Insights

VASP license vs MiCA authorization

How local VASP registration differs from EU MiCA authorization, and the operational shift crypto businesses need to plan for MiCA compliance.

For most of the last decade, running a crypto business in Europe meant securing a VASP license — a national registration as a Virtual Asset Service Provider, granted country by country under local transpositions of the FATF standards. The Markets in Crypto-Assets Regulation (MiCA) changes the picture: it replaces that fragmented, AML-focused registration with a single, fuller EU authorization. Understanding how the two regimes differ is the first step in planning a realistic regulatory roadmap.

VASP registration: national and AML-led

A VASP registration is fundamentally an anti-money-laundering measure. It confirms that a firm offering services such as exchange, custody or transfer of crypto-assets has registered with its national supervisor and put an AML/CFT programme in place. It is valid only in the country that granted it, and firms operating across several markets historically had to register separately in each. The obligations centre on customer due diligence, transaction monitoring, suspicious-activity reporting and periodic review.

MiCA authorization: unified and much broader

MiCA is not simply a rebranded VASP regime. It is a full authorization that layers prudential, governance, conduct, disclosure and market-abuse requirements on top of the AML obligations firms already carry. Once a Crypto-Asset Service Provider (CASP) is authorized in one member state, that authorization can be passported across the EU. The trade-off is a materially higher bar to entry and a heavier ongoing compliance burden.

The differences at a glance

AspectVASP registrationMiCA authorization
Legal natureNational AML registration under local law transposing FATF standards.Single EU authorization regime with harmonized rules across member states.
ScopeFocused on AML/CFT obligations for virtual asset service providers.AML plus prudential, governance, conduct, disclosure and market-abuse rules.
Market accessValid in the country of registration only; separate registrations per market.Passportable across the EU once authorized in one member state.
SupervisionNational competent authority / FIU.National competent authorities coordinated with ESMA and the EBA.
Ongoing burdenAML programme, monitoring, reporting and periodic review.The above plus capital, safeguarding, complaints and continuous conduct compliance.

The operational shift to plan for

The move from VASP to MiCA is less a form-filling exercise and more an operational change. Firms that treated compliance as an AML programme now need to evidence capital adequacy, safeguard client assets, run complaints handling, and monitor for market abuse on a continuous basis. Monitoring MiCA compliance for a crypto platform means mapping each authorized service to its obligations, assigning named owners, and testing controls periodically rather than relying on a single registration event.

  • Map every crypto-asset service you offer to its MiCA obligations before applying.
  • Plan for the transitional window in each member state — grandfathering periods vary.
  • Build a continuous control framework, not a one-off registration file.
  • Carry your existing AML controls forward; MiCA adds to them, it doesn't replace them.

Frequently asked questions

What is the difference between a VASP registration and a MiCA license?

A VASP (Virtual Asset Service Provider) registration is a national AML registration, supervised country by country under local transposition of the FATF standards. MiCA (Markets in Crypto-Assets) is a single EU authorization regime that, once granted, can be passported across all member states. VASP focuses on AML/CFT registration; MiCA is a fuller prudential and conduct authorization on top of AML obligations.

Do I still need a VASP registration once MiCA applies?

MiCA replaces the patchwork of national VASP regimes for in-scope crypto-asset services within the EU, subject to transitional grandfathering periods that vary by member state. Firms already registered as VASPs generally need to transition to MiCA authorization within their national transitional window rather than relying on the old registration indefinitely.

How do you monitor MiCA compliance for a crypto platform?

Ongoing MiCA compliance means mapping each authorized service to its conduct, governance, prudential and disclosure obligations, then monitoring them continuously: capital adequacy, complaints handling, market-abuse surveillance, safeguarding of client assets, plus the AML controls carried over from the VASP regime. Most platforms need a documented control framework with named owners and periodic testing rather than a one-off registration exercise.

Planning a VASP-to-MiCA transition or unsure which regime applies to your activity? Get in touch or see our services.

Back to Insights