Crypto exchange or trading venue
"Operating a trading platform or exchanging crypto-assets for funds or for other crypto-assets requires a CASP license; the trading platform is also the service with the highest capital requirement."
We handle your CASP license in Spain —the crypto-asset service provider authorization required by the MiCA Regulation— before the CNMV: service scoping, capital, governance, custody, cybersecurity and anti-money laundering, with an EU passport. The Spanish transitional period ended on 30 June 2026: since 1 July 2026, only authorized (or passported) CASPs may operate.
Free consultation
We'll get back to you within 24h
A CASP license (short for Crypto-Asset Service Provider; in Spanish, proveedor de servicios de criptoactivos) is the mandatory authorization that Regulation (EU) 2023/1114 (MiCA) requires from anyone who provides crypto-asset services professionally in the European Union. In Spain, this MiCA license is granted and supervised by the CNMV (Spanish Securities Market Commission).
The rule is simple: without CASP authorization, you cannot provide crypto-asset services in the EU (save for very strict exceptions). And one date has changed everything in Spain: the transitional period ended on 30 June 2026, so since 1 July 2026 only CASPs authorized by the CNMV —or authorized in another Member State and passported— may keep operating. The former Bank of Spain register of providers (VASP), which existed for anti-money laundering purposes only, no longer qualifies you to operate under MiCA.
Six workstreams that take your CASP authorization from start to finish: from the initial assessment and service classification to the CNMV application file, solvency, governance, anti-money laundering and cybersecurity.
We analyze your business model and determine which crypto-asset services you provide, whether you need CASP authorization and which prudential class applies to you, before you approach the CNMV.
We prepare and file the complete application under MiCA and its delegated regulations: programme of operations, policies, contracts and all the documentation the CNMV assesses.
We size the minimum capital according to your service class and the prudential safeguards (the higher of the required capital and one quarter of the previous year's fixed overheads).
We demonstrate the suitability of directors, senior managers and significant shareholders under the European guidelines the CNMV applies to crypto-asset service providers.
We design your anti-money laundering policies (KYC, monitoring, reporting to SEPBLAC) and the Travel Rule, an essential pillar of the application file and of ongoing supervision.
We structure the secure custody of keys and wallets and your digital operational resilience (DORA): ICT risk management, business continuity and oversight of technology providers.
MiCA defines what a "crypto-asset service" is and lists ten activities. Providing any of them professionally in the EU requires a CASP license. The service (or services) you provide determines your prudential class and, with it, your minimum capital.
MiCA groups services into three prudential classes with increasing minimum capital. The required safeguard is always the higher of that minimum capital and one quarter of the fixed overheads of the preceding year.
Exchanges, custodians, fintechs adding crypto and providers coming from the Bank of Spain register: if you provide crypto-asset services to third parties from Spain, CASP authorization —your crypto license in Spain— is your way in (and your way to stay in business).
"Operating a trading platform or exchanging crypto-assets for funds or for other crypto-assets requires a CASP license; the trading platform is also the service with the highest capital requirement."
"Custody and administration of client crypto-assets is one of the core CASP services; the application file requires a robust custody policy: segregation, key management and a recovery plan."
"An entity that is already authorized (bank, payment institution, electronic money institution) can provide crypto services through the notification route, but it is not automatic: there are requirements and deadlines to meet."
"Providers registered with the Bank of Spain needed CASP authorization from the CNMV before the transitional period ended; the old register, for anti-money laundering purposes only, no longer qualifies you to operate."
Operating without authorization, having missed the end of the transitional period or filing a weak application file are the risks that most expose —and most hold back— a crypto-asset provider.
The transitional period ended on 30 June 2026. Since 1 July 2026, only CASPs authorized by the CNMV or passported from another Member State may operate in Spain.
Operating without authorization is illegal: providing crypto-asset services without a CASP license exposes you to administrative and, where applicable, criminal penalties under national law.
VASP registration is no longer enough: the former registration with the Bank of Spain (for anti-money laundering purposes only) does not qualify you to operate under MiCA; they are different things.
Depending on the services, minimum capital ranges from €50,000 to €150,000, and the required safeguard is the higher of that amount and one quarter of the previous year's fixed overheads.
A demanding application file: fit and proper assessment of directors and shareholders, custody policy, risk management, AML/KYC and digital operational resilience (DORA). Outsourcing does not remove responsibility.
EMTs and payment services: anyone transferring or holding in custody e-money tokens that qualify as payment services must also comply with PSD2 or rely on an authorized institution (EBA no-action letter).
A solid application file takes months to prepare, and the transitional window has closed. The sooner we carry out the assessment and classify your services, the better we can plan the capital, custody and the rest of your CNMV application file.
Once the application is filed, the CNMV has one period to check that the file is complete and another to assess it, which can be suspended if it requests information. In practice, a well-built application file takes several months to process.
The authorization application is not a form: it is a very specific information package. This is what you should have ready and, above all, be able to prove with evidence.
| Document or policy | What it must demonstrate (and evidence) |
|---|---|
| Programme of operations | The exact services you provide, where they are provided and how they are marketed. |
| Capital and safeguards | Consistency with your service class and your fixed overheads. |
| Corporate governance | Organization chart, responsibilities and a suitable management body. |
| Shareholders and qualifying holdings | Structure, good repute and supporting documentation. |
| Internal control and risk management | Operational risk, anti-money laundering and business continuity. |
| ICT and security | Architecture and controls backed by evidence: access, logs, incidents and backups. |
| Custody and segregation | Real separation of client assets and funds, with a working mechanism. |
| Complaints | Procedure, deadlines and customer service channel. |
| Service-specific policies | Custody, execution policy, exchange pricing methodology, etc. |
What the supervisor looks at most: consistency between what you sell (marketing and user experience), what you do (actual operations) and what you document (policies, ICT and controls). If they diverge, the application stalls.
"Evidence" is the key word: a license does not stand on generic texts, but on records, controls that are actually in place and traceability: what was done, who approved it and on what basis.
Beware of "cosmetic relabeling": changing the wording on your website ("we only provide technology", "we don't hold custody") does not work if, in practice, you control keys, move assets or decide how an order is executed. Authorization is assessed on your operational reality.
Beyond the CNMV's statutory deadlines, the preparation work is planned in phases. Rushing it "at the last minute" usually fails for lack of evidence and because of the iterations (information requests, clarifications, adjustments).
Tip: keep all the material in a single folder (01 Scope and flows · 02 Governance · 03 Risks and controls · 04 ICT and security · 05 Service-specific policies · 06 Evidence). With everything organized, answering CNMV information requests is much faster.
For the application file to be defensible, you need to turn "what we do" into a clear programme of operations and a matrix that links risks → controls → evidence. These are the two starter templates.
| CASP service | Operational description | Systems / ICT | Outsourcing |
|---|---|---|---|
| Custody | How wallets, keys, approvals and recovery are managed. | Wallet infrastructure, key management, access and monitoring. | Custody provider or HSM (if applicable). |
| Crypto-fiat exchange | Pricing model, execution, settlement and fees. | Matching and pricing engine, monitoring. | Liquidity provider (if applicable). |
| Risk | Control | Frequency | Evidence |
|---|---|---|---|
| Loss of assets through unauthorized access | Two-factor authentication, least-privilege roles and permission reviews. | Monthly | Access logs and review minutes. |
| Commingling of client and company funds | Segregation by wallets or accounts and reconciliation. | Daily | Reconciliation report, alerts and period-end closes. |
Indicative templates for information purposes. The recommended order is: first settle the CASP scope and flows, then draft the policies and, finally, generate the evidence (controls actually performed). Doing it the other way round —generic policies with no real flow behind them— usually proves costly.
Not everyone reaches MiCA by the same path. This comparison helps you avoid confusing the CASP license with the notification route for already authorized entities or with the old Bank of Spain register.
Compared with the other routes, CASP authorization from the CNMV is the one that fully entitles you to provide crypto-asset services under MiCA and to use MiCA passporting across the EU.
First of all, we carry out a MiCA assessment to determine whether you need full authorization or the notification route fits you, and we classify your services to set the capital and the scope of the application file.
| Route | For whom | What it requires | Outcome |
|---|---|---|---|
| CASP authorization (CNMV) | Crypto firms and new operators | Full MiCA application file: capital, custody, governance, AML and ICT | CASP license + EU passport |
| Simplified notification | Already authorized entities (banks, investment firms, EMIs) | Prior notification with the required information | Permission to provide the crypto services notified |
| VASP register (Bank of Spain) | Pre-MiCA providers, for AML purposes only | AML registration (closed to new applicants) | Does not qualify you to operate under MiCA since 1 July 2026 |
Indicative table for information purposes. The regime derives from Regulation (EU) 2023/1114 (MiCA) and its implementing rules; requirements, amounts and deadlines may vary and should be validated case by case with legal advice. This page is for information only and does not constitute advice.
It is the authorization that the MiCA Regulation requires from any natural or legal person that professionally provides crypto-asset services in the EU. CASP stands for Crypto-Asset Service Provider (in Spanish, proveedor de servicios de criptoactivos). In Spain, it is granted and supervised by the CNMV.
The CNMV is the competent authority to authorize and supervise CASPs. The Bank of Spain is competent for stablecoin issuers (asset-referenced tokens and e-money tokens), and SEPBLAC is the anti-money laundering supervisor.
In Spain, the transitional period, extended to 18 months, ended on 30 June 2026. Since 1 July 2026, MiCA has applied in full and only CASPs authorized by the CNMV, or authorized in another Member State and passported, may operate.
No. The former Bank of Spain register of providers (VASP) existed for anti-money laundering purposes only and no longer accepts new registrations. It does not qualify you to provide services under MiCA; the CASP license is a separate activity authorization, granted by the CNMV.
The ten crypto-asset services under MiCA: custody and administration, operation of a trading platform, exchange for funds, exchange for other crypto-assets, execution of orders, placing, reception and transmission of orders, advice, portfolio management and transfer services.
It depends on the services: €50,000 (class 1), €125,000 (class 2, which adds custody and exchange) or €150,000 (class 3, which adds the trading platform). The required safeguard is the higher of that minimum capital and one quarter of the fixed overheads of the preceding year.
The CNMV has 25 working days to check that the application is complete and 40 working days to assess it, a period that can be suspended while it requests information. In practice, preparing and processing a solid application file usually takes several months.
Yes. MiCA provides for an EU passport: a single CASP authorization lets you provide services throughout the European Economic Area by notification (MiCA passporting), with no need for a new authorization in each country.
Not always. Certain already regulated entities (credit institutions, investment firms, electronic money institutions, etc.) can provide certain crypto-asset services through prior notification instead of full authorization. It is not automatic: there are requirements and deadlines.
The exclusive client initiative exemption (reverse solicitation) is very narrow: it does not allow you to solicit clients in the EU or to turn advertising or targeted marketing into an exemption. If your activity targets the European market, you will normally need authorization.
A CASP provides services on crypto-assets (custody, exchange, execution…) and is supervised by the CNMV. The issuer of asset-referenced tokens (ART) or e-money tokens (EMT) creates the crypto-asset and is governed by Titles III and IV of MiCA, under the remit of the Bank of Spain.
In some cases, yes. Anyone who transfers or holds in custody e-money tokens that constitute payment services must, in addition to the CASP license, comply with PSD2 or rely on an authorized payment institution, in line with the EBA no-action letter (which set 1 March 2026 as the deadline).
Your prudential class is the highest among the services you provide. For example, if you provide custody (class 2) and also operate a trading platform (class 3), class 3 capital applies to you.
No. Outsourcing functions or technology does not remove responsibility: the CNMV requires control, governance, security and oversight of providers, including digital operational resilience under DORA.
A robust custody policy: segregation of clients' crypto-assets, secure key management (cold/hot wallets, multisig or MPC), key generation procedures and a recovery plan.
Yes: real substance is required (registered office and effective management, adequate resources and governance). The CNMV may carry out supervisory and verification actions, so the structure cannot be merely formal.
Once authorized, the provider is entered in a public register of crypto-asset service providers, accessible through the CNMV and through the register that ESMA maintains at European level, which brings transparency and trust to the market.
No. Authorization is granted based on the services you are going to provide (custody, exchange, platform, etc.). The more critical the service, the more requirements it carries: higher minimum capital and specific policies.
Yes, but your initial scope must be realistic. If you extend your services later, you will have to apply for the extension and provide additional documentation (and move up a capital class if applicable), so it is best to plan for it from the start.
Authorization is not the end: ongoing supervision begins. You must keep your policies up to date, submit periodic reporting, undergo audits and deal with the CNMV on any information request. A good application file makes that day-to-day work easier.
Because the license does not stand on generic texts, but on records, controls that are actually in place and traceability: what was done, who approved it and on what basis. Evidence reduces operational risk and is your best defense in a review.
Getting authorized is not just a matter of filling in a form: it means classifying your services, sizing capital and custody, setting up governance and anti-money laundering, and filing a consistent application with the CNMV. Order matters.
Before incorporating or applying for anything, determine which crypto-asset services you provide and which prudential class applies to you. That defines your capital and the scope of the application file.
Size your capital and design your custody policy and ICT resilience. This is the most technically demanding part and the one the CNMV scrutinizes most closely.
Since 1 July 2026, only authorized or passported CASPs may operate. An application file takes months: starting late means being left out.
Want to see where the CASP license fits within MiCA as a whole? See our pages on the MiCA Regulation, the transition from VASP to CASP and digital operational resilience (DORA).
Getting a CASP license is an ordered sequence before the CNMV (assessment, application file, filing, review and authorization + passport). This is the journey.
1) AssessmentWe analyze your model and identify which crypto-asset services you provide, whether you need authorization or notification and which prudential class applies to you.
2) Application fileProgramme of operations, capital and safeguards, governance and fit and proper, custody, AML/KYC and ICT resilience (DORA), in line with the delegated regulations.
3) FilingWe file the application with the CNMV, which checks that it is complete within 25 working days and may request additional information before assessing it.
4) Authorization + passportThe CNMV assesses the application within 40 working days (a period that can be suspended if it requests information). Once authorization is granted, you are entered in the CASP register and activate the passport to operate throughout the EEA.
Quick decisionFull CASP authorization from the CNMV, with a complete application file and EU passport.
Credit institution, investment firm or EMI: prior notification route for crypto services.
If you issue ARTs or EMTs, the Bank of Spain is the competent authority (you are not a CASP).
CNMV; covers MiCA's ten crypto-asset services.
ARTs and EMTs fall under the Bank of Spain.
€50,000, €125,000 or €150,000 depending on the service class.
Or one quarter of the previous year's fixed overheads, whichever is higher.
Suitable directors, senior managers and significant shareholders.
In line with the European guidelines applied by the CNMV.
Asset segregation, key management and a recovery plan.
Cold/hot wallets, multisig or MPC.
KYC, Travel Rule and reporting to SEPBLAC; operational resilience (DORA).
Outsourcing the technology does not remove responsibility.
Anticipate them before filing your application to avoid information requests and further delays, now that the transitional window has closed.
If you are applying for a CASP license, these terms will come up in the assessment, in the CNMV application file and in ongoing supervision.
Crypto-asset service provider. A person authorized under MiCA to professionally provide one or more of the ten crypto-asset services.
Regulation (EU) 2023/1114 on markets in crypto-assets. It creates a single European framework for issuers and providers of crypto-asset services.
A digital representation of a value or a right that can be transferred and stored electronically using distributed ledger technology or similar technology.
Any of the ten activities listed in MiCA (custody, platform, exchange, execution, placing, reception/transmission, advice, portfolio management and transfers).
A crypto-asset that aims to maintain a stable value by referencing several currencies, assets or baskets. Its issuance is governed by Title III of MiCA.
A crypto-asset that maintains a stable value by referencing a single official currency. It is the e-money "stablecoin" under Title IV of MiCA.
The mechanism by which a CASP authorization granted in one Member State allows you to provide services throughout the EEA by simple notification.
A grouping of services that determines a CASP's minimum capital: class 1 (€50,000), class 2 (€125,000) and class 3 (€150,000).
The service of safekeeping crypto-assets, or the means of access to them (keys), on behalf of clients. It requires segregation and enhanced controls.
The former Bank of Spain register of exchange and custody service providers, for anti-money laundering purposes only. It does not qualify you to operate under MiCA.
Exclusive client initiative. A very narrow exemption that does not allow you to solicit clients in the EU or to turn advertising into a way around authorization.
The obligation for crypto-asset transfers to be accompanied by information on the originator and the beneficiary, under Regulation (EU) 2023/1113.
A practical guide to obtaining your CASP authorization: the ten crypto-asset services, the capital classes, the CNMV procedure, the EU passport, anti-money laundering and cybersecurity, and the timeline for the end of the transitional period.
Tell us which crypto-asset services you provide or plan to provide and where you operate from, and we will tell you whether you need authorization or notification, what capital and custody requirements apply and how to plan your CNMV application file now that the transitional period is over.
The CASP license derives from Regulation (EU) 2023/1114 (MiCA) on markets in crypto-assets and its implementing rules, in particular Delegated Regulations (EU) 2025/303 and 2025/305, which specify the information to be included in the authorization application. In Spain, the competent authority to authorize and supervise crypto-asset service providers is the CNMV, which has published an authorization manual and a notification template, as well as a questions-and-answers document on the application of MiCA.
The Spanish transitional period, extended to 18 months, ended on 30 June 2026: since 1 July 2026, MiCA has applied in full and only authorized or passported CASPs may operate. The issuance of asset-referenced tokens (ART) and e-money tokens (EMT) falls under the Bank of Spain, and anti-money laundering supervision under SEPBLAC. The former Bank of Spain register of providers (VASP), for AML purposes only, does not qualify you to operate under MiCA.
Anyone who transfers or holds in custody EMTs that constitute payment services must also comply with PSD2 or rely on an authorized payment institution, in line with the EBA no-action letter. The anti-money laundering framework includes the Travel Rule under Regulation (EU) 2023/1113, and technology operations must meet digital operational resilience (DORA) requirements. That is why a CASP license is not designed as a stand-alone procedure, but integrated with the rest of the financial regulatory framework.
You can consult the regulation directly in its official sources: the CNMV MiCA portal and the CNMV questions and answers on MiCA document. This page is for information only and does not constitute legal advice; each project must be analyzed individually.