MiCA · CASP operations & lifecycle

CASP Operations and Lifecycle 2026 — MiCA Passport, Banking, Wind-Down

Authorisation is the start, not the finish. Running a MiCA-authorised CASP means making the Article 65 passport work cross-border, securing banking, keeping the management body fit and proper, structuring outsourcing, holding records under Article 68, staffing the MLRO and compliance function, operating KYC, and planning for wind-down and resolution. This pillar walks the full operational lifecycle, with the passport as its spine.

CASP operations and lifecycle is the set of post-authorisation obligations a MiCA-authorised crypto-asset service provider runs in practice — exercising the Article 65 cross-border passport, securing operating and client-money banking, satisfying management-body fit-and-proper tests, structuring outsourcing under Article 73, keeping records under Article 68, staffing the MLRO and compliance function, operating KYC and ongoing monitoring, and maintaining wind-down and recovery-and-resolution plans under Article 84.

Quick facts

ParameterValue
Legal basisMiCA Regulation (EU) 2023/1114 Article 65
Passport mechanicHome-state NCA notifies host-state NCA(s); host-state NCAs cannot impose additional authorisation requirements
Notification timingHome-state NCA notifies within 10 working days of receiving complete operator notification; host-state can begin within 15 working days of notification
Operational status (mid-2026)Substantive cross-border passport activity established across EU; substantive home-state vs host-state coordination patterns developed
Host-state powers retainedConsumer-protection enforcement, host-state language requirements (typically marketing), local-investor protection measures, AML cooperation
Common passport servicing patternsCross-border online services without local presence; cross-border services with local marketing partnerships; cross-border services with local advisory partnerships
Related provisionsArticle 63 (initial authorisation), Article 64 (withdrawal), Article 95 (supervisory cooperation)
Banking requirementClient funds must be safeguarded at an EEA-authorised credit institution or central bank, segregated from CASP assets; an EMI partner can hold operating funds provided the chain ends at a bank
Fit-and-proper scopeManagement body (individually and collectively) and persons behind qualifying holdings are assessed for good repute, knowledge and experience, integrity, and time commitment
Outsourcing (Article 73)Operational and ICT functions can be outsourced; senior-management responsibility cannot; ICT outsourcing also triggers DORA Articles 28-30 register and risk-management obligations
Wind-down and resolution (Article 84)Every CASP maintains a recovery plan (reviewed annually) and cooperates on an NCA-owned resolution plan; customer-asset segregation and transferability is the central variable

Authorisation gets a CASP to the starting line. What follows is an operational lifecycle: making the cross-border passport work, securing banking, keeping the management body fit and proper, structuring outsourcing, holding records, staffing the MLRO and compliance function, running KYC, and eventually winding down. The Article 65 passport is the spine of this pillar because it is where most operators first feel the gap between the clean framework and operational reality, but the same gap recurs across every workstream below. The sections that follow walk the lifecycle in turn.

What 18 months of passport experience reveals

MiCA CASP passport went operational with MiCA application date 30 December 2024. By mid-2026, substantive cross-border passport activity has been established across the EU. The framework substantively works — operators authorised in one member state successfully service customers across the EU without separate host-state authorisations.

But operational realities differ from the clean Article 65 framework. Host-state NCAs maintain substantive engagement. Notification mechanics matter operationally. And the passport works substantively differently for different service types. Operators that planned for theoretical Article 65 framework face substantive operational gaps; operators that planned for actual cross-border operational reality face substantively better outcomes.

The substantive operational pattern through 2025-2026:

Passport works as intended for cross-border online services — operators providing custody and exchange services (and trading-platform services) from substantive single-jurisdiction operational base to customers across the EU. Framework substantively delivers regulatory simplification.

Host-state engagement persists for consumer-protection — host-state NCAs maintain substantive engagement on consumer-protection enforcement and marketing-conduct requirements, along with complaint-handling expectations. Substantive operator infrastructure required for major passport markets.

Language requirements substantive in some markets — host-state language requirements for consumer-facing materials substantial in France, Germany, Italy, Spain, Poland. Operators serving substantial customer base in these markets need substantive local-language infrastructure.

AML cooperation substantive across all passport markets — substantive AML cooperation with host-state FIUs and AML supervisory authorities, together with law-enforcement cooperation across all passport markets. Standard infrastructure across the EU.

Service-type variations material — different MiCA services have substantively different passport-operational reality. Custody passport substantively cleaner than advisory passport. Trading-platform passport substantively more complex than exchange passport.

The notification mechanics — what actually happens

Article 65 notification framework on paper:

  • Operator notifies home-state NCA of intent to passport services to host-state(s)
  • Home-state NCA validates notification, transmits to host-state NCA(s) within 10 working days
  • Host-state CASP servicing can begin within 15 working days of notification

In practice through 2025-2026, the substantive mechanics:

Substantive home-state validation engagement — home-state NCA typically engages substantively with operator on notification adequacy. Standard notifications complete within 10 working days; complex notifications (multi-service, multiple host-states) can extend to 4-8 weeks.

Substantive host-state engagement post-notification — host-state NCAs typically engage substantively with passporting operator post-notification. Requests for substantive operator information beyond formal notification and substantive engagement on local customer-protection arrangements, as well as substantive interaction on complaint-handling infrastructure.

Substantive operational preparation expected — host-state NCAs expect substantive operator preparation for local servicing: local customer-protection materials and complaint-handling infrastructure, plus substantive operator knowledge of local consumer-protection framework.

Substantive ongoing engagement — host-state engagement isn’t one-time. Ongoing supervisory engagement on substantive consumer-protection matters and marketing-conduct reviews, complaint-handling oversight included.

The practical implication: passport notification is procedural but operators should plan substantive host-state engagement preparation 8-16 weeks before notification, not reactively after.

What works — passport patterns that operationally succeed

Operational patterns demonstrating substantive passport effectiveness through 2025-2026:

Cross-border online services without local presence — operators providing services entirely through online infrastructure without local presence in host-state. Common pattern for custody, exchange, brokerage services. Framework substantively delivers regulatory simplification — operators face home-state primary supervision and host-state consumer-protection engagement, with substantively unified operations.

Cross-border services with local marketing partnerships — operators providing core services from home-state while partnering with local marketing or business-development partners in host-states. Substantial pattern for operators serving substantial customer base in multiple member states. Substantive operational complexity but framework supports the structure.

Cross-border services with local advisory partnerships — for specialised products (advisory services, portfolio management), operators frequently structure with local advisory partners providing substantive customer engagement while core services delivered from home-state CASP. Article 65 framework supports this structure.

Multi-jurisdictional operations with single CASP authorisation — substantial operators with substantive customer base across multiple member states operating under single home-state CASP authorisation rather than multiple national authorisations. Framework substantively delivers operational simplification compared to pre-MiCA national-licence patchwork.

What requires substantive operational work — passport patterns that need preparation

Operational patterns requiring substantive preparation through 2025-2026:

Substantial customer base in single host-state — operators serving substantial customer base in single host-state (Germany, France, Italy, Spain) face substantive host-state operational expectations even without separate authorisation. Local-language infrastructure, substantive local customer-protection materials, substantive complaint-handling infrastructure, substantive host-state regulatory engagement.

Advertising and marketing in host-states — substantive host-state marketing-conduct requirements. Operators with substantive marketing in host-states face substantive engagement on local conduct compliance. Some host-states (notably Spain, France) have heightened marketing-conduct requirements applying substantively to passporting operators.

Trading-platform passport — Article 76 + 82 trading-platform obligations apply substantively across passport markets. Host-state interaction on market-conduct expectations, host-state engagement on consumer-protection arrangements for trading-platform users.

Advisory and portfolio-management services — host-state suitability requirements, host-state customer-protection arrangements for advisory products substantially. Operators frequently structure with local advisory partners to manage host-state expectations.

Service-type variations in passport reality

Different MiCA services have substantively different passport-operational realities:

Custody passport — substantively cleanest passport experience. Custody services largely commodity from passport perspective. Host-state engagement focused on substantive customer-protection arrangements (segregation under Article 75, customer-asset return arrangements). Standard infrastructure across passport markets.

Exchange and execution-of-orders passport — substantively clean for online services. Host-state engagement on best-execution arrangements (Article 80), substantive customer-protection for execution services. Standard infrastructure with substantive customer-protection arrangements.

Trading-platform passport — substantively more complex. Host-state engagement on Article 76 + 82 trading-platform arrangements and market-conduct expectations, alongside substantive customer-protection arrangements for trading-platform users. Operators face substantive host-state engagement on platform-operational arrangements.

Advisory services passport — substantively most complex. Host-state suitability requirements, host-state local-customer arrangements substantial. Many operators structure with local advisory partners managing substantive customer engagement.

Portfolio-management passport — similar to advisory passport in complexity. Substantive host-state engagement on portfolio-management arrangements, substantive customer-protection requirements.

Cross-border supervisory cooperation — Article 95 in practice

Article 95 supervisory-cooperation framework supports passport operations:

Home-state primary supervision — substantive home-state NCA supervision continues regardless of passport scope. Primary supervisory relationship is home-state.

Host-state engagement coordinated through ESMA — substantive coordination through ESMA when host-state engagement requires home-state cooperation or supervisory action.

Joint supervisory actions — substantive cross-border supervisory matters can trigger joint home-state + host-state supervisory action, typically coordinated through ESMA.

Information sharing — substantive ongoing information sharing between home-state and host-state NCAs on supervisory matters affecting passporting operators.

Operator engagement — operators face substantive interaction with both home-state primary supervisor and host-state engagement authorities. Substantive substantive coordination infrastructure required for major operators.

Common operational mistakes and how to avoid them

Through 2025-2026 implementation experience, common operational mistakes include:

Inadequate host-state preparation — operators that prepare for theoretical Article 65 framework face substantive host-state engagement gaps. Substantive operational planning for major passport markets is essential.

Underestimating language requirements — host-state language requirements substantively affect major passport markets. Substantive local-language infrastructure required for substantial customer-base markets.

Inadequate consumer-protection infrastructure — substantive host-state engagement on consumer-protection arrangements. Operators with substantive consumer-protection infrastructure designed for home-state market only face substantive host-state engagement on inadequate arrangements.

Inadequate complaint-handling infrastructure — substantive complaint-handling expectations across passport markets. Substantive infrastructure required including local-language complaint procedures, substantive cross-border complaint coordination.

Underestimating AML cooperation requirements — substantive AML cooperation requirements across passport markets. Substantive infrastructure required including substantive FIU reporting across passport markets, substantive law-enforcement cooperation arrangements.

Banking access — the friction point post-authorisation

A MiCA authorisation answers the supervisory question — is the firm fit, capitalised, and governed to provide crypto-asset services. It does not answer the operational one: which bank holds the operating funds, settles client fiat, and accepts the AML risk of the customer base. Several authorised CASPs in 2025-2026 sat in that gap — licensed by the supervisor, unbanked by every EEA institution they approached, unable to onboard customer fiat flow for months. The friction is structural, not idiosyncratic: EEA banks built their risk frameworks around traditional counterparts, and CASPs sit outside them even when fully licensed.

Two MiCA provisions drive the banking workstream. Under the client-asset safeguarding rule (MiCA Article 70), client funds (fiat received pending a crypto purchase, or fiat held against a pending withdrawal) must be deposited at an EEA-authorised credit institution or central bank, segregated from the CASP’s own assets, identified separately in accounting, and not used for the CASP’s own account. The rule does not prescribe which institution — only that the chain ends at one. Class 3 firms running a trading platform pick up additional operational expectations under the custody and operations rulebook (Article 75). Beyond MiCA itself, the EBA Opinion on the interplay between PSD2 and MiCA (June 2025) sets the supervisory expectation for hybrid arrangements (fiat on/off ramps, customer top-up flows, withdrawal routing) that sit at the PSD2-MiCA boundary.

The banking patterns operating successfully in 2026 fall into four shapes:

  • Direct EEA bank relationship. The cleanest pattern, hardest to obtain — typically a specialist or challenger bank rather than a domestic universal bank, with material lead time for onboarding (months, not weeks).
  • EMI partnership. An electronic money institution holds operating funds and runs the fiat rail, itself safeguarding funds at a credit institution. The practical default for retail-facing Class 2 firms.
  • Banking-as-a-service partner. A BaaS provider holds the regulated authorisation and provides accounts, rails, and (sometimes) safeguarding-grade infrastructure as a service; the CASP integrates by API.
  • Multi-bank redundancy. Mature CASPs hold at least two operating relationships, typically across jurisdictions. After de-banking events hit several authorised CASPs in 2025-2026, redundancy became a planning default rather than an exception — and for Class 3 platforms with institutional flow, effectively a requirement.

CASPs that also issue ARTs (Title III) or EMTs (Title IV) run a second banking workstream entirely. EMT reserve assets must sit in credit-institution deposits, central-bank reserves, or secure low-risk assets; ART reserves must be invested in highly liquid instruments under specific composition, custody, and segregation rules reviewed at authorisation. A hybrid CASP-issuer therefore runs three parallel workstreams (operational, client-fund safeguarding, and reserve-asset) and should plan all three from the start. National supervisors treat the banking arrangement as a credibility signal at authorisation: a documented operating relationship and a documented safeguarding arrangement demonstrate seriousness, and filing without addressing banking is a real deficiency in supervisory practice.

Management body fit and proper — who can run a CASP

A MiCA application is not only a test of the firm; it is a test of the people. Before a national competent authority authorises a CASP, it has to be satisfied the firm will be run soundly — a function of who sits on the management body and who stands behind the firm’s significant shareholdings. Two groups fall in scope: the management body (directors and senior managers, assessed individually and collectively) and qualifying holders (the natural persons behind significant shareholdings or other control). A founder who is both controlling shareholder and CEO is assessed in both capacities.

Suitability for the management body breaks into four assessment areas:

  • Good repute. No record indicating the contrary — relevant criminal history and prior regulatory findings, plus financial-integrity issues such as insolvency or disqualification. Good repute is evidenced through criminal-record certificates and disclosure declarations, not asserted.
  • Knowledge, skills, and experience. Individually as appropriate and collectively as a body, adequate to understand the firm’s activities including its main risks — custody and key-management risk, market-abuse risk on a venue, ICT and operational-resilience risk, and crypto-specific AML typologies.
  • Honesty, integrity, and independence of mind. Sufficient independence to assess and challenge management-body decisions. A board that cannot challenge a dominant founder is a governance weakness supervisors look for.
  • Time commitment. Each member must be able to commit sufficient time. A director on many unrelated boards, or a CEO plainly running other businesses full-time, raises a time-commitment concern — the supervisor expects the arithmetic to add up.

Beyond the individual, the board as a whole must hold adequate knowledge, skills, and experience. A board can be collectively suitable even if no single member covers everything, provided the mix covers the firm’s activities and risks — which makes board composition a design decision at application stage, not an afterthought. Applicants concentrate on directors and frequently under-prepare the qualifying-shareholder assessment: the ownership chain must be transparent to the natural persons at the top, and those persons are assessed for good repute and integrity. Source-of-funds evidence is often required. An opaque structure or a controller who cannot evidence source of funds can stall an application even where the management body is strong. The single most useful principle is to disclose proactively — a disclosed, explained, resolved matter is almost always survivable; the same issue undisclosed and then discovered becomes a credibility problem.

Outsourcing under Article 73 — and the DORA overlay

MiCA Article 73 permits a CASP to use third parties for operational functions, provided the arrangement does not impair the quality of internal control or the supervisor’s ability to monitor compliance. The Article enumerates four conditions: the arrangement must be in writing; the CASP must retain the expertise and resources to evaluate and supervise the outsourced function; the arrangement must not delegate senior-management responsibilities; and the CASP must take steps to avoid undue additional operational risk. The text is short, but the interpretive surface is large, and national supervisors have diverged on the operational reading.

In 2026 supervisory practice, the routinely outsourceable functions are the execution layer: ICT and cloud infrastructure (subject to DORA documentation), custody-tech (Fireblocks, Copper, Anchorage), exchange-tech, KYC verification (Sumsub, Onfido, Veriff), AML transaction monitoring and chain analytics (Chainalysis, Elliptic, TRM Labs), sanctions screening (World-Check, ComplyAdvantage), customer support, accounting, and back-office reconciliation. What cannot be outsourced is the decision and oversight layer: senior-management decision-making, risk-management oversight, compliance oversight, the MLRO function (with narrow exceptions, see below), and internal-audit oversight (the audit can be performed externally, but engaging, reviewing, and escalating findings stays in-house). The boundary test in every case is whether the CASP retains the authority to direct the function and the capability to evaluate its output — a KYC provider the CASP cannot meaningfully evaluate is over-outsourced even if the contract is technically Article-73-compliant.

The MLRO function is the most-debated edge case. Cyprus accepts MLRO outsourcing for small firms (typically below EUR 5M revenue and EUR 25M custody) with documented escalation paths to a CySEC-registered AML services firm; Lithuania accepts narrow outsourcing of support functions but requires a resident in-house MLRO; Estonia, Malta, and Ireland expect an in-house function with no outsourcing; and the Czech Republic formally permits outsourcing but ČNB practice has narrowed acceptability since 2024. For a multi-jurisdiction firm passporting from a permissive home to a strict host, the realistic answer is to plan to the strictest jurisdiction — in-house MLRO from day one.

For any ICT outsourcing, DORA Articles 28-30 layer additional requirements on top of Article 73. Article 28 requires a register of all ICT third-party providers, with categorisation and criticality classification, plus contract summaries available to the supervisor. Article 29 requires a documented ICT third-party risk-management framework covering selection, monitoring, concentration risk, and per-provider exit planning. Article 30 governs the designation of critical ICT third-party providers (CTPPs) — providers serving multiple regulated firms whose failure could create systemic risk, subject to EU-level oversight by a Lead Overseer; major cloud providers (AWS, Microsoft Azure, Google Cloud) are expected to be designated. The most common 2026 supervisory deficiency in ICT-outsourcing reviews is an incomplete register — many CASPs cover cloud and custody-tech but omit KYC vendors and AML tooling (and chain analytics). A clean file pairs a board-approved outsourcing policy with a live register, per-provider risk assessments, per-provider exit plans with specific triggers, and a quarterly oversight cadence. The principle: decision and oversight live in-house; the work itself can sit anywhere DORA and Article 73 permit. Two patterns to avoid — importing FCA, MAS, or VARA outsourcing structures directly (the EU framework is heavier on senior-management substance retention) and treating exit triggers as boilerplate (supervisors expect specific triggers and a defined exit timeline, not generic “material breach” language).

Record-keeping under Article 68

MiCA Article 68 is short on the page but expansive in operational implication. It requires CASPs to keep records of all services provided, transactions executed, orders received, and communications with clients and third parties for a minimum of five years, extendable to seven on competent-authority request. Failure carries administrative sanctions up to EUR 5M or 10% of annual turnover under Article 111.

Each element unpacks into infrastructure. Services provided means trade records for exchange, deposit/withdrawal and balance-state records for custody, order books for execution, and decision records for advice and portfolio management. Transactions executed means full transaction-level granularity (customer, counterparty, asset, amount, price, timestamp, venue, fees), not just summaries. Orders received means time-stamped order books including unfilled, cancelled, and modified orders. And communications with clients (the obligation operators most underestimate) covers email, live chat, support tickets, recorded calls, and structured messaging, plus communications with third parties about specific client matters.

The operational lever is the format requirement: records must be kept in a format that lets the competent authority retrieve and process them without delay. That rules out bulk archive storage without indexing and records dispersed across operational systems with no unified retrieval, along with records locked in proprietary vendor formats. The infrastructure that passes the retrievability test is consolidated, indexed, queryable, and exportable — most CASPs build it through a data-warehouse layer that ingests from operational systems, at a typical build cost of EUR 200-500k for a mid-tier operator. The communications-retention obligation is the broadest gap: corporate email systems often expire records after 1-2 years and customer-service platforms default to shorter retention, while consumer-grade mobile messaging (Telegram, Signal, WhatsApp) has no enterprise archiving — several CASPs in 2025-2026 received NCA findings for failing to retain client-facing mobile-messaging communications. Records can be stored anywhere geographically but must remain accessible to the EU NCA without delay (a typical expectation of 24-72 hours for routine requests), so EU-resident storage is the lowest-friction path, with non-EU storage requiring a documented transfer mechanism such as the EU-US Data Privacy Framework or Standard Contractual Clauses. Article 68 also overlaps with (but is distinct from) AMLR/AMLA record-keeping (typically five years from end of relationship), Article 75 custody record-keeping, and Travel Rule (TFR) records; most CASPs build a unified retention architecture with metadata flags routing each record type to the right obligation.

The MLRO role, substance, and the wider compliance function

The crypto compliance officer role under MiCA runs broader than pre-MiCA VASP compliance positions. It combines MLRO duties (customer-due-diligence oversight, suspicious-activity reporting to the national FIU, AML-programme management, sanctions-screening oversight) with broader compliance leadership across conduct, prudential, ICT/DORA resilience, customer-asset protection, and market abuse, plus senior-management responsibility with direct board reporting and personal accountability. It is a recognised senior management function under MiCA Article 68 and national equivalents (for example the UK FCA’s SMF-16 and SMF-17). The combined role typically requires a senior-tier hire at EUR 120,000-200,000 base for a mid-tier CASP, rising to EUR 200,000-400,000 at premier tier. Role splits scale with the operator: small CASPs combine MLRO and Head of Compliance, sometimes with DPO; mid-tier firms split MLRO from Head of Compliance; substantial firms run a full senior-management split. The role carries material personal liability (civil regulatory penalties, loss of personal authorisation, and in extreme cases criminal liability), so operators should expect a compliance officer to push back on commercial pressure to relax controls.

The MLRO function is also the AML side of MiCA’s substance test, and national regulators have diverged sharply on what “adequate seniority, independence, and resources” means in 2026. The expectations cluster into three groups. The strict jurisdictions are Estonia (FSA), Malta (MFSA), and Ireland (CBI). They expect a local-resident MLRO and a defined FTE allocation, together with prior CASP-relevant experience; Malta requires functional separation of the MLRO and Compliance Officer for above-threshold Class 3 firms, and Ireland applies banking-grade governance expectations across all classes. The middle jurisdictions are Lithuania (Bank of Lithuania) and the Czech Republic (ČNB / FAÚ). They expect local residency and an FTE expectation scaled by licence class, as well as local-language capability for FIU correspondence. The lighter jurisdiction, Cyprus (CySEC), expects residency plus an AML qualification (CAMS, ICA International Diploma, or equivalent) with more flexibility on FTE and role-combination. Three principles for any file: plan to the strictest applicable jurisdiction (a Cyprus-to-Estonia passport should satisfy the FSA, not CySEC); match MLRO experience to the firm’s risk profile (Class 3 custody firms need high-volume transaction-monitoring and self-hosted-wallet CDD experience); and document the MLRO appointment with the same rigour as senior management, including source-of-funds evidence where the MLRO holds significant equity.

KYC operations

Crypto KYC operates at the intersection of MiCA, AMLR (Regulation (EU) 2024/1624), FATF guidance, and national AML frameworks. The compliance build runs EUR 200-500k in the first year and EUR 100-300k per year ongoing for a mid-tier CASP, and it has six operational components: customer identification, identity verification, beneficial-ownership verification, PEP and sanctions screening, customer risk assessment, and ongoing monitoring.

Identity verification must run through reliable independent sources, not customer self-attestation — the operational standard is document authentication (security-feature validation, MRZ extraction, tamper detection) plus a biometric face match with liveness detection, plus proof-of-address documentation within three months. Corporate customers require beneficial-ownership transparency at the 25%+ ownership/control threshold, with registry verification where available (UK Persons of Significant Control register, EU UBO registers) and careful identification of the ultimate natural person behind layered structures. PEP and sanctions screening runs continuously: foreign, domestic, and international-organisation PEPs plus their family and close associates, screened against the EU consolidated list, UN, US OFAC, UK, and national lists at onboarding and then daily, with an alert-handling workflow for false-positive disposition and confirmed-match escalation. Enhanced due diligence applies to higher-risk customers (high-risk jurisdictions, PEPs, high transaction values, complex ownership, and product-risk factors such as privacy coins or mixer activity) and requires source-of-funds information and senior-management approval, alongside tighter ongoing monitoring. KYC is not a one-time onboarding exercise: transaction monitoring, periodic CDD refresh, behavioural analytics, and suspicious-activity reporting to the national FIU all run for the life of the relationship. Records are retained five years from the end of the relationship under AMLR, extendable on supervisor request. Note that the pre-MiCA exemptions for low-value transactions have been removed — KYC applies to all CASP onboarding regardless of transaction value.

Wind-down planning under Article 84

Wind-down planning is the part of MiCA compliance operators most often defer and most often regret deferring. Article 84 requires a documented orderly wind-down framework as part of recovery and resolution planning, and NCAs increasingly test wind-down plans during routine supervisory dialogue, particularly for larger and designated CASPs under Article 85. A plan can activate under three scenarios: voluntary wind-down (board decision), supervisor-directed wind-down (authorisation withdrawal under Article 64, or enforcement with cessation as remedy), and insolvency-protective wind-down (to preserve client assets and produce an orderly market exit). A typical orderly wind-down runs 6-18 months — Class 1 advisory CASPs at the shorter end, Class 3 platforms with substantial customer-asset bases at the longer end.

Customer notification is operationally the longest and most resource-intensive part of the exercise. It needs multiple channels (email, in-app, web banner, SMS), multi-language content for the EU customer base, a tiered notification timeline in waves, clear customer instructions, customer-support capacity scaled to a typical 5-10x volume increase, and an escalation framework for unresponsive customers. Asset return is the operational and legal core: client crypto-assets remain segregated under Article 75 throughout, then return either to customer-designated wallets (with address verification and an audit trail) or to a regulated successor CASP (with consent and KYC re-onboarding); fiat balances return through the banking framework (banks can become less cooperative once a wind-down is public), and unresponsive-customer assets typically transfer to a custodial successor or escheat under national law. Every return needs a documented audit trail for supervisor reporting and later dispute defence. ICT third-party exit is one of the most under-planned aspects: the DORA Article 28 exit-planning framework supports the wind-down directly, so a CASP that has built DORA-compliant exit plans for cloud, custody-tech, KYC, and analytics providers already holds most of the ICT-exit capability. The final step is regulatory deregistration — authorisation withdrawal under Article 64, ESMA register update, AML record retention (typically 5-7 years post-cessation), DAC8 and tax closure, and corporate dissolution under national law. Wind-down plans need annual review and material-change refresh; stale plans fail at activation, so the build should involve the cross-functional team that would execute it, not be a compliance-only document.

Recovery and resolution under Article 84

The MiCA framers built in a recovery-and-resolution obligation because they could see the question coming. The history of crypto failures (Mt. Gox in 2014, QuadrigaCX in 2019, FTX in 2022) produced a pattern of customer-asset losses caused by inadequate segregation and weak governance, together with the absence of an orderly wind-down framework. Article 84 is the EU’s answer: build the recovery and resolution machinery into the regulatory architecture so a CASP failure does not become a customer-asset catastrophe. The obligation applies to every authorised CASP regardless of size — proportionality reduces depth for smaller operators but does not exempt them.

The framework splits into two documents. The recovery plan is the CASP’s own, setting out what it would do to restore financial soundness under stress: a range of recovery options (capital actions, liquidity actions, business actions), stress-scenario analysis, governance arrangements for triggering recovery, a communication strategy, and integration with the firm’s broader risk-management framework including ICT incident response. The home NCA reviews it and either approves or requires revisions, with annual review the default. The resolution plan is the NCA’s, setting out how the supervisor would wind the CASP down in an orderly manner if recovery fails — customer-asset segregation and transferability, communication with customers and counterparties, wind-down sequencing, interaction with home and host NCAs, and the interface with national insolvency law. The CASP provides input; the NCA owns the document and reviews it at least every two years. What MiCA does not import is the full BRRD toolkit (bail-in, bridge institution, asset separation) for standalone CASPs; the MiCA toolkit is lighter, centred on customer-asset transfer and orderly wind-down. Credit institutions under Article 17 issuing ARTs are the exception: they remain subject to BRRD via the underlying banking licence.

Customer-asset transferability is the single most important variable in CASP resolution — can customer crypto-assets be moved to an alternative authorised CASP in an orderly manner if the original fails? The variable touches segregation under Article 75, identification (a reliable customer-asset ledger and reconciliation cadence), transferability (alternative-provider readiness, technical interfaces, regulatory permissions), and customer communication. CASPs that treated segregation as a compliance checkbox often discover the transferability question is harder than the segregation question — segregation is an internal control, but transferability is an operational capability that must function under stress. For CASPs operating cross-border under the Article 65 passport, the supervisory college engages in resolution planning: host NCAs participate because the plan covers customer-asset transfer and communication in their territories, with the home NCA chairing and ESMA facilitating information exchange for the largest operators. For ART issuers designated under Article 43, the EBA chairs the resolution-planning college rather than the home NCA.

The framework’s strategic implication

For operators planning EU strategy under MiCA, CASP passport framework has substantive strategic implications:

Home-state selection matters substantively — different home-state NCAs have different supervisory cultures, processing capacities, and operational engagement styles. Home-state selection affects substantive ongoing operational experience for the entire passport network.

Passport scope planning — substantive operational planning required for major passport markets. Not all passport markets equal in substantive operational requirements.

Local-language infrastructure investment — substantive infrastructure investment for major passport markets pays substantive operational dividends through substantive host-state engagement.

Cross-border operational coordination — substantive operational infrastructure managing home-state + multiple host-state supervisory engagements. Operational overhead is real but framework substantively delivers compared to pre-MiCA national-licence patchwork.

Long-term strategic flexibility — passport framework supports substantive strategic flexibility: operators can adjust passport scope and add or remove host-state servicing, restructuring operational arrangements without changing home-state authorisation foundation.

For operators using or planning CASP passport, the framework substantively works — but operational reality requires substantive engagement with host-state expectations beyond the clean theoretical Article 65 framework.

Pitfalls and nuances

1 Assuming passport eliminates host-state NCA engagement

MiCA Article 65 prevents host-state authorisation requirements but doesn't eliminate host-state regulatory engagement. Host-state NCAs maintain substantive supervisory engagement on consumer protection, marketing conduct, complaint handling, AML cooperation. Passporting operators that ignore host-state expectations face substantive enforcement engagement even without authorisation requirements.

2 Underestimating host-state language requirements

Many host-state NCAs require substantive local-language compliance for consumer-facing materials — marketing communications, customer agreements, customer-protection disclosures, complaint procedures. Operators relying solely on English-language materials face substantive host-state engagement. Plan local-language infrastructure for substantial passport markets.

3 Treating notification as purely procedural

Passport notification is procedural but operators that submit notifications without substantive operational planning face host-state engagement on inadequate preparation. Substantive host-state NCAs request substantive operator information beyond formal notification — business plans, local customer-protection arrangements, complaint-handling infrastructure. Plan substantive notification engagement.

4 Missing substantive AML host-state expectations

AML cooperation with host-state authorities is substantive. Operators serving substantial host-state customer base face substantive AML reporting expectations to host-state FIU, substantive cooperation with host-state AML supervisory authorities, and substantive interaction with host-state law-enforcement on AML-related matters. Plan substantive AML infrastructure for major passport markets.

Frequently asked questions

How does MiCA CASP passport notification work in practice?

Home-state NCA notifies host-state NCAs within 10 working days of receiving complete operator notification. Host-state CASP servicing can begin within 15 working days of notification. Process is procedural — no host-state approval required.

Can host-state NCAs impose additional requirements on passporting CASPs?

Not for authorisation matters — host-state cannot require separate authorisation. But host-state retains consumer-protection enforcement, language requirements for local marketing, local-investor protection measures, and substantive AML cooperation.

Has the CASP passport worked operationally?

Yes, with operational refinement through 2025-2026. Substantive cross-border passport activity established across the EU. Initial implementation friction (host-state expectations clarification, notification mechanics) substantially resolved through ESMA coordination.

What are common passport servicing patterns?

Cross-border online services without local presence (most common), cross-border services with local marketing partnerships (substantive for major operators), cross-border services with local advisory partnerships (specialised products), and full local operational presence (largest operators).

Do passporting CASPs need host-state customer-protection compliance?

Yes for substantive consumer-protection requirements. Host-state retains enforcement of consumer-protection rules including marketing-conduct requirements, complaint-handling expectations, and substantive customer-protection standards. Compliance with host-state expectations is mandatory.

Does a MiCA authorisation solve banking for a CASP?

No. A licensed CASP still needs operating and client-money banking, and EEA banks have limited appetite for crypto. Plan banking outreach in parallel with authorisation, not afterward.

Can a CASP outsource its MLRO or compliance function under Article 73?

Senior-management responsibility cannot be outsourced. The MLRO function is in-house in Estonia, Malta, and Ireland; Cyprus permits limited outsourcing for small firms. Plan to the strictest jurisdiction.

Does every CASP need a wind-down and recovery plan?

Yes. Article 84 requires every authorised CASP to maintain a recovery plan and cooperate on an NCA-owned resolution plan, with depth proportionate to scale. Customer-asset transferability is the key variable.

Are crypto KYC rules the same as the old VASP registration regime?

No. Under MiCA and AMLR, KYC applies to all onboarding regardless of value, requires verification through independent sources, and demands ongoing monitoring. Pre-MiCA low-value exemptions are removed.

Get matched

Working through a crypto-licensing decision?

Get an editorial shortlist of firms matched to your business — customer market, model, jurisdiction, and stage. Free, and not influenced by sponsorship.

Get a firm shortlist →

Sources cited

  1. Regulation (EU) 2023/1114 (MiCA) — Article 65 — regulation
  2. ESMA Technical Standards on CASP passport notification — regulator
  3. ESMA Q&A on MiCA passport operational considerations — regulator