MiCA transition is over: check who you are actually working with
On 1 July 2026 the last national transitional periods under MiCA, Regulation (EU) 2023/1114, expired. ESMA said it plainly in its April statement: a firm that has not obtained authorisation as a crypto-asset service provider (CASP) must stop providing those services in the EU. MiCA itself has applied in full since 30 December 2024. What ran out last week was the grace period for firms already on the market under national rules.
Three groups, one register
The market now splits into three groups. The first holds a CASP authorisation and can serve clients across the Union. The second filed an application and is waiting for a decision. A pending application is not an authorisation: these firms may finish the licensing procedure, but they may not provide crypto-asset services in the meantime. The third group never applied, or was refused, and must cease activity in the EU and wind down client relationships.
The reference point is public. ESMA keeps a register of authorised providers, and a check takes minutes. It cuts both ways: your bank and your counterparties can check your providers as easily as you can.
You do not need a licence to have a MiCA problem
Most companies reading this are not CASPs. They use one: a payment provider settling in stablecoins, a custodian holding tokens, a treasury desk keeping part of the balance sheet in crypto-assets. For them, 1 July changed the risk picture on three fronts.
Contract risk first. If your provider must cease activity, what happens to open transactions, to assets in custody, to your migration path? Many agreements signed in 2024 and 2025 assumed the authorisation would arrive in time. Read the termination and asset-return clauses before you need them.
AML risk second. An obliged entity has to assess who it deals with. A counterparty providing crypto-asset services without the required authorisation is a warning sign you must document and act on, and it can pull your own transactions into questions about source of funds.
Banking risk third. Banks run the same checks. A payment flow routed through an unauthorised provider can freeze an account faster than any regulator moves.
Picture your July board meeting. The CFO reports that part of the company’s payouts runs through a crypto payment provider. A director asks who verified that provider’s status after 1 July. If the room goes quiet, that silence is the gap.
What we recommend now
Five steps for the next two weeks.
- List every crypto touchpoint in the company: payments, custody, treasury, loyalty tokens. Give each one an owner.
- Check each provider in the ESMA register and file a dated extract. Repeat quarterly.
- Where a provider is missing from the register, ask in writing for its authorisation status and home regulator, and set a date for a suspend-or-exit decision.
- Reread the contracts: termination rights, return of assets and data, a realistic migration path to an authorised CASP.
- Give the board one page: the three groups, where each of your providers sits, and what you decided. Obliged entities feed the result into the AML risk assessment.
The questions for July are short. Who are our crypto counterparties? Are they authorised today? Who checked, and when? A board that can answer these three has done the work.
Sources: ESMA statement on the end of MiCA transitional periods · Regulation (EU) 2023/1114 (MiCA)