Crypto / CASP Licence in Romania
MiCA authorisation · CASP registration · AML/CFT · ASF · VASP Romania
Crypto-asset service providers (CASPs) operating in Romania are regulated under EU Regulation 2023/1114 — the Markets in Crypto-Assets Regulation (MiCA) — which became fully applicable across all EU member states on 30 December 2024. MiCA replaces the previous VASP registration regime and introduces a unified EU-wide authorisation framework administered in Romania by ASF (Autoritatea de Supraveghere Financiară).
Romania For Business SRL assists crypto businesses, exchanges, wallet providers, token issuers and other virtual asset service providers in obtaining the correct MiCA authorisation or registration from ASF. We assess the applicable MiCA service category, prepare the complete application file — including the AML/CFT policy, business plan and fit-and-proper documentation — and manage the ASF submission and correspondence throughout the review period.
MiCA replaced the previous VASP registration regime from 30 December 2024
Prior to MiCA, Romania operated a national VASP registration regime administered by ASF and ONPCSB. From 30 December 2024, MiCA became fully applicable — replacing national regimes with a harmonised EU CASP authorisation framework. Businesses previously registered as VASPs must assess whether they need to obtain a MiCA authorisation. Businesses that were not previously registered cannot rely on transitional provisions and must apply for authorisation before operating.
What Is a Crypto-Asset Service Provider (CASP) Under MiCA?
MiCA defines a Crypto-Asset Service Provider (CASP) as any legal entity that provides one or more of the following crypto-asset services on a professional basis to clients in the EU. A business that provides any of these services to Romanian or EU clients must be authorised as a CASP under MiCA — regardless of where the business is incorporated.
€125,000
Class 2 — full authorisation required
€150,000
Class 3 — full authorisation required
€125,000
Class 2 — full authorisation required
€50,000
Class 1 — registration route available
€0 min. capital
Class 1 — registration route available
€0 min. capital
Class 1 — registration route available
In addition to CASP services, MiCA regulates issuers of crypto-assets (including asset-referenced tokens — ARTs — and e-money tokens — EMTs). Issuers must publish a MiCA-compliant whitepaper and, for ARTs and EMTs with significant market impact, obtain ASF approval before issuance.
CASP Registration vs Full MiCA Authorisation — Which Route Applies?
MiCA provides two regulatory routes depending on the services provided and the business’s prior regulatory status. The correct route must be identified at the outset — applying under the wrong route wastes time and triggers an ASF rejection.
CASP Registration (lighter regime)
Available to:
- Businesses providing only custody and administration of crypto-assets for clients
- Credit institutions, investment firms and other regulated entities providing limited CASP services as ancillary activity
- Smaller operators within defined thresholds
Minimum capital:
€50,000
Timeline:
3–4 months (indicative)
Full MiCA Authorisation
Required for:
- Crypto exchanges (crypto-to-crypto or crypto-to-fiat)
- Portfolio management services
- Transfer services, placing and reception/transmission of orders
- Any CASP providing services not covered by the registration route
Minimum capital:
€50,000 – €150,000 depending on service class
Timeline:
6–12 months (indicative)
ASF — Romania’s MiCA Competent Authority
In Romania, ASF (Autoritatea de Supraveghere Financiară) is the national competent authority responsible for CASP authorisation and supervision under MiCA. ASF’s remit for crypto-assets sits alongside its existing role as regulator of capital markets, investment firms, insurance and private pensions.
| ASF requirement | Detail |
|---|---|
| Registered office in Romania | The CASP must be incorporated as a Romanian legal entity (SRL or SA) with a registered office in Romania. A branch of a non-EU company cannot obtain a MiCA authorisation — only a fully incorporated EU entity qualifies. |
| Management body fit and proper | All members of the management body (directors) must satisfy ASF’s fit and proper criteria — professional competence in crypto-asset markets, clean criminal record, no history of regulatory sanctions and sufficient reputation and integrity. |
| Shareholder fit and proper | Shareholders holding a qualifying interest (10% or more of capital or voting rights) must also satisfy fit and proper criteria and be approved by ASF before the authorisation is granted. |
| AML/CFT compliance programme | The CASP must have a documented AML/CFT policy and procedure manual compliant with both MiCA and Romanian AML Law 129/2019. An AML compliance officer must be designated. The programme must be operational before the authorisation is granted. |
| Business plan | A detailed business plan must be submitted as part of the full authorisation application — describing the services, target market, revenue model, risk management framework, IT systems, outsourcing arrangements and a three-year financial forecast. |
| Own funds / capital requirement | The minimum own funds must be subscribed and paid up before the application is submitted. Evidence of paid-up capital is required as part of the application file. |
| Governance and internal controls | MiCA requires CASPs to have robust governance arrangements — including an internal audit function (or equivalent), a risk management framework, a compliance function and documented policies on conflicts of interest, client asset safeguarding and complaints handling. |
| Prudential insurance or guarantee | For some CASP service classes, MiCA requires a professional indemnity insurance policy or an equivalent financial guarantee — covering potential claims from clients arising from negligent provision of crypto-asset services. |
MiCA CASP Application Process — Step by Step
The MiCA CASP authorisation process in Romania follows ASF’s published procedure. Romania For Business SRL manages the complete process from eligibility assessment through to licence award and post-authorisation compliance briefing.
Eligibility & service classification
Company structure prepared
AML/CFT programme drafted
Business plan prepared
Capital confirmed & evidenced
ASF application submitted
ASF review & queries managed
Authorisation granted
| Stage | What happens |
|---|---|
| Eligibility assessment | We review the planned crypto-asset services against the MiCA service classification framework and confirm whether the registration route or full authorisation is required. We identify the correct ASF application form and the minimum capital and governance requirements. |
| Company structure preparation | We review the company structure — confirming that the Romanian SRL has the correct share capital, registered office and management body composition. If the company has not yet been incorporated, we coordinate the registration process. |
| AML/CFT programme | We prepare an AML/CFT policy and procedure manual compliant with MiCA and Romanian AML Law 129/2019 — including risk assessment, CDD/EDD procedures, PEP and sanctions screening, transaction monitoring and ONPCSB reporting. The compliance officer is designated. |
| Business plan | We prepare the ASF-format business plan — services description, target market, governance structure, IT systems overview, outsourcing arrangements, risk management framework and three-year financial projections. |
| Application submission | The complete application file is assembled and submitted to ASF via the official portal. ASF acknowledges receipt and confirms the review timeline — typically 3 months for registration, 6–12 months for full authorisation. |
| ASF correspondence | We manage all ASF queries and information requests during the review period. ASF can suspend the review clock if information is missing — prompt responses are essential to keep the process moving. |
| Authorisation and conditions | When ASF grants the authorisation, we review the licence conditions with the client — identifying all ongoing obligations (capital maintenance, periodic reporting, AML programme updates, ASF supervisory levies). |
AML/CFT Obligations — CASPs as Obliged Entities
Under Romanian AML Law 129/2019 (implementing the EU 5th AML Directive), crypto-asset service providers are obliged entities — subject to full AML/CFT compliance obligations. These are separate from, and in addition to, MiCA’s own governance requirements.
| AML obligation | What the CASP must implement |
|---|---|
| Business-wide AML risk assessment | A documented analysis of the money laundering and terrorist financing risks specific to the CASP’s services — by client type, transaction type, geography and delivery channel. Must be updated whenever significant changes occur. |
| CDD / KYC procedures | Full customer due diligence (CDD) on all clients — identity verification (name, address, date of birth, identity document), source of funds assessment and ongoing monitoring. Enhanced due diligence (EDD) for higher-risk clients, PEPs and clients from high-risk jurisdictions. |
| Transaction monitoring | Automated or manual monitoring of client transactions for unusual patterns — large cash-equivalent transactions, rapid movement between wallets, geographic anomalies and patterns inconsistent with the client’s risk profile. |
| Travel Rule compliance | CASPs transferring crypto-assets must comply with the FATF Travel Rule (implemented via EU TFR Regulation 2023/1113) — transmitting originator and beneficiary information with transfers above €1,000. |
| ONPCSB reporting | Suspicious transaction reports (STRs) must be filed with ONPCSB (the Romanian AML authority) when a CASP suspects that a transaction or funds are related to money laundering or terrorist financing. |
| AML compliance officer | A designated AML compliance officer with sufficient authority and independence. The compliance officer is personally responsible for the CASP’s AML programme and ONPCSB liaison. Criminal liability applies for non-compliance. |
Criminal liability for AML non-compliance applies to CASP directors personally
In Romania, failure to implement AML procedures, failure to designate an AML compliance officer and failure to report suspicious transactions to ONPCSB can result in criminal liability for the CASP director personally — in addition to administrative fines and revocation of the MiCA authorisation. AML compliance is a pre-condition for CASP authorisation — not an afterthought.
CRYPTO / CASP LICENCE — ROMANIA
engagement fee
CASP LICENSING ENGAGEMENT INCLUDES:
- Eligibility and service classification assessment — which MiCA category applies
- CASP registration or full MiCA authorisation application — determined at scoping
- Company structure review — SRL capital, shareholding and management requirements
- Fit and proper declarations — shareholders, directors and UBO regulatory vetting
- AML/CFT policy and procedure manual — ONPCSB and ASF requirement
- Business plan and financial projections — required by ASF for full authorisation
- Whitepaper review for asset issuers — MiCA Art. 5–55 compliance
- ASF application preparation — all forms, annexes and supporting documentation
- ASF submission and correspondence management throughout the review period
- Licence condition compliance briefing — ongoing obligations post-award
- Coordination with legal (AML/GDPR), accounting and company establishment teams
INDICATIVE ENGAGEMENT FEES
- CASP registration — MiCA Class 1 (limited services, e.g. custody only) from €12,000
- CASP full authorisation — MiCA Class 2–3 (exchange, brokerage, etc.) from €13,500
- Asset issuer — crypto-asset / e-money token (MiCA whitepaper review) from €12,500
- AML/CFT policy package — ONPCSB + ASF compliant from €3,000
- Post-authorisation compliance review (annual) from €600
- Regulatory authority (ASF) fees billed at cost

