Summary
A CASP, or Crypto-Asset Service Provider, is a legal person or other undertaking permitted to provide one or more regulated crypto-asset services under the European Union's Markets in Crypto-Assets Regulation (MiCA).
CASP services can include crypto custody, operating a trading platform, exchanging crypto for funds, exchanging one crypto asset for another, executing customer orders, providing advice, portfolio management and crypto transfers.
A MiCA CASP authorization is more than a generic claim that an exchange is "registered in Europe." However, it still applies to a specific legal entity and specific authorized services.
Users should therefore verify which company holds the authorization, which authority granted it, what services are covered and whether the authorization is currently valid.
Key Facts
| Question | Short Answer |
|---|---|
| What does CASP stand for? | Crypto-Asset Service Provider |
| Which regulation defines CASPs? | EU Markets in Crypto-Assets Regulation (MiCA) |
| Can a crypto exchange be a CASP? | Yes |
| Is CASP the same as VASP? | No |
| Is a CASP authorization an EU crypto license? | It is commonly called one, but MiCA authorization is the more precise term |
| Can a CASP operate across the EU? | Yes, for authorized services through MiCA's cross-border framework |
| Does one CASP authorization cover every crypto product? | No |
| Do old EU VASP registrations automatically equal CASP authorization? | No |
| Does CASP authorization mean an exchange is safe? | No |
| Where can CASP status be checked? | ESMA and the relevant national competent authority |
What Is a CASP?
CASP stands for:
Crypto-Asset Service Provider
The term is formally used under the European Union's Markets in Crypto-Assets Regulation, usually called MiCA.
Under MiCA, a CASP is a legal person or other undertaking whose business involves professionally providing one or more regulated crypto-asset services to clients and that is permitted to provide those services under the regulation.
In practical terms, CASPs can include:
- Centralized crypto exchanges
- Crypto custodians
- Crypto brokers
- Crypto transfer providers
- Crypto advisers
- Crypto portfolio managers
A business does not become a CASP merely because it works with blockchain technology.
What matters is whether it provides one or more services specifically regulated under MiCA.
What Is MiCA?
MiCA stands for:
Markets in Crypto-Assets Regulation
Its formal designation is:
Regulation (EU) 2023/1114
MiCA created a common regulatory framework for large parts of the crypto market across the European Union.
Before MiCA, crypto companies often operated under different national regimes.
For example, one exchange might have been:
Registered as a VASP in Country A
↓
Registered under another national framework in Country B
↓
Subject to different rules in Country CThis made it difficult for users to compare regulatory status across Europe.
MiCA introduced a more harmonized framework, including authorization and operating requirements for Crypto-Asset Service Providers.
Which Crypto Services Are Covered by MiCA?
MiCA identifies ten categories of crypto-asset services.
A CASP authorization should specify which of these services the provider is permitted to perform.
1. Custody and Administration of Crypto-Assets
This covers safeguarding or controlling crypto-assets, or the means of accessing them, on behalf of customers.
For example:
Customer
↓
Deposits BTC
↓
Exchange controls the private keysThis can constitute a custody service.
Custody is particularly important because it creates risks involving:
- Private-key security
- Cyberattacks
- Internal controls
- Customer asset protection
- Operational failure
2. Operating a Trading Platform for Crypto-Assets
This applies to businesses operating systems that bring together multiple third-party buying and selling interests in crypto-assets.
For many centralized exchanges, this relates directly to the operation of order-book trading markets.
Examples can include:
BTC/EUR
ETH/EUR
BTC/USDC3. Exchange of Crypto-Assets for Funds
This covers buying or selling crypto-assets against funds using the provider's own capital.
For example:
EUR → BTC
BTC → EUR4. Exchange of Crypto-Assets for Other Crypto-Assets
This covers exchanging one crypto asset for another.
For example:
BTC → ETH
ETH → USDT5. Execution of Orders on Behalf of Clients
A provider may execute agreements to buy or sell crypto-assets for customers.
This is different from merely operating the trading venue itself.
6. Placing of Crypto-Assets
This involves marketing crypto-assets to purchasers on behalf of, or for the account of, an offeror or related party.
It can be relevant to certain token offerings and distributions.
7. Reception and Transmission of Orders
A provider may receive a customer's order and transmit it to another party for execution.
Conceptually:
Customer
↓
Broker
↓
Trading Venue8. Providing Advice on Crypto-Assets
Personalized recommendations concerning crypto-assets or crypto-asset services can fall within this category.
This differs from publishing general market commentary or educational content.
9. Portfolio Management of Crypto-Assets
This involves managing crypto-asset portfolios on a discretionary, client-by-client basis under a customer mandate.
10. Transfer Services for Crypto-Assets
This covers transferring crypto-assets from one distributed-ledger address or account to another on behalf of customers.
Is a CASP the Same as a Crypto Exchange?
No.
A crypto exchange may be a CASP, but CASP is a broader category.
| Business Type | Potential CASP Activity |
|---|---|
| Centralized exchange | Trading, exchange, custody, transfers |
| Crypto custodian | Custody |
| Crypto broker | Execution or transmission of orders |
| Crypto adviser | Advice |
| Portfolio manager | Portfolio management |
| Crypto transfer provider | Transfer services |
| Token placement provider | Placing |
A single CASP can also be authorized for multiple services.
This is why the existence of a CASP authorization alone does not tell you everything about what a company is permitted to do.
Is CASP Authorization a Crypto License?
You will often see phrases such as:
MiCA License
EU Crypto License
MiCA CASP License
These are commonly used descriptions.
The more precise regulatory term is generally:
CASP authorization under MiCA
This distinction matters because the authorization covers specified crypto-asset services and is subject to defined regulatory requirements.
It is not simply a generic badge saying:
EU Regulated ✓
What Requirements Do CASPs Have to Meet?
Requirements differ depending on the services being provided, but MiCA establishes obligations covering areas such as:
- Governance
- Prudential safeguards
- Management suitability
- Conflicts of interest
- Complaints handling
- Outsourcing
- Operational controls
- Client protection
- Custody
- Trading-platform operation
- Recordkeeping
CASPs are also required to continue meeting their authorization conditions after approval.
This makes CASP authorization materially different from a simple company registration.
CASP vs VASP: What Is the Difference?
This is one of the most common points of confusion.
VASP
VASP means:
Virtual Asset Service Provider
The term is strongly associated with FATF and international AML/CFT standards.
Countries around the world have implemented VASP-related rules in different ways.
Some VASP regimes focus heavily on:
- AML
- KYC
- Transaction monitoring
- Financial crime reporting
CASP
CASP means:
Crypto-Asset Service Provider
In this context, it is a legal regulatory category under EU MiCA.
MiCA specifies:
- Which crypto services are regulated
- How authorization works
- Operating requirements
- Cross-border provision of services
VASP vs CASP
| VASP | CASP | |
|---|---|---|
| Full name | Virtual Asset Service Provider | Crypto-Asset Service Provider |
| Main framework | FATF / national implementation | EU MiCA |
| Geographic context | Global | European Union |
| Regulatory form | Varies by jurisdiction | MiCA authorization |
| Main origins | AML/CFT | Broader crypto regulation |
| Service scope | Depends on local rules | Defined under MiCA |
| EU passporting | Not inherent | Yes |
The most important practical conclusion is:
A VASP registration does not automatically equal a MiCA CASP authorization.
What Happened to Old EU VASP Registrations?
Before MiCA, many crypto businesses operated under national registration regimes.
MiCA provided transitional arrangements allowing some companies that had already been legally providing crypto services before December 30, 2024 to continue temporarily under existing national rules.
However, this transition was not permanent.
The maximum MiCA grandfathering period ended:
July 1, 2026
and individual EU Member States were allowed to shorten the transition or not apply it.
This matters because an old statement such as:
"Registered as a VASP in Europe"
is no longer sufficient by itself to determine a company's current EU regulatory status.
As of September 2026, users should check the company's current MiCA status rather than rely only on historical national registrations.
Who Authorizes a CASP?
A company generally applies to the competent authority of its home EU Member State.
The authorization belongs to the legal entity.
For example:
Exchange Brand
↓
European Legal Entity
↓
Home Member State
↓
National Competent Authority
↓
CASP AuthorizationThe authority can assess information relating to areas such as:
- Legal structure
- Management
- Shareholders
- Business plan
- Governance
- Internal controls
- Security
- Custody arrangements
- Prudential safeguards
- Outsourcing
Why Does the Legal Entity Matter?
Global crypto exchanges often operate through several companies.
For example:
Global Exchange
│
├── European Entity
│ └── MiCA CASP
│
├── Middle East Entity
│ └── Local regulatory framework
│
├── Asian Entity
│ └── Separate regulatory framework
│
└── Offshore EntityIf the European entity is authorized under MiCA, that does not automatically mean every company in the group has the same authorization.
Therefore:
"Exchange X has a MiCA license"
is less precise than:
"Exchange X's European legal entity holds a MiCA CASP authorization."
Why Does the Authorized Service Scope Matter?
CASP authorization is not unlimited.
An entity could, for example, be authorized for:
✓ Custody
✓ Exchange
✓ Transfer Serviceswithout necessarily being authorized for:
? Portfolio Management
? Crypto AdviceMiCA requires authorization records to specify the crypto-asset services the CASP is allowed to provide.
Therefore:
CASP authorized
does not mean:
Authorized for every possible crypto product.
What Is MiCA Passporting?
One of MiCA's most important features is its cross-border framework.
An authorized CASP can provide its authorized crypto-asset services across EU Member States after following the required notification process.
This is often described as:
MiCA passporting
Conceptually:
Home Member State
↓
CASP Authorization
↓
Cross-Border Notification
↓
Other EU Member StatesThis reduces the need to obtain an entirely separate crypto authorization in every EU country.
Does Passporting Expand What a CASP Can Do?
No.
Passporting primarily extends the geographic reach of the existing authorization.
It does not automatically expand the service scope.
For example:
Authorized:
✓ Custody
✓ Exchangedoes not become:
Authorized:
✓ Every MiCA servicesimply because the company begins operating cross-border.
Can a CASP Operate Across the Entire EU?
An authorized CASP can generally provide its authorized crypto-asset services across the EU under MiCA's cross-border framework.
However, users should still check:
- Which services are authorized
- Which Member States the provider has notified
- Which legal entity provides the service
- Whether the authorization remains active
A statement such as:
EU licensed
can therefore be directionally correct but still incomplete.
Does a CASP Need to Be Based in the EU?
For the standard MiCA CASP authorization route, the provider must have a registered office in an EU Member State where it carries out at least part of its crypto-asset services.
It must also have its place of effective management in the EU, and at least one director must be resident in the Union.
This helps ensure that the authorized entity has a meaningful regulatory presence in Europe.
Can a Non-EU Exchange Serve EU Users Without CASP Authorization?
MiCA contains a limited provision for services initiated at the exclusive initiative of the client, often discussed as reverse solicitation.
In simplified terms:
EU Customer
↓
Independently approaches
↓
Non-EU Providermay be treated differently from a provider actively targeting EU customers.
However, this is a narrow concept.
If a third-country exchange:
- Solicits EU customers
- Markets services in the EU
- Advertises to EU users
- Actively promotes its services to prospective EU customers
it cannot simply rely on the idea that customers approached it independently.
A website disclaimer alone does not automatically create a broad regulatory exemption.
Does Website Availability Mean an Exchange Is Authorized in the EU?
No.
The fact that an exchange website can be opened from:
- France
- Germany
- Italy
- Spain
does not prove the exchange is authorized to market and provide all of its services there.
Internet accessibility and regulatory authorization are separate issues.
Can Banks and Other Financial Institutions Provide MiCA Crypto Services?
Yes, in certain circumstances.
MiCA contains separate provisions for some businesses already regulated under other EU financial-services frameworks, including certain:
- Credit institutions
- Investment firms
- Electronic money institutions
- Market operators
- Asset management firms
Depending on the institution and service, these entities may use a notification route rather than the standard CASP authorization process.
Therefore, not every legitimate provider of MiCA crypto services will necessarily enter the market through exactly the same authorization process.
Does CASP Authorization Mean a Crypto Exchange Is Safe?
No.
CASP authorization is an important regulatory signal.
It does not eliminate:
- Cybersecurity risk
- Private-key risk
- Liquidity risk
- Withdrawal risk
- Operational risk
- Governance failures
- Fraud
- Insolvency
- Regulatory breaches
A regulated crypto company can still fail.
Therefore:
CASP Authorized
≠
Risk-FreeDoes CASP Authorization Protect Customer Assets?
MiCA imposes regulatory obligations on authorized service providers, including requirements relevant to client protection and custody.
However, users should not interpret a CASP authorization as a guarantee that:
- Crypto prices cannot fall
- An exchange cannot be hacked
- A company cannot become insolvent
- Every customer loss will be reimbursed
- Every product offered under the same brand has the same protections
The exact legal entity, service and circumstances still matter.
Is CASP Authorization a Government Endorsement?
No.
Authorization means that an entity is permitted to provide specified regulated services under the applicable framework.
It does not mean that the regulator:
- Recommends the exchange
- Guarantees its financial health
- Guarantees returns
- Certifies every product as safe
Regulatory authorization and regulatory endorsement are different concepts.
How to Verify Whether an Exchange Is a MiCA CASP
Do not rely only on an exchange press release saying:
We are MiCA licensed.
A better process is:
1. Identify the European Legal Entity
Check:
- Terms of Service
- Legal notices
- Regulatory disclosures
- Customer agreements
Find the exact company serving EU users.
For example:
Brand:
Example Exchange
EU Entity:
Example Digital Assets Europe S.A.2. Identify the Home Member State
Determine where the entity received authorization.
For example:
Home Member State:
France3. Identify the Competent Authority
Find the national regulator responsible for granting the CASP authorization.
4. Search the Official Register
Check:
- ESMA's MiCA register
- The relevant national competent authority
Official records are stronger evidence than:
- Exchange blog posts
- Press releases
- Affiliate reviews
- Social media claims
5. Match the Exact Legal Name
The brand and regulated entity can have very different names.
Make sure the company in the regulator's database is the same entity referred to in the exchange's customer terms.
6. Check the Authorized Services
Verify whether the authorization covers:
- Custody
- Trading platform operation
- Exchange for funds
- Crypto-to-crypto exchange
- Order execution
- Advice
- Transfers
- Other MiCA services
Do not assume all ten services are automatically included.
7. Check Cross-Border Information
If the exchange claims to serve multiple EU countries, check whether the regulatory information supports its cross-border service status.
8. Check the Current Status
Authorization can potentially be:
- Active
- Restricted
- Withdrawn
- Renounced
- Otherwise changed
A historical license announcement does not necessarily describe the current position.
9. Check When the Information Was Updated
Crypto regulatory structures change quickly.
Prefer current official register information over older articles or announcements.
What Else Should You Check Besides CASP Status?
If you are evaluating an exchange, CASP authorization should be only one part of the review.
Also consider:
Security History
Has the exchange experienced major hacks or private-key incidents?
Proof of Reserves
Does it provide verifiable information about customer asset backing?
Withdrawal Reliability
Has it experienced significant withdrawal delays or restrictions?
Custody
Who controls customer assets?
Legal Entity
Which company actually provides the service to your account?
Recent Risk Events
Has the exchange recently faced regulatory, security or operational problems?
A strong regulatory authorization is useful evidence.
It is not a complete exchange safety assessment.
How to Read a "MiCA Licensed" Claim
When an exchange says:
"We are MiCA licensed."
ask:
Which legal entity?
↓
Which home Member State?
↓
Which regulator?
↓
Which crypto services?
↓
Which EU markets?
↓
Is the authorization active?These questions tell you much more than the phrase:
MiCA Licensed ✓
alone.
Frequently Asked Questions
What does CASP stand for?
CASP stands for Crypto-Asset Service Provider.
What is a CASP under MiCA?
A CASP is a legal person or other undertaking permitted under MiCA to professionally provide one or more regulated crypto-asset services to clients.
Is a crypto exchange a CASP?
Many centralized crypto exchanges can be CASPs because they provide services such as trading, exchange, custody and transfers.
Is CASP the same as VASP?
No. VASP is strongly associated with FATF and national virtual-asset frameworks. CASP is the regulatory category used under EU MiCA.
What is a MiCA license?
"MiCA license" is a common informal term. For crypto service providers, the more precise concept is authorization as a Crypto-Asset Service Provider under MiCA.
Does a CASP license cover all crypto services?
No. The authorization specifies which crypto-asset services the provider is permitted to offer.
Can a CASP operate throughout the EU?
Yes, an authorized CASP can provide authorized services cross-border under MiCA after following the required notification procedure.
What is MiCA passporting?
MiCA passporting is the common term for using a CASP's home-state authorization to provide authorized crypto services across other EU Member States under MiCA's cross-border framework.
Does passporting give a CASP permission to offer every service?
No. It does not expand the underlying service scope of the authorization.
Does an old EU VASP registration count as MiCA authorization?
Not automatically. The maximum MiCA transitional period ended on July 1, 2026, and some Member States adopted shorter periods.
Where can I check whether a company is an authorized CASP?
Check ESMA's MiCA register and the relevant national competent authority's official regulatory records.
Does ESMA authorize CASPs directly?
CASP authorization is generally granted by the competent authority in the provider's home Member State. ESMA maintains the EU-level MiCA register.
Can a non-EU crypto exchange serve EU customers?
MiCA provides a narrow framework for services initiated exclusively by the client, but this should not be treated as a general exemption allowing foreign exchanges to actively market to EU customers without authorization.
Does CASP authorization mean an exchange is safe?
No. An authorized CASP can still face cybersecurity, liquidity, operational, governance or insolvency risks.
Does CASP authorization apply to the whole exchange brand?
Not necessarily. Authorization belongs to a specific legal entity and specifies the services that entity may provide.
Can CASP authorization be withdrawn?
Yes. Regulatory authorization can change and, under applicable conditions, can be withdrawn.
Key Takeaway
A CASP is a Crypto-Asset Service Provider permitted to provide specified regulated crypto services under the EU's MiCA framework.
But:
CASP Authorization
≠
Unlimited EU Crypto Licenseand:
CASP Authorized
≠
Risk-Free ExchangeWhen an exchange says:
"We are MiCA licensed."
the useful questions are:
Which legal entity?
↓
Which EU Member State?
↓
Which regulator?
↓
Which services are authorized?
↓
Which markets are being served?
↓
Is the authorization still active?The CASP label is important.
The entity, scope and current regulatory status behind the label are what actually tell users how the exchange is regulated.