CASP vs VASP
VASP is a supervisory label that appears nowhere in EU legislation, used by national regulators for firms on the anti-money-laundering registers the Fifth Anti-Money Laundering Directive required. CASP is an authorization under MiCA Title V with a defined service list and an EU passport. This guide sets the entity-level regimes side by side, including the electronic money institution license and the Article 60 notification route that removes the need for a CASP application for seven categories of already-licensed institution.
Technically reviewed by Olena Zaichenko, D.Sc.
- VASP is a supervisory label, not a European legal status The phrase virtual asset service provider appears nowhere in MiCA or in the Fifth Anti-Money Laundering Directive, and what national regulators call a VASP is a firm on their own anti-money-laundering register whose perimeter was drawn in national law.
- An AMLD5 registration was a registration, in the source text as well as in effect The directive requires exchange providers and custodian wallet providers to be registered in the same clause that requires currency exchange offices and trust or company service providers to be licensed or registered, and it created no EU-level register and no passport.
- A CASP authorization names its services and carries the Union with it Competent authorities must specify which crypto-asset services an authorization covers, the application goes to the home Member State alone and the 40-working-day assessment window runs from a complete application and not from the day the file was submitted.
- Seven institution types notify instead of applying, inside limits that differ Credit institutions, central securities depositories, investment firms, market operators, electronic money institutions, UCITS management companies and AIFMs file at least 40 working days before first provision, and an EMI is confined to custody, administration and transfer for the e-money tokens it issues.
- The transitional rule had two limbs and a national variable Continuity ran until the outer limit or until an authorization was granted or refused, whichever came sooner. Member States could also decline the regime or shorten it, so a single EU-wide end date stated without that qualification is stronger than the regulation.
CASP and VASP get used as though they named the same permission in two dialects. They do not. One is an authorization created by MiCA, granted for a named list of services and valid across the Union. The other is a label that appears nowhere in European legislation, applied by national supervisors to firms they registered for anti-money-laundering purposes under a directive that predates MiCA. This page sets those regimes beside each other, with the electronic money institution license and the notification route that lets an already-licensed bank provide crypto-asset services without a CASP application.
In short: VASP is not a term of EU law. Neither MiCA nor the Fifth Anti-Money Laundering Directive contains the phrase, and what a supervisor calls a VASP is a firm on a national AML register, with no EU-level register and no passport. A CASP is an authorization under MiCA Title V, granted by the competent authority of the home Member State, specifying which crypto-asset services it covers and carrying the right to serve the whole Union. Seven categories of already-licensed institution do not need it: they notify their home authority at least 40 working days before first providing the service, inside scope limits that differ by institution type. Issuing an e-money token is a third regime again, and the issuer must itself be authorized as a credit institution or an electronic money institution.
VASP is not a term of EU law
Start with the measurement. The text of MiCA as published in the Official Journal contains no occurrence of virtual asset service provider, none of virtual asset and none of VASP. The Fifth Anti-Money Laundering Directive, which first pulled crypto firms into the EU anti-money-laundering perimeter, contains none of the three either. Both regimes were written without the word.
The term comes from the Financial Action Task Force, a standard-setting body rather than a legislature, whose definition of a virtual asset service provider covers five activities. Those standards are not EU law. The European Union implementation of them chose its own vocabulary, and the words it chose are the ones a supervisor can act on.
One transposition shows the shape of it. The Central Bank of Ireland uses VASP as its house label and describes it as a firm providing any of five listed services relating to virtual assets: exchange between virtual assets and fiat currencies, exchange between forms of virtual assets, transfer of a virtual asset on behalf of another person, custodian wallet provision and participation in or provision of financial services related to an issuer's offer or sale of a virtual asset. It adds that VASPs established in Ireland must register with it for AML purposes only, and that carrying on the business of a VASP without that registration is a criminal offense there. Both facts are Irish and neither states an EU rule.
Two firms doing identical work in two Member States could therefore sit inside the VASP perimeter in one and outside it in the other. A country-by-country comparison is a separate question, answered in our comparison of MiCA against the UK, US and Dubai regimes.
What an AMLD5 registration actually was
The Fifth Anti-Money Laundering Directive did not create a crypto license. It extended an existing list of obliged entities by two functionally described categories, which in the directive text read "providers engaged in exchange services between virtual currencies and fiat currencies" and "custodian wallet providers". Crypto exchange and wallet provider are serviceable shorthand. They are not what the instrument says.
That obligation is a registration, and one sentence of the directive shows registration and licensing used as distinct terms inside a single clause: "Member States shall ensure that providers of exchange services between virtual currencies and fiat currencies, and custodian wallet providers, are registered, that currency exchange and cheque cashing offices, and trust or company service providers are licensed or registered". An AMLD5 registration was a registration, not an authorization and not a license.
The definitions the directive inserted are worth reading against the vocabulary that has grown up since. A virtual currency is "a digital representation of value that is not issued or guaranteed by a central bank or a public authority, is not necessarily attached to a legally established currency and does not possess a legal status of currency or money", and the same sentence continues that it "is accepted by natural or legal persons as a means of exchange and which can be transferred, stored and traded electronically". Nothing in it mentions tokens, stablecoins or trading platforms. The perimeter was drawn by the two obliged-entity categories above, not by this definition.
Timing here is a transposition rule, not a firm-level one. The directive requires that "Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive by 10 January 2020". That date binds governments. It says nothing about when any individual firm had to appear on a register, which each state set in its own transposing law. Ireland's VASP provisions commenced on 23 April 2021.
Three consequences follow, and a CASP authorization changed each of them. The directive created no EU-level register of VASPs, conferred no passport and left the perimeter to national transposition, which drew it differently from state to state.
What a CASP authorization is under MiCA Title V
MiCA supplies the definition the label never had. Under Article 3, a crypto-asset service provider is "a legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis, and that is allowed to provide crypto-asset services in accordance with Article 59".
The permission itself is a closed list. Article 59 opens with "A person shall not provide crypto-asset services, within the Union, unless that person is" and then names two categories: a firm authorized under Article 63, or "a credit institution, central securities depository, investment firm, market operator, electronic money institution, UCITS management company, or an alternative investment fund manager that is allowed to provide crypto-asset services pursuant to Article 60". There is no third door.
MiCA defines ten crypto-asset services, and an authorization is granted against them individually, not as a general permission to be a crypto business. Article 59 is explicit: "Competent authorities that grant authorisations in accordance with Article 63 shall ensure that such authorisations specify the crypto-asset services that crypto-asset service providers are authorised to provide". Which services you apply for is the first design decision of the project, and we map each of the ten CASP services to what a platform actually does.
The application goes to one authority. Under Article 62, "Legal persons or other undertakings that intend to provide crypto-asset services shall submit their application for an authorisation as a crypto-asset service provider to the competent authority of their home Member State". The assessment clock in Article 63 runs from completeness rather than from filing: "Competent authorities shall, within 40 working days from the date of receipt of a complete application, assess whether the applicant crypto-asset service provider complies with this Title and shall adopt a fully reasoned decision granting or refusing an authorisation". A submitted file is not a complete file, and the clock does not start until it is. Our walkthrough of the CASP license application covers what the authority reads and in what order.
What the authorization buys is the Union. Under Article 59, "Crypto-asset service providers shall be allowed to provide crypto-asset services throughout the Union, either through the right of establishment, including through a branch, or through the freedom to provide services", and a provider serving another Member State cross-border needs no physical presence there. Two separate clocks govern the passport, and they are easy to collapse into one. Article 65 gives the home authority ten working days to pass the filing to the host states, ESMA and the EBA, after which the provider "may begin to provide crypto-asset services in a Member State other than its home Member State from the date of receipt of the communication referred to in paragraph 3 or at the latest from the 15th calendar day" after having submitted the information.
Both perimeters have an outside, and it is worth naming. The Article 59 prohibition bites on a person who provides crypto-asset services, and Article 3 defines a crypto-asset service as "any of the following services and activities relating to any crypto-asset" and then closes the list at ten. A firm that builds software for a licensed operator, holds no client crypto-assets, no client funds and no keys, and provides none of those ten services to clients on its own account, is not a CASP and needs no authorization for the code it writes. The AMLD5 perimeter beside it was drawn by the two obliged-entity categories quoted above. Where the same firm starts safeguarding keys or holding client assets, both answers change.
Which regime applies to which activity
Read the left column as what you intend to do. The scope limits in the Article 60 rows are not interchangeable, and the sections below take each row in turn.
| Activity | Regime | Who authorizes or receives the filing | EU passport |
|---|---|---|---|
| Any of the ten crypto-asset services, by a firm that is not one of the seven listed institutions | CASP authorization, MiCA Title V, Articles 59, 62 and 63 | Competent authority of the home Member State | Yes, by notification under Article 65. Ten working days for the home authority to pass the file on, then service may start on receipt or at the latest on the fifteenth calendar day after filing |
| Crypto-asset services by a credit institution | Notification under Article 60(1), no separate CASP authorization | Home Member State competent authority, at least 40 working days before first providing the services | Not a Title V passport. Reaches the same ESMA register via Article 109(5) |
| Custody and administration of crypto-assets only, by a central securities depository | Notification under Article 60(2) | As above, at least 40 working days ahead | As above |
| Services equivalent to the investment services it already holds under MiFID II, by an investment firm | Notification under Article 60(3) | As above | As above |
| Custody, administration and transfer services for the e-money tokens it issues only, by an electronic money institution | Notification under Article 60(4) | As above | As above |
| Services equivalent to portfolio management and to its non-core services, by a UCITS management company or an AIFM | Notification under Article 60(5) | As above | As above |
| Operating a trading platform for crypto-assets, by a market operator | Notification under Article 60(6) | As above | As above |
| Offering an e-money token to the public or seeking its admission to trading | Credit institution or EMI status plus a notified and published white paper, MiCA Title IV, Article 48 | Competent authority. The issuer notifies its intention at least 40 working days before the offer, and the white paper is notified and published under Article 51 | The EMI license passports under EMD2 through the payment services provisions it applies |
| Issuing electronic money | EMI authorization under EMD2, or one of the other recognized issuer categories | National competent authority. Initial capital of not less than EUR 350 000 at the time of authorization | The EBA maintains the PSD2 register of licensed EMIs and payment institutions |
| Exchange between virtual currencies and fiat, or custodian wallet provision, before MiCA applied | Registration under the national transposition of AMLD5, not an authorization | The national AML supervisor | None. No EU-level register and no passport |
Two rows repay a second reading. An EMI reading row five sometimes reads its existing license as covering a broad crypto offering, when Article 60(4) stops at custody, administration and transfer for its own tokens. And a firm reading the last row treats its national registration as a position MiCA would upgrade. It was not.
The Article 60 notification route

A common shorthand has every firm offering crypto-asset services in the EU holding a CASP authorization. Seven categories of institution do not need one, and they are lawful. Each already holds an authorization under another EU financial services regime, and MiCA lets them extend it by filing instead of by applying.
Every one of the six paragraphs of Article 60 carries the same clock. Take the banking case: under Article 60, "A credit institution may provide crypto-asset services if it notifies the information referred to in paragraph 7 to the competent authority of its home Member State at least 40 working days before providing those services for the first time". That is a minimum notice period running before first provision. It is not an assessment window and not an approval granted at the end of it. The separate 40-working-day assessment in Article 63 belongs to CASP applications and runs from a complete file, so the same number appears twice in MiCA meaning two different things.
What the notification buys differs by institution type, and the differences are the part worth reading closely. A central securities depository may provide only custody and administration of crypto-assets on behalf of clients. A market operator may operate a trading platform. An investment firm is confined to services equivalent to the investment services it is already specifically authorized for under MiFID II. A UCITS management company or an alternative investment fund manager is limited to services equivalent to portfolio management and to its non-core services. Electronic money institutions carry a limit bounded by token as well as by service. Under Article 60, "An electronic money institution authorised under Directive 2009/110/EC shall only provide custody and administration of crypto-assets on behalf of clients and transfer services for crypto-assets on behalf of clients with regard to the e-money tokens it issues". Custody, administration and transfer, for its own e-money tokens only. An EMI cannot notify its way into running an exchange.
Notifying institutions do reach the same public register as authorized CASPs. Under Article 60, the authority verifies completeness, sends ESMA the Article 109(5) information, and "ESMA shall make such information available in the register referred to in Article 109 by the starting date of the intended provision of crypto-asset services". That is a publication fact, not a status fact. An Article 60 institution is not authorized under Article 63 and does not become a CASP by being listed beside them.
A firm's absence from the CASP population is therefore not by itself evidence that it is operating unlawfully. The AFM names three possible meanings for absence from its own register: no authorization is required, an application is still under assessment, or the undertaking is operating illegally. A bank operating on a notification, or a notification still inside its notice period that only has to be visible by the intended starting date, both read as absence too. Whether a counterparty serves you under Article 63 or Article 60 changes which permissions cover it, so ask which and check the answer in the ESMA CASP register.
EMI licensing and the e-money token seam
The electronic money institution license is older than both regimes above and becomes load-bearing the moment a token references a single currency. Under the consolidated Second Electronic Money Directive, an electronic money institution is "a legal person that has been granted authorisation under Title II to issue electronic money". The perimeter is closed at the other end too: "Member States shall prohibit natural or legal persons who are not electronic money issuers from issuing electronic money".
The entry price sits in the same instrument, which requires that "Member States shall require electronic money institutions to hold, at the time of authorisation, initial capital" of not less than EUR 350 000. That is the capital required at authorization. Ongoing own-funds requirements are calculated separately.
Now the seam. MiCA defines an e-money token as "a type of crypto-asset that purports to maintain a stable value by referencing the value of one official currency", which is the single-currency case. Offering one to the public or seeking its admission to trading is not a CASP activity at all. Under Article 48, "A person shall not make an offer to the public or seek the admission to trading of an e-money token, within the Union, unless that person is the issuer of such e-money token", and that issuer "is authorised as a credit institution or as an electronic money institution" and has notified and published a crypto-asset white paper. Both limbs bind, and they bind on the issuer itself. An EMI without a published white paper does not qualify, and neither does a white paper from a firm that is neither.
Three conditions sit around that rule and are easy to lose in a summary. The same article provides that "Notwithstanding the first subparagraph, upon the written consent of the issuer, other persons may offer to the public or seek the admission to trading of the e-money token", and those other persons then have to comply with Articles 50 and 53. It provides that "Paragraph 1 of this Article shall not apply to issuers of e-money tokens exempted in accordance with Article 9(1) of Directive 2009/110/EC", which is the small-issuer waiver in the same directive that carries the EUR 350 000 figure. And it provides that "This Title, with the exception of paragraph 7 of this Article and Article 51, shall not apply in respect of e-money tokens exempt pursuant to Article 1(4) and (5) of Directive 2009/110/EC". The credit institution or EMI requirement is the rule for an issuer offering to the public, with those exemptions carved out of it.
The two regimes are then stitched together explicitly by Article 48. "E-money tokens shall be deemed to be electronic money" and "Titles II and III of Directive 2009/110/EC shall apply with respect to e-money tokens unless otherwise stated in this Title", so an EMT issuer is running an e-money business with MiCA modifications on top, not a crypto business with a payments flavor. The notice period matches the Article 60 pattern in length: "Issuers of e-money tokens shall, at least 40 working days before the date on which they intend to offer to the public those e-money tokens or seek their admission to trading, notify their competent authority of that intention". We cover the build side of that in our guide to e-money token issuance.
Two boundaries are worth naming, because they are where this article stops. Asset-referenced tokens are a different category under Title III with a different authorization route, and deciding which category a token falls into belongs to ART versus EMT classification. Whether an instrument is caught by MiCA at all or by MiFID II instead is a prior question again, covered in our comparison of MiCA against MiFID II. Supervision splits across the seam as well: the EBA assesses issuers of asset-referenced tokens and e-money tokens for significance and supervises the significant issuers, jointly with the national authority in the e-money token case, and separately maintains the PSD2 register of licensed EMIs.
What became of VASP registrations under MiCA
Nothing converted. The transitional provision in Article 143 is a continuity rule with two limbs, and the second limb is the one worth keeping: "Crypto-asset service providers that provided their services in accordance with applicable law before 30 December 2024, may continue to do so until 1 July 2026 or until they are granted or refused an authorisation pursuant to Article 63, whichever is sooner". A refusal ended the cover as surely as the calendar did, and it ended it earlier.
The rule also varies by Member State by design. The same article provides that "Member States may decide not to apply the transitional regime for crypto-asset service providers provided for in the first subparagraph or to reduce its duration where they consider that their national regulatory framework applicable before 30 December 2024 is less strict than this Regulation", and it required every Member State to tell the Commission and ESMA by 30 June 2024 whether it had used the option, and for how long. So 1 July 2026 is a ceiling rather than a uniform end date, and any statement of one EU-wide end date without that qualification is stronger than the regulation. The Netherlands is one evidenced example of a shorter window: the AFM states that firms registered with DNB for exchange between virtual and regular currencies or for custodian wallet provision could use the MiCAR transitional regime until 30 June 2025, and that in the Netherlands the regime ended on that date. That is one national case rather than a pattern.
What was available was a shortcut through the procedure, not through the standard. Under Article 143, "Member States may apply a simplified procedure for applications for an authorisation that are submitted between 30 December 2024 and 1 July 2026 by entities that on 30 December 2024, were authorised under national law to provide crypto-asset services", and competent authorities had to satisfy themselves that Chapters 2 and 3 of Title V were complied with before granting on that basis. A simplified procedure is at Member State option, open only to entities already authorized nationally on the qualifying date, and it ends in the same substantive test.
Two populations never had transitional cover at all, a point ESMA makes in its statement on the end of the transitional periods: firms that were not providing crypto-asset services in accordance with applicable national law before the qualifying date, and firms in Member States where the transitional period had already ended. ESMA adds that the transitional period expired across the EU on 1 July 2026 and that an entity serving EU clients without a MiCA license after that date is in breach of EU law and must cease.
National supervisors describe the same layering from below. BaFin notes that a German authorization is published in the Federal Gazette, in its own company database and in the interim MiCA register maintained by ESMA, and that authorized providers may serve the EU after prior notification without a separate authorization per Member State. The AMF states that its own white list is not real time and points readers to the ESMA register alongside it.
How Pharos Production helps
Which regime you fall under is an architecture question long before it is a filing question. An EMI extending into custody for its own tokens, a CASP applying for four services and not ten and a bank filing an Article 60 notification build different systems with different segregation and record-keeping obligations, and the cheapest moment to find that out is while the design is still on a whiteboard. We build the platforms underneath those permissions. If you are working out which authorization your service mix needs, our MiCA compliance software development team can walk the perimeter with you.
Sources: Regulation (EU) 2023/1114 (MiCA), Articles 3, 48, 59, 60, 62, 63, 65 and 143, as published in the Official Journal; Directive 2009/110/EC on electronic money, consolidated at 13 January 2018; Directive (EU) 2018/843, the Fifth Anti-Money Laundering Directive; the ESMA statement ESMA75-113276571-1679 of 17 April 2026 on the end of the MiCA transitional periods; the ESMA MiCA activities page; the EBA page on its supervisory role under MiCA; and national pages published by the Central Bank of Ireland, the AFM, BaFin and the AMF. This article is engineering guidance, not legal advice. Confirm every requirement against the primary text with qualified counsel.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 6
No matches
Try a different keyword, change the topic or clear filters
-
No, and they are not even the same kind of thing. CASP is a status defined by MiCA and granted by a competent authority against a named list of services.
VASP is a supervisory label that does not appear in MiCA or in the Fifth Anti-Money Laundering Directive at all. It came into use from a standard-setting body's vocabulary and was applied by national supervisors to firms entered on their own anti-money-laundering registers, so its scope was set in national law and differed between Member States.
-
No. Nothing in MiCA converts one into the other. What existed was a continuity rule allowing firms that provided services lawfully before the qualifying date to keep going until the outer limit or until an authorization was granted or refused, whichever came first.
Member States separately had the option of running a simplified application procedure for entities already authorized under national law. The simplified route was an option and not an entitlement, was open only to already-authorized entities and still required the competent authority to confirm compliance with the substantive MiCA chapters before granting.
-
Seven categories named in Article 59: credit institutions, central securities depositories, investment firms, market operators, electronic money institutions, UCITS management companies and alternative investment fund managers. They file a notification with the competent authority of their home Member State at least 40 working days before first providing the services.
The permitted scope differs by category, so a central securities depository is limited to custody and administration while an investment firm is limited to services equivalent to the MiFID II permissions it already holds.
-
Only a narrow set of them. Article 60(4) permits an EMI to provide custody and administration of crypto-assets on behalf of clients and transfer services for crypto-assets on behalf of clients, and only with regard to the e-money tokens that the EMI itself issues.
Anything wider, such as operating a trading platform or exchanging third-party crypto-assets for funds, falls outside the notification and needs a CASP authorization.
-
To offer an e-money token to the public or seek its admission to trading, the issuer must itself be authorized as a credit institution or an electronic money institution and must also notify a crypto-asset white paper to the competent authority and publish it. Both conditions apply together, and Article 48 carves out two cases: paragraph 1 does not apply to issuers exempted under Article 9(1) of the Second Electronic Money Directive, and another person may offer the token or seek its admission with the issuer's written consent.
The rule is specific to e-money tokens, meaning crypto-assets that reference the value of a single official currency. Asset-referenced tokens are a separate category with a different authorization route under Title III.
-
Yes, through the passport in Title V. A provider may operate throughout the Union under the freedom to provide services or by right of establishment, including through a branch, and a cross-border provider is not required to have a physical presence in the host Member State.
The mechanism is a notification, not a fresh application. The home authority passes the information to the host states, ESMA and the EBA within ten working days, and the provider may begin from receipt of that communication or at the latest on the fifteenth calendar day after filing.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.