Which services should be licensed under MiCA?
Starting from 30 December 2024, operating in the EU without an MiCA license will no longer be an option for many. Companies involved in custodial wallets, crypto exchanges, or portfolio management will be required to obtain authorization as a Crypto-Asset Service Provider (CASP). A misstep in the legal qualification of services can come at a high cost, from forced shutdowns to multimillion-euro fines. The line between a “technical feature” and a “regulated service” is often unclear. In this article, we will explain which services require a MiCA license, what this means in practice, and how to avoid the key compliance risks.
What is MiCA and who does it apply to?
Regulation (EU) 2023/1114, known as MiCA (Markets in Crypto-Assets Regulation), is the first comprehensive legal framework adopted by the European Union to regulate crypto-assets that are not already covered by existing financial directives, such as MiFID II or PSD2. The regulation was adopted in June 2023 and enters into force in two phases:
- From 30 June 2024 – for issuers of e-money tokens (EMTs) and asset-referenced tokens (ARTs);
- From 30 December 2024 – for crypto-asset service providers (CASPs).
MiCA pursues several key objectives: protecting consumers and investors, ensuring financial stability within the EU market, and promoting innovation through legal certainty.
Unlike fragmented national regulations, MiCA introduces a single licensing regime applicable across the entire European Union. This means that a CASP license granted in any EU Member State is valid throughout the EU.
The regulation applies to both legal and natural persons if they provide regulated crypto-asset services within the EU or offer crypto-assets to users located in the EU, regardless of the provider’s jurisdiction.
What types of crypto-assets fall under MiCA?
MiCA covers three primary categories of crypto-assets, as defined in Article 3 of the Regulation:
- Asset-referenced tokens (ARTs) – tokens backed by a basket of assets (such as fiat currencies, precious metals, or cryptocurrencies) that aim to maintain a stable value.
- E-money tokens (EMTs) – tokens denominated in a single official currency, designed for use as a means of payment, similar to electronic money.
- Other crypto-assets – all other digital assets transferred using distributed ledger technology (DLT), including utility tokens that do not fall under ART or EMT classifications.
MiCA does not apply to the following assets:
- Non-fungible tokens (NFTs) – provided they are truly unique and not part of a larger collection (Recital 10);
- Central Bank Digital Currencies (CBDCs) – issued by central banks;
- Security tokens – which fall under existing EU securities legislation;
- Decentralised protocols – where no identifiable legal entity is responsible;
- Issuers with an annual offering volume below EUR 1 million (Article 2(4)).
Who supervises MiCA compliance?
MiCA establishes a multi-tiered supervisory structure. Primary oversight and enforcement are conducted by the National Competent Authorities (NCAs) of each EU Member State. These authorities are responsible for granting CASP licenses and monitoring compliance with operational and prudential requirements.
For significant ART and EMT issuers that may impact financial stability, supervision is transferred to the European Banking Authority (EBA). Additionally, the European Securities and Markets Authority (ESMA) is responsible for developing technical standards, coordinating national regulators, and maintaining centralized registers of authorized CASPs and white papers.
What services are regulated under MiCA?
According to Annex I and Article 59 of the MiCA Regulation, any company providing certain types of crypto-asset services is required to obtain the status of a Crypto-Asset Service Provider (CASP). This licensing obligation applies throughout the EU and has been in force since 30 December 2024.
MiCA identifies 10 types of services that require authorisation:
- Custody and administration of crypto-assets on behalf of third parties – custodial wallets, access to private keys, and storage infrastructure.
- Operation of a trading platform – centralized interfaces through which users can place buy and sell orders.
- Exchange of crypto-assets for fiat currency – traditional exchange platforms and brokerage interfaces.
- Exchange of one crypto-asset for another – decentralized or centralized token swaps without fiat involvement.
- Execution of orders on behalf of clients – brokerage activity involving execution of transactions in the interest of third parties.
- Placing of crypto-assets – offering tokens to potential buyers on behalf of the issuer, similar to investment underwriting.
- Reception and transmission of orders – handling instructions for crypto-asset transactions.
- Providing advice on crypto-assets – recommending actions regarding the purchase, sale, or custody of crypto-assets.
- Portfolio management of crypto-assets – making decisions about crypto-assets on behalf of clients under a discretionary mandate.
- Transfer services for crypto-assets on behalf of third parties – transferring assets between wallets when the user is not the direct initiator.
Even if a company provides just one of these services, it is subject to mandatory licensing
Specifics of service qualification
Determining whether an activity falls under MiCA licensing requirements is not always obvious. The Regulation uses legal definitions similar to those applied in traditional capital markets. Therefore, business models that appear to be “technical solutions” or “not directly related to custody or trading” may, in practice, meet the criteria of regulated services.
For example, a developer of a custodial wallet with key management functionality may be classified as a custody service provider. A platform that allows users to interact via smart contracts may qualify as a trading venue if it involves a centralized interface.
The core test is not the technical implementation, but the functional substance — whether the service enables users to perform activities listed under the regulated categories, and whether there is a legally accountable entity behind the operation.
To make a more accurate assessment, businesses are advised to conduct a legal review of their model, review the official guidance issued by ESMA and EBA, and engage specialized legal counsel to evaluate potential risks and determine whether licensing is required under MiCA.
Who needs a MiCA license?
The MiCA Regulation requires all crypto-asset service providers to obtain a license if they intend to operate within the territory of the European Union. This applies both to companies established in EU Member States and to entities from third countries if their services are targeted at users in the EU.
Licensing is mandatory for:
- Legal entities incorporated in the EU, if they provide at least one of the 10 services listed in Annex I to MiCA;
- Non-EU companies wishing to operate in the EU — in this case, they must establish a branch and obtain a license in one of the EU Member States;
- Startups and fintech companies offering decentralized solutions, particularly those with centralized governance, monetization, or control over user assets.
It is further emphasized that even a single interface, such as a web platform or mobile application, through which EU-based users can access crypto services may qualify as "providing a service" within the Union.
Who may be exempt from licensing?
MiCA sets out a limited list of exemptions under which a company may be relieved from the obligation to obtain CASP status:
- Small CASPs – if their annual turnover from crypto-asset services does not exceed EUR 150,000 (Article 60). In such cases, the company may only operate in its home country and cannot offer services across borders.
- Credit institutions (banks) are already licensed under the CRD IV Directive. These banks may provide crypto-asset services similar to their traditional activities without separate MiCA authorisation.
- Certain electronic money institutions and payment service providers, provided they operate within the scope of their existing licenses and offer only EMTs (e-money tokens that are treated as equivalent to traditional e-money).
Legal and compliance risks of operating without a MiCA license
Engaging in activities covered by MiCA without the appropriate CASP license is considered the unlawful provision of regulated financial services. A company operating without authorisation may face administrative penalties, suspension of operations, and sanctions against its management.
According to Article 63 of MiCA, national supervisory authorities have the power to:
- Immediately prohibit the performance of unlicensed activities within the EU;
- Block access to platforms or online interfaces that breach regulatory requirements;
- Order the cessation of advertising and client outreach directed at EU residents.
Under Article 97, violations of licensing requirements may lead to administrative fines and other sanctions as established by the national legislation of each Member State. In some jurisdictions, such breaches are treated as serious financial offences.
In addition to formal penalties, companies that violate MiCA’s licensing regime face long-term reputational and business risks:
- Loss of access to banking and financial partners in the EU. Without official CASP status, banks often refuse to provide account services or process transactions.
- Risk of website and service blockage. Regulators may request that internet service providers restrict access to unlicensed platforms.
- Challenges with future registration. Companies flagged for prior violations frequently face rejection when applying for licenses later.
- Loss of client and investor trust. A MiCA license is not just a legal requirement — it acts as a mark of credibility and compliance with EU standards.
Even companies acting in good faith but failing to secure CASP authorisation in time risk being excluded from the European crypto ecosystem before launching full-scale operations.
How to determine whether your service needs licensing
One of the most complex challenges for crypto businesses is determining whether their activities fall under MiCA regulation. Many projects mistakenly assume that if they do not directly handle custody functions or trading operations, they are not subject to CASP licensing. In reality, what matters is not the name of the service or its technical implementation, but the legal nature of the function being provided.
Regulators assess what the company does: whether it receives user assets, provides access to trading functionalities, or executes transactions on behalf of clients. Even actions such as building an interface for a decentralized exchange or integrating a token transfer module can be classified as licensable activities.
MiCA applies a functional approach: if the activity corresponds to one of the 10 service categories listed in Annex I, it requires a license, regardless of how the service is delivered or technically structured.
Where should crypto businesses begin?
To determine whether CASP status is required, companies should begin with a formal legal self-assessment. This process includes:
- Analysing the business model and platform functionalities — what actions are performed by the user, which transactions are initiated by the company, and who controls keys, assets, orders, and interfaces.
- Mapping these functions to the list of regulated services under MiCA — based on Annex I and related regulatory guidance.
- Identifying the presence of centralized control — whether there is a legal entity managing the service, its code, or its commercial operation.
- Assessing geographical targeting — whether the company offers services to EU-based users directly or indirectly (via marketing, targeting, interface language, etc.).
It is also essential to consider plans: service expansion, the launch of new products, or creation of white-label solutions may all impact the need for licensing.
How Key2Law can help you navigate MiCA licensing
If you are planning to enter the EU market with a crypto product, whether it’s a wallet, platform, interface, or token transfer service — it is essential to understand the licensing requirements and regulatory risks in advance. The Key2Law team provides full-cycle regulatory support under the MiCA Regulation, from business model assessment to obtaining CASP authorization.
What we offer our clients:
- Comprehensive qualification of your activities. We conduct a detailed review of your product, determine which specific functions fall under MiCA regulation, and deliver a formal regulatory opinion with substantiation for each category of service.
- Preparation and submission of the CASP license application. We develop and tailor all required documentation, including the AML policy, IT infrastructure description, internal procedures, financial model, and corporate structure. When needed, we handle communications with regulators and respond to requests for clarification or amendments.
- Support during the MiCA implementation process. The transitional period requires not only formal compliance but also practical adaptation of internal processes. We help establish internal controls, ensure regulatory compliance, train your team, and minimize the risk of regulatory friction.
Key2Law is a reliable partner with hands-on experience in crypto regulation. We help companies not only obtain CASP licensing but also successfully integrate into the EU legal ecosystem with minimal risk and maximum efficiency. Contact us right now for a professional assessment of your case and begin your MiCA licensing journey without delays.