How Long Does a MiCA CASP Licence Take?

Under Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), statutory review windows set clear legal boundaries for regulators, but overall project timelines vary. While National Competent Authorities (NCAs) operate within fixed assessment periods, an applicant's path to compliance, internal speed, technical readiness, and operational agility ultimately dictate the calendar.
Token Issuers vs. Crypto-asset Service Providers’ Schedules
Compliance schedules vary significantly for many reasons, with the overall trajectory shifting depending on whether an entity seeks comprehensive entity licensing or prepares technical disclosures for specific crypto-assets.
Token issuers, Layer 1 protocol foundations, and exchange listing departments navigate a much lighter administrative pathway governed by Article 8 white paper notifications and ongoing mandatory risk disclosures. Primary timeline drivers for those projects involve compiling structured technical specifications, verifiable consensus data, and mandatory sustainability indicators. For crypto-assets other than asset-referenced tokens or e-money tokens, Title II requires a 20-working-day notification window prior to publication. Unlike entity licensing, technical documentation timelines remain completely within the control of those issuing teams.
Statutory Limits in Practice
What are the statutory deadlines for MiCA authorisation? For crypto-asset service providers (CASPs) assessment clocks begin once a formal application reaches the regulator. Under Article 63, NCAs must acknowledge receipt within five working days and confirm file completeness within 25 working days. Following formal acceptance, the authority conducts a substantive review within a limit of 40 working days, with the decision of that review notified to the applicant within a further five working days.
Statutory review windows refer to uninterrupted assessment time. In practice, regulatory assessment periods pause whenever an authority issues a formal Request for Information (RFI). Missing data, incomplete governance disclosures, or non-compliant technical whitepapers trigger these pauses. Consequently, total timelines depend less on regulatory processing speed and more on internal document readiness and submission quality.
Strictly calculated, the acknowledgement, confirmation, and review stages equal 70 working days of active regulatory processing, or about 3.5 calendar months. However National Competent Authorities may issue an RFI up to the 20th working day of the assessment, which can pause the clock for an additional 20 working days while the applicant compiles a response.
When factoring in the maximum allowable clock-stops and transition windows permitted by the text, the legal baseline stretches out to a maximum of 105 working days, translating in practical terms to roughly up to five months of institutional review time.
What Does Pre-Submission Preparation Require?
The duration of the pre-submission phase is entirely variable with the actual calendar depending directly on an applicant's internal resources, corporate complexity, and operational maturity. A well-resourced team dedicated exclusively to dossier compilation will progress significantly faster than an organisation managing compliance as an adjunct task.
Regardless of team size, any entity seeking authorisation must complete a standardized set of milestones before submitting a file to an NCA:
- Corporate Substance and Home-State Selection: Establishing legal and physical presence in the chosen EU member state, appointing resident directors, and ensuring management bodies meet regulatory standards for competence and integrity.
- Governance and Risk Framework Alignment: Designing and implementing a three-lines-of-defense governance model, defining clear oversight functions, and conducting formal fit-and-proper evaluations for all key-holder positions.
- The Comprehensive Documentation Package: Authoring the core application materials, including detailed three-year financial projections, operational programs, AML/CFT policies, client asset safeguarding procedures, and conflict-of-interest management frameworks.
- Technical and ICT Resilience Integration: Embedding the requirements of the Digital Operational Resilience Act (DORA), such as ICT risk management frameworks, incident reporting protocols, and third-party vendor exit strategies, directly into the technical architecture.
Despite these preparation requirements varying based on a company's internal scale and resource deployment, industry implementation indicates that a well-resourced team typically requires 2 to 4 months of dedicated dossier compilation before filing.
What Slows Down or Speeds Up CASP Authorisation?
No two CASP authorisations move at the same pace, and the difference rarely comes down to how quickly the regulator works. It comes down to how much the NCA has to ask, and how many places it has to look before it is satisfied.
Applicants that already sit within a regulated group tend to move faster, since the NCA can draw on an existing supervisory relationship rather than building one from nothing. The same is true of those whose governance and risk policies are already aligned with DORA and the EBA/ESMA guidelines before the file is submitted, and of those who keep their intended service offering narrow and clearly scoped. A shareholder structure simple enough that ownership and control are easy to establish at a glance also tends to smooth the process.
The reverse holds for applicants whose structures or activities invite closer inspection. Custody of client assets brings a heavier standard of scrutiny, and complex group structures and non-EU qualifying shareholders slow matters further still. And any prior AML history, however resolved, tends to invite the kind of additional questions that extend a review well beyond its statutory minimum.
What Causes Delays in the MiCA CASP Authorisation Process?
When paired with the statutory review ceiling enforced by the NCA, the total end-to-end trajectory from initial document drafting to final authorization regularly spans six to twelve months. What expands that window?
Regulatory friction during the review phase almost always traces back to preventable administrative gaps during document assembly.
Files frequently face delays when technical descriptions land on a regulator's desk without clear, transparent explanations of underlying governance structures, smart contract audit trails, or token economic models. Reviews also slow down significantly when applicants struggle to accurately calculate network energy consumption, consensus mechanism impacts, and mandatory ESMA adverse environmental disclosures.
Compounding these technical hurdles is the issue of format non-compliance. Submitting whitepapers in unstructured formats that fail mandatory inline XBRL (iXBRL) machine-readable standards guarantees an immediate administrative pushback.
When filings contain gaps in these areas, NCAs exercise their authority to stop the clock and request corrected submissions. Eliminating these preparation bottlenecks from the outset preserves the original assessment schedule and keeps the authorization process moving forward.
Managing the MiCA Authorisation Timeline
A MiCA CASP licence may be delayed by regulators moving too slowly; however, it is more often delayed by applicants moving too fast before their internal frameworks are fully aligned.
While understanding statutory review windows is necessary for project planning, treating the application as a simple paperwork exercise misses the point. The depth and quality of the initial submission dictate whether an institution spends months fighting administrative friction or moves efficiently toward a sustainable, fully passported entry into the European market.
______________________________________________________________
Navigating the MiCA authorisation process requires precision, technical depth, and rigorous administrative preparation. If you would like support with structuring your application, aligning your frameworks, or managing engagement with National Competent Authorities, speak to our regulatory specialists today.
Frequently Asked Questions
What information is required in a MiCA white paper?
A MiCA white paper is not the same as a project whitepaper.
A traditional crypto whitepaper may explain a protocol, tokenomics, roadmap or community vision. A MiCA white paper is a regulatory disclosure document. It must follow prescribed content requirements and, depending on the category of token, cover information on the issuer, offeror or person seeking admission to trading, the project, the offer or admission, the crypto-asset, rights and obligations, underlying technology, risks, and adverse impacts on climate and the environment. MiCA’s rulebook lists separate content provisions for OTH tokens, ARTs and EMTs: Article 6, Article 19 and Article 51 respectively.
There are also technical format requirements. Commission Implementing Regulation (EU) 2024/2984 and Commission Delegated Regulation (EU) 2025/422 lay down standard forms, formats and templates for crypto-asset white papers, and explains that the white paper framework is intended to make white papers available in machine-readable format. The implementing regulation also requires crypto-asset white papers to be drawn up in XHTML format with Inline XBRL tagging of the relevant fields.
This means a MiCA white paper project usually has four workstreams: legal classification, regulatory drafting, technical and sustainability data collection, and XHTML/iXBRL production.
Do I need a white paper for my asset-referenced token?
For asset-referenced tokens, the practical position is strict. As it can be observed in our questionnaire, an ART could take advantage of an exemption if its average outstanding value of the ART has never exceeded EUR 5 million over 12 months, or if it is being offered solely to qualified investors. However, even in these cases, a white paper is needed: projects can leverage these exemptions to not be required to meet many of the usual ART rules, but not the white paper one specifically — unless the person seeking admission to trading of an ART can convince exchanges that the asset lacks an identifiable issuer and no white paper is needed.
Why is MiCA important for the crypto industry?
MiCA establishes a single, harmonised framework for crypto-assets across all EU Member States, replacing the patchwork of national regimes. It introduces clear rules for disclosure, conduct and governance, enabling CASPs to operate throughout the EU under a single authorisation passport.
By setting consistent standards for white papers, risk disclosure and consumer protection, MiCA aims to increase legal certainty, market integrity and investor confidence. Projects that fail to comply, for example by not publishing a MiCA-compliant white paper or by misrepresenting risks, may face regulatory enforcement, delistings or trading restrictions.
Compliance under MiCA builds trust, transparency and cross-border market access, strengthening the overall credibility and stability of Europe’s digital asset ecosystem.
Do I need a white paper for my e-money token?
For e-money tokens, a white paper is generally needed. If the e-money token can only be used to acquire goods or services in the issuer’s premises, within a limited network of service providers, or for a limited range of goods or services, the project can benefit from many exemptions, but typically the white paper requirement is not one of them. The same happens if the e-money token is used to make payment transactions where the purchased goods or services are delivered to and used through a telecommunication, digital or IT device.
Do I need a white paper for my other crypto-asset (OTH)?
Most non-stablecoin crypto-assets fall into the “other than asset-referenced tokens or e-money tokens” category, often abbreviated as OTH.
For these assets, our questionnaire also identifies some exemptions.
Do I need a white paper if my OTH token is already listed?
OTH assets already admitted to trading by 30 December 2024 (a similar regime applies to offers to the public that ended prior to this date) do not require a white paper in those particular trading platforms until 31 December 2027. Other trading platforms still need to submit white papers. However, a person may still prepare and submit a white paper voluntarily.