MiCA CASP Authorization: Which EU Member State Should You File In?
Moses · July 17, 2026 · 5 min read
MiCA CASP Authorization: Which EU Member State Should You File In?
MiCA Article 68(1) is clear: you file for CASP authorization with the competent authority of the member state where you have your registered office. You do not choose your NCA the way you choose a cloud provider. The NCA follows the entity.
What you can choose is where to incorporate — and that choice has real operational consequences that most CASP applicants underestimate.
This article breaks down the five most active NCAs in the EU CASP authorization pipeline and what they actually mean for your application in practice.
Why NCA Choice Matters
ESMA provides a common framework through its technical standards (ESMA/2024/1710 and ESMA/2024/1711), which standardize the format and content of CASP authorization applications across all member states. But the regulation delegates significant discretion to NCAs on:
- Capital requirements above the Article 67 floor. ESMA sets minimum own funds for three tiers: €50,000 (Class 1), €125,000 (Class 2), €150,000 (Class 3). NCAs can — and do — require higher capital.
- AML/CFT integration. Some NCAs run AML review simultaneously with the CASP authorization assessment. Others route it to a separate authority (AMF routes to ACPR in France). Timing depends heavily on how these flows interact.
- Completeness interpretation. Article 62(4) gives NCAs 25 working days to declare an application complete or incomplete. What "complete" means in practice is an NCA-specific call. Some NCAs treat missing ancillary documentation as a minor gap; others return the entire package.
- Prior framework experience. NCAs that ran national crypto registration regimes before MiCA have deeper institutional knowledge. That translates into more calibrated assessments and fewer generic information requests.
BaFin (Germany)
Institutional posture: Rigorous and process-driven. Germany's existing crypto custody regime (GwG §1(1a) Nr. 6) gave BaFin direct experience with custody-specific licensing before MiCA. BaFin's institutional knowledge on the CASP types that involve custody (trading platforms, custodians) is strong.
Capital requirements: BaFin's historical ask for trading platform applicants has been significantly above the Article 67 minimum. €500,000 in own funds is a reasonable planning assumption for Class 3 applicants. Verify with BaFin's current guidance — this is not static.
AML integration: BaFin runs its AML/CFT assessment concurrently with the authorization assessment. This is efficient once the application is in — but BaFin's AML/CFT documentation bar is high. A comprehensive AML/CFT program document, mapped explicitly to the 5th and 6th AML Directives, is not optional.
Processing: The 25-working-day completeness clock is taken seriously. BaFin has returned applications on detailed grounds. First submissions should be complete in every dimension. Allow 6-9 months from submission to authorization in a realistic best case.
Good fit for: Entities with well-documented AML/CFT programs, sufficient capital, and existing institutional credibility. Less suitable for early-stage startups that are building compliance infrastructure in parallel with the application.
AMF (France)
Institutional posture: France was the first major EU member state to create a voluntary DASP (Digital Asset Service Provider) registration regime, predating MiCA. Entities that registered under the French DASP framework before 30 December 2024 received a streamlined path to MiCA authorization under Article 143(3). If you held a French DASP registration, this is your fastest route.
Capital requirements: AMF generally enforces the Article 67 minimum floors without significant uplifts for Tier 1 and Tier 2 applicants. Tier 3 (trading platforms, custodians) receives more scrutiny.
AML integration: AML/CFT review is delegated to ACPR (Autorité de Contrôle Prudentiel et de Résolution), which operates separately from the AMF. This two-authority structure adds coordination complexity but distributes the review burden.
Processing: For DASP-to-MiCA conversions, the AMF has published a specific guidance path. For new applicants without a prior DASP registration, processing timelines are broadly comparable to other major NCAs.
Good fit for: Entities with existing French DASP registrations. Also suitable for entities targeting the French market specifically or those with existing French legal entities.
Central Bank of Ireland (CBI)
Institutional posture: Ireland has been a top choice for EU-licensed financial services entities for decades. The CBI's track record includes MiFID II investment firms, UCITS funds, and AIFMD management companies. Several major crypto exchanges and custody providers registered VASPs with the CBI before MiCA.
Capital requirements: CBI generally enforces Article 67 minimum floors. Its focus is more on governance and conduct than capital uplift for standard CASP types.
AML integration: CBI integrates AML/CFT review into the core authorization assessment. The AML/CFT documentation pack needs to be filed with the main application — not sequentially.
Processing: CBI has historically been considered one of the more accessible EU financial regulators for technology-driven financial services. Processing timelines vary. Applications acknowledged before 1 July 2026 are proceeding under transitional protection.
Good fit for: Entities seeking a market-accessible, English-language NCA with deep fintech licensing experience. Ireland's corporate tax framework is an additional consideration for holding structure planning, though MiCA authorization depends on the operating entity's registered office, not its tax domicile.
CSSF (Luxembourg)
Institutional posture: The Commission de Surveillance du Secteur Financier (CSSF) has deep experience with complex investment fund structures and cross-border financial services. Its experience with crypto-native entities is more limited than BaFin, AMF, or CBI — but it is developing.
Capital requirements: Case-by-case, but CSSF's prudential approach tends toward conservatism for novel business models.
AML integration: CSSF has detailed AML/CFT requirements. For some CASP types, a third-party AML audit may be required or strongly recommended before the application is declared complete.
Processing: CSSF processes are methodical. Applications receive detailed initial reviews but the back-and-forth on completeness can extend timelines.
Good fit for: Entities that are already Luxembourg-domiciled for fund or holding company reasons. Less suitable for new entities choosing a domicile primarily for the CASP authorization.
AFM/DNB (Netherlands)
Institutional posture: The Netherlands splits financial regulation between two authorities: AFM (conduct of business) and DNB (prudential supervision). For CASP authorization under MiCA, this two-regulator structure means two parallel assessments.
Prior enforcement track record: DNB actively fined entities for operating crypto services without registration under the pre-MiCA Dutch AML/CFT framework. Binance, Coinbase, and several smaller exchanges were subject to Dutch enforcement actions before or during their registration process.
Capital requirements: DNB has been known to require higher capital than the Article 67 minimum for entities with significant Dutch market exposure.
AML integration: DNB enforces strict AML/CFT requirements. The Netherlands has a long track record of FATF-aligned AML enforcement across financial services.
Good fit for: Entities already incorporated in the Netherlands with existing compliance infrastructure calibrated to DNB standards. Less suitable for entities incorporating from scratch primarily for CASP authorization.
A Note on "NCA Shopping"
MiCA does not permit selecting an NCA based on regulatory preference. Authorization is filed in the jurisdiction of your registered office. If you intend to be licensed in Germany, your entity must be registered in Germany.
What you can legitimately plan is where to establish your operating entity before applying. This is a legal and structural decision, not a regulatory arbitrage play. The decision should factor in:
- Your existing legal entities and where they are registered
- Your target EU markets (Article 82 passporting reaches all member states, but your NCA relationship is in your home state)
- Your team's location and the requirements for management body members under Article 68(6)
- Tax and corporate governance considerations (outside MiCA's scope but relevant to the decision)
The authorization decision and the entity incorporation decision should be made together, not sequentially.
The Timeline
From a standing start — no EU entity, no compliance documentation — to CASP authorization typically takes 8–14 months across any of these NCAs. The breakdown:
| Phase | Duration | |-------|----------| | Jurisdiction analysis and entity decision | 2–4 weeks | | EU entity incorporation | 4–8 weeks | | Program of operations, business plan, AML/CFT program | 6–10 weeks | | Technical systems documentation | 2–4 weeks | | Assembly and submission | 1–2 weeks | | NCA completeness check | Up to 25 working days | | NCA substantive review | Up to 40 working days |
Entities that started this process in Q1 2025 and had their files in shape by mid-2025 are the ones that made the 1 July 2026 transitional deadline under Article 143(3). For new entrants, the authorization path remains open — it just does not come with transitional protection.
The Takeaway
MiCA CASP authorization is not a generic compliance checklist. The NCA you work with — or more precisely, the member state your entity is incorporated in — shapes your capital requirements, your AML/CFT review process, and your processing timeline in ways that are not visible in the regulation text alone.
If you are at the entity structuring stage and building toward CASP authorization, the jurisdiction decision deserves dedicated legal analysis — not a back-of-envelope read of the ESMA technical standards.
Moses is a practicing commercial attorney and founder of BizLegal AI (est. 2026), a compliance intelligence platform for digital-asset teams. BizLegal tracks MiCA developments across EU member states and publishes source-cited compliance briefs daily. This article does not constitute legal advice. Jurisdiction selection decisions require qualified legal counsel familiar with your specific structure and target markets.
Primary sources:
- Regulation (EU) 2023/1114 (MiCA) — Articles 59, 62, 67, 68, 82, 143
- ESMA/2024/1710 — Draft RTS on content and format for CASP authorization
- ESMA/2024/1711 — Draft ITS on standard forms for CASP authorization
- BaFin MiCA CASP authorization guidance (bafin.de)
- AMF DASP → CASP conversion guidance (amf-france.org)
- CSSF CASP authorization requirements (cssf.lu)
Related reads
BOI Filing: Who Bears Liability When the Certifying Officer Gets It Wrong?
ComplianceCompliance Ops Retainer vs. In-House CCO: What Early-Stage Fintechs Actually Need
ComplianceMiCA Article 68: What EU Crypto-Asset Service Providers Must Do Before the Transitional Period Ends
ComplianceGDPR vs CCPA vs LGPD: Comparing the World's Three Major Data Privacy Regimes
Need compliance support beyond what a post can provide?
DocAI scans your SaaS agreements, DPAs, and vendor contracts for the clauses that destroy startups — clause location, severity, and suggested negotiation position — in under 10 minutes.
Scan a Contract — $97