What Adding Crypto-Asset Services Involves
A regulated financial institution adding crypto-asset services needs five things on top of its existing licensed perimeter: a routing decision (simplified notification or full authorisation), a custody and settlement layer, a crypto-fiat banking extension, a compliance overlay covering MiCA, DORA and the Transfer of Funds Regulation, and a conflicts framework that ring-fences the crypto business from the existing book. We deliver all five and we are accountable for the result.
Unlike a crypto-native start-up, an incumbent bank, MiFID investment firm, electronic-money institution, UCITS management company or AIFM already holds most of the regulatory chassis. The question is not how to become a CASP from scratch, but which of the ten MiCA crypto-asset services to add and which existing authorisation each one fits under. We answer that with you, then file the work.
Infrastructure Checklist
| Component | Purpose | Typical Timeline |
|---|---|---|
| Regulatory routing decision (MiCA Art. 60 notification vs. full CASP authorisation vs. non-EU equivalent) | Determines authorisation path, capital impact, and time-to-market | 2 to 6 weeks |
| Internal entity decision (use existing authorised entity, ring-fence inside group, or new subsidiary) | Aligns the regulated perimeter with conflicts of interest, capital optimisation, and group structure | 2 to 8 weeks |
| Crypto-asset service authorisation (notification under MiCA Article 60, or new CASP authorisation, or non-EU equivalent) | Permits the specific crypto-asset services the firm intends to provide to clients | 40 working days (notification) to 12 months (full authorisation) |
| Custody & settlement architecture (self-custody, sub-custody, or qualified custodian routing) | Establishes the segregation, key-management, and operational risk controls under MiCA Title V | 3 to 9 months |
| Banking & fiat-rail extension (correspondent accounts, on/off-ramp, multi-currency settlement) | Allows crypto-fiat conversion, client redemption, and treasury operations | 1 to 3 months (existing relationship extends); 3 to 6 months (separate institution required) |
| Dual-regime compliance overlay (DORA, AMLR, Transfer of Funds Regulation, MiCA conduct rules, conflicts of interest) | Integrates crypto-specific obligations into the existing compliance, ICT, and risk frameworks | 3 to 9 months (parallel) |
Choosing the Right Jurisdiction
Jurisdiction selection for an incumbent is rarely a clean-slate choice. You already hold your primary regulated entity somewhere, and the real question is whether to add the crypto perimeter inside the existing licensed entity, set up a sister entity in the same jurisdiction, or establish a new subsidiary in a regime that better fits your target clients. Inside the EU we deliver this in Estonia and Cyprus, our two core MiCA-passport jurisdictions, and we also file crypto-asset licensing in Lithuania, Malta and Switzerland. Where the right answer is outside the EU, the United Arab Emirates and Hong Kong are the realistic non-EU bases, and we cover those as reference below.
The decision runs across four variables: which framework already governs your firm, where your target clients sit, whether passporting matters, and whether you prefer a single regulator or a federated structure. An EU credit institution can in most cases use MiCA Article 60 to notify its home regulator and add crypto services without a separate authorisation; a non-EU bank cannot. We run that mapping for you and recommend the route that gets you to market fastest under your existing licence.
Jurisdiction Comparison
| Factor | Estonia | Cyprus | UAE | Hong Kong |
|---|---|---|---|---|
| Primary regulator | Finantsinspektsioon (FI) | CySEC | VARA; ADGM FSRA; DIFC DFSA | SFC; HKMA |
| Framework | MiCA; Krüptovaraturu seadus (in force 1 Jul 2024) | MiCA; CySEC competent under Art. 93 | VARA Rulebooks; ADGM FSMR; DIFC Crypto Token regime | SFO + VATP regime (Jun 2023); HKMA Stablecoin Ordinance (Aug 2025) |
| Path: already-authorised firm | MiCA Art. 60 notification (40 working days) | MiCA Art. 60 notification (40 working days) | Variation of existing FSRA / DFSA permission | HKMA AI adds activities; SFC Type 1/4/7/9 apply for VATP uplift |
| Path: new vehicle | Full CASP authorisation under MiCA Title V | Full CASP authorisation under MiCA Title V | New ADGM AP / DIFC AF; VARA VASP for retail | New SFC VATP; HKMA-authorised Stablecoin Issuer |
| Capital floor | €50k / €125k / €150k (MiCA Annex IV) | €50k / €125k / €150k (MiCA Annex IV) | ADGM 3C: USD 250k; DIFC 3D: USD 200k; 3C: USD 500k; VARA tiered | HK$5m base VATP; HK$25m + 12-mo reserve for HKMA stablecoin |
| Timeline | 40 working days (notification); 6–9 months (full CASP) | 40 working days (notification); 6–12 months (full CASP) | 6–14 months | 9–18 months |
| Market access | EEA passport | EEA passport | Jurisdictional only; SCA for tokenised securities | Jurisdictional only |
| Headline corporate tax | 22/78 on distributions; 0% retained | 15% CIT (from 1 January 2026); non-dom regime for mgmt | 9% federal CIT; 0% qualifying free-zone | 16.5% profits tax; 0% offshore profits |
| Tomberg delivery | Serviced — we file the notification or full CASP | Serviced — we file the notification or full CASP | Reference — talk to us about your situation | Reference — talk to us about your situation |
Choose Estonia if you are an EU-authorised credit institution, MiFID investment firm, EMI, UCITS management company or AIFM that wants a fast route to a MiCA-passportable crypto service line, via Article 60 notification through Finantsinspektsioon or a full CASP authorisation. We file and manage both routes here. See the full Estonia crypto licensing guide.
Choose Cyprus if you are a Cyprus Investment Firm (CIF), an existing Cyprus EMI, or an asset manager that wants a credible EU base with UCITS, AIFMD and MiCA together under a single regulator (CySEC), with non-domicile tax treatment for senior management. We deliver this through our Cyprus team. See the full Cyprus crypto licensing guide.
Consider the UAE if your clients are institutional, sovereign or high-net-worth, and ADGM (FSRA) or DIFC (DFSA) fits your architecture better than an EU base. This sits outside the jurisdictions we license directly; talk to us and we will tell you honestly what we can deliver. See the UAE crypto licensing guide.
Consider Hong Kong if you are an Asia-Pacific bank, securities firm or asset manager already authorised by the HKMA or SFC, and the priority is Asia-Pacific banking and distribution rather than EU passporting. This sits outside the jurisdictions we license directly; we will be candid about what we can deliver here. See the Hong Kong crypto licensing guide.
Setting Up the Entity
For most institutions, no new entity is needed: the crypto perimeter sits inside the existing authorised entity under Article 60 notification or a licence variation. A new entity becomes material only where you need to ring-fence the crypto business for capital or conflicts reasons, where the existing authorisation does not reach the target market, where the existing entity sits outside the EU and EU access requires a MiCA-authorised subsidiary, or where you want a parallel issuance entity for stablecoins or asset-referenced tokens (which under MiCA Article 48 must be an EMI or credit institution). When one is needed, we form it.
Where a new entity is needed, the formation mechanics are jurisdiction-specific (see the table below). For an EMT or ART issuance entity, the company must be either a credit institution (already CRR-authorised) or an EMI under Directive 2009/110/EC; this is MiCA Article 48(1) and is not negotiable.
Substance and management residency are the most underestimated factors. EU competent authorities apply substance tests to the management function under MiCA Article 62: a real registered office, management resident in the jurisdiction, a real MLRO and real operational personnel. A holding-company-only shell will not survive the first information request from Finantsinspektsioon or CySEC. We build the substance properly from the start, with in-country people we work with directly, so the file holds up.
Formation by Jurisdiction
| Jurisdiction | Entity Type | Formation Timeline | Capital at Formation |
|---|---|---|---|
| Estonia | Osaühing (OÜ) | 1 to 3 weeks (faster with e-Residency) | Nominal at formation; CASP capital paid in before the file progresses |
| Cyprus | Private Limited Company | 2 to 4 weeks | Nominal at formation; CASP capital paid in pre-application |
| United Arab Emirates | ADGM SPC / DIFC Co Ltd / Free-Zone Co | 4 to 10 weeks (free-zone) | Capital paid up before licence grant; typically pre-application |
| Hong Kong | Private Limited Company under Cap. 622 | 1 to 3 weeks | Nominal at formation; SFC / HKMA capital paid in pre-application |
The cleaner structure is the operating entity in the licensing jurisdiction, one layer of holding above, and real substance in both places. We set it up that way, rather than parking a shell holding company that the home regulator then pulls into the fit-and-proper perimeter mid-application.
Licensing: Article 60 vs. Full CASP
A regulated financial institution adding crypto-asset services has two paths inside the EU and a third outside it: the MiCA Article 60 simplified notification, the full CASP authorisation under MiCA Title V, and the non-EU equivalent (a variation of an existing UAE FSRA / DFSA permission, an HKMA / SFC uplift in Hong Kong, the FCA cryptoasset gateway in the UK from 30 September 2026, or state-by-state money-transmitter routing in the US). The Article 60 route is the single most important mechanism for an incumbent because it removes the duplicate-authorisation problem crypto-native firms cannot avoid. We work out which path fits your licence, then we prepare and file it and deal with the regulator directly.
MiCA Article 60 simplified notification
Under MiCA Article 60(1), credit institutions, central securities depositories, MiFID investment firms, market operators, electronic-money institutions, UCITS management companies and AIFMs may provide crypto-asset services without a separate CASP authorisation, provided they notify the competent authority that authorised them at least 40 working days before they start. The notification must contain the Article 60(7) package: a programme of operations, internal control and risk-management procedures, evidence of compliance with the relevant Title V operational requirements, and the identity of the persons providing the services. The authority assesses completeness within the 40-day window and may extend by up to 20 working days where the file is incomplete. Filings from 12 March 2025 must use the prescribed Level 2 templates, which we file on as standard.
A structural distinction matters here: a credit institution may provide any of the ten crypto-asset services under a single notification, whereas an investment firm may provide only those equivalent to the MiFID II services for which it is already specifically authorised. We map this before you file, so you do not notify for a service you cannot yet evidence.
The route does not displace MiCA Title V. It is a procedural shortcut, not a back door: the notifying entity still complies with Title V conduct, organisational, custody, segregation and capital provisions. The common mistake is reading the 40-day window as the binding timeline. The load-bearing work is extending your existing MiFID or CRR control stack to absorb on-chain settlement, blockchain-address sanctions screening, custody-key governance and the DORA register entries for crypto-execution and custody providers. That uplift typically runs three to six months in parallel with the file, and we build it for you alongside the notification.
Equivalence mapping: MiFID II to MiCA
MiCA Article 60(2) sets out a direct equivalence between the MiFID II investment services and the MiCA crypto-asset services: reception and transmission, portfolio management, investment advice, execution of orders, placing, and operation of a trading platform each map to their crypto-asset counterpart. The investment firm may provide each crypto-asset service for which it holds the equivalent MiFID authorisation. For services with no MiFID equivalent (custody and administration, exchange of crypto-assets, transfer services), it adds the authorisation through a MiFID variation where the regulator treats it as ancillary, or a separate CASP authorisation where it falls outside the MiFID perimeter. We run that gap analysis for you.
Capital and own funds
For an Article 60 entity, the capital requirement is the higher of the existing sectoral floor (CRR own funds, MiFID initial capital, or EMD2 initial capital) and the MiCA Annex IV class floor for the services provided. Under Article 67(1)(b) the firm must also hold a safeguard equal to one quarter of the preceding year’s fixed overheads where higher; for established credit institutions and Cyprus Investment Firms this fixed-overheads safeguard, not the nominal class floor, is typically the binding constraint. The EBA Opinion of 10 June 2025 confirmed that custody or transfer of e-money tokens is a PSD2 payment service as well as a MiCA service, so the firm complies cumulatively with both regimes. We size the binding floor against your existing licence so you hold the right capital, not more than you need.
MiFID II / MiCA boundary
Crypto-assets that qualify as financial instruments under MiFID II Section C of Annex I remain inside MiFID II and outside MiCA (Article 2(4), Recital 14). A tokenised bond, equity, fund unit or security token is regulated under MiFID II, the Prospectus Regulation and national-law overlays, with the EU DLT Pilot Regime (Regulation (EU) 2022/858) providing a parallel sandbox for DLT market infrastructures. Firms adding tokenised securities are doing MiFID business with a DLT settlement layer, so the route is a MiFID variation rather than a CASP authorisation. We classify each product so it is filed against the correct perimeter.
Reverse solicitation under MiCA Article 61
A third-country firm may serve EU clients at the exclusive initiative of the client without MiCA authorisation, but the carve-out is narrow. ESMA’s Guidelines (applicable from 27 April 2025) treat targeted advertising, EU-language websites, country-code TLDs, EU event sponsorship and affiliate programmes directing EU traffic as triggers that defeat it, and confine any ongoing relationship to the same service type initially solicited. A firm that wants a continuing EU client relationship cannot rely on reverse solicitation; it needs an EU subsidiary or an Article 60 notification through an EU-authorised group entity, which we deliver. We do not act for US persons as service clients.
Non-EU pathways (reference)
We license directly inside the EU. The regimes below are included so you can see the full perimeter; where the right answer is one of them, we will tell you honestly what we can deliver.
- United Kingdom. Transitioning from the FCA registration regime to a full regulated-activities regime under SI 2026/102. The authorisation gateway opens on 30 September 2026 and the regime commences fully on 25 October 2027; UK banks will need an additional Part 4A FSMA permission.
- United States. A federal-state matrix reshaped by the GENIUS Act of 18 July 2025. State money-transmitter licences remain required in most states for non-bank transfer services. We do not act for US persons as service clients; this is reference only.
- United Arab Emirates. Three regulators in parallel: VARA (Dubai retail), ADGM FSRA and DIFC DFSA. Institutional firms typically route through ADGM or DIFC; a retail exchange routes through VARA.
- Hong Kong. The SFC supervises VATP and tokenised-securities activity; the HKMA supervises stablecoin issuance and Authorised-Institution banking under the Stablecoin Issuer Ordinance (in force 1 August 2025).
Crypto-Fiat Banking
Banking is rarely the binding constraint for an incumbent the way it is for a crypto-native start-up. You already hold correspondent banking, treasury operations and SEPA / SWIFT access for your existing book. The crypto-specific question is narrower: where the crypto-fiat conversion sits, which segregated client-money account holds the fiat leg of crypto-asset trades, and which institution clears the on-ramp and off-ramp flows. Arranging this is a core service for us, and we build it into the plan alongside the formation and licensing work.
The conversion question is operational, not regulatory. MiCA Title V requires the firm to segregate client crypto-assets and client funds but does not prescribe the banking architecture. The standard model uses three accounts: a segregated client-money account, a treasury account for the firm’s own balances, and a flow account for the conversion leg. For an existing bank or EMI all three sit inside the institution; a MiFID investment firm, UCITS management company or AIFM without internal banking capability holds them at one or more credit institutions or EMIs that onboard crypto business.
Not every existing correspondent will tolerate crypto-flows on the wire, and may impose new monitoring conditions, restrict settlement volumes or withdraw. Where you need a new crypto-fiat relationship, we arrange it through licensed EU credit institutions and EMIs that onboard institutional crypto business, matched to your services, client geography and existing correspondent footprint. We never name a bank publicly and we never offload you to an unverified intermediary.
Ongoing Compliance
Compliance is where the gap between a crypto-native firm and an incumbent narrows fastest. You already run MiFID II conduct and conflicts frameworks, MAR surveillance, AML transaction monitoring and ICT-risk governance. Adding crypto-asset services extends each into a new asset class rather than building from zero, but the extension is non-trivial: most systems were calibrated for cash equities, fixed income, FX and derivatives, and you have to add the parametrisation for crypto-asset volatility, on-chain flow-tracing, sanctions screening against blockchain addresses and DLT-specific operational risk. We build that into your existing stack across four workstreams.
Dual conduct and market-abuse
An Article 60 firm runs MiFID II and MiCA Title V conduct rules in parallel and applies the more stringent where they diverge. The MiCA overlay covers fair treatment of clients (Article 66), conflicts (Article 72), outsourcing (Article 73) and white-paper compliance (Title II). A trading-venue operator extending into crypto runs a single market-abuse surveillance function catching both MAR and MiCA Title VI.
DORA
The Digital Operational Resilience Act has applied since 17 January 2025. An incumbent already in scope extends three components to crypto: the ICT third-party risk register (crypto-asset providers, custody-technology providers, DLT dependencies), the resilience testing programme, and the major ICT-incident reporting framework. The architecture is the same; the scope expands. We deliver that extension.
AML and the Transfer of Funds Regulation
The recast Transfer of Funds Regulation has applied to crypto-asset service providers since 30 December 2024, requiring originator and beneficiary information on every transfer with no de-minimis threshold; for an existing bank or EMI this extends your wire-transfer infrastructure to the crypto rail. The AML Regulation (Regulation (EU) 2024/1624) applies in full from 10 July 2027. We integrate the Travel Rule and the AMLR uplift into your existing AML stack.
Conflicts of interest and segregation
MiCA Article 72, read with MiFID II Article 23, requires CASPs to identify, manage and disclose conflicts. For an incumbent running crypto alongside an existing investment book, the framework must address cross-trading between crypto and non-crypto assets, internalisation of client orders, proprietary trading in crypto the firm also recommends, and the custodian-versus-exchange-counterparty conflict. Segregation runs through functional separation, information barriers and, where needed, a sister entity or sub-licensed subsidiary. We design the framework with you.
Realistic Timeline
The realistic end-to-end timeline runs from four months (an Article 60 notification through an existing EU-authorised entity) to eighteen months (a full CASP authorisation in a new subsidiary, or a non-EU regime with no existing footprint). The notification path is procedurally compressed; the authorisation path is not. Either way, the load-bearing work is the operational and compliance overlay running in parallel, not the regulatory file. We give you a firm timeline for your specific authorisation at the consultation.
Timeline by Phase
| Phase | Timeline | What we do |
|---|---|---|
| Routing & scoping | 2 to 6 weeks | We scope the Article 60 vs. full CASP decision, run the MiFID equivalence mapping under MiCA Article 60(2), assess conflicts of interest and gap-test against your existing authorisation perimeter. |
| Entity & jurisdictional structuring | 4 to 12 weeks | Where a new subsidiary is needed, we form it; where the Article 60 notification sits inside the existing entity, this step does not apply. |
| Notification or authorisation | 40 working days (notification) to 12 months (full CASP) | We draft and file the MiCA Article 60(7) package, programme of operations, internal-control description, white papers where applicable, fit-and-proper documentation and IT/security policies, and we deal with the regulator directly. |
| Crypto-fiat banking extension | 1 to 3 months | We extend your existing relationship to the crypto perimeter, or arrange a new account with a licensed EU credit institution or EMI where a separate institution is required. |
| Custody & technology integration | 3 to 9 months | Driven by self-custody build versus sub-custody routing. Self-custody needs HSM infrastructure, key-management procedures and operational personnel; sub-custody routes the obligation to a qualified custodian but you retain MiCA Title V responsibility. |
| Compliance & operational overlay | 3 to 9 months (parallel) | We extend your DORA, AML, MAR-equivalent and conflicts frameworks to crypto, including blockchain-analytics tooling, on-chain sanctions screening and Travel-Rule data exchange. |
| Go-live, training & first transaction | 2 to 6 weeks | Staff training, client onboarding-flow testing, a parallel run with your existing book, and the regulatory go-live notification where required. |
| Total: Article 60 notification through existing EU entity | 4 to 9 months | Compressed path for an EU-authorised incumbent. |
| Total: Full CASP authorisation in new EU subsidiary | 9 to 18 months | Full authorisation path where a new vehicle is required. |
The single most important architectural decision is the custody choice. Self-custody with on-chain settlement carries a much heavier integration burden than sub-custody to a qualified custodian with the crypto-asset book treated as a settlement layer on external infrastructure. MiCA Article 75 permits both; the choice is strategic, and we make it with you. For a route tailored to your existing licence and target services, book a free consultation.
Frequently Asked Questions
Does my bank or investment firm need a separate CASP authorisation to provide crypto-asset services in the EU?
In most cases, no. Under MiCA Article 60(1), credit institutions, central securities depositories, MiFID investment firms, market operators, electronic-money institutions, UCITS management companies and alternative investment fund managers may provide crypto-asset services without a separate CASP authorisation, provided they notify the competent authority that authorised them at least 40 working days before providing the services. The notification must contain the information set out in Article 60(7): a programme of operations, internal control mechanisms, risk-management procedures, evidence of compliance with the relevant Title V operational requirements, and the identity of the persons providing the services. The notification route does not displace MiCA Title V conduct, organisational, custody and capital obligations; these continue to apply. We prepare and file this notification for you and manage it through to clearance.
Can I passport crypto-asset services across the EEA under MiCA?
Yes. MiCA passporting works the same way for the simplified notification route under Article 60 and for the full CASP authorisation route under Title V. Once notified or authorised by the home Member State, the entity passports across the EEA under MiCA Article 65 by notification to the home competent authority, which transmits the notification to the host Member State. The passport covers each crypto-asset service for which the entity is notified or authorised. The host Member State may not require additional authorisation but may impose host-state conduct rules in limited circumstances. For an investment firm already passporting under MiFID II, the MiCA passport is an extension of the existing notification infrastructure rather than a new mechanism.
Can a US bank or asset manager rely on reverse solicitation to serve EU clients?
Only narrowly. MiCA Article 61(1) permits a third-country firm to provide crypto-asset services to clients established in the EU at the exclusive initiative of the client. ESMA guidelines confirm that any solicitation, marketing, advertising or active outreach to EU clients defeats the carve-out, and that ongoing relationships entered into at the client’s initiative stay inside it only for the same type of service initially solicited. For a firm that wants a continuing crypto-asset service relationship with EU clients, reverse solicitation is not a viable route. The realistic alternatives are an EU subsidiary with a full CASP authorisation, or an Article 60 notification through an EU-authorised entity in the group. We do not act for US persons as service clients; this is general guidance only.
What happens if I already hold an EMI licence and I want to issue an e-money token?
Under MiCA Article 48(1), only credit institutions and electronic-money institutions may issue e-money tokens; Article 48(2) provides that e-money tokens are deemed to be electronic money. An existing EMI may issue EMTs subject to the MiCA Article 51 white-paper notification (the white paper is notified to the home regulator, not approved), MiCA Article 48 obligations including reserve requirements, and the cumulative PSD2 capital overlay confirmed by the EBA Opinion of 10 June 2025. For an incumbent EMI the route is faster than for a non-EMI, but the dual MiCA / PSD2 compliance overlay is not trivial. We build and file it for you, and we plan for the operational and capital work up front. See the full EMI and payment institution licensing guide for the underlying authorisation framework.
How long does an Article 60 notification take in practice?
The procedural minimum is 40 working days from the date the competent authority confirms the notification complete, extendable by up to 20 working days under Article 60(8) where the file is incomplete. The notification phase alone typically sits in the eight to fourteen-week range, and the realistic end-to-end timeline from project start to go-live is four to nine months when the notification sits inside an existing EU-authorised entity. The variable that most determines the timeline is the operational and compliance overlay, not the regulatory file itself. Book a free consultation and we will give you a timeline for your specific authorisation.
Add Crypto-Asset Services to Your Firm
Book a free consultation with Tomberg & Partners. We weigh the Article 60 notification, the full CASP authorisation and the non-EU routes against your existing authorisation, then file and manage the one we recommend, deal with the regulator directly, and stand behind the outcome.
Initial consultations are free · Response within 24 hours
Banking & Payments A company and a licence still need a bank account
Banking is one of our three core services. We help high-risk and regulated businesses open the bank and payment accounts that others refuse: we work directly with EU EMIs, payment institutions and crypto-aware banks, confirm appetite before you apply, and make the introduction. Take it with your company and licence, or on its own.
Related Services
- Crypto Licensing Overview: MiCA CASP authorisation and Article 60 notification, filed and managed
- Company Formation: entity formation across our serviced jurisdictions where a new vehicle is needed
- Crypto & Fiat Settlement: crypto-fiat rails arranged through licensed EU institutions