What Is a Crypto-Asset Service Provider (CASP)?

기술적 분석 교육적인
What Is a Crypto-Asset Service Provider (CASP)?

As digital asset adoption accelerates, regulators are moving from guidance to enforcement. In the European Union, that shift runs through a single term: crypto-asset service provider, or CASP. Under the Markets in Crypto-Assets Regulation (MiCA), any business offering crypto exchange, custody, trading, or advisory services to EU clients now falls under this classification, and with it, a defined set of licensing, AML, and operational obligations. In addition to CASP, MiCA also regulates token issuers — more specifically, issuers of asset-referenced tokens (ART), e-money tokens (EMT), and crypto-assets other than ART or EMT. As for other regulatory frameworks, issuers of tokens are treated separately, and MiCA takes a similar approach by addressing CASP requirements in dedicated sections (“TITLEs”) and Articles.

For exchanges, wallet providers, and trading platforms operating in or expanding into the EU, understanding CASP status isn't optional. It determines whether a business can legally operate, what it must disclose, and what security and compliance infrastructure it needs in place before launch.

CASP Definition Under MiCA

Article 3(1)(15) of MiCA defines a crypto-asset service provider as "A legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis, and that is allowed to provide crypto-asset services in accordance with “Article 59” (of MiCA).

In practice, this covers any business conducting the advice, exchange, transfer, or custody of crypto assets — including Bitcoin, stablecoins, and other digital tokens — on a professional basis. CASPs are the licensed intermediaries connecting users, institutions, and blockchain infrastructure within the EU's regulatory perimeter.

Which Activities Qualify a Business as a CASP?

MiCA defines "crypto-asset service" directly in Article 3(1)(16), and a business performing any one of the following on a professional basis is classified as a CASP:

(16) 'crypto-asset service' means any of the following services and activities relating to any crypto-asset:

  • (a) providing custody and administration of crypto-assets on behalf of clients;
  • (b) operation of a trading platform for crypto-assets;
  • (c) exchange of crypto-assets for funds;
  • (d) exchange of crypto-assets for other crypto-assets;
  • (e) execution of orders for crypto-assets on behalf of clients;
  • (f) placing of crypto-assets;
  • (g) reception and transmission of orders for crypto-assets on behalf of clients;
  • (h) providing advice on crypto-assets;
  • (i) providing portfolio management on crypto-assets;
  • (j) providing transfer services for crypto-assets on behalf of clients.

From MiCA, Article 3(1)(16).

Each of these ten activities brings CASPs closer to the compliance standards long applied to traditional financial institutions and each carries its own licensing and disclosure requirements.

What MiCA Requires of CASPs

MiCA is the EU's first comprehensive legal framework for crypto assets, built around four core objectives:

  1. Consumer protection: Standardized disclosures, including white papers, before a client engages with an issuer or provider.
  2. Market integrity: Safeguards against conflicts of interest, market manipulation, and fraud.
  3. Financial stability: Bringing crypto markets under established financial supervision.
  4. AML/CFT alignment: Compliance with FATF guidelines on money laundering and terrorist financing.

Every CASP must register with a competent national authority before offering services in any EU jurisdiction. Once authorized, a CASP can passport its license across all EU Member States — a single approval unlocking the full EU market, provided compliance is maintained in every jurisdiction it operates in.

AML and Cybersecurity Obligations for CASPs

MiCA's AML obligations for CASPs are formalized versions of the FATF Recommendations, the international standard most global crypto regulation traces back to. To maintain CASP status, a business must sustain:

  • Risk-based approach (RBA): FATF Recommendation 1. Entities should take a risk-based approach, based on their industry, customers, and transaction characteristics, when applying AML controls.
  • Customer due diligence (CDD): FATF Recommendation 10. Entities must identify and verify customer identities, evaluate their risk profile, and conduct ongoing monitoring, especially for Politically Exposed Persons.
  • Suspicious transaction reporting (STR): FATF Recommendation 20. Transactions must be monitored, and suspicious money laundering or terrorist financing activity must be reported to national authorities.
  • Travel Rule: FATF Recommendation 16. Information on the sender and beneficiary of a transaction must be shared between the entities involved, to ensure transparency and facilitate law enforcement.
  • Additional requirements: FATF Recommendations 11 and 18. Other requirements commonly adopted include record keeping (Recommendation 11) and internal programs, training, and audits (Recommendation 18).

This is where the line between compliance and security stops being a line at all. A CASP that can demonstrate AML controls but hasn't independently verified its smart contracts, custody infrastructure, or API surface is exposed on the side regulators increasingly treat as inseparable from compliance.

How CertiK Helps CASPs Meet MiCA Obligations

Security assurance is now a functional requirement of CASP compliance. CertiK works with exchanges, wallet providers, and established financial entities operating under MiCA to close that gap, including:

  • Smart contract auditing for platforms handling custody, trading, or asset transfer.
  • Penetration testing and API security assessments to identify exploitable weaknesses before regulators or attackers do.
  • Formal verification to mathematically validate the correctness of core blockchain infrastructure.
  • Continuous on-chain monitoring, surfacing anomalies and vulnerabilities in real time rather than at the next scheduled review.
  • Readiness assessments and gap analysis against MiCA technological requirements and DORA (Digital Operational Resilience Act) mandates.

For CASPs, this combination turns security from a compliance checkbox into a demonstrable, ongoing control — the kind regulators are increasingly expecting to see, and the kind that protects users and reputations regardless of what's required on paper.

The Bottom Line

CASP status under MiCA marks a structural shift for crypto businesses in the EU: compliance is no longer a differentiator, it's a prerequisite for operating at all. For exchanges, wallet providers, and platforms scaling into or within the EU, meeting CASP obligations means pairing regulatory registration with the security infrastructure to back it up — audits, monitoring, and verification that hold up under both regulatory review and real-world attack.

FAQs

What is a crypto-asset service provider (CASP)?

A CASP is any business that provides crypto-related financial services, such as exchange, custody, trading, or transfer services, on a professional basis, and is licensed to do so under the EU's MiCA Regulation.

Do CASPs need to register in every EU country they operate in?

No. A CASP registers once with a competent authority in an EU Member State, then can passport that license to operate across all EU Member States, provided it maintains compliance in each.

Are smart contract audits required for CASP compliance?

MiCA doesn't mandate smart contract audits by name, but its cybersecurity and operational resilience requirements make independent security assessments a practical necessity for CASPs handling custody, trading, or transfer of crypto assets.

관련 블로그

CertiK Intel3D PSAV and the New Brazil Security Standard
새로운 · Report Review ·Intel3D

CertiK Intel3D PSAV and the New Brazil Security Standard

Brazil’s crypto market is entering a new era. By 30 October 2026, VASPs must demonstrate robust AML, sanctions, security, and custody controls to gain authorization—turning compliance and independent assurance into key competitive advantages.

CLARITY Act Stalls as Regulators Move Ahead
새로운 · 정책 펄스

CLARITY Act Stalls as Regulators Move Ahead

Senate leadership released a massive 616-page draft of the CLARITY Act, representing the most detailed legislative effort to date to regulate the digital asset industry. This comprehensive text includes expansive provisions for both crypto market structure and new law enforcement mandates designed to modernize federal oversight of the ecosystem.

CertiK Skill Scanner: The Antivirus for the AI Age

CertiK Skill Scanner: The Antivirus for the AI Age

CertiK Skill Scanner establishes a standardized security layer for third-party AI Skills, identifying execution-stage risks before they reach user data, assets, or systems.