MiCA regulation Austria: FMA Licences 2026
Austria has become one of the EU's most active MiCA licensing jurisdictions. As of May 2026, the country's Financial Market Authority (FMA) had authorized nine Crypto-Asset Service Providers (CASPs) under MiCA, placing it among the top home-country licensing hubs in Europe. Bitpanda, Bybit, and KuCoin all hold FMA authorizations. A further 136 CASPs licensed elsewhere in the EEA passport their services into Austria on top of that. This guide covers which exchanges are licensed in Austria, how that licensing works, and what it actually means for Austrian crypto users.
Austria's FMA: A MiCA Licensing Powerhouse
MiCA (Markets in Crypto-Assets Regulation, EU 2023/1114) is the EU-wide framework that brought crypto exchanges and custodians under formal financial regulation for the first time. Every EU member state designates a national competent authority to supervise the rules locally. In Austria, that authority is the FMA.
The country's MiCA Enforcement Act (MiCA-VVG) formally designates the FMA as the national MiCA supervisor, a status confirmed in ESMA's list of competent authorities. The FMA began accepting CASP applications in late 2024, making Austria one of the first MiCA-ready jurisdictions in the bloc. By May 2026, the FMA had granted nine MiCA CASP authorizations. Many EU regulators are still working through their first applications; Austria has processed a meaningful pipeline and attracted major international names.
Why do exchanges choose Austria? A few practical reasons stand out. Austria's regulatory process has been comparatively predictable; the FMA communicated its readiness for MiCA early, and Vienna's position as a Central European financial center provides licensed entities with a credible basis for EEA passporting. A single MiCA CASP license granted by any EEA regulator can be passported across all 30 EEA states, so the home-country choice matters less for geographic reach than for regulatory relationship and processing speed.
Malta's MFSA was the dominant crypto-licensing hub under the pre-MiCA era (through its Virtual Financial Assets Act), and it retains a significant presence in the ESMA register. Austria has not displaced Malta, but it has established itself as a credible alternative, particularly for exchanges that want a Central European regulatory anchor rather than an offshore association.
FMA-Licensed Exchanges: The Full List
Three major exchange groups hold home-country MiCA authorizations from the Austrian FMA. The table below summarises the key details.
| Legal Entity | Exchange Brand | Authorisation Date | Services Covered |
|---|---|---|---|
| Bitpanda GmbH | Bitpanda | 9 April 2025 | Custody, exchange (fiat/crypto), order execution, placing, reception and transmission, transfer |
| Bybit EU GmbH | Bybit | 28 May 2025 | Custody, exchange, placement, transfer |
| KuCoin EU Exchange GmbH | KuCoin | 27 November 2025 | Title V MiCA CASP |
All three entities appear in current MiCA exchange lists and ESMA-based summaries with the regulator FMA and the country of Austria.
The approved research contains conflicting reporting about WhiteBIT. One ESMA-based exchange list names WB-Shields Innovations GmbH (WhiteBIT EU) as FMA-authorized, while another current register summary does not list WhiteBIT. This guide, therefore, does not treat WhiteBIT as confirmed in the table.
Bitpanda GmbH was the first to receive FMA authorization on 9 April 2025. Its Austrian license covers the broadest service range of the three, including custody, fiat-to-crypto exchange, order execution, placing, reception, and transmission of orders, and transfer services. It also carries passporting rights to 30 EEA countries.
Bybit EU GmbH received its authorization on 28 May 2025. Bybit's FMA license covers custody, exchange, placement, and transfer services, and its Vienna-based entity serves as the EEA base for Bybit's regulated operations.
KuCoin EU Exchange GmbH was granted its Title V MiCA CASP license on 27 November 2025, making it the most recent of the three major FMA-licensed entities.
One name conspicuously absent: Bitget. As of 9 July 2026, Bitget does not appear in the ESMA MiCA CASP register. It has neither a confirmed FMA authorization nor a registered CASP entity in Austria. Any application it may have filed is either pending, unregistered, or carried under a non-public legal entity name.
Bitpanda's Unique Three-License Structure
Bitpanda holds three separate MiCA CASP licenses across three EU jurisdictions. That is unusual. Most exchanges pursue a single home-country authorization and rely on passporting for the rest of the EU.
The three entities are:
- Bitpanda GmbH (Austria, FMA), authorized 9 April 2025, LEI 5493007WZ7IFULIL8G21, covering custody, exchange, order execution, placing, reception and transmission, and transfer services
- Bitpanda Asset Management GmbH (Germany, BaFin), MiCA CASP authorization
- BP CA 23 Ltd (Malta, MFSA), MiCA CASP authorization
Bitpanda publicly describes this as "three MiCAR licenses" and positions itself as "the most regulated crypto platform under the new EU framework."
Here's the honest issue with that framing: a single MiCA license already allows passporting across all EEA states, so the three-license structure does not materially expand geographic coverage beyond what the Austrian authorization alone provides. The German and Maltese licenses add local regulatory positioning rather than new territory.
What they do provide is structural redundancy and local credibility. A German BaFin authorization carries weight with German institutional counterparties. A Maltese MFSA license connects to Malta's established crypto-regulatory infrastructure. For a company of Bitpanda's scale, operating under three national regulators simultaneously is a compliance investment, not a geographic necessity.
The Austrian entity also holds additional licenses beyond MiCA: Bitpanda GmbH is licensed as an e-money institution and payment institution under PSD2 (reference 501412x) and as an investment services provider/securities firm (Wertpapierfirma, firm register number 551181k). These cover services outside MiCA's scope, such as fiat payment processing and securities-adjacent products. No other exchange currently operating in Austria holds three separate MiCA CASP licenses across three jurisdictions. That distinction is real, even if its practical effect on Austrian users is limited.
Passported Exchanges in Austria
An FMA home-country license is not the only route to legally serving Austrian users. Under MiCA, any CASP licensed by an EEA regulator can passport its authorization into Austria. The home-state regulator retains primary supervision; the FMA acts as host regulator on the basis of a passport notification.
As of mid-2026, 136 CASPs authorized in other EU/EEA states passport their services into Austria. Austrian residents have access to a wide range of regulated exchanges beyond the three with direct FMA authorizations. Major names operating in Austria via passporting include Kraken and Coinbase (both licensed from Ireland) and Gate (licensed from Malta). These exchanges serve Austrian residents through their EEA-licensed entities, subject to each firm's approved scope of services.
The passporting mechanism matters for users because it determines which regulator handles a complaint. If an Austrian user has a dispute with a passported exchange, the primary regulator is the exchange's home-state authority, not the FMA. This directs the complaint to the exchange's home-state authority instead of the FMA.
Binance is a different case. As of 9 July 2026, Binance does not hold MiCA authorization and does not appear in ESMA's Interim MiCA CASP Register. Austria ended its pre-MiCA grandfathering regime on 31 December 2025. From 1 July 2026, no exchange may serve Austrian clients without MiCA authorization. Binance cannot currently offer regulated crypto-asset services in Austria unless and until it secures a MiCA CASP license.
What Austrian Users Should Know About MiCA
MiCA creates real protections for exchange users. Any firm professionally providing custody, exchange, or trading platform services to Austrian clients must be licensed as a CASP. CASPs must meet obligations, including segregation of client assets and a ban on re-using client crypto for the custodian's own account. Those rules improve user protection in the event of platform failure or malpractice.
But the protections have clear limits. They do not cover losses from self-custody key mismanagement. They do not apply to fully decentralized protocols or non-EU exchanges. Transfers between regulated CASPs and self-hosted wallets are subject to stricter AML requirements, meaning larger withdrawals to personal wallets can trigger identity checks.
Regulation also does not guarantee recovery of all losses. A licensed exchange can still face technical failures, market disruptions, or insolvency. The CASP framework reduces certain risks; it does not eliminate counterparty risk entirely.
Here's what MiCA explicitly does not cover: self-custody. Under MiCA, only custody and management of crypto-assets on behalf of clients is regulated. Non-custodial wallets, in which users hold their own private keys, are not considered CASP services and do not require MiCA licensing. The Austrian FMA's own consumer guidance confirms that self-custody is fully lawful but falls outside MiCA's consumer-protection regime. The user bears full responsibility for key storage and loss, with no recovery mechanism from the FMA or any other authority.
That distinction matters practically. An Austrian user who keeps crypto on a licensed exchange benefits from MiCA's asset-segregation rules. The same user who withdraws to a personal wallet takes on full custody responsibility. Neither choice is wrong. They carry different risk profiles.
Tangem Wallet is one option for that second scenario. It stores private keys offline on NFC-enabled physical cards, requires no seed phrase in its default setup, and signs transactions on-chip without exposing keys to an internet-connected device. The wallet requires no KYC and collects no personal data. For Austrian users who want to move assets off an exchange after trading, it provides a concrete self-custody layer that MiCA regulation does not reach, and that no exchange can substitute for.
One limitation to keep in mind: a Tangem set can include two or three cards that share the same private key. If all cards are lost or destroyed, funds cannot be recovered by Tangem or any other entity. Self-custody means sole responsibility, and that applies to Tangem as much as any other non-custodial wallet.
FAQ
-
As of May 2026, Austria's FMA has authorized nine MiCA CASPs, making it one of the EU's most active licensing authorities. The major exchange brands among those include Bitpanda, Bybit, and KuCoin. A further 136 CASPs licensed in other EEA states passport their services into Austria, giving Austrian residents access to a broad regulated market.
-
Austria was among the first EU jurisdictions to prepare for MiCA, with the FMA accepting CASP applications from late 2024. Its regulatory process has been comparatively predictable, and Vienna's position as a Central European financial centre appeals to exchanges seeking a credible EEA base. A license granted by the FMA can be passported across all 30 EEA states, so the home-country choice carries weight beyond Austria's own market.
-
Yes. Bitpanda GmbH received its FMA MiCA CASP authorization on 9 April 2025, making it the first major exchange to receive Austrian MiCA authorization. It also holds separate MiCA licenses from Germany's BaFin (through Bitpanda Asset Management GmbH) and Malta's MFSA (through BP CA 23 Ltd), giving it three MiCA CASP authorizations across three EU jurisdictions.
-
No. MiCA requires licensed CASPs to segregate client assets and bans them from reusing client crypto for their own account. It does not guarantee the recovery of all losses from a technical failure, market disruption, or insolvency.
-
Start with the exchange's legal documentation, then compare the named entity with the ESMA MiCA CASP Register. The trading brand and the licensed company can differ, so the legal entity and its approved scope of services matter.
-
Once assets leave a licensed exchange, MiCA's exchange-custody protections no longer apply to their storage. Self-custody remains lawful, but the wallet holder controls the private keys and bears responsibility for key storage and loss. Austria's position as an active MiCA licensing hub reflects a deliberate regulatory choice to engage with crypto early and clearly. Nine home-country authorizations, a predictable FMA process, and 136 passported CASPs give Austrian residents a well-regulated exchange landscape. For assets that move off those exchanges and into personal wallets, MiCA's protections stop at the withdrawal transaction. What comes after is entirely the user's responsibility.