How CASP Authorization Works
To provide crypto-asset services in the EU you apply for authorization to the National Competent Authority of your home member state — the country where your legal entity is established and effectively managed. Once granted, the licence is passportable across all 27 member states. The NCA assesses your application against MiCA's authorization conditions, and the file you submit must demonstrate that you meet every one of them.
The checklist below follows Article 62. Treat it as a structured project: each item is a document you produce, review, and assemble into a coherent file.
Applicant, Ownership & Governance
The core corporate and governance documentation:
- Legal name, legal form, registered and head-office address, website, and LEI;
- Articles of association and proof of incorporation;
- Identity of members of the management body, with evidence of good repute, knowledge, skills, and experience (fit-and-proper);
- Identity of shareholders with qualifying holdings (direct or indirect ≥10%) and proof of their good repute;
- A description of governance arrangements, internal control mechanisms, and risk-management procedures;
- Business-continuity policy.
Fit-and-proper assessment of directors and qualifying shareholders is rigorous — gaps here are a frequent cause of delay.
Programme of Operations
The programme of operations is the heart of the file. It must set out the types of crypto-asset services the applicant intends to provide, including where and how they will be marketed. It should describe:
- Each service and the assets involved, mapped to the MiCA service definitions and the resulting capital class;
- The operating model, client onboarding, and order/transaction flow;
- Marketing strategy and target markets (including passporting intentions);
- Outsourcing arrangements.
The programme of operations must align with every other document — capital, AML, and ICT all flow from the services you declare here.
Compliance & Client-Protection Documents
MiCA places client protection at the centre of authorization. Required documents include:
- Proof of prudential safeguards meeting the Annex IV minimum (see our capital requirements guide);
- AML/CFT policies and procedures — risk assessment, KYC/CDD, transaction monitoring, and Travel Rule arrangements (see AML/KYC programme);
- A description of segregation of client crypto-assets and funds;
- Complaints-handling procedures;
- Conflict-of-interest policy;
- Where custody is provided, the custody policy and key-management approach.
Technical, Security & ICT Documentation
MiCA and DORA require strong technology controls, evidenced at application:
- A description of ICT systems and security arrangements, including cybersecurity and resilience controls aligned with DORA;
- Business-continuity and disaster-recovery plans;
- Where a trading platform is operated, the operating rules and market-abuse detection arrangements;
- Where applicable, procedures for the secure custody and transfer of client crypto-assets.
Technical documentation is increasingly scrutinised — vague "we use secure cloud infrastructure" statements no longer suffice.
The NCA Assessment Timeline
MiCA fixes the procedural clock (Article 63):
- Completeness check — 25 working days: the NCA confirms whether the application is complete. If not, it sets a deadline for missing information.
- Assessment — 40 working days: once complete, the NCA assesses the substance and decides to grant or refuse authorization.
The clock can pause while the NCA awaits requested information, which is why a complete, high-quality first submission is the single biggest lever on your overall timeline. In practice, total elapsed time is typically several months once preparation and information requests are included.
Common Mistakes That Delay Applications
The recurring failure points we see:
- Service misclassification — declaring the wrong MiCA services, leading to the wrong capital class and an inconsistent file;
- Weak fit-and-proper evidence for directors or qualifying shareholders;
- Generic AML policies not tailored to the actual business model;
- Thin ICT/DORA documentation;
- Inconsistencies between the programme of operations, capital, and compliance documents.
A coherent, internally consistent file passes the completeness check and shortens assessment. That is exactly what our CASP authorization service delivers.