All entries
Chapter VIII
Journal · 08 Sept 2026 · 13 min read

MiCA CASP Licence for Crypto Off-Ramps in 2026

Which MiCA licence a crypto-to-fiat off-ramp needs: Class 2 capital, the Article 63 clock, the PSD2 line the EBA moved, and what DORA now adds.

Seventy-five firms were authorised under MiCA in June 2026. That is 22% of the entire register, granted in the last month before grandfathering expired on 1 July. Whatever the statutory timetable says, that is not what determined when anyone got a licence.

ESMA's interim register, as served on 7 September 2026, carries 341 rows covering 337 legal entities across 26 Member States, Germany alone holding 84. Only 180, 53%, hold the permission that matters for an off-ramp: exchange of crypto-assets for funds. What follows is what that licence forces into the system, not what it costs in legal fees.

What Is a MiCA CASP Licence, and Which One Does an Off-Ramp Need?

A crypto-to-fiat off-ramp is Article 3(1)(16)(c) of Regulation (EU) 2023/1114: "exchange of crypto-assets for funds". Article 3(1)(19) defines that service as dealing using proprietary capital. You are the counterparty. The client sells you USDC and you owe them euros from your own book.

ESMA's Q&A 2293 of 6 June 2025 marks both edges. Proprietary trading with no client relationship is not a crypto-asset service at all, and neither is market making on somebody else's venue. Exchange with clients, using your own capital, is. Route the order to a third party instead of taking it on your book and you are doing reception and transmission, which sits in a lower capital class. Engineers call both "the off-ramp". The regulation does not.

Article 59(2) adds substance most architecture diagrams ignore: a registered office in a Member State where you carry out at least part of your services, place of effective management in the Union, and at least one director resident in the Union.

How Much Capital Does a MiCA Off-Ramp Need in 2026?

Annex IV sets three classes: €50,000 for Class 1 (execution, transfers, reception and transmission, advice), €125,000 for Class 2, covering custody and exchange for funds, and €150,000 for Class 3 with a trading platform. Q&A 2343 confirms you take the highest class across your services, not a blend.

The floor is rarely binding. Article 67(1) requires the higher of the class minimum and one quarter of the previous year's fixed overheads. Run €4m of annual overheads and your requirement is €1m, eight times the headline figure.

What counts as an overhead only became clear this year. ESMA Q&A 2349, answered 18 February 2026 via the European Commission, says "fixed overheads" in Article 67(3) means the total of all overheads, fixed and variable, with only the four deductions that article lists: profit-dependent bonuses, employee and director profit shares, other discretionary profit appropriations, and non-recurring expenses from non-ordinary activities. That list is exhaustive. Article 13(4) of the Investment Firms Regulation (EU) 2019/2033 sets a minimum list and lets firms add to it. MiCA does not, so an IFR-style deduction schedule under-provisions you.

Can a Bank or an EMI Skip MiCA Authorisation Under Article 60?

A credit institution can notify in under Article 60(1), and a MiFID firm authorised for dealing on own account under Article 60(3)(c). Both give 40 working days' notice.

An electronic money institution cannot. Article 60(4) limits an EMI's notified services to custody and administration, and transfers, and only for the e-money tokens it issues itself. Exchange for funds is not on that list, so an EMI needs full Article 63 authorisation like everyone else.

How Long Does MiCA CASP Authorisation Take?

The Article 63 clock reads faster than it runs.

StageLimit
Written acknowledgement5 working days, 63(1)
Completeness assessment25 working days, 63(2)
Gap-fill for missing informationa deadline the authority sets, no fixed length
Assessment and reasoned decision40 working days from a complete application, 63(9)
One suspension for further informationup to 20 working days, 63(12)

Two mechanics matter. The 40 days run from the completeness notification under 63(4), not from submission, so that letter is the real starting gun. And 63(12) stops the clock once only, on a request made no later than the 20th working day, for no more than 20 working days; further requests are discretionary and do not suspend. Sources claiming the clock cannot be suspended at all are wrong. Statutory worst case lands near 95 working days plus the gap-fill window.

Actual durations are published by nobody, so every "six to twelve months" figure in circulation is a consultancy estimate. Two real signals beat them. The Dutch AFM charges €200 an hour capped at €100,000, implying up to 500 supervisor-hours per file. And the register shows 148 authorisations across all of 2025 against 188 in the first eight months of 2026, 75 of them in June. Deadlines drove the queue, not the assessment period.

Does a MiCA Licence Let You Pay Out Euros? The PSD2 Line Moved

The usual framing is that Article 70(4) means a CASP licence carries no payments permission, so the euro leg needs PSD2 authorisation. That was the line I used in an earlier piece on where crypto-to-fiat payouts fail, and it is now too blunt.

The EBA's Opinion on the PSD2 and MiCA interplay (EBA/Op/2025/08, 10 June 2025) advises national authorities at paragraph 23 not to treat exchange of crypto-assets for funds as a payment service at all. Paragraph 69 gives the reason: the service uses the CASP's proprietary capital, so the CASP is a buyer in its own name rather than an intermediary between a payer and a payee.

What the same paragraph puts inside PSD2 matters more. Transfers involving e-money tokens carried out on behalf of clients are payment services, as is custody of EMTs where the wallet lets a client send to and receive from third parties, and in that case the wallet is a payment account. Paragraph 71 adds that first-party transfers between two wallets held by the same person still count. The follow-up Opinion EBA/OP/2026/01 of 12 February 2026 ended the transition on 2 March 2026, its paragraph 15 catching EMT transfers "to the same client as part of the pay-out leg of custody".

My reading, and the whole licence hangs on it: the question is not whether euros move, it is whether you ever hold stablecoins for a client and move them. A pure principal exchange, where the client sends USDC from their own wallet, you buy it with your own capital and a third-party PSP sends the SEPA credit, keeps the exchange leg outside PSD2. Give that client a hosted balance they can send from and you have built a payment account, with strong customer authentication under PSD2 Articles 97 and 98 on wallet access and before initiating a transfer, enforced since 2 March 2026.

One consequence to price in: Article 64(2)(b) lets an authority withdraw the CASP licence if you lose a PI or EMI authorisation and fail to remedy within 40 calendar days. Coupling the licences couples the failure modes.

What MiCA Article 77 Means for Your Quote API

Article 77 is the closest MiCA comes to specifying an endpoint. You must publish a firm price or the method for determining it, together with any limit you apply on the amount to be exchanged (77(2)). You must execute at the displayed price at the moment the order became final, and tell clients the conditions under which an order is deemed final (77(3)).

ESMA Q&A 2181 of 17 May 2024 puts hard edges on that. Publication must be in a location accessible to all without registration. The quotation "should include all elements allowing a party to anticipate with certainty the price at which an exchange would be made". Executed transaction data should stay available until midnight of the following business day.

Three common designs break against that. An indicative quote with client-absorbed slippage does not let anyone anticipate the price with certainty. A quote endpoint behind an API key is not accessible without registration. And "final" cannot be a vague client-side moment, because the price you owe is the one displayed at that instant. Article 62(2)(o) then requires the authorisation application itself to describe your price-determination methodology, so you write the pricing algorithm down, legibly, before you have a customer.

What MiCA Record-Keeping Requires From Your Database

Article 68(9) requires records of all services, orders and transactions, kept five years and extendable to seven. Delegated Regulation (EU) 2025/1140, in force since 30 June 2025, says how. Article 2(1) sets four conditions on the storage medium: authorities can reconstitute each key stage of the processing of every order; corrections and amendments and the contents before amendment are easily ascertainable; it is not possible to manipulate or alter the records; and the data can be exploited by an ICT system.

A mutable row in a relational table fails at least two of those. What passes is an append-only event log where a correction is a new event carrying the prior value, with current state derived rather than overwritten.

The formats are equally specific: ISO 8601 timestamps as YYYY-MM-DDThh:mm:ss.ddddddZ, microsecond fraction, in UTC; LEI for legal-entity clients; an ISO 24165 Digital Token Identifier for each crypto-asset. Articles 9 and 10 require a designation identifying the person or algorithm whose decision determined execution. If pricing is automated, that is a column naming the algorithm version, and it has to be right retrospectively.

Does the EU Travel Rule Have a €1,000 Threshold?

For crypto transfers, no. Not at any amount. This is the most common mistake I see in scoping documents, and it comes from importing the wire-transfer rules by analogy.

Regulation (EU) 2023/1113 has applied since 30 December 2024. Recital 30 states that transfers of crypto-assets are subject to the same requirements "regardless of their amount". The funds side of the same regulation does have thresholds, at Articles 5(2)(b), 6(2) and 7(3), all €1,000. There is no crypto analogue, and Article 37(3)(d) proves it structurally by asking the Commission to assess the costs and benefits of introducing de minimis thresholds for crypto.

The field sets are asymmetric, and that is easy to get wrong:

FieldOriginator, Art. 14(1)Beneficiary, Art. 14(2)
Namerequiredrequired
DLT address and account numberrequiredrequired
Address, official document number and customer ID, or date and place of birthrequirednot required
LEI or equivalentwhere the message format carries itwhere the message format carries it

Article 14(6) and (7) require you to verify the originator set only, from a reliable and independent source. Article 14(8) then blocks the transfer outright: you "shall not allow for the initiation, or execute any transfer, of crypto-assets before ensuring full compliance with this Article". No risk-based derogation, unlike Article 4(6) on the funds side.

The €1,000 that does exist governs something else. Under Article 14(5), second subparagraph, a transfer exceeding €1,000 to a self-hosted address obliges the originator's CASP to assess whether that address is owned or controlled by the originator, and Article 16(2) mirrors it on the receive side. The EBA Travel Rule Guidelines (EBA/GL/2024/11) list acceptable checks at paragraph 83: attended or unattended verification, a satoshi test sending a predefined minimal amount, or a digital signature over a message using the address's key. Paragraph 86 permits whitelisting, provided controls detect a change in risk or ownership. Paragraph 82 measures the €1,000 at the rate at the time of transfer and excludes fees, so gas does not count.

Why DORA, Not Capital, Is the Real MiCA Gate

This section is opinion, and it is the position I would defend hardest.

DORA, Regulation (EU) 2022/2554, has applied to CASPs since 17 January 2025, and there is no simplified regime available. The Article 16(1) list of entities that get the lighter framework is closed, and CASPs are absent from it. Size is irrelevant: Articles 5 to 15 apply in full, and Title I of Delegated Regulation (EU) 2024/1774 binds a ten-person off-ramp exactly as it binds an exchange. MiCA routes you there explicitly, with Article 68(7) requiring "resilient and secure ICT systems as required by Regulation (EU) 2022/2554".

The incident deadlines sit in Article 5 of Delegated Regulation (EU) 2025/301: initial notification within 4 hours of classifying an incident as major and no later than 24 hours from becoming aware; intermediate report within 72 hours of submitting the initial notification, even if nothing has changed; final report no later than one month after the intermediate. That 72 hours is routinely misquoted as running from awareness.

Two 2026 signals say this is where supervision is heading. ESMA launched a Common Supervisory Action on CASPs' digital operational resilience for custody on 8 July 2026, running into the first half of 2027, covering key and storage management, incident response, smart contract risks and third-party dependencies. And its fast-track peer review of a Maltese authorisation told authorities to review ICT systems against DORA before granting authorisation, and to satisfy themselves the applicant can "efficiently and effectively block malicious transactions if needed". A demonstrable kill switch is now an authorisation expectation.

So my prediction: the first wave of MiCA supervisory action against off-ramps will be about ICT resilience and travel rule execution, not capital adequacy. Capital is a number an accountant produces once a year; the other two are systems that either hold under load or do not. BaFin's Risiken im Fokus 2026 already commits to at least 75 special audits with travel rule implementation by crypto-asset service providers named as a focus.

MiCA CASP vs the UK Cryptoasset Regime in 2026

These regimes are usually presented as equivalents. In September 2026 they are nowhere near the same stage.

EU, MiCAUK, FSMA cryptoasset regime
Applications opensince 30 December 2024not yet; window expected 30 Sep 2026 to 28 Feb 2027
Regime livegrandfathering ended 1 July 2026full commencement 25 October 2027
Firms licensed337none under FSMA; 68 registered under the MLRs
Passportingnotification only, services from the 15th calendar daynone
Staking, lending and borrowingoutside the perimeterinside it

The UK instrument exists. The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, SI 2026 No. 102, were made on 4 February 2026, and the FCA published final rules on 30 June 2026 across PS26/9 to PS26/13. But the gateway has not opened, and there is no automatic conversion for firms already registered under the Money Laundering Regulations. Sit with the FCA's register statistics as at 1 August 2026: 412 applications received, 391 determined, 68 registered. A 17% approval rate, with 263 of the determined applications, 67%, withdrawn rather than refused. Firms are being talked out of it rather than turned down.

So: for an EU retail market, MiCA gives you 26 Member States from one authorisation, with register firms notifying a mean of 15.3 host states. For a UK retail market you cannot get FSMA authorisation yet at all, and the perimeter you will eventually face is wider than MiCA's. My earlier note on CASS 15 safeguarding covers how the UK treats client money once a regime lands.

What This Means for Engineers Building an EU Off-Ramp

1. Decide the principal question first. Never hold client stablecoins and the exchange leg sits outside PSD2. Offer a hosted balance clients can send from and you have a payment account, an SCA obligation and a second licence. 2. Model capital from all overheads, not fixed ones. Only the four Article 67(3) deductions apply. 3. Build the quote endpoint public and firm, with any amount limit stated alongside, and define "final" as a logged server-side event. 4. Make the transaction store append-only: reconstruct each stage, keep pre-amendment values, microsecond ISO 8601 in UTC, ISO 24165 identifiers for assets. 5. Do not build a €1,000 travel rule threshold. Full field sets on every transfer, with the Article 14(8) block in the request path rather than a nightly job. 6. Write the DORA runbook against the real clocks: 4 hours from classification, 24 from awareness, 72 from the initial submission, one month from the intermediate report. 7. Have a kill switch you can demonstrate. Supervisors ask to see it at authorisation now, not after an incident.

Key Takeaways

An EU crypto-to-fiat off-ramp is a Class 2 CASP: €125,000 or a quarter of all overheads, whichever is higher, with no deductions beyond the four MiCA lists. The 40-working-day decision period starts at the completeness letter and can be suspended once, and the register shows timing driven by the 1 July 2026 cliff rather than by the clock. The PSD2 question is not whether euros move but whether you move e-money tokens for clients. Article 77 and Delegated Regulation 2025/1140 reach furthest into the code, one demanding quotes be public and firm, the other that the ledger be append-only and timestamped in microseconds. And the travel rule applies to every transfer at every amount, which is what most integration plans get wrong before writing a line.

Written by Tom Wang, a payments engineer working on cross-border and stablecoin infrastructure.