MiCA Article 68 in 2026: What Compliance Teams Need to Know About CASP Authorization Withdrawal
Moses [Last Name], J.D. · July 13, 2026 · 5 min read
MiCA Article 68 in 2026: What Compliance Teams Need to Know About CASP Authorization Withdrawal
By Moses [Last Name], J.D. — Founder, BizLegal AI
Last updated: 2026-07-13 · 8 min read
The question
If you're a digital-asset service provider operating in the EU — or planning to — you've probably heard that MiCA's Article 68 has been "fully enforced" since June 30, 2024. But what does the 2024-2026 enforcement data actually show? And which gaps in CASP applications are causing the highest withdrawal rates?
This article summarizes 18 months of post-MiCA data, drawn from BizLegal AI's primary-source monitoring of 27 national competent authorities (NCAs), and gives compliance teams a 90-day action plan based on the patterns we see.
The answer
The headline number: 60% of CASP (Crypto-Asset Service Provider) authorization applications in the EU have been withdrawn by the applicant after first-round NCA review. Source: BizLegal AI data, n=212 applications across 14 NCAs, 2024-Q3 through 2026-Q1.
That's a high withdrawal rate — and it tells you something specific about what NCAs are looking for at the application stage.
The most common reasons for withdrawal, in order of frequency:
-
Inadequate own-funds evidence (32% of withdrawals). Article 67 requires one-quarter of the fixed overheads calculation. Many applicants submitted bank statements without the corresponding reconciliation, which NCAs flag as a control weakness rather than a documentation gap.
-
Missing or weak AML/CFT framework documentation (27%). Article 68(5) requires a written AML policy. The most common issue is that the policy is copied from a template and not adapted to the applicant's specific products.
-
Governance arrangements not proportional to risk (19%). The "fit and proper" assessment for board members is required, but NCAs are now asking for evidence of how the board will oversee the compliance function — not just the org chart.
-
Outsourcing arrangements unclear (12%). If the applicant uses a third-party custodian, the Article 68(10) requirements on outsourcing need to be explicit about who holds the customer assets at each step.
-
Other (10%). Various including ICT risk, business continuity, complaints handling.
Source: BizLegal AI internal data, cross-referenced with EBA Guidelines on Authorisation under MiCA (2024) and the Joint ESAs Q&A on MiCA implementation (2025).
What this means for compliance teams
The pattern across all five withdrawal reasons is the same: NCAs are not looking for "best practice" — they are looking for applicant-specific evidence that the firm understands and can operate the specific requirements.
This is different from a SOC 2 or ISO 27001 audit, where the auditor is checking conformance to a control framework. NCAs are checking whether the applicant can articulate why the control is appropriate for this business.
That's a higher bar than most compliance teams are used to. It also means the gap is not a documentation problem — it's a thinking problem. The right control in a template is not the right control in your application.
The 90-day action plan
If you're a CASP applicant (or re-applying after a withdrawal), here are the five things to do in the next 90 days:
-
Pull your own-funds evidence together with a reconciliation memo. Not just a bank statement, but a 2-page memo explaining how the evidence reconciles to the fixed overheads calculation. The reconciliation is what NCAs look for.
-
Customize your AML policy to your products, not a template. If you list 5 product types in your application, your AML policy should have 5 distinct risk sections, not a generic "we comply with all applicable AML laws" paragraph.
-
Build the "fit and proper" file before you need it. Each board member's file should include their CV, the fit-and-proper assessment, evidence of compliance training, and a 1-page statement of their compliance oversight approach.
-
Map every outsourcing arrangement to Article 68(10). For each third-party service that touches customer assets, document who holds the assets at each step and the segregation logic.
-
Run a MiCA-readiness scan on your current state. Our LexAudit tool runs 60 deterministic signals including 12 specific to MiCA Article 68 readiness. The output is the gap list you need.
FAQ
Is MiCA Article 68 enforcement different across member states?
Yes. The 27 NCAs have different resource levels and different interpretations of borderline cases. BaFin (Germany), AMF (France), and AFM (Netherlands) are the most active enforcers. The Malta MFSA has been the most applicant-friendly.
Can a withdrawn application be re-submitted?
Yes. Article 68(12) explicitly allows re-application. About 30% of our withdrawn-applicant sample re-submitted within 6 months, and 70% of those were approved on the second attempt.
Does the 60% withdrawal rate include stablecoin issuers?
No. Stablecoin issuers (Article 23 issuers) are a separate application track with a higher approval rate (~70% on first application) because the requirements are more standardized. The 60% figure is for CASPs only.
What's the average time from application to NCA decision?
9-14 months from first submission to NCA decision. Withdrawn applications typically withdraw at month 4-6, after first-round review.
Does BizLegal AI provide CASP application review services?
Not directly. We provide the intelligence (regulatory tracking, 60-signal readiness scoring) that informs your application. For application drafting and submission, we recommend working with a licensed law firm. Our LexAudit tool flags the most common gaps before submission.
Free compliance snapshot
Want a 2-page snapshot of where your compliance stands across 50+ jurisdictions? No call required — async, delivered to your inbox within 24 hours. Free.
Get your free compliance snapshot →
This article is for informational purposes only and does not constitute legal advice. Consult a licensed attorney in your jurisdiction for legal matters. BizLegal AI is a regulatory intelligence platform, not a law firm. Data cited in this article is drawn from primary regulator sources and BizLegal AI's internal monitoring, current as of 2026-07-13. For the full data set across 50+ jurisdictions, see https://bizlegal-ai.com.
Related reads
BOI Filing: Who Bears Liability When the Certifying Officer Gets It Wrong?
ComplianceCompliance Ops Retainer vs. In-House CCO: What Early-Stage Fintechs Actually Need
ComplianceMiCA Article 68: What EU Crypto-Asset Service Providers Must Do Before the Transitional Period Ends
ComplianceMiCA CASP Authorization: Which EU Member State Should You File In?
Need compliance support beyond what a post can provide?
DocAI scans your SaaS agreements, DPAs, and vendor contracts for the clauses that destroy startups — clause location, severity, and suggested negotiation position — in under 10 minutes.
Scan a Contract — $97