Why the shift from VASP to CASP matters
For years, cryptocurrency businesses globally operated under the VASP (Virtual Asset Service Provider) framework, established by the Financial Action Task Force (FATF). However, with the full implementation of Europe’s MiCA (Markets in Crypto-Assets) regulation, a new standard has emerged: CASP (Crypto-Asset Service Provider).
Understanding the differences between these two frameworks is crucial for fintech companies seeking to offer crypto services legally in European and global markets.
Key legal points
- Scope of Activities: While VASP frameworks primarily focus on AML/CFT (Anti-Money Laundering) compliance, CASP introduces rigorous prudential requirements, consumer protection, and capital reserve rules.
- Passporting Rights: A CASP license obtained in one EU member state can be “passported” across all EU/EEA countries, whereas VASP registrations are strictly local and country-specific.
- Transition Period: Existing VASPs must transition to the CASP framework to continue offering services legally within European jurisdictions.
- Liability: CASPs face stricter liability rules, including responsibility for lost client assets due to hacks or operational failures.
Operating as a VASP is no longer enough to scale internationally. Transitioning to a CASP license requires restructuring internal compliance, increasing minimum capital, and establishing local substance.
Technical differences: CASP vs VASP
Below is a quick comparison of how these two regulatory frameworks differ across key operational areas:
| Feature | VASP (Virtual Asset Service Provider) | CASP (Crypto-Asset Service Provider) |
| Primary Regulator | Local Financial Intelligence Units (e.g., FIUs) | National Competent Authorities (e.g., BaFin, CySEC) |
| Main Focus | AML/CFT compliance and KYC checks | Comprehensive prudential supervision & consumer protection |
| Capital Requirements | Typically low or none (country-dependent) | Range from €50,000 to €150,000+ depending on services |
| EU Passporting | ❌ No (requires separate registry in each country) | Yes (one license for all EU/EEA markets) |
| Client Asset Custody | Basic security requirements | Strict segregation of client assets and mandatory custody rules |
Due diligence checklist for licensing
Before applying for a CASP license or upgrading your existing VASP registration, ensure you have the following in place:
- Minimum capital requirements aligned with your specific service category
- Fit and proper assessment documentation for board members and key shareholders
- Robust AML/CFT policies, including travel rule compliance solutions
- Business continuity plans and IT infrastructure audit reports
- Segregated bank accounts for client funds and corporate funds
- Clear consumer disclosure templates and complaints-handling procedures
Typical licensing pathway
The transition or new application process generally follows these stages:
- Gap Analysis: Assessing your current VASP compliance policies against CASP standards.
- Entity Substance: Establishing a local physical presence, including local directors and compliance officers in the licensing jurisdiction.
- Application Drafting: Preparing detailed policies on custody, conflict of interest, and market abuse prevention.
- Submission & Review: Undergoing assessment by national regulators (which typically takes between 3 to 6 months).
Common pitfalls
- Underestimating capital reserves: Failing to maintain the required capital buffers from day one.
- Ignoring the transition deadlines: Waiting too long to upgrade an existing VASP registration, leading to service disruption.
- Lack of local substance: Attempting to get a CASP license with a “shell company” without real physical presence or local employees.
Final takeaway
The evolution from VASP to CASP marks the maturity of the crypto-asset market. While the barrier to entry under the CASP framework is significantly higher, the benefits—such as full EU-wide passporting and increased trust from banking partners—are highly rewarding for fintech companies aiming for long-term growth.