Guides
Aug 25, 2026

CASP Licence Cost in 2026: Fees, Capital and Timelines

What a MiCA CASP licence actually costs in 2026: application fees, minimum capital by class, professional indemnity, staffing, and the timelines regulators are really running to.

CASP Licence Cost in 2026: Fees, Capital and Timelines

Ask three consultants what a CASP licence costs and you will get three answers, all of them incomplete. The application fee is the smallest line on the invoice. What actually determines your budget is minimum capital, the people you must hire before you can file, and how long your regulator takes to come back with questions.

This guide breaks the cost into the four buckets that matter, using the figures firms are working with in 2026.

1. Minimum capital: set by what you do, not where you are

MiCA fixes prudential requirements by service class, and they are the same in every member state. This is the one number you cannot negotiate down by picking a friendlier jurisdiction.

  • Class 1 — EUR 50,000. Reception and transmission of orders, execution on behalf of clients, placing, advice, portfolio management, transfer services.
  • Class 2 — EUR 125,000. Custody and administration of crypto-assets on behalf of clients, plus exchange of crypto-assets for funds or for other crypto-assets.
  • Class 3 — EUR 150,000. Operation of a trading platform.

You hold the higher of your class minimum or one quarter of the prior year's fixed overheads. For a firm running real headcount, that overheads test usually bites first — a team burning EUR 1.2m a year needs EUR 300,000 held, not the EUR 125,000 headline.

2. Application and supervisory fees

These are set nationally and vary far more than the capital requirement. Application fees across member states generally land between EUR 5,000 and EUR 25,000, with annual supervisory fees on top, often scaled to your turnover or client assets.

The fee is rarely the deciding factor. Regulator throughput and the quality of pre-application engagement matter more, which is why the same paperwork can take four months in one country and eleven in another. We compare that directly in where to get a CASP licence.

3. The people you must hire before you file

This is the bucket that surprises people. A CASP application is assessed on substance, and substance means named individuals resident in the authorising member state.

  • Two executive directors with relevant experience, effectively running the business from the jurisdiction
  • A compliance officer — in practice a full-time hire, not a shared service
  • An MLRO responsible for AML/CFT, sometimes combinable with compliance at smaller firms
  • A risk function proportionate to the services offered
  • An IT/security lead who can answer to the DORA obligations that arrive alongside MiCA

Budget EUR 300,000 to EUR 600,000 a year for a credible minimum team before you write a line of the application. Regulators reject shell structures with non-resident directors, and they have become notably better at spotting them.

4. The compliance stack

You cannot file without describing the systems that will do the work. Auditors will ask for them, and "we will procure this post-authorisation" is a weak answer.

Realistic annual spend for a mid-size firm sits between EUR 60,000 and EUR 200,000 depending on volume and how many vendors you consolidate.

Putting it together

A first-time applicant offering custody and exchange — Class 2 — should plan for roughly:

  • EUR 125,000+ held as regulatory capital (not spent, but locked)
  • EUR 10,000–25,000 in application fees
  • EUR 60,000–150,000 in legal and advisory support to prepare the file
  • EUR 300,000–600,000 in annual staffing
  • EUR 60,000–200,000 in compliance tooling

Call it EUR 450,000 to EUR 1m of first-year cost before a single client is onboarded, with capital locked on top. Firms that budget only for the application fee are the ones that stall halfway through.

The costs that only start after authorisation

Budgets built for the application routinely stop at the day the licence is granted, which is the day the recurring cost base begins. The ongoing run-rate is usually larger than the one-off project cost by the end of year one.

  • Annual supervisory fees. Charged by your national competent authority, frequently scaled to turnover or client assets, so they grow with you.
  • Statutory audit. A regulated entity needs an audit, and auditors with crypto experience price accordingly.
  • Regulatory reporting. Periodic returns on capital, client assets, complaints and incidents. This is recurring staff time, not a system you buy once.
  • Professional indemnity insurance. Renewed annually, and priced on your service class and claims history.
  • Compliance tooling. Screening, monitoring and case management are subscriptions that scale with customer count.
  • Named-role retention. Your compliance officer, MLRO and risk function are permanent headcount. Losing a named role can require notification and, in some jurisdictions, restricts activity until replaced.

Where budgets actually overrun

Three line items account for most of the overrun in files that go over budget, and none of them are the application fee.

The overheads capital test. Firms budget the headline class minimum and forget that the requirement is the higher of that figure or one quarter of prior-year fixed overheads. Hiring to strengthen the application raises overheads, which raises the capital you must hold. The two move together, and the second move is the one nobody models.

Remediation rounds. Regulators come back with questions. Each round costs advisory time and, more expensively, calendar — during which you are paying a full team and earning nothing. Budget for at least two rounds.

ICT and DORA workstreams discovered late. Teams scope MiCA, then find DORA obligations landing on the same entity mid-process. Retrofitting an ICT risk framework and third-party register under authorisation time pressure costs multiples of building it alongside.

Funding the capital requirement

Minimum capital is held, not spent — but it must be genuinely available and composed of eligible own funds, which constrains how you raise it. Regulators look at composition, not just the number, and a capital base assembled from instruments that do not qualify will be challenged.

Two practical points. First, capital must be in place before authorisation, so it is dead money for the length of the process — a real cost at any sensible discount rate. Second, the overheads test means a growing firm must top up as it scales; treating the initial figure as a one-off is a planning error that surfaces at the worst moment, usually during a funding round.

Timelines

MiCA gives regulators 40 working days to assess completeness and a further 40 to decide. In practice the clock stops every time they request information, and most applications go through two or three rounds. Six to nine months from first submission to authorisation is a realistic planning assumption; firms with weak pre-application engagement have taken longer.

Where DORA fits

MiCA is not the only regime landing at once. DORA imposes ICT risk management, incident reporting and third-party oversight obligations on the same firms, and regulators increasingly review both together. Budgeting for MiCA alone leaves a gap — we set out the overlap in MiCA and DORA and in our DORA compliance guide.

Before you commit

The cheapest licence is the one you do not need. If your model can operate as a decentralised protocol without custody or an operated trading venue, MiCA may not apply to you at all — a distinction we explore in MiCA-compliant crypto platforms and top blockchains for Europe under MiCA.

If you do need one, pick the jurisdiction on regulator throughput and talent availability rather than headline fees. The difference between a six-month and a fourteen-month authorisation is worth far more than a EUR 15,000 saving on the application.

Frequently asked questions

How much does a MiCA CASP licence cost in total?

There is no single figure, because the largest components scale with your business. Application fees generally land between EUR 5,000 and EUR 25,000, but minimum capital (EUR 50,000 to EUR 150,000 by class, or one quarter of fixed overheads if higher) and the staffing you must have in place before filing dominate. For a firm with real headcount, the people cost is usually the largest line by a wide margin.

Which minimum capital class applies to me?

It follows the services you provide, not your jurisdiction. Class 1 (EUR 50,000) covers order reception and transmission, execution, placing, advice, portfolio management and transfers. Class 2 (EUR 125,000) covers custody and exchange. Class 3 (EUR 150,000) covers operating a trading platform. You hold the higher of your class minimum or one quarter of prior-year fixed overheads.

Can I reduce the cost by choosing a cheaper member state?

Only at the margin. Minimum capital is harmonised across the EU, so the largest fixed component does not vary. Application and supervisory fees do vary, but the differences are small relative to staffing and capital. Regulator throughput and local talent depth affect your total cost far more than fee schedules — see CASP jurisdictions compared.

How long does authorisation take in practice?

Longer than the statutory clock, because the clock generally pauses while your regulator waits for responses. Firms that file a complete application with the compliance stack already operating move fastest; firms that file early to "start the clock" spend the saved time in remediation rounds and usually finish later.

Do I need the compliance stack before I file, or after?

Before. The application asks how you screen, monitor and report, and answers describing a system you intend to procure are weak. Having screening and monitoring genuinely operating, with policies and sample outputs, is the difference between one remediation round and three.

Does DORA apply on top of MiCA?

Yes, to the same entities, covering ICT risk management, incident reporting, resilience testing and third-party risk. It is increasingly reviewed alongside the authorisation file rather than afterwards, so budget both workstreams together.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.