MiCA does not issue one crypto licence. It defines ten separate crypto-asset services, and an authorisation names the ones you may provide. So the first question is not which country to apply in, it is which of the ten your product triggers. Get that wrong and the capital, the file and the timetable are all wrong with it.
Authorisation is granted service by service: four numbers from ESMA's register
Since 1 July 2026 there is no transitional tier left in the EU, which makes scope the whole game. Reverse solicitation, the procedural clock and the Annex IV classes are covered in Swiss SRO vs EU MiCA vs El Salvador; this page takes the ground that comparison does not. Undecided on a region? Start at licence selection.
Key takeaways
- MiCA lists ten crypto-asset services. Authorisation is granted service by service, not as a single licence.
- An existing credit institution, investment firm or e-money institution has a separate route in - but only for the services MiCA treats as equivalent for its type of entity.
- A pending application does not let you keep trading. ESMA has answered that directly.
- Not one row of ESMA's own register names Poland as its home Member State.
Which of MiCA's ten crypto-asset services does your product trigger?
Article 3(1)(16) defines a crypto-asset service as any of ten named services: custody and administration on behalf of clients; operation of a trading platform; exchange for funds; exchange for other crypto-assets; execution of orders on behalf of clients; placing; reception and transmission of orders; advice; portfolio management; and transfer services on behalf of clients (MiCA Article 3, ESMA single rulebook).
Article 59(6) requires the authorisation to specify which of them you may provide; Article 59(8) requires a formal extension request before you add another. The definitions are narrower than their plain-English labels, which is where scoping goes wrong:
What you do, and the MiCA service it is
| What you do | The MiCA service | What people get wrong |
|---|---|---|
| Hold user private keys or assets | Custody and administration | The definition covers the assets or the means of access to them - private keys included. |
| Buy from and sell to users off your own book | Exchange for funds, or for other crypto-assets | Using proprietary capital is the trigger, not the exemption. |
| Match third-party buyers and sellers | Operation of a trading platform | No order book is still a multilateral system if it results in a contract. |
| Market a token to buyers for the issuer | Placing of crypto-assets | Marketing for the offeror or a related party is the service, not just promotion. |
| Take a client order and pass it on | Reception and transmission of orders | Not executing does not put you outside the ten. |
The usual discovery is that one product triggers three or four services at once - the glossary defines each term.
Do you need a CASP authorisation if you already hold an EMI or investment-firm licence?
Not from scratch, but not broadly either. Article 59(1) offers two routes: authorisation as a CASP under Article 63, or being "a credit institution, central securities depository, investment firm, market operator, electronic money institution, UCITS management company, or an alternative investment fund manager that is allowed to provide crypto-asset services pursuant to Article 60".
A regulated financial entity takes the Article 60 road - but only for the services regarded as equivalent for its type of entity; anything beyond that means "applying for a crypto-asset service provider (CASP) authorisation under Article 62 of MiCA" (ESMA Q&A 2125). Even then the file is smaller than it looks: Article 62(4) says authorities shall not re-request information they already hold from an e-money, MiFID or payment-services authorisation, provided it is still current - which is where our fintech licence work starts.
What changed on 1 July 2026 - and what did not?
Grandfathering ended. Article 143(3) let firms providing services in accordance with applicable law before 30 December 2024 continue until 1 July 2026, or until authorisation was granted or refused, whichever came sooner. ESMA's statement of 17 April 2026 put the consequence plainly: after that date, "any entity providing crypto-asset services to EU clients without a MiCA licence will be in breach of EU law and must cease offering such services" (ESMA statement).
Every unauthorised CASP was expected to have implemented its wind-down plan by that date. Three things did not change:
- Applying was never permission to trade. A firm not authorised by the end of the transition "must cease providing crypto-asset services until they are granted authorisation as a CASP under MiCA", and should apply as early as possible (ESMA Q&A 2220).
- Two categories were never inside it - firms not providing services under national law before 30 December 2024, and firms in Member States whose transition ended earlier.
- The simplified procedure has closed. Article 143(6) applied only to applications filed between 30 December 2024 and 1 July 2026 by entities already authorised nationally. Anything filed now is an ordinary application.
Can a non-EU firm still reach EU clients through a licensed partner?
The arrangement most often sold to founders outside the EU, and ESMA closed it. Its April 2026 statement says entities established outside the EU are, "outside the narrow exception of reverse solicitation", not permitted to provide crypto-asset services that qualify as MiCA services to EU investors, nor "to solicit EU clients with a view to provide MiCA services to them".
Licensed offshore with custody parked at an authorised EU partner is not a workaround - the offshore entity is still providing MiCA services to EU clients, which is the first thing that statement rules out - and ESMA says this applies in a business-to-business context too, because MiCA "specifically prohibits CASPs from outsourcing or delegating certain services, namely custody, to entities not authorised as CASPs themselves".
Two rules that travel with it
- MiCA protections apply only to the authorised EU legal entity - not to group companies or non-EU entities, even under one brand: entity proof.
- Article 59(2) requires a registered office in a Member State where you carry out at least part of your services, effective management in the Union, and one EU-resident director. Substance, not an address.
What does ESMA's own register show - and where does that leave Poland?
ESMA's interim MiCA register, downloaded on 28 August 2026, holds 335 authorisation rows covering 330 distinct entities across 26 home Member States - Germany 79, France 35, the Netherlands 29, Cyprus 26, Malta 22, and Poland none. No commentary in this section, only that file.
How often each of the ten services appears across 335 rows
| Service | Rows |
|---|---|
| Custody and administration | 220 |
| Transfer services | 205 |
| Exchange for funds | 183 |
| Execution of orders | 176 |
| Exchange for other crypto-assets | 151 |
| Reception and transmission of orders | 94 |
| Portfolio management | 57 |
| Advice | 44 |
| Placing | 36 |
| Operation of a trading platform | 21 |
Custody appears in over six in ten authorisations; a trading platform in 21 rows, the rarest of the ten. That matches what the Polish authority published on 30 June 2026: because MiCA applies directly, "registration in the Register of Virtual Currency Activities will no longer constitute authorization to conduct virtual currency activities in Poland or outside its borders", the authority is not a MiCA supervisor, and firms unauthorised anywhere in the EU by 1 July 2026 should be treated as high-risk (Tax Administration Chamber in Katowice). Poland extended nothing; the same notice records the transitional period as expiring on 1 July 2026. A compliance story resting on that registration has nothing under it - the same test applies country by country.
What really sets your capital requirement?
Article 67(1) sets the number: the prudential safeguard is the higher of the Annex IV permanent minimum and one quarter of the preceding year's fixed overheads, reviewed annually. For a firm that genuinely operates, the overheads test usually bites harder - the headline figure is a starting point, not a budget.
ESMA has clarified the mixed case: the minimum is whichever service requires the higher one - EUR 125 000 for Class 2 only, EUR 150 000 for Class 3, and EUR 150 000 where Class 1 and Class 3 combine (ESMA Q&A 2343). Article 67(4) allows own funds, insurance or a combination. The Annex IV classes themselves are tabulated on the route comparison page, alongside local substance requirements explained.
What if the EU is not where your clients are?
Confirm where your paying clients are before deciding what to apply for. MiCA is built for serving EU clients; carrying EU substance to reach users elsewhere is a poor trade.
Fix the client geography
Where your clients sit, and where you market, creates the obligation. Preference does not.
Fix the services
Map each product action onto the ten and freeze the scope. Capital and the file follow.
Then pick the route
The EU is one option. CryptoLicense covers twelve jurisdictions - Singapore, Hong Kong, Abu Dhabi, Bahrain, Switzerland, Latvia, Malta, Canada, El Salvador, the United States, Australia and New Zealand. The Swiss route end to end: the complete Swiss SRO application process.
Common questions
Can we keep operating while our CASP application is being assessed?
No. ESMA's answer is that a firm not authorised by the end of the transition period in the relevant Member State must cease providing crypto-asset services until authorisation is granted.
Is a Polish virtual-currency registration still a valid basis to operate?
No. The Polish Tax Administration Chamber in Katowice stated on 30 June 2026 that entry in the register no longer constitutes authorisation to conduct virtual-currency activity in Poland or outside it.
Does one MiCA authorisation cover every crypto activity?
No. It specifies which services you may provide; adding another requires a formal extension request to the authority that granted it, under the same procedure.
A note on what this is
This describes published legislation, supervisory documents and register data; it is not legal advice. CryptoLicense is the licensing-advisory brand of CL GLOBAL SDN BHD (1421939-T) - neither a regulator nor a law firm - and has served 100+ companies across 10+ jurisdictions. No application can be guaranteed: whether authorisation is granted rests entirely with the regulator, exercising its own discretion. Bring us your model and your client geography; we do the scope test first, the route second.
Part of a series: the full guide is licence selection.
