Custody Won the MiCA Register: How to Scope CASP Permissions
- Custody appears on 194 of the roughly 330 CASP authorizations on ESMA’s register; operating a trading platform appears on twenty. The industry licensed itself as broker-dealers with wallets.
- Annex IV Class 1/2/3 are capital floors keyed to your highest-risk service, and Article 59 requires the authorization to name each service individually. Class 3 grants nothing beyond the platform permission you asked for.
- ESMA’s Q&A 2653 settles exchange vs execution vs RTO on the order fulfillment flow and whose capital fills the trade, so contractual labeling does not decide the permission.
- Advice and portfolio management sit on the EUR 50,000 floor with the heaviest conduct load in the regime, and only 34 and 48 authorizations carry them.
- Staking, lending and DeFi still have no dedicated permissions, and the Commission’s consultation asks at Questions 61, 66 and 67 whether that should change. It is a working document.
Of the roughly 330 CASP authorizations sitting on ESMA’s register on 20 August 2026, twenty carry permission to operate a trading platform, while custody and administration appears on 194 of them, transfer services on 193, and exchange of crypto-assets for funds on 166, according to one tabulation of the register. An independent count two weeks earlier reached 329 authorizations with 21 trading platforms but put custody considerably higher at 221 and transfers at 206, so treat the service-level numbers as approximate rather than audited. The distribution is the same under either count, and it is worth sitting with, because an industry that spent a decade describing itself in the language of exchanges came out of the EU licensing process holding custody permissions and quoting prices off its own balance sheet.
Most MiCA scoping goes wrong in that gap between the word a firm uses for itself and the permission it holds, because there is no generic CASP license to apply for. Article 59 requires the authorization to name the individual crypto-asset services the provider may perform, so a firm holding the trading-platform permission and nothing else cannot give advice, cannot run a dealer book, and cannot custody a single client key, no matter what its capital class implies.
Annex IV sets the floor, Article 59 sets the permissions
The Class 1 / Class 2 / Class 3 labels get read as tiers because they are laid out like tiers, with Annex IV putting execution, placing, transfer, reception and transmission, advice and portfolio management at EUR 50,000, adding custody and the two exchange services at EUR 125,000, and topping out at EUR 150,000 once trading-platform operation enters the picture. Each class is written to include the one below it, which is exactly what makes it misleading, because the inclusion is arithmetic rather than entitlement. The classes tell you what the floor is once you already know which services you hold, and they never hand you the services themselves.
And the floor stops binding almost immediately for anything with real infrastructure behind it, because Article 67 sets the requirement at the higher of the Annex IV minimum and one quarter of the preceding year’s fixed overheads. A trading platform running a matching engine, a market-abuse surveillance function, order-book retention and a DORA-grade ICT stack will clear EUR 600,000 in fixed costs without trying, at which point the EUR 150,000 headline is a historical curiosity and the overheads calculation is the number the supervisor cares about. Applicants have to project that requirement across their first three business years under stress assumptions anyway, which Delegated Regulation (EU) 2025/305 spells out alongside expected client counts, order volumes and projected assets under custody.
At the bottom end the classes invert the risk they appear to describe. Advice and portfolio management sit on the EUR 50,000 floor while carrying the heaviest conduct load in the regime, with mandatory suitability assessment, periodic reporting, knowledge and competence requirements for the staff giving the recommendation and a prohibition on retaining third-party inducements, and only 34 and 48 authorizations on the register carry them respectively. A firm that bolts a recommendation engine onto its interface to make onboarding smoother has bought a suitability obligation at the price of the cheapest capital tier, which is a trade very few product roadmaps price correctly.
The order fulfillment flow decides the permission
Scoping gets genuinely hard at the line between exchange, execution and reception and transmission, because all three describe a client who wants to buy something and a firm that makes it happen. ESMA answered that directly in Q&A 2653 in October 2025, and the test is mechanical rather than commercial. A firm that concludes the purchase or sale contract on the client’s behalf is acting as agent and performing execution. A firm that hands the order to a third party which concludes the contract or forwards it further is performing reception and transmission. A firm that concludes the contract with the client using proprietary capital is performing exchange, and the assessment runs on the order fulfillment flow and the balance sheet rather than on how the arrangement is papered.
Applied to a product surface, this is less abstract than it reads. An instant-buy button that fills from the firm’s inventory is a Class 2 exchange service, the same button routed to a liquidity provider is reception and transmission, and the same button where the firm concludes the trade for the client at a venue is execution. A retail app doing all three across different pairs and different times of day needs all three permissions, and the fact that the user journey looks identical in every case is precisely why product teams ship the regulated function without noticing.
Two adjacent clarifications tighten the same screw. Article 78(5) requires prior express consent before executing outside a trading platform, and Q&A 2711, answered on 8 December 2025, reads “trading platform” there as meaning only entities authorized under Article 59, so OTC arrangements, third-country venues and decentralized exchanges all trigger the consent requirement. Then in June 2026 ESMA held in Q&A 2882 that MiCA’s advice perimeter is broader than the MiFID II equivalent, and that an introductory service recommending a particular CASP can constitute advice even without any recommendation about a specific crypto-asset, provided the recommendation is personalized and presented as suitable (a generic reference equally available to everyone stays outside). Referral and affiliate businesses built on the assumption that they were merely pointing at a provider should read that one twice.
Custody is the permission that swallows the others
Nothing else on the register comes close to custody’s 194 authorizations, and the reason is that custody keeps absorbing activities that look like separate businesses. Staking is the clearest case, since MiCA contains no staking permission at all, and Q&A 2067 treats staking-as-a-service as a custody service the moment an intermediary holds the client’s assets or keys and stakes them on the client’s behalf, with the segregation, liability and consent obligations that come attached. Pre-funding is the less obvious case, because ESMA concluded in July 2025 that using a client’s crypto-assets to pre-fund that client’s orders qualifies as sub-custody, permissible only where the third party holding those assets is itself an authorized custody CASP, with a carve-out only for the direct settlement of transactions already executed. That quietly closes off a common liquidity shortcut.
Whether a wallet product is custodial is a question about control rather than contract drafting, and the statutory language covers safekeeping or controlling the means of access, including private cryptographic keys. An MPC scheme where the provider holds a share that can reconstruct a signature, a smart-contract wallet with an upgrade key or a company-held co-signer, a recovery flow that lets support move funds, and a policy engine that can freeze a withdrawal all point at control regardless of what the marketing page says about self-custody. A firm describing itself as non-custodial should be able to prove it with the key ceremony and the signer thresholds rather than with its terms of service.
Supervisory weight has followed the permission, and on 8 July 2026 ESMA launched a Common Supervisory Action on CASPs’ digital operational resilience for custody, running across a risk-based sample from the second half of 2026 into the first half of 2027, with NCAs examining governance, key and storage management, transaction controls, incident detection and response, smart-contract risk and third-party dependencies. A firm that treated the custody application as a legal exercise and the key infrastructure as a vendor problem is going to have an uncomfortable eighteen months.
The broker funnel does not survive contact with a supervisor
There is an obvious arbitrage available in a regime that licenses functions individually, which is to license the cheapest function in the EU and keep the expensive one offshore, and ESMA saw it coming. Its Opinion on broker models from 31 July 2024 describes groups seeking authorization only for brokerage while leaving the trading platform outside MiCA, and instructs NCAs to assess whether the EU applicant would in fact be soliciting clients for the group’s non-EU entities, to pay close attention to hedging schemes whose main purpose or effect is channeling EU order flow systematically to a single non-EU execution venue, and to refuse authorization outright where structural conflicts of interest have been left inadequately managed.
The same instinct produced the shared order book Q&A in June 2025, which holds that merging an EU platform’s book with one operated by a non-EU entity breaches the authorization requirement, because managing the unified multilateral system is itself operation of a trading platform. Article 75 does the equivalent for custody by requiring that any onward custodian be authorized under Article 59, which rules out placing client assets with a technically superior offshore custodian. Three different provisions carry the same principle, and global groups keep testing it anyway.
For operators, the other structural rule sits in Article 76(5), which bars a trading-platform operator from dealing on own account on the platform it runs, including where it separately holds exchange permissions. The carve-out in Article 76(6) allows matched principal trading with client consent, notification to the competent authority and ongoing monitoring, and it is narrow enough that treating it as a route to running a house book on your own venue would be a misreading.
The passport carries the permissions you have and nothing else
Cross-border expansion under Article 65 is administratively light, since the CASP notifies its home authority of the host Member States, the services it intends to provide there and the intended start date, the home authority has ten working days to communicate that to the host single points of contact along with ESMA and the EBA, and the firm may begin on receipt of that communication or at the latest on the fifteenth calendar day after submission, with host states barred from demanding a physical presence for cross-border provision alone. What travels is the schedule on the license, so a custody-only CASP passporting into six markets acquires six markets’ worth of custody clients and no brokerage rights anywhere.
That makes the home-state decision less strategic than it is usually sold. Germany accounts for 71 of the authorizations on the register, France 34, the Netherlands 28, Cyprus 24 and Malta 22, and that clustering reflects supervisory throughput, banking access and local infrastructure rather than any difference in what a permission permits. ESMA’s supervisory briefing on CASP authorization of 31 January 2025 pushed authorities toward examining operational substance, locally based personnel, management expertise and genuine autonomy over outsourced or group-provided functions, which is why a letterbox in a fast jurisdiction is a worse plan now than it looked during the transition. Third-country firms leaning on the exclusive-initiative exception face the same tightening from the other side, since ESMA’s reverse solicitation guidelines treat EU-directed marketing, affiliate funnels and campaigns as solicitation rather than as client initiative.
Staking, lending, and the services MiCA declines to name
Custodial staking sits inside custody, and direct staking by an asset holder sits outside MiCA entirely, which leaves a genuine gap for validator businesses and delegation products that never touch a client key. Lending sits in a similar gap with sharper edges. ESMA published Q&A 2883 on 18 June 2026, framed as whether CASPs can offer crypto-asset lending services under MiCA and under which conditions, particularly with respect to the use of clients’ crypto-assets. The framing is the tell, since there is no lending permission for a desk to need, and the pressure sits entirely on whether assets held under a custody authorization can be redeployed into a lending book, which Article 70’s prohibition on using client crypto-assets for the CASP’s own account governs regardless of what the product is called.
Presentation is the other exposure, and ESMA addressed it in a public statement on 11 July 2025 warning that a CASP’s regulated status “may create a ‘halo effect’ that may often serve to provide potentially misguided reassurance” about unregulated products on the same platform, and noting that some providers “may even use their regulated status under MiCA as a marketing argument and encourage the confusion.” Separating the two is a matter of interface, contracting and legal-entity attribution, and burying the distinction in terms and conditions is the specific failure the statement describes.
DeFi remains the largest unresolved boundary, with Recital 22 excluding services provided in a fully decentralized manner without any intermediary while leaving no operative test for what that means, so the analysis falls back on who performs the function. A protocol with a company-controlled front end that chooses routes, holds upgrade keys, matches orders or charges clients for execution is doing things the ten service definitions describe, and the decentralization of the settlement layer underneath does not undo that.
All three gaps are now live policy questions rather than settled ones. The Commission’s targeted MiCA review consultation, The Commission’s targeted MiCA review consultation, which ran from 20 May 2026 and closed on 31 August, asks at Question 45 whether the Article 3(16) service list adequately covers crypto-asset markets, at Question 66 whether the current approach of not separately regulating staking is adequate, at Question 67 whether lending and borrowing should be regulated at all, and at Question 61 which criteria signal decentralization, listing the existence of an identifiable intermediary and the presence of control by an identifiable person or group among them. The document is explicit that it “is a working document of the Commission services for consultation and does not prejudge the final decision,” so none of it is law and none of it should be built into a licensing plan. It is worth noting, though, that the consultation describes “around 170 CASPs listed in the ESMA register,” roughly half the number tabulated there in August 2026, which is a drafting-snapshot artifact and also a decent measure of how fast the population moved once the transition closed. The Commission owes its review report to the Parliament and the Council by 30 June 2027, so the answers to those four questions land well after every licensing decision being taken now.
Issuing a token is not providing a service
Token issuers keep being told they need a CASP license, and for the plain case that is wrong. ESMA confirmed in Q&A 2417 that an issuer distributing newly issued crypto-assets directly from a smart contract to purchasers’ wallets during a primary issuance is providing neither transfer nor custody services, because both definitions require acting on behalf of another person and an issuer distributing its own tokens is not doing that. Issuance and offering are governed by the issuer and offeror titles, with white paper and disclosure obligations that have nothing to do with Title V.
Placing is the permission that catches the intermediary rather than the issuer, since it covers marketing crypto-assets to purchasers on behalf of or for the account of an offeror, and only 32 authorizations on the register carry it. A launchpad running token sales for third-party issuers is squarely in that population, and it usually stacks further permissions on top depending on what else the platform does, because listing the token for secondary trading brings in the platform permission, holding sale proceeds and allocations brings in custody, and filling participant orders brings in execution or exchange.
The second perimeter nobody scopes for
MiCA classification answers only half the question for payment-adjacent models, and the EBA closed the grace period on the other half. Its no-action letter of 2 June 2025 gave CASPs transacting e-money tokens a transition on dual authorization, that period ended on 2 March 2026, and on 12 February 2026 the EBA advised national authorities to require CASPs that do not meet the conditions to discontinue the provision of such EMT services, with more than 100 CASPs having filed for payment institution authorization since June 2025. A transfer permission under MiCA is not a payment services license, and an EMT product that functions as a payment service needs the second authorization.
The classification question upstream of all of this is whether the token is a financial instrument at all, which ESMA’s guidelines on the qualification of crypto-assets address. Tokenization platforms get this backwards constantly. Putting a share or a bond on a distributed ledger leaves it a security, subject to MiFID II, MAR, the prospectus rules and possibly the DLT Pilot Regime, and no breadth of CASP permission touches that perimeter.
Enforcement before there is case law
Title V has been fully applicable since 30 December 2024 and the last transitional entitlement expired on 1 July 2026, which is not enough time to have produced merits case law construing the ten service definitions. What exists instead is supervisory precedent, and the largest number attached to an EU crypto firm so far came from adjacent law. On 6 November 2025 the Central Bank of Ireland imposed a EUR 21,464,734 penalty on Coinbase Europe after system faults left 30,442,437 transactions worth EUR 176 billion, around 31% of the firm’s transactions in the relevant window, not fully and properly monitored between 23 April 2021 and 19 March 2025, with the sanction confirmed by the High Court on 12 January 2026 and reflecting a 30% settlement discount off an original EUR 30,663,906. That was Irish anti-money-laundering law rather than a MiCA infringement, and calling it MiCA enforcement is wrong, but transaction monitoring sits inside every CASP authorization file and every ongoing supervisory review.
Authorization decisions are themselves being audited. ESMA’s fast-track peer review of the MFSA, published 10 July 2025, rated the authority as fully meeting expectations on supervisory resources and expertise while finding the authorization process only partially met expectations, with material issues unresolved or pending remediation at the point of authorization and the review committee questioning why the process was not used to force remediation before the license took effect. Jurisdiction shopping does not survive that kind of scrutiny, and it never changed the definition of the service being requested anyway.
Scope the smallest complete set
Requesting permissions defensively is a worse strategy than it looks, because each additional service brings its own policies, systems, staffing and supervisory surface, and a higher-risk permission drags the whole file up with it. Missing one is worse, since providing an unnamed service is unauthorized business, and ESMA’s statement of 23 June 2026 told unauthorized providers to immediately stop onboarding new EU clients, refrain from opening accounts, cease marketing and limit activity to what is necessary to sell, transfer or close out positions.
For every order path in the product, establish who the client’s counterparty is, whose capital fills the trade, who holds or can reconstruct the key, who selects the venue, who signs and broadcasts the transaction, whether third-party interests are being brought together under system rules, and who earns each fee or rebate. Those facts map onto Article 3 without much interpretive room, and the answers change when a product team ships a swap button, a staking toggle, a routing upgrade or a recovery feature, which is why the permission schedule needs a change-control gate rather than an annual review.
What the register suggests is that most firms landed on custody plus transfers plus a dealer permission, which describes a broker-dealer with a wallet rather than an exchange. Twenty firms in the EEA run a multilateral order book, and everyone else on that list quotes a price, holds the keys and moves the assets.
See more: View EU-regulated companies for sale
Frequently Asked Questions (FAQ)
Does a Class 3 MiCA license let me provide all ten crypto-asset services? +
No. Annex IV classes are permanent minimum capital groupings. Article 59 requires the authorization to name the individual services, so the EUR 150,000 figure applies once you hold the trading-platform permission and tells you nothing about which other services you may perform.
Do I need a separate MiCA permission for staking? +
There is no staking permission. ESMA's Q&A 2067 treats staking-as-a-service as a custody service the moment an intermediary holds the client's assets or keys and stakes them on the client's behalf. Direct staking by an asset holder sits outside MiCA.
Is crypto lending regulated under MiCA? +
MiCA contains no lending permission. The live constraint is Article 70's prohibition on using client crypto-assets for the CASP's own account. ESMA published Q&A 2883 on 18 June 2026 addressing the conditions attaching to the use of clients' crypto-assets, and the Commission's consultation asks at Question 67 whether lending and borrowing should be regulated at all.
Can a MiCA trading platform make markets on its own venue? +
Article 76(5) bars the operator from dealing on own account on the platform it operates, including where it separately holds exchange permissions. Article 76(6) permits matched principal trading with client consent, notification to the competent authority and ongoing monitoring.
Does the MiCA passport extend my permissions in host Member States? +
It carries only the services named on the authorization. Under Article 65 you notify the home authority of host states, services and start date, the home authority has ten working days to communicate it onward, and you may begin on receipt or at the latest on the fifteenth calendar day after submission.
Does an issuer selling its own token need a CASP license? +
Not for the plain case. ESMA's Q&A 2417 confirms that distributing newly issued crypto-assets directly from a smart contract to purchasers' wallets is neither transfer nor custody, because both definitions require acting on behalf of another person. A launchpad marketing tokens for third-party issuers usually needs placing.
Does a MiCA transfer permission cover crypto payments? +
No. The EBA's no-action letter transition on dual authorization ended on 2 March 2026, and on 12 February 2026 the EBA advised NCAs to require CASPs not meeting the conditions to discontinue EMT services that qualify as payment services. That is a separate payment services authorization.
