Crypto regulation in Italy is now governed primarily by the EU Markets in Crypto-Assets Regulation (MiCA), which applies directly across all member states and has reshaped the compliance landscape for every business dealing in digital assets. Italy has layered its own national framework on top of MiCA through Legislative Decree No. 129/2023 and related implementing measures, assigning supervisory authority to the Organismo Agenti e Mediatori (OAM) for registration and to the Banca d';Italia and Consob for prudential and market-conduct oversight respectively. For founders, exchanges, wallet providers and token issuers, the practical result is a multi-layer compliance structure that is stricter, more costly and more transparent than the pre-MiCA environment. This guide covers the current legal framework, licensing and registration requirements, ongoing compliance obligations, enforcement posture and the practical steps businesses must take to operate lawfully in Italy.
Italy';s approach to digital assets sits at the intersection of EU law and national implementing legislation. MiCA is the dominant instrument. It is a directly applicable EU regulation, meaning it does not require transposition - it creates rights and obligations automatically. MiCA covers crypto-asset service providers (CASPs), issuers of asset-referenced tokens (ARTs) and issuers of e-money tokens (EMTs). It also sets out a passporting mechanism that allows a CASP authorised in one EU member state to offer services across the bloc.
Beneath MiCA, Italy enacted Legislative Decree No. 129/2023, which amended the Consolidated Law on Finance (TUF) and the Consolidated Banking Act (TUB) to align national rules with the EU framework. This decree designated Consob as the competent authority for CASP authorisation and market-conduct supervision, and the Banca d';Italia as the authority responsible for prudential oversight of significant token issuers and payment-related crypto services.
The OAM retains a residual but important role. Before MiCA';s full application, the OAM maintained a public register of virtual asset service providers (VASPs) operating in Italy. That register has now been integrated into the MiCA authorisation pathway, but entities that were registered with the OAM under the transitional regime must migrate to full CASP authorisation within the timelines set by Consob. Failure to migrate is treated as operating without authorisation.
Anti-money laundering obligations derive from Legislative Decree No. 231/2007, which implements the EU';s Anti-Money Laundering Directives. CASPs are classified as obliged entities under this decree, requiring customer due diligence, transaction monitoring, suspicious activity reporting to the Unità di Informazione Finanziaria (UIF) and record-keeping for a minimum of five years.
A crypto-asset service provider wishing to offer services in Italy - whether to Italian residents or from an Italian legal entity - must obtain authorisation from Consob under MiCA. The authorisation covers a defined list of crypto-asset services, including operation of a trading platform, exchange of crypto-assets for fiat or other crypto-assets, custody and administration, execution of orders, placing of crypto-assets, reception and transmission of orders, and portfolio management.
The application to Consob must include a programme of operations, a business plan, governance documentation, proof of initial capital meeting MiCA';s tiered requirements, fit-and-proper assessments for directors and qualifying shareholders, internal control and risk management policies, and IT security documentation. Consob has up to 40 working days to assess a complete application and issue a decision. In practice, the clock stops if Consob requests additional information, which is common for first-time applicants unfamiliar with the level of detail expected.
Capital requirements under MiCA are tiered by service type. Providers offering only reception and transmission or execution of orders face the lowest threshold. Operators of trading platforms face the highest. These are minimum requirements; Consob may require additional own funds based on a risk assessment of the specific business model.
A common mistake among foreign founders is assuming that an OAM registration obtained before MiCA';s full application date is equivalent to a CASP authorisation. It is not. The OAM registration was a lighter-touch anti-money laundering measure, not a full licence. Businesses that relied solely on OAM registration and have not yet applied for CASP authorisation are operating in a legally precarious position.
For businesses already authorised as CASPs in another EU member state, the MiCA passporting procedure applies. The home-state regulator notifies Consob, and the provider may begin offering services in Italy within a defined period unless Consob raises objections. This route is significantly faster than a fresh Italian authorisation and is the preferred path for groups with an existing EU regulatory footprint.
If you are assessing whether your current structure meets Italian and EU requirements, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
MiCA distinguishes sharply between three categories of crypto-assets, and the obligations attached to each differ substantially.
Utility tokens are crypto-assets intended to provide access to a good or service supplied by the issuer. They are subject to the lightest MiCA requirements: a white paper must be prepared, notified to Consob and published before the offer. The white paper must contain prescribed disclosures about the issuer, the token, the rights attached and the risks. Consob does not approve the white paper but may require amendments or suspend an offer if the document is misleading or incomplete.
Asset-referenced tokens are crypto-assets that maintain a stable value by referencing a basket of assets, currencies or commodities. Issuers of ARTs must be authorised by Consob and meet ongoing capital, reserve management, redemption and governance requirements. Significant ARTs - those exceeding thresholds set by the European Banking Authority - fall under direct EBA supervision, with Consob acting in a supporting role.
E-money tokens are crypto-assets that reference a single fiat currency and function as electronic money. EMT issuers must be authorised either as credit institutions or as electronic money institutions under Italian law, supervised by the Banca d';Italia. This means EMT issuance is effectively a banking or payments licence question, not purely a crypto question.
A non-obvious requirement for token issuers is the marketing communications rule. Any promotional material relating to a crypto-asset offer must be clearly identifiable as marketing, consistent with the white paper and not misleading. Consob has the power to require prior submission of marketing materials and to prohibit their use. Issuers who launch aggressive social media campaigns before reviewing this requirement frequently receive regulatory correspondence within weeks of launch.
Authorisation or registration is the beginning, not the end, of the compliance journey. CASPs operating in Italy face a continuous set of obligations that require dedicated internal resources or external legal and compliance support.
AML and KYC obligations are among the most operationally demanding. Under Legislative Decree No. 231/2007, CASPs must apply customer due diligence at onboarding, at transaction thresholds set by the implementing rules and whenever there is a suspicion of money laundering or terrorist financing. Enhanced due diligence applies to politically exposed persons and high-risk customers. Suspicious transaction reports must be filed with the UIF promptly - delays are treated as failures of the reporting obligation, not merely administrative shortcomings.
The Travel Rule, derived from the EU';s Transfer of Funds Regulation (TFR) as extended to crypto-assets, requires CASPs to collect and transmit originator and beneficiary information for transfers above a threshold of EUR 1,000. For transfers to or from unhosted wallets, additional verification steps apply. Many smaller operators underestimate the technical infrastructure required to comply with the Travel Rule, particularly for peer-to-peer and DeFi-adjacent products.
Consob requires periodic reporting from authorised CASPs, including financial statements, capital adequacy reports and incident notifications. A material cyber incident or operational disruption must be reported to Consob within timelines specified in the MiCA implementing technical standards. Failure to report promptly is treated as a breach of authorisation conditions.
Custody providers face specific client-asset protection requirements. Client crypto-assets must be segregated from the provider';s own assets, held in a manner that protects them in insolvency and covered by an appropriate liability regime. Consob may inspect custody arrangements as part of its ongoing supervisory programme.
Consob and the Banca d';Italia have broad enforcement powers under the MiCA framework and national implementing legislation. The range of available measures runs from private warnings through to public censure, administrative fines, suspension of services and withdrawal of authorisation.
Administrative fines under MiCA can reach up to EUR 5 million for natural persons and up to EUR 15 million or five percent of annual turnover for legal entities, whichever is higher, for the most serious breaches. National law may set higher ceilings in some cases. Consob publishes enforcement decisions on its website, creating significant reputational consequences alongside financial penalties.
Operating as a CASP without authorisation is treated as a serious offence. Consob can issue a public warning, order the immediate cessation of services and refer the matter to criminal prosecutors where the facts support charges under Italian financial crime law. In practice, the regulator has shown willingness to act against both domestic operators and foreign entities offering services to Italian residents without the required authorisation.
A common mistake among businesses expanding into Italy from non-EU jurisdictions is assuming that a regulatory licence from a respected third-country jurisdiction - such as the United Kingdom, Switzerland or the United Arab Emirates - provides any protection under Italian or EU law. It does not. MiCA applies to any CASP offering services to persons located in the EU, regardless of where the provider is incorporated or licensed.
Consob has also signalled active monitoring of token offers that may constitute unregistered securities offerings under Italian and EU law. The boundary between a utility token and a financial instrument remains contested in specific fact patterns, and issuers who do not obtain a legal opinion on classification before launch face the risk of retrospective enforcement.
Scenario one: a non-EU exchange seeking Italian customers. A crypto exchange incorporated outside the EU wishes to market its services to Italian retail users. Under MiCA, this requires either establishing an EU legal entity and obtaining CASP authorisation in a member state, or using the reverse solicitation exemption - which is narrow and applies only where the client initiates contact entirely on their own initiative. Active marketing, including social media advertising targeted at Italian users, eliminates the reverse solicitation defence. The practical path for most exchanges is to establish an EU subsidiary, obtain CASP authorisation in a jurisdiction with a well-resourced regulatory process, and then passport into Italy.
Scenario two: an Italian startup issuing a utility token. A technology company based in Milan wishes to issue tokens that grant access to its software platform. The tokens are not intended to be investment instruments. Under MiCA, the company must prepare a compliant white paper, notify Consob at least 20 working days before publication, and ensure all marketing materials are consistent with the white paper. If the token is offered to fewer than 150 persons per member state, or the total consideration across the EU is below EUR 1 million over 12 months, certain exemptions may apply. The company should obtain a legal opinion on token classification before launch, as a misclassification that results in the token being treated as a financial instrument would trigger the full prospectus regime under EU law.
For assistance navigating either scenario, contact info@vlolawfirm.com. We can assist with documents, filings and regulatory strategy.
What is the difference between OAM registration and CASP authorisation in Italy?
OAM registration was an anti-money laundering measure introduced before MiCA applied. It placed VASPs on a public register and required them to comply with AML obligations, but it did not constitute a licence to provide crypto-asset services. CASP authorisation under MiCA is a full regulatory licence granted by Consob after a substantive review of the applicant';s governance, capital, controls and business model. The two regimes serve different purposes. Businesses that operated under OAM registration alone must now obtain CASP authorisation or cease offering services to Italian clients. The transition period has closed, and Consob treats continued operation without authorisation as a breach.
How long does it take to obtain CASP authorisation in Italy, and what does it cost?
Consob has a statutory assessment period of 40 working days from receipt of a complete application. In practice, the process takes longer because Consob routinely issues requests for additional information, each of which pauses the clock. A realistic timeline from initial preparation to authorisation is six to twelve months for a well-prepared applicant. Professional fees for legal, compliance and technical advisory support typically run from the mid-five-figure range upward, depending on the complexity of the business model and the state of the applicant';s existing documentation. State fees payable to Consob are set by regulation and vary by service category. Capital requirements must be met and maintained on an ongoing basis, adding to the financial commitment.
Can a crypto business authorised in another EU country operate in Italy without a separate Italian licence?
Yes, through the MiCA passporting mechanism. A CASP authorised in any EU member state may offer its services in Italy by notifying its home-state regulator, which then informs Consob. The provider may begin operating in Italy within a defined period unless Consob raises a substantive objection. This mechanism does not exempt the provider from Italian AML obligations, consumer protection rules or Consob';s market-conduct supervision. Passporting is the most efficient route for groups that already hold a CASP authorisation elsewhere in the EU, and it avoids the need to establish a separate Italian legal entity in most cases.
Italy';s crypto regulatory environment has matured significantly, moving from a registration-based system to a full authorisation regime under MiCA. Businesses operating in or into Italy must now meet EU-level standards for governance, capital, AML and market conduct, supervised by Consob, the Banca d';Italia and the UIF. The framework is demanding but navigable for well-prepared operators.
VLO Law Firms advises international clients on crypto regulation in Italy. We can assist with CASP authorisation applications, token classification analysis, white paper review, AML compliance frameworks and passporting procedures. To request a consultation, contact: info@vlolawfirm.com