and mind-and-management being located in Norway.

Step 2, Confirm the scope of services

MiCA defines an exhaustive list of crypto-asset services. Identify precisely which activities you will offer, because capital thresholds, governance obligations and application content all vary by service. The MiCA services include custody and administration of crypto-assets, operation of a trading platform, exchange of crypto-assets for funds or for other crypto-assets, execution of orders, placing of crypto-assets, reception and transmission of orders, advice, portfolio management and transfer services. Being precise about scope now avoids costly variations later.

Step 3, Conduct a gap analysis

Benchmark your current operations against MiCA and Finanstilsynet expectations. A thorough gap analysis covers organisational structure, own funds, ICT and cyber resilience, complaints handling, conflicts-of-interest policy, safeguarding of client assets, and AML/KYC systems. For firms already operating as a vasp norway mica registrant, this step reveals the specific uplifts required to reach CASP standard.

Step 4, Prepare governance, capital and prudential documentation

Assemble evidence of the required minimum capital (own funds), a programme of operations, an organisational chart, business continuity plans and the internal control framework. Finanstilsynet will scrutinise whether the applicant has robust governance arrangements proportionate to the nature, scale and complexity of the services. Detailed guidance on these obligations is set out in our MiCA compliance requirements resource.

Step 5, Build the AML/KYC programme and coordinate with authorities

Design a risk-based anti-money-laundering programme covering customer due diligence, transaction monitoring, sanctions screening, record-keeping and suspicious transaction reporting. Norway’s AML regime, supervised by Finanstilsynet, applies alongside MiCA’s organisational requirements. The programme should reflect the risk profile of the specific crypto-asset services offered and account for the EU’s evolving anti-money-laundering architecture.

Step 6, Prepare the application dossier

Consolidate the required forms, attestations and policy documents into a coherent dossier. This includes identity and suitability information for directors and qualifying shareholders, proof of capital, the programme of operations, the ICT security policy, the safeguarding and segregation arrangements, and the AML manual. A well-indexed dossier accelerates review. See our Finanstilsynet CASP application checklist for the document list.

Step 7, Submit to Finanstilsynet and pay fees

Submit the complete application to Finanstilsynet through its designated procedure and pay the applicable fees. The regulator assesses completeness first, then substance. MiCA prescribes statutory assessment periods during which the authority determines completeness and then evaluates the merits; the clock is generally paused where further information is requested. Confirm current fee levels and submission channels directly with Finanstilsynet.

Step 8, Respond to queries, inspections and pre-authorisation conditions

Expect requests for additional information, clarifications and, potentially, on-site or remote assessments. Finanstilsynet may impose pre-authorisation conditions, for example, requiring evidence that capital is fully paid up or that a key control has been operationalised. Prompt, complete responses keep the assessment period moving.

Step 9, Obtain authorisation and prepare for EEA passporting

On authorisation, your entity is entered as an authorised CASP and may commence the notified services. This is the moment to activate passporting preparations if you intend to serve clients in other EEA states. Our dedicated guide to EEA passporting for CASPs explains the notification mechanics in detail.

Step 10, Ongoing reporting and the regulatory calendar

Authorisation is the beginning of an ongoing supervisory relationship. Maintain the capital position, submit periodic reports, notify material changes, keep AML systems current and manage a compliance calendar. Ongoing mica compliance norway obligations are continuous, and lapses can trigger supervisory measures up to and including withdrawal of authorisation.

Comparison, Finanstilsynet / Norway vs a typical EEA supervisor

Because MiCA is a directly harmonising regulation, the substantive requirements for a CASP are broadly consistent across the EEA. Differences arise principally in process, language, fee structures and expected timelines. The table below is indicative only; costs and timeframes vary considerably by scale, service scope and the quality of the application submitted.

Dimension Finanstilsynet (Norway) Typical EEA supervisor
Legal basis MiCA as incorporated into the EEA framework and given effect in Norwegian law MiCA directly applicable in EU Member States
Core requirements Harmonised MiCA standards: own funds, governance, safeguarding, AML/KYC Harmonised MiCA standards, substantively equivalent
Application language Norwegian; English documentation frequently accepted in practice, confirm with regulator National language, sometimes English accepted
Typical fees Application and supervisory fees per Finanstilsynet schedule, confirm current rates Varies by authority; application plus ongoing supervisory levies
Expected timeline Statutory MiCA assessment periods apply; realistic end-to-end preparation and review commonly spans several months Comparable statutory periods; total duration driven by dossier quality
Passporting role Acts as home competent authority; issues passport notifications to host EEA states Same home/host model under MiCA
Local substance Effective management and registered office in Norway required Effective management and registered office in the home state required

Note: Costs and timelines depend heavily on the number and complexity of services, group structure, outsourcing arrangements and readiness of documentation. Treat any figures obtained from the regulator as authoritative and refresh them before budgeting.

Key requirements and eligibility for CASP authorisation

Understanding what Finanstilsynet checks allows applicants to front-load the most scrutinised elements. The eligibility criteria for a crypto asset service provider norway flow from MiCA and are applied through the lens of Norwegian supervisory practice.

Eligible legal forms

The applicant must be a legal person established in the EEA with a registered office and place of effective management in the state of authorisation. For Norway that generally means a Norwegian limited company with genuine local substance, decision-makers, key control functions and appropriate operational resourcing present in-country.

Scope of services and excluded activities

Authorisation is granted for specified crypto-asset services only. Activities that fall outside MiCA, for example, certain services relating to instruments already regulated as financial instruments under other EU/EEA law, may require different or additional authorisations. Applicants must map their business model carefully to avoid gaps or overlaps with the securities regime.

Director and management suitability

Members of the management body must be of sufficiently good repute and possess the appropriate knowledge, skills and experience, individually and collectively, to perform their duties. Finanstilsynet assesses time commitment, relevant sector experience and the collective competence of the board.

Fit and proper checks

Qualifying shareholders and beneficial owners are subject to fit-and-proper assessment. The regulator examines integrity, financial soundness and any adverse regulatory or criminal history. Ownership and control structures should be transparent and documented up to ultimate beneficial owner.

Outsourcing and local presence rules

Where a CASP outsources operational functions, it retains full responsibility and must ensure the outsourcing does not impair supervision or internal control quality. Critical or important functions must be governed by robust arrangements, with clear service levels, audit rights and exit plans. Local presence must be real: outsourcing cannot be used to hollow out effective management from Norway.

Finanstilsynet application checklist

A complete, well-organised dossier is the single biggest driver of a smooth review. The list below reflects the categories a finanstilsynet casp application is expected to address. Always cross-check against the regulator’s current published requirements, as forms and formats are updated.

Mandatory documents

  • Corporate documentation: Certificate of incorporation, articles of association and current company register extract.
  • Programme of operations: Description of the crypto-asset services to be provided and how they will be delivered.
  • Governance and organisation: Organisational chart, description of internal control mechanisms, risk management and business continuity arrangements.
  • Proof of own funds: Evidence that the required minimum capital is in place and how it will be maintained.
  • Management and ownership information: Suitability documentation for directors, key function holders and qualifying shareholders.
  • Safeguarding arrangements: Policies for holding and segregating client crypto-assets and funds.
  • ICT and security policy: Cyber resilience, systems security and data protection measures.
  • AML/KYC manual: Customer due diligence, monitoring, screening and suspicious transaction reporting procedures.
  • Complaints handling and conflicts-of-interest policies: Documented procedures meeting MiCA conduct standards.

Suggested templates and attestations

Applicants often benefit from standardised templates for board attestations, capital confirmations, and policy documents. These reduce inconsistency across the dossier and demonstrate maturity to the reviewer. Our forthcoming templates page and the Finanstilsynet CASP application checklist will provide model attestations, a sample programme of operations and a governance manual outline. Recommended formats are searchable PDFs for policies and structured spreadsheets for capital and organisational data.

Transitional rules for existing VASPs

The shift from national VASP registration to full MiCA CASP authorisation is one of the most consequential aspects of mica casp norway for incumbents. Firms already registered under Norway’s earlier virtual-asset regime must not assume that existing permissions automatically carry over.

Do existing providers reapply?

Existing VASPs should assess whether their current registration covers the full range of MiCA-defined CASP activities. In most cases, providers will need to regularise their status by obtaining formal authorisation under the MiCA framework as incorporated into the EEA. The precise mechanism, whether a fresh application or a streamlined conversion, depends on the transitional provisions applied in Norway, which should be confirmed directly with Finanstilsynet and against the relevant national implementing measures on Lovdata.

Practical steps and timing to transition

Incumbents should begin the gap analysis immediately, prioritising capital adequacy, safeguarding of client assets and governance uplift, the areas where VASP-era arrangements most often fall short of MiCA standards. Working backwards from the 30 June 2026 readiness window, allow generous lead time for board recruitment, capital raising and system remediation. Our transitional rules for VASPs in Norway resource sets out a phased plan.

Temporary permissions and provisioning

MiCA contemplates transitional arrangements under which certain existing providers may continue to operate for a defined period while their authorisation is processed. The availability, length and conditions of any such grandfathering in Norway turn on how the transitional provisions are applied domestically following EEA incorporation. Because these dates are the most frequently misreported detail in secondary commentary, providers should rely only on Finanstilsynet, the EEA Joint Committee / EFTA publications and the Ministry of Finance for confirmation.

How to passport a Norwegian CASP across the EEA

One of the principal commercial attractions of a norway crypto licence is access to the single market through passporting. Once authorised, a Norwegian CASP can provide services in other EEA states without seeking a fresh licence in each. Getting the mechanics right is central to any multi-market strategy, and eea passporting mica is where careful planning pays dividends.

Notification mechanics

Passporting under MiCA operates through a notification procedure rather than a separate authorisation. The CASP informs its home competent authority, Finanstilsynet, of its intention to provide services in one or more host states, specifying the services and the states concerned. Finanstilsynet then transmits the notification to the host authorities and to ESMA, after which the CASP may commence cross-border activity once the prescribed period has elapsed.

Home and host supervisor coordination

The home authority retains primary prudential supervision, while host authorities monitor conduct within their territory and cooperate on information exchange. This home/host split means a well-run Norwegian CASP can serve multiple markets under a single supervisory relationship, provided it respects host-state conduct expectations and any local consumer-protection nuances.

Passporting timeline and strategic considerations

Passporting is generally faster than fresh authorisation because it relies on the existing licence. Even so, firms should factor in the notification period and any host-state onboarding practicalities. Strategically, many operators begin with the Nordic markets, where language, regulatory culture and customer expectations are familiar, before expanding into major EU capitals. Mapping target markets early allows the initial application to specify the intended passporting footprint, streamlining subsequent notifications. Detailed sequencing is covered in our EEA passporting for CASPs guide.

MiCA compliance in Norway, capital, governance and AML/KYC

Authorisation is proof that a CASP meets MiCA standards at a point in time; sustained mica compliance norway requires those standards to be maintained continuously. Three pillars dominate ongoing obligations: capital and prudential soundness, governance and internal controls, and AML/KYC.

Capital and prudential requirements

MiCA imposes minimum own-funds requirements on CASPs, calibrated to the services provided. The regime typically requires firms to hold the higher of a fixed minimum amount or an amount linked to fixed overheads, with the specific threshold depending on the category of services offered. Firms must maintain own funds on an ongoing basis, not merely at the point of application. The precise numeric thresholds are set out in the MiCA text and interpreted through Finanstilsynet’s supervisory practice; applicants should confirm the exact figure applicable to their service mix before finalising their capital plan.

Governance and internal controls

MiCA requires sound and prudent management, effective risk management, robust internal control mechanisms and clear conflict-of-interest management. Boards must ensure that responsibilities are allocated, that key control functions (risk, compliance and, where relevant, internal audit) are appropriately resourced and independent, and that decision-making is documented. Safeguarding of client crypto-assets, including segregation from the firm’s own assets and clear custody arrangements, is a supervisory focus area given its direct impact on consumer protection.

AML/KYC obligations and reporting

CASPs are obliged entities under Norway’s anti-money-laundering framework, supervised by Finanstilsynet. Firms must implement risk-based customer due diligence, ongoing monitoring, sanctions and PEP screening, record-keeping and suspicious transaction reporting to the Norwegian financial intelligence function. These obligations sit alongside MiCA’s organisational requirements and must be embedded in the operating model rather than treated as a bolt-on. As the EU’s anti-money-laundering rules continue to develop, firms should design programmes that can adapt to strengthened, harmonised standards. Our MiCA compliance requirements deep-dive addresses these controls in full.

Next steps toward mica casp norway readiness

The path to mica casp norway authorisation is demanding but navigable with disciplined planning. The time-critical actions are consistent for new entrants and incumbents alike: define your service scope precisely, complete a rigorous gap analysis, secure and evidence the required capital, build board and control-function capacity, and assemble a complete Finanstilsynet dossier well ahead of the 30 June 2026 readiness window. Existing VASPs in particular should treat the transition as a substantive uplift rather than a formality, prioritising safeguarding and capital adequacy.

By grounding every step in primary regulatory sources, the MiCA text, Finanstilsynet guidance, EEA incorporation instruments and Norwegian implementing measures, applicants can move confidently and avoid the timeline errors that circulate in secondary commentary. Firms that begin their mica casp norway preparation early will be best placed to secure authorisation, activate EEA passporting and enter the single market on schedule.

Sources

FAQs

When will MiCA apply in Norway and what are the key deadlines?
MiCA applies to Norway once incorporated into the EEA framework. Key practical dates include phased application milestones and a readiness window culminating around the 30 June 2026 period for formal CASP authorisations and EEA passporting readiness. Always confirm current dates with Finanstilsynet and the EEA Joint Committee / EFTA publications.
Prepare a complete application dossier, company details, governance arrangements, proof of capital, safeguarding and AML/KYC policies, and submit it to Finanstilsynet following its published procedure. Expect pre-authorisation queries and possible conditions. Consult Finanstilsynet’s guidance for the current forms and fee details.
Yes. Once authorised by Finanstilsynet as the home competent authority, a Norwegian CASP can notify to passport services across other EEA states, subject to the MiCA notification mechanics and home/host supervisory cooperation rules. No separate licence is required in each host state.
Existing VASPs should assess whether their current registration covers MiCA-defined CASP activities. Many will need to regularise their status or apply for formal authorisation under the MiCA/EEA regime. Transitional provisions may apply, so incumbents should confirm the applicable mechanism with Finanstilsynet.
MiCA sets minimum own-funds, organisational and governance standards, senior-management suitability and risk controls. Exact capital thresholds depend on the services offered and are set by the MiCA text as applied by Finanstilsynet. Confirm the figure applicable to your service mix before budgeting for a mica casp norway application.
Norway enforces AML obligations through national anti-money-laundering law and Finanstilsynet supervision, aligned with MiCA’s organisational expectations. CASPs must operate risk-based customer due diligence, transaction monitoring, screening and suspicious transaction reporting, and report to the relevant Norwegian authorities.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Mica CASP Authorisation in Norway, How to Obtain a Norway Crypto Licence and EEA Passport

Send welcome message

Custom Message