In this piece
MiCA + FMA Reality for an Austrian Web3 Startup in 2026
If you are building a Web3 product from Austria, do not begin with the word "crypto" and assume one licence follows. Start with four questions: what asset is involved, what activity the business performs, for whom it performs it, and which entity controls the service. MiCA may govern the activity, another EU financial-services regime may apply, or the arrangement may sit outside MiCA.
This is an engineering guide, not legal advice. Qualified counsel should own the regulatory classification. Engineering should turn it into explicit requirements for custody, permissions, records, disclosures, resilience, and customer flows.
Building under MiCA?
Book Free ConsultationWho needs CASP authorization in Austria?
MiCA lists ten crypto-asset services: custody and administration; operating a trading platform; exchange for funds; exchange for other crypto-assets; execution of orders; placing; reception and transmission of orders; advice; portfolio management; and transfer services on behalf of clients. A person that professionally provides one or more of those services generally needs authorization before operating as a crypto-asset service provider (CASP).
That is not the end of the classification. MiCA provides a notification route for certain already regulated financial entities that offer specified equivalent services. Crypto-assets that qualify as financial instruments fall under existing financial-services law rather than MiCA. Issuing a token does not automatically make the issuer a CASP, although separate issuer, offer, admission-to-trading, ART, or EMT rules may apply. The FMA's applicant guidance describes the Austrian authorization process, service categories, competent authority, and Article 60 notification route (FMA CASP applicant information).
What are the prudential safeguards?
MiCA Annex IV assigns permanent minimum-capital requirements according to the services authorized:
| Class | Services covered | Permanent minimum capital |
|---|---|---|
| Class 1 | Execution, placing, reception and transmission, advice, portfolio management, and transfer services | EUR 50,000 |
| Class 2 | Class 1 services plus custody and exchange | EUR 125,000 |
| Class 3 | Class 2 services plus operating a trading platform | EUR 150,000 |
The prudential safeguard is the higher of the applicable permanent minimum and one quarter of the preceding year's fixed overheads, subject to MiCA's calculation and adjustment rules. It can be met through own funds, an eligible insurance policy, or a combination. A new business uses projected fixed overheads. Treat this as a finance and regulatory calculation, not a one-line engineering budget.
What applies after Austria's transition ended?
Austria's MiCA transition ended on 1 July 2026. The FMA says an unauthorized provider should stop onboarding and marketing, limit activity to what is necessary for an orderly wind-down, inform clients, and preserve effective safeguards during the exit. A pending application does not itself authorize normal operations. Confirm the exact obligations for the entity and service with counsel. The FMA published the Austrian position when the transition ended (FMA notice, 23 June 2026).
What does token issuance require?
Separate the token path from the CASP path. For a crypto-asset other than an asset-referenced token (ART) or e-money token (EMT), Title II can require a compliant white paper, notification to the competent authority, publication, and consistent marketing communications before an offer to the public or admission to trading. Exemptions and exceptions depend on the offer, token, network, and audience. ARTs and EMTs have different issuer and authorization rules. A token that is a financial instrument is outside MiCA and must be assessed under the relevant securities regime.
Under the general Title II process, the white paper is notified at least 20 working days before publication. Retail holders can have a 14-calendar-day withdrawal right, but MiCA specifies conditions and exceptions, including where the asset was admitted to trading before purchase. Do not turn those headline periods into a universal launch checklist. The consolidated regulation is the controlling source for the service definitions, exclusions, prudential rules, offer rules, and transitional provisions (Regulation (EU) 2023/1114).
Are NFTs outside MiCA?
Only crypto-assets that are genuinely unique and not fungible are excluded on that basis. Fractional parts of a unique crypto-asset are not treated as unique, and issuing a large series or collection is an indicator of fungibility. Neither collection size nor a "1/1" label decides the question alone. Economic substance, rights, interdependence, and actual use matter. Counsel should document the classification rather than rely on the token standard or artwork.
Does decentralization remove MiCA?
MiCA states that services provided in a fully decentralized manner without an intermediary should not fall within its scope. That wording is narrower than calling a project a DAO. Admin keys, upgrade powers, a controlled frontend, fee capture, order routing, customer support, or an identifiable operator can change the analysis. The engineering task is to map every control point and service, not to claim an exemption from a governance label.

"Regulatory scope becomes useful engineering input only when it names the asset, service, entity, customer flow, and control points."
What should an FMA workstream contain?
The FMA describes CASP authorization as a fee-based, multi-stage process. It does not impose a general obligation to appoint a legal representative. The application scope and evidence depend on the services and business model. Build one traceable workstream around:
- A written perimeter analysis for each asset, service, entity, jurisdiction, and customer type.
- A responsibility map linking governance, fit-and-proper ownership, policies, controls, and technical evidence.
- Architecture evidence for custody, segregation, key management, order handling, pricing, records, complaints, conflicts, and outsourcing where relevant.
- Financial projections and a reproducible prudential-safeguard calculation.
- An authorization, notification, or issuer path with assumptions, owners, dependencies, and regulator questions.
- A launch gate that prevents regulated activity before the required status is effective.
The FMA Regulatory Sandbox is a separate route for eligible innovative models. Do not assume a fixed application calendar, acceptance, or authorization outcome. DORA can also apply to CASPs, but obligations such as incident reporting, testing, and third-party risk management depend on the entity and facts. Convert counsel's conclusion into an owned control matrix.
What does the build-side checklist look like?
- Custody and segregation. Define ownership records, wallet architecture, reconciliation, access, and return-of-assets procedures.
- Key management. Document signing authority, recovery, compromise response, backups, and tested continuity.
- Transfer information. The EU Transfer of Funds Regulation requires originator and beneficiary information for in-scope crypto transfers. EUR 1,000 is relevant to particular checks involving self-hosted addresses, not a general threshold below which required transfer information disappears.
- Order and market controls. Match controls to the service, including execution records, conflicts, pricing, venue operation, and market-abuse duties where applicable.
- Customer operations. Connect onboarding, disclosures, complaints, consent, record retention, and exit procedures to system states.
- ICT and suppliers. Maintain system inventories, incident paths, continuity evidence, access reviews, and third-party dependencies at the level the applicable rules require.
How long and how much will it take?
There is no defensible universal "CASP MVP" duration or licensing budget. Scope varies with the service class, custody model, token and payment flows, jurisdictions, existing regulated status, outsourcing, inherited systems, evidence quality, and regulator questions. Separate at least four estimates: regulatory classification and counsel, authorization or notification work, technical implementation and remediation, and independent assurance. State assumptions and confidence ranges for each.
Our role is the technical workstream: architecture, implementation, remediation, and evidence. External counsel owns legal classification and advice; independent assessors should remain independent. Our blockchain engineering service covers the build side, while Scramble Pay is a published example of cross-chain payment engineering, not evidence of a particular authorization outcome. Because regulatory dependencies make change expensive, use our contract-model guide to make scope and uncertainty explicit.
Final thoughts
MiCA is a perimeter and operating framework, not a single crypto licence. Austria's transition has ended, but the right path still depends on the asset, service, entity, customer, and control model. Determine whether the activity needs CASP authorization, an Article 60 notification, an issuer route, another financial-services permission, or no MiCA permission before estimating the build.
Record that conclusion as engineering requirements. Gate regulated activity on effective status, trace every control to evidence, and keep legal advice, implementation, and independent assurance roles clear. If you need an engineering review of a MiCA-shaped architecture, we can help scope the technical workstream alongside your counsel.