Regulatory Guide

MiCA Regulation: What Crypto Startups Must Do in 2025

The EU's Markets in Crypto-Assets Regulation (MiCA) is now fully in force. If you operate a crypto exchange, custody service, or other crypto-asset service provider — or if you issue tokens targeting EU investors — you need authorization or registration in the EU. This guide explains who MiCA applies to, what it requires, and what you need to do.


What MiCA Covers

MiCA creates a comprehensive regulatory framework for crypto-assets in the EU. It covers three main categories:

  • Asset-Referenced Tokens (ARTs): tokens that maintain a stable value by referencing multiple currencies, commodities, or crypto-assets. The most common example is a multi-collateral stablecoin. Issuers need authorization; significant ARTs face additional capital and liquidity requirements.
  • E-Money Tokens (EMTs): tokens referencing a single official currency. Essentially crypto-native e-money. Issuers must be authorized as either a credit institution or an e-money institution under existing EU law.
  • Other Crypto-Assets: utility tokens, payment tokens, and other crypto-assets not qualifying as ARTs or EMTs. Offering these in the EU requires a public whitepaper (with some volume exemptions) but does not require issuer authorization.

In addition to token issuers, MiCA regulates Crypto-Asset Service Providers (CASPs) — any business providing crypto-asset services, from custody to exchange to portfolio management.

CASP Authorization: Who Needs It and How It Works

MiCA defines 10 categories of crypto-asset services requiring authorization:

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds or other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders for crypto-assets
  • Providing advice on crypto-assets
  • Providing portfolio management on crypto-assets
  • Providing transfer services for crypto-assets

To obtain CASP authorization, you apply to the national competent authority (NCA) in an EU member state — typically the financial regulator (BaFin in Germany, AMF in France, AFM in the Netherlands, and so on). Applicants must meet minimum capital requirements, fit-and-proper assessments for management, governance arrangements, and operational safeguards including client asset segregation.

Once authorized in one member state, you can passport your authorization across all EU member states — a significant advantage over pre-MiCA national licensing fragmentation.

Transitional Provisions for Existing CASPs

Businesses that were already providing crypto-asset services under national law before MiCA's CASP rules became applicable (December 30, 2024) may benefit from a transitional period. Member states can allow these businesses to continue operating under national law for up to 18 months while they obtain full MiCA authorization.

Not all member states have implemented this transitional provision, and not all have implemented it for the same duration. If you relied on a national registration (e.g., a VASP registration) in a specific member state, you need to verify whether that state's transitional regime applies to you and when it expires.

Whitepaper Requirements for Token Offerings

A public offering of crypto-assets (other than ARTs and EMTs) in the EU requires a compliant crypto-asset whitepaper. This is a departure from the pre-MiCA environment where token offerings in the EU were lightly regulated (or unregulated) unless they qualified as securities.

The whitepaper must include:

  • Information about the offeror/issuer (legal form, identity, contact)
  • Description of the project the crypto-asset serves
  • Description of the crypto-asset (type, features, rights and obligations)
  • Offering terms (price, allocation, admission to trading)
  • Technology and protocol description
  • Risks specific to the issuer, project, and crypto-asset
  • Principal adverse impacts on the environment and climate

Offerors bear civil liability for misleading or inaccurate whitepapers. Unlike EU securities prospectuses, crypto-asset whitepapers do not require regulatory pre-approval — they must be notified to the NCA before publication, but the NCA does not approve the content. Key exemptions: offerings below €1 million over 12 months, offerings to qualified investors only, and offerings of free tokens (airdrops with no consideration).

Non-EU Companies Serving EU Clients

MiCA has extraterritorial reach. A non-EU CASP that actively markets to EU clients or acquires EU clients through solicitation needs CASP authorization. "Reverse solicitation" — where the EU client initiates the relationship of their own exclusive initiative — is an exception, but regulators interpret it narrowly.

For practical purposes: if you are a US, UK, or Asia-based exchange that actively acquires EU customers (through advertising, social media campaigns, app store listings, or localized websites), you are likely providing services in the EU and need to address MiCA compliance — either through an EU subsidiary or by limiting EU client acquisition.

AML Obligations Under MiCA

MiCA itself is not an AML regulation — it works alongside the EU's AML framework. CASPs authorized under MiCA are subject to the EU's Anti-Money Laundering Directive (AMLD) and the Transfer of Funds Regulation as applied to crypto (the "Travel Rule"). In practice, CASPs must implement: customer due diligence (KYC) procedures, transaction monitoring, SAR filing, and the Travel Rule for crypto transfers above €1,000. The incoming AML Regulation (AMLA) will further harmonize these requirements.

Assess your MiCA compliance exposure

BRAI generates a counterparty risk and regulatory exposure report for crypto businesses — covering MiCA, AML/KYC, VARA, and SEC framework mapping. Understand your obligations before you apply for authorization or expand into EU markets.

Explore BRAI Risk Reports

Contract Risk — $97

Review Your MiCA-Related Contracts in 60 Seconds

CASP service agreements, token issuance contracts, AML/KYC vendor agreements, and custody arrangements all need MiCA-compliant language. BizLegal AI scans your contracts for missing MiCA-required provisions — liability caps, governance disclosures, data handling clauses — and flags every gap with a risk rating.

Scan Your MiCA Contracts →

Frequently Asked Questions

What does MiCA stand for and when did it take effect?

MiCA stands for Markets in Crypto-Assets Regulation — Regulation (EU) 2023/1114. The regulation entered into force on June 29, 2023. Rules for asset-referenced tokens (ARTs) and e-money tokens (EMTs) became applicable from June 30, 2024. Rules for crypto-asset service providers (CASPs) became applicable from December 30, 2024.

Which businesses does MiCA apply to?

MiCA applies to: (1) crypto-asset service providers (CASPs) — exchanges, custodians, portfolio managers, advisors, transfer services, and placement services for crypto-assets; (2) issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) that are offered or traded in the EU. It applies to businesses based in the EU and to those outside the EU seeking to provide services to EU clients.

Do I need a MiCA license (CASP authorization)?

If you operate any of the crypto-asset services listed in MiCA — exchange, custody, execution of orders, reception and transmission of orders, portfolio management, advice, transfer services, or placement — and you serve EU clients, you need CASP authorization from a national competent authority in an EU member state. Without authorization, you cannot lawfully provide these services in the EU.

What is required for a crypto-asset whitepaper under MiCA?

Any public offering of crypto-assets (other than ARTs and EMTs, which have additional requirements) in the EU requires a crypto-asset whitepaper. It must include: description of the issuer, project and asset; rights and obligations attaching to the crypto-asset; technology and protocol description; relevant risks; principal adverse impacts on climate and the environment; and liability provisions. The issuer bears civil liability for the whitepaper.

Are NFTs covered by MiCA?

Generally, NFTs are excluded from MiCA if they are truly unique and non-fungible. However, a series of identical NFTs, or NFTs that share significant characteristics making them functionally fungible, may not qualify for the exclusion. MiCA is also explicit that its asset classification may still apply to NFTs that are otherwise regulated financial instruments under MiFID II.

How does MiCA interact with existing EU financial services regulation?

MiCA explicitly does not apply to financial instruments that already fall under MiFID II, e-money regulated under the E-Money Directive, or deposits regulated under the Capital Requirements Directive. If your crypto-asset qualifies as a security under MiFID II (i.e., it is a transferable security), it is subject to MiFID II rather than MiCA. The boundary between security tokens and utility/payment tokens remains a key regulatory determination.

Related: MiCA Framework Hub — enforcement analysis, licensing tracker, and compliance briefs