Malta · MFSA · Class 3 substance

Malta MFSA Class 3 CASP Substance: The Strictest Bar in the EU

Maltese supervisory practice in 2025-2026 makes the position explicit — the MFSA does not see functional separation of MLRO and Compliance Officer as optional for above-threshold Class 3 CASPs. This is the substance file the regulator actually wants to see.

Valletta harbour — Malta MFSA CASP licensing jurisdiction

Malta MFSA Class 3 substance is the set of governance and headcount expectations applied by the Malta Financial Services Authority to crypto-asset service providers seeking authorisation under the CASP authorisation requirement MiCA for the highest-risk class of services — custody, exchange, and operation of trading platforms — under which the MFSA requires functional separation of the MLRO from the Compliance Officer, full-time engagement of both, and Malta-resident senior management.

Quick facts

ParameterValue
RegulatorMalta Financial Services Authority (MFSA)
Class 3 minimum capital€150,000 (MiCA floor) — practical reserve €250,000+
MLRO / Compliance OfficerMust be separate persons; both full-time; Malta-resident
Senior managementTwo Malta-resident senior managers; CEO Malta-resident; board majority EU/EEA
Timeline6-9 months from complete application (longest in active EU jurisdictions)
Small-firm threshold (practitioner-reported)approx. <€25M annual revenue and <€100M client custody — combined role acceptable below; precise threshold determined by MFSA on a per-file basis
DORA expectationsFull regime; named third-party ICT provider risk-treatment register

Why Malta is the strictest substance bar in the EU

The MFSA’s substance posture sits at the strict end of the EU spectrum, alongside Ireland — but Malta is uniquely strict on functional separation of the MLRO and Compliance Officer. No other EU regulator reads the requirement as a mandatory precondition for Class 3 authorisation as far as practitioner-reported file experience is documented in 2025-2026; the MFSA does.

The position is rooted in the MFSA’s reading of the CASP authorisation requirement MiCA together with EBA-level AML/CFT guidance — both, in the MFSA’s view, contemplate an AML reporting function that is structurally independent of the broader compliance function. Combining the roles, the supervisor argues, compromises the escalation channel for suspicious-transaction reporting because a combined officer reports to themselves on issues that should escalate independently to the board and the Financial Intelligence Analysis Unit (FIAU).

Whether the legal basis is bullet-proof is a separate question. What matters for an applicant is that the MFSA treats combined role allocation in above-threshold Class 3 files as a substantive deficiency, and is unlikely to soften the position before formal ESA-level guidance forces a change. Plan to the strict reading.

How does the small-firm threshold work?

The MFSA in practice distinguishes smaller firms from larger ones, with practitioner-reported thresholds typically in the order of €25M annual revenue and €100M client custody (the precise figures are set out in supervisory correspondence on a file-by-file basis). Below the threshold, combined MLRO/Compliance Officer roles are acceptable provided the firm documents a succession plan for splitting the roles as it grows. Above the threshold, separation is the supervisory expectation.

The threshold is checked at application and re-tested annually. A firm that crosses the threshold mid-year is expected to file a notification within 30 days and effect the role split within 90 days. Failure to do either is a supervisory finding.

In practice, applicants in our advisory conversations land in three groups:

  • Clear small firms (advisory or low-volume Class 1) — combined role acceptable, low friction
  • Edge cases (early-stage Class 2/3 with growth ambition) — separation recommended even at authorisation, to avoid mid-year transition friction
  • Clear large firms (Class 3 with custody balance projection above €100M) — separation mandatory, no flexibility

The middle group is where most cost-optimisation discussions happen with counsel.

Malta substance vs Estonia substance

Both jurisdictions are at the strict end of the EU spectrum but they emphasise different things:

Substance dimensionMalta MFSAEstonia FSA
Resident senior management2 Malta-resident, CEO Malta-resident1 resident director
MLROFull-time, Malta-resident, separated from Compliance0.5 FTE+, Estonia-resident, can combine with Compliance
Compliance OfficerFull-time, Malta-resident, separated from MLRO0.5 FTE+, can combine with MLRO
Board compositionEU/EEA majorityNo formal composition rule
Local registered officeRequired, no virtual addressRequired
Local staff (operations)Documented headcount expectedEncouraged, not strictly required
Substance interviewYes, 45 min per roleYes, 30-60 min per role

The aggregate cost differential is significant. A Class 3 Maltese establishment carries a salaried-headcount floor around €350,000 per year before commercial activity; an Estonian establishment can run on around €200,000. For applicants choosing between the two, the Maltese reputation premium has to justify the cost differential.

Why does Malta still attract Class 3 applicants?

Despite being the strictest substance bar, Malta retains commercial attractiveness for two reasons:

  1. Established VFA-Act practice. Malta has had a domestic crypto-services regime since 2018. The pool of local counsel and consultancy with practical experience is the deepest in the EU. For complex applications involving cross-border structuring, the Malta practice base is hard to replicate elsewhere.

  2. English-language regulator. All MFSA correspondence, supervisory engagement, and formal filings are in English. For non-EU founders, this materially reduces translation and counsel-coordination cost. Estonia operates similarly bilingually but Czech Republic and Lithuania expect local-language correspondence.

  3. Banking access. Counter-intuitively, Maltese authorised CASPs have better domestic banking access than Cyprus or Estonia counterparts. Two Malta-domiciled banks accept CASP onboarding post-authorisation with documented governance. This is a meaningful operational advantage that offsets the higher establishment cost.

What does the MFSA actually look for in a CASP file?

The the own-funds requirement governance file is where most 2026 applications consume time. The MFSA’s reviewers ask three implicit questions of every page:

  1. Is the documented arrangement specific to this firm’s business model, or generic?
  2. Are roles, responsibilities, and escalation triggers concrete enough to test?
  3. Does the firm understand its own crypto-specific risk profile?

The fastest way to fail is template language — Big Four-style governance documents that read identically regardless of business model. The MFSA reviewers see hundreds of these and recognise them immediately. The file that succeeds reads like the firm’s own thinking, with specific examples drawn from the proposed operating model.

Working with counsel on a Malta Class 3 file

The diagnostic question for counsel: how many MFSA Class 3 applications has the firm processed since March 2026? Practice that pre-dates the implementing procedures is partial — the substance bar moved materially in early 2026. Counsel without recent files is still calibrating. The firms in our index with documented Malta CASP track record are listed below.

Pitfalls and nuances

1 Combining MLRO and Compliance Officer in a Class 3 file

Practitioner experience with MFSA in 2025-2026 indicates that combined role allocation in firms above the small-firm threshold is treated as a substantive deficiency. Even with experienced individuals, the MFSA reads the CASP authorisation requirement as requiring functional independence. Plan to the separated structure from day one if growth is plausible.

2 Importing the Maltese VFA-Act framework directly

Many applicants reuse VFA-Act-era documentation. The MFSA expects MiCA-shaped the own-funds requirement governance arrangements with crypto-specific risk treatment, not VFA-Act language. Recycled VFA files trigger long information-request rounds.

3 Underestimating Malta-resident headcount cost

Two Malta-resident senior managers plus separated MLRO and Compliance Officer plus support staff — the salaried headcount floor is ~€350K per year before any commercial activity. Cost-conscious applicants under-budget.

4 Light DORA documentation

MFSA reviewers explicitly require named third-party ICT providers with concrete risk treatments per provider. Generic DORA plans referencing 'cloud providers' and 'security tooling' without naming specific contractual counterparties are returned for revision.

5 Missing succession plan for the small-firm threshold transition

Firms close to the small-firm threshold need a documented plan for splitting the MLRO/Compliance roles before crossing it. The MFSA asks for this plan even at small-firm authorisation; absence is a deficiency.

Frequently asked questions

Why does Malta require separated MLRO and Compliance Officer roles?

MFSA reads the CASP authorisation requirement MiCA together with EBA AML guidelines as requiring functional independence of the AML reporting function — combining roles undermines the supervisory escalation channel for STR escalation.

Can a smaller firm combine the roles in Malta?

Yes — firms below the small-firm threshold of €25M revenue and €100M client custody may combine roles, with documented succession planning for separation as the firm grows.

How is Malta substance different from Ireland?

Ireland requires full-time MLRO with banking-grade experience; Malta requires the same plus separated Compliance Officer. Malta is the only EU jurisdiction with mandatory functional separation.

What does an MFSA substance interview look like?

Forty-five minutes per senior manager and per MLRO. The interviewer probes day-to-day responsibilities, escalation triggers, and the specific business model — generic answers fail.

Get matched

Working through a crypto-licensing decision?

Get an editorial shortlist of firms matched to your business — customer market, model, jurisdiction, and stage. Free, and not influenced by sponsorship.

Get a firm shortlist →

Sources cited

  1. Regulation (EU) 2023/1114 (MiCA), Article 59 and Article 67 — regulation
  2. MFSA Crypto-Asset Services Provider authorisation page — regulator
  3. MFSA MiCA Rulebook (March 2025) — regulator
  4. EBA Guidelines on AML/CFT compliance officers — regulator