Skip to content
← Dossiers

Training module · European Union · Part 1 of 2

MiCA: building the permission set

August 2026·EU
MiCACASPAuthorisationAMLTraining

Training module · European Union · Part 1 of 2

Almost every account of MiCA authorisation starts with the list of ten crypto-asset services and stops there. The list is the easy part. What determines the shape of the application, the capital, the size of the compliance function and how long the whole thing takes is the combination — which services are asked for together, and which authority is asked.

This module is built around that. Select a permission set below and the panel recomputes the prudential floor, the articles that bite, what each service does to the anti-money-laundering function, and — from the register itself — whether any firm in the European Union has actually been authorised for that shape, and by whom.

Part 2 takes a single applicant company through the phases, from the decision to apply to the day the register entry appears.

In summary

  • Ten services, 1,023 possible combinations, 81 in actual use. The register records 335 authorisation records across 331 firms. The market occupies about eight per cent of the theoretical space.
  • The capital table is a floor, not a budget. Article 67(1) requires the higher of the Annex IV figure and one quarter of the previous year's fixed overheads. For any firm of size, the second limb is the binding one.
  • The statutory clock is the same everywhere and is not the real window. Article 63: 25 working days to test completeness, 40 working days to assess, suspensions capped at 20. Where the time actually goes is before the file is submitted.
  • The choice of authority is not neutral, and the register shows it: firms authorised in some member states passport across nearly the whole EEA, while others operate almost entirely at home.

The ten services, and why the grouping matters

MiCA Article 3(1)(16) lists the crypto-asset services, lettered (a) to (j). Each carries its own obligations article in Title V, Chapter 3 — Articles 75 to 82 — and each pulls the firm into a minimum capital class under Annex IV.

The grouping is where the design decisions live. Three examples the builder makes visible:

Custody changes the class, and the function. Adding custody (a) to any class 1 permission set moves the firm from EUR 50,000 to EUR 125,000, and brings Article 75 with it: a written custody agreement, a position register per client, segregation, quarterly statements, and liability to the client for lost assets up to market value. It also moves the AML function from monitoring transactions to attributing addresses.

Operating a trading platform changes everything. Service (b) is the only route to class 3, and Article 76 is the longest of the service-specific articles. It is also the rarest permission in the register: 20 firms out of 331. Its Article 76(1)(a) obligation puts customer due diligence into the listing decision, not just the onboarding one — a distinction that catches applicants who have built AML around users alone.

It is heavy enough that at least one group has put it in a separate legal entity. Kraken holds two Irish authorisations, both granted on 25 June 2025: one entity carries eight services — custody, both exchanges, execution, placing, reception and transmission, and transfers — and a second, distinct entity is authorised for the trading platform alone. Ring-fencing the venue from the business that deals on it is a structuring answer to Article 76 and to the conflicts that come with running both.

Exchange for funds and exchange for crypto are the same article and different businesses. Both sit in Article 77. But (c) creates a fiat boundary — a bank account, a payment rail and a named person attaching to a chain address — and (d) does not. A firm holding (d) without (c) is telling its supervisor something specific about where its audit trail begins.

Where the AML function actually meets MiCA

MiCA is not an anti-money-laundering instrument. It says so by omission: the AML obligations sit in the Anti-Money Laundering Directive and its successor package, and the transfer obligations sit in Regulation (EU) 2023/1113. What MiCA does is decide which of those apply to you, by deciding what you are authorised to do.

Three interlocks are worth stating plainly, because applicants routinely treat them as one thing.

The travel rule attaches to transfers, not to the licence. Holding (j) — transfer services — is what makes Regulation (EU) 2023/1113 an operational problem rather than a policy paragraph. Originator and beneficiary information must accompany every transfer regardless of value; the self-hosted wallet assessment bites above EUR 1,000. If the permission set includes (j), the application needs to answer how the messaging works, with whom, and what happens when the counterparty cannot receive.

Market-abuse surveillance is a different pipeline from AML alerting. Article 92 obliges persons professionally arranging or executing transactions to have arrangements to prevent and detect market abuse, and to report suspicion using the STOR template specified in the technical standards. That is a separate system, a separate report, and a separate recipient from a suspicious activity report to the financial intelligence unit. Applicants who describe one system doing both invite a question they usually cannot answer.

Customer due diligence in Article 76 is an admission decision. For a trading platform, the AML question is asked about the asset as well as the customer — and MiCA blocks admission to trading of crypto-assets with built-in anonymisation unless holders and transaction history can be identified.

The statutory clock, and the real one

Article 63 sets the assessment timetable, and it is worth knowing exactly because it is quoted loosely:

StepPeriodSource
Completeness assessment25 working days from receiptArt 63(1)
Substantive assessment and reasoned decision40 working days from receipt of a complete applicationArt 63(9)
Notification of the decision5 working days from the decisionArt 63(9)
Suspension while missing information is providedcapped at 20 working daysArt 63

Two things follow. The clock only starts on a complete application, so completeness is the applicant's problem and the first real gate. And the regulator's share of the elapsed time is roughly thirteen working weeks — which is not where most of the calendar goes.

The register shows where it does go. Authorisations cluster hard at two moments: 44 in December 2025 and 75 in June 2026. Both spikes have the same cause, and it is not capacity.

MiCA's transitional period let firms already operating under national law continue while they sought authorisation. It expired across the EU on 1 July 2026 — after which, in ESMA's words, "any entity providing crypto-asset services to EU clients without a MiCA licence will be in breach of EU law and must cease offering such services". But member states were permitted to shorten the window, and several did: Germany and Ireland closed theirs on 31 December 2025, and the Netherlands, Poland, Latvia, Hungary and Slovenia allowed six months rather than eighteen.

Put the two together and the register reads as a record of deadlines rather than of demand. The December 2025 cluster is the German and Irish cut-off; the June 2026 cluster is everybody else arriving at the EU-wide one. Anyone planning a timetable should assume the queue is lumpy, and that arriving in it alongside the whole market is a choice with a cost.

What the shapes say about the businesses

Read the register with the letters in mind and the business models become legible without reading a single website.

FirmStateServicesWhat the shape says
ClearstreamLUaCustody alone — a central securities depository doing what it already does, in a new asset class
Circle · Société Générale FORGE · Standard CharteredFR, FR, LUajCustody and transfers, no exchange. Hold it and move it; do not make a market in it
DekaBank · DZ BANK · MLP · several cooperative banksDEe or aejExecution for existing customers, passported into one state. The domestic banking population behind Germany's median
One TradingNLabA venue plus the custody it needs to run one. Nothing else
OKXMTabcdefgijNine of ten — everything except transfers. The broadest permission in the register
MoonPay EuropeNLcdjExchange and transfer, no custody — an on-ramp, not a wallet

MoonPay's entry is dated 30 December 2024, the first day the regime applied.

Choosing the authority

The statutory process is identical in every member state. The population is not.

Germany has authorised 79 providers, more than twice the next authority, and the firms it authorised have passported into a median of one state. The Netherlands has authorised 28, starting on 30 December 2024 — the first day the regime applied — and its firms have passported into a median of 30. Malta, Luxembourg, Austria, Ireland and Liechtenstein all sit in the high twenties for passporting breadth.

Read carefully, that is a statement about populations rather than about regulators. It does not show that one authority grants broader permissions than another; passporting is a notification, not a grant, and a firm passports because it intends to sell abroad. What it does show is that the authority you choose comes with a peer group, and that peer group tells you what the authority is used to seeing. An applicant proposing pan-EEA distribution through an authority whose entire population trades domestically is not doing anything wrong. It is asking for something unfamiliar, and unfamiliar applications take longer and draw more questions.

The builder makes the specific version of that question answerable: has this authority granted this exact basket before, and how many times?

For the practitioner, and for the person paying for it

The same facts land differently depending on who is reading them, and a training module that only speaks to one of them is half a module.

The practitioner needs to know which articles attach to which permission, what the completeness gate consists of, where the AML and market-abuse pipelines diverge, and which parts of the file the authority will test hardest. The obligations panel in the builder is the checklist for the programme of operations.

The decision-maker needs to know three numbers and one risk. The numbers: the prudential floor the permission set creates, the fixed-overheads limb that will overtake it, and the number of comparable firms the chosen authority has already authorised. The risk: that the permission set has been drawn to match an aspiration rather than a business, and that every additional letter carries an article, a control, a policy and a person for the rest of the firm's life. Permissions are not free to hold. The cheapest sentence in this module is that the application should ask for what the business will do in the first two years, and no more.

What Part 2 will cover

Part 2 is here. A single applicant, followed through: the pre-application decision and the perimeter analysis; assembling the programme of operations; the completeness gate; the substantive assessment and the questions that arrive with it; the AML and market-abuse build in parallel; passporting notifications; and the first supervisory cycle after authorisation. Each phase with the practitioner's task list and the decision-maker's brief alongside it.

Sources


Research and training material, not legal advice. Figures derived from the ESMA register as at 24 August 2026 — re-check the register before relying on a count. The information provided is for research and educational purposes only and does not constitute legal advice.

Build the permission set

Select the crypto-asset services the business will provide. Everything below recomputes from the text of Regulation (EU) 2023/1114 and from the ESMA register as it stood on 24 August 2026.

Nothing selected. Of the 1,023 possible combinations of these ten services, just 81 appear anywhere in the register — across 335 authorisation records. The space is far larger than the market.

Service definitions, articles and capital classes: Regulation (EU) 2023/1114, Art 3(1)(16), Arts 67 and 75–82, Annex IV. Population figures derived from the ESMA register of authorised CASPs, snapshot 24 August 2026 335 authorisation records. Re-check the register before relying on a count.

Working on a matter this touches?

Start a conversation