Skip to content
CNMV · Spain

CASP authorisation in Spain — what CNMV expects under MiCA

Fintech Passport
June 21, 2026 · 7-min read
CASP authorisation in Spain — what CNMV expects under MiCA

CASP authorisation in Spain runs through CNMV — with Banco de España at the table for E-Money Tokens. The legal framework is the directly-applicable MiCA Regulation, overlaid by Spanish implementing law that designates the competent authorities and sets the transition rules from the prior PSAN registration regime. This piece walks through who grants what, what the application file must contain, how the PSAN migration works, and what switches on the day the authorisation lands — with worked examples showing how the services catalogue drives the file.

  • Regulation (EU) 2023/1114 — MiCA, directly applicable across all member states
  • Spanish implementing law — designating CNMV as competent authority for Crypto-Asset Service Providers under Title V MiCA, and Banco de España for matters relating to E-Money Tokens (EMTs) and Asset-Referenced Tokens (ARTs) under Titles III and IV
  • The prior PSAN registration regime at Banco de España — the pre-MiCA registration scheme for crypto-asset service providers, now subject to transitional provisions

2. Who grants what

ActivityCompetent authority in Spain
CASP authorisation under Article 59 MiCACNMV
ART issuer authorisationBanco de España
EMT issuanceBanco de España (issuer must be a CRR-bank or an EMI)
Prior PSAN registration (legacy)Banco de España
AML supervisionSEPBLAC, with CNMV / BdE inputs

CNMV leads on the CASP services catalogue — custody, exchange, trading-platform operation, advice, portfolio management, transfer services. Banco de España leads on tokenised-money issuance. A firm operating an exchange that also issues an EMT interacts with both.

3. The MiCA services catalogue

Article 3(1)(16) MiCA lists the services a CASP can be authorised to provide:

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders
  • Provision of advice on crypto-assets
  • Portfolio management of crypto-assets
  • Transfer services for crypto-assets on behalf of clients

The application specifies which services the CASP will provide, and the scope drives capital, operational and conduct requirements — exactly the way the PSD2 services selection drives a payment-institution file.

4. Capital and prudential requirements

Article 67 MiCA sets minimum capital floors by service class:

  • €50,000 — the lightest class (e.g. reception and transmission, advice, placing, transfer services)
  • €125,000 — exchange, execution, custody, portfolio management
  • €150,000 — operation of a trading platform

Ongoing own funds must be the higher of the floor and a quarter of the previous year’s fixed overheads. CNMV expects the three-year projections to show headroom against both measures, not a balance that touches the floor at launch.

5. What goes in the application file

Core sections of a CASP file at CNMV:

  • Programme of operations — the services to be provided, the customer journey, the asset types in scope
  • Business plan — three-year financial projections
  • Governance map — board, senior management, key function holders, fitness-and-properness
  • Internal-control framework — risk, compliance, internal audit
  • ICT and operational-resilience framework — aligned with DORA
  • Custody and segregation — the segregation model, cold-storage vs hot-wallet split, key management, sub-custody arrangements
  • Market-abuse policy — Articles 88 onwards MiCA introduce crypto-specific market-abuse rules; the policy and monitoring framework must be documented
  • AML / CTF programme — including the Travel Rule implementation and self-hosted-wallet attestation flow
  • Conduct framework — risk warnings, complaint handling, marketing-communications consistency
  • White papers where the CASP also issues tokens — see our MiCA white paper piece
  • Shareholder structure — direct and indirect, with fitness-and-properness on qualifying shareholders

6. Worked example — brokerage app adding crypto

Facts: a Spanish fintech wants to let retail customers buy and sell a shortlist of crypto-assets in-app. Customer assets are held with a third-party custodian; the firm executes against a liquidity provider. No trading platform, no token issuance.

What the rule says: the model combines execution of orders and exchange of crypto-assets for funds — the €125,000 class under Article 67. If the firm also holds the customers’ crypto-assets itself rather than passing custody entirely to the third party, custody and administration is triggered too, in the same capital class but with the full segregation, key-management and sub-custody documentation attached.

What the practitioner does: pins down the custody question first, because it is the most expensive section of the file. If the third-party custodian genuinely holds the assets, the firm documents the sub-custody chain and its due diligence over it; if the firm touches keys at any point, it writes the custody section as if it were the core business — because for CNMV’s review, it is.

7. Worked example — PSAN-registered exchange migrating

Facts: an exchange has operated in Spain for several years under a PSAN registration at Banco de España, offering fiat-to-crypto and crypto-to-crypto exchange plus hosted wallets. It assumed its registration would roll into MiCA.

What comes back: PSAN registration is not CASP authorisation. The Article 143 MiCA transitional provisions allow in-scope firms to continue operating during a defined window while the CASP application is prepared and decided — but the window has firm dates set in the implementing framework, and missing them means operating without authorisation. The MiCA file demands substantially more than the PSAN registration did: governance, DORA-aligned ICT, custody segregation, market-abuse policy.

What the practitioner does: starts the CNMV file immediately rather than at the end of the window, reusing what already exists — the KYC programme, transaction monitoring, customer master — and budgeting the new work where the PSAN regime was silent: the custody-segregation memo, the market-abuse monitoring design and the DORA register. Migrating firms typically run faster than greenfield applicants, but only if they treat the file as new, not as a renewal.

8. Worked example — CASP that wants its own stablecoin

Facts: a CASP applicant also wants to issue a euro-referenced stablecoin to power in-app settlement.

What the rule says: a token referencing a single official currency is an E-Money Token under Title IV MiCA, and only a CRR credit institution or an EMI may issue one — an authorisation that sits with Banco de España, not CNMV. The CASP authorisation alone does not cover issuance.

What the practitioner does: splits the programme: the CASP file to CNMV for the services, and either an EMI authorisation track at Banco de España or a partnership with an existing EMT issuer for the settlement token. Sequencing matters — most firms launch the CASP services first and revisit issuance once volumes justify a second licence.

9. Realistic timing

Article 63 MiCA gives the authority 25 working days for the completeness check and 40 working days for the substantive assessment once the file is complete. End-to-end — with pre-application engagement and feedback rounds — a realistic plan is six to nine months for a first-time applicant. PSAN-migrating firms typically run shorter because the underlying programmes already exist.

10. What switches on at grant

  • Travel Rule compliance on every crypto-asset transfer
  • DAC8 reporting from 2026 onwards
  • AML and tipping-off obligations under Law 10/2010, with the designated SEPBLAC representative
  • Market-abuse monitoring and reporting under Articles 88 onwards MiCA
  • Conduct and complaint handling
  • ESMA / EBA-coordinated supervisory reporting through CNMV
  • Passporting notifications where activity extends to other member states

11. FAQ

Do I file with CNMV or Banco de España?

CNMV for the CASP services authorisation. Banco de España for ART issuer authorisation and for EMT issuance, which sits inside an EMI or CRR-bank licence. A firm doing both interacts with both.

If I have a PSAN registration, am I CASP-authorised?

No. PSAN registration was a different regime. MiCA requires a fresh CASP authorisation; the Article 143 transitional provisions allow continued operation during the application process, within defined windows.

What is the difference between a CASP and an EMI for stablecoin work?

An EMI may issue an E-Money Token — a stablecoin referencing one official currency — under Title IV, inside its EMI licence. A CASP provides crypto-asset services to clients under Title V. A firm doing both holds both authorisations.

Are there specific Spanish overlays on MiCA?

MiCA is a directly-applicable Regulation, so the substance is uniform. Spanish overlays are procedural — competent-authority designation, language, the PSAN transition. The substantive rules apply identically across the EU.

Can CNMV reject the application?

Yes, on the grounds in Article 63 MiCA — fitness-and-properness failures, governance deficiencies, AML or operational concerns. Rejections are appealable through the Spanish administrative-litigation route.

Does the CASP authorisation passport into other EU member states?

Yes — Article 65 MiCA. CNMV as home authority notifies the host, which has limited grounds to refuse. See our branch vs Freedom of Services piece for the operating-model choice.

12. What to do, today

  • Founders: confirm whether the services catalogue triggers CASP authorisation, ART/EMT issuance, or both — and engage the right authority early.
  • PSAN-registered firms: do not assume continuity — start the CASP file inside the transition window.
  • CTOs: build custody segregation, the market-abuse policy and the Travel Rule implementation as core file elements, not add-ons.
  • Programme leads: run pre-application engagement with CNMV before the formal submission.
  • COOs: plan post-grant reporting alongside the application — Travel Rule, DAC8 and market-abuse monitoring switch on at grant.

Related: MiCA white paper drafting · MiCA Travel Rule · DAC8 — EU crypto reporting · CASP in Italy · CASP authorisation in Luxembourg · Spain’s crypto-asset information returns (modelo 172/175) · The MiCA CASP transition after 1 July 2026 · CARF and how it lines up with DAC8

Related reads.