Regulation (EU) 2023/1114

MiCA explained: who needs authorisation, and what changed when grandfathering ended

MiCA creates a single authorisation regime for crypto across the EU and splits obligations three ways between issuers and service providers. Every national transitional window has now closed. This guide sets out what each group must hold, who supervises, and what the end of grandfathering means for firms still trading.

Markets in Crypto-Assets ยท Fully applicable since 30 December 2024 ยท Transition closed 1 July 2026

Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.

Instrument
Regulation (EU) 2023/1114
Fully applicable since
30 December 2024
Transition closed
1 July 2026 โ€” no cover remains anywhere in the EU or EEA
Who is in scope
Crypto-asset issuers and crypto-asset service providers
Supervisor
National authorities; ESMA maintains the public register
Sharpest sanction
Withdrawal of authorisation, which ends the business in the EU

The three issuer regimes

MiCA creates a single authorisation regime for crypto across the EU and splits obligations three ways.

  • Ordinary crypto-assets. Issuers must publish a white paper with prescribed content, notify it to their competent authority, keep marketing fair and not misleading, and accept legal liability for what the white paper says.
  • Asset-referenced tokens. Full authorisation, an approved white paper, a segregated reserve of assets, own funds and redemption rights.
  • E-money tokens. Issuable only by credit institutions or electronic money institutions. Redeemable at par on demand, and cannot pay interest.

Tokens deemed significant by size or usage are pulled up to EBA supervision with heavier requirements.

Crypto-asset service providers

The third group is crypto-asset service providers: custody, trading platforms, exchange, order execution, placing, reception and transmission, advice, portfolio management and transfers. Each needs authorisation from a national regulator, which then passports across the EU.

The obligations look like MiFID adapted for crypto: prudential safeguards, fit-and-proper management, segregation and safekeeping of client assets, conflicts policies, outsourcing controls, complaints handling, and ICT resilience via DORA.

Market abuse and the travel rule

Title VI adds a market abuse regime with a positive duty to detect and report suspicious orders and transactions, and the Transfer of Funds Regulation layers the travel rule on top. Supervision sits with national authorities, with ESMA maintaining the public register of authorised firms.

The sharp end is not the fine

It is withdrawal of authorisation, which ends the business in the EU. That is a different kind of risk from a monetary penalty, and it is the reason MiCA readiness is treated as an existential question rather than a budget line.

Every transitional window is now shut

Article 143(3) let member states grant existing providers a transitional period of up to 18 months from 30 December 2024. States chose different lengths, and many attached an earlier filing deadline as a condition of benefiting at all. ESMA confirmed in April 2026 that there would be no extension, and the outer boundary of 1 July 2026 has now passed. There is no transitional cover anywhere in the EU or EEA. Serving EU clients requires a full authorisation, or passporting in from a firm that holds one.

The scale of the contraction is worth stating plainly. Estimates put the active pre-MiCA provider population at somewhere between 1,100 and 1,300 firms, against roughly 230 on ESMA's register in late June 2026. Grandfathering never conferred passporting rights, and market abuse and travel rule obligations applied from the start with no transition at all.

Transitional periods by member state

Historical now, but still material: whether a firm was lawfully trading during 2025 and early 2026 depends on which window its member state elected and whether the attached filing condition was met.

MiCA transitional periods as elected by member state, all closed as at 2 August 2026
WindowClosedMember statesConditions attached
6 months30 June 2025Finland, Hungary, Latvia, Netherlands, Poland, SloveniaFirms in these states have been operating unlawfully without authorisation for over a year
9 months30 September 2025SwedenFull benefit conditional on filing by a set date
12 monthsEnd December 2025Austria, Germany, Ireland, Lithuania, SlovakiaGermany conditioned the full period on an earlier application date
18 months1 July 2026Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, France, Greece, Italy, Luxembourg, Malta, Portugal, Romania, SpainCzechia required filing by 31 Jul 2025; Belgium and Bulgaria by 8 Oct 2025; Denmark by 30 Dec 2024; Italy required AML-registered VASPs to file by 30 Dec 2025

Sources differ on a small number of states, in particular whether Greece and Spain elected 12 or 18 months. ESMA's published list of grandfathering periods under Article 143(3) is the record to check, and it carries its own caveat that some notified periods were expectations rather than enacted law. Since every window has now closed, the distinction is historical for compliance purposes but still matters for assessing the lawfulness of activity conducted in 2025 and early 2026.

Common questions

Is there any transitional cover left under MiCA?

No. Article 143(3) let member states grant existing providers up to 18 months from 30 December 2024. ESMA confirmed in April 2026 that there would be no extension, and the outer boundary of 1 July 2026 has passed. There is no transitional cover anywhere in the EU or EEA. Serving EU clients requires a full authorisation, or passporting in from a firm that holds one.

How many firms actually made it through authorisation?

Estimates put the active pre-MiCA provider population at somewhere between 1,100 and 1,300 firms, against roughly 230 on ESMA's register in late June 2026.

Did grandfathering ever allow passporting?

No. Grandfathering never conferred passporting rights, and market abuse and travel rule obligations applied from the start with no transition at all.

Who can issue an e-money token?

Only credit institutions or electronic money institutions. E-money tokens must be redeemable at par on demand and cannot pay interest.

What does a crypto-asset service provider have to hold?

Authorisation from a national regulator, which then passports across the EU. The obligations look like MiFID adapted for crypto: prudential safeguards, fit-and-proper management, segregation and safekeeping of client assets, conflicts policies, outsourcing controls, complaints handling, and ICT resilience via DORA.

What is the real enforcement risk under MiCA?

Not the fine. Withdrawal of authorisation, which ends the business in the EU.

Does MiCA pull us into DORA as well?

Yes. Crypto-asset service providers are one of the categories of EU financial entity DORA covers, and MiCA routes ICT resilience through it. MiCA sets the authorisation and conduct regime; DORA supplies the operational resilience layer underneath it.

Producing the evidence is the part that does not stop

ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score โ€” cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.

Sources and status

These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.

Spotted something out of date? [email protected].