Regulation (EU) 2023/1114 · Compliance, Registers & Licences

MiCA CASP authorisation: preparing your application to NBS

Crypto-asset services in the EU require CASP authorisation, and Slovakia’s transitional period for former crypto trade licences ended on 30 December 2025. Delegated Regulation (EU) 2025/305 defines the NBS application requirements, and subsequent changes restart assessment.

Crypto-asset services, from custody and exchange to transfers, are regulated throughout the EU under Regulation (EU) 2023/1114 (MiCA). In Slovakia, the National Bank of Slovakia (NBS) grants crypto-asset service provider (CASP) authorisation, supplemented by Act No. 248/2024 Z. z. on certain obligations and powers in crypto-assets. Anyone starting services today must be authorised before accepting the first client.

The transitional period has ended

Under § 12 of Act No. 248/2024 Z. z., persons providing virtual currency exchange or wallet services under a trade licence before 30 December 2024 could continue no later than 30 December 2025. Slovakia therefore used a shorter transition than MiCA allowed. Since that date, there is no old regime to rely on: unauthorised activity is unauthorised financial market business. NBS may impose corrective measures and fines under § 8 and order blocking of the online interface through which services are offered under § 10.

A legal entity or other undertaking wishing to provide crypto-asset services needs CASP authorisation and applies under Article 62 MiCA. Selected financial institutions, including banks, investment firms, electronic money institutions, management companies, market operators and central securities depositories, do not need a new authorisation and instead notify under Article 60. Delegated Regulation (EU) 2025/303 defines the notification. See when is NBS authorisation required for lending? for other authorisation regimes.

What the application must contain

Delegated Regulation (EU) 2025/305 details Article 62 application requirements in seventeen articles. The core consists of:

  • A three-year programme of operations (Article 2): services and crypto-asset types, target markets and clients, domains and applications, marketing plans and group membership.
  • Prudential safeguards (Article 3): Article 67 MiCA safeguards through own funds or insurance, with calculations for the first three financial years and stress scenarios.
  • Governance and internal policies (Articles 4 and 5): internal controls and business continuity.
  • AML arrangements (Article 6): money laundering risk assessment and policies under domestic implementation of Directive (EU) 2015/849.
  • People (Articles 7 and 8): management body members’ reputation, knowledge and time commitment, and qualifying shareholders’ details.
  • ICT and cybersecurity (Article 9): technical system documentation and compliance with Regulation (EU) 2022/2554 (DORA), including critical functions, ICT supplier contracts and a cybersecurity audit with penetration testing.
  • Service-specific modules (Articles 12–17): custody policy, trading platform rules, exchange, order execution, advice and transfer services, depending on the requested activities.

A Slovak requirement under § 7(5) of Act No. 248/2024 Z. z. adds that an applicant using a network and information system must submit a description of the cybersecurity audit with the application.

Form and timing: changes restart assessment

Implementing Regulation (EU) 2025/306 governs submission: the standard annex form is used, NBS publishes its contact point and acknowledges receipt with details of who handles the application.

Article 4 contains the key rule. Applicants must notify changes without undue delay, and the assessment period under Article 63(9) MiCA then starts anew when the updated information is received. NBS may also request additional information under Article 63(12). In practice, it is advisable to file only once the application is complete and internally consistent. A change to the information must, however, be distinguished from supplementation at NBS’s request: the completeness check follows Article 63(2)–(4) MiCA, while a request for additional information during assessment is governed by paragraph 12, which permits the assessment period to be suspended for no more than 20 working days. This does not automatically restart the entire process.

After authorisation: NBS reporting

Authorisation does not end the obligations. Under § 5 of Act No. 248/2024 Z. z. and NBS Measure No. 3/2025, effective from 1 July 2025, an authorised CASP submits eight reports through the Statistical Collection Portal. Quarterly reports cover the balance sheet and profit and loss account, own funds, services and fees, wallet addresses and complaints. The provider report is annual, AML/CFT reporting half-yearly, and management body changes are reported within five working days. Internal policies must therefore address reporting during application preparation: the system must produce the data NBS wants quarterly from day one.

How to prepare

Treat the application as a project: define service scope and the authorisation structure first, then prepare policies, ICT documentation and the AML programme, completing the form last. We assist throughout through MiCA CASP authorisation. AML for businesses covers AML arrangements, and public offer assessment addresses the boundaries if you also plan to offer crypto-assets publicly.

This article provides general legal information as at 5 September 2026. It does not constitute legal services or advice on your specific matter. Laws change and the details of your situation may differ. Check the appropriate course of action or contact us before making a decision.

Facing a similar situation?

Tell us what you need help with.

Describe your situation. We will review it and tell you within 24 hours whether and how we can help, including an indicative fee.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.

Contact a lawyer