Guide
The MFSA authorisation process for a crypto licence, step by step
Updated
The statutory clock in MiCA is 25 working days plus 40. The MFSA's own process has more stages than that, and the ones after the licence is granted catch people out.
The rulebook that governs it
The MFSA issues the Markets in Crypto-Assets Rulebook under article 38 of the MiCA Act. Title 2 covers authorisations, Title 3 the ongoing requirements for crypto-asset service providers and Title 4 those for issuers of asset-referenced tokens. The rulebook has been revised since issue: version 2.00 in June 2025 added newly issued Level 2 and Level 3 requirements and version 3.00 in March 2026 added more, so check the version you are working from.
What the MFSA assesses first
The rulebook calls due diligence the fundamental first step. The fitness and properness assessment applies to every person with a qualifying holding in the applicant, every beneficial owner, every member of the board, senior managers, the Money Laundering Reporting Officer and the Compliance Officer, plus anyone else the Authority considers necessary. The MFSA applies its own Guidance on Fitness and Properness alongside the joint EBA and ESMA guidelines on the suitability of management bodies and qualifying shareholders.
The stages
- Statement of intent. The MFSA's December 2024 circular directs prospective applicants to submit a statement of intent, signed by a prospective director or authorised signatory, before the application itself.
- Application. Submitted on the MFSA's forms through its portal, with the application fee under the fee regulations. The content is set by Article 62 of Regulation (EU) 2023/1114 and by the regulatory technical standard adopted under it.
- Assessment. The MiCA clock applies: 5 working days to acknowledge, 25 working days to test completeness, 40 working days from a complete application to decide, with one suspension of up to 20 working days for further information.
- In-principle approval. The MFSA approves the business plan in principle and imposes pre-licensing conditions: certified memorandum and articles, finalised versions of anything filed in draft, outstanding due diligence, a signed business plan, confirmation that key functionaries have been recruited, audited evidence of the capital, executed outsourcing engagement letters and appointment of key function holders.
- Six months to satisfy them. The rulebook expects pre-licensing conditions to be met within a maximum of six months of the in-principle approval letter, failing which the letter becomes invalid. An extension can be requested with a justifiable explanation.
- Licence, then commencement. After the licence issues the MFSA may impose post-licensing, pre-commencement conditions: the executed engagement letter with the credit institution holding client funds, board declarations that policies, agreements and tested systems are in place, confirmation of recruitment, contact details for the Compliance Officer and MLRO, the registered and business address, and notification of the actual commencement date.
- After you start. Further post-licensing conditions can be imposed with deadlines from 6 to 18 months, including a compliance or internal audit report, reassessment of key function holders' time commitment and of the governance structure, and submission of redemption, recovery or wind-down plans where applicable.
Classification comes before everything
Rule R2-2.1.4 records that in deciding whether a crypto-asset is in scope, and which type it is, the MFSA applies the joint European Supervisory Authorities' guidelines on the standardised test for classifying crypto-assets and ESMA's guidelines on when a crypto-asset is a financial instrument. Rule R2-2.1.5 applies ESMA's reverse solicitation guidelines to third-country firms. Getting the classification wrong does not make the file late, it makes it the wrong file.
White papers are notified, not approved. The rulebook is explicit that the MFSA neither requires prior approval of a crypto-asset white paper nor of marketing communications relating to it, and that the issuer remains responsible for compliance after notification. Asset-referenced token white papers from credit institutions are the exception: Article 17 requires approval.