How to Start a Crypto Exchange in the EU
At a glance
1. Service model: A matching venue, an exchange using its own capital, an order-routing broker and a custodial wallet are different MiCA services. [1]
2. Authorisation: Serving EU clients requires CASP authorisation for the services performed, unless a specific Article 60 route applies. [2]
3. Capital: Annex IV floors are EUR 50,000, EUR 125,000 or EUR 150,000 by service class; Article 67 may require more. [3]
4. Banking: A standard CASP holding client funds needs safeguarding arrangements and must place those funds with a credit institution or central bank under Article 70, subject to its exemption for EMIs, PIs and banks. [4]
5. Timing: MiCA gives authorities 25 working days to check completeness and 40 working days to assess a complete application, with a possible suspension for further information. [12]
If you are searching for how to start a crypto exchange in Europe, the first question is what the business will actually do. MiCA does not issue a single, all-purpose “exchange licence.” It authorises named crypto-asset services. An order book matching third-party buyers and sellers, a broker selling from its own inventory and an app routing orders to someone else are different businesses under the regulation. [1, 2]
That distinction sets the capital floor, the operating rules and the contents of the application. It also decides when custody, client money and banking become critical. This guide follows the order in which a founder needs to make those decisions.
1. Define the exchange model before the licence
Under MiCA, a trading platform is a multilateral system bringing together third-party buying and selling interests under its rules. Exchange of crypto-assets for funds or other crypto-assets is a purchase or sale with a client using the provider’s own capital. These are separate services, even though customers might call both products an exchange. [1]
| Customer experience | Likely MiCA service | Capital class |
|---|---|---|
| Buyers and sellers meet in an order book | Operation of a trading platform | Class 3 |
| The company quotes a price and trades against its own inventory | Exchange for funds or for other crypto-assets | Class 2 |
| The app passes a customer order to another provider | Reception and transmission of orders | Class 1 |
| The company completes a trade on the client’s behalf | Execution of orders on behalf of clients | Class 1 |
| The app controls clients’ assets or private keys | Custody and administration, in addition to any trading service | At least Class 2 |
This is an indicative mapping, not an authorisation decision. A real product may perform several services at once. The precise scope depends on who contracts with the customer, who sets the price, whose capital is used, who controls the assets and where orders are executed. MiCA’s Article 3 definitions and Annex IV classes are the basis for the mapping. [1, 3]
A trading platform operator cannot deal on its own account on the platform it operates, including through a separately authorised exchange service. MiCA permits matched principal trading only with client consent and subject to supervisory monitoring. The planned liquidity model therefore belongs in the first architecture discussion, not in a late compliance review. [6]
2. Establish the authorisation and the EU entity
Article 59 requires a person providing crypto-asset services in the Union to be authorised as a crypto-asset service provider under Article 63, or to be a qualifying financial entity allowed to provide the relevant services under Article 60. An Article 63 provider must have its registered office in a member state where it carries out at least part of its services, effective management in the Union and at least one EU-resident director. [2]
A foreign incorporation alone is not a route to EU customers. After the MiCA transition expired on 1 July 2026, ESMA stated that an entity providing crypto-asset services to EU clients without a MiCA licence is in breach of EU law and must stop. The narrow reverse solicitation exception does not support an ordinary customer-acquisition strategy. [7]
The home member state matters because its authority assesses and supervises the application. Once authorised, the provider can use MiCA’s cross-border route for its authorised services. Article 65 requires a notice to the home authority identifying the host states, services and intended start date. The provider may begin after receiving the home authority’s communication, or at the latest on the fifteenth calendar day after submitting the information. [2, 8]
Choose the home state for a credible operating presence and supervisory relationship. Moving a paper company to the lowest advertised fee will not solve a model whose decision-makers, controls or banking sit elsewhere. That is a structuring judgement based on the Article 59 location and management requirements, not a separate statutory test. [2]
3. Size the capital to the services and the overheads
MiCA Article 67 requires prudential safeguards equal to at least the higher of the Annex IV floor for the authorised services or one quarter of the previous year’s fixed overheads. A provider in its first year uses projected fixed overheads from its application. The safeguards can take the form of eligible own funds, qualifying insurance or a comparable guarantee, or a combination. [3]
| Class | Services that place a firm in the class | Annex IV floor |
|---|---|---|
| Class 1 | Order execution, placement, transfers, order reception and transmission, advice, portfolio management | EUR 50,000 |
| Class 2 | Class 1 services plus custody or exchange against the provider’s own capital | EUR 125,000 |
| Class 3 | Class 2 services plus operation of a trading platform | EUR 150,000 |
These are regulatory floors, not a total launch budget and not DM Strategy fees. Platform build, security, staff, legal work and liquidity arrangements add to the cash required. The fixed-overheads test can also produce a prudential requirement above the floor. [3]
There is a useful commercial consequence: a matching venue carries a EUR 150,000 floor, while a broker routing customer orders may start in Class 1. The cheaper class is only available if the actual service stays inside it. Labelling a matching venue as a broker does not change the Article 3 definition. [1, 3]
4. Design custody, client funds and banking together
A crypto-asset service provider that holds clients’ crypto-assets or access credentials must safeguard client ownership rights and prevent use of those assets for its own account. If a standard CASP holds client funds other than e-money tokens, Article 70 generally requires it to protect those funds and place them with a credit institution or central bank by the end of the next business day, in a separately identifiable account. The client-funds provisions do not apply to CASPs that are themselves EMIs, payment institutions or credit institutions. [4]
For custody, Article 75 adds a client agreement, a register of positions, a custody policy and separation of client holdings from the provider’s own assets. It also restricts a custodian using another custodian to a provider authorised under Article 59, with client notice. These requirements affect wallet architecture, reconciliation and outsourcing before the product is built. [9]
This is why banking cannot be treated as an account-opening task after the licence. If the exchange expects fiat deposits and withdrawals, the application must explain the movement of client funds and the safeguards. Article 62 explicitly asks for the procedure for segregating client assets and funds. A banking partner that cannot support the proposed flow leaves a gap in the operating model. [4, 5]
A CASP may itself provide related payment services, or use a third party, only where the provider of those payment services is authorised under PSD2. Where the model uses e-money tokens for custody or transfers, a separate PSD2 analysis may also be needed. The EBA’s transition for those EMT payment activities ended on 2 March 2026. [4, 10]
5. Assemble the application around how the business will operate
Article 62 requires the applicant to submit a programme of operations, evidence of prudential safeguards, governance and management information, ownership details, risk and AML controls, ICT and security documentation, client-asset segregation procedures and complaints processes. It then adds service-specific material for custody, platforms, exchange, order execution and transfers. [5]
For a trading platform, the service-specific file includes operating rules and a system to detect market abuse. Article 76 requires rules for admission of crypto-assets, participation, fair and orderly trading, settlement and suspensions, as well as resilient systems that can detect or prevent abuse. These documents have to describe the live product, not an imagined compliant version of it. [5, 6]
For a business trading with customers from its own capital, Article 62 asks for its non-discriminatory commercial policy and price methodology. Article 77 requires the provider to publish a firm price or pricing method and applicable limits. ESMA has said the published information should be accessible without registration and let a customer anticipate the exchange price. [5, 11]
The clean application sequence is to freeze the service map, settle the legal entity and control structure, establish capital and banking feasibility, document custody and payments, then draft the Article 62 file against the product that will actually launch. Each step resolves an item the authority is required to assess. [2, 3, 4, 5]
6. Plan around the regulatory clock
Under Article 63, the authority has 25 working days from receipt to assess whether an application is complete. Once it confirms completeness, it has 40 working days to assess the applicant and issue a reasoned decision. A request for further information during that assessment can suspend the clock for up to 20 working days. [12]
Those are procedural windows, not a promise that an exchange can launch in 65 working days. They exclude the time needed to build the product, arrange capital and banking, complete the file, respond to questions and begin any required cross-border notification. If the application is incomplete, the authority sets a deadline for missing information and may refuse to review a file that remains incomplete. [12]
After authorisation, the provider can offer only the services specified in its authorisation. Adding custody to a broker model later is a scope change that requires an extension request under Article 59(8), not simply an update to the website. [2]
7. Check the two boundary cases before launch
Two common extensions of an exchange model require separate analysis: e-money tokens and services delivered by third-country entities. A MiCA authorisation covers specified crypto-asset services; it does not automatically authorise payment services, and an EU licence cannot be used as a front for an unauthorised non-EU operator serving EU clients. [2, 7, 10]
If the exchange handles e-money tokens, test whether its custody or transfer activity is also a payment service under PSD2. If a non-EU group company supplies custody or another regulated service to EU clients, test who legally and operationally provides that service. ESMA has said the restriction on unauthorised third-country service provision applies in business-to-business structures as well. [7, 10]
These issues are easier to solve while the product and entity structure can still change. They are expensive to discover after an application has been filed or a banking partner has reviewed the group.
The order of decisions before filing
- Write the customer journey and asset flows from deposit to withdrawal. Identify every legal entity, custodian and payment provider touching the flow.
- Map each activity to Article 3 and select the service scope that matches the product. Decide whether the business matches third-party orders, trades with customers from its own capital, routes orders or combines services.
- Choose the home member state and establish real governance and effective management in the Union.
- Calculate the Article 67 safeguards from both the Annex IV floor and projected overheads. Budget separately for operations, technology and partner onboarding.
- Confirm a workable arrangement for client funds, custody, fiat settlement and any related PSD2 payment services.
- Prepare the Article 62 evidence and the service-specific policies, then file only when the product and documentation describe the same operation.
Frequently asked questions
Do I need a MiCA licence to start a crypto exchange in the EU?
Usually yes. A business providing crypto-asset services in the Union must be authorised for the services it performs under Article 63, unless it qualifies for a specific Article 60 route. The customer-facing label “exchange” is insufficient; a matching venue, broker, custodian and order router may require different authorised services. [1, 2]
What is the difference between a crypto trading platform and a broker?
A trading platform brings together third-party buying and selling interests under its rules. A broker exchanging crypto-assets for funds or other crypto-assets concludes purchases or sales with clients using its own capital. MiCA treats them as different services, with different operating rules and Annex IV capital floors. [1, 3, 6]
How much regulatory capital does an EU crypto exchange need?
The Annex IV floor is EUR 150,000 for an operator of a trading platform, EUR 125,000 for exchange against the provider’s own capital or custody, and EUR 50,000 for Class 1 services such as order routing. Article 67 requires safeguards equal to the higher of that floor or one quarter of fixed overheads. [3]
Can I operate an EU exchange from a company outside the EU?
A non-EU company cannot use its foreign incorporation as a substitute for MiCA authorisation when it serves EU clients. An Article 63 provider needs a registered office in a member state, effective management in the Union and an EU-resident director. ESMA says unauthorised EU-facing services after 1 July 2026 breach EU law. [2, 7]
Can the exchange trade against its own order book?
No. Article 76 prohibits a provider operating a crypto-asset trading platform from dealing on its own account on that platform, including where it also provides an exchange service. Matched principal trading is treated separately and is allowed only with client consent and supervisory monitoring. The liquidity model therefore needs to be fixed before filing. [6]
How long does MiCA authorisation take?
Article 63 gives the authority 25 working days to check whether an application is complete and 40 working days to assess a complete application. A further-information request can suspend the assessment for up to 20 working days. Preparation, remediation and banking arrangements sit outside those statutory clocks, so they are not a total launch timeline. [12]
What banking arrangement does a crypto exchange need?
A standard CASP holding client funds other than e-money tokens must place them with a credit institution or central bank by the end of the next business day in a separately identifiable account. Article 70 exempts CASPs that are themselves EMIs, payment institutions or credit institutions from its client-funds provisions. The precise arrangement follows the entity and fiat flow. [4]
Can one MiCA authorisation serve customers across the EU?
Yes, for the specific services covered by the authorisation. Article 65 requires the provider to notify its home authority of the host member states, services and proposed start date. The provider may begin after the authority communicates the notice, or at the latest on the fifteenth calendar day after submitting it. [2, 8]
Related DM Strategy guides
- Where to licence a crypto exchange: Compare the EU route with Switzerland, Dubai, the US, Canada and Panama
- Why crypto businesses get rejected by banks: Plan the banking file before structure and licensing are fixed
- Stablecoins under MiCA: Check the PSD2 and e-money token overlap
- Latvia EMI and CASP licensing: Review a specific home-state route
Key primary sources
| Ref | Primary source |
|---|---|
| 1 | MiCA Article 3, service definitions: source |
| 2 | MiCA Article 59, authorisation and EU establishment: source |
| 3 | MiCA Article 67 and Annex IV, safeguards and capital classes: source 1; source 2 |
| 4 | MiCA Article 70, safekeeping client assets and funds: source |
| 5 | MiCA Article 62, application contents: source |
| 6 | MiCA Article 76, trading platform rules: source |
| 7 | ESMA, end of MiCA transitional periods, 17 April 2026: source |
| 8 | MiCA Article 65, cross-border services: source |
| 9 | MiCA Article 75, custody and administration: source |
| 10 | EBA, PSD2 and MiCA e-money token interplay: source |
| 11 | MiCA Article 77 and ESMA Q&A 2181, exchange pricing: source 1; source 2 |
| 12 | MiCA Article 63, application assessment: source |
Disclaimer
This article is for information only and is not legal or regulatory advice. The required permissions depend on the actual service and may change as the product changes.
DM Strategy works with founders on the structure, licensing and banking decisions behind a crypto exchange. If you are planning an EU launch, book an introductory call at dmstrategy.io to map the service model before committing to a jurisdiction or a build.

.jpg)