Skip to main content
Compliance

MiCA Article 68: What EU Crypto-Asset Service Providers Must Do Before the Transitional Period Ends

Moses · July 17, 2026 · 5 min read


MiCA Article 68: What EU Crypto-Asset Service Providers Must Do Before the Transitional Period Ends

The Markets in Crypto-Assets Regulation (EU 2023/1114, "MiCA") entered into force in June 2023. Title V, covering crypto-asset service providers, became applicable on 30 December 2024. That date matters because it triggered a transitional period under Article 143(3) — and that transitional period does not run indefinitely.

If you are operating a crypto-asset exchange, a custodian, a portfolio manager, a transfer agent, or any other entity that falls within MiCA's definition of a CASP, you need to know what Article 68 requires, when the deadline lands, and what the documentation package actually looks like.

This article covers that ground, citing the regulation directly where it matters.


What Article 68 Actually Says

Article 68(1) of MiCA sets the authorization requirement:

"Entities wishing to provide crypto-asset services shall, prior to doing so, obtain an authorisation as a crypto-asset service provider from the competent authority of the Member State where they have their registered office."

The authorization is not a notification. It is not a registration. It is a licensing decision by a national competent authority (NCA) — the same category of decision as a MiFID II investment firm authorization.

The key structural elements are:

Single authorization, EU-wide passport. Once an NCA grants CASP authorization, the entity can passport that authorization to operate across the EU under Article 82 without requiring re-authorization in each member state.

Home member state jurisdiction. Authorization is filed where the entity has its registered office. If you set up in the Netherlands, you file with the AFM. If you set up in Ireland, you file with the Central Bank of Ireland. There is no "forum shopping" unless you actually relocate.

Service-specific scope. MiCA defines eight categories of crypto-asset services in Article 3(1)(16). Your authorization covers the services you applied for. If you expand services later, you need to notify the NCA and may need supplemental authorization.


The Eight CASP Services Under Article 3

Before you file anything, map exactly which services you provide:

  1. Custody and administration of crypto-assets on behalf of third parties (Article 3(1)(16)(a))
  2. Operation of a trading platform for crypto-assets (Article 3(1)(16)(b))
  3. Exchange of crypto-assets for funds (Article 3(1)(16)(c))
  4. Exchange of crypto-assets for other crypto-assets (Article 3(1)(16)(d))
  5. Execution of orders for crypto-assets on behalf of third parties (Article 3(1)(16)(e))
  6. Placing of crypto-assets (Article 3(1)(16)(f))
  7. Reception and transmission of orders for crypto-assets on behalf of third parties (Article 3(1)(16)(g))
  8. Providing advice on crypto-assets (Article 3(1)(16)(h))
  9. Providing portfolio management of crypto-assets (Article 3(1)(16)(i))
  10. Providing transfer services for crypto-assets (Article 3(1)(16)(j)) (added in final text)

The services you tick determines your minimum capital requirement.


Capital Requirements Under Article 67

Authorization is conditional on minimum own funds. Article 67 sets three tiers:

| CASP tier | Services covered | Minimum capital | |-----------|-----------------|-----------------| | Class 1 | Advice, reception/transmission, order execution, placing | €50,000 | | Class 2 | Exchange for funds, exchange for other crypto-assets, transfer services | €125,000 | | Class 3 | Operating a trading platform, custody | €150,000 |

If you provide services across tiers, the highest applicable minimum applies. These are floor requirements. NCAs may (and frequently do) require higher capital based on their assessment of your business model and risk profile.


The Authorization Application Package (Article 62)

Article 62 sets the documentation requirement. The list is not short:

  1. Program of operations — a description of the type of crypto-asset services you intend to provide, including where and how you intend to provide them
  2. Business plan — a description of the business model with a 3-year financial forecast
  3. Governance arrangements — description of the management body (Article 68 cross-references Article 68(6), which requires at least two directors of good repute with sufficient knowledge and experience)
  4. Internal controls and risk management — description of internal control mechanisms, AML/CFT procedures, and outsourcing arrangements
  5. Technical systems — description of your technical infrastructure, including cybersecurity policy
  6. Safeguarding arrangements — for custodians, description of how you segregate client assets
  7. AML/CFT program — your anti-money laundering and counter-terrorist financing compliance documentation, mapped to the EU's 5th/6th AML Directives
  8. Complaint-handling procedure — description of your procedures under Article 71
  9. Conflicts of interest policy — description of your policy under Article 72
  10. Proof of own funds — documentation that you meet the Article 67 capital requirements at the point of application

The NCA then has 25 working days to declare the application complete or incomplete (Article 62(4)), and a further 40 working days after declaration of completeness to grant or refuse authorization (Article 64).


The Transitional Provisions: Article 143(3)

Article 143(3) of MiCA provides a grandfathering window for entities that were already providing crypto-asset services before 30 December 2024 under existing national frameworks:

"By way of derogation from Article 59, entities referred to in Article 2(5) that were providing crypto-asset services in accordance with applicable law prior to 30 December 2024 may continue to provide those crypto-asset services in the Union until 1 July 2026, or until they are granted or refused an authorisation as a crypto-asset service provider in accordance with Article 59, whichever is the earlier."

The key date is 1 July 2026.

As of the publication date of this article, that deadline has passed for entities that relied on the transitional period. Entities that did not secure authorization before 1 July 2026, and which are not already in an active application process that their NCA has acknowledged as pending, are operating without authorization.

The enforcement consequence is not uniform across member states — NCAs have discretion — but operating without authorization is a civil and potentially criminal breach of MiCA in the jurisdictions where NCAs have transposed enforcement authority.


Practical Compliance Timeline (Working Backward from Any Future Deadline)

If you are advising a client who has not yet begun the authorization process, here is a realistic timeline:

| Milestone | Typical duration | |-----------|-----------------| | Jurisdiction analysis and NCA selection | 2–4 weeks | | Legal entity setup (if not yet incorporated in EU) | 4–8 weeks | | Program of operations and business plan drafting | 4–6 weeks | | AML/CFT program development | 4–8 weeks | | Technical systems documentation | 2–4 weeks | | Assembly and NCA submission | 1–2 weeks | | NCA completeness check | Up to 25 working days | | NCA substantive review | Up to 40 working days |

Total: roughly 6–12 months from a standing start. Entities that began in Q1 2025 and had their files in shape by mid-2025 are the ones that made the July 2026 transitional deadline.


Which Member State Should You File In?

This is a legal question, not a preference question. MiCA's answer is your registered office. That said, there are real differences between NCAs that matter:

Germany (BaFin): BaFin is rigorous and well-staffed for digital asset authorizations. Germany was also one of the jurisdictions with an existing crypto custody regime (GwG §1(1a) Nr. 6), so BaFin has institutional familiarity with the space.

Ireland (CBI): The Central Bank of Ireland has historically been one of the more accessible EU financial regulators for technology-driven financial services. Several major crypto exchanges registered existing VASPs here.

France (AMF): France was one of the first EU member states to create a voluntary DASP (Digital Asset Service Provider) registration regime. Existing DASP registrants received a streamlined path to MiCA authorization under Article 143(3).

Luxembourg (CSSF): The CSSF is experienced with complex fund structures and cross-border financial services. Less experience with crypto-native entities but improving.

Netherlands (AFM/DNB): The Netherlands had an existing AML-based crypto registration regime. The AFM and DNB have been active on enforcement, including significant fines for operating without registration pre-MiCA.

The choice matters because NCAs vary in: processing time, depth of AML scrutiny, capital requirements above the MiCA floor, and their institutional posture toward novel business models.


ESMA Technical Standards: What They Add

ESMA has published regulatory technical standards (RTS) and implementing technical standards (ITS) under MiCA that add specificity to the Article 62 documentation requirements. Relevant documents include:

  • ESMA/2024/1710: RTS on the content and format of information for the application for authorization as a CASP (Article 62(5))
  • ESMA/2024/1711: ITS on standard forms, templates, and procedures for authorization
  • ESMA/EBA Joint Guidelines: On the assessment of suitability of members of the management body and shareholders

The ESMA technical standards are not optional. They specify the exact format the NCA expects for each element of your application package. Filing in a non-conforming format will result in an incompleteness finding that restarts the 25-day completeness clock.


What "Good Repute" and "Sufficient Experience" Mean for Directors

Article 68(6) requires that members of the management body of a CASP have "at all times" good repute and "sufficient knowledge, skills, and experience to perform their duties."

ESMA's joint guidelines with EBA on management body suitability assessment define the criteria. In practice, NCAs expect:

  • No criminal convictions for financial crime, fraud, or dishonesty
  • No regulatory censures or enforcement orders in prior regulated roles
  • Documented experience in financial services, technology, or a directly relevant sector
  • A collective management body that covers at minimum: legal/compliance, technology/cybersecurity, and financial risk

Small teams should plan for this requirement carefully. A three-person founding team where all three have pure tech backgrounds will encounter questions about collective competence in compliance and risk management. The most efficient solution is an independent non-executive director with verifiable financial services compliance credentials.


What Happens If You Miss the Deadline

Three scenarios:

Scenario A: You are in an active application. Most NCAs have published guidance that entities with applications submitted and acknowledged as pending before 1 July 2026 can continue operating while the application is pending. Document your submission date and NCA acknowledgment carefully.

Scenario B: You stopped operating. You are not in breach. If you intend to recommence, you need authorization before resuming.

Scenario C: You continued operating without authorization. You are in breach of Article 59. Depending on your NCA, this exposes you to: administrative fines (MiCA Article 120 sets maximum fines at €500,000 or 5% of annual turnover for individuals; €5 million or 3% of annual turnover for legal persons), public censure, and in member states with criminal referral authority for financial crime, potential criminal referral.


The Takeaway

MiCA Article 68 is a licensing requirement, not a registration formality. The transitional window was narrow — 18 months — and it has closed. Entities that remain in the EU crypto market without authorization are operating in breach of an EU regulation with direct criminal and civil consequences under member state law.

The authorization path is documented. The NCA resources are available. ESMA's technical standards remove ambiguity from the documentation package. What remains is execution: engage a firm with direct NCA experience in your chosen member state, build the documentation package to ESMA/2024/1710 specifications, and get the file submitted.


Moses is a practicing commercial attorney and founder of BizLegal AI (est. 2026), a compliance intelligence platform for digital-asset teams. BizLegal tracks MiCA developments across EU member states and publishes source-cited compliance briefs daily. This article does not constitute legal advice. If you are seeking authorization as a CASP, engage qualified legal counsel in the relevant member state.


Primary sources cited:

  • Regulation (EU) 2023/1114 (MiCA), OJ L 150, 09.06.2023 — Articles 3, 59, 62, 64, 67, 68, 82, 120, 143
  • ESMA/2024/1710 — Draft RTS on content and format for CASP authorization application
  • ESMA/2024/1711 — Draft ITS on standard forms for CASP authorization
  • ESMA/EBA Joint Guidelines on suitability assessment of management body members

Related reads

Compliance

BOI Filing: Who Bears Liability When the Certifying Officer Gets It Wrong?

Compliance

Compliance Ops Retainer vs. In-House CCO: What Early-Stage Fintechs Actually Need

Compliance

MiCA CASP Authorization: Which EU Member State Should You File In?

Compliance

GDPR vs CCPA vs LGPD: Comparing the World's Three Major Data Privacy Regimes

Need compliance support beyond what a post can provide?

DocAI scans your SaaS agreements, DPAs, and vendor contracts for the clauses that destroy startups — clause location, severity, and suggested negotiation position — in under 10 minutes.

Scan a Contract — $97

This article is for informational purposes only and does not constitute legal advice. Regulations vary by jurisdiction and change frequently. Consult a licensed attorney for advice specific to your situation.

Contact