Home/Licensing and regulatory authorisation

Licensing and regulatory authorisation

What each regime requires, what it costs in capital and time, and why applications actually fail.

Three regulatory families cover most of what a digital business in Europe needs: crypto-asset services under MiCA, payment and electronic money authorisation, and national online gaming licences. This page sets out what each one is, who needs it, what it requires and where applications actually fail.

One thing this page will not do is tell you how many days it takes to get a licence. Regulators do not work to a promised date, the clock stops every time they ask a question, and any firm quoting you a guaranteed timeline is quoting a sales figure. What we can do is show the statutory review windows, explain what makes a file move quickly, and be honest about the range.

01

The three regimes

Crypto-asset services — MiCA / CASP

The Markets in Crypto-Assets Regulation created a single EU authorisation for crypto-asset service providers. The transitional period during which firms could keep operating under national regimes ended on 1 July 2026, and ESMA confirmed in April 2026 that it would not be extended. Providing crypto-asset services to clients in the EU without a CASP authorisation is now unlicensed activity, and national authorities — the French AMF among them — have said explicitly that it will be treated that way.

Who needs it: exchanges, brokers, custodians, transfer services, portfolio managers, advisers and trading platforms serving EU clients. What distinguishes it: one authorisation passports across the EEA on notification, so the decision is which member state to apply in, not how many applications to file.

Payments and electronic money

Two authorisations sit close together and are regularly confused. A payment institution executes payment transactions, acquires, initiates or provides account information. An electronic money institution additionally issues e-money — stored value that a customer holds as a balance. If your product holds customer balances, you are almost certainly in EMI territory, and the difference in initial capital is substantial.

The framework is being revised. Political agreement on PSD3 and the Payment Services Regulation was reached in November 2025, and the reform consolidates the e-money regime into a single payment institution licence with e-money issuance as a sub-activity. Existing institutions are expected to be grandfathered rather than forced to reapply, but they will have to update authorisation files, governance documentation and reporting to the new taxonomy. Anyone applying now should build the file with that consolidation in mind.

Online gaming

There is no EU gaming licence. Each member state regulates its own market, and a licence in one state does not give you the right to accept players in another. The practical questions are therefore which markets you intend to serve, whether those markets require local licensing, and which licence your payment providers and software suppliers will accept.

Malta remains the reference EU jurisdiction: a ten-year licence, B2C types 1 to 4 and a B2B critical gaming supply licence, with mandatory key function holders including a compliance officer and an MLRO. Outside the EU, Curaçao rebuilt its regime under the National Ordinance on Games of Chance, in force since 24 December 2024 — the master and sub-licence model is gone, the Curaçao Gaming Authority licenses operators directly, and a resident managing director is required from day one.

02

Comparison of requirements

Indicative figures drawn from the current regulatory texts. They are a planning tool, not advice on a specific application — the amount that binds you depends on which services you provide and on your fixed overheads.

Figures reflect the position as at August 2026. Capital is the minimum entry threshold, not the amount required to operate — regulators assess the business plan against realistic running costs.
RegimeMinimum capitalStatutory review windowLocal presenceAfter authorisation
CASP — custody, transfer, advice, RTO, placing, portfolio management€50,00025 working days completeness check, then 40 working days to decide (extendable)Effective management in the member state; at least one director resident in the EUOwn funds maintained at all times, at the higher of the class minimum or one quarter of fixed overheads
CASP — exchange and order execution€125,000As aboveAs aboveAs above, plus service-specific conduct requirements
CASP — operating a trading platform€150,000As aboveAs aboveMarket abuse controls, transparency and reporting
Payment institution — full services€125,0003 months from a complete applicationHead office in the member state of authorisationOwn funds calculation, safeguarding, incident and fraud reporting
Payment institution — money remittance only€20,0003 months from a complete applicationAs aboveReduced but not absent reporting
Electronic money institution€350,0003 months from a complete applicationAs aboveOwn funds of 2% of average outstanding e-money, safeguarding, reconciliation
Malta B2C gaming, types 1–2€100,000 share capitalNo fixed statutory period; driven by applicant responsiveness and a systems reviewMaltese company; CEO, key compliance officer and MLRO as key function holdersAnnual licence fee, compliance contribution, gaming tax, audits and periodic returns
Malta B2C types 3–4 and B2B critical supply€40,000 share capitalAs aboveAs above (B2B requires CEO and key compliance officer)As above, scaled to the licence type
Curaçao B2C or B2B under the LOKSet by the authority per applicantTwo phases of roughly eight weeks each, each extendable; three to five months realisticallyCuraçao company with statutory seat; resident managing director from day one; compliance officer and MLRO separate from the CEOFATF-aligned AML/KYC, ADR and responsible gaming obligations; further key persons and a physical office phasing in to 2028–2029
Where the real threshold sits

Capital is the least interesting number on this table. Applications are rarely refused for lack of capital, because that is the one requirement everybody checks. They are refused on governance, on a business plan that does not match the application, and on key personnel who cannot evidence what the regulator asks.

03

How an application runs

  1. Regime and gap analysis

    Which authorisation the model requires, in which member state, and the distance between your current position and the standard. Two to three weeks, ending in a written memo.

  2. Build the file

    Programme of operations, business plan and financial projections, governance, policies, outsourcing, ICT and key-personnel documentation. Six to twelve weeks depending on regime.

  3. Pre-submission review

    Reading the file the way the regulator will: does the business plan match the application, does the org chart match the policies, is every assertion evidenced. One to two weeks.

  4. Submission and review

    Filing, then answering requests for further information. This is where timelines are won or lost — a well-prepared file typically faces one or two rounds, a weak one considerably more.

What a realistic timeline looks like

For a CASP application, the statutory clock is 25 working days for the completeness check and 40 working days for the substantive decision, which can be extended. That is the clock; it is not the calendar. Counting file preparation, the completeness check, at least one round of questions and the authority's internal process, four to six months from engagement to decision is a realistic planning assumption for a well-prepared file, and longer where the business model raises novel questions.

For payments and e-money, the three-month decision period runs from a complete application. Regulators exercise real discretion in deciding when an application is complete, and a file that arrives with gaps can sit outside that clock for months before it formally starts.

Gaming applications work differently again: Malta runs a fit-and-proper assessment, a business and operational review and an independent systems audit against a live environment, and the pace is largely set by how quickly the applicant responds.

04

What we need from you

Corporate and ownership

  • Constitutional documents of every entity in the chain
  • Ownership structure to natural persons, with percentages
  • Passports and proof of address for shareholders above the threshold, directors and key function holders
  • CVs and, where required, criminal record certificates and professional references
  • Latest financial statements, or opening balance for a new entity

Financial

  • Evidence of capital and its source — this is examined, not merely noted
  • Three-year financial projections with the assumptions written down
  • Bank references and existing banking relationships

Operational

  • A precise description of every service you intend to provide, in the regulator's own vocabulary
  • Customer journey from onboarding to withdrawal, including the money flow at each step
  • Technology stack, hosting, and which functions are outsourced to whom
  • Existing policies, however imperfect — we would rather see them than start blind
  • Any previous refusal, withdrawal or regulatory correspondence, anywhere

People

  • Proposed compliance officer and MLRO, and evidence of their competence and availability
  • Organisation chart with reporting lines and delegated authority
Disclose the history

The last item in the corporate list matters more than it looks. A previous refusal that surfaces during the review, rather than being disclosed and explained in the file, converts a difficult application into a failed one. Tell us early; there is almost always a way to present it.

05

Why applications fail

This is the section clients tell us is the most useful, because it is the one nobody publishes.

01

The file is incomplete on arrival

The single most common cause. The statutory clock does not start until the application is complete, so an incomplete filing does not buy time — it loses it, and it sets the tone for everything that follows.

02

The business plan contradicts the application

Projected volumes that no staffing plan could support, revenue from a service not listed in the application, or a market the licence would not cover. Reviewers read both documents together.

03

Key personnel cannot be evidenced

A compliance officer who holds the same role at four other firms, an MLRO who is also the operational director, a director with no demonstrable experience of the activity. Several regimes now require these roles to be genuinely separate.

04

Source of funds is asserted rather than shown

Capital arrives from a shareholder loan with no underlying documentation, or from a chain that cannot be traced to an economic origin. Expect this to be examined closely.

05

Policies are generic

A risk assessment that does not mention your customer base, monitoring rules that could belong to any firm, an outsourcing register that omits your main technology dependency.

06

Substance does not match the claim

An address that is a mailbox, a director resident elsewhere, decisions minuted in one country and taken in another. This is checked, and increasingly checked in person.

07

Adverse history surfaces late

A prior refusal, a related company under investigation, a shareholder on an adverse media list. Disclosed and explained, most of these are survivable; discovered, they rarely are.

08

Questions go unanswered for too long

Requests for information have deadlines. Missing them, or answering partially, signals that the applicant will be equally responsive once supervised.

06

Life after authorisation

Obtaining a licence and keeping one are different disciplines, and the second is where most firms are underprepared. The authorisation is a set of continuing conditions, and supervisors assess compliance with those conditions rather than the quality of the original application.

What continues

  • Capital and own funds. Not a one-off entry test. CASPs must hold the higher of the class minimum or a quarter of fixed overheads at all times; EMIs must maintain own funds against outstanding e-money.
  • Reporting. Periodic returns, and in some regimes monthly filings. Late returns are the most common supervisory finding in every regime we work in.
  • Notifications. Changes in shareholding, directors, key function holders, outsourcing arrangements or the service list generally require prior notification or approval. Doing it afterwards is a breach even where the change itself would have been approved.
  • Audit. Financial audit, and in gaming regimes a compliance audit on a defined cycle.
  • AML supervision. Independent of the licence itself, and the area where enforcement is most active. See AML/KYC and internal control.
  • Record keeping. Retention periods that outlast the customer relationship, in a form that can be produced on request rather than reconstructed.

We maintain an obligation calendar for retained clients: what is due, to whom, and what evidence has to exist when it is filed. It is unglamorous work and it is the reason licences survive their first inspection.

Related pages

Further reading

Frequently asked questions

How long does it take to get a licence?

We do not quote a date, and you should be wary of anyone who does. What we can give you are the statutory windows — 25 plus 40 working days for a CASP decision, three months from a complete payments application — and a realistic planning range that accounts for file preparation and at least one round of regulator questions. For a well-prepared CASP file that is typically four to six months from engagement. The variable that moves it most is how quickly you supply what the regulator asks for.

Can we start operating while the application is pending?

Not in the regulated activity. This was the practical effect of the MiCA transitional period ending: there is no longer a national regime to operate under while you wait. Preparatory activity — building, hiring, contracting — is different from providing the service, and the line is worth drawing carefully in writing before you approach it.

Is it faster to buy a licensed company?

Often, yes, because due diligence replaces a multi-month application. It also transfers the target's history, including any supervisory findings, and the change of control itself requires regulatory approval that can take as long as a fresh application. It is a genuine option, not a shortcut, and it needs the same rigour applied in the opposite direction.

Do we need a local director?

Under MiCA, effective management must be in the member state of authorisation and at least one director must be EU-resident. Under the Curaçao regime a resident managing director is required from the day the licence is granted. Malta requires key function holders with genuine availability. In every case the test is whether the person actually performs the role, and nominal appointments are increasingly identified.

Can one licence cover several EU countries?

For crypto-asset services and for payments, yes — authorisation in one member state passports to the others on notification. For online gaming, no: gaming is licensed nationally, and serving players in a regulated market generally requires a licence from that market.

What if we were refused before?

Tell us at the first conversation. A prior refusal is a fact the next regulator will find, and the difference between a survivable application and a doomed one is whether it appears in your file with an explanation or in theirs as a discovery. Remediation is usually possible; concealment never is.

Tell us what you are building

A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.

Describe your matter

We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.

Prefer another channel? Write to info@itlex.pro or t.me/itlexpro. Your data is used only to answer this enquiry.