Buying a MiCA licensed company is increasingly pitched as the fast lane into European crypto. When evaluating a MiCA licence for sale, however, an acquirer has to look past the asking price and assess what regulatory, tax and compliance liabilities come attached. The market conditions behind the pitch are real enough. When the transitional period under the Markets in Crypto-Assets Regulation (MiCA) closed on 1 July 2026, more than 80% of the firms that had operated under earlier national regimes did not make it into the licensed market. The few hundred that did now handle the great majority of European trading activity.
For a company that wants to serve European clients and does not yet hold authorisation, two routes remain: apply for a new licence, or acquire a company that already holds one. Buying is often presented as the shorter path. The licence is already granted, the business is already running, and the clients are already onboarded.
But a MiCA licence is not something that can simply be bought off the shelf. The change of ownership must be approved by the national competent authority. What the buyer actually acquires depends on questions that are anything but standard: which of the ten crypto-asset services the authorisation covers, what anti-money laundering (AML) and know-your-customer (KYC) history comes with the company, and whether its technology meets the operational-resilience requirements. Access to banking does not transfer automatically either. What follows is what a buyer has to check before relying on the shortcut. It begins not with what the target is worth, but with whether the acquisition can lawfully happen at all.

Step 1: Sanctions screening.
Can you buy at all? The first constraint is not commercial but political. Under the EU’s sanctions regimes, a crypto-asset service provider (CASP) established in a member state may not be owned or controlled by Russian or Belarusian nationals or residents, and such persons may not sit on its governing body. Put simply, the target’s shareholders, beneficial owners and board members must not be Russian or Belarusian nationals or residents. The exception is where they also hold EU, European Economic Area (EEA) or Swiss nationality, or a valid residence permit in one of those states.
For a buyer this sets a threshold question before any other. Is the acquirer a permitted holder? And is the target’s ownership, as it stands and as it stood, free of any prohibited holder who has not genuinely exited? A share transfer to a permitted name does not help if the original owner keeps effective control. The regulator, and the buyer, must look through to the ultimate beneficial owner. Where the residence-permit exemption is relied on, it has to be documented and the permit’s validity monitored. A lapsed permit puts the holder back within the prohibition.
Step 2: CASP acquisition approval under Articles 83 and 84
Buying a licensed CASP is not, in law, buying a company that happens to hold a licence. It is acquiring a permission the regulator granted to specific owners, and the regulator has the right to assess the new ones and to oppose them. This is the mechanism that most directly undercuts the idea that buying is the simple route. The acquisition reopens a supervisory assessment of who stands behind the firm.
The trigger is the qualifying holding: any direct or indirect stake of at least 10% of the capital or voting rights, or any holding that allows significant influence over the firm’s management. A proposed acquirer must notify the competent authority in advance. Notification is required again at each further threshold: 20%, 30%, 50%, or where the CASP would become the acquirer’s subsidiary. The transaction is typically structured as a share deal in which this clearance is the condition for closing.
Once notified, the authority acknowledges receipt within two working days and then has 60 working days to assess the proposed acquisition. It weighs five criteria under Article 84: the reputation of the acquirer; the reputation and experience of anyone who will direct the business as a result; the financial soundness of the acquirer; whether the CASP will remain able to meet its MiCA obligations after the change; and whether the transaction raises money-laundering or terrorist-financing concerns. The authority may oppose only on these grounds, or where the information supplied is incomplete or false.
Two practical points follow. First, the clock is real but not the whole story. As with authorisation, the assessment can be paused for further information, so a buyer should plan for longer than 60 working days and engage the regulator before filing rather than after. Second, closing without clearance is not a technicality to be regularised later. It exposes the parties to supervisory sanctions, which depending on national law may include suspension of voting rights or unwinding of the transaction. It also puts the very asset being bought, the authorisation, at risk.
One exception is worth noting, because it changes the analysis entirely. Where the CASP is one of the financial institutions listed in Article 60, such as a credit institution, an investment firm under the Markets in Financial Instruments Directive (MiFID II) or an electronic money institution, the qualifying-holding assessment runs under that entity’s own prudential regime, not the CASP rules. A buyer should establish at the outset which regime the target sits in.
Step 3: AML history comes with the licence
In a share deal, the company’s past comes with it. Fines that have not yet been imposed, inspections that have not yet concluded, breaches that have not yet surfaced: all of it transfers to the new owner. Nowhere is that risk more concentrated than in AML compliance, because this is where regulators act most readily.
So the first questions are backward-looking. Has the target been inspected, and what did the regulator find? Is there open correspondence with the supervisor, such as remediation plans, warnings or information requests? Have there been fines or ongoing proceedings, here or in another jurisdiction? What do internal and external audit reports say, and were the findings actually fixed? A seller’s assurance that “everything is compliant” is worth exactly as much as the paper trail behind it.
Then the present state. Do customer due diligence, transaction monitoring and screening against sanctions lists genuinely function, or do they exist only on paper? Does the firm meet the Travel Rule? That requirement, in force since December 2024, means identifying information on sender and recipient must accompany every crypto transfer, with no minimum threshold. Gaps here are not hypothetical exposure. They are the most likely source of the fine the buyer will end up paying for conduct that happened before the deal.
The practical consequence belongs in the deal itself. What due diligence uncovers should be priced in. What it cannot rule out should be covered by warranties and indemnities against pre-closing conduct.
Step 4: What the CASP authorisation covers: services and tokens
Before examining what the authorisation covers, confirm that it exists and is live. Check that it has not lapsed or been withdrawn, that no enforcement or wind-down proceedings are pending, and that the company does not appear on the register of non-compliant entities kept by the European Securities and Markets Authority (ESMA).
A MiCA authorisation is not a single, uniform permission. MiCA defines ten distinct crypto-asset services, and a CASP is authorised only for those its regulator has approved. The first check is therefore a simple comparison. Does the scope of the target’s authorisation match what the buyer actually intends to do with it? A firm authorised for exchange does not become a custodian by being acquired. The missing service has to be added through a fresh regulatory approval, with the time and cost that implies. Buying the wrong scope means buying only part of what was needed.
The second check runs in the opposite direction. Is everything the target does, and everything it lists, covered by law at all? Every token the target touches falls into one of four boxes: a financial instrument under MiFID II; an e-money token (EMT), which only credit institutions and electronic money institutions may issue; an asset-referenced token (ART), with its own authorisation regime; or other crypto-assets under MiCA, which carry whitepaper and notification requirements. A CASP distributing EMTs or ARTs must verify the issuer’s status. A token that fits none of the boxes lawfully is a red flag. A target running services or listing tokens outside its authorised perimeter is not an asset with an irregularity. It is an enforcement case that has not happened yet.
The practical exercise is an inventory. List every service the target provides and every token it lists or touches, and map each against the authorisation and the applicable regime. What that inventory shows determines the deal. Gaps that can be fixed, such as a token to delist or a service to wind down before closing, are matters of timing and price. But a business whose model depends on activity outside its authorised perimeter is not a bargain waiting for a discount. A violation bought cheaply is still a violation, and it becomes the buyer’s on day one. Some findings do not reduce the price. They end the deal.
Step 5: Operational resilience under DORA
For a crypto platform, technology is not infrastructure supporting the business. It is the business. The Digital Operational Resilience Act (DORA), which has applied to CASPs since January 2025, treats it that way. It makes the firm’s ability to withstand failures, attacks and outages a regulatory obligation, with board-level responsibility, incident-reporting deadlines and mandatory testing. A buyer should read the target through the same lens. Weaknesses here are inherited in exactly the same way as AML breaches, and, unlike a policy gap, a compromised platform can destroy the business before any regulator gets involved.
The backward look comes first, as it did with AML. What incidents has the target had, whether outages, breaches or losses of client assets, and were the major ones reported to the regulator within DORA’s deadlines? What did post-incident reviews find, and were the fixes actually made? An unreported major incident is a double problem: the vulnerability itself, and the reporting breach sitting on top of it.
Then the present state. Does the firm have a genuine information and communication technology (ICT) risk-management framework owned by the board, or a folder of policies nobody follows? How are clients’ crypto-assets protected? How are private keys stored, who can access them, and what happens if a key holder leaves or a system fails? Can the platform keep operating, and can clients reach their assets, through a core-system failure or a sudden market shock? Has resilience actually been tested, and what did the tests show?
Third parties deserve their own pass. Most crypto platforms run on rented rails: cloud hosting, custody technology, market data, blockchain infrastructure. DORA holds the firm fully responsible for its ICT providers. It requires a register of those arrangements, due diligence on critical ones, and specific contractual terms including audit and exit rights. A target that cannot produce a current register, or whose critical contracts lack those terms, has a remediation project priced in euros and months. A concentration risk, meaning the whole platform standing on one irreplaceable provider, is a finding in its own right.
The dividing line matters more here than in any other step. Most DORA findings are remediation items with a price, but not all of them. Client keys that cannot be securely migrated, a platform whose security debt would take years to repair, an incident history the seller cannot explain: these are not discounts. They go to whether the asset is worth having at all.
Step 6: Data protection under GDPR
A crypto platform’s client base is a database of verified identities tied to financial behaviour: names, documents, wallet addresses, transaction histories. Under the General Data Protection Regulation (GDPR), that database is not simply an asset that transfers with the shares. It is a set of obligations, and the buyer takes them over along with any breaches of them that have already happened.
Has the target had personal-data breaches, and were they notified to the supervisory authority and, where required, to the affected clients? Is there open correspondence with a data-protection authority, such as complaints, inquiries or orders? How has the firm handled data-subject requests, particularly access and erasure? Those sit awkwardly in a business that must also retain records for AML purposes. A pattern of ignored requests is a live liability, not a housekeeping issue.
The present state centres on documentation and processors. The target should be able to produce its records of processing, its privacy notices, and its agreements with the processors it relies on, cloud hosting above all. It should also be able to say where client data is physically stored. For any storage or access outside the EU, the transfer mechanism relied on, whether an adequacy decision or standard contractual clauses, should be identified and documented, not assumed. The overlap with the previous step is deliberate. The same cloud contract that DORA examines for resilience, GDPR examines for data protection, and a gap usually shows up in both.
One obligation looks forward rather than back. The share purchase itself changes nothing for the data. The company remains the same controller, and clients need not be notified merely because the shareholder changed. Obligations arise only if the buyer chooses to change how data is handled after closing: merging the target’s client database with its own, moving data onto group infrastructure, or using it for new purposes. Most buyers plan at least some of this, since integration is usually the point of the deal. Each step has legal preconditions. A data protection impact assessment is likely required where client databases are merged, privacy notices will need updating, and in some cases fresh legal bases will be needed. Folding the target’s data into the group is an integration task with legal prerequisites, not just a technical one.
Step 7: Tax reporting duties and inherited exposure
Tax is where a share deal’s logic bites hardest. Every under-declared euro, every mis-filed return, every position the tax authority later disagrees with stays with the company, and therefore passes to the buyer.
The newest obligation comes from the eighth amendment to the Directive on Administrative Cooperation (DAC8), which extends EU tax reporting to crypto-assets. Since 1 January 2026, reporting crypto-asset service providers must collect identifying information on their users and report their transactions to the tax authorities, which exchange the data across member states. The first reports, covering 2026, are due in 2027. For a buyer this is a readiness question. Has the target built the collection and reporting pipeline, and is the data it gathers accurate? Failures here will surface on the new owner’s watch.
Alongside the new sits the perennial. Value-added tax (VAT) deserves particular attention, because crypto platforms sit in an awkward spot. The exchange of crypto-assets for fiat currency is VAT-exempt as a financial service, but most platforms also provide taxable services. A business with mixed activities may recover input VAT only in proportion to its taxable side. Over-recovery is a recurring error in the sector. It produces exactly the kind of quiet, accumulating liability that surfaces in a later audit, payable, by then, by the buyer.
Beyond VAT, the review should cover the positions that follow from a crypto business model. How are the firm’s own crypto holdings valued and taxed, including unrealised gains and losses and the deferred tax they generate? Was any staff or management remuneration paid in crypto-assets properly treated for payroll-tax purposes? Where the business is run across borders, does the location of people and decision-making create taxable presence in other jurisdictions, and would intra-group pricing withstand scrutiny?
None of this is exotic. It is standard tax due diligence applied to an unusual asset class. What is different is the state of practice. A target may never have been through a tax audit, and the absence of findings is not the same as the absence of problems.
Step 8: Governance and the people behind the licence
A CASP’s authorisation was granted not only to a company but to a set of people the regulator vetted: board members, executives, key function holders. MiCA requires them to be of good repute and to have the knowledge, skills and experience for the role, individually and as a body. That standard is continuous. Changes in management after licensing go back to the regulator for assessment, just as changes in ownership do. A buyer planning to install its own leadership should treat those appointments as regulatory filings with lead times, not internal decisions to announce after closing.
Due diligence on the target’s side starts with the register of who actually holds which role, and whether anyone in it would struggle to pass a vetting today because of past insolvencies, criminal proceedings or regulatory sanctions in any jurisdiction. It continues with how the firm is actually run. Does the board meet and minute its decisions? Does the compliance function have standing and staff? Do internal audit findings get acted on? A weak compliance culture is the common root of the problems the earlier steps look for. Where diligence finds it, the buyer should assume the specific findings are a sample, not the full population.
Two roles deserve individual attention: the compliance officer and the money laundering reporting officer (MLRO). They hold the institutional knowledge and the working relationship with the regulator. Their departure at closing would leave the buyer running a regulated business without the people who understand its obligations. Retention arrangements for key compliance staff, and where useful a handover period for departing founders, belong in the transaction documents, not in post-closing improvisation.
Step 9: Intellectual property and key contracts
The question sounds elementary, but in this sector it rarely is. Does the target actually own its platform? Crypto businesses are typically built fast, by founders and contractors, and early code is often written before anyone thought about assignment clauses. If a developer never signed over rights to what they wrote, the company is running on software it does not fully own. The person who does own it may be the departing founder. Due diligence should confirm that employment and contractor agreements assign intellectual property to the company, that the chain is complete back to the earliest code, and that trademarks and domains sit with the company rather than with an individual. Open-source components deserve a check of their own. Most platforms use them, and some licences impose obligations that sit badly with proprietary commercial software.
Ownership, however, is only half the picture, because much of a modern platform is not owned at all. It is rented. A typical CASP runs on external rails at every layer: liquidity providers and market makers supplying the order book, market-data feeds, KYC and transaction-monitoring vendors, payment gateways, custody technology, cloud and blockchain infrastructure. Most of it is connected through application programming interfaces (APIs) under contracts the buyer inherits. The due-diligence exercise is to map these dependencies and read the underlying agreements, asking three questions of each. Can the counterparty walk away, because the contract contains a change-of-control clause that lets it terminate or renegotiate when the shares change hands? What happens to the business if this connection fails? A platform can be fully licensed and fully compliant and still unable to trade the day its main liquidity provider disconnects. And do any exclusivity or non-compete terms bind the target in ways that collide with the buyer’s own plans?
Banking relationships belong on the same map, and at the top of it. Access to accounts and payment rails is not automatic for a crypto firm. If part of the target’s value is that it is banked, the buyer needs to know whether that survives the change of ownership, or whether the bank, too, has a consent right and an opinion about the new shareholder.
The last set of contracts is the largest: the client terms. They should permit the platform to be operated by a new owner without re-papering every relationship. They should also comply with consumer-protection rules, because a defect in the standard terms is a defect multiplied by the entire client base.
Step 10: Integration after closing
Closing changes the shareholder. It does not pause the company’s obligations. Reporting deadlines, capital requirements and notification duties keep running from day one, whether or not the integration is ready. Material changes that typically follow an acquisition, from new directors to a new name to changes in the programme of operations, must be notified to the regulator, several of them for approval in advance. An integration plan built on internal deadlines alone will collide with regulatory ones.
The substance of integration deserves the same discipline. Two compliance frameworks have to be reconciled, and the working rule is to harmonise upward, to the stricter standard. Client-facing changes need care, because the value of the deal sits largely in the client base, and that is easiest to lose in a badly handled first quarter.
Conclusion: Buy a MiCA Licence in Europe or Apply for Your Own?
The idea that buying a licensed company is the easy way into the European crypto market rests on a misreading of what a licence is. A MiCA authorisation is not an asset that changes hands like a trademark. It is a regulator’s ongoing permission, granted to specific people running a specific business in a specific way. An acquisition puts every element of that sentence back on the table. The sanctions screen decides whether the deal can happen. The change-of-control assessment reopens the regulator’s judgment. And everything the company did before closing, from its compliance record and tax positions to its incidents and contracts, arrives with the shares.
None of this makes acquisition the wrong route. It makes it a route with the same destination requirements as the other one. A buyer who acquires a clean target still needs what a fresh applicant needs: qualified management, a working compliance framework, resilient technology and the capital to sustain them. The licence will only remain valid as long as those are in place. For a company deciding whether to buy a MiCA licence in Europe or apply for its own, the real difference is smaller than the market assumes. One route starts with an assessment of an application, the other with an assessment of an acquirer, and both end in the same supervision.
That is worth remembering when weighing the alternative. Applying fresh means preparing in advance rather than inheriting: no legacy exposure, no historical due diligence, a scope tailored to the actual business plan. Among the jurisdictions worth considering, Latvia has positioned itself deliberately. Pre-licensing consultations with the regulator are free, the application fee is among the lowest in the EU, and ongoing supervision costs are among the lowest in Europe, in a jurisdiction that does not tax profits until they are distributed. For a buyer whose due diligence keeps turning up findings, the fresh application is not the slow option. It is the clean one.
Whichever route is taken, the discipline is the same: know exactly what is being acquired, price what can be fixed, and walk away from what cannot. In a market of a few hundred licence holders, scarcity will keep tempting buyers to move fast. The ones who do well will be those who remember that they are not buying a licence. They are buying everything the licence sits on.
-
Tradersdna is a leading digital and social media platform for traders and investors. Tradersdna offers premiere resources for trading and investing education, digital resources for personal finance, market analysis and free trading guides. More about TradersDNA Features: What Does It Take to Become an Aggressive Trader? | Everything You Need to Know About White Label Trading Software | Advantages of Automated Forex Trading