Skip to content

CASP under MiCA: What Crypto-Asset Service Providers Need to Know

  • by
CASP under MiCA: What Crypto-Asset Service Providers Need to Know

The crypto market is gradually moving away from the “launch quickly — figure it out later” approach. For companies from Kazakhstan, Uzbekistan, Georgia and Kyrgyzstan that work with clients, partners or infrastructure in Europe, the topic of CASP under MiCA is becoming not just legal news, but a practical issue of market access, trust and sustainable growth.

MiCA is the European regulation on markets in crypto-assets. It establishes uniform rules for the issuance of crypto-assets and the provision of related services in the EU. A separate set of requirements applies to CASPs — Crypto-Asset Service Providers, meaning companies that professionally provide services involving crypto-assets. The MiCA Regulation was adopted as Regulation (EU) 2023/1114, and ESMA describes it as the basis for a unified set of rules for crypto-assets in the EU.

Who Is Considered a CASP

If a company helps clients buy, sell, store, transfer or exchange crypto-assets, it may potentially fall under CASP status. In simple terms, a crypto-asset service provider is not only a large exchange with millions of users. It may also be a custodial service, brokerage platform, exchange service, trading platform operator or a company that executes client orders.

The CASP category may include companies that provide services such as:

  • custody and administration of crypto-assets on behalf of clients;
  • exchange of crypto-assets for money or other crypto-assets;
  • execution of orders for crypto-assets;
  • placing of crypto-assets;
  • operation of a trading platform for crypto-assets;
  • advice and portfolio management relating to crypto-assets.

For businesses from Central Asia and the Caucasus, this is important even if the company is not physically located in the EU. If it plans to serve European clients, attract partners from the EU or enter the European market, MiCA for crypto businesses becomes part of strategic planning.

What CASP Authorisation Means

CASP authorisation is permission that allows a company to legally provide crypto-asset services within the EU. Under MiCA, a company must demonstrate that it has a clear governance structure, a transparent business model, sufficient internal policies, risk controls, protection of client assets and mechanisms for regulatory compliance.

It is important not to confuse authorisation with a mere formal document. The regulator assesses not an attractive presentation, but the company’s actual ability to operate in a controlled environment. It is similar to a vehicle inspection: you can wash the bodywork and add a logo, but if the brakes do not work, you will not get very far.

CASP Licensing: What Is Checked

CASP лицензированиеCASP licensing usually requires comprehensive preparation. Companies need to describe which services they provide, where their clients are located, how their IT systems are organised, who manages the business, how risks are controlled and what happens in the event of disruptions.

In practice, attention is usually focused on several areas:

  • corporate governance and management experience;
  • AML/CFT procedures and customer due diligence;
  • protection of client assets;
  • information security and cyber resilience;
  • management of conflicts of interest;
  • complaints handling procedures;
  • transparency of communications with clients.

ESMA has also emphasised the importance of a consistent approach to CASP authorisation across the EU and warned about the risks of companies using regulated status in a way that may lead clients to misunderstand which products are actually covered by MiCA.

MiCA Compliance: Not Just for Lawyers

MiCA compliance is not a task for a single lawyer who can “finish writing the policy on Friday evening”. For a crypto business, it is cross-functional work involving management, finance, security, the product team, operations managers and compliance.

A company should assess in advance:

  • which services fall under MiCA;
  • whether registration or full authorisation is required;
  • whether internal processes meet the regulator’s requirements;
  • how operations and decisions are documented;
  • whether employees are ready to work under the new rules;
  • how clear client notices and agreements are.

For companies from Kazakhstan, Uzbekistan, Georgia and Kyrgyzstan, a separate issue is the alignment of local regulation with European requirements. For example, a business may be legally registered in its own jurisdiction, but this may not be sufficient to work with EU clients.

Why This Matters for Businesses Outside the EU

MiCA is gradually becoming a benchmark not only for the European market. Partners, banks, payment providers, investors and institutional clients are increasingly looking for a clear compliance system. Even if a company is not yet applying for a licence, readiness for MiCA requirements strengthens its negotiating position.

For entrepreneurs, this means several practical advantages. First, it reduces the risk of the sudden blocking of partner relationships. Second, it creates a clearer scaling model. Third, the company can prepare its processes in advance instead of having to rebuild the business in emergency mode.

Where to Start Preparation

The best first step is to carry out a gap analysis: to compare the company’s current processes with MiCA requirements. This analysis helps identify where everything is already in order and where documents, training, changes to IT systems or stronger controls are needed.

It is useful to move step by step:

  • define the list of crypto-asset services;
  • describe target markets and client categories;
  • review AML, KYC and sanctions procedures;
  • assess the protection of client assets;
  • prepare risk management policies;
  • train the team on MiCA requirements;
  • create a roadmap for authorisation.

This approach saves time and budget. Instead of collecting documents chaotically, the company gets a clear plan: what needs to be fixed now, what should be prepared for the application and which processes must be maintained on an ongoing basis.

The Role of Consultants and Training

For many companies, the complexity of MiCA lies not in one specific requirement, but in how the requirements are connected. Legal rules, operational processes, cyber security, risk management and client communication must work as a single system. If one element fails, the whole structure becomes vulnerable.

On our website isocerthub.com , preparation for MiCA can be seen as part of a mature management system: not as a tick-box exercise, but as a way to build clear processes, partner trust and long-term access to markets.

Leave a Reply

Your email address will not be published. Required fields are marked *

EN