ESMA's Fourth MiCA Update: 321 Authorized CASPs and Three New Non-Compliant Flags
ESMA published its fourth post-deadline update to the Markets in Crypto-Assets register on 31 July 2026, adding 12 newly authorized crypto-asset service providers and pushing the cumulative authorized CASP count to 321. At the same time, three entities were flagged as non-compliant on a separate register maintained at the EU level, with Italy's national regulator CONSOB making the referral. For accounting firms, auditors, and CFOs with EU crypto clients, this latest update tightens the compliance boundary and sharpens the practical questions that must be answered about counterparty status, AML obligations, and financial-statement treatment.
What the Fourth Update Actually Changed
Twelve New Authorized CASPs
The July 31 update added 12 companies to ESMA's MiCA-authorized CASP register, spanning four EU member states. Three of the new entrants are German cooperative banks operating under the Volksbank/Raiffeisenbank network: Volksbank Raiffeisenbank Oberbayern Südost, VR Bank Schleswig-Holstein Mitte, and VR-Bank Landau-Mengkofen. Their inclusion is notable because it confirms that traditional deposit-taking institutions are pursuing MiCA authorization as a route to offering crypto-asset services, rather than relying solely on transitional grandfathering arrangements.
Spain contributed two entries: Basque Pay and Fintech Payments. France added four: Finary, Woorton, Blockchain Process Security, and Shares Financial Assets. The breadth of firm types, ranging from retail-facing fintechs to portfolio management platforms, illustrates that MiCA is now being applied across meaningfully different business models, each carrying distinct compliance and accounting implications.
Three Entities Flagged as Non-Compliant
ESMA's update also extended the non-compliant entities register, adding Cervo Rendisco, Flandenzo, and Corona Fondenza. All three were referred by CONSOB, Italy's securities and markets regulator. The non-compliant register now contains 167 entries in total. This register is not a warning list or a watchlist: it identifies firms that have been determined by a national competent authority to be operating outside MiCA's authorization requirements. For any firm whose clients interact with these entities, that determination has immediate practical consequences.
Stable Counts for Token Issuers
The update left two other MiCA-related registers unchanged. The count of authorized e-money token (EMT) issuers remains at 41, and the asset-referenced token (ART) issuer register continues to show zero entries. The absence of any authorized ART issuers is a significant regulatory data point: it means no entity has yet achieved authorization under MiCA's most stringent token category, which carries reserve, reporting, and capital requirements that are considerably more demanding than those for EMTs.
Context: MiCA Authorization Since the July 1 Deadline
How the Transitional Regime Works
MiCA's full application date for CASP authorization was 30 December 2024, but member states were permitted to run transitional regimes allowing previously registered firms to continue operating for up to 18 months. That transitional window began closing at different speeds depending on each member state's domestic rules. The July 1 deadline referenced in ESMA's update marks a significant moment in that wind-down: firms that have not secured MiCA authorization or that fall outside a valid transitional arrangement are, from that point, operating without legal cover.
The pace of additions since that deadline, four updates in roughly a month, reflects ESMA coordinating with national competent authorities as each jurisdiction processes its own pipeline of applications. The register is a live document, not a one-time snapshot, and accounting professionals should treat it accordingly.
What the Growing Non-Compliant Register Signals
The non-compliant register's growth from zero at the regulation's effective date to 167 entries is the more consequential trend for compliance and risk professionals. National regulators are actively identifying and referring firms that are not meeting MiCA's authorization requirements. CONSOB's three referrals in this cycle add to Italy's existing contributions to the list. Accounting firms with Italian crypto-sector clients should verify counterparty status against both the authorized CASP register and the non-compliant register as a baseline due-diligence step.
For context on how ESMA has been framing its supervisory expectations around MiCA's transitional period, see our earlier analysis of ESMA's MiCA transitional period and CASP supervision priorities.
Accounting and Financial Reporting Implications
Counterparty Classification on the Balance Sheet
Whether a CASP is on ESMA's authorized register or on the non-compliant register is not merely a regulatory compliance question; it feeds directly into how balances held with, or receivables due from, that entity are classified and disclosed on a client's financial statements. A counterparty on the non-compliant register presents a materially different risk profile from an authorized one. Auditors assessing going-concern risk, credit risk, or the recoverability of crypto-asset balances will need to factor in whether the counterparty holds a valid MiCA authorization.
Under IFRS 9, the credit-risk assessment of financial instruments involves evaluating counterparty-specific factors. A firm operating without MiCA authorization in a jurisdiction that requires it may represent an elevated probability of regulatory action, enforcement, or forced wind-down. That assessment should inform expected credit loss calculations and any related disclosures in the notes to financial statements.
Revenue Recognition and Service Agreement Validity
Where accounting firms or their clients have entered into service agreements with CASPs, the MiCA authorization status of the counterparty may affect the enforceability of those contracts under applicable national law. Finance teams should review material contracts with crypto-asset service providers against the current state of ESMA's registers, particularly where those contracts govern custody, trading, or exchange services that fall within MiCA's scope. Revenue recognized under a contract with a non-compliant counterparty may carry additional disclosure obligations.
Digital Asset Accounting Software and Register Monitoring
Firms using digital asset accounting software to record and reconcile crypto-asset positions will need a process for tagging transactions by CASP authorization status. This is relevant both for internal controls documentation and for audit trail purposes. If a platform used by your clients has appeared on the non-compliant register, transactions routed through that platform after the determination date carry a qualitatively different risk label than those routed before. Your crypto bookkeeping software workflow should accommodate this distinction, either through system flags or through supplementary compliance documentation.
This connects to the broader challenge of maintaining accurate crypto accounting software processes in a regulatory environment where the authorized-entity landscape is changing on a monthly, sometimes weekly, basis. For further reading on what a delayed US regulatory framework means for firms operating across jurisdictions, our piece on Hungary's MiCA licensing milestone and what it signals for EU authorizations provides useful comparative context.
AML and KYC Obligations for EU Firms
Counterparty Due Diligence
The EU's Anti-Money Laundering framework, and the forthcoming AMLA (Anti-Money Laundering Authority) regulation, sit alongside MiCA rather than inside it, but the two regimes interact. A CASP's MiCA authorization status is a relevant input to a firm's customer due diligence and enhanced due diligence assessments. Dealing with an entity on ESMA's non-compliant register may, depending on the firm's internal risk policy, trigger an obligation to apply enhanced due diligence, escalate to a compliance officer, or in the most serious cases, consider a suspicious activity report.
Accounting firms acting as auditors or advisers to businesses that hold assets with a non-compliant CASP should document their own counterparty risk assessment. The appearance of 167 entities on the non-compliant register means this is no longer a hypothetical edge case: it is a real population of service providers that clients may be using.
German Cooperative Banks and AML Risk Tiering
The addition of three VR/Volksbank-affiliated cooperative banks to the authorized CASP register has a specific AML implication. These institutions already operate under the German Banking Act (KWG) and BaFin supervision, and their MiCA authorization layered on top of existing prudential oversight. For firms dealing with these entities, the counterparty risk profile is meaningfully different from that of a standalone crypto-native firm without a banking license. The AML risk tiering applied to transactions with these banks can reasonably reflect their dual regulatory status.
Practical Steps for Accounting Firms and CFOs
Immediate Actions
First, reconcile your client's list of CASP counterparties against the current ESMA register. ESMA publishes the register publicly and updates it without a fixed schedule, so a process dependent on annual checks is inadequate in the current environment. A monthly review cadence is the minimum defensible standard given the update frequency observed since July 1.
Second, check the non-compliant register separately. The two registers are distinct: a firm's absence from the authorized list does not automatically mean it appears on the non-compliant list, but the non-compliant list is the more urgent one to screen against. Any client holding material assets with a non-compliant entity needs an immediate risk assessment and a documented escalation decision.
Third, review service-provider contracts. Where your firm or your clients engage CASPs for custody, trading, portfolio management, or exchange services under MiCA's scope, validate that the counterparty remains authorized. Authorization can be withdrawn as well as granted.
For CFOs Specifically
CFOs at firms with material crypto-asset positions should build ESMA register monitoring into the quarterly close process. The non-compliant register's 167 entries represent real credit and operational risk exposures that need to be disclosed if they are material. Board-level reporting on crypto counterparty risk should include a CASP authorization status summary as a standing agenda item.
The ART issuer register showing zero entries is also relevant for treasury teams evaluating stablecoin usage. It means that any stablecoin that presents itself as an asset-referenced token is either operating under a transitional arrangement or is not authorized under MiCA. CFOs should obtain clarity from legal and compliance teams on the MiCA status of any stablecoin their treasury currently holds or intends to use as a settlement vehicle.
Frequently Asked Questions
What is ESMA's MiCA CASP register and who maintains it?
ESMA maintains the EU-wide register of authorized crypto-asset service providers under the Markets in Crypto-Assets Regulation. National competent authorities, such as BaFin in Germany, AMF in France, CNMV in Spain, and CONSOB in Italy, process applications and notify ESMA, which then updates the central register. Firms must be listed as authorized to provide MiCA-regulated services without relying on a valid transitional arrangement.
What does it mean for a firm to be on the non-compliant entities register?
Appearing on ESMA's non-compliant entities register means a national competent authority has determined that the entity is providing MiCA-regulated services without authorization. It is not a preliminary warning: it is a regulatory finding. Dealing with such an entity after that determination carries legal, AML, and financial-reporting risk for any counterparty or adviser.
Why does the ART issuer register still show zero entries?
Asset-referenced tokens face the most demanding authorization requirements under MiCA, including reserve asset rules, reporting obligations, and capital requirements. As of ESMA's July 31 update, no issuer has yet completed that process and been listed. This means any token marketed as an ART is currently either operating under a transitional arrangement or is not MiCA-authorized.
How should an auditor treat a client's assets held with a non-compliant CASP?
The auditor should assess whether the non-compliant status creates a heightened risk of asset loss, regulatory freeze, or forced wind-down at the counterparty. Under IFRS 9, this feeds into the expected credit loss assessment for any receivable from, or deposit held with, that entity. Material exposures should be disclosed. If the exposure is significant to the going-concern assessment, that determination must be documented and reported in accordance with ISA 570.
How frequently is the ESMA MiCA register updated?
ESMA does not publish a fixed update schedule. Four updates were published in roughly one month following the July 1 transitional deadline, indicating that updates can occur at any point. Accounting firms and CFOs should not rely on annual or even quarterly checks: a monthly reconciliation process is the minimum defensible standard given the observed update cadence.
Source: Cointelegraph
