MiCA in Austria: Roadmap to the CASP license for crypto projects.

Three Essential Documents for Your Licensing Journey
Author: NEXORA Team, NEXORA Unternehmensberatung GmbH Reading time: 12–14 minutes
Version 1.0 | December 2025
This article is aimed at founders, C-level executives and legal/compliance teams of crypto projects that want to operate in a regulated manner in Austria or the EU. You will learn how the MiCA regulation affects your business models, when you need a CASP license yourself and when a regulated partner is sufficient. The article offers a practical roadmap until the end of 2025, document checklists, typical sources of error and references to download templates for your preparation.
The 5 most important points
- MiCA harmonizes the EU crypto regime: Since December 30, 2024, uniform rules have applied to Crypto Asset Service Providers (CASP) in all member states. Anyone who provides professional CASP services (custody, exchange, brokerage, etc.) needs a license – previous national VASP registrations will expire in the member states for a limited time according to the current legal situation [source required – details on the respective national transitional regulation].
- CASP license vs. partner model: Not every crypto project needs its own CASP license. If you concentrate on UI/UX, community and marketing and use a licensed CASP/EMI partner for regulated services, a model with a regulated partner may be sufficient – provided your project itself does not provide any MiCA-regulated services. The decisive factor is who provides the regulated services in their own name.
- Realistic time horizon for Austria: The FMA approval process is multi-stage and requires complete, high-quality documentation. From the fit/gap analysis to approval, it typically takes several months – depending on business model complexity, governance maturity and outsourcing structure. Early preparation is essential.
- Core cluster of documentation: Governance & UBO evidence, business model & risk analysis, AML/KYC policies, IT security & outsourcing contracts, fit-&-proper documents for management bodies. Each cluster must be consistent and comprehensible – the FMA attaches importance to substance and clear responsibilities.
- Start early: Projects that want to operate by the end of 2025 should start with a fit/gap analysis now. Transitional periods expire differently nationally; ESMA emphasizes orderly wind-down plans for providers without a timely license. The later you start, the higher the risk of delays or incomplete preparation.
MiCA in 90 seconds: What changes for crypto projects?
The Regulation (EU) 2023/1114 on Markets in Crypto-assets – MiCA or MiCAR for short – has been fully applicable since the end of 2025 and creates a harmonized EU-wide licensing regime for providers of crypto-asset services.
For crypto projects, this means:
- Uniform rules instead of a national patchwork: Previously, member states had different approaches – from simple VASP registrations under AML law to more complex national licensing regimes. MiCA replaces this fragmentation with an EU-wide valid licensing regime; on the basis of a CASP license granted in one member state, cross-border activity in other EU states is generally possible by means of passporting, subject to the notification procedures and technical standards provided for in MiCA.
- CASP services only with approval: MiCA defines in Art. 3(1)(16) a list of services that may only be provided by approved CASPs; each project should check which services are specifically covered (custody, operation of a trading platform, exchange services, execution and transmission of orders, placement, portfolio management, advice and transfer services) in the light of its business model.
- Custody and administration of crypto assets for third parties
- Operation of a trading platform for crypto assets
- Exchange of crypto assets for fiat money or other crypto assets (exchange services)
- Execution, acceptance and transmission of orders for crypto assets
- Placement of crypto assets
- Portfolio management in crypto assets
- Advice on crypto assets
- Transfer services on behalf of third parties
Consequences for projects without a license: If your project does not have its own CASP license, you may not provide the above-mentioned services yourself in your own name. Instead, you must work with a licensed CASP (or an e-money institution with an additional CASP license) as a partner and ensure that your contract, brand presence and customer communication make it clear who is providing the regulated service. Otherwise, you risk fines, warnings and, in the worst case, criminal consequences for unauthorized business activity.
Transitional mechanisms are expiring: MiCA allows member states to set national transitional periods so that providers already active can adjust to the new requirements. In Austria, according to the current status, it is planned that existing VASP registrations can only be used temporarily and will be replaced in the medium term by MiCA CASP licenses. Status: December 2025 – the national transitional regulation in the MiCA Enforcement Act (MiCA-VVG) is still being drafted or may change; projects should therefore check the current legal status and the information provided by the FMA. In its statements on MiCA Transitional Measures, ESMA emphasizes that last-minute applications carry a high risk and that market integrity and customer protection have top priority.
Practical example 1 – Transitional period missed (2025, anonymized)
A crypto service provider active in several EU member states relies on the fact that the national transitional period is "long enough" and submits its MiCA application shortly before it expires. The responsible supervisory authority determines that the application is not complete in time and orders the provider to discontinue its affected services in the respective member state. Existing customer relationships must be wound down in an orderly manner, and new customers may no longer be onboarded.
For the company concerned, this means: short-term loss of sales, considerable communication effort with customers and partners and damage to its reputation – even though the business model itself would be fundamentally eligible for approval. The lesson to be learned from this: Transitional periods are not an extension of the old regime "indefinitely", but an end date that you have to actively work towards.
CASP vs. Crypto-Project: The decision tree
Not every crypto project has to apply for a CASP license itself. The central question is: Do you provide one or more of the MiCA-defined CASP services yourself – in your own name and for your own account?
When do you need your own CASP license?
You generally need a CASP license from the FMA if you professionally provide one or more of the following services in Austria (or cross-border from Austria):
- Custody of crypto assets: You hold private keys for your customers and offer them wallet services in which they do not have access to their keys themselves.
- Operation of an exchange: You provide a platform on which users can trade crypto assets with each other or against fiat – and you are the operator/marketplace provider.
- Brokerage/exchange: You buy and sell crypto assets in your own name with your customers (dealing on own account) or arrange such transactions.
- Execution/transmission of orders: You accept customer orders and forward them to exchanges or other trading venues.
- Portfolio management, advice, transfer services: Specialized services in which you actively make decisions for customer portfolios, provide advisory services or carry out transfers on behalf of third parties.
When is a partner model sufficient (compliance-by-contract)?
Many crypto projects focus on UI/UX, community building, marketing, education or decentralized protocol development – but they do not provide regulated services themselves. In these cases, you can work with an already licensed CASP or e-money institution (EMI with additional CASP license). This is also known as "Banking-as-a-Service" (BaaS) or "Crypto-as-a-Service" (CaaS).
Example: Your project is a DeFi app with an appealing frontend. Users can buy, sell and store crypto assets via your app. Technically, however, everything runs via a licensed CASP partner in the backend – this partner holds the wallets, carries out KYC, processes transactions and takes care of reporting. Your project is "only" the frontend and the brand. In this setup, you do not need a CASP license yourself, but must ensure:
- The partner has a valid MiCA license (or national license with transitional rights).
- Contracts, terms and conditions and communication make it unmistakably clear who the service provider is.
- Your project does not take on any functions that would require a license (e.g. no own custody, no own trading in the name of the project).
- You adhere to advertising regulations and transparent customer communication in accordance with MiCA.
Practical example 2 – "Everything is regulated"? (2025, anonymized)
A European provider combines MiCA-regulated CASP services (e.g. custody of crypto assets) with additional, unregulated products. In marketing communications, however, all offers are presented together as "fully regulated" – without clearly distinguishing which services are actually covered by the MiCA license and which are not. The supervisory authority classifies this communication as misleading because customers could assume that they enjoy the same supervisory protection for all products.
The consequence: The provider must revise its entire marketing and contract documentation, publish clarifications on the website and expect stricter supervision. For crypto projects, this means: A clean dividing line between regulated and unregulated services is not only a legal detail, but is central to customer trust and supervisory risk.
Decision logic (simplified)
- Do you provide a CASP service in your own name?
- Yes → You need a CASP license (or must adapt the business model so that you do not provide a service).
- No → Check further.
- Do you have direct access to customer crypto assets or fiat (custody, keys, money flows)?
- Yes → Probably CASP service; legal review required.
- No → Check further.
- Do you work with a licensed CASP/EMI partner who takes over all regulated services?
- Yes → Partner model is possible; pay attention to a clean contractual and communicative demarcation.
- No → Need for clarification: Who provides the service? Without a license, you risk unauthorized business activity.
- Are you unsure?
Austria as a location: What you should realistically plan for
Austria offers several advantages as a MiCA jurisdiction: an established financial supervisory authority (FMA), legal clarity through the MiCA Enforcement Act (MiCA-VVG), a central location in the EU and access to qualified specialists. At the same time, you should know what you are getting into if you are seeking a CASP license from the FMA.
Role of the FMA and expectations of applicants
The Financial Market Authority (FMA) is the responsible authority for CASP approvals in Austria. It reviews applications on the basis of the MiCA Regulation and the national enforcement act. According to current supervisory practice, the FMA attaches particular importance to:
- Clarity and completeness of the application documents: Incomplete, contradictory or poor-quality applications lead to delays due to requests for additional information (requests for improvement).
- Substance and governance: It is not enough to formally establish a company. The FMA expects you to demonstrably have the necessary structures, processes and resources to provide the planned services safely and compliantly.
- Fit & Proper of the management bodies: Management, supervisory board (if any) and key functions (compliance, risk, AML, IT security) must be professionally qualified and personally reliable. The FMA conducts a hearing in the approval process in which fit-&-proper aspects are discussed.
- Transparent outsourcing arrangements: If you outsource core functions (e.g. IT operations, custody technology, KYC provider), these arrangements must be clearly documented, controllable and terminable at any time. In its information formats (e.g. "Let's talk about supervision"), the FMA has emphasized that outsourcing at CASP must meet special requirements – in particular, the outsourcing must not lead to the FMA losing effective supervision.
What costs time – realistic assessment
A CASP approval process typically goes through several time- and resource-intensive phases. The main factors that take time:
- Building substance: You need an Austrian legal form (typically GmbH), an office, local management, functioning internal structures. This means: company formation, company register entry, UBO registration, lease agreement, personnel build-up.
- Framework development: Policies, processes, roles and responsibilities must be defined, documented and operationalized. Each document must be consistent and fit your business model.
- Bank account and payment transaction connection: CASPs need a business account, often also a segregated account for customer funds (depending on the service). Banks in Austria require extensive due diligence documents. Expect considerable time to be required for a successful account opening.
- Qualified personnel: You need to find people for compliance, AML/CFT officer, risk management and IT security who have proven experience in regulated environments.
- FMA procedure: According to the FMA information letter on the CASP approval procedure, the procedure runs in several steps: application submission, confirmation of receipt, completeness check, if necessary request for improvement/additional information, content check, hearing/fit-&-proper interview, material decision. In practice, follow-up loops can significantly extend the procedure – especially if documents are unclear or contradictory.
Roadmap to the end of 2025: A practice-oriented phase model
In order to obtain a CASP license by the end of 2025 – or at least have submitted a solid application to the FMA – you need a structured approach. Here is a five-phase model to help you manage the complexity.
Phase 0: Fit/Gap analysis
Goal: Gain clarity about where you stand and what is missing.
Core activities:
- Inventory of the business model (services, jurisdictions, customer segments, legal form, team, infrastructure)
- Mapping to MiCA-CASP services in accordance with Art. 3(1)(16) MiCA
- Gap analysis: actual state vs. MiCA requirements
- Decision CASP vs. partner model
Phase 1: Target Operating Model (Governance, Roles, Policies)
Goal: Define your target operating model.
Core activities:
- Legal form and corporate structure (GmbH, shareholder structure, UBO transparency, capital equipment)
- Organization chart and roles (management, supervisory bodies, key functions in accordance with Art. 68 MiCA – this article regulates the requirements for members of the management body, including reliability and sufficient experience)
- Governance framework and risk management basic structure
- Create a policy map
Result: Target Operating Model with organizational chart, role descriptions, initial governance framework.
Phase 2: AML/KYC & Risk Framework
Objective: Build a functional AML/KYC system and comprehensive risk management.
Core activities:
- AML/KYC policy (Customer Due Diligence, Risk Classification, Ongoing Monitoring, PEP/Sanctions Screening, Suspicious Activity Reports)
- Integration of KYC tools and screening software
- Risk management framework with KRIs and reporting structures
Practical example 3 – Regulatory violation as a civil risk (2025, based on published case law)
A large European provider of crypto services fails to register or obtain a license in a timely manner under the applicable regime, even though it professionally provides services to end customers. At the same time, essential parts of the AML/KYC framework remain underdeveloped – in particular, ongoing monitoring and the documentation of suspicious cases. In subsequent court proceedings, injured parties argue that the lack of registration or licensing constitutes a violation of protective laws and justifies the provider's liability – regardless of whether "classic" breaches of due diligence can be proven in individual cases.
The court partially follows this argument and clarifies: Anyone who operates without the required status and does not take AML/KYC obligations seriously is exposed not only to administrative sanctions, but also to civil claims. For CASPs in waiting, this means: License and AML issues are two sides of the same coin – anyone who separates them or thinks of them one after the other bears a significant liability risk.
Phase 3: IT/Security/Outsourcing Readiness
Objective: Ensure that your IT infrastructure, security measures and outsourcing arrangements meet the requirements.
Core activities:
- IT security concept in accordance with Art. 73 MiCA (access control, encryption, logging, incident response, backup & business continuity)
- Outsourcing strategy with Vendor Risk Management
- Outsourcing agreements and control mechanisms
Phase 4: Application Documents & Submission
Objective: Compile all required documents and submit the application to the FMA.
Core activities:
- Complete application documents in accordance with the FMA application form and information letter
- Proof of capital resources in accordance with Art. 67 MiCA
- Submission via FTAPI (Secure File Exchange)
- Support through procedural steps (completeness check, requests for further information, hearing)
Phase 5: Post-Licensing Operation
Objective: Comply with all regulatory obligations after the license has been granted.
Core activities:
- Operational start with functioning systems
- Ongoing reporting to FMA
- Governance and Risk Reviews (at least annually)
- Preparation for on-site inspections and audits
Practical example 5 – Underestimated market surveillance (2025, anonymized)
A trading venue for crypto assets formally has a monitoring system for trading transactions, but focuses primarily on classic indicators such as volume and price spikes. More complex patterns – such as recurring wash trading structures, coordinated pump-&-dump campaigns via social media or certain MEV-like strategies – are not systematically recorded or analyzed. The supervisory authority criticizes that the provider is only inadequately fulfilling its obligations to monitor the market under MiCA, imposes measures and demands the expansion of surveillance functions.
For the operator, this means: additional investments in RegTech tools, strengthening of the compliance and market surveillance team, and closer coordination with the supervisory authority. For other CASPs, the message is clear: Market abuse surveillance is not a "nice-to-have", but an integral part of the operating model – technically, organizationally and in terms of personnel.
Result: Stable, compliant CASP operation with continuous development.
Documents & Proofs: The Checklist
Here is a structured overview of the document clusters that you need to prepare for a CASP application.
Corporate / UBO / Governance
- Articles of Association / Statutes
- Extract from the Commercial Register
- UBO Register Proof
- CVs of all managing directors and supervisory board members
- Certificates of good conduct / criminal record extracts
- Fit-&-Proper Declarations
- Organizational chart
- Job descriptions for key roles
Business Model & Risk Analysis
- Business Plan
- Programme of Operations
- Financial Planning (Revenue Forecasts, Cost Structure, Cash Flow Forecast)
- Proof of Capital Resources
- Risk Analysis and Risk Appetite Statement
Policies / Processes
- Governance Policy
- Risk Management Policy
- Compliance Policy
- AML/KYC Policy
- Complaint Handling Policy
- Conflicts-of-Interest Policy
- Remuneration Policy
- IT-Security Policy
- Business Continuity & Disaster Recovery Plan
- Outsourcing Policy
IT / Security / Incident / BCP
- IT Architecture Description
- Information Security Concept
- Access and Authorization Concept
- Logging and Monitoring Concept
- Incident-Response-Plan
- Backup and Recovery Strategy
- Business-Continuity-Plan
Outsourcing / Vendor Management
- Outsourcing Register
- Outsourcing Agreements
- Vendor Due Diligence
- Risk Analysis per Outsourcing
- Monitoring Concept
- Exit Strategy
Typical Mistakes of Crypto Projects
- Unclear demarcation of whether CASP or not: Many projects assume that they do not need a CASP license because they are "only" developing a front end. But if you actually provide custody, exchange or other regulated services, this can be problematic.
- Late engagement with governance and substance: projects underestimate the effort required to build a real corporate structure. Governance is not "a few documents", but lived organization.
- Underestimation of AML/KYC obligations: The FMA expects a well-thought-out risk management system, screening against sanctions lists, ongoing monitoring, a suspicious activity reporting system, and documentation obligations.
- Unstructured outsourcing models without clear responsibilities: If you formulate unclearly who is responsible for what, or if outsourcing agreements are incomplete, there will be requests for further information.
- Whitepaper / Tokenomics without MiCA perspective: Many whitepapers do not offer a regulatory classification. If your whitepaper uses terms such as "Staking Rewards" without explaining how this fits in with MiCA, the FMA will be skeptical.
- Missing Fit-&-Proper Evidence: Anyone who does not have relevant financial services experience, cannot provide references or has had regulatory problems in the past has poor chances.
- Defective IT security documentation: The FMA wants concrete descriptions: How are access rights regulated? Where are the private keys located? How does backup work?
- Incomplete or inconsistent application documents: Documents contradict each other. The FMA notices this and requests further information – this delays the process considerably.
- Overly optimistic scheduling: Anyone who relies on short transition periods without starting preparations in good time risks that these will expire before the license is granted.
- No bank account strategy: No operational operation without a business account. Anyone who only takes care of an account after the license has been granted loses further time.
- Misleading communication: All offers are presented as "fully regulated", although only part of them are actually MiCA-regulated CASP services. Customers do not understand the difference – and the supervisory authority reacts sensitively.
What to do next? – Three paths for your project
Path 1: Quick Check (Self-Diagnosis)
Structured questionnaire for initial orientation. At the end: rough assessment "CASP-relevant: yes/no", "Maturity level: low/medium/high", "Top 3 Gaps".
For whom: Projects in the early orientation phase.
Path 2: Readiness Workshop
Compact workshop with your team and external experts. Together you will examine your business model, governance, AML/KYC, IT and outsourcing.
For whom: Teams who want clarity quickly and are willing to invest in an intensive kick-off.
Path 3: End-to-End Support
Expert team accompanies you through all phases – from fit/gap analysis to post-licensing support.
For whom: Projects with little experience in regulated business models who want to get to the license quickly and safely.
FAQ – Frequently Asked Questions
1. Can I simply continue with my existing VASP registration?
No, not indefinitely. MiCA replaces national VASP registrations with an EU-wide licensing regime. In many member states, there is a temporary transition phase in which already registered providers can continue to work under certain conditions, but must submit a MiCA application in good time or adapt their business model. In Austria, according to the current status, a temporary transitional arrangement is planned for existing VASP registrations; under certain conditions, these providers can continue to work temporarily, but must submit a MiCA CASP application in good time and prepare for a possible orderly wind-down if the license is not granted in time. Status: December 2025 – the specific design (deadlines, conditions) of the Austrian transitional arrangement may still change; please check the current status on the FMA website. In its statements on MiCA Transitional Measures, ESMA emphasizes that providers who do not receive a MiCA license by the end of the transitional phase must discontinue their CASP services and wind down customer relationships in an orderly manner.
2. Do I need a registered office in Austria to get a CASP license from the FMA?
Basically, yes. According to the current understanding of Austrian supervisory practice, you must establish or maintain a company based in Austria (typically a GmbH) if you want to apply for a CASP license from the FMA. The FMA expects the management to be based in Austria and the ongoing administration to actually take place from Austria – i.e. office, business address and operative substance on site; mere "letterbox seats" are not sufficient. The specific substance requirements result from the MiCA Ordinance Enforcement Act (MiCA-VVG), the Financial Market Supervision Authority Act and the lived FMA supervisory practice and may continue to develop over time. Status: December 2025 – for specific projects, the current legal status and the information of the FMA should be checked, ideally in addition to individual legal advice.
3. Which functions do I have to fill internally (Compliance, AML, Risk)?
MiCA requires CASPs to have certain key functions. According to Art. 68 MiCA and the FMA practice, these typically include:
- Compliance Officer
- AML/CFT Officer
- Risk Manager
- IT-Security Responsible
4. Can I outsource IT and Operations completely?
Basically yes, but only under clear conditions. MiCA allows the outsourcing of important functions, but requires that the CASP retains overall responsibility and can effectively control and monitor the outsourced areas. Neither governance nor risk management or compliance may be factually "transferred" to the service provider. The FMA emphasizes in its information formats that, especially for CASPs, critical functions (e.g. IT operation, custody technology, KYC provider) may only be outsourced in such a way that the supervisory authority retains insight and access to the relevant information at all times; pure "black box models" are problematic. Outsourcing agreements should therefore contain clear service descriptions, control and audit rights, exit strategies and regulations on data availability. Status: December 2025 – which functions are still considered "core functions" in individual cases and should not be completely outsourced results from MiCA, the MiCA-VVG and the lived FMA practice; project-specific legal review is recommended here.
5. How does passporting work in other EU countries?
As soon as you have obtained a CASP license in an EU member state, you can in principle use this approval to provide your services in other EU countries. This is done by means of so-called passporting: You report to your home supervisory authority (in Austria the FMA) in which other member states you want to operate; this in turn informs the supervisory authorities of the affected host states. The basic principle is laid down in MiCA itself, but the details on the procedure, deadlines and technical requirements are specified by supplementary regulatory and implementing standards (RTS/ITS), which are gradually finalized and put into force by ESMA and the EU Commission.
Status: December 2025 – anyone who wants to use passporting should check the current status of the technical standards and the relevant guidelines of ESMA as well as the practice of the home supervisory authority and, if in doubt, seek expert advice.
6. What happens if I don't have a MiCA license by the end of the transition period?
Then you are no longer allowed to provide CASP services. ESMA has made it clear that providers must carry out an orderly wind-down: do not onboard new customers, inform and process existing customers, do not accept new transactions. Anyone who continues despite the lack of a license is engaged in unauthorized business activity – this can lead to fines and criminal consequences.
7. What costs will I incur?
This cannot be quantified across the board, because the total costs depend heavily on your business model, your target market and your chosen operating model. Typical cost blocks are: – Official fees: CASP approvals are subject to fees according to the relevant tariffs of the FMA and the general fee regulations; the specific amount depends on the type and scope of the application and should be taken from the current information of the FMA. – Legal and compliance advice: External support for MiCA analysis, structuring of the business model, document creation and support of the FMA procedure is usually a significant cost factor. – IT & Security: Development or expansion of IT infrastructure, custody solutions, KYC/AML tools, logging and monitoring systems as well as incident response and BCP capacities. – Personnel & Organization: Management, Compliance, AML/CFT, Risk Management, IT Security and Operations – often the largest ongoing cost block. – Office & Infrastructure: Physical presence in Austria (office, equipment, ongoing fixed costs) as part of the required operational substance.
8. Is the CASP license valid indefinitely?
The CASP approval is generally valid indefinitely as long as you comply with the regulatory requirements. There is no regular "renewal" as with some national licenses. However, the FMA can check at any time and withdraw the license in the event of serious violations.
9. Do I need a MiCA license if I am based outside the EU?
That depends on whether and how you address EU customers. The basic principle is: Anyone who actively serves EU markets is subject to EU rules – even if the registered office is outside the EU. The supervisory authorities distinguish between genuine "reverse solicitation" (customer approaches you on their own initiative without you having actively approached them) and active market cultivation.
Practical example 4 – Reverse Solicitation as a Boomerang (2025, anonymized)
A crypto provider based outside the EU assumes that it does not need a MiCA license as long as it formally invokes “reverse solicitation” – i.e. only responds to customers who approach the offer on their own initiative. There is a corresponding disclaimer on the website. In fact, however, the provider operates localized websites in several EU languages, places targeted online advertising in EU markets and cooperates with European influencers. The responsible supervisory authority assesses these activities as actively addressing the EU market and classifies the offer as an unauthorized cross-border provision of crypto services. The consequences: The provider must discontinue its offer in the affected countries, stop marketing measures and expect warnings and reputational damage. This example shows that projects should not rely on supposed “gray areas” in reverse solicitation. If the target market is actually in the EU, it should be clarified at an early stage whether a MiCA license or cooperation with a regulated EU partner is required.
NEXORA provides you with a compact MiCA CASP Implementation Toolkit that directly ties in with the roadmap described in this article. It comprises three central building blocks that you can use to prepare for a CASP license in Austria and the EU: A) CASP Readiness Checklist – Clear checklist with all critical areas: Governance & Organization, Business Model & Risk Analysis, AML/KYC, IT Security, Outsourcing, Documentation, Schedule. – Each field can be marked with a maturity level (e.g. “not started”, “in progress”, “largely fulfilled”) and serves as the basis for your internal fit/gap analysis. B) Application documents – Sample structure (table of contents) – Structured structure of your FMA application package, based on the typical document clusters: General information, business model & strategy, governance & organization, risk management & compliance, IT & security, outsourcing, capital resources, attachments. – Helps you to organize your business plan, programs of operations, policies and evidence in such a way that they build on each other consistently. C) Operating Model Canvas for CASP – Visual canvas with ten building blocks: CASP services, customer segments, core processes, roles & functions, technology & infrastructure, compliance & risk controls, outsourcing & partners, financial model, regulatory interface, implementation phases. – A supplementary guide with examples and formulation aids supports you in documenting your target operating model in a MiCA-compliant manner – from onboarding processes and AML controls to FMA reporting and growth phases.
What to do next? – Our offers for you
Next step: If you are looking for a structured introduction after reading this article, use the MiCA CASP Implementation Toolkit as a starting point – with a readiness checklist, sample structure for application documents and CASP Operating Model Canvas. In combination with a short readiness call or workshop, your biggest gaps and priorities can be identified within a few days. Projects with their own compliance/legal team can use the toolkit as a basis for internal development; those with little regulatory experience usually benefit from end-to-end support, in which documents and the operating model are developed together with experienced consultants.
1. MiCA/CASP Readiness Check (Fixed Scope)
Structured analysis of your current status with executive summary, prioritized gap list and rough roadmap. Ideal as a basis for decisions for the board/investors.
2. Regulatory Roadmap & Document Package
Detailed roadmap with phase planning, document template package and checklists. For projects with internal capacities that need structure and templates.
3. Partner screening: Selection of a CASP/EMI partner
If you are pursuing a partner model: market screening, due diligence and support in contract negotiations.
Would you like to set up or sharpen your MiCA/CASP setup professionally?
- Free 30-minute initial consultation: Discuss your business model, your MiCA questions and receive an initial assessment of CASP license vs. partner model, transition periods and location choice in Austria (non-binding, without obligation).
- MiCA/CASP Readiness Assessment (Fixed Scope): Structured fit/gap analysis along the phases described in this article – governance & substance, business model, AML/KYC, IT security, outsourcing – with prioritized list of measures and management summary (typically: 2–3 weeks).
- CASP Operating Model & Application Documents: Development or review of your CASP operating model based on the Operating Model Canvas (services, customer segments, processes, roles, IT, outsourcing, financial model, FMA interface) as well as structuring and quality assurance of the application documents for the FMA.
- Partner Model & Provider Selection: Support in deciding between a CASP own license vs. a regulated partner (CASP/EMI), market screening of suitable providers and support in the design of contractual and communicative demarcation.
Contact us for a non-binding consultation:
About NEXORA Unternehmensberatung GmbH:
NEXORA Unternehmensberatung GmbH is a consulting firm based in Vienna specializing in RegTech, FinTech and strategic Regulatory Guidance. We support companies in navigating complex regulatory requirements in Austria and the EU.
Our focus: Market Entry & Location Selection, Compliance & RegTech (with a focus on MiCA & CASP licensing), Digital Transformation & Operating Model Design.
Our team combines in-depth regulatory know-how with practical implementation experience.
Disclaimer
This article does not constitute legal, tax or investment advice. All information is of a general nature and is for informational purposes only. The regulatory landscape is constantly evolving.
An individual legal, tax and regulatory review is essential for specific projects. NEXORA Unternehmensberatung GmbH assumes no liability for decisions made on the basis of this article.
Sources & further links
- Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA)
- ESMA – MiCA page
- FMA Austria – CASP approval
Need a consultation?
Book a free initial consultation with the NEXORA team.