MiCA CASP authorization requirements: Class 1/2/3 capital (€50k to €150k), fit and proper governance, AML/KYC, DORA ICT security and client protection.
The fit and proper test assesses whether directors, senior managers, and significant shareholders have the knowledge, skills, experience, and integrity required for their role. NCAs evaluate: absence of criminal convictions, relevant professional experience, financial soundness, and sufficient time commitment. The assessment applies to the management body collectively and individually.
MiCA requires that CASPs be established in an EU member state, but the level of local substance required varies by NCA. Lithuania's Bank of Lithuania historically required a CEO, CCO, and MLRO to be physically present. Other NCAs such as Malta's MFSA accept outsourcing of certain functions. Your chosen NCA's substance requirements should factor into jurisdiction selection.
The Digital Operational Resilience Act (DORA, EU 2022/2554) applies to CASPs from January 17, 2025. DORA requires ICT risk management frameworks, regular digital operational resilience testing, incident reporting within 4 hours for significant events, and third-party ICT provider oversight. MiCA applications must demonstrate DORA alignment, typically through a dedicated ICT security annex.
Yes. MiCA Article 67(3) allows CASPs to hold professional indemnity insurance (PII) covering liability in the territories where services are provided as an alternative to a portion of the minimum capital requirement. The PII must cover at least €1 million per claim and €1.5 million annually for Class 1 CASPs. Check with your target NCA for the specific coverage requirements they accept.
Enable JavaScript for the full interactive page. Canonical URL: https://micahub.net/mica-casp-license/requirements/