From VASP to CASP
Existing crypto businesses should map legacy activities against MiCA service categories and close gaps in governance, client disclosures and safeguarding.
Czech Republic CASP authorisation under MiCA
A practical one-page guide for founders, fintech groups and existing VASPs preparing for Czech authorisation under the EU Markets in Crypto-Assets Regulation. It covers licence scope, governance, AML, documentation, process planning and post-approval duties.
For Czech-specific licensing support, read more about the MiCA licence in the Czech Republic.
Regulatory landscape
MiCA creates a harmonised EU regime for crypto-asset service providers. In the Czech Republic, applicants should prepare for a formal authorisation process that looks beyond registration and tests whether the company has durable substance, competent management, credible policies and a controlled operating model.
Existing crypto businesses should map legacy activities against MiCA service categories and close gaps in governance, client disclosures and safeguarding.
A compliant authorisation strategy should anticipate cross-border service delivery, passporting, local language documentation and consistent customer treatment.
Policies are not enough. Applicants need board minutes, role descriptions, risk registers, vendor files and operational proof.
Custody, exchange, transfer, portfolio, advice and token-related activities carry different capital, control and disclosure expectations.
Scope mapping
Applicants should define exactly which MiCA services they will provide, because this drives capital, governance, outsourcing, IT security, conflicts, complaints and client asset safeguards.
| Service area | Typical business model | Key licensing focus |
|---|---|---|
| Custody and administration | Wallet custody, safekeeping of client crypto-assets | Segregation, private key controls, incident response, reconciliation |
| Exchange services | Crypto-fiat or crypto-crypto exchange | Pricing transparency, order handling, AML monitoring, market abuse controls |
| Trading platform operation | Marketplace matching third-party buy/sell interests | Rulebook, access criteria, surveillance, conflicts and resilience |
| Transfer services | Execution of crypto transfers on behalf of clients | Travel rule readiness, sanctions screening, beneficiary checks |
| Advice or portfolio services | Recommendations or managed exposure to crypto-assets | Suitability, disclosures, competence, conflicts and recordkeeping |
Substance
Financial crime controls
A Czech MiCA applicant should demonstrate a live AML framework, not a generic template. The programme must match customer type, asset type, transaction flows, geographies and delivery channels.
Onboarding, verification, beneficial owners and enhanced due diligence.
Rules, blockchain analytics, alerts, case handling and suspicious reports.
Screening at onboarding, transaction points and periodic review.
Staff competence, annual refreshers and evidence of completion.
Evidence pack
The application file should read like a controlled operating manual for the future authorised CASP. Each document should be internally consistent with the business plan, service scope and risk profile.
Articles, registry extract, ownership chart, UBO evidence, group structure, capital evidence.
Services, client segments, revenue model, forecasts, jurisdictions, marketing and growth assumptions.
Board rules, organisational chart, role descriptions, conflicts policy, remuneration approach.
Risk assessment, AML policy, KYC procedures, monitoring rules, sanctions controls, training plan.
Architecture, access control, key management, resilience, business continuity and incident response.
Terms, risk disclosures, complaints, asset safeguarding, order execution and record retention.
Authorisation route
Map activities to MiCA service categories, identify exclusions and define passporting goals.
Upgrade governance, AML, custody, ICT and client disclosure arrangements before submission.
Submit the file, manage regulator questions and keep all policies, diagrams and forecasts aligned.
Activate reporting, compliance calendar, training, complaint logs and monitoring dashboards.
After authorisation
A MiCA licence is not a static certificate. Czech CASPs should operate a compliance calendar and evidence continuous control over client assets, financial crime risk, conflicts, complaints, outsourcing and operational incidents.
| Area | Practical duty |
|---|---|
| Governance | Board packs, risk reviews, policy approvals, conflicts register. |
| AML | Periodic KYC refresh, alerts, SAR decisions, sanctions logs. |
| Operations | Incident register, outsourcing monitoring, business continuity tests. |
| Clients | Complaints, disclosures, asset reconciliations, service changes. |
| Regulatory change | Track guidance, update procedures and retrain relevant staff. |
Planning view
Scope, corporate setup, management checks, policy drafting, vendor documentation and operating model review.
Regulatory review depends on file quality, service complexity, ownership structure and responsiveness to follow-up questions.
Finalise controls, train staff, configure reporting, test incident escalation and confirm client-facing materials.
Practical answers
MiCA is designed around harmonised EU authorisation and cross-border service provision. Passporting should be planned during the licensing strategy, not after approval.
A legacy registration usually does not equal full MiCA readiness. Existing providers should review service scope, capital, governance, AML, client disclosures and operational controls.
The staffing model should be proportionate to activity, risk and outsourcing. Management must remain able to supervise the business effectively.
Common delays include unclear service mapping, generic AML policies, weak custody evidence, incomplete ownership documents, inconsistent financial forecasts and slow responses to regulator questions.
Yes, but the final submission must be coherent. Policies, business plan, organisational chart, outsourcing files and risk assessment should describe the same operating reality.
Contact block
Best for: exchanges, custodians, transfer providers, trading platforms, token projects and fintech groups.
Output: scope map, gap list, document plan and approval route.