Join our Newsletter — 33% off our NHI Course

Why can EMT transactions create extra licensing obligations for CASPs under MiCA and PSD2?

EMTs can be treated as both crypto assets and funds depending on context, and that dual status can move a transaction from pure crypto activity into regulated payment services. When that happens, a CASP may need a PSD2 payment services licence in addition to its MiCA authorisation. The key issue is legal classification, because the licence obligation follows the regulatory wrapper.

How EMT Classification Can Change the Regulatory Wrapper

Whether an EMT transaction creates extra obligations depends less on the token label and more on the legal function of the activity. If the flow looks like a payment service rather than a pure crypto transfer, the CASP can cross into regulated payments territory. That is why the same transaction can trigger both mica and PSD2 analysis, not because the token changed, but because the regulatory wrapper did.

The practical point is that EMTs sit at the intersection of crypto-asset regulation and payment regulation. Once the transaction involves executing, transmitting, or otherwise handling a payment service, the firm must test whether MiCA authorisation alone is sufficient or whether PSD2 licensing is also required.

That distinction matters for operating model design, because a CASP cannot assume one authorisation covers every EMT-related activity. The classification of the transaction, the role the firm plays in the flow, and whether value movement is being performed for a user all affect the licensing outcome.

When a CASP Moves from Crypto Activity into Payment Services

EMTs are especially sensitive because they are designed to behave like electronic money, which means their use can resemble a payment instrument rather than a purely speculative crypto asset. If the CASP is merely facilitating a token transfer, the licensing picture may remain within crypto-asset rules. If it is effecting a payment, safeguarding funds, or carrying out payment execution steps, PSD2 obligations can come into view.

This creates a boundary question for compliance teams: what exactly is the firm doing, and who is performing the regulated function? The answer usually turns on the transaction chain, the contractual role of the CASP, and whether the activity is incidental to crypto custody or a standalone payment service.

For that reason, firms need to classify the activity at the service level, not only at the asset level. A CASP can be fully compliant under MiCA and still need a separate payment services permission if the EMT workflow includes regulated payment functions.

The same technical rails can support different legal characterisations. An EMT may move through wallets, ledgers, or exchange infrastructure, but the regulatory question is whether the CASP is providing a service that PSD2 regulates. That is why legal analysis comes before product design when building EMT flows.

Practitioners should treat this as a mapping exercise between business activity and regulated service category. If the service includes payment initiation, execution, or similar functions, the firm should not rely on MiCA as a blanket wrapper. The correct permission set depends on how the service is marketed, structured, and delivered in practice.

This is also where governance breaks down in many firms. Product teams may describe the journey as “token transfer” while legal and compliance see a payment service. The licence obligation follows the substance of the activity, so inconsistent classification across teams can create hidden regulatory exposure.

Risk and Threat Considerations

Misclassifying EMT activity can create an unauthorised-services problem, which is both a licensing risk and an enforcement risk. The exposure is greatest when a firm scales a payment-like workflow before the compliance team has confirmed whether MiCA alone is enough.

Failure mechanism: The CASP treats a payment function as a crypto-asset service, so it operates without the PSD2 permission that the underlying activity requires.

Impact: The firm can face breach of licensing conditions, operational disruption, remediation cost, and supervisory challenge over the legality of the service model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Licensing decisions depend on who can execute regulated payment functions.
PM-9 — Risk Management Strategy CASPs need a repeatable method for classifying mixed crypto and payment services.
Recommendation — Verify only authorised staff can approve service classifications and payments changes. Include regulatory classification checks in the firm’s risk management strategy.
NIST CSF 2.0 GV.OC-01 — Organisational Context EMT licensing depends on correctly defining the service and regulatory context.
Recommendation — Define the service boundary and regulatory obligations before launching EMT workflows.
ISO/IEC 27001:2022 A.5.31 — Legal, statutory, regulatory and contractual requirements The question turns on identifying MiCA and PSD2 obligations for the same activity.
Recommendation — Maintain a current register of applicable regulatory obligations for each EMT service.

Practitioner Guidance

What to verify: Map each EMT journey to the exact regulated function being performed, then test whether the CASP is only facilitating crypto transfer or is actually executing a payment service. The licensing answer should be tied to the service description, customer contract, and money flow, not to internal shorthand.

Decision rule: If the EMT workflow includes payment execution or another PSD2-regulated function, treat MiCA authorisation as necessary but not necessarily sufficient. If the role is limited to a crypto-asset service with no payment service element, document that boundary explicitly and keep the analysis under review.

Practitioner takeaway: For EMTs, the safest compliance posture is to classify the activity by legal function first and product label second, because the extra licence obligation appears when the transaction stops being only a crypto service.