Having an EU entity, a local address, and paid-in capital may still fall short under MiCA. The article argues that regulators are not checking boxes. They are asking whether a crypto-asset service provider actually runs part of its business from within the European Union, or whether the setup is only a licensing shell.
According to the piece, many first-time applicants arrive with what looks like a complete structure on paper: a registered office in a favorable member state, a named director, cloud-based ICT systems or infrastructure managed by a global group team, and initial capital deposited into a newly opened account. Internally, that can feel like a functioning EU company. From the perspective of a national competent authority, it may still resemble a letterbox company with minimal real activity.
MiCA asks for genuine operations, not paperwork alone
The article links this approach to older EU legal principles rather than a new regulatory invention. It cites the Cadbury Schweppes judgment, where the Court of Justice of the European Union said freedom of establishment cannot be used for wholly artificial arrangements that lack genuine economic activity. MiCA brings that logic directly into crypto regulation.
Under Article 59(2), an authorized CASP must have its registered office in a member state where it carries out at least part of its crypto-asset services, keep its place of effective management within the Union, and have at least one director resident in the EU. The statutory wording is short. The supervisory expectation behind it is much tougher, and the article says this is where many applications begin to face friction. ESMA’s supervisory briefing on CASP authorization, though non-binding, signals how national authorities are likely to read those requirements in practice.
Supervisors look past nominee directors to real management
On personnel, the formal minimum is one EU-resident director. ESMA’s guidance sets a higher operational standard. The article says supervisors generally expect at least two senior executives jointly overseeing day-to-day operations, both to reduce concentration risk and to create basic internal checks. Residency alone does not solve the issue. Where a management body member does not live in the NCA’s jurisdiction, that person should still be able to attend in-person meetings within two business days if requested.
Time commitment is treated just as seriously. ESMA’s position is that executive management board members should usually devote 100% of their professional time to the CASP role. Holding executive roles across multiple entities is accepted only in limited circumstances. The article also stresses reporting lines: strategic and operational control must sit inside the EU entity itself, not with a parent company in a third country that makes decisions and sends instructions downward.
Anti-money laundering functions form part of the same substance analysis. The MLRO responsible for suspicious activity reports must be physically present, have genuine authority within the firm, and be able to deal directly with the local Financial Intelligence Unit. The article notes that MiCA’s staffing expectations align with broader international trends reflected in FATF standards and the OECD’s Crypto-Asset Reporting Framework, both of which push regulated crypto businesses toward demonstrable internal capacity and transparency.
For technology, the key question is who controls the systems
DORA applies directly to CASPs, and the article says supervisors are less interested in which infrastructure provider is used than in who has real control over the relevant systems. Hosting with AWS, Azure, or similar providers is not the problem by itself. The problem begins when the EU-authorized entity lacks meaningful authority over the ICT environment it depends on.
If encryption key management sits with a parent company’s global IT team, if access rights to client data are handled from outside the EU, or if a disaster recovery plan depends on approvals from a third-country headquarters, the EU entity may struggle to prove operational independence. Based on ESMA’s position cited in the article, the EU management team must have actual control over the ICT infrastructure tied to CASP operations, and the business continuity and disaster recovery plans required under Article 68(7) must be owned and executable by the EU entity itself.
The article frames this as a blunt operational test: if the parent company’s global IT team became unavailable overnight, could the EU entity keep operating, access client funds, and return assets to clients? If not, or not without major escalation to non-EU staff, the substance question remains open. DORA is only part of the picture. GDPR-related data governance, controller-processor arrangements, and data residency also sit inside the technical architecture regulators will examine.
Capital is only the floor, and prudential pressure can rise quickly
On the financial side, Article 67 sets the minimum prudential safeguards by service class. The article lists EUR 50,000 for Class 1 services such as reception and transmission of orders, investment advice, and portfolio management; EUR 125,000 for Class 2, which adds exchange of crypto-assets for fiat or other crypto-assets, execution of orders, and placing of crypto-assets; and EUR 150,000 for Class 3, which also covers operation of a trading platform and custody and administration of crypto-assets on behalf of clients.
That initial capital is only the starting point. Prudential safeguards must equal the higher of the permanent minimum capital or one-quarter of the previous year’s fixed overheads. As a CASP grows, the fixed-overheads limb can become the real constraint much sooner than operators expect. The article points out that once overheads exceed four times the initial paid-in capital, the firm must move into the overheads-based framework, and regulators expect monitoring before the threshold becomes a compliance problem.
The location of the capital also matters. The article says the funds must be paid into an account held with a formal credit institution; an EMI or payment services provider account does not meet the requirement. Because banking access for crypto firms is often slow and uncertain, starting that process early affects the whole authorization timeline. Newly incorporated firms must also include projections for their first 12 months of fixed overheads in the application, with a clear methodology, while financial statements used for the calculation must be audited or validated by national authorities.
Outsourcing is allowed, but the licensed entity cannot be hollowed out
Article 73 allows CASPs to outsource operational functions to third parties. The limit is clear: outsourcing cannot strip the authorized firm of substance. Responsibility remains with the CASP, and delegation does not transfer accountability. The article says ESMA’s supervisory briefing treats the share of total costs tied to functions outside the EU as a practical indicator of whether outsourcing has gone too far.
If most operating expenditure flows to non-EU service providers, even reputable ones, supervisors may ask whether the EU entity has enough internal capacity to qualify as a genuine service provider at all. The distinction drawn in the article is simple and strict: outsourcing selected functions while retaining control is one thing; outsourcing everything material while keeping only the legal form is something else.

