Services

EU CASP License: MiCA and DORA Requirements for Cryptocurrency Businesses

EU CASP License: MiCA and DORA Requirements for Cryptocurrency Businesses

What is a CASP License?

CASP (Crypto-Asset Service Provider) is a cryptoasset service provider status under the European MiCA regulation. A license is required for companies that professionally provide certain crypto services to clients in the EU: custody of crypto assets, management of a trading platform, exchange of crypto assets for fiat or other tokens, execution of orders, placement of crypto assets, and other regulated services.

Following the end of the MiCA transition periods, these requirements have become particularly relevant for companies wishing to work with European clients. In June 2026, ESMA specifically reminded that companies outside the EU cannot offer MiCA services to clients in the EU or actively solicit them, except under a narrow reverse solicitation regime.

MiCA Basic Requirements

To obtain a CASP license, a company submits an application to the national regulator of the selected EU member state. The application must include a description of the business model and planned services, information on the management structure and shareholders, confirmation of the business reputation of the management, internal risk control procedures, AML/CFT mechanisms, a business continuity plan, and technical documentation on IT systems and security.

The CASP must have a registered office in an EU member state, conduct at least part of its activities there, and have its place of effective management in the European Union. At least one director must be an EU resident. Once authorized, the company can provide authorized crypto services in other EU countries within the single European market.

DORA: Digital Resilience of CASPs

Obtaining CASP authorization means taking into account not only MiCA but also DORA—the European Regulation on Digital Operational Resilience in the Financial Sector. For authorized CASPs, DORA requirements become part of the overall IT risk management system.

The company must establish ICT risk management, information system security, incident response procedures, infrastructure backup and recovery, and control over critical IT suppliers. ESMA explicitly links MiCA requirements with ICT and digital resilience when authorizing CASPs.

Why preparation is important early

A CASP license is not a formal registration of a cryptocurrency company. The regulator evaluates the business model, corporate governance, capital, AML/CFT, technological infrastructure, and risk management system. Therefore, it is necessary to prepare the legal structure, compliance policy, and IT infrastructure even before submitting an application.

IT-OFFSHORE will help with a CASP license

IT-OFFSHORE assists entrepreneurs in choosing a jurisdiction and preparing a cryptocurrency business structure in the EU. Our specialists will help determine the appropriate operating model, prepare the corporate and regulatory aspects of the project, organize licensing support, and take into account MiCA and DORA requirements.

To improve your experience on our website, we would like to use cookies. This means that we collect some information about your activity while you are on the website.