A CASP license in Bulgaria is no longer a quirky “crypto registration” exercise. Under MiCA, it is a full financial authorization project, and the people who treat it like a cheap filing job usually get punished by governance, AML, banking, or technology gaps later. Bulgaria can still be a very attractive jurisdiction, yes. Low operating costs, 10% corporate tax, 5% dividend tax, access to the EU market, and a fairly practical company formation path all matter. What does not work is the fantasy that a Bulgarian entity, a policy binder, and a nice deck about blockchain will somehow satisfy the regulator.
That fantasy died when MiCA arrived.
If you are looking at a CASP license Bulgaria strategy, the short answer is this: you need a Bulgarian legal entity, a real operating model, fit and proper management, enough authorized capital for the services you plan to offer, documented AML and KYC controls, sound ICT and security architecture, clean ownership, and an application file that reads like the business already knows how to survive scrutiny. The Financial Supervision Commission, not your marketing team, decides whether that story is believable.
And there is a second point people gloss over. Bulgaria sits in a useful position for crypto businesses because the economics are appealing and the local setup cost is lighter than in many Western EU jurisdictions. Still, MiCA did not create a bargain-bin shortcut. It created a common European regulation with Bulgarian implementation layered on top. That means the upside is real, but so is the discipline. Passporting into EEA countries is valuable. Earning that authorisation is work.
You see the same pattern in other regulated sectors. Founders obsess over the license event and neglect the operating spine underneath it. Then the regulator asks the obvious adult questions. Who controls outsourcing? Who monitors suspicious transactions? What happens if wallet infrastructure fails? Who signs off on conflicts of interest? Where is the incident log? Who actually understands the technology risk? Silence. Expensive silence. If you have dealt with other local permits, the rhythm will feel familiar, whether in a crypto licence setup in Bulgaria or even a very different vertical that still turns on documentation discipline, like a gambling license in Bulgaria.
Bulgaria is useful for serious operators. That is the right frame. A founder can hold 100% ownership. The process can often be run remotely. A registered office in Bulgaria is manageable. Multilingual support exists. Fixed-fee legal and compliance support is common in the market. The tax optimization angle is obvious. Yet none of this removes legal compliance duties, and it definitely does not neutralize banking friction, source-of-funds review, or ongoing supervision.
So let’s get precise about the map. The core entity here is the Crypto-Asset Service Provider, or CASP, under the EU Markets in Crypto-Assets Regulation, usually called MiCA. The Bulgarian authorities around that map matter. The Financial Supervision Commission is central for CASP authorization and supervision. The Bulgarian National Bank matters in the electronic money token corner, especially where stablecoin-style structures drift toward electronic money. The National Revenue Agency still matters for tax, accounting, and legacy registration history. The Money Laundering Measures Act remains part of the compliance backbone. FATF logic still sits in the room even when nobody says it out loud.
That is the landscape. Attractive, but not soft.
Status update — reviewed 6 August 2026
Bulgaria’s transitional period is over. Bulgaria used the full 18-month window allowed under MiCA, so crypto firms already registered as VASPs could keep operating while they applied for a licence — until 1 July 2026. That date has passed. MiCA was transposed into Bulgarian law through the MICAL act, in force since July 2025, and the Financial Supervision Commission (FSC) is the licensing authority.
What this changes in practice:
- There is no national VASP registration to fall back on any more. CASP authorisation under MiCA is the only route to serve clients in the EU.
- ESMA has stated that firms still operating without MiCA authorisation after the transition must stop offering crypto-asset services to EU clients.
- The FSC has been sending questionnaires to previously registered VASPs to assess how ready they are for licensing.
- Plan for 6–12 months from incorporation to authorisation. There is no grandfathering left, so a late start now means a full substantive review with no interim permission to trade.
If you registered as a VASP before 2026 and have not filed for CASP authorisation, closing that gap is the first thing to deal with — ahead of any question about structure, banking or tax.
What rules govern authorization in Bulgaria?
MiCA alignment
The legal anchor is MiCA itself, meaning Regulation (EU) 2023/1114. Since it is an EU regulation, its core rules apply directly across member states. Bulgaria does not get to freestyle the substance. What Bulgaria does do is designate who supervises what, set procedural details under national legislation, and fit MiCA into the existing local architecture of company law, AML law, tax legislation, and administrative procedure.
That distinction matters more than people think. Founders often ask whether Bulgaria has its own “crypto law” separate from MiCA, as if the local state can just invent a looser lane. Not really. MiCA drives the core standards for authorization, governance, prudential safeguards, conduct, complaints handling, custody, conflicts management, and cross-border service rights. Bulgaria then operationalizes that through its own assets markets act implementation path, fee rules, supervision mechanics, and institutional competencies.
So when people say “Bulgaria CASP rules,” what they usually mean is a stack. At the top sits the European regulation. Under it sit local implementing measures, the Bulgarian law framework for AML and corporate operation, regulator practice, and sometimes the less glamorous but very real filing mechanics that decide whether your dossier moves or stalls.
MiCA also settled a long-running ambiguity in the crypto sphere. Some business models were trying to live in the cracks between financial instruments law, payments law, and old VASP-style registration logic. That gets harder now. If the service falls inside MiCA’s CASP categories and the token is a crypto-asset under MiCA, you are in a licensing universe, not a casual registration universe. If your product instead qualifies as a financial instrument, then MiCA may not be your main regime at all and the Financial Instruments Act line becomes relevant. That edge case is where bad classification advice can burn a company.
FSC and BNB
In Bulgaria, the main competent authority for CASPs is the Financial Supervision Commission. ESMA’s directory of competent authorities confirms the broader supervisory map at EU level. For most applicants, the Financial Supervision Commission is the body that reviews the application, tests the file against MiCA requirements, and supervises the licensed company afterward.
The Bulgarian National Bank is not decorative in this picture. It has a specific role around issuers of electronic money tokens and functions linked to electronic money, credit institutions, and the parts of the financial sector where stablecoin structures overlap with monetary and payment regulation. If your model touches EMT issuance, reserve handling, or token structures that look suspiciously close to e-money, the Bulgarian National Bank can become very relevant very fast. A token marketed like USDC, for example, pulls different questions than plain bitcoin brokerage.
And yes, that split creates practical tension. A business may begin by saying it only wants a crypto exchange license style model, meaning exchange, custody, transfer, or order execution around crypto assets. Then the product team adds yield, cards, fiat on-ramps, stored value, and tokenized balances denominated in euro. Suddenly the legal perimeter moves. That is why careful scoping early on matters.
There is also some local continuity with the old regime. Before MiCA, certain virtual currencies exchange and custodial wallet activities had registration obligations connected to the NRA under AML logic. The National Revenue Agency still matters for tax and historical compliance context, but that older register is not the same thing as a CASP authorization. Confusing the two is a beginner mistake. The NRA is not handing you MiCA passporting rights.
Transition period
MiCA included transition mechanics in Article 143(3), but transition periods are not an excuse to nap through implementation. Existing operators under prior local frameworks could, depending on the jurisdiction’s choices, continue temporarily under certain conditions while moving toward full authorisation. The details depend on national handling and timing. Bulgaria’s position has to be checked against current parliamentary implementation, regulator notices, and filing practice at the time you apply.
That means one uncomfortable truth. If you are reading stale advice from the VASP era, or advice built on the old Bulgarian crypto registration environment, you may be planning around a legal world that has already gone.
A practical way to think about it is this:
- Legacy registration or AML visibility is not the same as MiCA authorization.
- Transition rights, where available, are temporary and conditional.
- A firm that wants durable access to the EU market needs the full CASP file ready, not half-ready.
- Regulatory predictability improved in Bulgaria, but predictability is not leniency.
Industry observers were right to call MiCA compliance an operating-model rebuild, not a one-time formality. That sounds dramatic until you start drafting the internal control framework. Then it sounds accurate.
Which services require authorization?
Core service list
MiCA is service-specific. You do not apply for a vague crypto license and then do whatever feels commercial six months later. The authorization must match the regulated activities the company will actually perform. That means the business model, customer journey, revenue logic, wallet architecture, contracting, and risk controls all need to line up with the chosen services.
The core CASP service list generally covers activities such as custody and administration of crypto-assets on behalf of clients, operation of a trading platform for crypto-assets, exchange of crypto-assets for funds, exchange of crypto-assets for other crypto-assets, execution of orders on behalf of clients, placing of crypto-assets, reception and transmission of orders, providing advice on crypto-assets, providing portfolio management on crypto-assets, and transfer services for crypto-assets.
That sounds broad because it is broad. A brokerage flow touching ethereum or bitcoin against fiat currency is obviously inside the frame. A wallet business holding private keys for clients is inside the frame. An OTC desk routing client orders and settling in euro or stablecoins probably is too. A marketplace that operates more like a trading platform than a dumb software layer may be there as well. Product design cannot rescue you from legal classification if the economic function walks and talks like a regulated service.
A lot of crypto companies also underestimate how bundled their activities are. They say, “We only do exchange.” Then the model includes hosted wallets, client order routing, spread capture, internal matching, and transfer execution. That may trigger several CASP categories at once, which then affects capital, governance, disclosures, incident response, and outsourcing review.
Exempt activities
Not every blockchain-related business in Bulgaria needs CASP authorisation. Software development alone is not automatically regulated. Purely decentralized protocols with no service provider sitting in the middle raise separate classification debates. Mining by itself is not a CASP service. A business selling general infrastructure, analytics, or compliance tools to crypto businesses may stay outside the perimeter. NFT projects can fall outside MiCA in some structures, though fractionalization, financial features, or marketing games can narrow that comfort very quickly.
Then there is the old chestnut: “We’re just a technology company.” Maybe. Maybe not. Regulators do not care what your pitch deck calls you if clients hand over value, expect execution, rely on your platform’s rules, and face counterparty or custody risk shaped by your company.
This is also where founders drift into the financial instruments trap. Some crypto-assets are outside MiCA because they qualify as financial instruments, deposits, securitisations, or other already regulated products under EU regulations. When that happens, you are not free. You are just in a different regulatory lane, often a tougher one. So the correct question is never “Can we avoid CASP?” The correct question is “Which legal perimeter governs the exact activity and token structure?”
Cross-border scope
One of the reasons entrepreneurs look at Bulgaria is passporting. Once a CASP is duly authorized in one EU member state under MiCA, it can notify for cross-border services across the EEA under the relevant passporting mechanism. That is commercially powerful. A Bulgarian authorization can become a platform for serving clients in other EU countries without collecting a patchwork of separate national crypto licenses.
Still, passporting is not magic. It is not a permission slip to ignore consumer law, marketing rules, AML expectations, sanctions screening, tax exposure, or local conduct issues in the target state. Nor does it fix poor onboarding or weak governance. It simply provides the legal route for cross-border activity under the European regulation.
This is why Bulgaria is attractive to foreign founders. Lower setup costs. A transparent incorporation path. A remote process that is often realistic. Lean ownership structuring. Yet the value is tied to disciplined execution. If your real goal is serious EEA expansion, then Bulgaria can work very well. If your real goal is shopping for the easiest regulator, you are already thinking like a future enforcement target.
Meet the eligibility requirements
Legal entity
A CASP applicant in Bulgaria needs a legal entity established in Bulgaria. In practice, that usually means a Bulgarian company, often an OOD or EOOD depending on shareholder structure, entered in the company register with a registered seat and address. If you need the corporate spine first, the mechanics are close to a standard company formation in Bulgaria for foreigners, but the moment you move into CASP territory the ordinary incorporation file is only the beginning.
The corporate form is easy. The regulated substance is not.
Most founders choose the private limited structure because it is familiar, flexible, and workable for ownership, capital injection, and board or manager appointments. A Bulgarian OOD can fit multiple shareholders. A solo founder often uses an EOOD. The company can be foreign-owned. The manager can be a non-resident. The remote process is feasible with a proper power of attorney. None of that is controversial. What becomes controversial is whether the entity has enough local reality, staffing credibility, governance depth, and operational evidence to support the application.
That is where some offshore firms crash into reality. A Bulgarian entity with a rented desk, outsourced everything, a nominee-looking management story, and no operational substance is not a serious CASP candidate. The regulator wants to see who runs the firm, where decisions are made, how controls operate, and whether the Bulgarian entity is a genuine supervised business rather than a paper wrapper.
Related Bulgarian company and compliance guides
CASP licensing is easier to plan when the company structure, tax position, accounting base and local compliance setup are prepared correctly from the beginning.
Managers and owners
Owners and managers will be scrutinized. MiCA and local regulatory requirements push hard on fitness, propriety, good repute, competence, and clean ownership chains. Qualified holdings, beneficial owners, governance roles, and conflict lines need to be disclosed clearly. If the group structure is messy, uses layered foreign companies, or contains unexplained links to higher-risk jurisdictions, expect questions. Fair questions.
Managers need to do more than smile in a board resolution. The regulator will want evidence that the people directing the business understand crypto activities, AML exposure, operational resilience, outsourcing risk, client asset handling, complaints, and the basic fact that running a supervised firm is different from running a startup that improvises everything on Telegram.
Expect requests around:
- identity and background documents for shareholders, beneficial owners, and managers
- criminal record and integrity checks, plus reputation disclosures
- CVs showing relevant financial institution, fintech licensing, payments, or crypto market experience
- explanation of governance roles, reporting lines, and decision-making authority
In some cases, firms also need a local AML function or at least an AML officer arrangement that makes practical sense in Bulgaria. “Makes practical sense” is the key phrase. A name on a chart is worthless if the person cannot actually monitor alerts, train staff, review suspicious patterns, and interact with the Financial Intelligence Directorate or other government agencies when needed.
Capital thresholds
Capital is one of the first places where casual applicants get a rude surprise. CASPs do not all carry the same minimum capital requirement. Under MiCA, the threshold depends on the service category. The common ranges people discuss are €50,000, €125,000, and €150,000, though the exact amount depends on what you are applying for. Convert that for a US audience and you are roughly looking at about $54,000, $135,000, and $162,000 at typical recent exchange levels, but the legal threshold itself is set in euro.
Here is the cleaner view:
| Service profile | Typical minimum capital |
|---|---|
| Lower-risk CASP categories | €50,000 |
| Mid-tier service categories | €125,000 |
| Trading platform / custody-heavy or broader risk categories | €150,000 |
That is only the floor. It is not a comfort number. If your model has material technology, security, outsourcing, transaction monitoring, or custody exposure, the regulator may care less about bare-minimum math and more about whether the company is genuinely funded to operate safely.
And no, authorized capital is not the whole prudential story. A firm can technically meet minimum capital and still look underbuilt if projected expenses, staffing, insurance logic, vendor dependencies, or incident response demands clearly exceed its resources. A serious application links capital to operating reality.
Prepare the application file
Governance package
This is the part people always underestimate because it looks boring until it becomes decisive. The application dossier is not just a stack of forms. It is a narrative with evidence. It needs to show how the cryptocurrency company is governed, who controls what, how risk is identified, how decisions are documented, and how the board or managers can challenge the business rather than just approve whatever the founders want.
A decent file usually includes constitutional documents, group structure, program of operations, business plan, financial projections, service descriptions, internal governance rules, conflict-of-interest policy, complaints handling, safeguarding or custody logic where relevant, client terms, outsourcing map, continuity planning, and fit-and-proper documentation for key persons. MiCA Article 62 is the place to start reading, not the place to stop.
I would be blunt here. If your governance package reads like it was generated from a template library with your company name pasted over another firm’s policies, the regulator will smell it. Good files are coherent. The risk matrix matches the services. The outsourcing appendix matches the tech stack. The financial plan matches the headcount. The governance narrative matches the actual management team. No dead language. No fantasy.
This is also where smart founders quietly get help from accountants early rather than late. A CASP can drown in tax, payroll, and reporting confusion if the finance setup is an afterthought, which is why proper accounting support for navigating Bulgarian regulations is not some post-license accessory. It is part of credibility.
AML and KYC
AML is not a side appendix. For many crypto businesses, it is the center of gravity. Bulgaria’s AML environment still leans on the Measures Against Money Laundering Act, sometimes casually called the money laundering act or money laundering measures act in English discussions, and it reflects broader European AML directives and FATF standards. If your file is weak here, nothing else looks trustworthy.
The regulator will expect a risk-based framework. Customer onboarding, KYC verification, beneficial ownership checks, sanctions screening, source-of-funds logic, transaction monitoring, suspicious activity escalation, recordkeeping, staff training, periodic review, and reporting channels all need to be described in a way that fits the actual model. An OTC desk, a hosted wallet provider, and a trading platform do not carry the same risk profile, so their controls should not read identically.
The FATF guidance on virtual assets and VASPs still matters because MiCA did not erase the global AML baseline. Neither did Bulgaria. If you plan to deal in virtual currencies, convert crypto to fiat, or handle transfers involving high-risk geographies, stablecoins, mixers, or layered wallet behavior, your monitoring model needs to show adult supervision. Not “best efforts.” Not “we will use an external vendor.” Actual control logic.
A thin AML file often reveals a deeper problem. The founders have not really decided who their customers are, how they will price risk, what geographies they will exclude, or how much friction they are willing to tolerate to stay clean. Those are business decisions as much as compliance decisions.
Important practical note
A Bulgarian CASP application should not be prepared as a paper exercise. The regulator will look at the real business model, ownership chain, AML controls, ICT security, outsourcing structure and financial capacity behind the company.
ICT and security
MiCA pushed technology and operational resilience into the licensing conversation in a much more serious way than many old-school crypto entrepreneurs expected. Good. Frankly, it was overdue. If you are safeguarding wallets, routing orders, integrating APIs, using cloud providers, relying on blockchain analytics tools, or operating trading infrastructure, your ICT model is not back-office trivia. It is the machine.
Expect the file to cover system architecture, access controls, data protection, incident handling, key management logic, wallet segregation where relevant, business continuity, disaster recovery, cybersecurity testing, logging, third-party dependencies, and internal accountability for security decisions. If you use outsourced custody, white-label exchange rails, or cloud-native environments, that needs to be documented in a way that explains who is responsible when things go wrong.
People who come from pure software culture often say, “We move fast.” Fine. Regulators hear, “We improvise.” Different audience. Different standard.
That does not mean Bulgaria demands some impossible gold-plated infrastructure on day one. It does mean the application should demonstrate that the company understands operational risk in a regulated environment. If your platform handles bitcoin, ethereum, USDC, or other cryptocurrencies at scale, the weakness of one key process can become a client asset event, a reporting event, a reputation event, and then, almost immediately, a supervisory event.
Set up the business model
Registered office
A CASP in Bulgaria needs a real Bulgarian base. At minimum, a registered office and address are required. In practice, the office setup should support actual administration, correspondence, document storage logic, inspection readiness, and a credible local presence. This does not mean every founder must relocate or that all managers must be Bulgarian resident individuals. It does mean the Bulgarian entity cannot feel ghostlike.
That is one reason the incorporation phase should be handled cleanly. If the company documents, seat, manager consents, shareholding evidence, and power of attorney chain are sloppy at the start, the licensing file inherits that sloppiness. Anyone thinking about structure first and license second usually benefits from reading through the normal step-by-step Bulgarian company registration process before adding the CASP layer.
There is a practical reality here too. Banks, tax offices, and regulators all react better when the company looks like it exists in the grown-up world. Clear address. Clear manager. Clear business purpose. Clear accounting arrangement. Clear contact channels. It sounds basic because it is basic, and yet this is where plenty of crypto companies still manage to look suspiciously theatrical.
Outsourcing controls
Most CASPs outsource something. Many outsource a lot. KYC vendors, blockchain analytics, cloud hosting, wallet infrastructure, customer support layers, transaction screening, cybersecurity monitoring, development, even parts of finance. Outsourcing is not prohibited. Sloppy outsourcing is the problem.
The regulator will expect you to identify critical functions, due-diligence your providers, monitor performance, preserve audit rights where needed, keep data and access controlled, and ensure that outsourcing does not dissolve management responsibility. “The vendor handles it” is not a defense. It is usually an admission that nobody internal owns the risk.
This is one of those areas where cheap setups become expensive. A low-cost provider with weak SLAs, patchy incident reporting, or unclear subcontracting can turn a clean application into a credibility problem. Bulgaria is cost-effective, yes. That does not mean every control should be bought at discount-bin level.
And because founders always ask, no, a fully empty shell with every meaningful function outsourced abroad is usually not a persuasive posture for a Bulgarian crypto company seeking authorisation. The local entity still needs substance, governance, and oversight capacity.
Local tax setup
The tax headline is the bait, and to be fair it is good bait. Bulgaria’s 10% corporate income tax remains one of the more appealing rates in the European Union. Distributed dividends are commonly taxed at 5%. For foreign entrepreneurs building margin-sensitive operations, that is a serious argument. You can dig deeper into the mechanics in this guide to Bulgaria corporate income tax rules.
Still, tax planning for a CASP goes well beyond headline rates. You need corporate tax registration, bookkeeping, annual returns, payroll treatment for managers and employees, social security analysis, transfer pricing where there is a group, VAT analysis where relevant, and clean records at the National Revenue Agency. Some crypto services sit outside standard VAT assumptions, some do not, and the details depend on the service line. If the company crosses thresholds or runs taxable support operations, the Bulgarian VAT registration process may become part of the setup.
Founders also need to avoid a common mistake. Low tax does not mean low supervision. The National Revenue Agency can be perfectly polite while still asking sharp questions about turnover, invoicing, cross-border flows, salaries, and beneficial ownership. Bulgaria is friendly to business. It is not asleep.
How does the approval process work?
The approval process starts before filing. Classification first, structure second, documents third, filing fourth. People reverse that and waste months. You need to know exactly which CASP services the company will seek, which tokens or product categories it will touch, whether any electronic money or financial instrument issues lurk in the model, and how the governance and tech architecture support that scope.
Then the Bulgarian entity is established, capitalized, staffed or at least credibly organized, and paired with a business plan that does not read like fantasy fiction. The application dossier is built around MiCA requirements and FSC practice. Supporting evidence gets translated where needed. Owners and managers are documented. Policies are aligned. Vendors are mapped. AML controls are tuned. ICT documentation is pulled into shape. Then the file goes in.
After that, expect questions. Many of them. The FSC is not there to admire the executive summary. It will test whether the narrative and the evidence match. Gaps on ownership, outsourcing, risk scoring, token classification, prudential funding, complaints, safeguarding, cybersecurity, or manager competence can all trigger follow-up. Fast replies help. So does not lying in the first place.
A rough process flow looks like this:
- scope the services and classify the business model under MiCA
- form the Bulgarian legal entity and fund the required capital
- prepare the full application file with governance, AML, ICT, and financial documentation
- submit to the FSC, answer information requests, and wait for the formal decision
- once authorized, complete passporting notifications if cross-border expansion is planned
Timelines are always the question founders ask too early. The honest answer is that the timeline depends on the quality of the dossier, the complexity of the service package, whether the ownership structure is clean, whether translations and apostilles were prepared properly, and how busy the regulator is. Some providers market rosy estimates. I would not build a launch budget around rosy estimates.
If the file is mature, think in months, not days. If the file is weak, think in rounds of questions, revisions, and delays. Licensing periods that sound “fast” in sales material often refer to the moment of submission, not the moment you are actually authorized and operational. Two very different dates.
There is also a wider company setup issue for foreign founders. If key people will relocate, manage locally, or need long-term presence, immigration and work status can matter in parallel, especially if a non-EU manager wants to operate in-country. That is not a CASP rule as such, but it can shape execution, just as it does in a standard non-resident company opening path in Bulgaria.
What does it cost to operate?
Founders usually fixate on the license fee and ignore the machine around it. That is backwards. Official administrative fees matter, and the FSC’s own fee rules under Ordinance No. 76 should be checked in current form. Still, the larger cost center is usually preparation and ongoing compliance, not the filing receipt.
Below is the more useful operating picture:
| Cost area | What usually sits inside it |
|---|---|
| Regulatory filing and legal work | application drafting, regulatory analysis, translations, apostilles, local counsel |
| Corporate setup | incorporation, registered office, company maintenance, corporate secretary support |
| Compliance build-out | AML framework, KYC tooling, sanctions screening, internal controls, training |
| ICT and security | infrastructure, custody or wallet providers, cloud services, cybersecurity, audits |
| Finance and tax | accounting, payroll, annual filings, tax returns, NRA interactions |
| Prudential funding | minimum capital, working capital buffer, insurance or reserve planning where relevant |
This is why the “Bulgaria is cheap” line needs adult handling. Bulgaria is cheaper than many competing EU jurisdictions. True. It is not cheap in the sense of careless. A proper CASP build still involves lawyers, accountants, compliance professionals, technology spending, and time. If the company wants genuine transparency, fixed-fee support where possible, and a remote process that does not blow up halfway through, the budget needs to reflect reality.
Tax-wise, the headline remains favorable. A Bulgarian company pays 10% corporate tax on profits. Dividend distributions are commonly taxed at 5%. Payroll taxes and social contributions depend on employment structure. Cross-border intragroup arrangements may trigger transfer pricing concerns. A founder who treats all of this as “later” usually pays for that optimism twice.
Then there is the ugly little side issue nobody advertises: banking. Even licensed companies can face cautious onboarding, enhanced due diligence, source-of-funds review, transaction monitoring conditions, and practical limits tied to the bank’s risk appetite. A CASP authorization helps credibility. It does not hypnotize a compliance officer into saying yes.
Need help preparing a CASP licence strategy in Bulgaria?
If you are planning a crypto exchange, wallet service, brokerage model, transfer service or another MiCA-regulated activity, we can help you review the structure, prepare the Bulgarian company setup and coordinate the next licensing steps.
FAQ
Can a foreigner own 100% of a Bulgarian CASP?
Yes. Foreign ownership is generally possible, including full ownership by one person or one foreign corporate shareholder, provided the ownership chain is transparent and the beneficial owners pass scrutiny.
Can the process be done remotely?
A lot of it can. Company formation, document preparation, and filing often work through a notarized and apostilled power of attorney. Some banking, identity verification, or follow-up steps may still require in-person involvement. Remote process does not mean zero friction.
Is the old VASP registration enough?
No. Legacy NRA-related registration and AML visibility are not the same as MiCA CASP authorization. If you want passportable regulated operations under the current EU framework, you need the proper CASP authorisation.
Do all crypto businesses need a CASP license in Bulgaria?
No. Pure software, certain infrastructure providers, and some models outside MiCA may avoid the CASP regime. But classification must be done carefully, especially where custody, exchange, transfer, advice, execution, or platform activity is involved.
How long does authorization take?
Usually months. The exact timing depends on the dossier quality, business complexity, regulator workload, and how quickly the applicant responds to follow-up questions.
What is the minimum capital?
It depends on the services. The common MiCA thresholds are €50,000, €125,000, or €150,000. The relevant category must be confirmed against the actual service mix.
Can a Bulgarian CASP serve clients across Europe?
Yes, through MiCA passporting after authorization and the required notifications. That is one of the major strategic reasons founders choose Bulgaria.
Conclusion
Bulgaria is attractive for CASP licensing for the right reasons and the wrong ones. The right reasons are obvious: sensible costs, 10% corporate tax, 5% dividend tax, workable incorporation, foreign ownership, and access to the European market through MiCA passporting. The wrong reason is the fantasy that Bulgaria offers soft-touch crypto authorization. It does not.
A CASP license in Bulgaria is viable for serious operators willing to build a real regulated business. That means a Bulgarian entity with substance, clean ownership, competent managers, enough capital, disciplined AML, credible ICT controls, sound tax and accounting setup, and documents that reflect operational truth rather than brochure language. The Financial Supervision Commission will read the difference.
That is really the whole game. Bulgaria gives you an efficient door into the EU market. MiCA decides how narrow that door is. Your preparation decides whether you actually fit through it.
Weighing a CASP application against other routes? Read our full guide to business licensing in Bulgaria.
Daniel Malbašić is a business expert with extensive experience in the field of business consulting, organization and business optimization. His expertise includes market analysis, strategic planning, and implementation of effective business solutions. Daniel is dedicated to helping companies grow and improve their operations, providing them with comprehensive support in making key business decisions.











