Crypto / CASP Licence in Romania

MiCA authorisation · CASP registration · AML/CFT · ASF · VASP Romania

Crypto-asset service providers (CASPs) operating in Romania are regulated under EU Regulation 2023/1114 — the Markets in Crypto-Assets Regulation (MiCA) — which became fully applicable across all EU member states on 30 December 2024. MiCA replaces the previous VASP registration regime and introduces a unified EU-wide authorisation framework administered in Romania by ASF (Autoritatea de Supraveghere Financiară).

Romania For Business SRL assists crypto businesses, exchanges, wallet providers, token issuers and other virtual asset service providers in obtaining the correct MiCA authorisation or registration from ASF. We assess the applicable MiCA service category, prepare the complete application file — including the AML/CFT policy, business plan and fit-and-proper documentation — and manage the ASF submission and correspondence throughout the review period.

MiCA replaced the previous VASP registration regime from 30 December 2024

Prior to MiCA, Romania operated a national VASP registration regime administered by ASF and ONPCSB. From 30 December 2024, MiCA became fully applicable — replacing national regimes with a harmonised EU CASP authorisation framework. Businesses previously registered as VASPs must assess whether they need to obtain a MiCA authorisation. Businesses that were not previously registered cannot rely on transitional provisions and must apply for authorisation before operating.

What Is a Crypto-Asset Service Provider (CASP) Under MiCA?

MiCA defines a Crypto-Asset Service Provider (CASP) as any legal entity that provides one or more of the following crypto-asset services on a professional basis to clients in the EU. A business that provides any of these services to Romanian or EU clients must be authorised as a CASP under MiCA — regardless of where the business is incorporated.

Custody & admin of crypto-assets

€125,000
Class 2 — full authorisation required

Operating a crypto exchange

€150,000
Class 3 — full authorisation required

Exchange: crypto for fiat

€125,000
Class 2 — full authorisation required

Portfolio management

€50,000
Class 1 — registration route available

Transfer services

€0 min. capital
Class 1 — registration route available

Placing of crypto-assets

€0 min. capital
Class 1 — registration route available

 

In addition to CASP services, MiCA regulates issuers of crypto-assets (including asset-referenced tokens — ARTs — and e-money tokens — EMTs). Issuers must publish a MiCA-compliant whitepaper and, for ARTs and EMTs with significant market impact, obtain ASF approval before issuance.

CASP Registration vs Full MiCA Authorisation — Which Route Applies?

MiCA provides two regulatory routes depending on the services provided and the business’s prior regulatory status. The correct route must be identified at the outset — applying under the wrong route wastes time and triggers an ASF rejection.

CASP Registration (lighter regime)

Available to:

  • Businesses providing only custody and administration of crypto-assets for clients
  • Credit institutions, investment firms and other regulated entities providing limited CASP services as ancillary activity
  • Smaller operators within defined thresholds

Minimum capital:

€50,000

Timeline:

3–4 months (indicative)

Full MiCA Authorisation

Required for:

  • Crypto exchanges (crypto-to-crypto or crypto-to-fiat)
  • Portfolio management services
  • Transfer services, placing and reception/transmission of orders
  • Any CASP providing services not covered by the registration route

Minimum capital:

€50,000 – €150,000 depending on  service class

Timeline:

6–12 months (indicative)

ASF — Romania’s MiCA Competent Authority

In Romania, ASF (Autoritatea de Supraveghere Financiară) is the national competent authority responsible for CASP authorisation and supervision under MiCA. ASF’s remit for crypto-assets sits alongside its existing role as regulator of capital markets, investment firms, insurance and private pensions.

ASF requirement Detail
Registered office in Romania The CASP must be incorporated as a Romanian legal entity (SRL or SA) with a registered office in Romania. A branch of a non-EU company cannot obtain a MiCA authorisation — only a fully incorporated EU entity qualifies.
Management body fit and proper All members of the management body (directors) must satisfy ASF’s fit and proper criteria — professional competence in crypto-asset markets, clean criminal record, no history of regulatory sanctions and sufficient reputation and integrity.
Shareholder fit and proper Shareholders holding a qualifying interest (10% or more of capital or voting rights) must also satisfy fit and proper criteria and be approved by ASF before the authorisation is granted.
AML/CFT compliance programme The CASP must have a documented AML/CFT policy and procedure manual compliant with both MiCA and Romanian AML Law 129/2019. An AML compliance officer must be designated. The programme must be operational before the authorisation is granted.
Business plan A detailed business plan must be submitted as part of the full authorisation application — describing the services, target market, revenue model, risk management framework, IT systems, outsourcing arrangements and a three-year financial forecast.
Own funds / capital requirement The minimum own funds must be subscribed and paid up before the application is submitted. Evidence of paid-up capital is required as part of the application file.
Governance and internal controls MiCA requires CASPs to have robust governance arrangements — including an internal audit function (or equivalent), a risk management framework, a compliance function and documented policies on conflicts of interest, client asset safeguarding and complaints handling.
Prudential insurance or guarantee For some CASP service classes, MiCA requires a professional indemnity insurance policy or an equivalent financial guarantee — covering potential claims from clients arising from negligent provision of crypto-asset services.

MiCA CASP Application Process — Step by Step

The MiCA CASP authorisation process in Romania follows ASF’s published procedure. Romania For Business SRL manages the complete process from eligibility assessment through to licence award and post-authorisation compliance briefing.

01

Eligibility & service classification

02

Company structure prepared

03

AML/CFT programme drafted

04

Business plan prepared

05

Capital confirmed & evidenced

06

ASF application submitted

07

ASF review & queries managed

08

Authorisation granted

Stage What happens
Eligibility assessment We review the planned crypto-asset services against the MiCA service classification framework and confirm whether the registration route or full authorisation is required. We identify the correct ASF application form and the minimum capital and governance requirements.
Company structure preparation We review the company structure — confirming that the Romanian SRL has the correct share capital, registered office and management body composition. If the company has not yet been incorporated, we coordinate the registration process.
AML/CFT programme We prepare an AML/CFT policy and procedure manual compliant with MiCA and Romanian AML Law 129/2019 — including risk assessment, CDD/EDD procedures, PEP and sanctions screening, transaction monitoring and ONPCSB reporting. The compliance officer is designated.
Business plan We prepare the ASF-format business plan — services description, target market, governance structure, IT systems overview, outsourcing arrangements, risk management framework and three-year financial projections.
Application submission The complete application file is assembled and submitted to ASF via the official portal. ASF acknowledges receipt and confirms the review timeline — typically 3 months for registration, 6–12 months for full authorisation.
ASF correspondence We manage all ASF queries and information requests during the review period. ASF can suspend the review clock if information is missing — prompt responses are essential to keep the process moving.
Authorisation and conditions When ASF grants the authorisation, we review the licence conditions with the client — identifying all ongoing obligations (capital maintenance, periodic reporting, AML programme updates, ASF supervisory levies).

AML/CFT Obligations — CASPs as Obliged Entities

Under Romanian AML Law 129/2019 (implementing the EU 5th AML Directive), crypto-asset service providers are obliged entities — subject to full AML/CFT compliance obligations. These are separate from, and in addition to, MiCA’s own governance requirements.

AML obligation What the CASP must implement
Business-wide AML risk assessment A documented analysis of the money laundering and terrorist financing risks specific to the CASP’s services — by client type, transaction type, geography and delivery channel. Must be updated whenever significant changes occur.
CDD / KYC procedures Full customer due diligence (CDD) on all clients — identity verification (name, address, date of birth, identity document), source of funds assessment and ongoing monitoring. Enhanced due diligence (EDD) for higher-risk clients, PEPs and clients from high-risk jurisdictions.
Transaction monitoring Automated or manual monitoring of client transactions for unusual patterns — large cash-equivalent transactions, rapid movement between wallets, geographic anomalies and patterns inconsistent with the client’s risk profile.
Travel Rule compliance CASPs transferring crypto-assets must comply with the FATF Travel Rule (implemented via EU TFR Regulation 2023/1113) — transmitting originator and beneficiary information with transfers above €1,000.
ONPCSB reporting Suspicious transaction reports (STRs) must be filed with ONPCSB (the Romanian AML authority) when a CASP suspects that a transaction or funds are related to money laundering or terrorist financing.
AML compliance officer A designated AML compliance officer with sufficient authority and independence. The compliance officer is personally responsible for the CASP’s AML programme and ONPCSB liaison. Criminal liability applies for non-compliance.

Criminal liability for AML non-compliance applies to CASP directors personally

In Romania, failure to implement AML procedures, failure to designate an AML compliance officer and failure to report suspicious transactions to ONPCSB can result in criminal liability for the CASP director personally — in addition to administrative fines and revocation of the MiCA authorisation. AML compliance is a pre-condition for CASP authorisation — not an afterthought.

CRYPTO / CASP LICENCE — ROMANIA

from €12,000
engagement fee

CASP LICENSING ENGAGEMENT INCLUDES:

  • Eligibility and service classification assessment — which MiCA category applies
  • CASP registration or full MiCA authorisation application — determined at scoping
  • Company structure review — SRL capital, shareholding and management requirements
  • Fit and proper declarations — shareholders, directors and UBO regulatory vetting
  • AML/CFT policy and procedure manual — ONPCSB and ASF requirement
  • Business plan and financial projections — required by ASF for full authorisation
  • Whitepaper review for asset issuers — MiCA Art. 5–55 compliance
  • ASF application preparation — all forms, annexes and supporting documentation
  • ASF submission and correspondence management throughout the review period
  • Licence condition compliance briefing — ongoing obligations post-award
  • Coordination with legal (AML/GDPR), accounting and company establishment teams

INDICATIVE ENGAGEMENT FEES

  • CASP registration — MiCA Class 1 (limited services, e.g. custody only) from €12,000
  • CASP full authorisation — MiCA Class 2–3 (exchange, brokerage, etc.) from €13,500
  • Asset issuer — crypto-asset / e-money token (MiCA whitepaper review) from €12,500
  • AML/CFT policy package — ONPCSB + ASF compliant from €3,000
  • Post-authorisation compliance review (annual) from €600
  • Regulatory authority (ASF) fees billed at cost

Fees confirmed in writing after eligibility assessment. MiCA is a live and evolving regulatory framework — requirements may change. ASF regulatory fees are billed at cost separately. Fees may be subject to Romanian VAT.

Frequently Asked Questions — Crypto / CASP Licence in Romania

MiCA (Markets in Crypto-Assets Regulation — EU Regulation 2023/1114) is the EU-wide regulatory framework for crypto-asset service providers and crypto-asset issuers. It became fully applicable across all EU member states, including Romania, on 30 December 2024. MiCA replaced previous national VASP registration regimes with a harmonised EU framework. In Romania, ASF (Autoritatea de Supraveghere Financiară) is the competent authority responsible for CASP authorisation under MiCA.

Any business providing crypto-asset services on a professional basis to clients in the EU must be authorised as a CASP under MiCA — regardless of where the business is incorporated. MiCA crypto-asset services include: custody and administration of crypto-assets, operating a crypto exchange, exchanging crypto for fiat, portfolio management, transfer services, placing of crypto-assets, reception and transmission of orders, and advice on crypto-assets. If your business provides any of these services to EU clients, you need a MiCA authorisation or registration.

MiCA provides a lighter registration route for businesses providing only custody and administration of crypto-assets as their sole service, and for certain regulated entities adding CASP services as an ancillary activity. All other CASPs — including crypto exchanges, portfolio managers and transfer service providers — require a full MiCA authorisation. The full authorisation requires higher minimum capital (€50,000–€150,000 depending on service class), a more detailed application file and a longer ASF review period (6–12 months).

The minimum own funds requirement under MiCA depends on the services provided. For businesses providing only custody and administration of crypto-assets (registration route), there is no minimum capital requirement. For full authorisation: transfer services, placing of crypto-assets and reception/transmission of orders — €50,000; portfolio management — €125,000; operating a crypto exchange or exchanging crypto for fiat — €150,000. Capital must be paid up and evidenced before the application is submitted to ASF.

Indicative timelines from application submission to ASF decision: CASP registration (lighter regime) — approximately 3–4 months; full MiCA authorisation — 6–12 months. ASF’s published review period under MiCA is 25 working days for completeness check, followed by 60 working days for the substantive assessment. However, ASF can suspend the review clock by requesting additional information — prompt and complete responses to ASF queries are essential to maintain the timeline.

MiCA includes transitional provisions for businesses that held a national VASP registration before MiCA’s application date. However, transitional provisions are time-limited and subject to national transposition rules. Romania For Business SRL assesses whether the transitional provisions apply to each client’s specific situation and advises on the timing and procedure for converting to MiCA authorisation. Do not assume the transitional period extends indefinitely — confirm the applicable deadline with a qualified adviser.

Yes — MiCA provides a passporting mechanism that allows a CASP authorised in one EU member state to provide services in all other EU member states, either on a cross-border basis or through a branch, following a notification to the home state competent authority (ASF in Romania’s case). This is one of the key commercial advantages of MiCA — a Romanian CASP authorisation provides an EU-wide service passport.

CASPs in Romania are obliged entities under Romanian AML Law 129/2019 — subject to full AML/CFT obligations including: business-wide AML risk assessment, customer due diligence (CDD/KYC) and enhanced due diligence (EDD) for higher-risk clients, transaction monitoring, Travel Rule compliance for transfers above €1,000, suspicious transaction reporting to ONPCSB, and designation of an AML compliance officer. AML compliance is a pre-condition for MiCA authorisation — not something that can be addressed after the licence is granted.

Yes. Post-authorisation compliance obligations include: annual ASF supervisory reporting, capital maintenance at the required level, AML programme annual updates, ongoing transaction monitoring, ONPCSB reporting, periodic fit-and-proper reassessments when management or ownership changes, and compliance with MiCA’s ongoing client disclosure requirements. Romania For Business SRL offers post-authorisation compliance support as a separate annual engagement.