Guide · Crypto

MiCA Licence Renewal in Europe: Keeping a CASP (2026)

MiCA renewal is not a re-application, it is continuous compliance: the CASP obligations, capital, DORA and AML reporting you must hold all year.

Contents

Getting a crypto licence is the milestone everyone talks about. Keeping it is the part that quietly ends businesses. Under MiCA, a CASP authorisation isn’t a certificate you frame and forget — it’s a standing set of obligations under continuous supervision, and in our experience most operators budget for the application and nothing for what comes after. The result is avoidable: capital that drifts below the minimum, reports filed late, a DORA gap flagged at review. Here’s what it actually takes to keep an EU crypto licence live in 2026.

Key takeaways
  • A MiCA CASP doesn’t expire like an offshore permit — it continues only while you keep meeting the conditions and reporting.
  • Ongoing obligations: maintain capital, run an active AML/MLRO function, DORA resilience, client-asset segregation and periodic reporting.
  • Withdrawals usually come from capital shortfalls, AML/reporting failures, unnotified changes, or DORA gaps — nearly all avoidable.
  • Old national VASP registrations must be converted to a CASP before your member state’s transition window closes, or you lose the right to operate.

”Renewal” under MiCA means continuous compliance

The word “renewal” is slightly misleading for an EU licence. Unlike an offshore VASP permit that you re-pay annually, a MiCA CASP authorisation continues indefinitely — as long as you keep satisfying the conditions on which it was granted. There’s no expiry date to renew against; instead there’s a standing supervisory relationship. Your “renewal” is really the ongoing discipline of staying compliant, reporting on schedule, and keeping the regulator informed. Fail that, and the authorisation can be conditioned, suspended or withdrawn — which is functionally worse than an expiry, because it’s on the record.

MiCA licence renewal: triggers, timeline and the 1 July 2026 deadline

Because a CASP authorisation has no expiry date, “MiCA licence renewal” isn’t a form you file on a fixed anniversary — it’s a set of triggers that force regulatory action, on their own timelines. These are the ones that matter:

Renewal trigger Timeline What it forces
Transitional-period expiry (legacy VASPs) 1 July 2026 — hard deadline Convert the national registration to a CASP authorisation or stop serving EU clients
Change of control / new shareholder Notify before the change takes effect Regulator re-assesses suitability; can object
New crypto-asset service added Extension-of-authorisation filing, assessed within ~40 working days Scope of the authorisation is widened before you offer the service
Annual & prudential reporting Periodic (at least annually) Own-funds, AML and safeguarding evidence filed on schedule
Capital falling below the minimum Immediate — reportable breach Remediation plan, or suspension/withdrawal

The deadline everyone should have circled is 1 July 2026. MiCA’s Article 143 let each member state grant legacy providers a transitional (“grandfathering”) window of up to 18 months, running from 30 December 2024 — so the outer boundary is 1 July 2026, and no member state may extend grandfathering beyond it. Several states set shorter windows: Germany and France, among others, closed theirs earlier. If you were relying on a pre-MiCA national VASP registration, that window is the one true “renewal” clock in the whole regime — miss it and there is no lapse-and-reapply grace, you simply lose the right to serve EU clients until a fresh CASP authorisation issues.

Everything else on that list is continuous rather than dated: you keep the authorisation live by hitting the reporting calendar, notifying material changes before they happen, and never letting own funds drift below the class minimum. Treat those as the real renewal work — the section below is what that maintenance looks like in practice.

The 2026 picture: the transition closed, supervision has begun

For most of MiCA’s rollout, the conversation was about getting in. That phase is over. The transitional period for legacy national VASP registrations closed on 1 July 2026 with no extension, and by late July more than 300 CASPs were authorised across the EU/EEA, licensed by national regulators and passporting across the bloc. The centre of gravity has shifted from application to supervision — which is exactly where MiCA licence renewal lives.

That matters because a large, freshly-authorised population is now entering its first full supervisory cycle at the same time. First annual reports, first prudential filings, first DORA testing evidence, first change-of-control notifications — all landing on regulators who now have a register to police rather than a queue to process. The scrutiny that felt light during a rush of authorisations tends to sharpen once the register stabilises. In other words: keeping the licence is about to get harder to fake than getting it was.

There is no EU-wide “renewal fee” — but the recurring cost is real.

MiCA doesn’t set a periodic renewal charge you pay to keep a CASP alive. What you do carry are national supervisory and annual fees, set by your home-state regulator and varying by member state and firm size, plus the standing cost of the compliance function itself — MLRO, audit, DORA testing and reporting. Budget for the operating cost of authorisation, not a licence-renewal invoice; the firms that get caught out are the ones that priced only the application.

What you must maintain, continuously

The standing obligations

To keep a CASP in good standing you must maintain: minimum own funds (€50k–€150k by service class) at all times; a functioning AML/CFT programme with an active MLRO and ongoing monitoring; DORA ICT and operational-resilience controls; client-asset segregation and safekeeping; periodic regulatory and financial reporting; and prompt notification of material changes — change of control, new services, or key-personnel moves. Supervision is continuous, so compliance has to be too.

Capital is the one that catches operators out most often: it’s not a one-time deposit at licensing but a floor you must stay above every day, in qualifying own funds. The three CASP capital classes set the level, and dipping below — after a bad quarter, a large withdrawal, or an FX move — is a reportable breach.

Why licences get withdrawn — and how to avoid it

The reasons regulators withdraw or condition a crypto authorisation are consistent and, almost always, preventable:

  • Capital shortfalls — own funds slipping below the minimum without a remediation plan.
  • AML and reporting failures — a dormant MLRO function, late filings, weak monitoring.
  • Unnotified changes — a new shareholder, service or business model the regulator learns about after the fact.
  • DORA and resilience gaps — inadequate ICT risk management, untested incident response, or unmanaged third-party providers.

Each of these is a governance problem, not a legal one — which is why the fix is an ongoing-compliance function that owns capital monitoring, the reporting calendar, and regulator correspondence, rather than a one-off application team that moves on after issuance.

Don’t let an old national registration lapse into nothing

There’s a related trap specific to 2026: operators who hold an old national VASP registration and assume it will keep working. Inside the EU it won’t — the national regimes are being replaced by MiCA, and each member state’s transition window is closing. If you don’t convert to a CASP authorisation before your window ends, you lose the right to operate entirely. Our MiCA explainer and VASP vs CASP guide cover the conversion; the point here is simply: don’t wait for it to expire.

For the gaming side of the same job — annual fees by jurisdiction, what regulators ask for at renewal and the four failure modes that make licences lapse — see our licence renewal service.

We keep licences live, not just win them

We provide ongoing compliance and renewal support for CASP authorisations obtained anywhere — Lithuania, Estonia, Malta, Bulgaria and across the EU. That means maintaining capital and reporting, running the MLRO/AML function, keeping DORA and policies current, and handling change-of-control filings and regulator correspondence, so your authorisation stays in good standing long after launch. If you hold a licence that needs a steadier hand — or an old registration that needs converting — book a free consultation and we’ll take it on end to end.

Frequently asked questions

Does a MiCA CASP licence need to be renewed?

A CASP authorisation doesn't 'expire' the way an offshore permit does — it continues so long as you keep meeting the conditions and your ongoing obligations. In practice that means continuous compliance: maintaining capital, filing AML and prudential reports, notifying the regulator of material changes, and passing supervision. Miss those and the authorisation can be suspended or withdrawn.

What are the ongoing obligations to keep a CASP?

Maintaining minimum own funds (€50k–€150k by class), a functioning AML/CFT programme with an active MLRO, DORA-compliant ICT resilience, client-asset segregation, periodic regulatory and financial reporting, and prompt notification of any change of control, service or key personnel. Supervision is continuous, not a one-off.

Why do crypto licences get withdrawn in the EU?

The common causes are capital falling below the minimum, AML/reporting failures, unnotified changes of control or business model, and — increasingly — DORA and operational-resilience gaps. Regulators can impose conditions, suspend, or withdraw authorisation. Most withdrawals are avoidable with a proper ongoing-compliance function.

What happens if my old national VASP registration lapses?

Inside the EU the old national VASP regimes are being replaced by MiCA. If you relied on a national registration and haven't converted to a CASP authorisation before your member state's transition window closes, you lose the right to operate. The fix is to apply for the CASP now rather than let the national permit run out.

Can you take over compliance for an existing licence?

Yes. We provide ongoing compliance and renewal support — maintaining capital and reporting, running the MLRO/AML function, keeping DORA and policies current, and handling change-of-control and regulator correspondence — so an authorisation obtained anywhere stays live and in good standing.

Sources

Christina S.
Crypto Licensing · Vantegris

Part of the Vantegris desk that runs these licences end to end — writing from live applications across 40+ jurisdictions, not recycled marketing. Reviewed by Vladyslav S. (Compliance & Legal).

Related service All crypto licences →

This article is for general informational purposes only and is not legal, tax or financial advice. Consult a qualified professional before acting.

Share
TG X In WA Reddit Mail

Skip the reading

Talk to a specialist.

We'll map the fastest route to a licensed, banked, live operation.

Book a free consultation →

Get the cheatsheet

Stay ahead of the rules.

Licensing regimes shift fast. Get Vantegris updates and our 2026 licence cost & comparison cheatsheet — straight to your inbox, no noise.

No spam · unsubscribe anytime

Licence, done right.

300+ licences obtained across 40+ jurisdictions. Book a free consultation.

Book a free consultation