Introduction
Every EU‑facing crypto firm now confronts a binary regulatory choice: obtain full MiCA CASP authorisation and unlock an EU‑wide passport, or rely on a national VASP registration as a transitional foothold. This is the defining compliance decision for the mica casp vasp eu landscape in 2026 and the window for action has almost closed. The transitional period permitted under Regulation (EU) 2023/1114 (MiCA) ends on 1 July 2026, and ESMA has issued a public statement making clear that firms still operating without MiCA authorisation after that date must cease offering crypto‑asset services to EU clients.
The commercial stakes are significant. Firms that secure CASP authorisation gain single‑market passporting, regulatory credibility, and long‑term operational certainty. Those that have relied solely on national VASP registration face an abrupt compliance cliff with potential enforcement action, client‑asset transfer obligations, and reputational consequences. Meanwhile, national competent authorities (NCAs) across Member States have taken divergent approaches to the transitional period, creating a patchwork of deadlines, expectations, and grandfathering conditions that demands careful jurisdiction‑by‑jurisdiction analysis.
This guide delivers what general counsels, compliance officers, and crypto founders need: a single, actionable decision matrix that maps each firm profile to the right regulatory pathway. Readers will find a detailed process walkthrough for both the full MiCA CASP authorisation and the national VASP route, a head‑to‑head comparison table, cost estimates, implementation timelines, eligibility requirements, and a practical 30/90/180‑day checklist for immediate action. All legal references are grounded in the MiCA text, ESMA and EBA guidance, and NCA communications.
Executive Summary: Quick Decision Matrix
Not every crypto firm has the same regulatory risk profile, commercial ambition, or resource base. The right pathway depends on your firm type, scale, and strategic horizon. Below is a rapid‑decision framework for the most common firm profiles operating in the EU market.
Recommendation cheat sheet: If your firm intends to operate across multiple EU/EEA Member States, or plans to offer custody, exchange, or trading‑platform services at scale, full MiCA CASP authorisation is the only viable long‑term path. If your firm is testing EU market demand with a limited product set, a national VASP registration may have provided a valid interim foothold but only until 1 July 2026.
- Small exchanges and wallet/custody providers: If you were operating under national law before 30 December 2024 and have not yet applied for CASP authorisation, the transitional window has effectively expired for new applications in most jurisdictions. Prioritise immediate engagement with your NCA to confirm your status and, if necessary, prepare a wind‑down or asset‑transfer plan while expediting any pending CASP application.
- Token issuers (utility tokens, not EMTs/ARTs): MiCA’s white‑paper and disclosure requirements apply directly. If the token does not qualify as a financial instrument and falls within MiCA’s scope, the issuer’s service providers must hold CASP authorisation. Evaluate whether your project’s distribution partners are authorised or at risk of losing market access.
- DeFi service providers and non‑custodial platforms: MiCA’s scope may not extend to fully decentralised, non‑custodial protocols but borderline classifications require rigorous legal analysis. If any element of the service is custodial or intermediated, CASP authorisation is likely required. Do not assume exclusion without formal legal review.
Process / How‑To: Getting Regulatory Coverage in the EU/EEA
Two parallel paths exist for crypto firms seeking lawful market access in the EU: (A) full MiCA CASP authorisation, which delivers an EU passport and permanent operational status, and (B) national VASP registration, which provided temporary, single‑market access during the transitional period. Understanding the operational detail of each path and the practical steps for a vasp to casp transition is critical for firms that need to act now.
Path A: How to Obtain MiCA CASP Authorisation
- Pre‑application gap analysis and governance uplift (Weeks 1–6): Conduct a comprehensive gap analysis against MiCA compliance requirements. Map existing KYC/AML procedures, custody arrangements, operational resilience frameworks, risk management policies, and corporate governance structures against MiCA’s technical standards. For firms offering services related to e‑money tokens (EMTs) or asset‑referenced tokens (ARTs), this stage must also address EBA prudential requirements. Prepare a remediation plan and begin recruiting or upskilling compliance, legal, and technology personnel. Key documents to prepare include: governance and organisational structure charts, AML/CFT policies and procedures, business continuity and operational resilience plans, custody and safeguarding protocols, and client complaint‑handling procedures.
- Choose home Member State and engage local counsel / NCA (Weeks 4–10): Select the Member State whose NCA will serve as your primary supervisor. Factors include NCA processing speed, language, regulatory culture, existing corporate presence, and the availability of experienced local counsel. Initiate informal pre‑application discussions with the NCA where possible many NCAs (including the AMF in France) have published guidance and offer structured engagement. Complete KYB (Know Your Business) requirements, fitness and propriety assessments for directors and key function holders, and any required capital increases.
- Technical and prudential submissions (Weeks 8–16): Complete the formal application form prescribed by the NCA. Attach all supporting documentation: operational resilience plans, IT security and cyber-incident reporting protocols, AML/CFT measures (including Travel Rule compliance), capital schedules, and where applicable reserve management and redemption arrangements for EMTs/ARTs. Timelines for NCA processing vary considerably by jurisdiction; industry observers report that some NCAs target initial feedback within 8–12 weeks, while others may take longer.
- NCA review, queries, and remediation (Weeks 16–40+): Expect iterative rounds of NCA questions (“requests for information”). Common areas of focus include governance adequacy, cyber‑resilience testing, custody safeguarding, and the robustness of AML transaction monitoring. Respond promptly; delays at this stage extend the overall timeline. Maintain a dedicated NCA liaison function internally.
- Authorisation decision, ESMA register listing, and passport notification (Weeks 40–52+): Upon a positive decision, the NCA issues the CASP authorisation and notifies ESMA for inclusion on the ESMA interim MiCA register. The firm can then notify host NCAs in other Member States where it intends to provide services under the EU passport. Go‑live actions include activating supervisory reporting, publishing required disclosures, and ensuring client‑facing materials reflect authorised status.
- Post‑authorisation supervisory reporting and compliance calendar: Ongoing obligations include periodic supervisory reporting, AML/CFT reviews, operational resilience testing, client asset reconciliation, and complaint reporting. Budget for annual compliance costs and maintain a compliance calendar aligned to NCA expectations.
Path B: How to Rely on a National VASP Registration
- Confirm national eligibility and grandfathering: The firm must have been providing crypto‑asset services in accordance with applicable national law before 30 December 2024. Not all Member States applied the full 18‑month transitional period some shortened it or imposed additional conditions. Verify your eligibility directly with the relevant NCA.
- Register with the NCA under national VASP rules: Prepare and submit AML/CFT documentation, fit‑and‑proper assessments, and operational documentation as required under the national regime. Registration timelines have historically ranged from weeks to several months depending on the jurisdiction.
- Submit a transitional plan (if required): Some NCAs require firms relying on transitional provisions to submit a wind‑down or conversion plan, demonstrating how the firm will either obtain MiCA CASP authorisation or cease EU‑facing operations by the deadline.
- Monitor ESMA and NCA guidance; prepare migration playbook: Track MiCA‑level FAQs, ESMA public statements, and national guidance. Begin parallel preparation for CASP authorisation if long‑term EU operations are intended. This dual‑track approach is the most common strategy observed among transitioning firms.
Decision Checklist: Immediate Actions
- Within 30 days: Complete gap analysis; confirm transitional eligibility with NCA; engage external legal counsel; identify home Member State for CASP application.
- Within 90 days: File national VASP registration (if not already done) or submit CASP pre‑application materials to NCA; begin governance and compliance uplift; initiate capital planning.
- Within 180 days: Submit formal CASP application; prepare wind‑down contingency plan; begin passport notification planning for target host states; verify firm status on the ESMA register.
Comparison Table and Analysis: MiCA CASP Authorisation vs National VASP Registration
The following table provides a structured, side‑by‑side comparison of the two regulatory pathways. It is designed to support rapid decision‑making on the question of eu passporting for casp versus the limitations of national registration and to clarify the casp vs vasp costs and compliance trade‑offs.
| Feature |
MiCA CASP Authorisation (Full) |
National VASP Registration (Transitional) |
| Legal basis |
Regulation (EU) 2023/1114 (MiCA) NCA issues CASP licence; firm listed on ESMA register. |
National registration regime (pre‑MiCA rules) permitted only if operating under national law before 30 Dec 2024; Member States could shorten or deny transition. |
| Passporting |
Full EU/EEA passport once authorised (notify host NCAs). |
No EU passport limited to home‑state market only. |
| Services allowed |
All MiCA‑permitted CASP services (subject to authorisation scope). |
Only those permitted by the national registration; may be narrower. |
| Timeline to obtain |
Typically 4–12+ months (depends on jurisdiction, complexity, and prudential issues). |
Often weeks to months; provides temporary market access only. |
| One‑off cost |
Mid to high: application fees, legal/advisory, capital increases typically €100k–€1M+ depending on services and custody. |
Low to mid: registration fees and compliance uplift typically €10k–€100k for smaller firms. |
| Ongoing costs & compliance |
Higher: ongoing prudential, reporting, governance, and operational resilience requirements. |
Lower to mid: national supervisory fees and AML obligations; risk of mid‑term conversion costs. |
| Enforcement risk post‑1 July 2026 |
Authorised CASPs are compliant; subject to standard supervisory action. |
High must cease EU‑facing services if not converted to CASP by deadline. |
| Best for |
Firms seeking full EU market access, cross‑border scale, and long‑term operations. |
Firms testing EU market with limited scope only as a transitional foothold. |
Post‑Table Analysis: Practical Trade‑Offs
The choice between these pathways is not purely regulatory it has direct capital, operational, and commercial implications. Three example firm profiles illustrate the recommended approach:
- Small wallet or custody provider (single market): If resources are limited and the firm served only one Member State, national VASP registration was a rational short‑term strategy. However, with the 1 July 2026 deadline now upon the market, such firms must either complete a CASP application, secure a partnership with an authorised CASP, or prepare an orderly wind‑down of EU operations. The cost of conversion mid‑stream is often higher than early preparation would have been.
- Regional exchange with cross‑border ambitions: Full MiCA CASP authorisation is the clear recommendation. The EU passport eliminates the need for multiple national registrations and provides regulatory certainty for counterparties, banking partners, and institutional clients. The upfront investment in compliance infrastructure is significant but delivers a durable competitive advantage.
- Token issuer distributing via third‑party platforms: The issuer itself may not require CASP authorisation (depending on its role), but it must ensure that its distribution partners are authorised. Due diligence via the ESMA register is now a baseline standard. Issuers of EMTs or ARTs face additional prudential requirements under EBA supervision.
Key Requirements and Eligibility
What Counts as a CASP Under MiCA
A Crypto‑Asset Service Provider (CASP) is defined in MiCA as any legal person or undertaking whose occupation or business is the provision of one or more crypto‑asset services to clients on a professional basis. The specified services include: custody and administration of crypto‑assets on behalf of clients; operation of a trading platform for crypto‑assets; exchange of crypto‑assets for funds or other crypto‑assets; execution of orders for crypto‑assets on behalf of clients; placing of crypto‑assets; reception and transmission of orders; providing advice on crypto‑assets; providing portfolio management of crypto‑assets; and providing transfer services for crypto‑assets on behalf of clients.
Out‑of‑Scope Activities
MiCA does not apply to crypto‑assets that qualify as financial instruments, deposits, or structured deposits already regulated under existing EU financial services legislation (e.g., MiFID II). Certain decentralised finance (DeFi) activities that are performed in a fully decentralised manner without an intermediary may fall outside MiCA’s scope though the practical boundary is heavily fact‑dependent. Purely peer‑to‑peer, non‑custodial transactions with no intermediary are generally excluded. Firms must not assume exclusion without rigorous legal classification.
Basic Eligibility Checklist for MiCA CASP Authorisation
- Legal entity: The applicant must be a legal person established in an EU/EEA Member State.
- Fit and proper: Directors and key function holders must pass fitness and propriety assessments.
- Governance: Adequate organisational structure, internal controls, and conflict‑of‑interest policies.
- Capital: Minimum own funds requirements calibrated to the type of crypto‑asset services offered.
- AML/CFT: Robust anti‑money laundering and counter‑terrorist financing systems, including Travel Rule compliance.
- Operational resilience: ICT risk management, business continuity, and cyber‑incident reporting capabilities.
National VASP Registration Eligibility
To benefit from the vasp transitional period, a firm must have been providing services in accordance with applicable national law before 30 December 2024. Member States retained discretion to shorten the transitional window or to impose additional conditions. Firms should verify their specific eligibility and any local requirements directly with their NCA, as national implementations have varied materially.
Stablecoins and the Prudential Bar: EMTs and ARTs
Issuers of e‑money tokens (EMTs) and asset‑referenced tokens (ARTs) face a distinct and more demanding regulatory pathway under MiCA. The EBA oversees prudential requirements for these instruments, including reserve asset management, redemption rights, and enhanced capital and liquidity requirements. This pathway is separate from and additional to CASP authorisation for service providers dealing in such tokens. Firms involved in stablecoin issuance or distribution should treat the stablecoin prudential route (EMT/ART) as a parallel workstream requiring specialised legal and regulatory expertise.
Compliance, Costs and Resource Model
Budgeting for MiCA compliance requires clarity on both one‑off and ongoing cost categories. The total investment depends on the firm’s existing compliance maturity, the range of services sought, and the chosen home Member State. Below are the principal cost buckets and indicative ranges.
- Application and registration fees: NCA fees vary by jurisdiction. National VASP registration fees have typically been at the lower end (€1k–€20k), while CASP application fees are higher and vary significantly by Member State.
- Legal and compliance advisory: External counsel for gap analysis, application drafting, and NCA liaison typically represents a major cost component particularly for complex multi‑service applications.
- Capital reserves: MiCA sets minimum own‑funds requirements calibrated to service type. Firms providing custody or operating trading platforms face the highest capital thresholds. EMT/ART issuers face additional reserve requirements under EBA standards.
- Systems, security and custody infrastructure: Investment in IT resilience, custody technology, AML transaction monitoring, and cybersecurity is required to meet MiCA’s operational standards.
- Ongoing reporting, audit and supervisory costs: Annual compliance costs include supervisory fees, external audit, regulatory reporting, and staff training typically representing a sustained operational expense.
Indicative cost bands: National VASP registration has generally cost in the range of €10k–€100k for smaller firms (variable by state). Full MiCA CASP authorisation costs are typically €100k–€1M or more, depending on the breadth of services, capital requirements, and complexity of the remediation needed.
Resourcing model: Firms should plan for internal hires across three phases. In the first 0–6 months, prioritise a Head of Compliance and a dedicated NCA liaison (internal or external counsel). From months 6–12, add a Chief Technology Officer or equivalent responsible for operational resilience and a Money Laundering Reporting Officer. From months 12–24, build out ongoing supervisory reporting, internal audit, and training functions. Many firms combine internal resources with external specialist counsel to manage peak regulatory workloads.
Implementation Timeline and Checkpoints
Two broad timeline models apply, depending on whether a firm is pursuing a fast‑track strategy (using national VASP registration as a bridge while preparing a CASP application in parallel) or a full‑preparation approach (focusing solely on CASP authorisation from the outset).
- Days 0–30: Complete gap analysis; select home Member State; engage external counsel; confirm VASP transitional eligibility with NCA.
- Days 31–90: File VASP registration (if eligible and not already done); commence CASP pre‑application engagement with NCA; begin governance and compliance remediation.
- Days 90–180: Submit formal CASP application and supporting documentation; respond to initial NCA queries; finalise capital planning and operational resilience arrangements.
- Days 180–360+: Iterative NCA review and remediation; authorisation decision; ESMA register listing; passport notification to host NCAs; go‑live.
Critical checkpoint 1 July 2026: This is the hard deadline. ESMA’s public statement on the end of the transitional period confirms that firms must either hold MiCA authorisation or cease providing crypto‑asset services to EU clients. NCAs may require wind‑down plans, client‑asset transfer arrangements, and formal cessation notifications from firms that have not completed the authorisation process.
Decision Matrix and Next‑Step Checklist
Use the following decision logic to identify the recommended action for your firm profile:
- If your firm operates cross‑border or plans to scale across the EU: Prioritise full MiCA CASP authorisation. Begin or accelerate your application immediately.
- If your firm operates in a single Member State with limited scope: Confirm transitional eligibility with NCA. If eligible, use remaining time to prepare a CASP application or, if EU operations are not commercially viable under MiCA, prepare an orderly wind‑down.
- If your firm is a new market entrant (post‑30 December 2024): National VASP registration is not available. Full MiCA CASP authorisation is the only path to lawful EU operations.
- If your firm issues or distributes EMTs/ARTs: The stablecoin prudential route (EMT/ART) applies in addition to CASP requirements. Engage specialist counsel immediately.
30 / 90 / 180‑Day Checklist
- 30 days Legal: Confirm regulatory status; engage NCA; retain external counsel. Tech: Initiate IT resilience assessment. AML: Audit current AML/CFT framework against MiCA standards. Capital: Model minimum own‑funds requirements.
- 90 days Legal: Submit CASP pre‑application or national registration. Tech: Begin custody and cyber‑resilience remediation. AML: Implement Travel Rule compliance. Capital: Secure board approval for capital increases.
- 180 days Legal: Submit full CASP application; prepare passport notifications. Tech: Complete operational resilience testing. AML: Finalise ongoing monitoring systems. Capital: Execute capital increases; arrange insurance where applicable.
Sources