Financial Institutions and Fintech Licensing in the EU
Comprehensive advisory on financial institution licensing, passporting and regulatory compliance across the European Union and beyond.
A MiCA license (CASP authorization) lets a firm provide crypto-asset services across the EU and EEA under a single, passportable authorization. ECOVIS ProventusLaw guides crypto businesses through CASP licensing in Europe. Contact us for a free initial consultation.
A MiCA license is the authorization a firm needs to provide crypto-asset services in the EU under Regulation (EU) 2023/1114, the Markets in Crypto-Assets (MiCA) Regulation. It applies through a single, passportable rulebook covering two groups: the supply side (offerors, persons seeking admission to trading, and issuers of asset-referenced and e-money tokens) and crypto-asset service providers. The regulation gives the sector legal certainty across the Union, protects holders and market integrity, and supports innovation without regulating the underlying technology itself.
40+
end-to-end FinTech licensing projects since 2014
Top-ranked
FinTech legal team
90+
countries via ECOVIS International
Advising crypto and blockchain businesses since 2014. Contact us for a free initial consultation.
A CASP authorization is required for a business that professionally provides one or more of the following crypto-asset services:
These services cover what were previously known as crypto exchange and crypto wallet operations: a crypto exchange license and a wallet license now fall under a single MiCA CASP authorization. If a platform holds private keys (wallet and custody services), runs a matching engine (an exchange or trading platform), or converts euros into crypto, it needs the license. Which of the ten services you apply for determines your capital class, your ongoing reporting obligations and how closely the regulator supervises you afterward.
Looking for token classification or white paper support instead of a CASP license? See our MiCA compliance and token services.
Classification determines whether authorisation is required, whether a white paper is merely notified or must be formally approved, and which supervisory regime governs the business.
Asset-referenced tokens (ARTs) reference another value or right, or a basket of them, which may include one or more official currencies, and are not e-money tokens. The issuer must be authorised, and the white paper must be approved by the competent authority before the token is offered.
E-money tokens (EMTs) reference a single official currency and are treated as electronic money. The issuer must already be a credit institution or an electronic money institution. The white paper is notified, not approved.
Crypto-assets other than asset-referenced (ARTs) or e-money tokens (EMTs) are the residual category, covering utility tokens and most others. The offeror, or the person seeking admission to trading, draws up, notifies and publishes the white paper. There is no pre-approval, only notification, and the person responsible need not be an issuer in the formal sense.
The boundary between an e-money token and a payment service is contested in practice: the same product can sit under MiCA, under the Payment Services Directive, or under both, and national regulators are actively testing where firms have drawn that line.
The asset remains a crypto-asset, and service provider rules still apply to any regulated services performed on it, but the offer and white-paper obligations fall away for:
These exemptions fall away the moment admission to trading is sought. Structures built on an exemption and later listed on an exchange are a common source of retrospective compliance problems.
Not every issuer files the same document, and the national authority does not “approve” every white paper:
Where a white paper is required, its mandatory contents cover the offeror or issuer; the project; the offer or admission to trading; the crypto-asset itself; the rights and obligations attached to it; the underlying technology; the risks; and the principal adverse climate and other environmental impacts of the consensus mechanism used.
Minimum own funds under MiCA Article 67 are harmonized across the European Union, identical in every member state. Own funds must at all times be the higher of the fixed floor for your service class or one quarter of the previous year’s fixed overheads.
Class 1
€50,000
Advice, portfolio management, reception and transmission of orders, execution of orders, placing, transfer services
Class 2
€125,000
Custody and administration, exchange for funds, exchange for other crypto-assets
Class 3
€150,000
Operation of a trading platform
Firms providing services across more than one class must meet the highest applicable floor. Capital is a continuing condition of authorization, checked throughout the life of the license.
Anti-money-laundering and the Travel Rule. Identity verification for all customers, ongoing transaction monitoring, and reporting of suspicious transactions to the national financial intelligence unit. The Travel Rule under Regulation (EU) 2023/1113 applies to all qualifying crypto-asset transfers regardless of amount, with no minimum threshold. Transfers to and from self-hosted wallets carry additional verification obligations.
Segregation and client asset protection. Client assets must be kept separate from the firm’s own funds, held in a way that protects client rights if the firm becomes insolvent, and not re-used or lent out without the client’s explicit consent. Custody architecture, key management, and the split between hot, warm and cold storage are examined closely at authorization and remain under active supervision. This is one of the areas regulators return to most often once a license is granted.
Governance and substance. Management assessed on competence, reputation and financial soundness. The company needs a registered office in the member state where it provides services, a place of effective management in the EU, and at least one EU-resident director. A real local office is required, not a registered address. Documented risk management, conflicts-of-interest policies, outsourcing controls, and business continuity and wind-down planning.
Ownership screening. Beneficial owners, shareholders and directors are screened for sanctions exposure as a standard part of due diligence. European Union sanctions law has long prohibited Russian nationals and residents of Russia from directly or indirectly owning or controlling, or holding any post in the governing bodies of, an EU crypto-asset service provider. An equivalent restriction for Belarusian nationals and residents applies from 25 August 2026 under Council Regulation (EC) No 765/2006, Article 1u(3), extended to cover the full range of crypto-asset services defined under MiCA. The prohibition does not apply to persons who also hold European Union, EEA or Swiss nationality, or a valid residence permit in one of those states. Unresolved exposure anywhere in the ownership chain will stop an application.
Operational resilience. Since 17 January 2025, crypto-asset service providers have been within the scope of the Digital Operational Resilience Act, with no crypto-specific grace period. Regulators expect a functioning technology risk management framework, incident classification and reporting, resilience testing, and oversight of critical technology suppliers to already be in place at authorization. The European Securities and Markets Authority and national supervisors are examining this actively, with particular attention to custody and key management practices.
Conduct and disclosure. Acting honestly, fairly and professionally in clients’ best interests; fair, clear and non-misleading marketing communications; a working complaints-handling process; and service-specific obligations, including order execution policies, custody agreements and trading platform operating rules.
Authorization in one member state extends across all 30 EEA states. Under MiCA Article 65, the home regulator notifies host state authorities directly; host states are informed, not asked to approve. The right to operate in each additional state flows automatically from the home authorization.
A MiCA license covers crypto-asset services, but not banking. Fiat payment rails are arranged separately, and banking partners assess crypto businesses under their own risk criteria. This is one reason most applicants in Latvia file for a payment authorization alongside the crypto license.
A MiCA license from any EU or EEA state passports across all 30 EEA countries. ECOVIS ProventusLaw is present in the Baltics and has taken clients through authorization and white paper processes with regulators from various European countries.
Contact us for a free initial consultation.
Lithuania has one of the deepest fintech ecosystems in the European Union, built on its payment and electronic money institutions. It was among the first member states to offer crypto businesses a transparent national VASP authorization, and over 370 VASP companies were registered there before MiCA took effect.
Robinhood Europe, UAB was granted the first Lithuanian CASP license under MiCA, in May 2025. The license passports across the European Union, replacing Robinhood’s earlier national VASP registration. ECOVIS ProventusLaw has supported Robinhood’s European operations since 2023, when the entity was first incorporated and registered as a VASP in Lithuania.
The Bank of Lithuania is one of the fastest and most demanding CASP regulators in the EU. Statutory review runs 25 working days for the completeness check and 40 working days for the substantive assessment; in practice, a Lithuanian MiCA license takes three to six months to obtain. The regulator works in English, with clear application templates.
For foreign founders, the structure is simple: a Lithuanian private limited company (UAB) can be 100% foreign-owned, with no local shareholder requirement. The AML officer must be a Lithuanian resident.
The annual supervision fee is a maximum of 0.7% of annual income, minimum €3,000, under the Bank of Lithuania’s 2026 fee schedule. Corporate income tax is 17% from 1 January 2026.
Latvia is currently the most active Baltic route to a MiCA license. Of the ten licenses granted so far, eight were issued between 13 May 2026 and 9 July 2026. Latvijas Banka positions the country as a business-friendly destination for crypto-asset service providers, and Latvia’s national fintech strategy sets an explicit target of growing the number of fintech companies by one third.
The Latvian process runs in two stages. In the pre-licensing consultation stage, Latvijas Banka gives free consultations to prospective applicants, clarifying requirements and advising on how the regulation applies to a business model still in development. The company need not be incorporated yet, and documents may be submitted in English.
In the licensing stage, Latvijas Banka runs a 25-working-day completeness check followed by a 40-working-day substantive assessment. The review may be extended if the file does not support a decision. Latvijas Banka’s own indicative average is around three months; allowing for the preparation before a file is submitted, a realistic timeline from first engagement to a Latvian MiCA license is four to six months.
Latvia requires a physical office (virtual offices are not permitted), a dedicated AML officer with working KYC and KYT systems, and a board of two to three directors with at least one EU-resident director, a Latvian resident being an advantage. The full documentation set includes a business plan, IT security framework, business continuity plan, and internal control procedures.
The application fee is €2,500, among the lowest in the European Union, and the annual supervision fee under MiCA Article 63 is 0.6% of gross revenue, minimum €3,000. Under Latvia’s corporate income tax regime, 0% applies to undistributed or reinvested profit, with 20% due on distribution. Most applicants file for more than one authorization at once, so that fiat and crypto flows sit under a single roof rather than relying on a separate payment partner.
ECOVIS ProventusLaw guided Backpack EU (Trek Technologies SIA) through the full MiCA CASP licensing process at Latvijas Banka, with the license granted in May 2026.
Estonia runs a fully digital administrative environment: company formation and government filings are handled online, and its e-Residency programme lets non-residents establish and manage an Estonian company remotely. CASP licenses are issued by Finantsinspektsioon, Estonia’s financial supervisor. The applicant is an Estonian-registered legal entity, typically a private limited company (OÜ), with a registered office in Estonia.
The application is filed in Estonian, though supporting documents may be submitted in English if stated in the application. The state application fee is €3,000, and the statutory MiCA review periods apply.
Under Estonia’s corporate tax model, retained and reinvested profit is taxed at 0%. Corporate income tax of 22% falls due only when profit is distributed as dividends.
The best jurisdiction depends on your business model, governance structure, substance requirements, banking needs and intended services. Lithuania, Latvia and Estonia each offer different advantages.
Lithuania
Regulator: Bank of Lithuania
Timeline: 3–6 months
Local office: registered office
Language: English
Corporate tax: 17%
Latvia
Regulator: Latvijas Banka
Application fee: €2,500
Timeline: 4–6 months
Local office: physical office
Language: English / Latvian
Corporate tax: 0% / 20% on distribution
Estonia
Regulator: Finantsinspektsioon
Application fee: €3,000
Timeline: 3–6 months
Local office: registered office
Language: Estonian
Corporate tax: 0% / 22% on distribution
Advised on MiCA CASP authorisation with Latvijas Banka, covering custody, exchange, order execution, and transfer services, with EU passporting across all 30 EEA states. The engagement spanned the complete application package, governance and ICT architecture, e-money token regulatory boundary analysis (MiCA vs PSD2), and integration of a multinational group structure across Latvia, Lithuania, Cyprus, UAE, and BVI into a single MiCA-compliant operating model.
Advised on the preparation and notification of a MiCA-compliant crypto-asset white paper in the EU for the Backpack token, filed with the Bank of Lithuania. The engagement covered the end-to-end structuring of the white paper, assessment of the token and offering model under MiCA, and regulatory engagement throughout the notification process, supporting the proposed EU-wide offering of the token.
Advised on obtaining one of the first MiCA crypto-asset white paper approvals in the EU, filed with the Central Bank of Ireland. The engagement covered end-to-end white paper structuring, jurisdictional strategy, and full regulatory engagement through to approval, enabling a regulated EU-wide token offering.
Advised on one of the first MiCA crypto-asset white paper notifications filed with the Bank of Lithuania, enabling EU-wide token offering and admission to trading. The engagement covered end-to-end white paper structuring and submission, regulatory communications, and iterative supervisory feedback.
Advised on obtaining MiCA white paper approval from the Central Bank of Ireland, enabling EU-wide token offering and distribution. The engagement covered full white paper preparation and submission for a technically complex token structure. Notably, the Central Bank requested no amendments, reflecting the quality of the submission.
Advised Lithuania-based crypto-asset businesses on restructuring legacy VASP frameworks into full MiCA CASP compliance, and on remediation following a Bank of Lithuania request to withdraw an initial application. The work covered gap analysis, redesign of governance, custody infrastructure, outsourcing and ICT governance, and organisational substance, towards materially strengthened resubmissions.
Have a question or need more information?
Send us an email!