Passporting in Crypto Payments

 

 

How Passporting Works Procedurally

 

Passporting is a legal mechanism under EU financial services law that allows a regulated entity authorised in one member state to operate across all 27 EU member states using a streamlined notification process rather than separate national licensing. The entity notifies its home state regulator (the competent authority that issued its license) of its intention to provide services in one or more other member states, specifying the services it will offer. The home regulator then notifies the host state regulators, who have limited grounds to object.

Under MiCA, the passporting process for CASPs requires the home competent authority to transmit the notification to host state authorities within 10 working days. Host states may not impose additional authorisation requirements on passporting entities — they can only supervise the entity's conduct in their jurisdiction, not gate its entry. This creates a genuine single market for crypto asset services across the EU.

 

What Passporting Covers — and What It Does Not

 

A passporting notification covers the specific services listed in the notification — not all services the entity is authorised to provide. A CASP passporting its exchange services into France cannot, on the basis of that passport, also provide custody services in France unless custody was included in the notification. Services must be listed individually.

Passporting also does not override host state conduct rules. Host states can apply their own national consumer protection laws, advertising standards, and local language requirements to passporting entities. A Lithuanian-licensed gateway serving German merchants must comply with German consumer information requirements, even though it does not need a German license. Conduct supervision remains with the host state; prudential supervision remains with the home state.

 

MiCA Passporting vs. Pre-MiCA National Licensing

 

Before MiCA, crypto businesses operating across the EU faced a patchwork of national licensing regimes: Germany's BaFin required a separate crypto custody license; France had its DASP regime; the Netherlands had its own VASP registration. A gateway wanting to serve merchants in three EU countries needed to comply with three different national frameworks simultaneously.

MiCA's passporting replaces this fragmentation with a single authorisation. A gateway with a Lithuanian CASP license issued post-MiCA can serve customers in all 27 member states without additional national filings. Entities that held national licenses under pre-MiCA regimes benefit from transition provisions allowing continued operation while they seek MiCA authorisation.

 

Brexit and the End of UK Passporting

 

Before Brexit, UK-licensed payment institutions and financial services firms could passport into EU member states. That right ended on 31 December 2020. UK-based crypto payment gateways serving EU merchants must now either obtain a separate EU-based CASP license (establishing a subsidiary in an EU member state) or rely on reverse solicitation — where the EU customer proactively sought out the UK service without any EU-directed marketing. The reverse solicitation exemption is narrow and does not cover ongoing service relationships. Gateways with significant EU merchant bases have largely established EU subsidiaries to re-establish passporting rights under MiCA.

 

Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.