Skip to content
Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Audit & Advisory Investigation Crypto OSINT Investigation Training & Advisory Seqlense Immo Pricing Academy Blog Partners Supported Chains Contact My Seqlense Get Started
Back to blog

MiCA's transitional period is over: what CASPs must do now

On 1 July 2026 MiCA's grandfathering window closed. Crypto-asset service providers now need a granted EU authorisation to serve clients, and a pending application is no longer enough. Here is what changed, and the checklist that follows.

On 1 July 2026, the grace period ended. The transitional window that let crypto firms keep serving EU clients under their old national registrations is closed, and the rulebook that replaces it, the Markets in Crypto-Assets Regulation (MiCA), now applies in full across all 27 member states. If you provide crypto-asset services to Europe, the question is no longer "when will MiCA affect us?" It is "are we on the register, today?"


From national regimes to one EU rulebook

Before MiCA, a crypto business navigated a patchwork: a VASP registration in one country, a DASP number in another, and no automatic way to operate across borders. MiCA replaced that patchwork with a single authorisation that passports across the EU.

To smooth the switch, the regulation allowed a transitional ("grandfathering") period of up to 18 months. Firms already registered under a national regime could keep operating while their MiCA application was processed. Member states could shorten that window. France and Luxembourg ran the full 18 months from 30 December 2024, while others cut it short, but every version of it expired by 1 July 2026.

The transitional period was never an extension of the old rules. It was a countdown. That countdown has now reached zero.


What "authorised" actually means now

After the deadline, only firms that appear on ESMA's official register of authorised Crypto-Asset Service Providers (CASPs) may legally serve EU clients. Authorisation is granted under Article 63 of MiCA by a national competent authority, then passported EU-wide.

The single most misunderstood point: a pending application offers no protection. Only a granted authorisation counts. A firm still waiting on its file is, as of 1 July, operating without cover.

Uptake has been uneven across the bloc. By mid-2026, roughly 213 CASPs were authorised across 23 member states, concentrated in a handful of hubs:

Member state Authorised CASPs
Germany 55
Netherlands 26
France 19
Malta 15
Ireland 12
Other (18 states) ~86

Figures approximate, drawn from ESMA's register in mid-2026. The register is updated weekly, so always verify against the live source.


Three paths if you are not yet authorised

If your firm is not on the register, there are only three lawful positions to be in:

  1. Complete a full authorisation. Submit, or finish, an Article 63 application. Processing takes time, so this is the "should have started yesterday" option, but it is the only one that yields durable legal certainty.
  2. Passport through a licensed entity. If a parent or affiliate already holds a CASP authorisation, coverage can be extended through passporting, provided there is genuine operational substance rather than a nameplate.
  3. Cease EU-facing operations. An orderly wind-down: notify clients, offboard them, and transfer assets to authorised providers or self-hosted wallets before continuing to serve them becomes a breach.

One escape route that does not work is reverse solicitation. ESMA reads the exemption narrowly: any marketing aimed at EU clients invalidates it.


The obligations that don't stop at authorisation

Getting on the register is the start, not the finish. An authorised CASP carries continuous, evidenced duties:

  • Market-abuse detection and reporting: surveil for insider dealing and manipulation, and file reports.
  • AML/CFT, including the Travel Rule: originator and beneficiary information must travel with crypto transfers.
  • Wallet and transaction screening: assess counterparties for illicit-finance and sanctions exposure before transacting.
  • Sanctions management: screen against evolving lists in near real time.
  • Wind-down readiness: keep an orderly-cessation plan current, even while fully operational.

Why this is a monitoring problem, not a paperwork problem

Read that list again and a pattern emerges: almost none of it is a one-time filing. Market abuse, sanctions, Travel-Rule counterparties, register status: all of them change, often weekly, sometimes daily. Compliance under MiCA is a live signal, not a binder on a shelf.

That splits neatly into two questions a compliant CASP has to answer at any moment. First, what does the regulation now require of us, as guidance, technical standards and national interpretations keep landing? Second, what is actually happening on-chain and against our counterparties, right now? The firms that will find MiCA manageable are the ones that treat regulatory monitoring and on-chain monitoring as a single, continuous view rather than two annual projects.

The transitional period is over. The monitoring it demands is only beginning.

Related articles

Which blockchains should your compliance program cover first?

Prioritising chains by customer exposure, liquidity and traceability.

OSINT for compliance: enriching an investigation beyond the chain

Where public sources add the context a blockchain alone cannot.