A CASP authorisation application is not only a collection of policies submitted to a regulator. It must demonstrate that the applicant has a viable business model, effective EU governance, suitable management, adequate prudential safeguards and operational controls capable of supporting the crypto-asset services included in the application.
The strongest applications connect the regulatory documents with real systems, responsibilities, customer journeys and decision-making arrangements. The applicant should be able to explain not only what its policies require, but also who performs each control, which information is used, how exceptions are escalated and what evidence demonstrates that the framework operates in practice.
CASP readiness at a glance
- Define the exact crypto-asset services and regulatory perimeter.
- Establish credible governance and operational substance in the home Member State.
- Build an evidence-based programme of operations and financial plan.
- Implement AML/CFT, Travel Rule and sanctions controls.
- Demonstrate DORA-aligned ICT governance and operational resilience.
- Prepare service-specific procedures, safeguarding arrangements and passporting plans.
1. Define the services before preparing the application
The first step is to identify which MiCA crypto-asset services the business will actually provide. The authorisation scope determines the capital requirement, policies, systems, competencies and service-specific information that must be included in the application.
The analysis should cover:
- custody and administration of crypto-assets,
- operation of a trading platform,
- exchange of crypto-assets for funds or other crypto-assets,
- execution, reception and transmission of orders,
- placing of crypto-assets,
- advice or portfolio management,
- transfer services on behalf of clients,
- activities that remain outside MiCA or fall under another regulatory framework.
The service map should follow the complete customer journey and technical flow. Marketing terminology alone is not sufficient. A business describing itself as a wallet, broker, gateway, exchange or technology platform may perform several regulated services within one operating model.
2. Select the home Member State based on substance, not convenience
The application is submitted to the competent authority of the applicant’s home Member State. The selected jurisdiction should correspond to the applicant’s legal establishment, management and actual operating model rather than being chosen only because the authorisation process appears faster.
The applicant should be able to demonstrate:
- effective decision-making within the authorised EU entity,
- management capable of independently governing EU operations,
- sufficient locally controlled staff, systems and expertise,
- direct access to records and outsourced activities,
- the ability of the competent authority to supervise the complete operation,
- that the entity is not a letter-box structure controlled operationally from another jurisdiction.
Passporting does not remove the need for substance
A CASP can serve clients across the EU after authorisation and notification, but the home entity must remain capable of governing, controlling and explaining the business provided throughout the Union.
3. Build a credible programme of operations
The programme of operations should describe what the applicant intends to do, where the services will be offered and how the operating model supports the proposed scale. It should be consistent with the financial forecasts, staffing plan, ICT architecture and outsourcing model.
It should normally explain:
- target clients, products and distribution channels,
- countries and customer segments covered by the strategy,
- transaction and customer-volume assumptions,
- revenue sources, fees and key business dependencies,
- customer onboarding and service-delivery flows,
- use of group companies and external providers,
- staffing and control-function development,
- financial projections and stress assumptions.
Inconsistencies are likely to attract regulatory challenge. A business forecasting rapid cross-border growth should not rely on a minimal management team, untested systems or undefined compliance capacity.
4. Establish governance and fit-and-proper evidence
Members of the management body must collectively possess the knowledge, skills and experience needed to manage the proposed CASP. They must also be of sufficiently good repute and capable of dedicating enough time to their responsibilities.
A readiness pack should include:
- governance structure and reporting lines,
- role descriptions and allocation of responsibilities,
- management and committee terms of reference,
- individual and collective suitability evidence,
- time-commitment assessments,
- conflict-of-interest declarations,
- shareholder and qualifying-holding information,
- management information and escalation arrangements.
5. Calculate and evidence prudential safeguards
CASPs must maintain prudential safeguards equal to at least the higher of the applicable permanent minimum-capital requirement or one quarter of the preceding year’s fixed overheads.
Class 1
EUR 50,000
Includes services such as advice, order reception and transmission, execution, placing and transfer services.
Class 2
EUR 125,000
Includes Class 1 services together with custody or exchange of crypto-assets.
Class 3
EUR 150,000
Applies where the CASP operates a crypto-asset trading platform.
The applicant should document the calculation, forecasts, monitoring process and form of protection, which may consist of own funds, qualifying insurance or a combination permitted under MiCA.
6. Implement an operational AML/CFT framework
The AML framework should be proportionate to the services, customer population, geographies, crypto-assets and transaction flows described in the business plan. A generic AML policy that does not reflect the platform architecture or customer journey will not demonstrate operational readiness.
The framework should connect:
- business-wide and customer-level ML/TF risk assessments,
- KYC, KYB and beneficial-ownership verification,
- customer-risk classification and Enhanced Due Diligence,
- PEP, sanctions and adverse-information screening,
- blockchain analytics and transaction monitoring,
- investigation, escalation and suspicious-activity reporting,
- record keeping, training and quality assurance,
- management reporting and periodic framework review.
7. Design the Travel Rule operating model
The Travel Rule requires transfers of crypto-assets involving a CASP to be accompanied by specified information concerning the originator and beneficiary. The CASP also needs procedures for detecting and managing transfers with missing or incomplete information.
Readiness should address:
- collection and verification of originator and beneficiary information,
- exchange of information with other CASPs,
- interoperability and failure handling between Travel Rule solutions,
- transfers involving self-hosted addresses,
- assessment of ownership or control for relevant transfers above EUR 1,000,
- procedures to execute, suspend, reject or return transfers,
- sanctions, AML and transaction-monitoring integration,
- data protection, retention and audit trails.
The Travel Rule is an operating process, not only a technology purchase
Technology can transmit data, but the CASP must still decide whether information is complete, whether parties and addresses create additional risk and what action should be taken when a transfer cannot be processed normally.
8. Demonstrate DORA-aligned operational resilience
Authorised CASPs fall within the scope of DORA. ICT governance should therefore be treated as part of the authorisation operating model rather than as a separate technical project completed after the licence is granted.
The readiness programme should cover:
- ICT risk governance and management-body responsibility,
- asset, system and dependency inventories,
- information security and access management,
- incident classification, escalation and reporting,
- business continuity, response and recovery,
- digital operational-resilience testing,
- ICT third-party due diligence and contractual requirements,
- the register of ICT third-party arrangements.
9. Protect client assets and funds
Where the business model involves custody or control over clients’ crypto-assets, private keys or funds, the applicant must show how client ownership rights are protected and how assets are separated from the CASP’s own property.
The framework may include:
- client-asset and position registers,
- wallet architecture and key-management controls,
- segregation and reconciliation processes,
- authorisation and authentication controls,
- transaction approval and withdrawal controls,
- incident and loss-management procedures,
- custody agreements and client disclosures,
- recovery and orderly-transfer arrangements.
10. Build conduct, complaints and conflict controls
MiCA requires CASPs to act honestly, fairly and professionally in the best interests of clients. Marketing, fee disclosures, risk warnings and customer communications must be fair, clear and not misleading.
The applicant should also maintain an operational complaints process and identify conflicts involving the CASP, its group, shareholders, management, employees and different clients. Disclosure alone is not a substitute for preventing or managing a conflict where effective mitigation is possible.
11. Control outsourcing, continuity and wind-down
Outsourcing does not transfer the CASP’s responsibility. The authorised entity must retain the expertise, information and resources needed to supervise outsourced activities and manage the associated risks.
The framework should document:
- outsourced and retained responsibilities,
- provider due diligence and risk classification,
- service levels, quality controls and access rights,
- sub-outsourcing and delivery locations,
- regulatory and audit access,
- business-continuity and contingency arrangements,
- termination and exit strategies,
- orderly wind-down and transfer of client assets or services.
12. Prepare passporting as a controlled expansion
An authorised CASP may provide services in other Member States after submitting the required cross-border information through its home competent authority. The notification identifies the host countries, services, intended start date and other non-MiCA activities.
Passporting should not be treated as a purely administrative final step. Before entering each market, the CASP should assess language, marketing, customer-support, sanctions, complaints, consumer-protection and local operational considerations. The central framework should remain consistent while justified local variations are controlled and documented.
What should the CASP readiness evidence room contain?
01
Application documents
Programme of operations, financial projections, governance, prudential and service-specific documents.
02
Operational procedures
AML, Travel Rule, custody, complaints, conflicts, outsourcing, continuity and ICT procedures.
03
Implementation evidence
Configured systems, registers, contracts, training, testing results, management reports and decision records.
04
Readiness validation
Gap tracking, walkthroughs, sample testing, issue remediation and formal management acceptance.
Poland-specific position as at 4 August 2026
The Polish authorisation route remains dependent on the statutory designation of the national competent authority. UKNF has stated that, without that designation, domestic authorisation proceedings cannot be initiated, while cross-border activity by a CASP authorised in another Member State remains possible under MiCA.
Read the current analysis of the Polish MiCA and CASP position
How APOG supports CASP authorisation readiness
APOG supports crypto-asset businesses in translating MiCA, AML, Travel Rule and DORA requirements into defined readiness programmes. The scope may include:
- regulatory-perimeter and service mapping,
- readiness assessment and implementation roadmap,
- programme of operations and governance documentation,
- AML/CFT, KYC/KYB and transaction-monitoring frameworks,
- Travel Rule operating models and procedures,
- DORA and ICT-control coordination,
- outsourcing, quality assurance and management reporting,
- pre-submission testing and remediation tracking.
Prepare the operating model before assembling the application
The application becomes more credible when policies, systems, responsibilities, financial assumptions and evidence describe the same operating model.
Official sources
- Regulation (EU) 2023/1114 — MiCA
- Commission Delegated Regulation (EU) 2025/305 — CASP authorisation application information
- Commission Implementing Regulation (EU) 2025/306 — application forms and procedures
- ESMA Supervisory Briefing on CASP authorisation
- Regulation (EU) 2023/1113 — Travel Rule
- EBA Travel Rule Guidelines
- Regulation (EU) 2022/2554 — DORA
This article provides a practical readiness framework and does not constitute legal advice or a guarantee that authorisation will be granted. The applicable requirements depend on the proposed services, business model, home Member State, ownership, outsourcing arrangements and current regulatory position. Information concerning Poland should be checked again before taking an authorisation or market-entry decision.