Vassilev & Chisuse Law Firm · 2026-02-08
In 2026, the question “Can we build a crypto exchange in the EU?” is no longer answered with technology and marketing alone.
Establishing and operating a crypto-asset exchange in the European Union is primarily governed by Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA) and Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). MiCA establishes the authorisation framework, organisational requirements, client protection and market conduct rules, while DORA governs ICT risk, operational resilience, incident management and reliance on ICT third-party providers.
EU law does not provide a standalone category of authorisation called a "crypto exchange licence". A company must identify the crypto-asset services forming part of its business model and obtain authorisation as a Crypto-Asset Service Provider (CASP) for the relevant services. Certain already regulated financial entities covered by Article 60 MiCA may instead provide equivalent crypto-asset services after completing the applicable notification procedure.
In Bulgaria, the transitional regime for pre-existing service providers ended on 1 July 2026. As of September 2026, registration under the previous national regime no longer provides a sufficient legal basis for providing crypto-asset services. A new operator that does not fall within Article 60 MiCA must obtain the required MiCA authorisation before commencing regulated activities.
What Authorisation Does an EU Crypto Exchange Need?MiCA authorisation is granted for the specific crypto-asset services included in the business model. For a crypto exchange, these may include operation of a trading platform for crypto-assets, exchange of crypto-assets for funds, exchange of crypto-assets for other crypto-assets, custody and administration, execution of orders, reception and transmission of orders, transfer services, advice on crypto-assets and portfolio management.
Operating a trading platform is legally distinct from exchanging crypto-assets as principal. A trading platform operates a multilateral system that brings together or facilitates the bringing together of third-party buying and selling interests under non-discretionary rules. By contrast, an exchange service involves the CASP acting as counterparty to its client. Correctly distinguishing these functions is essential when defining the authorisation scope and designing the operating model.
In Bulgaria, the Financial Supervision Commission (FSC) is the principal competent authority for MiCA authorisation and supervision under MiCA and the Bulgarian Markets in Crypto-Assets Act. The Bulgarian National Bank (BNB) has competence in relation to e-money tokens and CASPs that are entities supervised by the BNB. The domestic framework is supplemented by Ordinance No. 77 of 12 March 2026 governing the authorisation and activities of CASPs and issuers of asset-referenced tokens.
MiCA establishes separate stages for the assessment of a CASP application. The competent authority has up to 25 working days from receipt to assess whether the application is complete. Once the application is complete, the authority has 40 working days to assess compliance and adopt a reasoned decision granting or refusing authorisation. The 40-working-day period should therefore not be treated as a guaranteed total period from the initial filing of an application to authorisation.
Can a Crypto Exchange Operator Deal on Its Own Account?A CASP operating a crypto-asset trading platform may not deal on its own account on the platform it operates. Article 76(5) MiCA applies this prohibition even where the same CASP is also authorised to exchange crypto-assets for funds or other crypto-assets.
Matched principal trading is permitted only where the client has consented and the arrangement does not create conflicts of interest. The CASP must explain its use of matched principal trading to the competent authority, which monitors whether the activity remains within the applicable definition and does not give rise to conflicts. Where a company combines operation of a trading platform with other CASP services, its organisational and technical arrangements must preserve these regulatory boundaries.
The platform must maintain clear, transparent and non-discriminatory admission rules. A crypto-asset with an inbuilt anonymisation function cannot be admitted to trading unless the trading platform operator can identify the holders of the crypto-asset and its transaction history.
Crypto-assets that qualify as financial instruments under Directive 2014/65/EU (MiFID II) fall outside the scope of MiCA. A trading platform must therefore classify assets before admission and consider the MiFID II framework and, where relevant, the DLT market infrastructure regime for instruments falling within that framework.
Asset-referenced tokens (ARTs) and e-money tokens (EMTs) are subject to specific MiCA requirements concerning issuers and admission to trading. An EMT issuer must generally be authorised as a credit institution or an electronic money institution and must notify and publish the crypto-asset white paper. An EMT white paper is not subject to prior approval by the competent authority, so describing it as an "approved white paper" would be inaccurate for this category of token.
Where Is the Boundary Between MiCA and Payment Services?CASP authorisation does not replace authorisation to provide payment services. Where the business model includes payment services related to the crypto-asset service, those services may be provided by the CASP itself only if it holds the necessary authorisation under Directive (EU) 2015/2366 (PSD2), or through a third party that is authorised to provide the relevant payment services.
Where a CASP business model requires it to hold client funds other than EMTs, MiCA requires appropriate arrangements to safeguard the clients' ownership rights. Such funds must be placed with a credit institution or central bank by the end of the following business day and held in an account separately identifiable from accounts holding the CASP's own funds.
Particular care is required for EMTs. MiCA treats EMTs as electronic money, and certain services involving EMTs may simultaneously qualify as payment services under PSD2. The European Banking Authority's transitional supervisory approach to this overlap ended on 2 March 2026. A CASP providing EMT services that qualify as payment services must therefore assess whether it requires its own PSD2 authorisation or an appropriate structure involving an authorised payment service provider.
What Does DORA Require from a Licensed Crypto Exchange?An authorised CASP is a financial entity within the scope of DORA. DORA has applied since 17 January 2025 and makes digital operational resilience a direct regulatory obligation. The management body is responsible for defining, approving and overseeing the ICT risk management framework.
The framework must address information system protection, access controls, business continuity, recovery, vulnerability management and dependencies on external ICT providers. For financial entities that do not fall within the applicable exemptions, ICT systems and applications supporting critical or important functions must undergo appropriate testing at least annually.
Threat-Led Penetration Testing is not automatically required for every crypto exchange. DORA requires TLPT at least every three years only for financial entities identified under the applicable criteria for advanced testing.
For a major ICT-related incident, the initial notification must be submitted as early as possible and in any event within four hours after classification as a major incident and no later than 24 hours after the financial entity becomes aware of the incident. The intermediate report is due no later than 72 hours after submission of the initial notification. The final report is due no later than one month after the intermediate report or, where applicable, the latest updated intermediate report.
Reliance on cloud providers, KYC solutions, key-management infrastructure or other external ICT services does not transfer regulatory responsibility from the CASP to the provider. For ICT services supporting critical or important functions, contractual arrangements must provide the required access, inspection and audit rights and appropriate exit and continuity arrangements.
How Does MiCA Address Market Abuse?Persons professionally arranging or executing transactions in crypto-assets must maintain effective arrangements, systems and procedures to prevent and detect market abuse. Where there is reasonable suspicion concerning an order, transaction, cancellation, modification or another aspect of distributed ledger operation indicating that market abuse has been committed, is being committed or is likely to be committed, the matter must be reported to the competent authority without delay.
Trading platform operators must maintain systems capable of preventing or detecting market abuse. Order data must be kept available to the competent authority for at least five years. Automated surveillance should form part of an effective process for identifying, analysing and reporting suspicious behaviour rather than being treated as a substitute for regulatory assessment.
What Rules Apply to Marketing and Crypto-Asset Advice?Information provided by a CASP to clients, including marketing communications, must be fair, clear and not misleading, and marketing communications must be identifiable as such. CASPs must also warn clients of the risks associated with transactions in crypto-assets.
There is no single universal rule requiring every CASP advertisement to contain identical wording concerning the risk of total loss. For advice and portfolio management, however, MiCA expressly requires warnings that crypto-asset values may fluctuate, that clients may incur partial or total losses, that crypto-assets may be illiquid and, where applicable, that investor compensation and deposit guarantee schemes do not provide protection.
Where a platform provides a personalised recommendation to an individual client regarding one or more crypto-assets, the operator must assess whether the activity constitutes advice on crypto-assets. CASPs providing advice or portfolio management must perform a suitability assessment taking into account the client's knowledge and experience, investment objectives, risk tolerance, financial situation and ability to bear losses.
A CASP offering both MiCA-regulated and unregulated products or services must clearly distinguish their regulatory status. ESMA has specifically warned against the "halo effect", where MiCA-authorised status may create a misleading impression that an unregulated product benefits from the same regulatory protections.
How Does MiCA Passporting Work?A CASP authorised in one Member State may provide its authorised services in other EU Member States through the Article 65 MiCA passporting procedure without obtaining a separate CASP authorisation in each host Member State.
The CASP submits to its home competent authority the target Member States, the services to be provided, the intended starting date and information on its other activities outside MiCA. The home authority transmits the information to the host authorities, ESMA and EBA within 10 working days. The CASP may commence cross-border activities from the date it receives confirmation that the information has been transmitted, or at the latest on the fifteenth calendar day after submitting the required information. A host Member State cannot require physical establishment merely as a condition for providing passported services.
Reverse solicitation under Article 61 MiCA is narrowly construed. A third-country firm may provide a service without MiCA authorisation only where the specific service is initiated at the client's own exclusive initiative. Contractual language stating that the client acted on its own initiative cannot create the exemption where the firm's actual conduct amounts to solicitation.
ESMA interprets solicitation broadly. Online advertising, targeted campaigns, affiliate marketing, social media promotions, sponsorships and influencers acting on behalf of or for the benefit of a third-country firm may constitute solicitation of EU clients. The language of a website or application can also be a relevant factor depending on the circumstances, but should not be treated in isolation as an automatic test.
Which Authorities Supervise Crypto Exchanges in Bulgaria?The Financial Supervision Commission is the principal competent authority under MiCA and the Bulgarian Markets in Crypto-Assets Act. The Bulgarian National Bank exercises the competences assigned to it by MiCA and Bulgarian law in relation to e-money tokens and CASPs that are entities supervised by the BNB.
Under the Bulgarian Measures Against Money Laundering Act, CASPs licensed under the Markets in Crypto-Assets Act are obliged entities under Article 4(19), subject to an express statutory exception for the activity of providing advice on crypto-assets. Supervisory responsibilities are allocated between the FSC, the BNB and the Financial Intelligence Directorate of the State Agency for National Security in accordance with their statutory competences.
Regulation (EU) 2023/1113 establishes the Travel Rule for transfers of crypto-assets. A CASP must ensure that the required information concerning the originator and beneficiary accompanies the transfer and must perform the applicable verification procedures. For transfers exceeding EUR 1,000 to or from a self-hosted address, the CASP must take adequate measures to assess whether the address is owned or controlled by its client. EU law does not automatically require an identical source-of-funds investigation or the same enhanced measures for every self-hosted wallet transaction. Additional controls depend on the applicable AML/CFT risk and the circumstances of the transfer.
How Should an EU Crypto Exchange Prepare for Authorisation?Authorisation planning should begin with precise regulatory mapping of the intended services. The operator should determine whether it will operate a trading platform, act as counterparty in exchange transactions, hold client crypto-assets, execute or transmit orders, provide transfer services, advice or portfolio management. The authorisation scope must correspond to the platform's actual functionality.
Where fiat functionality is involved, the operator should determine whether payment services arise and whether the necessary authorisation will be held by the operator itself or the relevant service will be provided through an authorised partner. EMT functionality requires a separate assessment of the MiCA and PSD2 overlap.
The DORA framework should be incorporated into the project before regulated activities commence. This includes an appropriate ICT risk management framework, incident and continuity procedures, ICT third-party risk management and compliant contractual documentation. AML/CFT and Travel Rule controls, together with market abuse monitoring and reporting systems, should be developed in parallel.
For a Bulgarian project, the authorisation documentation is submitted to the competent authority under MiCA, the Bulgarian Markets in Crypto-Assets Act and Ordinance No. 77. Project planning should not rely solely on the 40-working-day assessment period, since that period begins only once the application is complete.
Legal Assistance with MiCA Licensing and DORA ComplianceVassilev & Chisuse Law Firm provides legal assistance in crypto regulation, CASP structuring and digital operational resilience. The assistance may include regulatory mapping of the business model, preparation of MiCA and Bulgarian authorisation documentation, analysis of the payment architecture, review of ICT agreements and DORA policies, representation before the Financial Supervision Commission and structuring of cross-border service provision within the European Union.
This material is provided for general informational purposes only. It does not constitute individual legal, tax, financial or investment advice. The requirements under MiCA, DORA, payment services legislation, AML/CFT rules and the Travel Rule depend on the specific services, technological architecture, types of crypto-assets and manner in which the platform serves its clients.