Skip to content

Regulatory update

After the MiCA transition: what crypto-asset service providers should now have in place

With transitional periods over, the question for CASPs serving EU clients is no longer whether to seek authorisation, but whether their operating model matches what they were authorised to do.

6 min readJurisdictions: EU · MT · CY · LT · EE

MiCA's provisions on crypto-asset service providers have applied since 30 December 2024. Member states could allow firms already operating under national regimes to continue for a transitional period, but that period could not extend beyond 1 July 2026. For businesses serving EU clients, the grandfathering window is closed.

For firms that secured authorisation, attention now shifts from the application to the operating reality. Supervisors have begun to compare what firms described in their programmes of operations with how they actually run.

Where supervisory attention is likely to fall

  • Consistency between authorised services and the services actually offered, including new products added after authorisation.
  • Custody arrangements: segregation of client crypto-assets, reconciliation and the role of any sub-custodians.
  • Outsourcing to group entities outside the EU, and whether the authorised entity retains real control.
  • Marketing communications and the use of passported services in member states with active consumer authorities.
  • Conflicts of interest where the firm, or its group, trades on its own account.

Firms that did not obtain authorisation

Firms without authorisation that continue to serve EU clients need to reassess their position urgently. The reverse solicitation exemption is narrow: it covers services provided at the client's own exclusive initiative, and ESMA has made clear that it should not be used as a route to market. Practical options include pausing EU onboarding, partnering with an authorised CASP, or pursuing authorisation while restricting activity.

Practical next steps

  • Map current products and flows against the authorisation granted, service by service.
  • Review intra-group outsourcing agreements for audit, access and exit rights.
  • Stress-test the travel rule and sanctions screening processes with real transaction samples.
  • Update the regulatory calendar for reporting, notifications and changes requiring approval.

The first supervisory cycle after authorisation tends to set the tone of the relationship with the regulator. Addressing gaps before they are raised is considerably easier than remediating them under a formal finding.

This article is general commentary and does not constitute legal advice. Regulatory positions change; please seek advice on your specific circumstances.

Continue reading

Practice note

DORA in practice for payment and e-money institutions

The Digital Operational Resilience Act has applied since January 2025. For smaller payment and e-money institutions, the practical burden sits largely in ICT third-party arrangements.

5 min read

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.