Regulatory update
After the MiCA transition: what crypto-asset service providers should now have in place
With transitional periods over, the question for CASPs serving EU clients is no longer whether to seek authorisation, but whether their operating model matches what they were authorised to do.
6 min readJurisdictions: EU · MT · CY · LT · EE

MiCA's provisions on crypto-asset service providers have applied since 30 December 2024. Member states could allow firms already operating under national regimes to continue for a transitional period, but that period could not extend beyond 1 July 2026. For businesses serving EU clients, the grandfathering window is closed.
For firms that secured authorisation, attention now shifts from the application to the operating reality. Supervisors have begun to compare what firms described in their programmes of operations with how they actually run.
Where supervisory attention is likely to fall
- Consistency between authorised services and the services actually offered, including new products added after authorisation.
- Custody arrangements: segregation of client crypto-assets, reconciliation and the role of any sub-custodians.
- Outsourcing to group entities outside the EU, and whether the authorised entity retains real control.
- Marketing communications and the use of passported services in member states with active consumer authorities.
- Conflicts of interest where the firm, or its group, trades on its own account.
Firms that did not obtain authorisation
Firms without authorisation that continue to serve EU clients need to reassess their position urgently. The reverse solicitation exemption is narrow: it covers services provided at the client's own exclusive initiative, and ESMA has made clear that it should not be used as a route to market. Practical options include pausing EU onboarding, partnering with an authorised CASP, or pursuing authorisation while restricting activity.
Practical next steps
- Map current products and flows against the authorisation granted, service by service.
- Review intra-group outsourcing agreements for audit, access and exit rights.
- Stress-test the travel rule and sanctions screening processes with real transaction samples.
- Update the regulatory calendar for reporting, notifications and changes requiring approval.
The first supervisory cycle after authorisation tends to set the tone of the relationship with the regulator. Addressing gaps before they are raised is considerably easier than remediating them under a formal finding.
This article is general commentary and does not constitute legal advice. Regulatory positions change; please seek advice on your specific circumstances.



