Frankfurt skyline silhouette with compliance shield icon on dark navy background representing BaFin CASP licensing in Germany under MiCA
Back to blog

CASP Licence Germany: BaFin MiCA Requirements, Timeline & Costs 2026

Germany is the EU's largest CASP market — 53 authorised providers as of May 2026 — and BaFin is one of the most demanding NCAs on the continent. This guide explains exactly what MiCA requires, how the KMAG shapes Germany's national rules, what the Article 63 clock actually means in practice, and what a new applicant must prepare before submitting to BaFin and the Bundesbank.

Contents

Key facts

Why Germany Matters: BaFin's Position in the EU CASP Landscape

Germany is the EU's most active CASP jurisdiction under MiCA — which cuts both ways. The depth of regulatory precedent BaFin has already built makes a German authorisation credible across all 27 member states, but it also means BaFin applies institutional-grade scrutiny from day one. As of mid-2026, Germany hosts the largest number of MiCA-authorised CASPs in the EU — approximately 53 firms — and 151 of the 180 CASPs passporting cross-border into EU markets have chosen Germany as a target state, a clear signal that a BaFin licence is treated as the benchmark authorisation in the bloc. For firms targeting pan-EU scale, selecting Germany as the home member state under MiCA Article 48 is strategically rational: one supervisory relationship governs the firm's entire EU lifecycle, and BaFin's interpretive positions carry weight with other NCAs.

BaFin's enforcement posture reinforces why preparation matters as much as the application itself. The authority has adopted a public name-and-warn strategy: firms operating without authorisation are listed by name on BaFin's website, German courts upheld injunctions against non-compliant operators in 2025, and BaFin coordinated the blocking of domains belonging to at least six offshore exchanges that were soliciting German retail customers without a valid MiCA or transitional authorisation. This is not a jurisdiction that tolerates regulatory arbitrage. BaFin moved faster than the MiCA framework required: Germany legislated a transitional deadline of 31 December 2025 via §50(2) KMAG — twelve months rather than the maximum eighteen permitted under MiCA Article 143(3) — compressing the window firms had to regularise their status.

Choosing BaFin as home-state NCA is therefore a long-term structural decision, not just a licensing formality. BaFin is the designated competent authority for MiCA purposes under MiCA Article 59, with the Deutsche Bundesbank receiving copies of applications as part of the domestic coordination mechanism — BaFin retains sole decision-making authority. The result is a single, high-bar regulator that supervises everything from initial authorisation through ongoing prudential oversight, passporting notifications, and potential enforcement action. Firms that build their compliance architecture to BaFin's standard from the outset typically find reciprocal authorisation requests in other member states straightforward; those that do not are finding Germany's enforcement apparatus unforgiving.

Germany operates a two-layer regulatory architecture for crypto-asset service providers. MiCA (Regulation (EU) 2023/1114) is directly applicable EU law — it does not require national transposition and takes precedence over inconsistent domestic rules. Sitting alongside it is KMAG (Kryptomärkteaufsichtsgesetz), Germany's national companion act published in the Federal Law Gazette on 27 December 2024 as part of the broader FinmadiG legislative package. KMAG does not restate MiCA; it fills the gaps MiCA explicitly leaves to member states — primarily transitional windows, procedural coordination between BaFin and the Bundesbank, and the interface with existing national licensing regimes such as KWG, WpIG and ZAG.

Two transitional provisions in KMAG are material to any current application. First, §50(2) KMAG set Germany's grandfathering window at 12 months, expiring 31 December 2025 — shorter than the 18-month maximum MiCA permits. Firms that were already providing crypto-asset services under a KWG or other authorisation as of 29 December 2024 could continue operating during this window, but only while a compliant application is pending. Second, §50(3) KMAG read with Article 143(6) MiCA enables a simplified ("fast-track") procedure for those same firms: rather than submitting a full Article 63 dossier, they may apply via the Kryptomarkt-Zulassungsübergangsverordnung (KMZÜV) process, with BaFin having set an application deadline of August 2025. Firms that held KWG crypto-custody authorisation benefit most from this route, as much of the prudential and governance evidence already sits in their BaFin file. Missing that deadline means reverting to the full authorisation track — a significant operational risk.

Under MiCA Article 59, BaFin is Germany's sole designated National Competent Authority for CASP authorisation; the Deutsche Bundesbank receives copies of applications in a coordinating role and is not a co-decision maker. Critically, MiCA authorisation does not automatically resolve every regulatory question a crypto firm faces in Germany. Depending on the token classification and service profile, parallel analysis under WpIG (investment-firm rules implementing MiFID II), ZAG (payment services / PSD2), or WpHG (securities-trading obligations) may be required. Asset-referenced tokens and e-money tokens bring in additional issuer-level requirements under MiCA Titles III and IV respectively. Any firm operating across product lines should map its entire service stack against all applicable instruments before filing — not just the MiCA CASP list.

Which Services Require a BaFin CASP Authorisation

Under Article 59 of MiCA (Regulation (EU) 2023/1114), any legal entity providing crypto-asset services in Germany on a professional basis must hold a CASP authorisation granted by BaFin — unless a specific exemption applies. The ten regulated services are:

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders for crypto-assets on behalf of clients
  • Providing advice on crypto-assets
  • Portfolio management of crypto-assets
  • Transfer services for crypto-assets on behalf of clients

Certain already-regulated entities may use the Article 60 notification route instead of filing a full Article 63 authorisation application. Credit institutions, MiFID II investment firms, electronic money institutions (EMD2), UCITS management companies, AIFMs, central securities depositories, and regulated market operators can notify BaFin at least 40 working days before commencing CASP services. This route carries a critical limitation that is frequently misread: Article 60 only covers CASP services that are compatible with and directly correspond to the entity's existing authorised activities. It does not grant blanket access to all ten services. A MiFID II firm notifying under Article 60 can, for example, extend naturally into reception and transmission of orders or execution of orders for crypto-assets — but services outside that functional mapping, such as operating a trading platform, require a full Article 63 authorisation. Firms relying on Article 60 for services that fall outside their existing licence scope face regulatory enforcement risk.

Reverse solicitation under Article 61 is not a viable business model. ESMA's 2025 guidance confirms the exemption applies only where a client approaches the service provider entirely on their own initiative, without any prior solicitation, marketing, or targeted outreach by the firm. The moment a CASP advertises, runs promotions, or reaches out to prospective clients in Germany — including through social media or affiliates — the reverse solicitation defence falls away. BaFin has signalled it will scrutinise Article 61 claims closely, and reliance on this exemption as a structural workaround exposes firms to authorisation enforcement. For any firm with a sustainable German market presence, full authorisation under Article 63 or the Article 60 notification (where genuinely applicable) is the only defensible path.

Capital Requirements: MiCA Article 67 and Annex IV in Practice

Under Article 67 MiCA read together with Annex IV, every CASP must at all times hold prudential safeguards equal to the higher of two floors: the fixed class minimum for its authorised services, or 25% of the prior year's fixed overheads — the Fixed Overheads Requirement (FOR). Per ESMA Q&A 2349 (answered 18 February 2026 by the Commission), the FOR is computed from total overheads (fixed and variable combined), deducting only the four items listed in Article 67(3)(a)–(d). Firms operating for less than one year use projected overheads under Article 67(2). The table below reflects the three cumulative classes as set out in Annex IV MiCA and confirmed by ESMA Q&A 2343; consult the primary source on EUR-Lex for the authoritative text.

Class Minimum capital Services covered
Class 1 €50,000 Reception & transmission of orders; execution of orders; placing of crypto-assets; providing advice; portfolio management; transfer services for crypto-assets
Class 2 €125,000 All Class 1 services plus custody & administration of crypto-assets; exchange of crypto-assets for funds or for other crypto-assets
Class 3 €150,000 Operation of a trading platform for crypto-assets (irrespective of other services offered)

The highest applicable class governs. A firm providing only transfer services and advice sits at the €50,000 floor. The moment it adds custody or exchange, the floor rises to €125,000. Adding a trading platform raises it further to €150,000 — regardless of how few other services the firm offers. Whichever class minimum applies, if 25% of annual fixed overheads exceeds that figure, the higher FOR amount is what BaFin will expect the firm to hold.

Critically, Article 67(4) MiCA permits prudential safeguards to be met in three ways: (a) own funds consisting of CET1 instruments as defined in Articles 26–30 of Regulation (EU) 575/2013 (CRR), after full deductions under Article 36 CRR and without applying the threshold exemptions under Articles 46 and 48 CRR; (b) a qualifying insurance policy covering all EU Member States where CASP services are provided and meeting the characteristics set out in Article 67(5)–(6) MiCA; or (c) a combination of both. The insurance route is a fully legitimate alternative to holding CET1 capital — firms should not assume own funds are the only path. That said, BaFin's specific practice on the acceptability of insurance policies under Article 67(4)(b) should be verified directly with BaFin before relying on it in an application. See the complete CASP licence requirements guide for a broader treatment of prudential obligations across the EU.

The Article 63 Authorisation Process: Timeline and What BaFin Scrutinises

The CASP authorisation procedure under Article 63 MiCA runs in two legally distinct phases, each with its own clock. Applications must be submitted simultaneously to BaFin at [email protected] and to the relevant Deutsche Bundesbank regional office. The content of a complete application is governed by Article 62 MiCA and detailed in Commission Delegated Regulation (EU) 2025/305. BaFin requires governance documentation — programme of operations, internal controls, AML manuals, business continuity plans, shareholder structures — predominantly in German; submitting English-only governance arrangements is one of the most reliably avoidable causes of delay.

Phase one is the completeness check: BaFin has 25 working days to confirm the application is complete. If information is missing, BaFin may pause this phase by issuing a formal request with a deadline; if the applicant still fails to supply the missing material, BaFin may refuse to proceed. Once completeness is confirmed, a separate 40-working-day assessment clock begins. Under Articles 63(9) and 63(12) MiCA, this assessment period is not legally suspendable for CASP applications. BaFin may request further clarifications up to the 20th working day of this phase, but the clock continues to run. The outcome must be a grant or a fully reasoned refusal within those 40 working days. During assessment, BaFin also conducts a fit-and-proper review of every member of the management body under Article 68 MiCA, examining professional qualifications, absence of criminal convictions, and absence of conflicts of interest.

The statutory framework looks tight; practice is not. ESMA research indicates the completeness phase alone currently takes 45–60 calendar days for many applicants. A well-prepared file with no substantive gaps realistically reaches authorisation in four to six months; files with weak substance, generic AML manuals, or inconsistent service descriptions trigger clarification rounds that push the timeline to six to twelve months. The delays at BaFin are not caused by missing signatures — they are caused by generic governance documents that could belong to any firm, AML risk assessments that do not reflect the applicant's actual service mix, and programme-of-operations narratives that contradict the Annex IV service categories being applied for. Treat the completeness phase as a soft audit: every gap in the dossier that BaFin identifies will reappear as a harder question during the 40-day assessment.

Stage Statutory period Practical range
Submission & registration 1–2 weeks
Completeness check (Art. 63) 25 working days 45–60 calendar days
Full assessment (Art. 63(9)) 40 working days 8–12 weeks (longer if clarifications requested by day 20)
Decision (grant or refusal) Within 40-day window Total: 4–6 months (prepared); 6–12 months (with clarification rounds)

What Goes Into the BaFin Dossier: Governance, Substance and ICT

BaFin assesses CASP applications against the content requirements codified in Article 62 MiCA and the Commission Delegated Regulation (EU) 2025/305 (the application-content RTS). The dossier must demonstrate operational credibility on day one — BaFin explicitly rejects template governance documents and expects evidence that the business is, or is immediately capable of being, genuinely run from Germany. The legal entity must be incorporated under German law; a GmbH requires a minimum share capital of €25,000 and an AG €50,000. At least two qualified directors must be named, and BaFin expects them to be resident or actively and regularly present in Germany — not nominal figureheads managed from another jurisdiction.

Governance documentation forms the backbone of the dossier. This means a management body composition statement, fit-and-proper CVs for each director covering professional history, qualifications and any prior regulatory actions, a detailed organisational chart, and a remuneration policy aligned with the nature and scale of the business. BaFin requires core governance documents to be submitted in German; English annexes are tolerated for supporting materials, but the primary dossier language is German. Alongside governance, applicants must file a three-year business plan with financial projections that map each proposed service explicitly to its Annex IV MiCA capital class — this mapping must be unambiguous, because it determines both the minimum own-funds floor and the prudential safeguard form the applicant must maintain.

The AML/KYC framework must be GwG-compliant from submission. Germany designates CASPs as obliged entities under GwG §2(1) as expanded via the Financial Market Digitalisation Act (FinmadiG); the dossier must name a qualified AML officer and a deputy, and include documented KYC procedures, risk classification methodology and a suspicious-transaction reporting workflow. Travel Rule compliance under Regulation (EU) 2023/1113 requires a documented CASP-to-CASP and CASP-to-unhosted-wallet transfer workflow, not a placeholder reference to a future policy. ICT and operational resilience documentation — security architecture, incident-response plans and outsourcing controls — must reflect Regulation (EU) 2022/2554 (DORA), which runs as a parallel obligation for CASP applicants from 17 January 2025. Finally, the dossier must cover client-asset safeguarding arrangements, conflicts-of-interest policies and a complaints-handling procedure. Each element must be substantive; BaFin's review questions will probe whether the described controls are actually embedded, not merely described.

Germany's AML Layer: GwG, §15a EDD on Unhosted Wallets, and FIU Reporting

German CASPs operate under a dual AML layer that goes well beyond MiCA's own Title V obligations. At the EU level, the Transfer of Funds Regulation (TFR / Regulation (EU) 2023/1113) and MiCA Title V set baseline standards. On top of these sits the Geldwäschegesetz (GwG) — Germany's national AML statute — which was materially amended by the Finanzmarktdigitalisierungsgesetz (FinmadiG), in force December 2024. FinmadiG expanded the list of obliged entities under GwG to include CASP providers and certain ART issuers, bringing them squarely within the full GwG compliance architecture: risk-based customer due diligence, transaction monitoring, record-keeping, and Financial Intelligence Unit (FIU) reporting obligations. BaFin's Auslegungs- und Anwendungshinweise (AuA) — updated in February, March and July 2025 — set minimum standards for risk-assessment information sources and require faster customer data refresh cycles for clients classified as high-risk. Applicants are expected to demonstrate compliance with the AuA as part of their authorisation dossier.

The GwG contains enhanced due diligence (EDD) requirements specifically targeting transfers involving self-hosted (unhosted) wallets. BaFin's updated AuA (March 2025 revision) expanded requirements in this area, and the practical baseline is demanding: applicants must present documented risk-assessment procedures for unhosted-wallet interactions, including wallet ownership and control checks and blockchain analytics tooling integrated into the transaction flow — not added after the fact. BaFin expects these controls to be engineered into the platform architecture before authorisation is granted. Note: paragraph numbering within the GwG changes with each legislative amendment cycle; always verify the current numbering against the official consolidated text at gesetze-im-internet.de before relying on any specific paragraph reference. The regulatory obligation itself — EDD for self-hosted wallet transfers — is firmly established, even as its precise GwG location should be confirmed against the live text.

Two further operational requirements apply from day one. First, since 1 March 2026, all Suspicious Activity Reports (SARs) must be submitted exclusively via FIU Germany's goAML digital system in XML format, as mandated by the GwGMeldV; legacy submission channels are no longer accepted. Second, every obliged entity must appoint a dedicated AML officer and a named deputy — both must meet BaFin's fitness and seniority expectations and be identified in the authorisation application. BaFin treats the absence of a credible, senior AML officer as a substantive gap rather than a formality. Firms should also ensure that sanctions screening — covering EU, UN, and relevant third-country lists — is integrated into the same real-time monitoring stack as blockchain analytics, since BaFin assesses these controls as a single, coherent framework during its supervisory review. For the broader EU-level travel rule obligations layered on top of GwG, see the EU Travel Rule (TFR) compliance guide.

EU Passporting from Germany and BaFin's Enforcement Posture

A BaFin CASP authorisation is not merely a German licence — it is an EU passport. Under MiCA Article 59, a CASP authorised in one member state may notify cross-border services into all remaining 26 EU jurisdictions without applying for separate national licences. Germany has already emerged as the dominant passporting hub: 151 of approximately 180 cross-border CASPs operating across the EU have a German nexus, a share that reflects both Germany's large retail market and BaFin's established track record with crypto-asset intermediaries. That concentration creates a structural advantage for firms that secure BaFin authorisation first — one filing unlocks the entire single market. The notification procedure is straightforward in principle (a standard set of information submitted to BaFin, which forwards it to the host-state NCA within ten working days), but host-state regulators retain supervisory powers over conduct-of-business rules within their territory, so German CASPs operating cross-border must monitor local implementation divergences in parallel.

Timing matters acutely here. Several member states set transitional windows materially shorter than Germany's: the Netherlands, Poland, and Finland applied six-month transitional periods that expired in mid-2025. A German-headquartered CASP that had not yet obtained MiCA authorisation by those cut-off dates was effectively locked out of those markets regardless of its grandfathering status under §50(2) KMAG. Firms that delayed their BaFin applications discovered that Germany's generous transition to 31 December 2025 did not extend their passporting rights into stricter member states. That gap — between a firm's interim operational status in Germany and its passport into shorter-window jurisdictions — is one of the most concrete costs of a slow application timeline.

BaFin's enforcement posture under KMAG is deliberately visible. The regulator has pursued a proactive name-and-warn strategy, publicly identifying non-authorised offshore exchanges and blocking six domain-level access points during 2025–2026; German courts upheld BaFin's interim cease-and-desist orders throughout that period. Administrative sanctions for authorised CASPs in breach of MiCA obligations are set by Article 111 MiCA: for legal persons, at least €5,000,000 or between 3% and 12.5% of annual turnover — whichever is higher; for natural persons, at least €700,000. Market-abuse breaches under MiCA Title VI attract higher maxima. Decisions are published pursuant to Article 114, making enforcement actions part of the permanent public record. In this environment, early authorisation is not a competitive nicety — it is the only viable strategy for firms that intend to operate in Germany and hold EU passporting rights simultaneously. See also the EU passporting mechanics guide for the full notification workflow.

Frequently asked questions

Does Germany require a local legal entity to get a BaFin CASP licence?

Yes. BaFin requires a German-incorporated entity — a GmbH (minimum €25,000 share capital) or AG (minimum €50,000) is the standard choice. At least two qualified directors must be resident or actively present in Germany. A branch or representative office of a non-EU firm is not a substitute; the CASP must have its registered office in Germany where it carries out at least part of its crypto-asset services.

How long does BaFin's CASP authorisation process actually take in 2026?

The MiCA statute gives BaFin 25 working days to check completeness (this phase can be paused by an information request) and then 40 working days to decide once the application is declared complete — the 40-day assessment clock is not legally suspendable under MiCA Articles 63(9) and 63(12). In practice, the completeness phase alone is currently running 45–60 days due to application volumes, and a realistic end-to-end timeline for a well-prepared file is 4–6 months. Files with governance gaps, generic AML manuals, or inconsistent service descriptions typically take 6–12 months.

Can an existing German bank or investment firm use the Article 60 notification route instead of applying for a full CASP authorisation?

Yes, but only within strict limits. Credit institutions, MiFID II investment firms, EMIs, UCITS managers, AIFMs, CSDs, and regulated market operators may notify BaFin at least 40 working days in advance rather than applying under Article 63. However, Article 60 covers only those CASP services that directly correspond to the entity's existing authorised activities — services outside that mapping require a full Article 63 authorisation. Entities with a KWG crypto-custody licence as of 29 December 2024 could also use the simplified procedure under Article 143(6) MiCA and §50(3) KMAG.

What capital does a German CASP need, and are own funds the only option?

Capital requirements follow MiCA Article 67 and Annex IV: €50,000 (Class 1 services such as advice, RTO, execution, placing, transfer), €125,000 (Class 2 — adds custody and exchange), or €150,000 (Class 3 — trading platform). The actual floor is the higher of the applicable Annex IV minimum or 25% of the prior year's fixed overheads. Importantly, Article 67(4) allows prudential safeguards to be met by CET1 own funds, a qualifying insurance policy covering all EU territories of service, or a combination of the two — not solely by own funds. CET1 own funds must be calculated after full Article 36 CRR deductions and without the threshold exemptions under Articles 46 and 48 CRR. BaFin's specific practice on insurance acceptability should be confirmed directly with the authority.

What are Germany's specific AML obligations for CASPs beyond standard MiCA requirements?

German CASPs are obliged entities under GwG §2(1) no. 2 (expanded by FinmadiG in December 2024). They must appoint a dedicated AML officer and deputy, comply with BaFin's updated AuA guidance (effective from February 2025, amended July 2025), and apply enhanced due diligence for transfers to or from self-hosted (unhosted) addresses under §15a GwG. Since 1 March 2026, all suspicious activity reports must be filed exclusively via FIU Germany's goAML digital system. BaFin also expects blockchain analytics tooling and documented wallet screening to be operationally embedded — not just described in policy documents.

What does BaFin's enforcement against unlicensed CASPs look like in practice?

BaFin operates a proactive 'name-and-warn' strategy: it publicly flags suspected violators and has blocked six offshore exchange domains targeting German users without CASP authorisation. German courts upheld BaFin's interim cease-and-desist orders against a crypto issuer in 2025. Administrative fines under MiCA Article 111 reach at least €5,000,000 for legal persons (or 3–12.5% of annual turnover, whichever is higher) and at least €700,000 for natural persons; fine decisions are published under Article 114. Operating without authorisation in Germany carries both financial and reputational consequences that make early licensing the only commercially rational path.

Link copied to clipboard