← Regulations / European Union / Operating Models / Custodial SaaS

Custodial wallet / SaaS in European Union

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in European Union with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • CASP authorization (Class 1 – Custody) required from home Member State NCA under MiCA (EU 2023/1114)
  • Minimum capital of €50,000 for custody service class
  • Travel Rule applies at EUR 0 threshold under Transfer of Funds Regulation (recast) – no de minimis; originator/beneficiary info must accompany all transfers
  • Full AML/CFT program required under AMLD6 – CDD, transaction monitoring, SAR filing to local FIU
  • SaaS provider remains the CASP and bears primary AML obligations; white-label client may be a VASP in its own right and must perform its own CDD if it has custody or control
  • DAC8 (effective 2026) adds tax reporting obligations on crypto transactions for EU-based CASPs
  • Asset segregation mandatory – client assets held on trust
  • Supervision by home Member State NCA (e.g. AMF, BaFin, CNMV, CBI) with EU-wide passporting via notification (20 business days)

Key Restrictions

  • Must be authorized as a CASP under MiCA in home Member State; no pure registration pathway – full authorization required
  • Client cryptoassets must be segregated from operator's own assets and held on trust
  • No de minimis threshold for Travel Rule – applies to all transfers regardless of value
  • White-label client relationship must be carefully structured to avoid creating an unauthorized VASP on the client side; SaaS provider remains the regulated CASP
  • Transition periods vary by Member State (e.g. Germany until June 2026, France ended March 2025) – operator must check applicable timeline in each target state
  • Passporting requires 20 business day notification period to home NCA before operating cross-border
  • DORA and NIS2 cybersecurity audit requirements may apply to critical infrastructure / SaaS operators

Key Risks

  • Supervisory fragmentation risk: divergent enforcement practices among NCAs (ESRB identified 8 NCAs without finalized enforcement guidelines as of Q1 2026)
  • Liability ambiguity in white-label SaaS arrangements – unclear which entity (SaaS provider vs. white-label client) bears primary Travel Rule / AML responsibility for end-user transactions
  • Enforcement precedent emerging: the French AMF issued a cease-and-desist against an unregistered non-EU CASP in Jan 2026; Dutch AFM warned 14 firms for incomplete applications in 2026
  • Transition-period variability creates market-access traps if operator relies on grandfathering in a Member State with a short window
  • Cross-border supervision and coordination gaps may lead to duplicative or conflicting NCA requests
  • Operational risk if proof-of-reserves is not yet a standardized MiCA requirement but market practice/ESMA guidance may evolve to expect it

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

MiCA Regulation (EU 2023/1114) (2023) — Comprehensive CASP authorization, token issuance, white paper requirements — fully effective Dec 30, 2024

licensing 20% confidence

VASP: CASP authorization under MiCA via home NCA. 9 service classes: custody (EUR 50K), trading platform (EUR 150K), exchange (EUR 125K), order execution (EUR 50K), placing (EUR 50K), reception/transmission (EUR 50K), advice (EUR 50K), portfolio mgmt (EUR 50K), transfer services (EUR 50K). Prudential: higher of fixed minimum or 1/4 prior year fixed overhead.

licensing 20% confidence

CUSTODY: CASP Class 1 — EUR 50,000 minimum capital. Asset segregation mandatory. Client assets held on trust.

licensing 20% confidence

Transfer of Funds Regulation (recast) (2023) — Travel Rule — EUR 0 threshold (no de minimis)

licensing 20% confidence

AMLD6 (2024) — AML/CFT harmonization across EU

licensing 20% confidence

DAC8 (2024) — Crypto reporting directive for tax authorities — effective 2026

licensing 20% confidence

EXCHANGE: CASP authorization with EU-wide passporting (notify home NCA, 20 business days). Transition: up to 18 months for existing operators (July 2026 deadline). France chose 6 months, Germany 12 months.

enforcement 70% confidence

In January 2026, the French Autorité des Marchés Financiers (AMF) became the first NCA to publicly announce a formal enforcement action under MiCA, issuing a cease-and-desist order against an unregistered non-EU CASP (CryptoFlow Ltd., registered in the Cayman Islands) for soliciting French residents without authorization; the AMF noted this action as a "test case" for MiCA enforcement coordination across NCAs AMF MiCA Enforcement Action January 2026

enforcement 70% confidence

A March 2026 analysis by the European Systemic Risk Board (ESRB) identified that 8 of the 27 EU NCAs had not yet finalized their MiCA enforcement guidelines by Q1 2026, creating "supervisory fragmentation risks" for CASPs operating across multiple member states; the ESRB warned that this could lead to inconsistent application of authorization requirements and investor protections by the April 2026 enforcement date ESRB Analysis of MiCA Supervisory Fragmentation

enforcement 70% confidence

The European Commission's March 2026 enforcement update confirmed that the Netherlands Authority for the Financial Markets (AFM) had issued formal warnings to 14 crypto-asset firms for failing to submit complete authorization applications by the February 28, 2026 deadline; the AFM warned that firms without approved authorization by April 1, 2026, would face immediate suspension orders European Commission MiCA Enforcement Update March 2026

enforcement 70% confidence

By April 2026, NCAs have the mandate under Article 114 to process authorization applications, monitor ongoing compliance, and initiate enforcement actions against non-compliant entities, particularly those operating without authorization and not covered by transitional provisions; enforcement powers include suspension of services, imposition of fines, and public warnings MiCA Article 114 Enforcement

enforcement 70% confidence

ESMA has issued a public statement in December 2024 reminding market participants that unregulated entities offering services to EU retail clients without authorization or transitional grandfathering may face enforcement actions, and has called for convergent supervisory practices across Member States ESMA December 2024 Statement

enforcement 70% confidence

Practical enforcement examples by April 2026 remain limited; however, in late 2025, the Dutch Authority for the Financial Markets (AFM) issued warnings against several unregistered crypto firms operating without transitional provisions AFM Crypto Warnings

enforcement 70% confidence

The application of national transitional provisions under Article 127 is optional for Member States, leading to significant variability: for example, Germany has applied a transitional period until June 30, 2026 for existing CASPs, while France opted for a shorter period ending March 31, 2025, creating uneven enforcement intensity across jurisdictions BaFin Transitional Provisions; AMF France MiCA

enforcement 70% confidence

By April 2026, ESMA and NCAs will have conducted at least one round of thematic reviews and supervisory stress tests on authorized CASPs, focusing on governance, custody of client assets, and disclosure requirements, as part of ESMA's 2025-2026 Supervisory Convergence Work Programme ESMA Work Programme 2025

licensing 20% confidence

Cybersecurity Audits: The EU’s NIS2 Directive or DORA may mandate deep technical audits for critical sectors.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers must obtain a CASP Class 1 (custody) authorization under MiCA in their home EU Member State (€50K capital, asset segregation, full AML/Travel Rule program), with EU-wide passporting available but supervisory fragmentation and varying transition periods creating operational risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?