Blokchain Basics
•
9
min read

MiCA CASP Authorization File: Beginner Guide

Checklist for MiCA CASP licensing: map services, fix governance/AML/ICT gaps, draft the authorization file, and handle regulator review.

If you want to offer crypto services in the EU, you now need a MiCA license in many markets, and the application file is the document set that proves your firm is ready. If your file is weak, incomplete, or out of line with how your business works, review can stall. And after July 1, 2026, operating without a valid license can lead to fines of up to €5 million or 5% of annual turnover.

Here’s the short version:

  • Map your services first so you know which MiCA rules apply
  • Fix gaps early in governance, AML/CFT, Travel Rule, ICT, and DORA
  • Assign one owner per workstream across legal, compliance, finance, risk, and security
  • Build the file in review order: legal identity, ownership, governance, AML/CFT, ICT, disclosures
  • Prepare for regulator questions on wallet control, transaction monitoring, outsourcing, and incident response
  • Keep the file up to date after approval as your products, controls, and EU footprint change

In other words: I’d treat the authorization file as more than a filing pack. It’s the regulator’s first test of whether your firm is set up like a financial institution instead of just a crypto product with policies attached.

That means the job is simple to describe, even if it takes work to do:

  1. Define what you do
  2. Match each activity to a MiCA service
  3. Document the controls behind it
  4. Submit the file in the format your NCA wants
  5. Answer follow-up questions without creating conflicts across sections

A few points stand out from the article:

  • A fiat-to-crypto platform may trigger more than one MiCA service category, such as exchange, custody, execution, or transfer services
  • The EU Travel Rule has no minimum threshold, so every crypto transfer needs originator and beneficiary data handling
  • CASPs also fall under DORA, so ICT, incident response, business continuity, and outsourcing records need to line up with that framework too
  • Regulators want proof that the business is real, controlled, and resilient, not just well presented on paper
MiCA CASP Authorization: 4-Step Application Process

MiCA CASP Authorization: 4-Step Application Process

Quick view

Step What I’d focus on Main goal
1 Service mapping and internal gap check Know your scope and fix weak spots
2 Drafting the core file sections Show how the firm is built and controlled
3 Submission and regulator review Answer questions cleanly and keep the file aligned
4 Post-approval updates Keep the license record in line with business changes

Bottom line: if you start with service mapping, tie each service to a control set, and keep one clear owner over the file, you give yourself a much better shot at a smoother review.

Now I’ll walk through what that looks like in practice.

Step 1: map your services and prepare internally

Match your business model to MiCA service categories

Start by matching each product flow to the MiCA service it sets off: custody, trading-platform operation, exchange, execution, placing, order reception and transmission, advice, portfolio management, and transfer services.

A simple way to do this is with a service matrix that shows the planned activity, the MiCA label, the owner, and the controls it triggers.

For a fiat-to-crypto platform, the main category is often exchange of crypto-assets for funds. But that usually isn't the whole story. If the platform also holds crypto for users, routes orders, or moves assets between wallets, those actions can pull in custody, execution, or transfer-service rules too. On paper, the user journey may look simple. Under the hood, the authorization load can still be much larger.

Once you lock the service scope, pressure-test whether the business can support it.

Run a gap assessment across governance, AML, and ICT

After you've mapped the services, compare your current controls with what MiCA asks for. The gap check should cover three areas:

Area What to check
Governance Board composition, decision-making authority, fit-and-proper evidence, internal reporting lines
AML/CFT Customer due diligence, sanctions screening, suspicious activity reporting, Travel Rule readiness
ICT/Security Incident response, business continuity, wallet and key management, outsourcing oversight

The EU Travel Rule applies to every crypto-asset transfer, with no minimum threshold. That means your platform needs a process to collect, verify, transmit, and keep originator and beneficiary data for five years. If that process doesn't exist yet, that's a gap to fix before you start drafting the file.

On the ICT side, CASPs fall under DORA, so your security documents need to address both MiCA and DORA. Incident response, business continuity, and outsourcing oversight each need clear write-ups.

Once the gaps are on the table, give each workstream a named owner.

Assign owners and build a document checklist

Split the authorization file across legal, compliance, finance, risk, and security. Each area should have one named owner responsible for drafting and review.

Legal handles the corporate structure and entity records. Compliance maps services and prepares AML/CFT policies. Finance puts together the business plan and prudential inputs. Risk documents the control framework. IT and security cover ICT, key management, and incident response.

Then build a checklist that links each document to the MiCA rule it supports and marks its status as complete, draft, or pending. This should cover legal-entity records, ownership charts, the service matrix, governance records, AML/CFT policies, ICT/security documents, outsourcing records, and any missing evidence still to collect. If the business model, entity records, and controls don't line up, review tends to slow down.

Once the scope, owners, and gaps are clear, draft the core file sections in the same order the regulator will review them.

Step 2: build the core sections of the application file

Use the Step 1 checklist to draft the file in the same order the regulator will review it: identity, ownership, governance, AML/CFT, ICT, and disclosures.

That order matters more than it may seem. If your file jumps around, the reviewer has to piece the story together on their own. A file that follows regulator order is easier to check, easier to compare against the rules, and less likely to trigger back-and-forth follow-up.

Start with the records that show the applicant exists as a legal entity and how the business is owned.

This section should include your entity records, an ownership chart, and a business plan that explains your service model and operating assumptions. Keep it plain and direct. The reviewer should be able to understand who owns the business, what the firm plans to do, and how the model works in practice.

Governance, controls, and client protection policies

Next, set out who owns each major function and how decisions are recorded.

The regulator should be able to see a simple control structure, clear reporting lines, and policies that match the services you plan to offer. If your chart says one thing and your policies suggest another, that gap tends to stand out fast. The goal here is to make responsibility easy to trace.

AML/CFT, ICT security, and safeguarding arrangements

For each service you mapped in Step 1, attach the matching control evidence.

Include your AML/CFT manual, customer due diligence procedures, sanctions screening methodology, suspicious activity reporting workflow, and Travel Rule process.

Include an independent IT security audit and remediation evidence, plus a plan for ongoing cyber-resilience testing and monitoring.

For each asset or listing in your service scope, attach the matching due-diligence and conduct controls. For asset listing disclosures, include a due-diligence summary and a conduct policy covering marketing review and disclaimer placement. If the listing qualifies as a public offer, a MiCA white paper is required.

Document/Section Regulatory Evidence Required
IT Security Audit Report Independent audit of systems and ongoing cyber-resilience testing protocols
Due Diligence Summary Description of the scope and limitations of the review performed on listed assets
Conduct Policy (Marketing) Evidence of neutral language and disclaimers beside the relevant description
White Paper (if applicable) Required if the listing qualifies as a public offer

Once these sections are assembled, move to the official submission forms and regulator review points in Step 3.

Step 3: manage regulator review and final submission

Once the file is complete, submit it through your national competent authority's (NCA) required portal and forms. At this stage, the regulator will check whether the policies and evidence from Step 2 line up with how the business works in practice.

Use the official forms and submission templates correctly

Use the regulator's official forms and submission templates exactly as required. Small formatting mistakes can slow things down.

If your national regulator offers pre-submission contact, use it to confirm the filing route before you submit. It's a simple step, but it can help you avoid sending the file down the wrong path.

Prepare for questions on governance, AML, and resilience

During completeness checks and full review, NCAs look closely at governance, AML/CFT, ICT security, client asset controls, transaction monitoring, incident response, and outsourcing oversight. Put simply, they want to see that your controls match day-to-day operations, not just what's written on paper.

On AML, be ready to explain who controls the wallet, not just the account holder. This reflects the broader shift toward wallet intelligence and goes beyond standard KYC.

Final filing steps and how to handle regulator responses

After submission, handle each regulator question as its own item and answer only what was asked. Think of each request like change control: respond directly, update every affected section, and resubmit the revised pages together.

If the NCA asks for clarifications or revised documents, send them in the requested format. Then double-check that the updated file stays aligned across all sections. One answer can ripple into several parts of the application, so it's worth being careful here.

Conclusion: keep the file current after authorization

After submission and approval, the job changes. It moves from filing to maintenance. Authorization is a milestone, not the finish line. It marks the start of ongoing accountability.

The path is straightforward: define the scope, fix internal gaps, build the dossier, and respond directly to regulator review. In practice, that means the dossier needs to stay in step with the business as it changes.

Keep the file current as governance, AML, ICT, products, and markets change. Update it when you add services or expand into another EU Member State. As the business grows, controls need to grow with it.

Operating without a valid license after July 1, 2026, can lead to fines of up to €5 million or 5% of total annual turnover. Treat the authorization file as an active compliance record, and assign one owner to keep it current.

FAQs

Do I need a MiCA license for every crypto service I offer?

Not necessarily. You don’t need a separate license for each service if your CASP authorization already covers the activities you offer.

When you apply, you need to map your business activities to MiCA’s service categories with care. Your license class and capital requirements depend on the services in your application. If you add new services later, you may need to apply again.

What documents usually take the longest to prepare?

The biggest delays usually come from documents that need to prove how your company actually operates - not from generic templates.

That usually means AML policies, ICT risk management materials, and ICT audit and incident reporting frameworks aligned with DORA. If those pieces are drafted late, or written in terms that are too broad, they can slow down the entire MiCA CASP authorization file.

What happens if your business changes after approval?

If your business changes in a major way after receiving MiCA authorization, your day-to-day operations still need to line up with the standards and business model approved by your National Competent Authority.

Big changes to your operations, governance, or risk management can trigger a notice requirement or a new review. And if your filings are no longer accurate, or you stop following the conditions of your license, that can lead to compliance problems and affect how your firm appears in the ESMA public register.

Related Blog Posts