The recent implementation of MiCA brought about significant regulatory changes across the entire EU market. On the one hand, security standards and operational clarity for crypto entrepreneurs have improved significantly since the new framework fully came into force. On the other hand, these shifts have affected the authorization timeframe for businesses seeking to obtain the CASP license.
With regulation becoming more robust within the latest MiCA CASP license news, the European regulators eye each application with remarkable precision, often leading to prolonged delays in the licensing process in case of even minor paperwork errors. From provable local presence to effective internal policies and background checks, the list of regulatory requirements makes crypto entrepreneurs wonder how to make the most of this complex authorization process and secure your spot in the dynamic EU market as quickly as possible. Read further to find the answers to these and other critical questions.
- The Realistic CASP License Processing Time
- What Factors Make CASP Authorization Faster or Slower?
- What Changed After MiCA’s July 1, 2026 Deadline?
- What Is the Current State of CASP licensing across Europe?
- MiCA’s Governance, Security, and Compliance Criteria
- Associated Costs and License Maintenance
- FAQ
The Realistic CASP License Processing Time
When it comes to estimating the CASP MiCA license processing time in 2026, it’s important to remember that the actual timeline might significantly differ from the one on paper. While the statutory review periods may suggest a process of around three months for a complete application, the full CASP authorization process often takes significantly longer in practice, particularly when application preparation and additional information requests are included.
On paper, the CASP timeline looks brief and simple. Under MiCA, the authority has 25 working days to determine whether an application is complete, followed by 40 business days to evaluate the complete application itself. The latter period may be suspended for up to 20 working days if the authority requests further information. And yet, even those operators that begin their licensing journey with a spotless application quickly realize that instead of 25 days, they are navigating months and months of extensive paperwork preparation, compliance procedures, operational setup, and additional requests from the local regulators. So, where is this striking mismatch stemming from? Let’s break it down into stages you can realistically plan around.
How long does each CASP authorization step actually take?
| Licensing stage | Statutory clock | Practical timing |
|---|---|---|
| Application preparation under Article 62 | Unique to each case | Depends on the business model, internal readiness and scope of services |
| Completeness check | 25 business days | Will take longer if documents or information are missing |
| Substantive assessment | 40 business days | 2 to 4 months |
| Regular’s notification and the final decision | Within 5 working days after the decision | 1 to 2 weeks |
| In total | Approximately 105 business days | Between 6 months and 1 year |
What Factors Make CASP Authorization Faster or Slower?
While there are statutory time limits for the main stages of the application, several underlying factors can greatly impact the total time needed to obtain the CASP license by MiCA in 2026. However, just as there are things that may cause delays in the licensing process, there are also numerous factors that can help avoid unnecessary delays. Below is the breakdown of the key aspects of the licensing process that can either reduce or increase its practical timeline:
Factors speeding up the authorisation
- Having an existing, regulated entity in the preferred jurisdiction;
- Maintaining effective communication with the authority before and during the procedure;
- Having the mandatory policies already aligned with the applicable MiCA, EBA/ESMA and DORA requirements;
- Having a specific, clearly defined list of intended services;
- Having a clear and transparent ownership structure;
- Having experienced legal support throughout the entire process.
Factors slowing down the authorisation
- Custody of client assets in scope;
- Highly complex corporate structure;
- Shareholders with qualifying holdings failing to satisfy the applicable suitability assessment;
- Delayed or incomplete responses to requests from the relevant regulatory authorities;
- Having outsourcing-heavy operating models;
- Questionable AML/CFT or regulatory history;
- Inadequate AML/KYC policies and controls;
- Trying to navigate the authorisation process without adequate legal expertise.
What Changed After MiCA’s July 1, 2026 Deadline?
Now that the transition period ended on 1 July 2026, MiCA authorisation is mandatory for all providers wishing to continue offering crypto-asset services in the EU. Namely, ESMA has spelled out what consequences await the unauthorised and non-compliant crypto ventures in the market. All existing VASPs that had not fully transitioned to the CASP model before July 1 are now required to immediately cease their operations and stop onboarding their EU customers, while taking steps to wind down their existing EU activities in an orderly manner.
Moreover, in a number of EU Member States, the transitional window was closed even earlier than the permitted deadline. For instance, June 30, 2025 was the critical date for VASPs in Poland, the Netherlands, Latvia, Slovenia, Finland, and Hungary. Meanwhile, such jurisdictions as Ireland, Lithuania, Slovakia, Austria, and Germany closed the transition period already in late 2025.
What Is the Current State of CASP licensing across Europe?
The dynamics of adopting the new MiCA rules have been quite diverse among the EU member states. On the one hand, Germany, the Netherlands, and France have been among the Member States with the highest numbers of entities entered in the ESMA CASP register. However, authorisation is granted to individual entities and does not mean that every crypto platform operating in these jurisdictions is compliant with MiCA.
On the other hand, there are also countries whose efforts to implement MiCA’s policies have been significantly less proactive, resulting in either delayed or even still unfinished processes of transitioning to CASP authorisation. At the earlier stages of MiCA’s enforcement, among those were Portugal, Greece, Romania, Hungary, and Poland.
MiCA’s Governance, Security, and Compliance Criteria
As you read the latest MiCA CASP license news today, you might rightfully wonder, What are the current requirements for crypto businesses that seek to legally operate as CASPs? Take a closer look at the latest list of compliance standards established by MiCA for the EU-based crypto enterprises:
1. Governance standards
- Background checks for all board members and senior executives, demonstrating their sufficient expertise, good repute and clean criminal records;
- A physical registered office in the authorization jurisdiction and a place of effective management in the EU;
- At least one resident in the EU executive director and a compliance officer;
- Regular staff training to enhance the knowledge and competence of the team.
2. Security standards
- A clearly documented risk management strategy;
- ICT incident reporting in accordance with DORA;
- Client asset segregation where the CASP holds client assets or funds;
- Annual independent audits of financial statements, together with ICT testing and audits where applicable;
- Robust AML and KYC policies and controls under the applicable AML/CFT framework.
3. Complete and accurate documentation
- Resumes and supporting information for directors and beneficiaries with proof of their qualifications;
- A program of activities describing the services the company plans to provide;
- Evidence of compliance with the prudential safeguards, which may consist of own funds, qualifying insurance, or a combination of both;
- A description of the corporate governance structure;
- A policy on outsourcing management;
- Documentation related to IT systems and security measures;
- Policies and procedures verifying compliance with all applicable CASP MiCA license requirements 2026;
- Policy on segregation of client funds;
- Information on the company structure and its close links, including relationships with subsidiaries;
- Information on the provision of cross-border services;
- Notification of planned cross-border activities before commencing such services;
- Whistleblowing policy;
- The company’s policy on pricing, costs, and fees;
- Non-discriminatory commercial activities policy for exchange services and objective, non-discriminatory operating rules for trading platforms, where applicable.
4. Minimum share capital
CASPs must maintain capital equal to the higher of the applicable permanent minimum amount listed below or one quarter of the preceding year’s fixed overheads. These safeguards can consist of their own funds, insurance, or a combination of both:
- Class 1: €50,000;
- Class 2: €125,000;
- Class 3: €150,000.
Associated Costs and License Maintenance
Now, let’s talk about the financial side of the MiCA licensing. This aspect of authorization is indeed as significant as documentation or entity registration. You might wonder, How to obtain a CASP license in the EU while keeping it affordable? In fact, without tailored legal guidance, it’s easy to get overwhelmed by the numerous financial obligations that extend far beyond the license issuance fees. The total expenses associated with the CASP licensing include two major categories, differentiated by whether the fees are paid before or after the application approval. Below is the detailed breakdown of each of these two types of costs:
Initial costs for the company setup and license application
- Physical office setup in the licensing jurisdiction;
- Application fees;
- Mandatory internal policies, including AML, CFT, ICT, etc.;
- Legal entity registration in the target jurisdiction;
- Initial capital depots, varying from €50,000 for Class 1 to €125,000 for Class 2 and €150,000 for Class 3;
- Key management’s background checks;
- ICT assessments, testing, and audits;
- Certification and notarization of the corporate documents.
License maintenance fees
- Annual supervisory fees, where charged by the relevant competent authority;
- Annual statutory audits and regulatory reporting;
- Expenses related to the local substance maintenance;
- IT infrastructure maintenance;
- Maintenance of continuous capital adequacy.
While these are the common categories of costs to expect during your authorization under MiCA, additional costs may be added depending on your specific case. For instance, if your company needs a significant rebrand before registering in your selected jurisdiction, the ongoing adjustments to the corporate structure, office rent, or key hires might result in extra fees that you should be aware of. In order to avoid the unexpected costs at any stage of the licensing process, it’s highly recommended to cooperate with a reliable team of legal professionals who will help you plan your license budget with your best interests in mind.
FAQs
How many CASP licenses have been issued in the EU so far?
At the moment of this article being published, 330 CASP licenses have been issued across the European Union under the MiCA regulatory framework. The number is derived from the latest updates tracked via the European Securities and Markets Authority (ESMA) public register.
In the near future, the number of MiCA-authorised enterprises is expected to increase significantly as all emerging companies intending to provide regulated crypto-asset services in the EU must obtain the required authorization before launching operations.
Have any MiCA rules been updated or amended recently?
The most critical update in the MiCA guidelines this year has been the end of the transitional period on 1 July 2026. However, this was the expiry of the maximum transitional period under Article 143(3), rather than an amendment to MiCA itself. This date marked the moment when all providers that were relying on national transitional arrangements could no longer continue on that basis.
How does MiCA affect cross-border crypto operations in the EU?
One of the major advantages provided by the new MiCA framework is the passporting rights, which allow an authorised CASP to provide the services across the EU. This way, once licensed in one of the EU member states, the platform may provide those services in other EU member states after completing notification without having to apply for additional licenses.
This principle unlocks significant opportunities for businesses’ quick growth across the area. Meanwhile, MiCA’s strong emphasis on operational security ensures that the licensed entities contribute to the market’s integrity and stability. Unlike the former, fragmented crypto regulations across the EU, the current MiCA framework is taking a huge step forward in establishing clear, robust, effective, and unified standards applicable to CASPs across the entire area.
What role do national regulators play in CASP licensing?
While the compliance standards for all European CASPs are established by MiCA, it is the national regulators that process each particular application and communicate with the operators. In most cases, the national central banks oversee the applicants’ financial compliance and the fulfilment of the core requirements.
How often must CASPs report to regulatory authorities?
MiCA’s standards for operational security mandate licensed operators to submit their reports and notifications to the local authorities at various levels of frequency. Namely, there are three major categories of reporting that differ in their purpose and urgency:
- Quarterly and semi-annual reports are required for monitoring the transactions and financial activities of the licensed entity. These also include the basic volume reporting, user account counts, and cross-border activity statistics;
- Annual reporting applies to the internal controls, compliance monitoring, external financial audits, and ICT risk reports, depending on the applicable requirements;
- Occasional, event-related reporting associated with cybersecurity incidents, suspicious transactions, operational changes, and financial breaches.
What are the benefits of obtaining a CASP license?
Besides the obvious benefit of CASP licensing, which is the legal right to provide crypto services in the EU, the MiCA authorisation provides several other advantages. Namely, once licensed, your venture can perform crypto operations not only in your business setup jurisdiction but also in all EU member states under the same licensing, subject to the passporting notification procedure. This policy is particularly useful when it comes to expanding your business reach quickly and without spending extra.
Also, the CASP license serves as a trusted seal of your ongoing compliance and demonstrates your commitment to responsible financial conduct in the market. Since MiCA and related EU rules for cybersecurity, data protection, and local presence are known as incredibly robust, they ensure that only fully compliant and verified entities enter the market.
Is a CASP license recognized outside the European Union?
No, the CASP license issued under the EU’s Markets in Crypto-Assets (MiCA) regulation is not automatically recognized outside the European Union, except where MiCA applies through EEA arrangements (namely in Norway, Iceland, and Liechtenstein). In order to legally operate in any of the non-EU countries, operators must adhere to the local crypto rules and regulations. However, holding the CASP license acts as a certain trust indicator as it confirms the company’s basic AML and data protection compliance. This, in turn, can significantly simplify the verification process in the non-EU jurisdiction where you plan to provide your services.
How can a company prepare for a successful CASP license application?
While the CASP authorisation can become easily overwhelming if navigated alone, there are several ways to make it as smooth and efficient as possible:
- Make sure to contact a team of experienced legal consultants before starting the application process. They will help you build a clear, tailored authorisation strategy and assist you with each step of the procedure, including the document preparation, communication with the authorities, establishing local presence in the target jurisdiction, and beyond.
- Prepare the complete and accurate documentation featuring probable information about your business model and management. Most of the delays occur specifically during the document preparation phase, as even minor errors are taken with caution and must be corrected before sending the documents for the second revision.
- Ensure that the financial details you provide to the regulator are both accurate and provable. This includes the financial records, source of funds, and other relevant records. Compliance with the applicable share capital requirements falls into the same category of importance, too.
- Establish proper local presence in the jurisdiction where you plan to anchor your business. Under MiCA, the CASP must have its registered office in a Member State where it carries out at least part of its crypto-asset services, its place of effective management in the EU, and at least one director resident in the EU. Keep in mind that MiCA requires the applicants to also provide detailed documentation about each key hire, along with the confirmation of their expertise in the field of their work. If your application misses any of the relevant information in this regard, the risks of licensing delays are quite significant.
Are there cybersecurity requirements for CASP license holders?
Yes, MiCA and DORA have set strict cybersecurity requirements for operators seeking to proceed with CASP authorisation. Namely, the applicant companies must implement formal information and communication technology (ICT) security policies, data governance frameworks, and mandatory internal controls. The local regulators’ priority here is to protect the clients’ cryptographic keys, digital assets, and sensitive user data from possible breaches or information losses. Other security measures, such as the platforms’ testing, regular system audits, and infrastructure monitoring, also aim to guarantee sufficient security of operations in the long term.
Can startups apply for a CASP license?
Yes, both startups and established companies seeking to reach EU clients and to provide regulated crypto-asset services in the EU can and must obtain the CASP licence upon having their company officially registered in their target jurisdiction. Once the legal entity is incorporated, the applicable capital requirements are met, the mandatory local presence is established, and operational security measures are applied, the business is eligible to apply for the CASP authorisation.
What are the ongoing compliance costs associated with a CASP license?
When it comes to calculating your ongoing license expenses, it’s important to note that the exact price list is unique to each company and varies depending on the scope of permitted activities, the complexity of the business model, and other major factors. Yet, certain costs commonly apply to all CASPs who have already received their license and seek to maintain it in the years to come. Those include the annual supervisory fees, where charged by the relevant authority, physical office maintenance, compliance fees, regular audits and reporting, local substance costs, and other expenses.
Why is the CASP license important for the future of the European crypto market?
The Crypto-Asset Service Provider (CASP) license is the cornerstone of the Markets in Crypto-Assets Regulation (MiCA), establishing a single rulebook across all 27 EU member states. It replaces fragmented national registrations, provides EU-wide passporting rights, builds institutional trust, and sets strict operational and security standards required to legally operate. This way, the European market is currently undergoing a fundamental shift towards improved regulatory clarity and precision in operational standards for CASPs in all member states. Businesses that seek to serve clients in any of the EU countries no longer need to rely on the inconsistent operational rules of each particular jurisdiction. Instead, they are provided with a transparent, clearly defined framework of standards to adhere to, knowing that the same rules apply in all other EU destinations.







