Guide
CASP licence in the EU: one authorisation, twenty-seven markets
Updated
The reason firms tolerate the Article 62 file is Article 59(7). One authorisation, granted by one national authority, opens every member state without a second application.
What the passport actually says
"Crypto-asset service providers shall be allowed to provide crypto-asset services throughout the Union, either through the right of establishment, including through a branch, or through the freedom to provide services. Crypto-asset service providers that provide crypto-asset services on a cross-border basis shall not be required to have a physical presence in the territory of a host Member State" (Article 59(7), Regulation (EU) 2023/1114). Article 65 sets out the cross-border notification mechanics between home and host authorities.
What the home state has to be
The home member state is where the provider has its registered office (Article 3(1)(33)(f)), and Article 59(2) adds three conditions that rule out a nameplate: at least part of the crypto-asset services must be carried out in that state, the place of effective management must be in the Union, and at least one director must be resident in the Union. Article 63(7) and 63(8) let an authority refuse authorisation where close links, or a third country's laws governing them, prevent effective supervision.
The authorisation names the services
Article 59(6) requires the authorisation to specify which crypto-asset services it covers. Adding a service later is not a form-filling exercise: Article 59(8) requires a request to the original authority to extend the authorisation, complementing and updating the Article 62 information, and the request is processed under Article 63 like a fresh application.
What it does not cover
- Issuing tokens. A CASP authorisation is not authorisation to issue an asset-referenced token (Articles 16 to 21) or an e-money token, which only a credit institution or an electronic money institution may issue (Article 48).
- Payment services. Article 70(4) allows a provider to offer payment services connected to its crypto-asset service only if it or the third party is authorised under the Payment Services Directive.
- Anything outside MiCA. A token that qualifies as a financial instrument sits under MiFID II and the Prospectus Regulation instead (Article 2(4)).
- Third-country clients' comfort. An EU authorisation says nothing about the licences you need where clients sit outside the Union.
The obligations that travel with it
- Conduct: act honestly, fairly and professionally in clients' best interests (Article 66), with fair, clear and not misleading marketing communications.
- Governance: fit and proper management, effective policies, resilient ICT under Regulation (EU) 2022/2554, and records kept for five years and up to seven on request (Article 68).
- Client assets: safeguard ownership rights, keep client funds other than e-money tokens with a credit institution or central bank from the next business day (Article 70).
- Complaints and conflicts: effective and transparent complaints procedures free of charge (Article 71) and conflicts identified, prevented, managed and disclosed (Article 72).
- Outsourcing and wind-down: full responsibility for outsourced functions (Article 73) and a plan for orderly wind-down (Article 74).
The passport is the prize, and Article 59(5) protects it: a person who is not a crypto-asset service provider must not use a name, corporate name or marketing that suggests it is one, or is likely to create confusion.