Regulated United Europe OÜ
Registration number: 14153440
Anno: 16.11.2016
Phone: +372 56 966 260
Email: [email protected]
Address: Laeva 2, Tallinn, 10111, Estonia
Obtain BaFin-supervised MiCA CASP authorization in Germany. RUE supports exchanges, custody providers, brokers, and institutional crypto businesses from structuring to approval.
Schedule Free ConsultationGermany is one of the most credible but most demanding EU jurisdictions for crypto businesses. In 2026, a “crypto license in Germany” usually means MiCA CASP authorization supervised by BaFin, but the exact regulatory route depends on the service model, token type, and operational setup.
As your point of contact, I help coordinate the licensing process end-to-end, keep communication clear, and move your application forward without unnecessary delays.
RUE structures German crypto licensing projects end-to-end: business-model qualification, company formation, regulatory mapping, MiCA document pack, AML/CFT framework, ICT and outsourcing review, and regulator-facing support.
We also coordinate related workstreams that founders usually underestimate: banking strategy, German accounting and tax setup, shareholder source-of-funds evidence, local substance, and post-authorization compliance readiness.
A BaFin-supervised authorization sends a stronger credibility signal to banks, institutional clients, and counterparties than many lighter-touch EU setups.
Once authorized and properly notified, a German CASP can expand across the EU under MiCA passporting rules, subject to host-state conduct and local non-MiCA requirements.
Germany’s supervisory culture focuses on substance, fit-and-proper management, AML architecture, outsourcing control, and operational resilience rather than paperwork alone.
Germany is often preferred for custody, OTC, exchange, and B2B crypto models targeting banks, funds, corporates, and regulated financial-sector clients.
Compare MiCA Class 1, Class 2 and Class 3 by permitted activities and baseline requirements.
| Activity / Option | Mica Class 1 - 50 000 EUR | Mica Class 2 - 125 000 EUR | Mica Class 3 - 150 000 EUR |
|---|---|---|---|
| Reception and transmission of orders | V | V | V |
| Execution of orders on behalf of clients | V | V | V |
| Advisory and portfolio management | V | V | V |
| Crypto-fiat and crypto-crypto exchange | X | V | V |
| Custody and administration of crypto-assets | X | V | V |
| Operation of a trading platform | X | X | V |
Obtaining a crypto license in Germany in 2026 means meeting a full-stack regulatory standard, not just filing forms. For most operating models, the relevant route is MiCA CASP authorization supervised by BaFin. Depending on the token and service profile, additional analysis may be required under MiFID II, WpIG/WpHG, ZAG, the Prospectus Regulation, or issuer-specific MiCA regimes for ARTs and EMTs.
BaFin reviews whether the applicant is operationally credible on day one. That means your file must show coherent governance, transparent ownership, adequate capital, realistic financial projections, robust AML/KYC controls under the German AML Act (GwG), and a defensible ICT and outsourcing model aligned with the firm’s risk profile. In practice, weak substance, generic AML manuals, and inconsistent service descriptions cause more delays than missing signatures.
You must first determine whether your business actually falls within MiCA CASP services and, if yes, which exact services you will request. This is the most important scoping exercise because CASP authorization is not a universal crypto permit.
A frequent BaFin concern is mismatch between what the applicant markets commercially and what it requests legally. Your website, contracts, business plan, and internal procedures must describe the same business.
Minimum own-funds requirements under MiCA are generally service-dependent and are commonly referenced in three buckets: €50,000, €125,000, or €150,000, depending on the crypto-asset services provided. These thresholds are not the same as German company-law share capital.
BaFin will also assess whether the firm has enough funding for actual operations, not only to hit the legal minimum. In serious projects, founders usually budget for 12-18 months of runway covering staff, compliance tooling, legal support, IT security, insurance, and office substance. Capital must be traceable, documented, and typically funded in fiat rather than volatile crypto balances.
The applicant needs a defensible establishment structure for German authorization, including real governance and operational substance. For most founders, the standard vehicle is a German GmbH, although group structures can be built around other EU entities depending on the authorization model.
One practical nuance founders often miss: if all strategic decisions, security operations, and customer-risk decisions are effectively made outside Germany, the “German applicant” can look artificial. Substance must be visible in governance minutes, employment or service agreements, and actual control processes.
BaFin reviews directors, key function holders, and qualifying shareholders under a fit-and-proper lens. The regulator is not only checking CVs; it is checking whether the people behind the firm can actually run a regulated crypto operation.
BaFin also looks at time commitment and role overload. A director or MLRO who appears across multiple unrelated regulated entities without operational depth is a common credibility problem.
Your AML/CFT framework must be tailored to the actual crypto risks of your model and aligned with the German Anti-Money Laundering Act (GwG), EU AML standards, and market practice. Boilerplate policies are one of the fastest ways to trigger regulator questions.
A strong AML framework also maps operational ownership: who reviews alerts, who clears high-risk wallets, who files suspicious reports, and what SLA applies to escalation.
Travel Rule compliance is not just an AML footnote. Under Regulation (EU) 2023/1113, CASPs must collect, verify where relevant, and transmit originator and beneficiary data for transfers of crypto-assets.
A practical issue many applicants miss is reconciliation between blockchain transfer timestamps and Travel Rule message timestamps. If your audit trail cannot show which control was applied before release of funds, your framework may look weak in inspection.
Germany expects institutional-grade ICT governance for regulated crypto firms. In 2026, that means your security model should be assessed against DORA (Regulation (EU) 2022/2554), BaFin expectations, and the actual risk profile of your services.
RUE often advises clients to build forensic readiness into the architecture from the start: immutable logs, privileged-access reviews, and tested incident playbooks reduce both supervisory and litigation risk.
BaFin expects a business plan that is commercially realistic and internally consistent. A strong file usually includes a 3-year plan, conservative assumptions, documented revenue logic, and a clear explanation of how the firm will remain solvent while meeting compliance costs.
One recurring red flag is a business plan that projects aggressive user growth but budgets almost nothing for compliance analysts, support staff, or transaction monitoring. BaFin reads that as a governance failure, not optimism.
Compare Germany with other jurisdictions by key conditions for obtaining and operating a MiCA/CASP license: regulator, review period, fees, capital, local substance, and passporting.
* This table focuses on MiCA/CASP authorization conditions. Use the settings icon to customize countries and parameters.
Get an approximate cost estimate for your crypto license based on your business needs
Select options below to see estimated costs
Estimated Cost
€0
Estimated Timeframe
Country-specific
Capital Requirement
€0
* This calculator provides approximate estimates only. Actual costs may vary based on your specific situation. Contact us for a detailed personalized quote.
Taxation of a licensed crypto company in Germany must be analyzed under normal German corporate tax rules, not retail-investor myths. For companies, the key stack usually includes corporate income tax of 15%, solidarity surcharge of 5.5% on the corporate income tax, and trade tax, which varies by municipality. In practice, the combined effective burden is often around 30%+, depending on location and structure.
Popular online statements about tax-free holding periods or flat rates often refer to private individuals under specific fact patterns. They do not describe the tax treatment of a German crypto company carrying on a regulated business. A CASP, exchange, custody provider, or broker is taxed as a business, with accounting classification, revenue recognition, inventory treatment, and transfer pricing issues that require proper structuring.
VAT treatment in crypto is not uniform. Some exchange-related services may fall within financial-services exemptions depending on the exact structure and case law context, while technology, SaaS, advisory, white-label, or support services may be taxable. Cross-border B2B and B2C rules also matter. Germany-based crypto groups should confirm VAT treatment before launch, especially where they bundle custody, exchange, API access, and consulting into one commercial package.
Beyond headline tax rates, German crypto businesses should plan for:
RUE coordinates licensing with German accounting services and, where needed, detailed tax review via Crypto Taxes in Germany so the operating model is compliant from day one.
German corporations generally pay 15% corporate income tax on taxable profits. This applies to operating crypto businesses such as exchanges, brokers, custody providers, and advisory firms. Taxable profit depends on accounting treatment, deductible expenses, and transfer-pricing allocation where group services are involved.
The solidarity surcharge is generally 5.5% of the corporate income tax amount, not of total profit. On a simple basis, this increases the effective federal tax burden above the nominal 15% corporate rate.
Trade tax depends on the municipality and can materially change the effective tax burden. For many German locations, the practical range is roughly 7% to 17%. Location selection therefore affects not only office cost but also long-term tax efficiency.
Germany’s standard VAT rate is 19%, but some crypto-related transactions may be exempt depending on their legal and economic nature. Exchange services, custody, software access, consulting, and white-label infrastructure should each be reviewed separately. Do not assume all crypto revenue is VAT-exempt.
Dividend distributions can trigger withholding tax analysis depending on shareholder residence, EU directives, treaty access, and anti-abuse rules. Cross-border holding structures should be reviewed before profits are extracted from the German operating company.
Licensed crypto firms in Germany should budget for bookkeeping, payroll, annual financial statements, tax filings, and often audit-related readiness. The cost depends on transaction volume, number of wallets, fiat rails, and group complexity. Crypto reconciliation usually makes accounting more expensive than for a standard trading company.
Although not a tax, recurring compliance tooling is a real annual cost center and should be reflected in the tax and budgeting model. This often includes KYC vendors, sanctions screening, blockchain analytics, Travel Rule messaging, case management, and secure archival systems.
Custody and exchange businesses often need cyber insurance, crime cover, professional indemnity, penetration testing, and external assurance. These costs are frequently underestimated in early-stage German licensing budgets and should be built into the operating model from the start.
A German crypto license is the start of continuous supervision. After authorization, the firm must maintain governance, AML, safeguarding, reporting, and ICT controls on an ongoing basis.
A crypto license in Germany in 2026 usually means authorization as a Crypto-Asset Service Provider (CASP) under Regulation (EU) 2023/1114 — MiCA, supervised in Germany by BaFin. That is the default answer for exchanges, custodians, brokers, trading platforms, crypto portfolio managers, and certain transfer or advisory models targeting the EU market from Germany.
That said, the phrase is often used too broadly. Not every business touching digital assets needs the same authorization, and not every crypto project falls under the CASP regime. If your model involves asset-referenced tokens (ARTs), e-money tokens (EMTs), tokenized securities, payment services, or investment instruments, the legal analysis may move outside or beyond CASP licensing into issuer regimes, MiFID II, WpIG/WpHG, ZAG, or prospectus law.
The old German focus on Kryptoverwahrgeschäft under the KWG still matters historically, especially for legacy operators and for understanding BaFin’s supervisory culture. But for new market entry in 2026, the central question is no longer “Do I need the old crypto custody license?” It is “Which MiCA service bucket applies to my business, what additional regimes may overlap, and can my governance and operating model survive BaFin scrutiny?”
RUE helps founders answer that question before money is spent on the wrong structure. We start with business-model qualification, then align company setup, documents, AML architecture, ICT controls, and passporting strategy with the actual legal perimeter. Related routes include CASP License, MiCA Licence in Germany, and Crypto Regulations in Germany 2026.
Answer a few quick questions to find out if this jurisdiction suits your crypto business
Based on your answers, this jurisdiction matches your business requirements well. Here's a quick summary:
Recommended License
CASP License
Estimated Budget
€24,000 – €35,000
Estimated Timeframe
4–6 months
EU Passporting
Available
We qualify the business model, map services to MiCA and adjacent regimes, identify grey zones, and confirm whether Germany is the right authorization route. Duration: 1-3 weeks.
We structure the German vehicle or group setup, prepare incorporation, define ownership transparency, and align substance, governance, and banking strategy. Duration: 2-6 weeks.
We prepare the MiCA application file: business plan, financial model, AML/CFT framework, governance, safeguarding, ICT security, outsourcing, and internal policies. Duration: 6-12+ weeks.
We test the file for consistency across website claims, contracts, customer journey, financial assumptions, and technical architecture before regulator submission. Duration: 1-2 weeks.
The complete application is submitted to BaFin with supporting annexes and corporate records. The formal completeness review starts after filing. Duration: 1 week.
BaFin reviews the file, raises questions, and may request clarifications, remediation, interviews, or additional evidence on governance, AML, capital, and outsourcing. Duration: statutory windows apply after completeness; actual review often lasts several months.
We address any final conditions, operationalize remaining controls, finalize providers, and prepare passporting notifications if cross-border expansion is planned. Duration: 2-6 weeks.
We support launch readiness, ongoing compliance, internal reporting, banking coordination, tax and accounting setup, and change-management procedures after authorization. Duration: ongoing.