If you’re building a crypto business in Europe, or selling into Europe from somewhere else, this question shows up fast: do you need a local VASP registration, or do you need full MiCA authorisation?
Short answer: it depends on what you actually do. Not what your pitch deck says. Not what your developer thinks the product might become next year. What you’re doing now, how customer funds move, whether you touch custody, whether you execute orders, whether you’re dealing with fiat rails, all of that matters.
And honestly, alot of founders get this wrong at the start.
They hear “MiCA is here” and assume every crypto business needs the biggest possible licence straight away. Or they go the other way and think an old-school VASP registration somewhere in the EU will carry them forever. Nope. The right answer sits somewhere in the middle, and if you choose badly you can waste months, hurt banking, and box yourself into a structure that’s annoying to fix later.
First, stop treating VASP and MiCA like they’re the same thing
They aren’t.
VASP registration was the earlier model in a lot of places. Usually AML-focused. You register as a virtual asset service provider, show your policies, explain your ownership, identify your managers, build out controls, and prove you’re not running a chaos machine. Good start. But still a lighter framework in many jurisdictions than full MiCA authorisation.
MiCA is broader. Much broader. It creates a proper authorisation regime for crypto-asset service providers – CASPs – across the EU. That means regulators look beyond basic AML files and ask harder operational questions. Governance. Prudential setup. Complaints handling. Outsourcing. Safeguarding logic. ICT controls. Conflicts. Marketing. Cross-border passporting. The whole thing gets more grown-up, fast.
If you need the simple version, here it is:
- VASP registration – usually a national AML registration model, often narrower in scope
- MiCA authorisation – a fuller EU regulatory regime for crypto service businesses that want to operate on a more formal basis across the bloc
That difference isn’t cosmetic. It changes your compliance burden, your org chart, your board choices, your banking story, and sometimes your product roadmap too.
So which businesses can still think in “VASP registration” terms?
Mainly businesses in transition. Or businesses operating in places where a domestic VASP regime still matters during the move toward MiCA.
Say you’re launching a small exchange service in one country. No fancy yield products. No custody at scale. No immediate push into five EU markets. You may start by checking whether a local registration route still exists, whether it’s still usable for your model, and whether there’s a realistic path from that setup into MiCA later.
But don’t stop the analysis there. Big mistake.
Founders often ask the wrong question: “What’s the easiest licence?” The better question is: “What licence still makes sense after our first 12 months?” Because if your plan includes app-based wallets, execution, listing more tokens, card top-ups, fiat payouts, or passporting services across the EU, a temporary low-friction registration can become dead weight pretty quickly.
If you’re still comparing jurisdictions, this breakdown on Lithuania vs Estonia vs Czech Republic for crypto licensing is a useful starting point. It shows how founders often confuse market entry with long-term suitability.
And when do you clearly need MiCA?
If your business falls within crypto-asset services covered under MiCA and you’re targeting the EU seriously, assume MiCA is the endgame.
Typical examples:
- Custodial wallet providers holding client crypto
- Platforms exchanging crypto for funds or crypto for crypto
- Businesses executing orders for clients
- Firms placing crypto-assets or providing transfer services
- Operators marketing regulated crypto services across multiple EU states
That’s the simple view. Real life gets messier.
For example, maybe you call yourself a “software platform”, but in practice users onboard through your entity, your team controls transaction workflows, and settlement touches your infrastructure. Regulators won’t care that the website says “non-custodial” in soft blue letters. They’ll look at the actual operating model. Who controls keys? Who can pause or reverse? Who decides whether a transfer goes through? Who contracts with the customer?
That’s the analysis that matters.
And if you’re planning around MiCA, don’t guess the application workload. Read this first: CASP authorisation under MiCA: the full application timeline and what stalls it. It gives a pretty realistic picture of why some applications drag on for months.
The trap founders fall into
They scope the licence around today’s MVP, then quietly build tomorrow’s regulated business underneath it.
I’ve seen this a lot. A team starts with “we only do crypto swaps.” Six months later they add hosted wallets because users want smoother onboarding. Then fiat on-ramp. Then card funding. Then a business account layer for merchants. Then treasury conversion. Suddenly the original registration logic doesn’t fit the live product anymore, and the compliance file looks like it belongs to another company.
Banks notice this. Regulators definitely notice this.
If your licence perimeter and actual business model drift apart, you’ll eventually need to fix it under pressure. Usually during a due diligence review, a banking refresh, an investor legal audit, or a regulator information request. Worst possible timing.
What you should look at before choosing
Don’t start with the jurisdiction. Start with the activity map.
Write down, in plain English, what happens from the second a user signs up to the second value leaves your system. Seriously. No legal jargon. Just the actual flow.
Include:
- who the customer contracts with
- whether you hold fiat or crypto
- who controls wallets and keys
- whether you execute or merely transmit instructions
- whether you earn spread, commission, or both
- which countries you market into
- whether third parties are white-label only or operationally real
That document will tell you more than ten sales calls with formation agents.
After that, look at structure. Should the IP sit in the same entity as the licensed operation? Should the marketing company be seperate? Do you need a holding company above the regulated vehicle? Are founders taking tokens directly, or through a parent? These aren’t tax-only questions. They affect disclosures, fitness and propriety analysis, source of funds explanations, and banking.
If you need help setting up the licensing route itself, VASP Registration & MiCA Compliance is the relevant service page. If the model is broader and touches fiat, payments, or EMI-style features, Fintech Regulatory Advisory usually becomes part of the conversation pretty fast.
VASP registration can still be useful. Just don’t romanticise it
There are still cases where a VASP route makes commercial sense. Maybe you’re proving demand in a narrower market. Maybe your service is genuinely limited. Maybe you need an interim setup while preparing a fuller MiCA file. Fine.
But be honest with yourself.
If investors expect EU scale, if banking partners want a cleaner regulatory story, if institutional clients are asking awkward onboarding questions, or if your roadmap already includes services clearly inside the MiCA perimeter, treating VASP registration as the long-term answer is usually just delay with better branding.
And delay has a cost, even when the regulator invoice doesn’t show it. Re-papering customers. Updating disclosures. Rebuilding policies. Reworking outsourcing agreements. Changing the board. Re-explaining ownership. Re-doing banking packs. All annoying. All avoidable.
A practical way to decide
If you’re stuck, use this test.
Go for a VASP-style route only if all three are true:
- your services are genuinely narrow today
- your target market is limited, not broad EU expansion
- you already understand what triggers the move to MiCA later
Lean toward MiCA now if any of these are true:
- you want cross-border EU credibility from day one
- you’ll be providing custody or exchange services at scale
- you expect institutional counterparties, serious banking review, or a fundraise soon
- your product roadmap is obviously heading into a fuller regulated model
That’s not legal advice, obviously. But it’s a pretty reliable commercial filter.
The real question isn’t “what’s easier?”
It’s “what breaks later if we choose the smaller route now?”
Sometimes the answer is nothing. Great. Use the simpler setup and move.
But sometimes the answer is your banking stack, your investor diligence, your EU expansion plan, your ability to passport, and your whole internal compliance rebuild. That’s not a minor admin hassle. That’s a strategic own goal.
So don’t buy a licence for the business you were three months ago. Buy for the business you’re actually building.
That’s usually where the right answer shows up.