Crypto-asset service providers operating in or into Germany must hold MiCA authorization from BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht), the German financial supervisory authority. Regulation (EU) 2023/1114 (MiCA) replaced the prior Kryptoverwahrgeschäft regime on 30 December 2024, requiring all CASPs to apply under the new framework. Authorization is granted per service: custody, exchange, placement, advice, portfolio management, reception and transmission, or operating a trading platform. BaFin processes applications under Article 63 MiCA and notifies ESMA, which maintains the public register.
Which services require MiCA authorization in Germany
MiCA defines eleven crypto-asset services in Article 3(1)(16). BaFin authorizes German-established firms for:
- Custody and administration of crypto-assets on behalf of clients (Article 67)
- Operation of a trading platform for crypto-assets (Article 72)
- Exchange of crypto-assets for funds or other crypto-assets (Article 75)
- Execution of orders for crypto-assets on behalf of clients (Article 76)
- Placing of crypto-assets (Article 77)
- Reception and transmission of orders for crypto-assets on behalf of clients (Article 78)
- Providing advice on crypto-assets (Article 79)
- Portfolio management on crypto-assets (Article 80)
- Providing transfer services for crypto-assets on behalf of clients (Article 81)
Each service is authorized separately. A CASP offering custody and exchange must hold authorization for both. Services ancillary to an authorized activity — such as KYC verification or fiat on-ramping — do not require separate authorization if they are incidental to the authorized service.
Firms already holding a Kryptoverwahrgeschäft licence under the German Banking Act (KWG) had until 1 July 2026 to submit a MiCA application to continue operating beyond the transitional period. Those that notified BaFin by 1 July 2024 and submitted a complete application by the July 2026 deadline could continue operating while BaFin processed the file. Firms that missed the July 2026 deadline ceased authorized activity on that date.
BaFin's application process
Authorization follows Article 63 MiCA and BaFin's published guidance. The applicant submits a complete file demonstrating compliance with organizational, prudential, and operational requirements. BaFin reviews, may request supplementary information, and decides within six months of receiving a complete application — extended to nine months for complex cases or novel business models.
Required documentation
BaFin requires:
- Programme of operations describing each service, the types of crypto-assets offered, target client categories, and operational processes (Article 63(2)(a)).
- Business plan including projected balance sheets, profit-and-loss forecasts, and a description of the business model for at least three years (Article 63(2)(b)).
- Organizational structure, including governance arrangements, internal control mechanisms, risk-management procedures, and ICT systems (Article 63(2)(c)).
- Policies for safeguarding client assets, including segregation arrangements and the identity and jurisdiction of any third-party custodian (Article 67 for custody services).
- Detailed description of business continuity and disaster recovery arrangements (Article 63(2)(d)).
- Identity, CVs, and criminal record certificates for all management body members and persons responsible for the management of the CASP (Article 63(2)(e)).
- Evidence of initial capital meeting the threshold for the services applied for (Article 66).
- Identity of shareholders or members holding qualifying holdings, and the amounts of those holdings (Article 63(2)(f)).
- Details of close links to other natural or legal persons (Article 63(2)(g)).
- Complaints-handling procedures and arrangements for the compensation or protection of client assets (Article 63(2)(h)).
- Proof of professional indemnity insurance or comparable guarantee covering liability for operational failures, including loss of client crypto-assets (Article 66(4)).
Firms offering custody must additionally submit the segregation policy (Article 67(2)), the record-keeping system for client positions (Article 67(3)), and evidence of the third-party custodian's own authorization or equivalent safeguards if custody is outsourced (Article 67(4)).
All documents must be in German or English. BaFin may request certified translations.
Assessment timeline
BaFin has six months from the date it confirms the application is complete to grant or refuse authorization (Article 63(5)). The clock starts when BaFin notifies the applicant in writing that no further documentation is required. If BaFin requests additional information, the six-month period is suspended until the applicant responds.
For applications involving novel services, complex group structures, or outsourcing arrangements BaFin considers material, the assessment period extends to nine months (Article 63(5)).
Once BaFin grants authorization, it notifies ESMA within two working days (Article 63(6)). ESMA updates the register within five working days of receiving the notification. The CASP may begin providing the authorized services once ESMA has published the entry. Check a firm's current authorization status at /verify.
Initial capital and ongoing own-funds requirements
Article 66 MiCA sets minimum initial capital thresholds by service:
| Service | Initial capital |
|---|---|
| Custody and administration | EUR 125,000 |
| Operation of a trading platform | EUR 150,000 |
| Exchange of crypto-assets | EUR 150,000 |
| Execution of orders | EUR 150,000 |
| Placing of crypto-assets | EUR 150,000 |
| Reception and transmission of orders | EUR 50,000 |
| Providing advice | EUR 50,000 |
| Portfolio management | EUR 150,000 |
| Providing transfer services | EUR 150,000 |
Where a CASP is authorized for multiple services, the applicable initial capital is the highest single threshold, not a sum. A firm offering custody (EUR 125,000) and exchange (EUR 150,000) must hold EUR 150,000.
Initial capital must be fully paid in cash or cash-equivalent instruments at the time of application. BaFin verifies this through bank statements or audited accounts.
Ongoing own-funds requirements apply after authorization. Article 66(2) requires CASPs to maintain at all times own funds equal to at least one quarter of the preceding year's fixed overheads. BaFin reviews this in annual reporting. For newly authorized CASPs without a full year of operating history, own funds must match the projected fixed overheads stated in the business plan, divided by four.
Germany's transitional deadline and the July 2026 cut-off
MiCA's transitional provisions (Article 143) allowed firms holding a national crypto-asset licence before 30 December 2024 to continue operating under that licence, provided they notified their competent authority by 1 July 2024 of their intention to apply for MiCA authorization and submitted a complete MiCA application by 1 July 2026.
For Germany, this applied to Kryptoverwahrgeschäft licence holders under Section 1(1a) sentence 2 no. 6 KWG. BaFin required:
- Notification by 1 July 2024 that the firm intended to apply for MiCA authorization. BaFin published a notification form on its website; firms that did not submit this by the deadline lost transitional rights.
- Complete MiCA application by 1 July 2026. A complete application meant all documents listed in Article 63(2) submitted and acknowledged by BaFin as complete. Firms that filed incomplete applications or filed after 1 July 2026 ceased authorized activity on that date.
Firms that met both deadlines continued operating under their KWG licence while BaFin assessed the MiCA application. BaFin processed these applications within the standard six- or nine-month period from the date of completeness, but the transitional arrangement meant the firm did not have to cease operations while waiting.
Firms that missed either deadline had to stop all crypto-asset services on 1 July 2026 and could not resume until they received full MiCA authorization. There is no grace period beyond the July 2026 cut-off.
Notification and the ESMA register
Once BaFin grants authorization, it notifies ESMA within two working days (Article 63(6)). ESMA publishes the entry in the public register within five working days (Article 109(1)). The register lists:
- The CASP's legal name and LEI (Legal Entity Identifier).
- The registered office address.
- The date of authorization.
- The competent authority (BaFin for Germany).
- The crypto-asset services authorized.
- Any restrictions or conditions BaFin has imposed on the authorization.
The register is the only definitive source for whether a firm is authorized. BaFin's own website lists firms it supervises, but the ESMA register is updated more promptly and includes all EEA member states. View Germany's authorized CASPs at /registry/country/de.
Firms authorized in Germany may passport services throughout the EEA under Article 64 MiCA by notifying BaFin of the host member states and services they intend to provide. BaFin forwards the notification to the host authorities within ten working days. The CASP may begin cross-border activity once BaFin confirms the notification has been sent — no further authorization from the host state is required.
Conditions BaFin may impose
BaFin may grant authorization subject to conditions or restrictions where necessary to ensure compliance with MiCA (Article 63(7)). Common conditions include:
- Limitations on the types of crypto-assets the CASP may handle (for example, restricting custody to certain tokens pending further operational evidence).
- Requirements to notify BaFin before launching new services, even if those services fall within the authorized category.
- Enhanced reporting beyond the standard annual submission (Article 84) if BaFin considers the CASP's risk profile or client volume warrants closer oversight.
- Restrictions on outsourcing critical functions until the CASP demonstrates adequate oversight capacity (Article 68).
Conditions are published in the ESMA register. A CASP that breaches a condition risks suspension or withdrawal of authorization (Article 85).
When authorization may be refused
BaFin refuses authorization if (Article 63(4)):
- The applicant does not meet the initial capital requirements (Article 66).
- The management body does not meet the fit-and-proper criteria (Article 65): members must have sufficient knowledge, skills, and experience, and demonstrate honesty, integrity, and independence of mind. A criminal record for financial crime or prior regulatory sanctions typically results in refusal.
- The applicant's organizational structure, governance, or risk-management framework is inadequate.
- The applicant's shareholder structure raises concerns about effective supervision — for example, opaque ownership or shareholders with a history of non-compliance.
- The applicant intends to offer services that do not comply with Title V MiCA (crypto-asset services) or, where applicable, Title III (issuance of asset-referenced tokens or e-money tokens).
- The applicant has provided false or misleading information in the application.
BaFin's refusal decision states the reasons in writing. The applicant may appeal to the Frankfurt Higher Regional Court (Oberlandesgericht Frankfurt) within one month of receiving the decision.
Ongoing supervision and annual reporting
Authorized CASPs must submit an annual report to BaFin within four months of the financial year-end (Article 84). The report includes:
- Audited financial statements.
- A description of the crypto-asset services provided over the year.
- Details of any material changes to the organizational structure, management body, or shareholding.
- Evidence that own funds remain above the required threshold.
- A summary of complaints received and how they were resolved.
- Details of any operational incidents, including ICT outages, security breaches, or loss of client assets.
BaFin may request additional information or conduct on-site inspections (Article 85). CASPs must also notify BaFin immediately of any material change to the conditions under which authorization was granted — for example, a change of senior management, a qualifying holding acquisition, or a decision to cease offering an authorized service.
Failure to maintain compliance with MiCA's ongoing requirements may result in supervisory measures, including public warnings (Article 101), restrictions on services, or withdrawal of authorization (Article 85).
Post-authorization changes and variation of permissions
A CASP that wishes to add a service not covered by its existing authorization must submit a new application to BaFin under Article 63. BaFin treats this as a variation and may rely on documentation already on file, but the CASP cannot provide the new service until BaFin grants the additional authorization and ESMA updates the register.
A CASP that wishes to cease offering an authorized service must notify BaFin in writing. BaFin updates ESMA, and the register is amended to remove that service. The CASP remains authorized for its other services and continues to meet the prudential requirements applicable to those services.
Material changes to the business model, governance arrangements, or outsourcing structure require prior notification to BaFin (Article 84(3)). BaFin assesses whether the change affects the CASP's ability to comply with MiCA and may impose additional conditions or refuse the change if it raises supervisory concerns.