The European Union's grandfathering window for crypto-asset service providers closed for good on 1 July 2026. Any firm still serving EU clients without full authorisation under the Markets in Crypto-Assets Regulation is now, simply put, operating in breach of EU law.
That deadline had been on the calendar since MiCA's core provisions became fully applicable on 30 December 2024. Article 143(3) of the regulation gave member states discretion to let existing providers keep trading under their old national licences for up to 18 months while their MiCA applications worked through the system. Some countries shortened that runway considerably – the Netherlands, Finland, Latvia, Hungary and Slovenia cut it to six months, closing their windows back in mid-2025, while Sweden allowed nine. Others, including France, Malta, Luxembourg and Estonia, used the full 18 months, giving firms until this summer.
The Authorisation Numbers Tell Their Own Story
The scale of the shakeout is worth sitting with. Before MiCA existed, more than 1,200 entities held virtual asset service provider registrations across EU member states — a patchwork of national regimes with wildly different standards. By the time the transitional period closed, roughly 210 firms had secured full Cryto-Asset Service Provider (CASP) authorisation across 23 member states, according to the European Securities and Markets Authority’s (ESMA) interim register figures reported in mid-2026. That puts the conversion rate below 18%.
Ten member states, notably, showed zero public CASP authorisations in the register as of that point. Whether that reflects slow national processing or genuine market absence varies by jurisdiction, but the practical effect is the same: coverage across the bloc is uneven. Several major exchanges — Bitvavo, Bitpanda, Kraken, Coinbase, Binance, Crypto.com, OKX, Bitstamp, and Revolut among them — cleared authorisation well before the cutoff. Newer entrants weren't excluded from that group either: the Venga App, for instance, secured its MiCA licence from Spain's CNMV, building its custody and consumer-protection processes from the beginning around the regulation from the outset rather than retrofitting them under deadline pressure.
What Unauthorised Firms Are Required to Do Now
ESMA has been unambiguous on this point. Its April 2026 statement confirmed there would be no extensions, and it directed national competent authorities to enforce the deadline uniformly across all 27 member states. Firms that missed authorisation are expected to have credible, executable wind-down plans in place — not vague intentions, but actual mechanisms for offboarding EU clients and transferring their assets to an authorised CASP or a self-hosted wallet.
For in-house counsel and compliance teams still working through this, the practical checklist looks something like this:




