Most founders pursuing a MiCA license assume they are solving their EU regulatory problem. They are solving part of it. The rest depends on which services they actually offer.
MiCA Decoded is a 12-article weekly series for Bitcoin.com News, co-authored by LegalBison’s Co-Founding and Managing Directors: Aaron Glauberman, Viktor Juskin and Sabir Alijev. LegalBison advises crypto and FinTech companies on MiCA licensing, CASP and VASP applications, and regulatory structuring across Europe and beyond.There is a version of the MiCA authorization process that founders talk about as if it ends the moment the license arrives. Apply, wait, get authorized, operate in the EU. The license is the finish line.
This tenth installment of MiCA Decoded maps that gap precisely, service by service.
The Myth: MiCA Covers the Full Stack of What a Crypto Exchange Does Where the CASP License Stops Payment ServicesA platform that receives fiat or e-money tokens (EMTs) from a user, holds them, and transmits them somewhere is operating a payment service. This requires either a payment institution license or an Electronic Money Institution (EMI) license under Directive (EU) 2015/2366 (PSD2), rather than just a Crypto-Asset Service Provider (CASP) authorization. Because EMTs are legally deemed to be electronic money, CASP transfer services do not cover EMTs unless the activity falls under the “intermediation” exclusion.
A non-EMI CASP can transmit orders for EMTs only if the transaction stays within the CASP’s internal ecosystem or within a custodial account managed by an authorized licensed partner. If a service involves transmitting an order that triggers the transfer of an EMT to a third-party wallet or a private ledger, it constitutes the execution of a payment transaction or a money remittance service under PSD2/PSD3. Any CASP facilitating these external transfers after March 2026 must have its own EMI/PI license or use a licensed agent.
For an exchange that wants to let users top up via SEPA transfer, settle redemptions in euros, or issue a branded debit card, a CASP license is a necessary piece of the structure. It is not sufficient.
Perpetuals and FuturesThis is where the exposure tends to be sharpest for derivative-first platforms.
MiCA’s scope is defined around “crypto-assets,” which are digital representations of value or rights that can be transferred using distributed ledger technology. The regulation covers the services built around those assets: custody, trading on spot markets, exchange, execution of orders as well as routing of orders as a pure intermediary. What it does not cover is financial derivatives where the crypto-asset is the underlying instrument rather than the thing being traded.
Futures ContractsOperating a trading platform for such instruments requires authorization as a regulated market, multilateral trading facility (MTF), or organized trading facility (OTF) under MiFID II. CASP authorization covers the operation of a trading platform for crypto-assets under Article 76 of MiCA, which defines a trading platform as a multilateral system bringing together multiple third-party purchasing and selling interests in crypto-assets, not derivatives on crypto-assets.
In practical terms, this means the CASP provides a venue where clients meet and trade with each other under clear operating rules defined and maintained by the CASP itself. The platform operator pools and matches client orders to facilitate price discovery rather than setting prices. The CASP does not take market risk, book trades on its own sheet, or deal on its own account. The only exception is matched principal trading, which the operator may engage in strictly with explicit client consent and monitoring by the competent authority.
Both frameworks impose strict limits on permitted trading models. Under MiFID II, multilateral trading facilities (MTFs) are entirely banned from executing client orders against proprietary capital or engaging in matched principal trading. Organized trading facilities (OTFs) are permitted to act as matched principals for specific instruments, such as bonds, structured finance products, emission allowances, and certain derivatives, but only with explicit client consent.
MiCA establishes similar restrictions for crypto-assets. Crypto-asset service providers cannot deal on their own account on the trading platforms they operate. MiCA allows matched principal trading as an exception, but only where the client has consented to the process. The provider must supply the competent authority with information explaining its use of matched principal trading. The competent authority then monitors the engagement to verify it continues to fall within the strict definition of matched principal trading and does not give rise to conflicts of interest between the provider and its clients.
Bitstamp, which holds MiCA authorization in Luxembourg under the Commission de Surveillance du Secteur Financier (CSSF), also holds a MiFID license permitting it to operate an MTF. That dual licensing structure is not an accident. It reflects the actual scope of the activity.
Why Operators Miss ThisSeveral factors produce the misunderstanding.
First, the practical effect of pre-MiCA national VASP regimes varied significantly by jurisdiction and over time. While early registrations in some countries might have initially operated as a permissive baseline, regulators became increasingly stringent.
Second, the CASP register entries themselves are not always informative to founders reading them from the outside. An exchange listed as authorized for “operation of a trading platform” and “execution of orders” looks comprehensively authorized. Whether it is running derivatives products under a separate MiFID authorization requires reading beyond the CASP register entirely.
The Regulatory JunctionsPSD2 and the EMI regime govern payment services involving fiat. Any activity involving the receipt, holding, or transmission of euro-denominated or other official currency funds requires either a payment institution license (for payment initiation and money transmission) or an EMI license (where the platform stores fiat value electronically as a claim redeemable at par). An exchange that allows users to fund accounts by bank transfer and withdraw in euros is, at minimum, touching a payment service. Whether that requires PSD2 authorization depends on the specific flow and structure, but the question must be assessed deliberately, not assumed away.
MiFID II governs derivatives. Futures, perpetuals, options, and CFDs on crypto-assets are financial instruments. Operating venues for their trading, or providing investment advice and portfolio management in relation to them, requires MiFID II authorization. The specific authorization type, investment firm, regulated market, MTF, depends on the business model.
Platforms operating across all three categories need a structure that maps each product line to its authorizing framework. That is a multi-license, multi-entity architecture in some cases, not a single CASP application.
What the Compliance Gap Looks Like in PracticeConsider an exchange that:
Offers spot BTC/EUR trading (CASP: exchange of crypto-assets for funds) Allows SEPA deposits and euro withdrawals (payment service, potentially PSD2) Runs BTC perpetual contracts with up to 20x leverage (derivative product, potentially MiFID II) Offers a crypto-backed Visa card that spends euro balances (payment institution capability, PSD2/EMI) The Operational ConsequenceFor platforms already operating in the EU under grandfathering provisions that expire July 1, 2026, the regulatory gap has an immediate timeline consequence. A VASP registration does not solve the payment services problem any more than a CASP license will. These questions do not disappear with MiCA authorization; they persist and become more visible to regulators whose supervisory tools now match the formal authorization framework.
For platforms currently designing their EU market entry structure, the sequence matters. Mapping each product line to its authorizing framework comes before choosing the jurisdiction for the CASP application. The jurisdiction choice affects the CASP, but it also affects the feasibility of layering PSD2 and MiFID II authorizations on the same entity or within the same group.
Getting the architecture wrong is fixable. But it tends to be expensive to fix after authorization, and it tends to surface at the moment the platform is growing fast enough that the regulators start paying attention.
What This Article Decoded MiCA’s CASP license authorizes ten specific crypto-asset services. It does not authorize payment services under PSD2, derivative trading under MiFID II, or any activity that falls under the financial instruments exclusion in Article 2(4)(a) of the regulation. Perpetuals and futures on crypto-assets are financial instruments in the MiFID II sense when structured as derivative contracts. Operating trading venues for these products, or providing services related to them, requires MiFID II authorization independent of any CASP license. Fiat handling triggers PSD2. The receipt, storage, and transmission of euro-denominated or other official currency funds constitutes a payment service. A CASP license does not authorize payment services. This is a structural gap for any exchange offering direct bank funding, fiat withdrawal, or crypto-funded card products. Dual and triple licensing architectures are real. Major exchanges with MiCA authorization that also run derivatives and payment products typically hold MiFID II and PSD2/EMI authorizations alongside the CASP. The structure is not exotic; it reflects the actual scope of a full-service crypto exchange operating under EU law. The business model assessment happens before the application. NCAs reviewing CASP applications will examine the programme of operations. A business model that includes derivatives or payment services, unaddressed, creates exposure during the authorization review itself.


















