VASP licensing · Pre-MiCA frameworks
VASP License Crypto Explained — Pre-MiCA Frameworks to MiCA Migration
VASP — Virtual Asset Service Provider — was the dominant EU crypto-licensing concept before MiCA. The framework operated through national AML registers under 5AMLD: Estonia's MTR register, Lithuania's VASP register, Czech Republic's CNB list, Latvia's FCMC register, Finland's Fin-FSA register, Netherlands' DNB register. MiCA replaces all of this with unified CASP authorisation. Here's what changed and how migration works in practice.
VASP (Virtual Asset Service Provider) is the FATF-derived term used in pre-MiCA EU regulatory frameworks for entities providing crypto-asset services. VASP registration was AML-focused under 5AMLD national implementations. The MiCA Regulation (EU) 2023/1114 introduces unified CASP (Crypto-Asset Service Provider) authorisation across all 27 EU member states, replacing the fragmented pre-MiCA VASP framework with full prudential, conduct, and AML supervision.
Quick facts
| Parameter | Value |
|---|---|
| VASP term origin | Financial Action Task Force (FATF) 2018 recommendations on virtual assets and VASP regulation |
| Pre-MiCA VASP frameworks | Estonia MTR (since 2017), Lithuania VASP register (since 2020), Czech Republic CNB list (since 2017), Latvia FCMC register, Finland Fin-FSA register, Netherlands DNB register |
| Pre-MiCA framework scope | AML/CFT registration only under 5AMLD; no substantive prudential or conduct supervision |
| MiCA replacement | Full CASP authorisation under MiCA Articles 59-89 covering prudential, conduct, AML, ICT, operational resilience |
| Transitional regime | MiCA Article 143 — VASP register operators can continue under transitional arrangements until 1 July 2026 maximum |
| Migration deadline | 1 July 2026 — VASP register operators must hold MiCA CASP authorisation or cease EU customer operations |
| Member-state deadline variation | 1 July 2026 is the default maximum; member states could shorten or disapply. Per ESMA's Article 143(3) grandfathering list, Netherlands took 6 months and Germany/Ireland 12 months, while Italy and Spain extended domestic windows to 30 December 2026 |
| Pre-MiCA register peak | Estonia MTR peaked at 1,600+ registered VASPs; total EU pre-MiCA VASP population approximately 2,500-3,000 |
| Post-MiCA reality | Approximately 300-500 EU CASPs authorised as of 2026; substantial contraction from pre-MiCA VASP population |
What VASP licensing was
VASP (Virtual Asset Service Provider) is the term the Financial Action Task Force (FATF) introduced in its 2018 updated guidance on virtual assets. FATF defined VASP as any entity that conducts one or more crypto-asset services: exchange between virtual assets and fiat, exchange between virtual assets, transfer of virtual assets, custody and administration of virtual assets, or financial services related to issuer offerings or sales.
EU member states adopted the FATF definition into their AML/CFT frameworks under the 5th Anti-Money Laundering Directive (5AMLD). The directive required member states to subject crypto-asset service providers to AML/CFT obligations and supervisor oversight. Each member state implemented through national legislation — producing the patchwork of VASP register frameworks that defined EU crypto regulation from 2018 through 2024.
The pre-MiCA frameworks shared common characteristics:
AML-focused. Registration covered AML/CFT obligations under 5AMLD — customer due diligence, suspicious activity reporting, sanctions screening, record retention. The frameworks did not impose prudential capital requirements, conduct-of-business rules, or operational resilience standards.
National scope only. VASP registration in one member state did not produce passport access to other member states. Each operator needed separate registration in each member state where it conducted activity (in theory; in practice many operators relied on home-state registration plus cross-border services arrangements that varied by member state interpretation).
Variable supervisor intensity. Estonia and Lithuania applied lighter-touch registration with broad licensee populations. Finland, Netherlands, and Latvia applied more selective registration with substantive AML scrutiny. The intensity varied across the framework producing different operational realities in different member states.
Lower substance bar than MiCA CASP. Most pre-MiCA VASP frameworks accepted skeletal substance — non-resident senior management and corporate-services-provider addresses, with minimal in-jurisdiction operational presence. The exceptions (Finland, Netherlands) applied more demanding substance expectations even at registration phase.
The major pre-MiCA VASP frameworks
Estonia MTR register. Established 2017 under the Money Laundering and Terrorism Financing Prevention Act. The largest pre-MiCA VASP framework — at peak around 1,600 registered providers. Several enforcement scandals through 2019-2022 produced reputational damage and progressive policy tightening. By 2024 the register had contracted to under 100 active providers as the supervisor revoked registrations and operators exited.
Lithuania VASP register. Established 2020 under amendments to the Law on Prevention of Money Laundering and Terrorist Financing. Substantial population — peaked around 500-600 registered VASPs. More selective than Estonia from inception, with progressive substance tightening through 2022-2024.
Czech Republic CNB list. Czech National Bank operated the crypto-asset provider list since 2017 under the Czech AML Act. Substantial population around 500-700 registered operators. The framework was lighter than Lithuania or Finland with corresponding regulatory dynamics.
Latvia FCMC register. Smaller AML-registration framework under the Finance and Capital Market Commission. Limited registered population, limited enforcement history. The 2023 integration reform consolidated FCMC into Latvijas Banka producing a single integrated supervisor.
Finland Fin-FSA register. Established 2019 under the Act on the Provision of Virtual Currency Services. Selective framework with substantive AML and operational expectations — approximately 15-25 registered operators at peak. The Finnish framework produced more demanding registration than larger registers but smaller population.
Netherlands DNB register. Established November 2020 under amendments to the Dutch Money Laundering and Terrorist Financing Prevention Act. Approximately 30-50 registered VASPs at peak. DNB applied substantive substance and AML expectations producing a more selective registered population.
Other member states. Most other EU member states operated lighter pre-MiCA frameworks or had not implemented dedicated VASP registration before MiCA took effect. The pattern was inconsistent across the 27-member-state landscape.
What MiCA replaces and how
MiCA Regulation (EU) 2023/1114 introduced unified CASP authorisation across all 27 EU member states. The framework differs from pre-MiCA VASP registration in multiple dimensions:
Full multi-dimensional supervision. MiCA CASP authorisation covers prudential capital requirements (Article 67), conduct of business rules (Articles 66-82), AML obligations integrated with the broader Anti-Money Laundering Regulation (AMLR), ICT operational resilience under DORA, customer asset protection (Articles 70 and 75), and ongoing supervisor engagement under each national competent authority.
EU passport. CASP authorisation in one EU member state produces operational rights across all 27 member states under Article 65 passporting. The single market access transforms the operator’s cross-border capability compared to fragmented national VASP registration.
Substantive substance requirements. MiCA CASP authorisation requires substantive entity presence, named resident senior management, dedicated compliance and AML teams, real operational infrastructure. The substance bar is consistent across member states (varying somewhat by national supervisor temperament) and is materially higher than pre-MiCA VASP norms in most member states.
Categorised by service set. MiCA distinguishes Class 1 (advisory and limited services), Class 2 (operational services), and Class 3 (trading platform operations and substantial custody). Capital requirements scale with class — EUR 50,000 for Class 1, EUR 125,000 for Class 2, EUR 150,000 for Class 3 under Annex IV. The class system produces proportionate regulation matching activity scope.
The cleanest way to see the shift is to put the two frameworks side by side. Every row is a step up — CASP is not “VASP, renamed”:
| Dimension | VASP (pre-MiCA) | CASP (under MiCA) |
|---|---|---|
| Legal nature | National AML/CFT registration | EU financial-services authorisation |
| Legal basis | National transposition of EU AML Directives (5AMLD) | MiCA Regulation (EU) 2023/1114 |
| Geographic reach | National only | Passportable across all 27 EU states |
| Capital requirement | Typically none or minimal | EUR 50,000 / 125,000 / 150,000 (Annex IV) + ongoing |
| Governance supervision | Light | Full — management body suitability, conflicts |
| ICT resilience | Not a focus | DORA applies |
| Conduct rules | Minimal | Complaints, marketing, custody, best execution |
| Market abuse | Not covered | MiCA Title VI applies |
| Supervisory intensity | Administrative | Financial-institution-grade |
That table is also the source of the most common framing error we see. A founder who carries a VASP-era mental model into a CASP project under-scopes everything — the capital, the governance, the timeline, the cost, the supervisory depth. The vocabulary confusion (treating “VASP” and “CASP” as two names for one thing) leads directly to under-budgeted projects. And the regulators have not been quiet about the size of the jump.
Cited expert
MiCA represents a breakthrough for the regulation of crypto-assets.
The Article 143 transitional regime and the 1 July 2026 deadline
MiCA Article 143 provides a transitional regime for pre-MiCA VASP-registered operators. The regime allows existing VASP-registered operators to continue activities under MiCA-applicable rules during a defined transitional window without immediate CASP authorisation requirement.
Key features:
Effective date. MiCA CASP authorisation provisions came into effect 30 December 2024. The transitional regime started running from that date for operators registered under pre-MiCA VASP frameworks as of the effective date.
Maximum transitional window. The regime runs until 1 July 2026 maximum — eighteen months from MiCA effective date. Member states could elect shorter transitional windows in their national MiCA implementing legislation.
Member state-specific deadlines. Several member states have implemented transitional windows shorter than 18 months. The actual deadline varies by member state. Lithuania set 1 July 2026, Czech Republic set 1 July 2026, Estonia set earlier deadlines. Operators must verify the specific deadline in their home member state.
Migration obligation. During the transitional window, operators must apply for full MiCA CASP authorisation and have authorisation granted before the deadline. Failure to obtain authorisation by the deadline requires the operator to cease EU customer operations or face enforcement under Article 59 unauthorised-operation provisions.
Continued AML obligations. During the transitional window, operators continue under their existing VASP AML framework alongside developing MiCA CASP framework. The dual obligation period is operationally complex but is the bridge structure between regimes.
Three eligibility tests gate the regime. As of 30 December 2024 the firm had to (1) hold a national VASP registration or equivalent permission, (2) be actively providing crypto-asset services (not dormant), and (3) be in good standing — not suspended or revoked. Firms that registered after 30 December 2024 do not qualify; they are treated as new entrants and apply directly under MiCA’s application-content rule. The exact list of qualifying VASP regimes per member state is set out in ESMA’s Q&A on MiCA transitional provisions — counsel should check it for the target member state, because there are non-obvious exclusions, including some Czech Trade Licensing Office sub-categories ESMA has clarified do not count as VASP registrations.
Member-state deadlines vary — check ESMA’s grandfathering list
The 1 July 2026 default is a maximum, not a fixed date everywhere. Article 143 let member states shorten the window or disapply the transitional regime entirely; it did not let them extend beyond the 18-month default. So the actual deadline is set per member state, and getting it wrong is the most expensive mistake in the whole transition. Per ESMA’s list of grandfathering periods under Article 143(3):
| Member state | Deadline | Notes |
|---|---|---|
| Lithuania | 1 July 2026 | Default; Bank of Lithuania actively processing |
| Estonia | 1 July 2026 | Finantsinspektsioon applying full substance review to transitional files |
| Czech Republic | 1 July 2026 | Transitioned from Trade Licensing Office to ČNB January 2026 |
| Poland | 1 July 2026 | KNF backlog significant; deadline pressure expected |
| Bulgaria | 1 July 2026 | Default; smaller market |
| Cyprus | 1 July 2026 | CySEC integration of crypto-asset oversight ongoing |
| France | 1 July 2026 | AMF maintaining default for former PSAN registrants |
| Netherlands | 30 June 2025 (already passed) | 6-month window; DNB shortened |
| Germany | 30 December 2025 (already passed) | 12-month window; BaFin crypto-custody licensees |
| Ireland | 30 December 2025 (already passed) | 12-month window |
| Italy | 30 December 2026 | Extended domestic window; CONSOB capacity-building |
| Spain | 30 December 2026 | Extended domestic window |
The longer windows in Spain and Italy reflect regulator capacity, not a softer substance review. Firms that moved an application to Spain or Italy purely to buy time typically found the substance review at least as rigorous as in the default-deadline states. One more constraint worth stating plainly: the transitional filing must go to the member state where the firm already holds its VASP registration. A VASP registered in Estonia files with Finantsinspektsioon. Migrating to a different member state means a fresh new-entrant CASP application in the target state, not a transitional filing.
Practical migration realities
The migration from VASP to MiCA CASP is more demanding than many pre-MiCA operators anticipated. Common migration issues:
Substance uplift. Many pre-MiCA VASP operators built thin substance under the lighter pre-MiCA framework. MiCA CASP substance requirements demand named resident senior management, dedicated compliance and AML teams, real operational infrastructure. The substance build is real and runs months of preparation.
Capital reset. MiCA Annex IV minimum capital (EUR 50,000-150,000) is consistent across member states but is meaningfully higher than some pre-MiCA frameworks required at registration phase. Operators that capitalised at pre-MiCA-minimum levels need capital top-up before CASP authorisation.
Senior management fitness-and-properness review. MiCA fitness-and-properness review extends beyond AML competence into full senior-management substance assessment. Pre-MiCA senior management with limited industry experience or adverse regulatory history face material review challenges.
ICT and DORA framework. MiCA CASP authorisation requires DORA-aligned ICT operational resilience framework. Pre-MiCA VASPs typically had not built DORA-equivalent infrastructure. The DORA build is one of the most-time-intensive migration workstreams.
AML programme uplift. Pre-MiCA VASP AML programmes typically met 5AMLD baseline. MiCA-era AML expectations align with AMLR and MLD6 standards, including enhanced customer due-diligence and more detailed transaction monitoring, plus integration with the future EU FIU framework. Programme uplift is needed for most migrating operators.
The migration cost typically runs EUR 200,000-500,000 for a mid-tier operator including legal advisory, substance build, capital top-up, and system implementation. Operators that planned migration starting late 2024 are typically in the latter stages by mid-2026. Operators that delayed migration planning face the 1 July 2026 deadline with insufficient runway and material risk of operations cessation.
The transitional dossier is not a lighter file. It is the full new-entrant application-content set — there is no abbreviated version — and under MiCA that includes the programme of operations, internal-control and risk-management description, DORA-aligned ICT risk-management framework, governance arrangements with a conflict-of-interest matrix, fit-and-proper documentation for directors and qualifying shareholders, initial-capital evidence, professional-indemnity insurance or additional own funds, client-asset segregation and a recovery plan for Class 3, a marketing-communications policy, and a complaints-handling procedure. Transitional applicants face three extra disclosures on top: the existing VASP registration certificate, an operating-history summary (usually three years), and a material-changes statement. Regulators use that “material changes” line to spot firms whose model has drifted from the basis on which the original registration was granted — expand or pivot materially and expect heightened scrutiny.
On timing, the honest advice is unglamorous: file as soon as the dossier is genuinely complete. Filing on 30 December 2024 was mostly impossible because the portals were not ready; Q1 2025 was difficult because supervisors were still building capacity; volumes ramped through 2025 and peaked in Q4 2025 and Q1 2026. Files arriving in May and June 2026 hit a different, more congested regulator than files that arrived in November 2025 — slower completeness checks (5-15 days versus 5) and heavier first-round information requests, adding longer iteration cycles between deficiency rounds. The optionality of holding back to squeeze out a few more months of pre-MiCA revenue loses value fast as the deadline approaches.
What to do after the transitional period ends
The transitional window closed on 1 July 2026 in most member states (earlier where the NCA shortened it). After the deadline, the population of crypto-asset service providers in the EU splits into four groups, and your group decides what you can legally do.
Authorised CASPs. Operators with a granted MiCA Article 59 authorisation run under the full framework. Most early movers (firms that applied in 2024-2025 in well-resourced jurisdictions) sit here. Roughly 200-300 CASPs across the EU held granted authorisation by mid-2026.
Applications under active review. Operators whose substantive application was still under NCA review at the deadline operate under supervisory discretion. Most NCAs permit continued operation where the file is substantive and progressing, and have communicated grace policies to that effect. But the discretion is real — stalled applications, repeated information-request failures, or governance concerns raise the risk of the NCA withdrawing that discretionary cover. Treating grace as guaranteed is a mistake.
Late or post-deadline applicants. Missing the deadline does not bar a fresh application — but the firm must cease EU customer-facing operations during review and cannot rely on transitional cover. There is no extension mechanism for late filers. A missed transition typically adds a 5-7 month new-entrant timeline on top of the time already burned. Some operators keep serving non-EU customers from outside the bloc while they reapply; whether that works depends entirely on customer geography.
Service cessation. Operators who cannot or will not migrate have to wind down EU customer relationships: returning crypto-assets and closing fiat balances before terminating ongoing contracts. For a non-trivial customer base that is a 60-120 day process minimum, and deferring the planning until cessation is imminent produces operational chaos and avoidable customer-protection liability.
One obligation outlives the licence. Operators ceasing EU operations stay subject to AML record-keeping for customer data and transaction history — typically five years from the end of each customer relationship under the AMLR. Those records cannot be destroyed at cessation; the firm has to maintain them and keep access procedures running through the retention period. Several operators under-budgeted exactly this.
The Estonia and Lithuania VASP-sunset migration
Estonia and Lithuania built the two largest pre-MiCA VASP populations in the EU, so their sunsets are the clearest worked example of how migration actually played out. Both adopted the 18-month default window (30 December 2024 to 1 July 2026) and both came out of it with far smaller, more heavily supervised operator populations.
Estonia. The Money-Laundering Registration (MTR) framework, run by the Estonian FIU under the Money Laundering Prevention Act, peaked at 600+ registered entities in 2019 — the largest EU VASP register by count. Estonia’s 2020 tightening (capital and substance requirements) cut the active population to roughly 200 by 2022, and it held near there to MiCA application date. Finantsinspektsioon took over as the MiCA competent authority and ran the transition in three phases: guidance and early-mover applications in Q4 2024-Q1 2025; a bulk-migration phase in Q2-Q3 2025 where DORA, governance, and conduct documentation drew the most information requests; and a late-migration-and-rejection phase through Q4 2025-Q2 2026 where delayed, smaller operators hit capacity limits and several were refused on substance grounds. By the deadline, roughly 100-120 Estonian-domiciled operators held granted CASP authorisation — about half the pre-MiCA population. Most exits were economic, not refusals: the substance build was uneconomic at small scale.
Lithuania. The VASP register — administered by the Centre of Registers and the Bank of Lithuania, with AML supervision by the FCIS — hosted roughly 200-250 active operators at MiCA application date, skewed toward larger international operations using Lithuania as an EU base. The Bank of Lithuania (Lietuvos Bankas) had been building MiCA capacity since 2023 and entered the transition with more processing headroom than Estonia. It also applied banking-grade rigour: letterbox arrangements common in the pre-MiCA register did not survive MiCA review, and several operators received substance findings that forced restructuring. By the deadline, roughly 80-100 Lithuanian-domiciled operators held granted CASP authorisation. Some operators consolidated into Ireland, the Netherlands, or Malta rather than continue under the Bank of Lithuania’s heavier supervisory style.
The substance gap drove everything. Pre-MiCA Estonian MTR (post-2020) asked for EUR 100k minimum capital, an Estonian-resident director, a registered office, and an outsourceable AML/MLRO function. MiCA CASP under Finantsinspektsioon asks for prudential capital aligned with Article 67 (EUR 50k/125k/150k by class plus 25% of annual fixed overhead), substantive board composition and key-person fit-and-proper, a DORA-aligned ICT framework, a conduct-of-business framework, recovery and resolution arrangements under Article 84, real in-Estonia operational presence, and a three-year financial plan. The Lithuanian gap was comparable. Migration ran EUR 100-250k in the first year for a mid-tier operator in either jurisdiction, against a pre-MiCA all-in cost of EUR 5-20k — and that step-change is what pushed several hundred Baltic operators out.
For new entrants choosing between the two today: both are credible mid-tier MiCA jurisdictions whose passports carry identical EU-wide rights — MiCA passporting is jurisdiction-neutral. The choice comes down to operational fit. Estonia offers Tallinn cost efficiency, an English-language operational reality, Finantsinspektsioon’s efficient and directly-engaged style, and a 0% tax on retained earnings (20% on distribution). Lithuania offers the Vilnius financial-services ecosystem, banking-grade supervisory reputation, and a flat 15% corporate rate — at higher first-year cost (EUR 150-300k versus Estonia’s EUR 100-200k) and heavier, multi-round supervisory engagement. Neither runs a low-substance regime any more, whatever the pre-MiCA reputation suggested.
Current state of the EU CASP population
The pre-MiCA VASP population was approximately 2,500-3,000 registered operators across all EU member states. The post-MiCA CASP population in 2026 is materially smaller — approximately 300-500 authorised CASPs across the 27 member states.
The contraction reflects:
Voluntary exit. Many pre-MiCA operators exited rather than migrate. The cost-benefit analysis favoured exit for low-scale operators, and for those carrying serious substance gaps or reputational concerns from pre-MiCA enforcement history.
Migration failure. Some operators commenced migration but failed to complete authorisation in the transitional window — typically due to substance gaps, AML programme deficiencies, or fitness-and-properness concerns.
Selective member-state distribution. The post-MiCA authorised CASP population concentrates in fewer member states than the pre-MiCA register population — Lithuania, Czech Republic, Netherlands, and Cyprus host substantial CASP populations, while many smaller pre-MiCA registers have minimal post-MiCA presence.
The result is a tighter, more substantively-regulated EU crypto operator population than the pre-MiCA framework produced. Quality up, quantity down.
Practical takeaways
VASP licensing is an artefact of the pre-MiCA regulatory era. The framework was AML-focused and fragmented across member states, and it produced highly variable substance and supervisor intensity. MiCA’s CASP authorisation replaces it with unified, substantively-supervised EU regulation.
Three principles for operators thinking about the VASP-to-CASP transition:
Treat VASP and CASP as different products. They are not interchangeable terms. Marketing materials, consultant pitches, or strategy materials that conflate the two misrepresent regulatory reality. CASP is materially more demanding and materially more valuable.
Plan migration with real timeline buffer. The 1 July 2026 maximum transitional deadline is firm. CASP authorisation typically runs 6-12 months. Operators starting migration late risk operational cessation. Migration planning that started late 2024 or early 2025 has appropriate buffer; migration starting in 2026 is too late for clean transition.
Use the migration as an opportunity to build real compliance infrastructure. The substance investment, capital top-up, AML uplift, and DORA framework build that MiCA requires produce operational infrastructure with long-term value. Operators that build for compliance produce stronger operations than the pre-MiCA framework demanded.
For corrections, updates, or counsel referrals on VASP-to-CASP migration, email [email protected].
Pitfalls and nuances
1 Treating VASP and CASP as interchangeable terms
VASP and CASP are different regulatory frameworks with different scope. VASP was AML-only national registration; CASP is full multi-dimensional EU authorisation. Marketing materials or consultant pitches that use VASP and CASP interchangeably misrepresent the operational reality. CASP authorisation is materially more demanding and produces materially broader rights.
2 Underestimating the substance gap between VASP and CASP frameworks
Many pre-MiCA VASP operators had skeletal substance — corporate-services-provider addresses, non-resident senior management, minimal in-jurisdiction operational presence. MiCA CASP substance expectations are real and verifiable. The migration from VASP to CASP requires substantive substance build that catches operators that assumed continuity from light-touch VASP norms.
3 Missing the 1 July 2026 transitional deadline
MiCA Article 143 transitional regime ends 1 July 2026 maximum for VASP-register operators. Some member states have already shortened the transitional window. Operators relying on the transitional regime need to file CASP authorisation early enough for grant before the deadline — typical CASP timelines are 6-12 months, so filing late 2025 is the latest safe window.
4 Confusing VASP framework with general crypto-asset regulation
VASP framework was narrow — AML registration of specific service providers. It did not regulate crypto-asset issuance, secondary trading, or broader market activity. Operators planning issuance or market-making activity need MiCA Title III (ART), Title IV (EMT), or Title V (CASP) authorisation, not just VASP-style AML registration.
Frequently asked questions
What is a VASP licence?
VASP (Virtual Asset Service Provider) licence is the pre-MiCA EU crypto-asset registration under 5AMLD national implementations.
Is VASP licensing still available?
Not for new applicants in most EU member states. MiCA Regulation (EU) 2023/1114 transitioned the EU crypto framework from VASP registration to CASP authorisation effective 30 December 2024.
What is the difference between VASP and CASP licensing?
VASP was AML-only registration under national 5AMLD frameworks. CASP is full authorisation under MiCA covering prudential capital, conduct of business, AML, ICT operational resilience, customer asset protection, and ongoing supervisor engagement.
What happens to existing VASP-registered operators?
Under MiCA Article 143 transitional regime, existing VASP register operators can continue operations until 1 July 2026 maximum. To continue operating after the deadline, they need full MiCA CASP authorisation.
Can I still get an Estonian or Lithuanian VASP licence in 2026?
No. Estonian MTR registration and Lithuanian VASP registration are no longer accepting new applicants. The EU framework requires full MiCA CASP authorisation under Articles 59 and 63.
Get matched
Working through a crypto-licensing decision?
Get an editorial shortlist of firms matched to your business — customer market, model, jurisdiction, and stage. Free, and not influenced by sponsorship.
Get a firm shortlist →Sources cited
- Regulation (EU) 2023/1114 (MiCA), Article 143 transitional regime — regulation
- Directive (EU) 2018/843 (5AMLD) — the basis of national VASP registers — regulation
- FATF — Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — regulator
- ESMA — MiCA Implementation and Transitional Regime Guidance — regulator
- ESMA list of MiCA grandfathering periods under Article 143(3) — official document
- Bank of Lithuania — MiCA crypto-asset service providers — regulator
- Estonian Financial Supervisory Authority (Finantsinspektsioon) — regulator