Guide

CASP authorisation requirements: the document list, from the Regulation

Updated

Plenty of sites publish a MiCA document checklist. Two sources actually create one: Article 62 of the Regulation and the technical standard adopted under it. This is that list, with nothing added.

The Regulation's own list

Article 62(2) of Regulation (EU) 2023/1114 lists 19 items, (a) to (s). The first twelve apply to every applicant.

(a) to (c) Identity and constitution
Legal name and any commercial name, legal entity identifier, website, contact email, telephone number, physical address, legal form, and the articles of association where applicable.
(d) Programme of operations
The types of crypto-asset service you intend to provide, including where and how they will be marketed.
(e) Prudential safeguards
Proof that the applicant meets Article 67: own funds, a qualifying insurance policy, or a combination.
(f) to (h) Governance and ownership
A description of governance arrangements; proof that the management body is of sufficiently good repute and has the appropriate knowledge, skills and experience; the identity, holdings and repute of every direct or indirect shareholder with a qualifying holding.
(i) Risk and continuity
Internal control mechanisms, policies and procedures to identify, assess and manage risk including money laundering and terrorist financing risk, and the business continuity plan.
(j) ICT
Technical documentation of the ICT systems and security arrangements, plus a description of them in non-technical language.
(k) to (l) Client assets and complaints
The procedure for segregating clients' crypto-assets and funds, and the complaints-handling procedures.
(s) Asset type
The type of crypto-asset to which the service relates: asset-referenced tokens, e-money tokens or other crypto-assets.

Points (m) to (r) are conditional on the services you offer: a custody and administration policy, trading platform operating rules with a market abuse detection system, a commercial policy and pricing methodology for exchange, an execution policy, evidence of knowledge and expertise for advice or portfolio management, and a description of how transfer services will be provided. Our service table maps each one.

What Article 62(3) asks you to evidence

  • For all members of the management body: the absence of a criminal record for convictions and the absence of penalties under commercial, insolvency or financial services law, or in relation to anti-money laundering, counter-terrorist financing, fraud or professional liability.
  • That the management body collectively possesses the appropriate knowledge, skills and experience, and that its members are required to commit sufficient time.
  • The same absence of convictions and penalties for every direct or indirect shareholder or member with a qualifying holding, meaning 10% of capital or voting rights, or a holding that allows significant influence (Article 3(1)(36)).

The technical standard that expands it

Commission Delegated Regulation (EU) 2025/305 of 31 October 2024, published in the Official Journal on 31 March 2025, is the regulatory technical standard adopted under Article 62(5). Its articles run in the same order as the application: general information, programme of operations, prudential requirements, governance and conflicts, business continuity, AML and CFT detection and prevention, management body identity and suitability, qualifying shareholders, ICT systems and security, segregation and safekeeping of client assets, complaints handling, then one article each for the custody policy, trading platform rules and market abuse detection, exchange services, execution policy, advice and portfolio management, and transfer services. The programme of operations it describes covers three years, with financial forecasts including stress scenarios.

What you cannot be asked for twice

Article 62(4) stops a competent authority requiring information it already holds from an authorisation under the E-Money Directive, MiFID II or the Payment Services Directive, or under national crypto law in force before 29 June 2023, provided it is still up to date. That is worth invoking explicitly in a covering letter rather than assuming the authority will apply it.

Beyond authorisation, the ongoing file is set by further technical standards: Delegated Regulation (EU) 2025/1140 on the records to be kept of all services, activities, orders and transactions, and Delegated Regulation (EU) 2025/1142 on conflict of interest policies and disclosures.

Questions, answered directly

Is there an official MiCA CASP document checklist?

Yes, in two places. Article 62(2) and (3) of Regulation (EU) 2023/1114 list what an application must contain, and Commission Delegated Regulation (EU) 2025/305 specifies each heading in detail. National competent authorities then publish their own application forms built on those two texts.

What counts as a qualifying holding in a CASP?

Article 3(1)(36) defines it as a direct or indirect holding of at least 10% of the capital or voting rights, or one that makes it possible to exercise significant influence over management. Every such holder, direct or indirect, must be shown to be of sufficiently good repute.

Know your class before you draft anything

Four questions gives you the Annex IV class, the capital and the document list.

Talk to a specialist