NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

MiCA Compliance in 2026: What Crypto Firms Must Do Now

Đăng 4 giờ trước 4 phút đọc
MiCA Compliance in 2026: What Crypto Firms Must Do Now

MiCA Compliance in 2026: What Crypto Firms Must Do Now The National Law Review


The European Union's grandfathering window for crypto-asset service providers closed for good on 1 July 2026. Any firm still serving EU clients without full authorisation under the Markets in Crypto-Assets Regulation is now, simply put, operating in breach of EU law.

That deadline had been on the calendar since MiCA's core provisions became fully applicable on 30 December 2024. Article 143(3) of the regulation gave member states discretion to let existing providers keep trading under their old national licences for up to 18 months while their MiCA applications worked through the system. Some countries shortened that runway considerably – the Netherlands, Finland, Latvia, Hungary and Slovenia cut it to six months, closing their windows back in mid-2025, while Sweden allowed nine. Others, including France, Malta, Luxembourg and Estonia, used the full 18 months, giving firms until this summer.

The Authorisation Numbers Tell Their Own Story

The scale of the shakeout is worth sitting with. Before MiCA existed, more than 1,200 entities held virtual asset service provider registrations across EU member states — a patchwork of national regimes with wildly different standards. By the time the transitional period closed, roughly 210 firms had secured full Cryto-Asset Service Provider (CASP) authorisation across 23 member states, according to the European Securities and Markets Authority’s (ESMA) interim register figures reported in mid-2026. That puts the conversion rate below 18%.

Ten member states, notably, showed zero public CASP authorisations in the register as of that point. Whether that reflects slow national processing or genuine market absence varies by jurisdiction, but the practical effect is the same: coverage across the bloc is uneven. Several major exchanges — Bitvavo, Bitpanda, Kraken, Coinbase, Binance, Crypto.com, OKX, Bitstamp, and Revolut among them — cleared authorisation well before the cutoff. Newer entrants weren't excluded from that group either: the Venga App, for instance, secured its MiCA licence from Spain's CNMV, building its custody and consumer-protection processes from the beginning around the regulation from the outset rather than retrofitting them under deadline pressure.

What Unauthorised Firms Are Required to Do Now

ESMA has been unambiguous on this point. Its April 2026 statement confirmed there would be no extensions, and it directed national competent authorities to enforce the deadline uniformly across all 27 member states. Firms that missed authorisation are expected to have credible, executable wind-down plans in place — not vague intentions, but actual mechanisms for offboarding EU clients and transferring their assets to an authorised CASP or a self-hosted wallet.

For in-house counsel and compliance teams still working through this, the practical checklist looks something like this:

  • Confirm authorisation status against the ESMA interim MiCA register, which is updated weekly
  • Verify wind-down readiness if the firm, or any counterparty it relies on, lacks a full licence
  • Audit AML and Travel Rule procedures, since CASPs remain obliged entities regardless of their MiCA status
  • Map passporting coverage rather than assuming a licence in one member state guarantees EU-wide reach
  • Review client communications to ensure users understand where their assets sit and under what legal protection

None of this is optional housekeeping. A lapsed or missing authorisation doesn't just end a firm's ability to operate — it also puts its existing AML, KYC, and Travel Rule obligations under direct regulatory scrutiny.

The Consumer Side of the Equation

There's a user-facing dimension to this shift that's easy to overlook amid the compliance paperwork. ESMA's own guidance to consumers is blunt: check that a platform appears in the interim MiCA register before investing or transferring funds. For counsel advising clients on partnerships, custody arrangements, or even personal crypto holdings, that register — not marketing claims — is now the relevant source of truth.

This matters because platforms differ meaningfully in how they got here. Some are racing to catch up post-deadline. Others built their compliance posture from the ground up under MiCA's Title V framework, with custody and consumer-protection obligations baked in rather than retrofitted. That distinction is likely to become a genuine differentiator in a market where regulatory status is no longer a footnote — it's the gate.

Final Thoughts

The end of MiCA's transitional period doesn't close a chapter so much as open the one that actually matters. The regulation's stated goals — investor protection, market integrity, a genuinely harmonised framework across 27 jurisdictions — now depend entirely on enforcement, and enforcement depends on firms doing the unglamorous work of verification, documentation and, where necessary, orderly exit.

For legal and compliance professionals, the practical takeaway is straightforward: treat the ESMA register as a living document, not a one-time check, and revisit passporting assumptions regularly as national authorities catch up on processing backlogs. The firms that treated MiCA as a strategic requirement rather than a paperwork exercise are the ones now operating with a clear runway. The rest are working against a clock that has already run out.

Attribution

Originally reported by The National Law Review

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

Tin Liên Quan