What Does the End of MiCA's Transitional Period Mean for Crypto-Asset Service Providers?
For EU-facing crypto businesses, 1 July 2026 marked the point when historic national permissions ceased to support normal MiCA-regulated operations.

For EU-facing crypto businesses, 1 July 2026 marked the point when historic national permissions ceased to support normal MiCA-regulated operations.
The EU-wide grandfathering period ended on 1 July 2026
The MiCA transitional period 2026 deadline ended the temporary operating rights available to certain crypto-asset service providers under national regimes.
Article 143(3) of the Markets in Crypto-Assets Regulation allowed providers already operating lawfully under applicable national law before 30 December 2024 to continue temporarily. That permission ended on the earlier of:
- 1 July 2026
- The date MiCA authorisation was granted
- The date MiCA authorisation was refused
The MiCA Regulation therefore did not create an indefinite operating right for firms with a pending application. It created a limited bridge between national regimes and EU-level authorisation.
From 1 July 2026, an entity providing MiCA-regulated crypto-asset services to EU clients must hold the relevant MiCA authorisation, or qualify for the separate notification route available to certain regulated financial entities. Otherwise, it must stop offering those services to EU clients.
ESMA confirmed this position in its statement on the end of MiCA transitional periods. Its expectation applies even where a Member State has not fully aligned domestic legislation or administrative registers with MiCA.
National VASP registrations no longer provide a continuing EU operating basis
A legacy VASP, DASP or equivalent national registration may have allowed a firm to operate during the transition. It does not itself amount to MiCA authorisation.
This distinction was important throughout the transition and is decisive after its expiry. ESMA has stated in its MiCA Q&A on transitional providers that firms operating under Article 143 were not MiCA-authorised CASPs merely because they could continue under national arrangements.
For management teams, this affects more than regulatory terminology. It affects:
- Website statements about licensing or regulatory status
- Client terms and disclosures
- Sales and partnership representations
- Outsourcing due diligence
- Institutional counterparty onboarding
- Group-level brand claims
- The legal entity named in customer contracts
A company should avoid presenting a historic national registration, a submitted application or another group entity’s licence as evidence that the contracting entity is MiCA-authorised.
MiCA authorisation is specific to the authorised legal entity and the approved crypto-asset services. It does not automatically cover an entire corporate group, every product line, every non-EU affiliate or every shared operating function.
A pending application is not permission to continue business as usual
Submitting a MiCA application did not preserve grandfathering beyond 1 July 2026.
The statutory process includes a completeness review and an assessment period for complete applications. Under Article 63 of MiCA, competent authorities have 25 working days to assess completeness, followed by up to 40 working days to assess a complete application.
Those formal timelines should not be mistaken for a guaranteed authorisation timetable. A firm may need to provide further evidence, remediate controls or clarify its operating model before an authority treats the application as complete.
The relevant question after the deadline is therefore direct: does the EU entity serving the client have the correct MiCA authorisation or qualifying notification status for the service it provides?
A pending application, an historic customer base or a well-known brand does not answer that question.
Unauthorised firms must move into orderly wind-down
ESMA does not treat wind-down as a route for continuing normal commercial activity.
Its June 2026 public statement on the transitional period says that firms without the required authorisation should stop onboarding new EU clients, opening accounts, marketing and soliciting business.
Any remaining activity should be restricted to what is necessary to protect clients and support an orderly exit. Depending on the service and client position, this may include:
- Transferring crypto-assets to a client or another authorised provider
- Selling or reallocating assets at the client’s instruction
- Closing open positions
- Supporting withdrawals
- Maintaining custody only for the period strictly necessary to complete the exit
This is a narrow operational window. It should not be used to keep trading, custody, exchange or advisory services running in a form that resembles ordinary business activity.
The immediate work is operational as well as legal. Firms may need separate procedures for client communications, account restrictions, asset transfers, unresolved positions, complaints, support access and records retention. Senior management should ensure these processes have clear ownership across compliance, operations, technology, finance and customer support.
Client migration requires regulated re-onboarding
Moving clients to an authorised CASP is not simply a technical account transfer.
The receiving provider must conduct its own onboarding and meet applicable AML/CFT requirements. It cannot necessarily rely on the outgoing firm’s historic customer records, risk decisions or wallet assessments.
A migration programme can be delayed or disrupted by gaps in:
- Identity and beneficial ownership documentation
- Source-of-funds or source-of-wealth records
- Sanctions and adverse-media screening
- Wallet-risk information
- Customer consent and contractual transfer rights
- Tax reporting records
- Product suitability or availability at the receiving firm
- Reconciliation of balances, transaction histories and outstanding positions
Clients may also receive different custody protections, fees, trading options, product restrictions or contractual terms after migration. A successful blockchain transfer does not by itself mean the client has received equivalent legal or operational treatment.
For firms planning or completing client migrations, clear communication is part of client protection. Clients need to know which entity holds their assets, which services remain available, what action is required, and what will happen if they do not complete the transition.
Authorised CASPs can operate cross-border within their approved scope
MiCA creates an EU passporting route for authorised crypto-asset service providers.
Once authorised, a CASP may provide its approved services in other Member States after notifying its home competent authority of the intended host states, services and planned start date. The authorisation remains service-specific. It is not a broad permission to provide any crypto service across Europe.
This means operating models should be tested against three connected questions:
| Area | Decision to confirm |
|---|---|
| Legal entity | Which EU entity contracts with and serves each client? |
| Service scope | Which crypto-asset services has that entity been authorised to provide? |
| Cross-border activity | Have the required passporting notifications been made for relevant Member States? |
The same review should cover outsourced functions, custody and key-management arrangements, client support, shared technology, marketing approval and the role of non-EU group entities.
ESMA has cautioned that MiCA protections attach to the authorised EU entity. A non-EU affiliate cannot continue providing MiCA-regulated services to EU clients simply because it shares a brand, technology stack or customer-support operation with an authorised European group company.
Authorisation shifts the focus to ongoing conduct and disclosure
Obtaining permission to operate does not end implementation work.
The Dutch Authority for the Financial Markets found advertising-related deficiencies at 14 firms and cost-disclosure deficiencies at 19 firms in its review of 33 MiCA-licensed CASPs. Its findings on CASP marketing and cost disclosures show that websites, promotional materials and publicly available customer information remain active supervisory concerns.
For leadership teams, this makes customer-facing infrastructure part of the control environment. Website claims, fee information, legal-entity disclosures, service descriptions and educational content need to reflect the actual authorised operating model.
This is also relevant to market positioning. A firm can explain its licence status and service scope clearly without overstating what authorisation covers. Accurate communication reduces confusion for clients, counterparties and prospective partners assessing whether the business can lawfully provide a particular service.
The decision now concerns operating-model evidence
The transition period created different timelines across Member States because national authorities could shorten or decline grandfathering. That variation no longer changes the EU-wide position after 1 July 2026.
The remaining issues are more specific: whether the correct entity is authorised, whether its service scope matches reality, whether passporting is complete, and whether any wind-down or migration activity remains genuinely limited to client protection.
MiCA has made regulatory status an operating-model question, not a historic registration exercise.
