Training module · European Union · Part 1 of 2
Almost every account of MiCA authorisation starts with the list of ten crypto-asset services and stops there. The list is the easy part. What determines the shape of the application, the capital, the size of the compliance function and how long the whole thing takes is the combination — which services are asked for together, and which authority is asked.
This module is built around that. Select a permission set below and the panel recomputes the prudential floor, the articles that bite, what each service does to the anti-money-laundering function, and — from the register itself — whether any firm in the European Union has actually been authorised for that shape, and by whom.
Part 2 takes a single applicant company through the phases, from the decision to apply to the day the register entry appears.
In summary
- Ten services, 1,023 possible combinations, 81 in actual use. The register records 335 authorisation records across 331 firms. The market occupies about eight per cent of the theoretical space.
- The capital table is a floor, not a budget. Article 67(1) requires the higher of the Annex IV figure and one quarter of the previous year's fixed overheads. For any firm of size, the second limb is the binding one.
- The statutory clock is the same everywhere and is not the real window. Article 63: 25 working days to test completeness, 40 working days to assess, suspensions capped at 20. Where the time actually goes is before the file is submitted.
- The choice of authority is not neutral, and the register shows it: firms authorised in some member states passport across nearly the whole EEA, while others operate almost entirely at home.
The ten services, and why the grouping matters
MiCA Article 3(1)(16) lists the crypto-asset services, lettered (a) to (j). Each carries its own obligations article in Title V, Chapter 3 — Articles 75 to 82 — and each pulls the firm into a minimum capital class under Annex IV.
The grouping is where the design decisions live. Three examples the builder makes visible:
Custody changes the class, and the function. Adding custody (a) to any class 1 permission set moves the firm from EUR 50,000 to EUR 125,000, and brings Article 75 with it: a written custody agreement, a position register per client, segregation, quarterly statements, and liability to the client for lost assets up to market value. It also moves the AML function from monitoring transactions to attributing addresses.
Operating a trading platform changes everything. Service (b) is the only route to class 3, and Article 76 is the longest of the service-specific articles. It is also the rarest permission in the register: 20 firms out of 331. Its Article 76(1)(a) obligation puts customer due diligence into the listing decision, not just the onboarding one — a distinction that catches applicants who have built AML around users alone.
It is heavy enough that at least one group has put it in a separate legal entity. Kraken holds two Irish authorisations, both granted on 25 June 2025: one entity carries eight services — custody, both exchanges, execution, placing, reception and transmission, and transfers — and a second, distinct entity is authorised for the trading platform alone. Ring-fencing the venue from the business that deals on it is a structuring answer to Article 76 and to the conflicts that come with running both.
Exchange for funds and exchange for crypto are the same article and different businesses. Both sit in Article 77. But (c) creates a fiat boundary — a bank account, a payment rail and a named person attaching to a chain address — and (d) does not. A firm holding (d) without (c) is telling its supervisor something specific about where its audit trail begins.
Where the AML function actually meets MiCA
MiCA is not an anti-money-laundering instrument. It says so by omission: the AML obligations sit in the Anti-Money Laundering Directive and its successor package, and the transfer obligations sit in Regulation (EU) 2023/1113. What MiCA does is decide which of those apply to you, by deciding what you are authorised to do.
Three interlocks are worth stating plainly, because applicants routinely treat them as one thing.
The travel rule attaches to transfers, not to the licence. Holding (j) — transfer services — is what makes Regulation (EU) 2023/1113 an operational problem rather than a policy paragraph. Originator and beneficiary information must accompany every transfer regardless of value; the self-hosted wallet assessment bites above EUR 1,000. If the permission set includes (j), the application needs to answer how the messaging works, with whom, and what happens when the counterparty cannot receive.
Market-abuse surveillance is a different pipeline from AML alerting. Article 92 obliges persons professionally arranging or executing transactions to have arrangements to prevent and detect market abuse, and to report suspicion using the STOR template specified in the technical standards. That is a separate system, a separate report, and a separate recipient from a suspicious activity report to the financial intelligence unit. Applicants who describe one system doing both invite a question they usually cannot answer.
Customer due diligence in Article 76 is an admission decision. For a trading platform, the AML question is asked about the asset as well as the customer — and MiCA blocks admission to trading of crypto-assets with built-in anonymisation unless holders and transaction history can be identified.
The statutory clock, and the real one
Article 63 sets the assessment timetable, and it is worth knowing exactly because it is quoted loosely:
| Step | Period | Source |
|---|---|---|
| Completeness assessment | 25 working days from receipt | Art 63(1) |
| Substantive assessment and reasoned decision | 40 working days from receipt of a complete application | Art 63(9) |
| Notification of the decision | 5 working days from the decision | Art 63(9) |
| Suspension while missing information is provided | capped at 20 working days | Art 63 |
Two things follow. The clock only starts on a complete application, so completeness is the applicant's problem and the first real gate. And the regulator's share of the elapsed time is roughly thirteen working weeks — which is not where most of the calendar goes.
The register shows where it does go. Authorisations cluster hard at two moments: 44 in December 2025 and 75 in June 2026. Both spikes have the same cause, and it is not capacity.
MiCA's transitional period let firms already operating under national law continue while they sought authorisation. It expired across the EU on 1 July 2026 — after which, in ESMA's words, "any entity providing crypto-asset services to EU clients without a MiCA licence will be in breach of EU law and must cease offering such services". But member states were permitted to shorten the window, and several did: Germany and Ireland closed theirs on 31 December 2025, and the Netherlands, Poland, Latvia, Hungary and Slovenia allowed six months rather than eighteen.
Put the two together and the register reads as a record of deadlines rather than of demand. The December 2025 cluster is the German and Irish cut-off; the June 2026 cluster is everybody else arriving at the EU-wide one. Anyone planning a timetable should assume the queue is lumpy, and that arriving in it alongside the whole market is a choice with a cost.
What the shapes say about the businesses
Read the register with the letters in mind and the business models become legible without reading a single website.
| Firm | State | Services | What the shape says |
|---|---|---|---|
| Clearstream | LU | a | Custody alone — a central securities depository doing what it already does, in a new asset class |
| Circle · Société Générale FORGE · Standard Chartered | FR, FR, LU | aj | Custody and transfers, no exchange. Hold it and move it; do not make a market in it |
| DekaBank · DZ BANK · MLP · several cooperative banks | DE | e or aej | Execution for existing customers, passported into one state. The domestic banking population behind Germany's median |
| One Trading | NL | ab | A venue plus the custody it needs to run one. Nothing else |
| OKX | MT | abcdefgij | Nine of ten — everything except transfers. The broadest permission in the register |
| MoonPay Europe | NL | cdj | Exchange and transfer, no custody — an on-ramp, not a wallet |
MoonPay's entry is dated 30 December 2024, the first day the regime applied.
Choosing the authority
The statutory process is identical in every member state. The population is not.
Germany has authorised 79 providers, more than twice the next authority, and the firms it authorised have passported into a median of one state. The Netherlands has authorised 28, starting on 30 December 2024 — the first day the regime applied — and its firms have passported into a median of 30. Malta, Luxembourg, Austria, Ireland and Liechtenstein all sit in the high twenties for passporting breadth.
Read carefully, that is a statement about populations rather than about regulators. It does not show that one authority grants broader permissions than another; passporting is a notification, not a grant, and a firm passports because it intends to sell abroad. What it does show is that the authority you choose comes with a peer group, and that peer group tells you what the authority is used to seeing. An applicant proposing pan-EEA distribution through an authority whose entire population trades domestically is not doing anything wrong. It is asking for something unfamiliar, and unfamiliar applications take longer and draw more questions.
The builder makes the specific version of that question answerable: has this authority granted this exact basket before, and how many times?
For the practitioner, and for the person paying for it
The same facts land differently depending on who is reading them, and a training module that only speaks to one of them is half a module.
The practitioner needs to know which articles attach to which permission, what the completeness gate consists of, where the AML and market-abuse pipelines diverge, and which parts of the file the authority will test hardest. The obligations panel in the builder is the checklist for the programme of operations.
The decision-maker needs to know three numbers and one risk. The numbers: the prudential floor the permission set creates, the fixed-overheads limb that will overtake it, and the number of comparable firms the chosen authority has already authorised. The risk: that the permission set has been drawn to match an aspiration rather than a business, and that every additional letter carries an article, a control, a policy and a person for the rest of the firm's life. Permissions are not free to hold. The cheapest sentence in this module is that the application should ask for what the business will do in the first two years, and no more.
What Part 2 will cover
Part 2 is here. A single applicant, followed through: the pre-application decision and the perimeter analysis; assembling the programme of operations; the completeness gate; the substantive assessment and the questions that arrive with it; the AML and market-abuse build in parallel; passporting notifications; and the first supervisory cycle after authorisation. Each phase with the practitioner's task list and the decision-maker's brief alongside it.
Sources
- Regulation (EU) 2023/1114 (MiCA) — Art 3(1)(16) service definitions; Arts 62–63 authorisation and assessment; Art 67 and Annex IV prudential requirements; Arts 75–82 service-specific obligations; Art 92 market abuse
- ESMA register of authorised crypto-asset service providers — snapshot of 24 August 2026: 335 authorisation records, 331 distinct firms, 81 distinct service combinations
- ESMA, Statement on the End of Transitional Periods under MiCA, 17 April 2026 — the 1 July 2026 expiry and the wind-down expectation
- Regulation (EU) 2023/1113 — information accompanying transfers of funds and certain crypto-assets
- ESMA, Final Report — draft technical standards on market abuse under MiCA (December 2024), and the Level 3 Guidelines on prevention and detection of market abuse (29 April 2025). The Commission adopted the market-abuse RTS as a Delegated Regulation on 29 April 2025.
Research and training material, not legal advice. Figures derived from the ESMA register as at 24 August 2026 — re-check the register before relying on a count. The information provided is for research and educational purposes only and does not constitute legal advice.