How Long Does a MiCA CASP Licence Take?

August 19, 2026

Under Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), statutory review windows set clear legal boundaries for regulators, but overall project timelines vary. While National Competent Authorities (NCAs) operate within fixed assessment periods, an applicant's path to compliance, internal speed, technical readiness, and operational agility ultimately dictate the calendar.

Token Issuers vs. Crypto-asset Service Providers’ Schedules  

Compliance schedules vary significantly for many reasons, with the overall trajectory shifting depending on whether an entity seeks comprehensive entity licensing  or prepares technical disclosures for specific crypto-assets.

Token issuers, Layer 1 protocol foundations, and exchange listing departments navigate a much lighter administrative pathway governed by Article 8 white paper notifications and ongoing mandatory risk disclosures. Primary timeline drivers for those projects involve compiling structured technical specifications, verifiable consensus data, and mandatory sustainability indicators. For crypto-assets other than asset-referenced tokens or e-money tokens, Title II requires a 20-working-day notification window prior to publication. Unlike entity licensing, technical documentation timelines remain completely within the control of those issuing teams.

Statutory Limits in Practice 

What are the statutory deadlines for MiCA authorisation? For crypto-asset service providers (CASPs) assessment clocks begin once a formal application reaches the regulator. Under Article 63, NCAs must acknowledge receipt within five working days and confirm file completeness within 25 working days. Following formal acceptance, the authority conducts a substantive review within a limit of 40 working days, with the decision of that review notified to the applicant within a further five working days.

Statutory review windows refer to uninterrupted assessment time. In practice, regulatory assessment periods pause whenever an authority issues a formal Request for Information (RFI). Missing data, incomplete governance disclosures, or non-compliant technical whitepapers trigger these pauses. Consequently, total timelines depend less on regulatory processing speed and more on internal document readiness and submission quality.

Strictly calculated, the acknowledgement, confirmation, and review stages equal 70 working days of active regulatory processing, or about 3.5 calendar months. However National Competent Authorities may issue an RFI up to the 20th working day of the assessment, which can pause the clock for an additional 20 working days while the applicant compiles a response. 

When factoring in the maximum allowable clock-stops and transition windows permitted by the text, the legal baseline stretches out to a maximum of 105 working days, translating in practical terms to roughly up to five months of institutional review time.

What Does Pre-Submission Preparation Require?

The duration of the pre-submission phase is entirely variable with the actual calendar depending directly on an applicant's internal resources, corporate complexity, and operational maturity. A well-resourced team dedicated exclusively to dossier compilation will progress significantly faster than an organisation managing compliance as an adjunct task.

Regardless of team size, any entity seeking authorisation must complete a standardized set of milestones before submitting a file to an NCA:

  • Corporate Substance and Home-State Selection: Establishing legal and physical presence in the chosen EU member state, appointing resident directors, and ensuring management bodies meet regulatory standards for competence and integrity.
  • Governance and Risk Framework Alignment: Designing and implementing a three-lines-of-defense governance model, defining clear oversight functions, and conducting formal fit-and-proper evaluations for all key-holder positions.
  • The Comprehensive Documentation Package: Authoring the core application materials, including detailed three-year financial projections, operational programs, AML/CFT policies, client asset safeguarding procedures, and conflict-of-interest management frameworks.
  • Technical and ICT Resilience Integration: Embedding the requirements of the Digital Operational Resilience Act (DORA), such as ICT risk management frameworks, incident reporting protocols, and third-party vendor exit strategies, directly into the technical architecture.

Despite these preparation requirements varying based on a company's internal scale and resource deployment, industry implementation indicates that a well-resourced team typically requires 2 to 4 months of dedicated dossier compilation before filing. 

What Slows Down or Speeds Up CASP Authorisation?

No two CASP authorisations move at the same pace, and the difference rarely comes down to how quickly the regulator works. It comes down to how much the NCA has to ask, and how many places it has to look before it is satisfied. 

Applicants that already sit within a regulated group tend to move faster, since the NCA can draw on an existing supervisory relationship rather than building one from nothing. The same is true of those whose governance and risk policies are already aligned with DORA and the EBA/ESMA guidelines before the file is submitted, and of those who keep their intended service offering narrow and clearly scoped. A shareholder structure simple enough that ownership and control are easy to establish at a glance also tends to smooth the process.

The reverse holds for applicants whose structures or activities invite closer inspection. Custody of client assets brings a heavier standard of scrutiny, and complex group structures and non-EU qualifying shareholders slow matters further still. And any prior AML history, however resolved, tends to invite the kind of additional questions that extend a review well beyond its statutory minimum.

What Causes Delays in the MiCA CASP Authorisation Process?

When paired with the statutory review ceiling enforced by the NCA, the total end-to-end trajectory from initial document drafting to final authorization regularly spans six to twelve months. What expands that window? 

Regulatory friction during the review phase almost always traces back to preventable administrative gaps during document assembly.

Files frequently face delays when technical descriptions land on a regulator's desk without clear, transparent explanations of underlying governance structures, smart contract audit trails, or token economic models. Reviews also slow down significantly when applicants struggle to accurately calculate network energy consumption, consensus mechanism impacts, and mandatory ESMA adverse environmental disclosures.

Compounding these technical hurdles is the issue of format non-compliance. Submitting whitepapers in unstructured formats that fail mandatory inline XBRL (iXBRL) machine-readable standards guarantees an immediate administrative pushback. 

When filings contain gaps in these areas, NCAs exercise their authority to stop the clock and request corrected submissions. Eliminating these preparation bottlenecks from the outset preserves the original assessment schedule and keeps the authorization process moving forward.

Managing the MiCA Authorisation Timeline

A MiCA CASP licence may be delayed by regulators moving too slowly; however, it is more often delayed by applicants moving too fast before their internal frameworks are fully aligned.

While understanding statutory review windows is necessary for project planning, treating the application as a simple paperwork exercise misses the point. The depth and quality of the initial submission dictate whether an institution spends months fighting administrative friction or moves efficiently toward a sustainable, fully passported entry into the European market.

______________________________________________________________

Navigating the MiCA authorisation process requires precision, technical depth, and rigorous administrative preparation. If you would like support with structuring your application, aligning your frameworks, or managing engagement with National Competent Authorities, speak to our regulatory specialists today.

Frequently Asked Questions

What information is required in a MiCA white paper?

Do I need a white paper for my asset-referenced token?

Why is MiCA important for the crypto industry?

Do I need a white paper for my e-money token?

Do I need a white paper for my other crypto-asset (OTH)?

Do I need a white paper if my OTH token is already listed?