Regulations

BaFin Under MiCA: The Licensing Route for Crypto Firms in Germany

MiCA timelines, BaFin’s role, and CASP authorization in Germany. Capital thresholds, passporting, stablecoin paths, and practical steps firms are taking now.

BaFin Under MiCA: The Licensing Route for Crypto Firms in Germany

Picture a Berlin exchange that spent years earning BaFin’s crypto custody licence. December comes, MiCA’s CASP rules switch on across the EU, and suddenly that hard-won German badge needs to morph into an EU passport. The board wants France and Italy on the roadmap. Compliance wants clarity on what BaFin will actually accept on day one.

That’s where the real work begins. Under MiCA, the license shifts from national nuance to a single EU template, but the first draft is still written at home. In Germany, that means BaFin. If you plan to serve EU clients from Germany, here’s what your licensing route really looks like.

MiCA creates one authorization for crypto-asset service providers, or CASPs, that works across the EU. Parts of MiCA already apply, like the stablecoin sections, and the remainder covers the full stack of services from custody to operating trading platforms. BaFin is Germany’s gatekeeper for firms based in the country, and once you’re in, you can passport across the bloc.

National flavor meets EU uniformity: MiCA harmonizes the license, but day-to-day supervision and first authorization still run through your home regulator.

The changes touch almost everyone building in Germany. Custody firms that were licensed under the German Banking Act, trading venues that relied on bespoke setups, payment and brokerage models that skirted edges. Now there’s a common vocabulary and a common bar. ESMA and the EBA are layering detailed standards, while BaFin maps Germany’s pre-MiCA categories to CASP permissions and stablecoin paths.

If you want the source texts: the MiCA regulation is on the EU’s legal database EUR-Lex. ESMA has guidance and technical standards in progress on authorization, complaints, conflicts, and market integrity ESMA. BaFin’s MiCA explainer and German specifics sit on its official site BaFin.

From Germany’s crypto custody licence to MiCA CASP

Germany has been out in front on licensing since 2020, when crypto custody got folded into the German Banking Act as a regulated activity. That helped establish governance, AML, and IT expectations early. But MiCA redraws the map. You no longer combine bits of banking, investment, and custody law to assemble a crypto stack. You apply for defined CASP services.

Mapping the old to the new

Here’s how common activities line up conceptually. Your lawyers will do a detailed scoping, but at a high level this is the translation you’ll end up arguing over in your application pack.

Business activity Pre-MiCA in Germany MiCA category Lead supervisor
Custody of client crypto-assets Crypto custody under KWG licence Custody and administration of crypto-assets on behalf of clients BaFin (home), passportable EU-wide
Operating a crypto trading platform Varied setups, often outside MiFID venue perimeter Operation of a trading platform for crypto-assets BaFin; market integrity rules under MiCA
Exchange crypto-assets for funds or other crypto-assets Payment or brokerage constructs Exchange services (fiat-crypto and crypto-crypto) BaFin; AML and Travel Rule apply
Execution of client orders Investment services analogies Execution of orders for crypto-assets BaFin
Placing or advice on crypto-assets MiFID-adjacent models Placing; advice on crypto-assets BaFin
Issuing or offering a non-stablecoin token Prospectus-lite marketing Crypto-asset whitepaper regime BaFin notification; no prior approval required
Issuing an ART or EMT E-money and hybrid structures Asset-referenced tokens and e-money tokens BaFin, with EBA if token is significant

Two quick notes. First, staking and validator services can touch several buckets depending on design. Treat them as a scoping exercise, not a one-liner. Second, proprietary trading for own account sits outside MiCA’s CASP list but can trip other regimes. If in doubt, ask BaFin in writing.

What a German CASP application actually looks like

MiCA set the baseline. Germany adds its culture of detail. Expect a deep dive on governance, IT, and client asset protection. The legislation uses simple labels, but the file you submit doesn’t look simple at all.

Governance, people, and control

Senior managers must be fit and proper, with clear responsibilities and time commitments. BaFin wants a board that can challenge management, not a rubber stamp. Expect to document committees, escalation paths, and how you identify and manage conflicts of interest. If key functions sit abroad, explain how oversight actually works in practice.

Own funds and prudential cover

MiCA sets initial capital thresholds that vary by service. In plain terms, lighter services are at the lower end and trading platform or exchange activities sit at the top end. You can supplement own funds with professional indemnity insurance where the regulation allows, but the overall buffer has to make sense for your scale and risk profile. Assume BaFin will stress test your assumptions.

Safeguarding and wallet operations

This is always a focal point. You’ll need segregation of client assets, robust key management, documented recovery and reconstitution procedures, and a clean audit trail. If you use third-party wallet tech or cloud, bring a full vendor risk pack. The Digital Operational Resilience Act, or DORA, applies to in-scope financial entities and has real teeth on ICT risk and critical third parties. Build your CASP file with DORA in mind from the start.

Market integrity and surveillance

Trading platforms must monitor for abuse and disorderly trading. You’ll be expected to show surveillance tooling, alert governance, and incident reporting procedures. ESMA’s work on market integrity under MiCA gives a sense of what “good” looks like here ESMA.

AML and the Travel Rule

CASPs remain squarely under EU AML rules. The revised Transfer of Funds Regulation extends the Travel Rule to crypto transfers across the EU, which means originator and beneficiary information has to move with the transaction. BaFin will expect your Travel Rule vendor and procedures to be live, not theoretical, at authorization.

Outsourcing and third parties

Germany treats outsourcing as a governance topic, not a procurement one. Any critical or important function needs a contract with audit rights, exit plans, and continuous oversight. If a critical vendor sits outside the EU, be ready to explain data flows, sub-outsourcing, and incident playbooks in detail.

The application flow in practice

  1. Scope your services against MiCA’s CASP list and confirm which entity will apply in Germany.
  2. Engage BaFin early with a written scoping query if your model hits gray areas.
  3. Draft core policies: governance, risk, AML, safeguarding, ICT and DORA alignment, outsourcing, complaints handling, and market abuse where relevant.
  4. Build the people file: fit and proper evidence, org charts, role descriptions, and time commitments.
  5. Assemble financials: capital, liquidity where applicable, insurance coverage, and realistic revenue projections.
  6. Map and test your Travel Rule implementation end to end, including counterparty screening.
  7. Submit the application and respond quickly to BaFin’s follow-up questions. Keep a clean log of changes.

BaFin has published MiCA-focused resources and will point to the primary EU text for definitions. Start there, then tailor to German expectations BaFin, EUR-Lex.

Passporting and day-two operations

Authorization in Germany is your home base. Passporting lets you serve clients across the EU without separate licenses in each country. There’s a notification step to your home regulator and to ESMA and the host authorities, and then you can operate cross border or establish branches. Marketing rules travel with you, so check that your materials and disclosures meet MiCA standards in every language you use.

Reverse solicitation, the fine print

MiCA preserves a narrow reverse solicitation concept. It’s not a marketing strategy. Document your controls so sales and partnerships do not accidentally turn into active solicitation in countries you haven’t notified yet.

Timelines that actually matter

MiCA rolled out in stages. The dates below help teams plan product sequencing and compliance delivery. Treat them as anchors and confirm the current status on the primary sources.

Milestone What changed
MiCA published in EU Official Journal (2023) Regulation enters into force on a phased basis EUR-Lex
Stablecoin sections apply (2024) ART and EMT issuance rules activate; EBA begins significant token framework EBA
CASP regime applies EU-wide (late 2024) Authorization requirements for service providers begin; passporting framework starts ESMA
Transitional window for existing national permissions Member states can allow a limited transition period for firms under national regimes; check BaFin’s implementation note BaFin

The headline point is simple. If you want Europe, plan your passport on the same timeline as your authorization. Waiting until after go-live is how launch dates slip into the next quarter.

BaFin under MiCA — Track Switch Decision

Stablecoins through the German lens

Stablecoins are not one bucket under MiCA. There are asset-referenced tokens, ARTs, that peg to baskets or non-euro assets. Then there are e-money tokens, EMTs, that reference a single fiat currency, like the euro. The rules are different, and so are the authorizations.

EMTs usually mean e-money permissions

If you want to issue a euro EMT, you generally need to be a credit institution or an e-money institution under existing EU money rules, and then meet MiCA overlays on reserves, redemption, and governance. That often sends crypto-native teams into partnerships with e-money institutions or banks. Germany’s banks are watching this space closely.

ARTs and EBA oversight

ART issuers need authorization and a whitepaper approved by the home NCA. If your token becomes significant, the EBA steps in with additional standards, fees, and direct oversight, while BaFin remains your home authority. The EBA maintains a hub for MiCA-related standards and lists that’s worth bookmarking EBA.

Practical design choices

A few design calls simplify your German filing. Keep reserves conservative and simple. Build daily reconciliation and independent valuation into the operating model. Make redemption channels boring and reliable. And assume marketing claims will be read against the risk factors in your whitepaper.

What firms are running into now

Across the EU, people are discovering that the same MiCA text lands a little differently at each regulator. Germany is no exception, but its expectations are usually well documented and consistent. The sticky points show up in three places.

Service scoping at the edges

Hybrid models blur lines. Custody plus staking, brokerage plus platform features, wallet tech bundled with data services. Get these mapped early and get something in writing. It’s cheaper than reworking your stack a month before authorization.

ICT and operational resilience

DORA is not an afterthought. If your business runs on cloud, key management services, and external wallets, you’ll need to show layered controls and exit strategies. Expect BaFin to ask how you recover keys and reconstitute records after a severe incident, and how you monitor critical third parties in real time.

Travel Rule and counterparty frictions

The Travel Rule only works if both sides speak the same language. In practice, you’ll be dealing with different vendors, different data models, and inconsistent envelope handling. Build reconciliation and exception workflows that are visible to compliance, not buried in engineering tools.

Risks & what could go wrong

  • Backlog risk: national authorities face a surge of applications. Timelines stretch and product launches slip.
  • Scope creep: a small feature turns your service into a higher-risk CASP category with bigger capital and controls.
  • Vendor concentration: DORA highlights critical third parties. Over-reliance on a single wallet or cloud provider becomes a supervisory red flag.
  • Stablecoin flight risk: redemption mechanics that work in calm markets may break under stress without robust liquidity planning.
  • AML mismatches: Travel Rule data gaps with counterparties cause transfer delays and user frustration.
  • Marketing exposure: cross-border ads that miss MiCA disclosures can trigger action by host regulators even if your home license is clean.
  • Transitional misreads: assuming national permissions cover you longer than they do leads to unlicensed activity in the gap.

Build your authorization like you expect questions, then leave yourself time to answer them. The risk is rarely outright rejection. It’s delay.

Frequently Asked Questions

Do existing BaFin crypto custody license holders automatically become CASPs under MiCA?

No. MiCA is a separate EU regime. Some member states allow a limited transitional period for nationally authorized firms, but you still need to apply for CASP authorization to operate under MiCA long term. Check BaFin’s implementation notes for Germany-specific timelines BaFin.

What capital do we need for a German CASP authorization?

MiCA sets initial capital bands that depend on the services you choose. Lighter advisory or order transmission sits at the lower end, with custody and trading platform activities higher. Expect BaFin to assess the adequacy of your own funds and, where applicable, professional indemnity insurance against your specific risk profile.

How long does authorization take with BaFin?

There’s no guaranteed timeline. EU rules define steps and clocks once the application is deemed complete, but the reality depends on how complex your model is, how quickly you respond to questions, and regulator workload. Start early and budget time for at least one round of clarifications.

Can a non-EU firm serve German clients without a German or EU license under MiCA?

Only in very narrow reverse solicitation scenarios, where the client initiates the service without any prior marketing. If you actively target clients in Germany or elsewhere in the EU, you need an authorization and, if relevant, passport notifications.

Are NFTs covered by MiCA in Germany?

MiCA largely excludes unique, non-fungible tokens, but if tokens marketed as NFTs are in fact fractionalized or sold in large series with similar features, parts of MiCA may still apply. Treat NFT models as a scoping exercise and document the analysis for BaFin.

What happens if our euro stablecoin becomes “significant”?

Significance triggers extra obligations and oversight by the EBA, alongside your home authority. Expect higher reporting, potential capital add-ons, and tighter risk management rules. The EBA maintains the criteria and related standards on its public hub EBA.

What does passporting from Germany actually involve?

You notify BaFin with the services and countries you plan to cover. BaFin forwards the information to ESMA and host regulators. After the notification takes effect, you can provide those services cross border or set up a branch. Keep your marketing and disclosures aligned with MiCA in each target market.

Investment Disclaimer

Share this story

X LinkedIn

Related Stories