CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

EU 21st Sanctions Package: The Crypto Third-Country Ban and What It Means for Your Firm

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING EU 21st Sanctions Package: The CryptoThird-Country Ban and What It Means forYour Firm

The European Union's 21st sanctions package, published in August 2026, breaks new ground. For the first time, EU sanctions rules introduce what analysts are calling a "third-country ban" on crypto asset activity, meaning restrictions that target the geography of a service rather than only the identity of a counterparty. For accounting firms, auditors, and CFOs with any exposure to digital assets, this is not a background regulatory update. It redraws the perimeter of what transactions can be booked, what balances can be held, and what disclosures are required.

EU 21st Sanctions Package: The Crypto Third-Country Ban and What It Means for Your Firm

What the 21st Sanctions Package Actually Says

Previous EU sanctions packages targeting crypto largely followed the conventional pattern: freeze the assets of named individuals and entities, prohibit EU persons from transacting with them, and require crypto asset service providers (CASPs) to screen and block accordingly. The 21st package retains all of that, but layered on top is a geographic restriction that is structurally different.

The Third-Country Dimension

The new rules prohibit EU-authorised CASPs from providing services in or to specified third countries, where those services relate to crypto assets and where the concern is that the jurisdiction provides a channel for sanctions circumvention. The logic is straightforward: if a CASP can freely onboard users or process transactions routed through a non-EU jurisdiction that lacks equivalent controls, the entire EU sanctions regime can be bypassed with a single routing decision. The package addresses that gap directly.

This geographic layer means that compliance is no longer satisfied solely by screening counterparties against EU consolidated lists. Firms must also assess where a transaction originates or terminates, and whether that geography itself triggers a restriction, regardless of whether the specific counterparty is named on any list.

Interaction with Existing CASP Obligations

EU-authorised CASPs already operate under MiCA's authorisation framework and the Transfer of Funds Regulation's travel rule requirements. The 21st package sits on top of both. A CASP that is MiCA-compliant and travel-rule-compliant is not automatically sanctions-compliant under the new geographic rules. The three regimes are cumulative, not alternative. For firms advising CASPs or holding CASP investments on balance sheet, that layering has direct implications for how you assess a client's or investee's regulatory risk profile.

Who Is Directly Affected

The most immediate impact falls on regulated CASPs operating under MiCA authorisations across EU member states. But the downstream effects reach further.

Accounting Firms and Auditors

Firms that audit CASPs, or that audit corporates with material crypto treasury positions, now need to incorporate the third-country ban into their going-concern and risk assessment work. An audit client that routes a meaningful portion of its crypto volume through a restricted jurisdiction has a regulatory exposure that must be evaluated, disclosed, and potentially qualified. The same applies to firms providing outsourced compliance or financial-crime risk functions to CASPs: the scope of the engagement may need to be extended to cover geographic screening, not just counterparty screening.

From a MiCA compliance and institutional quality in European digital finance standpoint, the 21st package accelerates a trend that was already visible: the bar for what counts as adequate crypto compliance in Europe keeps rising, and firms whose internal frameworks were calibrated to earlier-generation requirements are now behind the curve.

CFOs and Treasury Teams

Corporate treasury teams holding crypto assets, or using crypto rails for cross-border payments, face two distinct questions. First, does the treasury's current counterparty or routing infrastructure pass through a restricted third country? Second, does the firm's CASP provider have adequate controls in place to ensure that the firm's own transactions are not inadvertently in breach? The second question matters because the regulations place obligations on both the CASP and, in some circumstances, the client entity. Ignorance of a routing geography is not a defence.

CFOs should also consider whether existing disclosures in annual reports and interim financial statements adequately capture this new regulatory layer. If a material portion of a firm's crypto activity is now subject to geographic restrictions, that is a contingent liability and a going-concern factor that auditors will ask about.

Fund Managers and Institutional Investors

Fund managers with digital asset allocations need to verify whether any of their holdings are custodied or administered through structures that touch restricted jurisdictions. This includes funds-of-funds and structured products where the underlying CASP exposure may not be immediately visible in the top-level fund documents. A position that appears clean at the fund level may carry a breach at the sub-fund or custodian level.

Accounting and Reporting Implications

Asset Impairment and Fair Value

Under both IFRS and US GAAP, crypto assets held at fair value require continuous assessment of whether market conditions or regulatory events have affected that value. A third-country ban that restricts the ability to trade, transfer, or liquidate a position in a particular geography is a Level 3 fair value input: it affects the principal market for the asset and the firm's ability to exit the position at the quoted price. Finance teams should review their fair value hierarchy disclosures and consider whether any adjustment is warranted.

For assets carried under the cost-less-impairment model, the question is whether the new restrictions constitute an impairment trigger. If a crypto position is held through a CASP that is itself restricted from operating in its primary market, the recoverability of that position is materially affected.

Provisions and Contingent Liabilities

Where a firm has already transacted in a geography that may now be restricted, or where there is uncertainty about whether past activity complies with the new rules, a provision or contingent liability disclosure may be required under IAS 37. The threshold is a present obligation as a result of a past event, with a probable outflow of resources. Regulatory fines or required disgorgement of proceeds from restricted activity could meet that test.

How Crypto Accounting Software Needs to Respond

The geographic dimension of the 21st package creates a direct requirement for crypto accounting software to capture and flag transaction geographies, not just counterparty identities. Firms using digital asset accounting software that was built around counterparty-level sanctions screening will need to assess whether that software can be configured to flag transactions by routing jurisdiction. Where it cannot, a manual override process is needed in the interim, with a technology upgrade roadmap for the medium term.

This is also worth considering when evaluating crypto bookkeeping software for CASP clients: geographic screening capability is now a compliance-critical feature, not a nice-to-have. Firms that help clients select or configure such software have a duty to flag this gap.

AML and Financial Crime Compliance

The AML implications of the third-country ban interact closely with the existing travel rule framework under the Transfer of Funds Regulation. The travel rule requires originator and beneficiary information to travel with any crypto transfer above the threshold. The 21st package's geographic restrictions add a further question: even where travel rule data is complete, does the routing geography itself create a breach?

Transaction Monitoring Reconfiguration

Compliance teams should expect to reconfigure transaction monitoring rules to add geographic flags alongside the existing counterparty and threshold-based alerts. This is not a trivial exercise. Many transaction monitoring systems in the crypto space were built with blockchain address screening as the primary control, with jurisdiction-level logic grafted on as a secondary layer. Inverting that priority, or at least giving the geographic layer equal weight, requires a formal rule-set review and, in many cases, vendor engagement.

The interaction with how AI-driven crypto crime is reshaping AML obligations for accounting firms is also relevant here: sophisticated actors seeking to exploit restricted geographies are increasingly using AI-assisted transaction structuring to obscure routing paths. Firms need monitoring systems that can detect layering through multiple jurisdictions, not just direct transfers to restricted geographies.

Suspicious Transaction Reporting

Where a firm identifies a transaction that may have touched a restricted jurisdiction, even historically, that may trigger a suspicious transaction report (STR) obligation under national AML legislation transposing the EU's Anti-Money Laundering Directives. The bar for reporting is reasonable suspicion, not certainty. Compliance officers should take a conservative approach in the period immediately following the package's adoption, while enforcement guidance from national competent authorities is still being issued.

Practical Steps for Firms: A Prioritised Checklist

Given the novelty of the geographic restriction, the most pressing need is a clear internal action plan. The following steps reflect the areas of highest immediate risk.

Step 1: Jurisdictional Mapping

Before anything else, firms need to know which third countries are specified under the 21st package and map their current client base, transaction flows, and custody arrangements against that list. This mapping should cover not only direct counterparties but also intermediary CASPs and sub-custodians. A transaction that passes through a restricted jurisdiction at any point in its routing may be in scope.

Step 2: Technology Gap Assessment

Review whether current crypto accounting software, transaction monitoring systems, and onboarding platforms can screen by routing jurisdiction. Where they cannot, document the gap, implement interim manual controls, and initiate a vendor conversation about a timeline for remediation. Regulators will expect firms to demonstrate that they identified the gap and acted on it promptly.

Step 3: Client and Counterparty Notification

Where a CASP has clients whose activity may be affected by the third-country ban, those clients need to be notified and, where necessary, offboarded or restricted from the relevant activities. This has contractual as well as regulatory dimensions: client agreements may need to be reviewed for force majeure or regulatory-change clauses that govern how the CASP can restrict services.

Step 4: Financial Statement Review

Finance teams should review current period and prior period financial statements for any disclosures, valuations, or provisions that may need to be updated in light of the new restrictions. Auditors should be briefed proactively rather than waiting for the next scheduled review.

Step 5: Monitor Enforcement Guidance

The 21st package is adopted legislation, but enforcement guidance from the European Commission and national competent authorities will continue to develop. Firms should assign a named individual to track that guidance and escalate material developments to senior management and audit committees promptly.

EU 21st Sanctions Package: The Crypto Third-Country Ban and What It Means for Your Firm

Frequently Asked Questions

Does the third-country ban apply to all crypto assets, or only specific types?

The restrictions apply to crypto assets broadly, consistent with how the EU's sanctions and MiCA frameworks define the asset class. There is no carve-out for specific asset types such as stablecoins or utility tokens at this stage. Firms should apply the restrictions across their full digital asset book until further enforcement guidance narrows or clarifies the scope.

If a firm's crypto accounting software flags a transaction after the fact, is the firm still liable?

Yes. The obligation is to prevent the restricted transaction from occurring, not merely to detect it retrospectively. After-the-fact detection may mitigate a penalty, particularly if the firm self-reports and cooperates with the competent authority, but it does not eliminate liability. The goal of any technology upgrade should be pre-transaction geographic screening, not post-transaction reporting only.

How does the third-country ban interact with the MiCA authorisation regime?

MiCA authorisation permits a CASP to operate across EU member states under a passporting regime, but it does not authorise activity in third countries. The 21st package's restrictions add a further prohibition on certain third-country services on top of MiCA's existing scope limitations. A MiCA-authorised CASP that was not providing services in restricted jurisdictions is largely unaffected operationally, but must still verify that its transaction routing does not pass through restricted geographies.

Are non-EU firms affected if they process EU-originating transactions?

The extraterritorial reach of EU sanctions is a complex legal question, but as a general principle, any firm that processes transactions involving EU persons or EU-origin funds may be subject to EU sanctions obligations. Non-EU CASPs that service EU clients should take legal advice on their exposure under the 21st package, particularly if any of their routing infrastructure touches restricted third countries.

What should an audit committee be asking management about this right now?

Audit committees should ask management to confirm: which third countries are listed under the 21st package; whether the firm has any direct or indirect exposure to those jurisdictions through client activity, custody arrangements, or transaction routing; whether current technology systems can screen at the geographic level; and whether any provisions or contingent liability disclosures are required in the next reporting period. Management should be able to answer those questions within days, not weeks.

Source: Elliptic

EUGLOBALGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
FATF's PPP Report: Crypto AML Gaps Firms Must Close Now
AML/KYC & Licensing
Digital Sovereignty Is Now a Board-Level Risk: What DORA and the ECB Mean for Crypto Accounting Software
AML/KYC & Licensing
Four Financial Centres Racing to Lead on Crypto Regulation
AML/KYC & Licensing
Continuous Monitoring: Why a Cleared Crypto Screening Can Become a Liability