Regulation (EU) 2023/1114
MiCA explained: who needs authorisation, and what changed when grandfathering ended
MiCA creates a single authorisation regime for crypto across the EU and splits obligations three ways between issuers and service providers. Every national transitional window has now closed. This guide sets out what each group must hold, who supervises, and what the end of grandfathering means for firms still trading.
Markets in Crypto-Assets ยท Fully applicable since 30 December 2024 ยท Transition closed 1 July 2026
Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.
- Instrument
- Regulation (EU) 2023/1114
- Fully applicable since
- 30 December 2024
- Transition closed
- 1 July 2026 โ no cover remains anywhere in the EU or EEA
- Who is in scope
- Crypto-asset issuers and crypto-asset service providers
- Supervisor
- National authorities; ESMA maintains the public register
- Sharpest sanction
- Withdrawal of authorisation, which ends the business in the EU
The three issuer regimes
MiCA creates a single authorisation regime for crypto across the EU and splits obligations three ways.
- Ordinary crypto-assets. Issuers must publish a white paper with prescribed content, notify it to their competent authority, keep marketing fair and not misleading, and accept legal liability for what the white paper says.
- Asset-referenced tokens. Full authorisation, an approved white paper, a segregated reserve of assets, own funds and redemption rights.
- E-money tokens. Issuable only by credit institutions or electronic money institutions. Redeemable at par on demand, and cannot pay interest.
Tokens deemed significant by size or usage are pulled up to EBA supervision with heavier requirements.
Crypto-asset service providers
The third group is crypto-asset service providers: custody, trading platforms, exchange, order execution, placing, reception and transmission, advice, portfolio management and transfers. Each needs authorisation from a national regulator, which then passports across the EU.
The obligations look like MiFID adapted for crypto: prudential safeguards, fit-and-proper management, segregation and safekeeping of client assets, conflicts policies, outsourcing controls, complaints handling, and ICT resilience via DORA.
Market abuse and the travel rule
Title VI adds a market abuse regime with a positive duty to detect and report suspicious orders and transactions, and the Transfer of Funds Regulation layers the travel rule on top. Supervision sits with national authorities, with ESMA maintaining the public register of authorised firms.
The sharp end is not the fine
It is withdrawal of authorisation, which ends the business in the EU. That is a different kind of risk from a monetary penalty, and it is the reason MiCA readiness is treated as an existential question rather than a budget line.
Every transitional window is now shut
Article 143(3) let member states grant existing providers a transitional period of up to 18 months from 30 December 2024. States chose different lengths, and many attached an earlier filing deadline as a condition of benefiting at all. ESMA confirmed in April 2026 that there would be no extension, and the outer boundary of 1 July 2026 has now passed. There is no transitional cover anywhere in the EU or EEA. Serving EU clients requires a full authorisation, or passporting in from a firm that holds one.
The scale of the contraction is worth stating plainly. Estimates put the active pre-MiCA provider population at somewhere between 1,100 and 1,300 firms, against roughly 230 on ESMA's register in late June 2026. Grandfathering never conferred passporting rights, and market abuse and travel rule obligations applied from the start with no transition at all.
Transitional periods by member state
Historical now, but still material: whether a firm was lawfully trading during 2025 and early 2026 depends on which window its member state elected and whether the attached filing condition was met.
| Window | Closed | Member states | Conditions attached |
|---|---|---|---|
| 6 months | 30 June 2025 | Finland, Hungary, Latvia, Netherlands, Poland, Slovenia | Firms in these states have been operating unlawfully without authorisation for over a year |
| 9 months | 30 September 2025 | Sweden | Full benefit conditional on filing by a set date |
| 12 months | End December 2025 | Austria, Germany, Ireland, Lithuania, Slovakia | Germany conditioned the full period on an earlier application date |
| 18 months | 1 July 2026 | Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, France, Greece, Italy, Luxembourg, Malta, Portugal, Romania, Spain | Czechia required filing by 31 Jul 2025; Belgium and Bulgaria by 8 Oct 2025; Denmark by 30 Dec 2024; Italy required AML-registered VASPs to file by 30 Dec 2025 |
Sources differ on a small number of states, in particular whether Greece and Spain elected 12 or 18 months. ESMA's published list of grandfathering periods under Article 143(3) is the record to check, and it carries its own caveat that some notified periods were expectations rather than enacted law. Since every window has now closed, the distinction is historical for compliance purposes but still matters for assessing the lawfulness of activity conducted in 2025 and early 2026.
Common questions
Is there any transitional cover left under MiCA?
No. Article 143(3) let member states grant existing providers up to 18 months from 30 December 2024. ESMA confirmed in April 2026 that there would be no extension, and the outer boundary of 1 July 2026 has passed. There is no transitional cover anywhere in the EU or EEA. Serving EU clients requires a full authorisation, or passporting in from a firm that holds one.
How many firms actually made it through authorisation?
Estimates put the active pre-MiCA provider population at somewhere between 1,100 and 1,300 firms, against roughly 230 on ESMA's register in late June 2026.
Did grandfathering ever allow passporting?
No. Grandfathering never conferred passporting rights, and market abuse and travel rule obligations applied from the start with no transition at all.
Who can issue an e-money token?
Only credit institutions or electronic money institutions. E-money tokens must be redeemable at par on demand and cannot pay interest.
What does a crypto-asset service provider have to hold?
Authorisation from a national regulator, which then passports across the EU. The obligations look like MiFID adapted for crypto: prudential safeguards, fit-and-proper management, segregation and safekeeping of client assets, conflicts policies, outsourcing controls, complaints handling, and ICT resilience via DORA.
What is the real enforcement risk under MiCA?
Not the fine. Withdrawal of authorisation, which ends the business in the EU.
Does MiCA pull us into DORA as well?
Yes. Crypto-asset service providers are one of the categories of EU financial entity DORA covers, and MiCA routes ICT resilience through it. MiCA sets the authorisation and conduct regime; DORA supplies the operational resilience layer underneath it.
The other two guides
Regulation (EU) 2022/2554
DORA โ Digital Operational Resilience Act
One binding set of ICT resilience rules across roughly twenty categories of EU financial entity: governance the board owns, an incident clock measured in hours, resilience testing, and a Register of Information covering every ICT contract.
Read the DORA guideDirective (EU) 2022/2555
NIS2 โ Network and Information Security Directive
A directive, so what binds you is your member state's law and not the directive text. Ten minimum security measures, a three-stage reporting clock, personal liability for management โ and 27 national timetables that do not line up.
Read the NIS2 guideProducing the evidence is the part that does not stop
ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score โ cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.
Sources and status
These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.
Spotted something out of date? [email protected].