Buying a MiCA-Authorised CASP: The Regulatory Checklist the Asking Price Doesn’t Cover


A MiCA licence is not what is for sale. The company holding it is.

Holding a CASP authorisation under MiCA’s Article 63 can look like a fast track into the market. But what the buyer is actually taking on goes well beyond the regulatory status.

The company also comes with:

its regulatory history, including AML;

its governance model and structure;

its staff and senior personnel;

outsourced services and the dependencies that come with them;

its technology and information systems, which sit inside DORA’s scope, not outside it: a CASP is a financial entity for the purposes of the EU’s digital operational resilience framework, which makes ICT risk, incident reporting and third-party technology dependencies one of the sharpest risk areas in a deal like this, not a footnote;

its banking and payment relationships.

This is where the gap between the asking price and what the company is actually worth starts to show.

A seller may have put in real time and money to get the authorisation. A buyer should be assessing something different: what stays usable after the deal closes, and what needs rebuilding.

Are the existing outsourced compliance providers staying on?

Can the existing operating model support the buyer’s strategy?

Are there unresolved regulatory, tax or contractual issues?

Will the company keep the same relationship with its banks and payment providers after the change of control?

That last point is not a regulatory question. Whether a bank keeps servicing a CASP after a change of control is the bank’s own commercial decision, usually governed by change-of-control clauses in the banking agreement itself, not by MiCA. It does not automatically follow the ownership of a company, even one that keeps its authorisation fully intact.

The buyer has its own regulatory process to clear

A qualifying holding, as MiCA’s Article 3(1)(36) defines it, is a direct or indirect holding of at least 10% of a CASP’s capital or voting rights, or any smaller stake that makes it possible to exercise significant influence over its management. Crossing that line triggers a notification duty under Article 83, and it works both ways. Acquiring or increasing a holding so that it reaches or exceeds 20%, 30% or 50%, or so that the CASP becomes the acquirer’s subsidiary, has to be notified to the regulator before the transaction, including for persons acting in concert. So does disposing of a holding, or dropping it below those same thresholds.

Article 83(3) to (9) lays out a defined rhythm, and it starts fast. A complete notification gets acknowledged in writing within two working days, and from there the regulator has up to 60 working days to actually assess it. Somewhere in that window, it can pull in the AML/CFT authorities and the local financial intelligence unit. Their opinion isn’t a courtesy, either: the regulator has to weigh it, which means a target’s own AML history can quietly decide whether the deal goes through. The clock can also stop. If the regulator wants more information, it can pause for up to 20 working days, stretching to 30 when the buyer sits outside the EU or answers to a third country’s regulator. Silence, on the other hand, works in the buyer’s favour: no objection inside the assessment period means the acquisition is deemed approved, though the regulator can still fix its own deadline for actually closing the deal.

What the regulator is actually testing, under Article 84(1), is the reputation of the proposed acquirer, the reputation, knowledge, skills and experience of whoever will run the business afterward, the acquirer’s financial soundness, whether the CASP will still be able to meet its Title V obligations, and whether there is reasonable suspicion of money laundering or terrorist financing tied to the deal. It can only object on those grounds, or because the information it was given is incomplete or false, and testing the transaction against the market’s economic needs is explicitly off the table under Article 84(2) and (3).

Two consequences that are easy to miss

Under Article 68, if the regulator later identifies risks to the CASP’s sound and prudent management, it can suspend the voting rights attached to the shares of a qualifying-holding shareholder, direct or indirect. That’s a live risk after closing, not just a hurdle before it.

Separately, Article 64(1) lets the regulator pull an authorisation outright: if it’s sat unused for twelve months after being granted, or if the company’s gone nine straight months without actually providing crypto-asset services, that’s grounds for withdrawal, no discretion involved. A “ready-made” licence that’s been sitting idle isn’t, on that basis alone, a safe thing to buy.

None of this comes with automatic EU-wide reach either. Article 65 covers passporting into another member state, and it needs its own notification: the home regulator has 10 working days to inform the host regulators, ESMA and EBA, and the CASP can only start operating there once that notification is confirmed, or, at the latest, 15 calendar days after it was submitted.

Practically, all of this makes regulatory clearance a condition precedent to closing. Legally, that undersells it. There’s an acknowledgment period built in, a fixed assessment window, rules for pausing the clock along the way. And the regulator, on top of all that, gets to set its own deadline for when the deal actually has to close. It’s worth managing on its own timeline, not treating as a formality that clears itself once due diligence is done.