Back to all articles
SCALECOMPLIANCE

MiCA/CASP Investor Briefing – Risk & Opportunity

·
12 min
MiCA/CASP Investor Briefing – Risk & Opportunity

Introduction

This briefing is aimed at professional and sophisticated retail investors considering exposure to EU-facing Crypto-Asset Service Providers (CASPs) or token projects. It explains how the Markets in Crypto-Assets Regulation (MiCA) is changing the regulatory risk landscape, how to interpret CASP license status, what red flags to look out for, and how MiCA readiness qualitatively affects the risk-return profile.

Information status: January 3, 2026

Important note: This briefing does not constitute investment advice and does not recommend any specific companies or products. It is for informational purposes only regarding regulatory developments and their impact on the risk profile of crypto-asset investments.

MiCA context for investors

The Markets in Crypto-Assets Regulation (MiCA, Regulation (EU) 2023/1114) marks a fundamental shift: From a fragmented national patchwork to a uniform EU framework. Before MiCA, Crypto-Asset Service Providers operated under widely differing national regimes. MiCA now creates a harmonized licensing and supervisory framework that applies in all EU countries and allows CASPs to offer their services EU-wide (Passporting).

More transparency, but not MiFID-level protection: MiCA improves the situation through mandatory white papers, organizational requirements for CASPs (governance, IT security, conflicts of interest), complaint mechanisms and safeguarding rules. However, the European Supervisory Authorities (ESAs) emphasize: MiCA does not bring protection to the level of traditional financial products.

The ESAs published joint warnings in October 2025 and December 2024: Crypto-assets remain high-risk and speculative; investors can lose their entire capital; high volatility, fraud and hacking risks persist; and no or only limited legal protection applies to non-EU authorized providers. ESMA also warns of the “halo effect”: Just because a CASP is authorized for certain services does not mean that all of its products fall under MiCA.

The central message: MiCA reduces regulatory uncertainty and sets minimum standards – but it is not a “safety net” like traditional financial products. Choosing the right provider and understanding its regulatory status are critical factors in risk management.

Regulatory Risk Buckets

From an investor perspective, Crypto-Asset Service Providers can be qualitatively classified into three “regulatory risk buckets" based on their MiCA license status:

Bucket 1: Fully MiCA-authorized CASP in the EU with Passporting

Characteristics: Full CASP authorization pursuant to Article 62 et seq. MiCA from a national supervisory authority (NCA), listed in the ESMA register, EU-wide passporting possible.

MiCA-Level Protections: Organizational requirements (governance, internal controls, qualified personnel), safeguarding (segregated custody, priority claims in the event of insolvency), functioning complaint management, conduct of business obligations (fair, professional, in the client's interest), IT & Operational Resilience, full EU-AML/KYC and Travel Rule compliance.

Wind-Down Risk: Low. However, even a licensed CASP can lose its license in the event of serious compliance violations or financial problems.

Qualitative Risk Assessment: Significantly reduced regulatory risk, greater confidence in governance and IT security (regulatory audits passed), better legal remedies in the event of breaches of duty. Trade-off: Higher compliance costs can lead to higher fees or lower margins.

Bucket 2: Provider under national VASP/DASP regime or transitional regime (country-specific end dates 2025–2026)

Characteristics: Operates under national registration or licensing regime (e.g. VASP, DASP) prior to full MiCA authorization. MiCA allows Member States transitional periods of 6–18 months from 30.12.2024: Austria/Germany: 12 months (until 31.12.2025); France/Luxembourg: 18 months (until 30.06.2026/01.07.2026). Note: Exact deadlines vary depending on the Member State (e.g. Netherlands/Finland: 6 months) and should be checked with NCAs (FMA, BaFin, AMF, CSSF).​

MiCA-Level Protections: During the transition period, primarily national rules (often AML/KYC-focused), not the full MiCA requirements. ESAs emphasize: Customers do not benefit from MiCA protections during the transition. After expiration: CASP license required or wind-down.​

Wind-Down Risk: High. Without a CASP license at the end of the deadline, the provider must cease EU business. ESMA warns: CASPs without authorization should activate wind-down plans. For investors: Liquidity risk (account closures, delayed payouts) and reputational risk.​

Qualitative Risk Assessment: Medium to high regulatory risk depending on the CASP approval process status. Weaker governance, IT security and market surveillance than Bucket 1. Investors should closely examine CASP roadmap status and prepare for possible disruptions – especially in countries with expired deadlines such as Austria/Germany.​

Bucket 3: Non-EU or unauthorized provider (including “Reverse Solicitation")

Characteristics: No EU license (neither MiCA-CASP nor national transitional regime). Operates from a third country or claims “Reverse Solicitation” (customer allegedly contacted exclusively on their own initiative).

MiCA-Level Protections: None. ESAs warn: Investors are not protected by MiCA for non-EU authorized providers. In the event of damage, often no legal options (cross-border lawsuits in third countries problematic).

Wind-Down Risk: Extremely high. NCAs can take action at any time (website blocking, warnings, criminal proceedings). Provider could suddenly leave the EU market.

Qualitative Risk Assessment: Very high regulatory risk. No governance or IT security standards. Maximum AML/KYC risk, fraud and hacking risk significantly higher without supervision. Reverse Solicitation Myth: ESMA clarifies that this exception is very narrow – active marketing disqualifies it. Not advisable for most investors, even with high expected returns.

Signals from case law and enforcement

The regulatory landscape is changing not only through legislation, but also through court decisions and enforcement measures. A landmark ruling shows that regulatory violations can have direct civil law consequences:

Court of Appeal of Grenoble (June 26, 2025): Bitstamp Europe – Failure to Register as DASP

In the case of a customer of the crypto exchange Bitstamp Europe, the French Court of Appeal in Grenoble ruled that the failure to register as a DASP (Digital Asset Service Provider) under the French PACTE regime constitutes a breach of duty that establishes civil liabilityregardless of whether there were additional technical or operational errors.

Facts (highly simplified):

  • Bitstamp Europe offered crypto services in France, but had not registered as a DASP with the AMF (Autorité des Marchés Financiers) by the legally required deadline (December 19, 2020).
  • A customer suffered losses due to fraudulent activity on their account (presumably through phishing or compromise of their credentials).
  • The court of first instance dismissed the claim, arguing that Bitstamp had taken technically appropriate security precautions (warning system for suspicious logins) and that the regulatory non-registration was irrelevant to the civil law claim.
Decision of the Court of Appeal:
  • The Court of Appeal reversed the judgment and ordered Bitstamp Europe to pay damages.
  • Core argument: The court found that Bitstamp acted unlawfully because it had operated without the required DASP registration. This regulatory breach of duty was recognized as an independent civil law fault (stand-alone regulatory fault).
  • The court argued that the lack of registration could be causal for the damage: If Bitstamp had been properly registered and under AMF supervision, higher security standards and better governance mechanisms might have been in place that could have prevented the loss.
  • Important: The court did not have to prove that Bitstamp had acted negligently technically or operationally. The mere fact that the provider was illegally operating without a license was sufficient for liability.
What does this mean for investors under MiCA?

This decision is a strong signal with potentially far-reaching consequences:

  • Regulatory compliance becomes a private law obligation: Courts can regard violations of licensing obligations (such as the lack of a CASP license under MiCA) as an independent breach of duty that justifies claims for damages.
  • Increased litigation risk for non-compliant providers: CASPs that operate without the required license (Bucket 3) or continue to operate after the end of the transition period (Bucket 2) expose themselves to a significant liability risk. Customers can argue that losses are due not only to technical errors, but also to the lack of regulatory compliance.
  • Shift in the burden of proof: Investors may no longer have to prove in detail which specific operational errors led to the damage – the fact that the provider was operating illegally may be sufficient.
  • Value of the CASP license from an investor perspective: Choosing a fully licensed CASP (Bucket 1) not only reduces regulatory risk, but also the litigation risk for the provider – which indirectly increases the stability and trustworthiness of the provider.
Early Enforcement in other member states

Although detailed court decisions on MiCA are still pending (as MiCA has only been fully applicable since the end of 2024), initial enforcement measures by national supervisory authorities show a similar direction:

  • BaFin (Germany): Several warnings about unlicensed providers; measures against companies that offer crypto services without the required permission.
  • ESMA: Publication of “Non-Compliant Entities” lists; request to NCAs to critically examine last-minute applications and to take action against unauthorized providers.
  • AMF (France): Consistent enforcement of the DASP registration obligation; several warnings and delistings.
The message is clear: Regulatory status becomes a central element of investor protection. An investor's first check should be: Is the provider listed in the ESMA register? If not, why not, and what risks does that entail?

DD questionnaire from a regulatory perspective

Professional investors should carry out a structured due diligence process when evaluating CASPs or token projects:

1. License status & roadmap

  • Do you already have full CASP approval under MiCA? Are you listed in the ESMA register?
  • If no CASP license: Under which national regime do you operate? How long is the transition period valid?
  • Have you submitted a CASP application? To which NCA? In which phase?
  • What is your roadmap to full MiCA compliance?
Red Flags: Vague or defensive answers, no CASP application despite expiring deadline, claim of “Reverse Solicitation” without clear documentation.

2. AML/KYC framework

  • How is your KYC process structured? (Onboarding, Ongoing Monitoring, Enhanced Due Diligence)
  • Which sanctions screening tools do you use?
  • How do you comply with the Travel Rule? Which technical solution?
  • Have you recently undergone AML/KYC audits by your NCA?
Red Flags: Superficial KYC processes, no Travel Rule compliance, unresolved AML findings.

3. Governance & key persons

  • Who is responsible for compliance, risk and IT security?
  • Do you have independent control functions?
  • How is your board composed? Are there independent members with regulatory experience?
  • How do you manage conflicts of interest?
Red Flags: Compliance/risk done “on the side” by the same person, board only consists of founders, no conflict of interest policies.

4. IT & Outsourcing

  • Which critical functions have you outsourced?
  • Do your outsourcing contracts have audit rights for CASP and NCA, data access, sub-outsourcing control, exit plans?
  • Where is data physically stored (EU vs. Non-EU)? GDPR compliance?
  • Have you recently performed penetration tests or security audits?
Red Flags: Critical functions outsourced without audit rights, cloud in Non-EU without GDPR compliance, “letter-box” structure.

5. Whitepaper & Disclosure (for token projects)

  • Does the token have a MiCA-compliant white paper? Was it notified/approved (for ARTs/EMTs)?
  • Are risk factors presented in a balanced way?
  • How is the tokenomics structured? Are there concentrated holdings?
Red Flags: No white paper or “Coming Soon”, exaggerated return promises without risk disclosures, misleading governance claims.

Generally: Vague or defensive answers are red flags. A reputable, MiCA-ready provider should be able to answer these questions clearly and transparently.

How MiCA-Readiness Influences Risk & Assessment (Qualitatively)

From an investor perspective, MiCA readiness is a qualitative factor that influences the risk-return profile:

Advantages of MiCA Readiness

Reduced regulatory uncertainty: Fully licensed CASPs have a lower risk of abrupt shutdowns or EU market access losses. Predictability for long-term investments.

Better bankability and institutional acceptance: Easier access to banking services and payment processors. Institutional investors often have compliance requirements that only allow investments in regulated entities.

Higher customer confidence and better retention: Reputation through supervision, protection against regulatory crackdowns.

Long-term market access: EU passporting enables access to 450 million inhabitants. Scalability without constant regulatory hurdles.

Disadvantages and Trade-Offs

Higher fixed costs: Compliance teams, legal, risk management, IT security, external audits significantly increase costs.

Potentially lower margins: Higher costs mean either higher fees or lower margins. Lower short-term profitability, but higher long-term stability.

Less speculative upside: Unregulated providers can pursue more aggressive business models. MiCA-ready CASP acts more conservatively – fewer “wild” profits, but significantly reduced tail risk.

Conclusion

For medium- to long-term investors, MiCA readiness is a rational trade-off: Slightly lower upside (higher costs, more conservative management) versus significantly reduced downside (lower risks of shutdowns, fraud, litigation).

The ESAs emphasize: MiCA is not a safety net. Even licensed CASPs can fail. But the probability and extent of such events are significantly lower than with unregulated providers.

Investor perspective: MiCA readiness is a quality feature – similar to licensing with BaFin, FCA or SEC. It is not a guarantee, but an important factor in reducing the regulatory risk premium.

Summary and Recommendations

Key messages for investors:

  • MiCA creates clarity, but not MiFID-level protection: Crypto-assets remain high-risk. MiCA improves transparency and sets minimum standards, but investors can still lose their entire capital.
  • Regulatory status is a central risk factor: Prefer CASPs from Bucket 1 (fully licensed). Bucket 2 (transitional regime) is acceptable if there is a clear roadmap to licensing. Bucket 3 (non-EU/unauthorized) should be avoided unless you have very specific reasons and are willing to bear the full risk. Important: Even fully licensed Bucket 1 CASPs do not guarantee against losses – as the ESAs emphasize in their warnings, crypto-assets remain highly volatile and can suffer technical failures, hacking attacks or mismanagement.
  • Case law shows: Regulatory violations have civil law consequences: The Grenoble/Bitstamp Europe case shows that courts may consider the lack of licensing as a breach of duty that establishes liability. This increases the litigation risk for non-compliant providers – and strengthens the position of customers/investors with licensed CASPs.
  • Due diligence is essential: Use the above DD questionnaire systematically. Check license status, AML/KYC framework, governance, IT/outsourcing and (for tokens) white paper quality. Vague answers are red flags.
  • MiCA readiness as a qualitative assessment criterion: Fully licensed CASPs have higher fixed costs, but significantly reduced regulatory and operational risk. For long-term investors, this is a sensible trade-off.
Practical steps:

Check the ESMA register: Is your provider listed?

Read the ESAs warnings: Understand the inherent risks of crypto-assets.

Ask about the roadmap: If the provider does not yet have a CASP license, what is the status?

Diversify: Don't put everything on one provider or one token. Spread the risk.

Stay informed: MiCA and supervisory practice are constantly evolving. Follow ESMA publications and national NCA updates.

Conclusion: MiCA is a paradigm shift. Investors who understand and embrace this change can make more informed decisions and better manage their risk profile. Those who ignore MiCA and continue to use unregulated or non-compliant providers expose themselves to unnecessary risks – at a time when courts and regulators are increasingly cracking down.

About NEXORA Unternehmensberatung GmbH

NEXORA is a Vienna-based boutique consulting firm specializing in RegTech, FinTech, strategic consulting and compliance services for Austrian and international clients. Our team supports both Crypto-Asset Service Providers and investors in navigating MiCA – from due diligence and CASP licensing to ongoing compliance consulting.

Need a consultation?

Book a free initial consultation with the NEXORA team.

Free Consultation