This is the fourth lesson in the foundational track of charliedesk Classroom. It builds on what you already know about how an exchange and a wallet work. Today we explain one specific thing that everyone who opens an account in Europe will encounter: the identity verification requirement.
Why does the platform ask for your ID?
Imagine you are opening an account on a European exchange. Before you are allowed to deposit anything, the app prompts you: upload a photo of your ID card or passport and take a selfie. This step is called KYC (from the English Know Your Customer).
The reason is not that the exchange wants your data for itself. It is a legal obligation. Rules against money laundering and terrorist financing apply here (in English AML, Anti-Money Laundering). A provider offering crypto services in the EU must know who its client is and must be able to prove this information to a supervisory authority on request.
A simple rule you can remember: an anonymous account with a regulated provider in the EU practically does not exist today. If a platform does not verify identity at all, that is not an advantage for you, it is a signal that it most likely does not follow European rules.
What is MiCA and why did it appear?
MiCA stands for Markets in Crypto-Assets, the European Union regulation on markets in crypto-assets (formally Regulation EU 2023/1114). It is the first comprehensive European framework that says who may issue crypto-assets and who may offer services around them (an exchange, a bureau de change, wallet custody, and the like). The rules for providers of crypto-asset services have applied since the end of 2024.
Until MiCA arrived, individual member states had various, fragmented rules. A company could be "registered" in one country under a national regime, but that meant something slightly different in each country. MiCA unifies this: it introduces one common set of rules for the entire EU.
You can find a more detailed definition and timeline in our glossary under the entry mica. Here the core of the matter is enough.
What exactly does a "MiCA license" mean?
To a company that wants to legally offer crypto services in the EU, MiCA says: you must obtain authorization from a national supervisory authority. In the Czech Republic this authority is the Czech National Bank, in Germany BaFin, in France the AMF, and so on. A company that obtains this authorization is referred to in the jargon of the regulation as a CASP (Crypto-Asset Service Provider).
What authorization means in practice for you as a reader:
- The company had to prove to the authority who owns and manages it.
- It had to show that it holds sufficient capital and keeps client funds separate.
- It is subject to ongoing supervision and an obligation to report problems.
One of the strongest features of MiCA is called passporting. When a company obtains authorization in one member state, it can offer services across the entire EU on that basis, without applying for a new license in each country separately. That is why it is crucial to know where a company is authorized and under whose supervision it falls.
An important note to avoid any misunderstanding: a license is not a guarantee that you will not lose your money. It does not mean a given platform is a safe investment, nor that the price of anything will rise. It means only that the company has met the entry and operating conditions and is subject to supervision. Market risk, the risk of a specific asset, and the risk of your own mistakes do not disappear because of it.
How can a reader verify for themselves that a platform holds a license?
Here is a concrete procedure you can go through step by step. Let us take a model situation: a platform claims it is "regulated in the EU". You want to verify this.
| Step | What to do | What you are looking for |
|---|---|---|
| 1 | Find the name of the legal entity and the country where it is based in the site footer or in the terms | The exact company name and the EU member state |
| 2 | Find out who the supervisory authority is in that country | E.g. the CNB, BaFin, AMF, CySEC |
| 3 | Open that authority's public register and search for the company name | An entry for the company as an authorized CASP |
| 4 | Compare whether the name and details match what the platform's site states | An exact match, not just a similar name |
Where to look for those registers. At the pan-European level, overviews and registers are maintained by the European authority ESMA (see the register section on its website). In the Czech Republic you can find the list of regulated and registered entities directly on the website of the Czech National Bank. Links to both sources are listed in the sources section below the article. These public registers are the only source of truth about whether a company is genuinely authorized.
Two practical tips. First: distinguish the company from the brand. The app may be named differently from the legal entity that operates it. You always verify the legal entity. Second: beware of phrasing such as "registration in progress" or "application submitted". A submitted application is not the same as granted authorization.
Charliedesk does not maintain its own list of licensed providers and we do not have a live figure for this term right now, so we do not give you any count of currently authorized firms. The source of truth is always the public register of the relevant national authority, or the aggregate overview at EU level.
What you should now be able to do
After this lesson you should be able to manage three things:
- Explain why a European platform asks you for ID (KYC as part of AML rules).
- Describe in your own words what a MiCA license is and what the term CASP means.
- Go through the verification procedure yourself: find the company name, look up its supervisory authority, and check the entry in the register.
What remains uncertain
Let us be honest about what this lesson does not resolve. MiCA is being introduced gradually and transitional periods differ from country to country, so the specific authorization status of a given company can change from day to day. There is no single universal "list of everyone licensed" that is always one hundred percent up to date. And above all: even a valid license says nothing about whether some asset is a good or a bad idea. Charliedesk fundamentally does not advise on that. Our job is to give you a tool to verify things, not to tell you what to do.

