Blokchain Basics
10
min read

CASP Registration Guide: Regional Rules 2026

Step-by-step MiCA CASP checklist: classify services, meet governance/AML and capital rules, file with your regulator, then passport EU access.

If you serve EU crypto users, July 1, 2026 was the cutoff. After that date, a firm needs MiCA CASP approval to keep serving EU clients, and old local VASP registrations are no longer enough.

Here’s the short version:

  • MiCA is now the base rule set for crypto service firms in the EU.
  • A CASP can include firms doing custody, trading, exchange, order execution, advice, portfolio management, transfers, and related services.
  • Firms must be set up as an EU legal entity, meet governance, AML/CFT, cyber, and complaints rules, and hold the right level of capital.
  • Capital tiers run from $50,000 to $150,000, based on the services offered.
  • CASP approval and token issuance are not the same thing. ART and EMT issuers face a separate MiCA track.
  • The filing process usually means: classify services, build the dossier, file with the local regulator, answer follow-up questions, then wait for approval.
  • Review style still varies by country, especially in France, Germany, Italy, Spain, the Netherlands, and Poland.
  • Once approved, a firm can passport across the EU and EEA, but only after getting its home-state license.
  • Penalties can reach €5 million or 5% of annual global turnover for firms that keep serving EU clients without MiCA approval.
  • As of mid-2026, only about 210 out of 1,200+ previously registered VASPs had secured CASP authorization.

Quick Comparison

Topic What you need to know
Cutoff date July 1, 2026
Who needs approval Crypto firms serving EU clients with MiCA-covered services
Old local registration No longer enough on its own
Capital tiers $50,000, $125,000, $150,000
Filing focus Service classification, governance, AML/CFT, ICT, custody controls
Regional differences Same MiCA rules, but local review pace and scrutiny still differ
Cross-border access Passporting works after approval
Main risk Fines up to €5 million or 5% of global annual turnover

I see this guide as a plain map of what changed, what firms need to file, and where local regulator practice still shapes the process.

MiCA CASP Rules Every Applicant Needs to Know

Once you understand the MiCA baseline, the next step is the filing rules that apply across the EU. And the process starts with one simple thing: classifying your services correctly.

Application Timeline and the End of Grandfathering

MiCA’s 18-month transitional period ended on July 1, 2026.

After July 1, 2026, firms can continue providing services only if they have been granted MiCA authorization. In plain English, old national registrations don’t give you the right to operate across the EU anymore.

That changes the game. At that point, the issue isn’t just paperwork. It’s whether the business is set up to operate under MiCA from day one.

Minimum Setup, Governance, and Capital Requirements

MiCA sets a clear floor for entry. A firm must be an EU legal entity with a registered office in an EU Member State. Management must pass a fit-and-proper review, and regulators also review significant shareholders.

The firm also needs documented controls in place for:

  • Governance
  • AML/CFT
  • Cybersecurity
  • Complaints handling

Capital requirements depend on the service class. If a firm offers more than one service, the highest applicable tier applies.

Service Class Minimum Capital Service Type Typical Activities
Class 1 $50,000 Lowest capital tier Reception and transmission of orders; providing advice on crypto-assets; portfolio management
Class 2 $125,000 Middle capital tier Execution of orders on behalf of clients; placing of crypto-assets; exchange of crypto-assets for funds or other crypto-assets
Class 3 $150,000 Highest capital tier Custody and administration of crypto-assets on behalf of clients; operation of a trading platform

Once you know where your services fit, building the application file gets much easier.

CASP vs. Issuer: Keeping the Scope Clear

This is where many teams need to slow down and draw a bright line.

CASP authorization covers services like trading, custody, and advice. But token issuance sits under a different part of MiCA. If a firm issues an Asset-Referenced Token (ART) or an E-Money Token (EMT), that triggers separate obligations under MiCA, including reserve requirements, redemption rights, and whitepaper disclosures.

One approval does not cover both tracks.

So if your firm provides services and also issues tokens, you need to treat those as separate rule sets from the start. With scope, capital, and governance mapped out, the dossier can then be built in the right sequence.

How the CASP Filing Process Works Step by Step

MiCA CASP Authorization: Step-by-Step Filing Process

MiCA CASP Authorization: Step-by-Step Filing Process

Classify Your Services Before Preparing the File

Before you draft anything, sort each activity into the right MiCA service category. That choice affects the capital tier, the controls you need, and whether you can use a simplified notification route instead of a full application.

If your firm already has regulated status, such as an investment firm or e-money institution, you may be able to use that simpler route. Check that first. It can change how much work goes into the dossier.

Once your service map is set, build the file around it.

Build the Application Dossier in the Right Order

The core dossier follows a standard structure, and the build order matters more than it may seem. Start with the program of operations and business plan. Those two documents set the direction for everything that follows.

Then add the rest of the file:

  • AML/KYC controls and Travel Rule protocols, tied directly to your technical systems instead of sitting only in policy documents
  • Governance chart showing management structure and ownership
  • Risk management framework and business continuity plan
  • ICT and cybersecurity policies
  • Custody and client asset segregation evidence

The dossier should line up with how regulators review the business. They want to see live controls working inside the platform, not just a stack of written policies. They also look closely at reserve transparency, redemption SLAs, and whether you can identify who controls each wallet, not only the named account holder.

Once the file is complete, submit it to the NCA for review.

Submission, Review, Approval, and Ongoing Duties

After submission to the NCA, the application enters review and usually starts with a completeness check. From there, expect follow-up questions. This stage can take months, not weeks, especially in markets dealing with heavy backlogs.

Approval doesn’t end the work. Firms still need to maintain capital adequacy, send regular reports to their home regulator, keep AML/CFT controls up to date, and stay ready for supervisory review at any time.

After submission, the main differences come down to how each market handles review and supervision.

Regional CASP Differences Across Key EU Markets

MiCA sets one baseline for all 27 EU member states. But on the ground, things still look different from country to country. The rules are the same. The path to approval isn't.

A lot depends on each market's legacy setup and how its regulator handles reviews. Some authorities are more strict. Some move more slowly. And some are dealing with a much bigger backlog than others.

Country Legacy Regime Main Authority Transition Note
France PSAN (Digital Asset Service Provider) AMF / ACPR AMF is enforcing the transition.
Germany Crypto Custody License BaFin Most detailed governance and AML expectations in the EU
Italy OAM VASP Registry OAM / Consob License issuance remained slow near the July 1, 2026 deadline.
Spain CNMV/Bank of Spain Registry CNMV Transition to unified MiCA supervision
Netherlands DNB VASP Registration DNB High focus on reserve transparency and redemption SLAs
Poland Virtual Currency Activity Register KNF / Ministry of Finance Largest legacy pool (1,400+ firms) but slow CASP issuance

These differences matter for a simple reason: they affect how long an application takes and how closely it gets reviewed.

France and Germany: Stricter Transition and Supervision

France is moving from the established PSAN (Prestataire de Services sur Actifs Numériques) regime to full MiCA CASP authorization. AMF is no longer just giving guidance. It's now enforcing the transition and warning non-compliant platforms.

Germany, meanwhile, has one of the toughest review approaches in the EU. BaFin looks closely at governance structures, AML controls, and fit-and-proper checks for management across each application. For firms applying there, this isn't a light-touch process.

Italy, Spain, and the Netherlands: From Registry to License

Italy, Spain, and the Netherlands all used national VASP or AML registration models before MiCA. Moving from a registry system to a full license is a big shift.

In Italy, OAM (Organismo Agenti e Mediatori) managed the legacy registry, while Consob now has a closer role under MiCA supervision. And here's the sticking point: Italy had issued zero CASP licenses in the months leading up to the July 1, 2026 deadline. That's a major gap, especially given how many firms needed to move over.

Spain's CNMV is making a similar jump, from registry-based oversight to full CASP supervision. The upside is clear: once a firm is authorized, that single license can cover the entire EU through passporting.

In the Netherlands, DNB has a reputation for close review, especially on reserve transparency and redemption SLAs. So even if the framework is now shared across the EU, the level of review can still feel very local.

Poland: Local VASP Status and the Move to MiCA

Poland started 2026 with the EU's largest legacy VASP pool, with more than 1,400 firms. That sounds like a head start. In practice, it mostly means more firms need to get through the same licensing funnel.

For businesses operating from Poland, local registration is only step one. The KNF and Ministry of Finance are overseeing the transition, but firms still need to complete the full CASP authorization process if they want to keep serving EU clients after July 1, 2026.

Passporting After Approval and Rule Changes After 2026

How MiCA Passporting Works Across the EU and EEA

Once a CASP gets approved in one EU member state, it can passport its services across the EU and EEA without getting a second license. That matters a lot. But there’s a catch: passporting happens after authorization, not before.

Put simply, passporting is the outcome of finishing the filing process. It’s not a way to skip it.

The process begins with a notification to the home regulator, which then works with the host authority. Even with passporting, firms still need to follow local rules in each market, including tax, consumer protection, and marketing requirements.

That broad cross-border reach is also why regulators are expected to watch firms more closely in the next phase.

What Regulators Are Likely to Tighten Next

Passporting gives firms access to more markets, but supervision doesn’t stop once approval is in place. After 2026, supervision is expected to become tighter and more centralized, with ESMA playing a bigger role for larger firms.

Wallet checks on-chain are also likely to matter more. Regulators are moving past basic KYC and putting more weight on identifying wallet control. That shift will likely lead to stricter AML and Travel Rule enforcement.

Compliance is also being treated less like a one-time setup and more like a day-to-day function. In plain English: firms should expect real-time transaction monitoring and steady reporting of suspicious activity to become standard practice.

Regulatory Focus Area Post-2026 Expected Shift
Supervision More centralized ESMA oversight for major firms
AML/KYC On-chain wallet ownership checks and identifying wallet control
Compliance Continuous operational accountability, not a one-time setup

Conclusion: Key CASP Registration Points to Remember

Passporting only works after authorization. The firms in the best position for the next cycle will treat compliance as an ongoing operating function. In 2026 and beyond, approval is only the starting point.

FAQs

Do I need MiCA approval if I only serve a few EU clients?

Yes. If you provide crypto-asset services to clients in the European Union, you need MiCA authorization no matter how many clients you serve.

That rule also applies if your company is based outside the EU. After July 1, 2026, platforms that serve EU clients must have MiCA authorization or a pending application with their National Competent Authority. If not, they may have to stop serving those clients.

How do I know which CASP capital tier applies to my business?

Match your business activities to the services defined under MiCA. Your capital tier depends on the services you plan to offer:

  • Class 1: €50,000 for advice, order execution, reception and transmission of orders, placing, portfolio management, and transfers
  • Class 2: €125,000 for all Class 1 services, plus custody and exchange services
  • Class 3: €150,000 for all Class 2 services, plus operating a trading platform

There’s also a second test. You must keep own funds at 25% of the previous year’s fixed overheads.

So it’s not just about picking the right service class. You also need to check whether the 25% fixed-overheads rule puts you above the base capital amount.

Can I passport across the EU before my home-state CASP license is approved?

No. You can passport across the EU only after your home-state CASP license is officially approved and your firm is added to the ESMA public register.

After that, you still need to complete the notification process. That step usually takes about 15 days. Only then can you legally operate across all 27 EU member states under MiCA.

Related Blog Posts