Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

Crypto-asset service provider (CASP): definition, scope and what it obliges you to do

What "Crypto-asset service provider (CASP)" means in practice, where the definition comes from, and the obligations that attach once the term applies to you.

A crypto-asset service provider (CASP) is a legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis. This definition is established under the regulatory framework set out in Regulation (EU) 2023/1114 (MiCA). Entities qualifying as CASPs must navigate rigorous authorization, operational, and conduct rules before offering their services within the European Union.

Definition of a crypto-asset service provider

Under the scope of Regulation (EU) 2023/1114 (MiCA) — full text, a crypto-asset service provider refers to any entity that habitually provides crypto-asset services to third parties as a regular occupation or business. This definition captures a broad range of operational models operating within digital asset markets. Entities must examine their business structures against the statutory definitions provided by the European Commission — crypto-assets policy to determine whether their activities trigger regulatory perimeters.

The classification as a crypto-asset service provider is not determined by the technology stack alone, but rather by the commercial nature of the services offered to clients. Whether an entity acts as a primary platform or an intermediary, providing services on a professional basis brings it squarely into the regulatory framework described in ESMA — Markets in Crypto-Assets Regulation (MiCA). Compliance teams utilize tools such as the tools/token-classifier to map digital instruments accurately.

Firms that operate without the proper status risk regulatory enforcement actions by national competent authorities. The legal threshold relies on the regularity and professional orientation of the services rather than the sheer volume of transactions processed. Understanding this baseline definition is the first step for legal operations teams preparing documentation for review under regulations/mica.

The test for whether CASP rules apply to your organization

The applicability test depends on whether an entity performs specific regulated activities with respect to crypto-assets. Regulated activities include the custody and administration of crypto-assets on behalf of clients, the operation of a trading platform for crypto-assets, and the exchange of crypto-assets for funds or other crypto-assets. Organizations can evaluate their specific asset profiles using the tools/mica-asset-classifier.

Additional triggers include the execution of orders for crypto-assets on behalf of clients, placing of crypto-assets, reception and transmission of orders on behalf of clients, providing advice on crypto-assets, and providing portfolio management on crypto-assets. When an undertaking engages in any of these functions as a regular business, the entity meets the criteria of a crypto-asset service provider. For stablecoin issuers, parallel evaluations using the tools/stablecoin-classifier are often necessary.

The following table outlines the core operational triggers and their primary operational focus under the framework:

| Service Trigger | Operational Focus | Primary Compliance Impact | |---|---|---| | Custody | Holding private keys for clients | Enhanced glossary/custody-of-crypto-assets controls | | Trading Platform | Operating matching engines | Market integrity and glossary/market-abuse-crypto prevention | | Exchange Services | Swapping tokens for fiat/tokens | Robust AML and operational resilience |

Firms must assess whether their outreach constitutes active marketing in the EU or if interactions fall under strict exemptions like glossary/reverse-solicitation.

What changes once CASP status applies to an enterprise

Once an entity qualifies as a crypto-asset service provider, a comprehensive suite of statutory obligations takes immediate effect. The organization must secure prior authorization from the relevant national competent authority before commencing operations. This authorization process requires extensive disclosures regarding governance arrangements, ICT systems, and risk management frameworks as outlined in the guidance provided by ESMA — Markets in Crypto-Assets Regulation (MiCA).

Licensed entities must maintain minimum capital reserves and adhere to strict organizational requirements, including measures to safeguard client crypto-assets and funds. These capital obligations closely mirror standard glossary/own-funds-requirement principles designed to protect consumers against operational failures. CASPs must establish robust complaints-handling procedures and maintain transparent pricing policies for all services rendered to retail and institutional clients.

Cross-border operations become structured through formal notification procedures rather than fragmented local registrations, utilizing mechanisms akin to glossary/passporting to service clients across multiple member states. Compliance teams must also implement continuous monitoring protocols to detect glossary/market-abuse-crypto and ensure that all published information complies with standards similar to those for a glossary/crypto-asset-white-paper.

Frequent mistakes compliance teams make regarding CASP status

A prevalent error among operating firms is assuming that decentralized finance (DeFi) architectures automatically exempt them from crypto-asset service provider categorization. Regulatory authorities examine the actual degree of decentralization and whether a centralized legal entity exercises control or captures commercial fees from the protocol. Misjudging this control boundary often leads to unexpected enforcement actions under Regulation (EU) 2023/1114 (MiCA) — full text.

Another frequent misstep involves misinterpreting the boundaries of custody services. Firms often store client encryption keys or facilitate multi-signature arrangements without realizing that holding the keys or exercising administrative control over client assets triggers the full scope of crypto-asset service provider obligations. Teams should cross-reference operational workflows with specific technical definitions found in glossary/custody-of-crypto-assets.

Finally, legal operations teams frequently underestimate the lead time required to compile the documentation mandated by the European Commission — crypto-assets policy. Treating authorization as a mere administrative filing rather than a rigorous audit of internal controls results in significant operational delays. Firms preparing for these requirements can review structured approaches detailed in guides/mica-regulation-crypto-compliance.

Adjacent terms often confused with crypto-asset service providers

Compliance officers routinely confuse crypto-asset service providers with the issuers of specific token types, such as issuers of asset-referenced tokens or e-money tokens. While an entity might perform both issuance and service provision, the regulatory regimes governing a glossary/asset-referenced-token issuer and a trading platform operator are distinct. Each category carries separate reserve requirements and governance standards under the overarching framework of Regulation (EU) 2023/1114 (MiCA) — full text.

Another frequent point of confusion arises between CASPs and traditional financial institutions operating under separate legislative frameworks like MiFID II. Although certain requirements overlap, the statutory definitions and supervisory authorities differ significantly. Teams must ensure their compliance taxonomies clearly distinguish between general financial intermediaries and entities governed specifically by ESMA — Markets in Crypto-Assets Regulation (MiCA).

Firms also conflate the issuance of a glossary/crypto-asset-white-paper with the provision of crypto-asset services. Publishing a disclosure document for a token offering does not automatically confer service provider status, just as operating a service platform does not necessarily make the entity an issuer of every token traded thereon. Clear structural mapping prevents regulatory misalignments.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does a purely software-based wallet provider always require CASP authorization?

Whether a wallet provider needs authorization depends entirely on whether they hold cryptographic keys on behalf of clients or exercise control over those assets. Non-custodial wallet providers where users retain sole control over their private keys generally fall outside the primary scope, whereas custodial arrangements trigger the requirements.

Can a non-EU entity provide services to European clients without a CASP license?

Non-EU entities generally cannot actively solicit clients within the European Union unless the interaction is initiated exclusively by the client at their own exclusive initiative, often referred to as reverse solicitation. Otherwise, establishing a licensed entity or securing proper authorization within the EU is mandatory.

Are issuers of asset-referenced tokens automatically classified as CASPs?

Issuers of asset-referenced tokens are governed by specific authorization requirements tailored to reserve management and asset backing. While an issuer may also apply for a CASP license to provide services like custody or trading, issuance and service provision remain distinct regulated activities.

What role do national regulators play in overseeing these service providers?

National competent authorities designated by each member state handle the initial authorization applications, ongoing supervision, and enforcement actions for entities operating within their jurisdictions, while European supervisory authorities coordinate regulatory technical standards across the bloc.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-05.

Contact