CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA MiCA Register Reaches 309 CASPs as BNY Mellon Unit and 14 Others Join in Third Update

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING ESMA MiCA Register Reaches 309 CASPs asBNY Mellon Unit and 14 Others Join inThird Update

The European Securities and Markets Authority added 15 crypto-asset service providers to its interim MiCA register on 27 July 2026, pushing the total roster to 309 licensed entities. The third post-deadline update is significant not just for its size but for its composition: a subsidiary of one of the world's largest custodian banks and three German cooperative banks are now formally recognised under the EU's first unified crypto regulatory framework. For accounting firms, auditors, and CFOs operating across the EU, the expanding register reshapes counterparty due diligence, AML screening obligations, and digital asset accounting workflows in concrete ways.

ESMA MiCA Register Reaches 309 CASPs as BNY Mellon Unit and 14 Others Join in Third Update

What the Third Update Actually Contains

ESMA's July update follows two earlier rounds of additions since the July 1 transitional deadline. This third batch of 15 new CASPs comes from eight jurisdictions, and the geographic spread matters for compliance teams that need to map regulatory status across multiple member states.

Banking Institutions Entering the Register

Four of the 15 new entrants are banking institutions, which is a notable pattern. BNY SA/NV, the Belgian subsidiary of US custodian giant BNY Mellon, is the highest-profile addition. Alongside it, three German cooperative banks received authorisation: Spar-und Kreditbank Rheinstetten, VR-Bank Augsburg-Ostallgäu, and Raiffeisenbank Falkenstein-Wörth. These are not crypto-native firms. They are regulated deposit-taking institutions that have sought CASP status, signalling that mainstream European banking is moving toward offering crypto-asset services under the MiCA umbrella rather than standing apart from it.

For corporate treasury teams and CFOs who hold digital assets or are considering custodial arrangements, the entry of established banking counterparties into the MiCA register is a material development. It widens the pool of MiCA-compliant custodians and service providers available without stepping outside the regulated perimeter.

Crypto-Native and Infrastructure Providers

The remaining 11 additions span a range of business models. Coinify and Bleap are digital asset platforms. Bulgaria contributes Altcoins BG and Digital Assist. Denmark adds SafeLynx Technologies and Januar, the latter described as a digital asset infrastructure company. Latvia's entries include Bleap and Nodu Digital. Belgium adds BNY SA/NV (already noted), Cyprus and the Netherlands each add one provider, and Liechtenstein adds one as well.

Germany and Denmark account for the largest national contributions with three new CASPs each, followed by Bulgaria and Latvia with two apiece. Belgium, Cyprus, Liechtenstein, and the Netherlands each contribute one.

Jurisdiction-by-Jurisdiction Breakdown

The table below summarises the new additions by country based on the information disclosed in ESMA's update.

Jurisdiction Number of New CASPs Named Providers
Germany 3 Spar-und Kreditbank Rheinstetten, VR-Bank Augsburg-Ostallgäu, Raiffeisenbank Falkenstein-Wörth
Denmark 3 SafeLynx Technologies, Januar
Bulgaria 2 Altcoins BG, Digital Assist
Latvia 2 Bleap, Nodu Digital
Belgium 1 BNY SA/NV
Cyprus 1 Not named in source
Liechtenstein 1 Not named in source
Netherlands 1 Not named in source

What Remained Unchanged

ESMA confirmed no changes to other MiCA-related registers in this update. The registers for authorised issuers of asset-referenced tokens (ARTs), e-money tokens (EMTs), and crypto assets were unaffected. The non-compliant entities list also saw no new additions. That last point is worth tracking: a stable non-compliant list alongside steady CASP growth suggests the immediate post-deadline period has not triggered a surge in enforcement actions, though the regulatory machinery is clearly still processing applications.

MiCA Compliance Costs and Market Structure Risks

The register's growth does not mean the compliance environment is straightforward. Comments attributed to the CEO of Gate Europe in the source reporting indicate that the ongoing cost of maintaining a MiCA licence is a genuine concern, with warnings that smaller firms could be priced out of the market over the longer term. This is a structural dynamic that compliance officers and auditors need to keep in view.

Concentration Risk in the CASP Ecosystem

If licensing costs systematically favour larger, well-capitalised institutions, the registered CASP universe could consolidate over time. Accounting firms advising smaller crypto-native clients should factor this into licensing strategy discussions now rather than at renewal. A client that can sustain initial authorisation may face a different calculation twelve or twenty-four months later when ongoing compliance costs compound. This is a planning conversation, not just a regulatory one.

The Banking Sector's Entry as a Structural Signal

The presence of four banking institutions in a single update cycle is not incidental. European banks have historically approached crypto-asset services cautiously, partly due to capital treatment under CRR and partly due to reputational uncertainty. BNY SA/NV's registration alongside three German cooperative banks suggests that the MiCA framework's clarity is now sufficient to justify the compliance investment for a broader range of banking entities. For auditors and CFOs at financial institutions still evaluating the decision, this cohort provides a useful reference point: these are not fringe actors but regulated deposit-takers with existing compliance infrastructures.

Accounting and AML Implications for Firms and CFOs

The expanding MiCA register has direct practical consequences for accounting firms and corporate finance teams, not just for the CASPs themselves.

Counterparty Due Diligence Obligations

Under the EU's AML framework, firms conducting business with crypto-asset service providers must verify that those counterparties hold appropriate authorisation. An up-to-date register check against ESMA's interim list is now part of standard onboarding and periodic review. With 309 registered entities and the list still growing, firms need a repeatable process for checking status, not a one-time lookup at the start of a relationship. Digital asset accounting software that integrates regulatory status feeds can reduce the manual burden here, but the procedural obligation rests with the firm regardless of tooling.

Financial Statement Disclosures and Custody Arrangements

CFOs holding digital assets on behalf of their entities face disclosure questions under both IFRS and national GAAP standards. When the custodian or service provider is a MiCA-registered CASP, the nature of the arrangement, safeguarding obligations, and client asset segregation rules are defined by the framework. That is relevant to balance sheet classification and to the notes disclosures around concentration of custody risk. Firms advising on IFRS crypto asset treatment versus FASB fair value requirements should now incorporate CASP registration status as a factor in the custody arrangement analysis.

Travel Rule and Transaction Monitoring

MiCA-registered CASPs are subject to the EU's transfer of funds regulation, including Travel Rule obligations for crypto-asset transfers. When an accounting firm or corporate treasury transacts with a newly registered CASP, it should confirm that the counterparty's Travel Rule compliance infrastructure is operational. A CASP being on the register does not automatically mean its transaction monitoring systems are fully configured; the registration signals authorisation, not a compliance audit. This distinction matters when assessing the risk profile of a new counterparty relationship.

The risk landscape around post-MiCA client migration has already drawn attention from regulators. Our earlier coverage of the AMLA warning on AML risks in post-MiCA client migration sets out the broader context for why onboarding controls at this stage require particular care. Similarly, the EU's extension of the Belarus crypto ownership ban to all MiCA service providers is a reminder that register membership carries ownership and control screening obligations that must be actively managed.

Tax Reporting Considerations

From a tax perspective, the identity and regulatory status of a CASP is increasingly relevant to DAC8, the EU directive requiring crypto-asset service providers to report user transaction data to tax authorities. With 309 entities now on the register and more expected, CFOs and their advisers should map which registered CASPs their entities or clients use and confirm that reporting flows are configured correctly. Gaps in DAC8 reporting linked to newly registered or recently migrated CASPs are a foreseeable audit risk. Crypto accounting software that automates the capture of CASP-level transaction data will reduce exposure, but the underlying compliance obligation is the firm's to own.

What Accounting Firms Should Do Now

Three immediate actions follow from this update.

Refresh Counterparty Registers

Any internal list of approved or reviewed CASPs should be updated to reflect the July 27 additions. The ESMA interim register is the authoritative source; checking it directly rather than relying on secondary lists is the correct approach. Build a calendar reminder for each subsequent ESMA update cycle, because the register is still evolving and the cadence of additions post-deadline suggests further batches are likely.

Review Custody and Service Agreements

For clients or treasury functions that use any of the 15 newly registered entities, review the service agreement to confirm it references MiCA obligations explicitly, particularly around asset segregation, complaints handling, and disclosure requirements. MiCA introduces minimum contractual standards; an agreement signed before registration may predate those requirements.

Update AML Risk Assessments

The entry of banking institutions into the CASP register changes the risk profile of certain counterparty relationships. A cooperative German bank operating as a CASP carries a different inherent risk rating than a crypto-native startup. AML risk assessments should reflect that distinction and should be reviewed whenever the register changes materially.

ESMA MiCA Register Reaches 309 CASPs as BNY Mellon Unit and 14 Others Join in Third Update

Frequently Asked Questions

What is the ESMA interim MiCA register?

It is the official European Securities and Markets Authority list of crypto-asset service providers that have received authorisation under the Markets in Crypto-Assets Regulation. National competent authorities grant licences; ESMA publishes the consolidated register. Firms on the list are permitted to offer crypto-asset services across the EU under passporting rules.

Why does BNY SA/NV's registration matter for accounting firms?

BNY SA/NV is the Belgian subsidiary of BNY Mellon, one of the world's largest custodian banks. Its entry into the MiCA register signals that major institutional custodians are now operating within the EU regulatory perimeter for crypto-asset services. For accounting firms, this creates a new class of MiCA-regulated custodial counterparty whose contractual terms and safeguarding obligations are governed by the framework, which has direct implications for balance sheet classification and audit procedures around client asset custody.

Does appearing on the ESMA MiCA register mean a CASP is fully compliant with all AML obligations?

No. Registration confirms that a CASP has met the authorisation criteria set by its national competent authority under MiCA. It does not constitute a certification that every operational AML control, Travel Rule system, or transaction monitoring procedure is fully deployed. Accounting firms and CFOs should conduct their own counterparty due diligence beyond a register check.

How should CFOs handle DAC8 reporting when a CASP joins the register mid-year?

DAC8 reporting obligations attach to the CASP, not to the corporate client. However, CFOs should confirm with newly registered counterparties that their reporting systems are configured for the current tax year and that historical transaction data captured before formal registration will be included where required. Any gaps should be documented and escalated to the firm's tax adviser promptly.

What is the risk if a firm continues using a CASP that is not on the ESMA register?

Operating with an unregistered CASP after the MiCA transitional deadline carries regulatory and reputational risk. Depending on the jurisdiction, it may also constitute a breach of AML onboarding obligations, since those rules require counterparties in the crypto-asset sector to hold the relevant authorisations. Accounting firms should flag unregistered CASP relationships to clients as a priority remediation item.

Source: Cointelegraph

EUDEBEGeneralEffectiveAML/KYC & Licensing

Related articles

Tax Reporting
DAC7 Platform Operator Reporting: EU Implementation Status and Compliance Requirements
AML/KYC & Licensing
ESMA MiCA Register Update: 37 New CASPs Approved Post-Deadline
AML/KYC & Licensing
MiCA CASP Authorization: Germany Leads the EU Race as July 1 Deadline Arrives
AML/KYC & Licensing
MiCA Transitional Period Expires July 1 2026: CASP Authorization Is Now Mandatory