Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should CASPs prepare for MiCA licensing if…
Governance, Ownership & Risk

How should CASPs prepare for MiCA licensing if grandfathering is still available?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Treat grandfathering as preparation time, not a reason to defer governance work. CASPs should map every regulated activity to the relevant licensing obligation, close evidence gaps, and prove that identity verification and control ownership are already operating in a repeatable way before full EU licensing applies.

Why Grandfathering Should Be Used to Build the Licence File, Not Delay It

Grandfathering gives CASPs a limited window to turn an upcoming licence obligation into an execution plan. The practical value is in using that window to align regulated activities, accountability, and evidence so the firm can show it already knows what it does, who owns it, and how it is controlled when the full mica application is submitted.

What Needs to Be Mapped Before the Transitional Period Ends

The first task is to translate business activity into regulatory scope. A CASP should be able to show which services depend on which entity, which permissions are required, and which controls prove that the service is operated under supervision rather than assumption. If that mapping is vague, the application will usually fail on traceability before it fails on policy.

That is why identity verification matters as a licensing input, not just a security control. licensing readiness depends on being able to evidence who can act, who approved access, and which operational owner is accountable for each regulated process. If those facts cannot be demonstrated from current records, the grandfathering period is already being spent inefficiently.

How to Turn Readiness Gaps Into a Licensing Workplan

The most useful way to use grandfathering is to divide the work into evidence, control, and ownership streams. Evidence means documents and records that prove the service is governed; control means the operational checks that make the service repeatable; ownership means a named person or function that can answer for exceptions, changes, and incidents. Taken together, these are what make a licence application credible.

For CASPs, a good test is whether every regulated activity has a current process owner, a current control owner, and a current evidence owner. If any of those three are missing, the gap is not administrative noise, it is a sign the firm cannot yet demonstrate stable governance to the regulator. That is the point at which grandfathering should accelerate remediation, not reassurance.

Risk and Threat Considerations

Grandfathering creates a false sense of safety when firms treat elapsed time as compliance. The main risk is that control weaknesses, weak identity assurance, or unclear ownership remain hidden until the licence deadline, at which point the organisation is forced into hurried fixes and may have to explain inconsistent records or weak operating discipline to supervisors.

Failure mechanism: A CASP delays process mapping, access review, and evidence collection because the transitional period appears to reduce urgency. When the full licensing review begins, the firm discovers that approvals, controls, and ownership records do not line up across functions, leaving the application exposed to challenge.

Impact: The firm can face delayed authorisation, remediation cost, operational disruption, and avoidable regulatory scrutiny. In the worst case, unresolved governance gaps also make it harder to prove that regulated activities were managed consistently during the grandfathering period.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextMiCA readiness depends on mapping regulated activities to business context and obligations.
GV.RM-01 — Risk Management StrategyGrandfathering should be used to close evidence and control gaps before licensing deadlines.
Recommendation — Define regulated-service scope and ownership so each CASP activity can be traced to governance obligations. Prioritise remediation against the licence-risk register before the transitional window closes.
NIST SP 800-53 Rev 5AC-2 — Account ManagementIdentity verification and access ownership are central to proving controlled operation of regulated services.
AU-6 — Audit Review, Analysis, and ReportingLicensing readiness needs repeatable evidence that controls and approvals are operating.
Recommendation — Maintain authoritative account records showing who can act on each regulated process. Retain audit evidence that approvals, ownership, and control operation are traceable end to end.
ISO/IEC 27001:2022A.5.2 — Information security roles and responsibilitiesCASPs must show named accountability for regulated activities during the grandfathering period.
A.5.15 — Access controlIdentity verification and controlled access are part of demonstrating disciplined service operation.
Recommendation — Assign and document explicit owners for each regulated activity and control. Verify access is governed consistently and supported by documented approval records.

Practitioner Guidance

What to prioritise: Build a licence-readiness register that ties each regulated activity to one accountable owner, one evidence set, and one control obligation. That register should be the basis for weekly remediation tracking, not a static compliance spreadsheet.

What to verify: Check that identity verification, approval records, and access ownership can be reproduced from source systems without manual reconstruction. If the answer depends on informal knowledge, the control is not ready for a licensing review.

Decision rule: If a regulated activity cannot be mapped to a named owner and a repeatable control trail, treat it as an active remediation item even if grandfathering is still available. The transitional period is only useful when it shortens the path to evidence, not when it postpones it.

Practitioner takeaway: The strongest MiCA transition posture is to behave as though the licence review is already live, because regulators will care less about the grandfathering window than about whether the firm can prove discipline, ownership, and traceable control when it matters.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org