MiCA licence in the Czech Republic for crypto-asset service providers

A practical one-page guide for founders, fintech groups and existing VASPs preparing for Czech authorisation under the EU Markets in Crypto-Assets Regulation. It covers licence scope, governance, AML, documentation, process planning and post-approval duties.

For Czech-specific licensing support, read more about the MiCA licence in the Czech Republic.

EUpassporting model
AMLrisk-based controls
CASPoperating framework

Czech MiCA licensing landscape

MiCA creates a harmonised EU regime for crypto-asset service providers. In the Czech Republic, applicants should prepare for a formal authorisation process that looks beyond registration and tests whether the company has durable substance, competent management, credible policies and a controlled operating model.

From VASP to CASP

Existing crypto businesses should map legacy activities against MiCA service categories and close gaps in governance, client disclosures and safeguarding.

EU market access

A compliant authorisation strategy should anticipate cross-border service delivery, passporting, local language documentation and consistent customer treatment.

Supervisory evidence

Policies are not enough. Applicants need board minutes, role descriptions, risk registers, vendor files and operational proof.

Risk-sensitive review

Custody, exchange, transfer, portfolio, advice and token-related activities carry different capital, control and disclosure expectations.

Eligible crypto-asset services

Applicants should define exactly which MiCA services they will provide, because this drives capital, governance, outsourcing, IT security, conflicts, complaints and client asset safeguards.

Service areaTypical business modelKey licensing focus
Custody and administrationWallet custody, safekeeping of client crypto-assetsSegregation, private key controls, incident response, reconciliation
Exchange servicesCrypto-fiat or crypto-crypto exchangePricing transparency, order handling, AML monitoring, market abuse controls
Trading platform operationMarketplace matching third-party buy/sell interestsRulebook, access criteria, surveillance, conflicts and resilience
Transfer servicesExecution of crypto transfers on behalf of clientsTravel rule readiness, sanctions screening, beneficiary checks
Advice or portfolio servicesRecommendations or managed exposure to crypto-assetsSuitability, disclosures, competence, conflicts and recordkeeping

Company and management requirements

  • ✓Clear legal entity structure, beneficial ownership disclosure and group chart.
  • ✓Fit-and-proper management with relevant financial, technology, compliance or crypto experience.
  • ✓Defined board responsibilities, management reporting and escalation channels.
  • ✓Local operational substance proportionate to Czech and EU market activity.
  • ✓Outsourcing controls for technology, custody infrastructure, compliance tooling and customer support.

AML programme

A Czech MiCA applicant should demonstrate a live AML framework, not a generic template. The programme must match customer type, asset type, transaction flows, geographies and delivery channels.

KYC / KYB

Onboarding, verification, beneficial owners and enhanced due diligence.

Monitoring

Rules, blockchain analytics, alerts, case handling and suspicious reports.

Sanctions

Screening at onboarding, transaction points and periodic review.

Training

Staff competence, annual refreshers and evidence of completion.

Application documents

The application file should read like a controlled operating manual for the future authorised CASP. Each document should be internally consistent with the business plan, service scope and risk profile.

Corporate file

Articles, registry extract, ownership chart, UBO evidence, group structure, capital evidence.

Business plan

Services, client segments, revenue model, forecasts, jurisdictions, marketing and growth assumptions.

Governance pack

Board rules, organisational chart, role descriptions, conflicts policy, remuneration approach.

AML documents

Risk assessment, AML policy, KYC procedures, monitoring rules, sanctions controls, training plan.

ICT and security

Architecture, access control, key management, resilience, business continuity and incident response.

Client protection

Terms, risk disclosures, complaints, asset safeguarding, order execution and record retention.

Approval process

01

Scope diagnosis

Map activities to MiCA service categories, identify exclusions and define passporting goals.

02

Gap remediation

Upgrade governance, AML, custody, ICT and client disclosure arrangements before submission.

03

Filing and Q&A

Submit the file, manage regulator questions and keep all policies, diagrams and forecasts aligned.

04

Launch controls

Activate reporting, compliance calendar, training, complaint logs and monitoring dashboards.

Ongoing reporting and maintenance

A MiCA licence is not a static certificate. Czech CASPs should operate a compliance calendar and evidence continuous control over client assets, financial crime risk, conflicts, complaints, outsourcing and operational incidents.

AreaPractical duty
GovernanceBoard packs, risk reviews, policy approvals, conflicts register.
AMLPeriodic KYC refresh, alerts, SAR decisions, sanctions logs.
OperationsIncident register, outsourcing monitoring, business continuity tests.
ClientsComplaints, disclosures, asset reconciliations, service changes.
Regulatory changeTrack guidance, update procedures and retrain relevant staff.

Timeline

Preparation: 4–10 weeks

Scope, corporate setup, management checks, policy drafting, vendor documentation and operating model review.

Application review: variable

Regulatory review depends on file quality, service complexity, ownership structure and responsiveness to follow-up questions.

Launch: 2–6 weeks

Finalise controls, train staff, configure reporting, test incident escalation and confirm client-facing materials.

FAQ

Can a Czech CASP serve clients across the EU?+

MiCA is designed around harmonised EU authorisation and cross-border service provision. Passporting should be planned during the licensing strategy, not after approval.

Is an existing Czech crypto registration enough?+

A legacy registration usually does not equal full MiCA readiness. Existing providers should review service scope, capital, governance, AML, client disclosures and operational controls.

Do all applicants need local staff?+

The staffing model should be proportionate to activity, risk and outsourcing. Management must remain able to supervise the business effectively.

What causes delays?+

Common delays include unclear service mapping, generic AML policies, weak custody evidence, incomplete ownership documents, inconsistent financial forecasts and slow responses to regulator questions.

Can documents be prepared in stages?+

Yes, but the final submission must be coherent. Policies, business plan, organisational chart, outsourcing files and risk assessment should describe the same operating reality.

Prepare a Czech MiCA readiness review

Best for: exchanges, custodians, transfer providers, trading platforms, token projects and fintech groups.

Output: scope map, gap list, document plan and approval route.