
A Regulator That Wasn’t Improvising
Ask around about EU crypto licensing and you’ll hear some version of the same story: a regulator figuring out the rules mid-flight, applicants serving as unwitting test cases, and «compliant» meaning whatever survives the first few enforcement actions. The Dutch experience doesn’t match that script.
The CASP authorisation rules under MiCA became binding on 30 December 2024. The Dutch Authority for the Financial Markets, AFM, had already been taking applications since April that year — eight months of lead time most other regulators didn’t build in. By the December deadline, the AFM wasn’t opening its first files. It had already granted several licences and cleared one notification.
Look at the Dutch public register now, in early 2026, and there’s a real list of authorised crypto-asset service providers on it. In plenty of places MiCA still reads like theory. In the Netherlands it’s something firms are operating under right now.
The Regulator Has Receipts
Any Member State running MiCA can issue a licence. Far fewer bring years of hands-on crypto supervision to the process before the regime even existed, and that history shows up in how an application actually gets reviewed.
Dutch oversight of crypto firms goes back to 2020, under the national anti-money-laundering framework, well before MiCA entered the picture. Providers offering exchange services or custodial wallets had to register with De Nederlandsche Bank, DNB. The registration wasn’t a formality — DNB checked firms against AML and counter-terrorist-financing standards, kept watch on the ones registered, and went after the ones that weren’t.
The fines tell that part of the story on their own. DNB hit Binance Holdings with a €3.325 million penalty in April 2022 for offering crypto services in the Netherlands without registering first. Coinbase Europe faced the same figure less than a year later, in January 2023, over an earlier stretch of unregistered activity. Crypto.com’s entity, Foris DAX MT, paid €2.85 million in October 2023 for operating without registration between May 2020 and November 2022.
So when AFM opened applications on 22 April 2024, months ahead of MiCA’s applicability date, it wasn’t a cold start. Firms that got approved could begin operating from 30 December 2024. Companies already registered with DNB had until 30 June 2025 to complete their transition — a shorter window than some other Member States allowed.
Apply today, and the regulator on the other side already knows what solid AML controls and governance look like — and has fined firms that didn’t have them.
Two Regulators, Two Sets of Questions, One Business
An application here doesn’t get read once by one authority looking for one thing. AFM issues the licence and reviews the services on offer, the information given to customers, and whether the business model actually fits within MiCA. DNB stays involved on the prudential side — most obviously for stablecoin issuers, but its view matters whenever capital adequacy, governance, or operational resilience comes up.
The two bodies end up interested in different aspects of the same company. AFM is looking at what a customer actually experiences: contract terms, fees, risk disclosures, marketing claims, how complaints get handled, whether the service is explained honestly. DNB is looking underneath that — whether there’s enough capital, whether the governance is real rather than decorative, how client assets are safeguarded, what happens if something breaks operationally.
You don’t need two business plans to satisfy both. You need one plan that holds up no matter which side is reading it. Describing the intended MiCA services and the legal structure is the straightforward part. Harder is showing who actually has decision-making authority, who can push back on those decisions, who owns the problem when something goes wrong, and where client money or crypto sits while it gets sorted out.
This is usually where an application starts to fall apart on closer inspection. A governance chapter might describe an engaged, capable board — while the AML procedures assume approvals come from people who were never given that authority. A risk policy might reference outsourcing oversight without the technology section ever naming who manages the supplier relationship. A website might promise transparent pricing and then actually bury the fees several clicks into the signup flow. On its own, each document might read fine. Put side by side, the cracks appear.
Dutch supervisors aren’t just checking that the paperwork is complete. They’re testing whether the company described in the file could actually run the way it’s described once it’s authorised — governance, risk controls, safeguarding, customer communication, staffing, outsourcing, technology, all pointing the same direction.
These sections get drafted separately because the application asks for separate forms. In a working business, they’re not separate at all. The people with governance authority need actual power over the risks the file describes. Compliance needs enough independence and staff to do the job. Client-asset protections need to match the services actually being sold. The technology and outsourcing setup needs to support all of that, not sit off to the side as its own thing.
A file can tick every box and still leave a regulator unconvinced. The applications that hold up are the ones where every document is describing the same company — same people, same responsibilities, same resources — that will exist the day after the licence is granted.
AFM has also started sending clearer signals about what it expects post-authorisation. Its reviews of CASP marketing and cost disclosures name specific examples of language it considers misleading, incomplete, or not clear enough for a customer to make an informed decision.
Worth studying those closely before finalising a website, an onboarding flow, or a fee schedule. MiCA sets the legal floor, but it doesn’t tell you exactly how a fee should be positioned next to a headline price, how visible a warning needs to be, or where a firm has to spell out what its service doesn’t cover.
It’s rarely an outright lie. A fee can be disclosed and still be nearly impossible to find. A warning can sit on a page almost nobody visits. Wording can quietly leave customers thinking a crypto account has protections similar to a bank deposit, when it doesn’t.
Calling the Netherlands «easy» would be the wrong word, if easy means fewer questions. What it offers instead is predictability — the questions come from actual supervisory experience, so applicants have a much better sense of what’s coming. A well-written policy document won’t save a weak underlying process here. Firms that build the real business alongside the application face more upfront work, and a much more direct path through it.
Why the Address Still Matters After the Licence
A Dutch MiCA licence gets you the legal right to offer authorised services across the EU. It doesn’t hire anyone, introduce you to a bank, or hand you a client. Where the company actually sits still shapes how fast those things come together.
Amsterdam has a financial and technology sector that’s been building for decades. Banks, payments companies, trading firms, fintechs, lawyers, accountants — they’re all already there, in numbers. For a company going through licensing, that means the people who understand financial regulation and cross-border operations don’t need to be flown in.
The hiring gap for a CASP isn’t just engineers. It’s compliance officers, operations staff, risk specialists, product people, finance staff, and people who understand how a bank thinks about a crypto counterparty. Amsterdam’s international, English-first business culture makes it workable for a company recruiting from outside the Netherlands. Good compliance and crypto talent is scarce everywhere, this city included — but the difference is not having to build a support network from absolutely nothing.
The city also hosts Euronext Amsterdam, part of a group running exchanges across several European countries. Its Amsterdam market is one of the venues where companies list shares and investment products for trading through brokers.
Euronext’s job doesn’t stop at running the trading screen. The group also handles what happens after a trade goes through — confirming it, arranging payment and delivery, keeping the record of who owns what. Usually bundled together as clearing, settlement, and custody.
Crypto-linked products already trade on those markets. They let an investor get exposure to bitcoin or ether through an ordinary brokerage account, no wallet or private keys required. Issuers active there include 21Shares, Bitwise, CoinShares, VanEck, and Virtune.
Most are structured as exchange-traded products, ETPs. Some use an exchange-traded note structure instead, an ETN. The distinction shapes what an investor actually owns and how exposed they are if the issuer runs into trouble. For a CASP weighing Amsterdam, the simpler point is that established securities infrastructure is already carrying regulated crypto exposure.
Euronext kept building on that. In March 2025, Euronext Clearing extended coverage to crypto ETPs, bringing them into the group’s existing clearing setup. At the time, the group reported 156 crypto products from different issuers listed and trading across its markets. By February 2026 that number had grown — more than 100 crypto-linked instruments accessible specifically through the Amsterdam and Paris venues.
That doesn’t mean a freshly licensed CASP walks into a listing, an institutional client, or a bank account. Those still depend on the firm’s permissions, controls, product, and whoever’s on the other side of the table saying yes. What it does mean is that crypto products aren’t a novelty in this market. Brokers, asset managers, market makers, and issuers in Amsterdam have already worked through the practical questions — settlement, custody, disclosure — that come with this kind of instrument.
A CASP still has to earn each of those relationships one at a time. But it’s making the case somewhere the underlying concepts don’t need explaining from scratch.
That’s the actual argument for Amsterdam. It won’t shorten the MiCA process, and it won’t do the relationship-building for anyone. It puts a licensed crypto company inside a financial centre that already has the people, the counterparties, and the market plumbing to support what it’s trying to build.
The Tax Rate Nobody Should Lead With
Dutch corporate tax runs 19% on the first €200,000 of profit, 25.8% above it. Reasonable by Western European standards, but not the number worth paying attention to. That’s the innovation box, which can drop the effective rate on qualifying IP-driven profit to 9%.
It matters who that’s built for. It rewards companies actually developing their own technology, not firms routing transactions through a cheap postbox. A CASP building its own trading engine, custody systems, or risk tooling — the kind of proprietary work separating a real Class 2 or Class 3 operator from someone reselling a white-label platform — gets to use the innovation box for what it’s meant for, genuine R&D, rather than as a structuring trick. Different pitch entirely from a jurisdiction selling itself on a low headline number with no requirement to build anything underneath it.
There’s a second tax obligation to plan for early: DAC8, the EU directive bringing crypto into its tax transparency regime. The Dutch implementing law took effect 1 January 2026, so CASPs here already need to be collecting detailed data on EU-resident users’ transactions — buy and sell volumes, transfers to wallets outside the provider’s control, the full set. First reports are due to the Belastingdienst by 31 January 2028. The Dutch version of the rule didn’t leave much to guess at — the data fields, formats, and deadlines were all set out early. That gives firms licensing here a real head start: the reporting logic can go into the compliance stack now, built alongside everything else, rather than bolted on later once the deadline is closer.
Picking the Right Licence Class
Dutch MiCA authorisation isn’t one template stretched over every business. It splits into three classes based on how complex and risky the intended services are, and getting this choice right early affects everything downstream — capital requirements, governance depth, all of it.
| Class | Services covered | Minimum own funds | Who it fits |
|---|---|---|---|
| Class 1 | Advisory services, order reception and transmission, execution, placing, and transfer services. | €50,000 | Firms not planning to hold client crypto-assets or run a trading venue. |
| Class 2 | Exchange and custody. | €125,000 | Most commercially active crypto businesses end up here — holding client assets, running exchange services, doing more than pure advisory work. |
| Class 3 | Running an actual trading platform. | €150,000 | Market infrastructure itself, not a service layered on top of somebody else’s venue. |
Every class requires the same baseline:
- a Dutch BV as the standard vehicle;
- an actually-present registered office;
- local management with real decision-making authority;
- at least one EU-resident director.
Dutch regulators want proof that «mind and management» genuinely function on the ground, not just a phrase written into an org chart somewhere.
What This Actually Costs, and How Long It Takes
AFM’s statutory review window is up to 105 working days once a file is declared complete. Few applications move that fast, though. AML documentation alone takes time to get right, and then there’s DORA compliance, governance work, and fit-and-proper checks stacked on top. For a well-prepared file, five to eight months is a more realistic timeline from start to finish.
Costs break down into more pieces than most applicants price out individually. Beyond AFM’s own fees, setting up and structuring the Dutch BV — notary work, bank onboarding, tax and substance planning — typically starts around €4,500 including VAT. The Chamber of Commerce fee, €85.15, barely registers against, barely registers against everything else. Share capital is where the real money sits, somewhere between €50,000 and €150,000 depending on the class. Monthly running costs for board oversight, an MLRO, and office presence usually start around €6,000. DORA and IT security documentation and audit work runs €10,000 to €18,000, genuinely technical work given that DORA has applied to every CASP since 17 January 2025. Accounting support is sometimes free for the first couple of months before settling into a regular monthly fee.
None of it is arbitrary. It reflects a regime that treats a CASP as a real financial institution with real operational obligations from the first day, not a lighter-touch registration that happens to mention crypto.
Where Applications Actually Go Wrong
The common mistake is treating this like a documentation exercise. It isn’t one. AFM isn’t only checking whether the paperwork is internally consistent — it’s asking whether the business on paper is the business that will actually run under Dutch supervision once the licence lands. Treat it as a project to finish and move on from, and the governance, AML frameworks, or outsourcing arrangements that looked fine on paper tend to fall apart the moment real onboarding and real regulatory back-and-forth start.
That’s the gap between having a strategy for getting licensed and being ready to actually be licensed. It shows up in governance built to satisfy an application rather than run a company. It shows up in AML frameworks shaped by a generalist advisor’s best guess rather than what AFM has already signalled through its own guidance and enforcement record. And it shows up hardest in the months right after authorisation, when reporting, client communication, and supervisory dialogue stop being theoretical.
Building the Business Before Filing the Application
Done properly, this means treating the application as an honest description of a working business, shaped around what Dutch regulators have already shown they expect, rather than paperwork assembled to get through the door. That means scoping the right MiCA services and building the entity — board, compliance capacity, local substance — around the Dutch approach from day one, rather than adapting a generic template afterward.
AFM offers an optional pre-scan before formal filing, an early read on how the regulator views the proposed services, governance, AML approach, DORA setup, and client protection model. That’s the point where problems are still cheap to fix, before they turn into formal deficiencies in a live file. From there, one coherent application — scoping, governance, AML and sanctions controls, risk management, outsourcing, ICT and DORA arrangements, client asset protection, disclosures, tied together by a single operational story — gives AFM something it can assess as a whole business, not a pile of disconnected filings.
Once submitted, it moves through AFM’s completeness review, then substantive assessment, supervisory dialogue, and whatever gaps still need closing before authorisation. The licence brings access to MiCA’s EU-wide passporting framework. That’s the starting gun, not the finish line — reporting, disclosure standards, and AML monitoring are the work that begins the day the licence arrives.
The Real Choice: License Here, or Build Here
There’s a version of MiCA where the licence is the finish line — get it, put it on the site, move on. The Netherlands doesn’t really reward that version. Almost everything about this market assumes the company plans to operate, not just qualify. The regulators have years of real supervisory history with crypto specifically. The tax structure rewards actual technology investment over financial engineering. The talent, the capital-markets access, the English-language business culture — none of that exists because of any one company’s decision to license here. It was already there. A CASP licensing in the Netherlands is stepping into infrastructure built for exactly this kind of business, not infrastructure it has to hope shows up eventually.
Treat the Dutch application for what it is: the first stage of running a business under real, continuous supervision, not a box to tick before moving on to the next thing.
Sources:
AFM Application Timeline & Register
AFM — «Crypto-asset services can submit licence applications to the AFM from 22 April»
AFM — «Requirements and licences» (CASP supervision page)
AFM — Crypto-asset service providers register
DNB Enforcement History (Pre-MiCA AML Registration)
DNB — Binance fine decision (official notice, Dutch)
Reuters — «Dutch central bank fines Binance 3.3 million euros»
DNB — «DNB imposes administrative fine on Coinbase Europe Limited»
DNB — Foris DAX MT (Crypto.com) fine decision (official notice, Dutch)
DNB — «Fine for crypto service provider for offering crypto services without registration»
Note: The Rotterdam court later reduced this fine to €2,277,500
Amsterdam / Euronext
Dutch Tax Structure (Innovation Box, DAC8)
PwC Netherlands — «From 2026 crypto providers will be required to share data»
Two Birds — «DAC8 implemented in the Netherlands: stay ahead of the curve»
Belastingdienst — «Information on DAC8 / CARF»
AFM Marketing & Cost Disclosure Reviews
AFM — Full report PDF: «Areas for improvement in information disclosure by CASPs»
AKD — «Crypto-asset service providers beware: Lessons to be learned from AFM report»
MiCA Licence Classes & Capital Requirements
KPMG Cyprus — «MiCA is shaping the future of Europe’s crypto»
MiCA Regulation itself — Regulation (EU) 2023/1114, Article 67 and Annex IV
DORA (Digital Operational Resilience Act)
EIOPA — «Digital Operational Resilience Act (DORA)»
Mayer Brown — «EU’s Digital Operational Resilience Act Takes Effect»



