CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

EU VASPs After MiCA: Who Got Licensed and Who Carries the Risk

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING EU VASPs After MiCA: Who Got Licensedand Who Carries the Risk

MiCA's transitional window closed on 1 July 2026, and the numbers are stark. Of 1,343 crypto service providers operating across the European Economic Area, only 281 secured a full MiCA CASP licence before the deadline. The other 1,062 are now operating outside the law, and a new analysis by blockchain intelligence firm TRM Labs shows they are materially riskier than the firms that made it through. For accounting firms, auditors, and CFOs whose clients either are crypto service providers or rely on them, this is not a background regulatory story. It is a counterparty risk event.

EU VASPs After MiCA: Who Got Licensed and Who Carries the Risk

What the Grandfathering Deadline Actually Meant

Before December 2024, every EU member state ran its own crypto registration or licensing regime. Standards varied enormously. A registration obtained in the most permissive jurisdiction carried the same nominal legitimacy as a full licence from one of the stricter national regulators, and firms chose their domicile accordingly.

MiCA replaced that patchwork with a single authorization standard under the Markets in Crypto-Assets Regulation. Firms already operating under national law before 30 December 2024 were given a transitional period under Article 143(3) to convert their existing national registration into a full CASP licence. That window ran until 1 July 2026. From that date onward, a firm without MiCA authorization cannot lawfully provide crypto asset services anywhere in the EU.

The scale of non-conversion

The conversion rate was low. TRM identified 1,343 firms offering observable crypto services across the EEA before the deadline. Of those, 281 obtained a MiCAR CASP licence. That is roughly one in five. The remaining 1,062 now face three options: exit the market in an orderly way, restructure into an authorized entity, or transfer their customer relationships to a firm that holds a licence. None of those options is quick or frictionless, and all of them create compliance exposures for every party involved.

Which Jurisdictions Converted and Which Did Not

The authorization data reveals a sharp divide between jurisdictions that built licensing capacity early and those that let large registers accumulate under lighter-touch national regimes.

High-conversion jurisdictions

Germany's BaFin authorized 55 of the 57 licensed firms operating in Germany, a conversion rate that reflects BaFin's longstanding requirement for substantive crypto custody licences under the German Banking Act before MiCA arrived. Luxembourg, Cyprus, Malta, and Ireland also achieved high conversion rates relative to their pre-MiCA registers. Malta and Cyprus each authorized more firms (20 and 19 respectively) than Italy, which authorized only 9 of the 145 firms operating on its register. Taken together, Malta, Cyprus, Ireland, and Luxembourg hold 63 of the bloc's 272 identified home authorizations, drawn from a base of just 101 operating firms.

Low-conversion jurisdictions

Lithuania and Poland present the starkest cases of the opposite dynamic. TRM observed 383 firms offering crypto services under Lithuanian registration and over 1,800 entries on Poland's register, though most Polish registrants never ran observable crypto services. Lithuania authorized eight firms from that register of more than 400. Poland authorized none. Greece and Portugal also issued no home authorizations of their own. These figures illustrate precisely the arbitrage problem MiCA was designed to eliminate: low-barrier national regimes attracted large numbers of registrants, and MiCA's more rigorous standard has now filtered most of them out.

Passporting and supervisory concentration

Passporting allows a firm authorized in one member state to operate across the entire bloc. That is by design, but the data shows a side effect: supervisory responsibility is now concentrating faster than market presence. A handful of regulators, particularly BaFin, the Central Bank of Ireland, the Malta Financial Services Authority, and the Commission de Surveillance du Secteur Financier in Luxembourg, are becoming the primary supervisors for firms serving customers in countries where no home authorizations were issued. This is the condition behind the EU's Anti-Money Laundering Authority (AMLA) warnings about uneven AML/CFT standards and regulatory arbitrage within the single market.

The Risk Gap Between Authorized and Unauthorized Firms

Authorization status and risk profile are not independent. TRM's risk ratings, applied to active firms over the trailing twelve months to 6 July 2026, show a clear and significant gap between the two cohorts.

High and Severe risk ratings

Twelve percent of unauthorized firms carry a High or Severe TRM risk rating. Among authorized firms, that figure is 2%. In absolute terms, 30 of 244 rated unauthorized firms fall into the High or Severe category, against just 2 of 90 rated authorized firms. Critically, every Severe rating in the entire dataset belongs to a firm that did not gain authorization. A further 20 unauthorized firms carry a Medium rating, widening the gap further when the full distribution is considered.

Direct illicit exposure

Illicit money reaches both groups at broadly similar aggregate rates. Unauthorized firms sent 0.09% of their volume directly to illicit or high-risk counterparties; authorized firms, 0.07%. At that level the difference looks modest. But the aggregate conceals a tail that matters.

Most firms in both groups have negligible direct illicit exposure. A small number of unauthorized firms are different: several send between 1% and 12% of their total volume straight to illicit addresses. No authorized firm exceeds the 1% threshold. That tail is what creates the acute counterparty risk for any firm absorbing unauthorized customers.

Sanctions exposure

The most significant divergence between the two groups is sanctions exposure. Unauthorized firms sent roughly three times as much volume directly to sanctioned counterparties as authorized firms did. The largest exposures across both cohorts are concentrated in high-risk exchanges and gambling services, but the sanctions gap is the number that will draw the attention of compliance officers and regulators first.

What AMLA Says Happens Next

AMLA issued an advisory note on the end of the MiCAR transitional period identifying three structural consequences: unauthorized firms leave the market, large volumes of customer relationships move or are terminated, and crypto activity concentrates among fewer authorized CASPs. AMLA characterizes these as having a material impact on how the EU crypto market functions.

Risks AMLA has flagged for authorized firms

As unauthorized firms wind down under compressed timelines, their AML controls come under strain. Authorized CASPs absorbing their customers face sudden shifts in their own risk profiles and immediate pressure on transaction monitoring systems calibrated to a different, narrower customer base. Supervisors, meanwhile, lose visibility over the transfers between the two groups precisely when that visibility matters most.

AMLA has asked national supervisors to prioritize oversight of exit planning and customer transfers, and to coordinate across borders as customers migrate. The TRM data gives that request a quantitative foundation: the 30 High or Severe rated unauthorized firms are identifiable now, before transfers happen, and they represent the sharpest concentration of risk that authorized CASPs and their supervisors need to manage.

Accounting and Compliance Implications for Firms and CFOs

The MiCA divide creates concrete work for accounting firms, auditors, and CFOs with EU crypto exposure. Three areas stand out.

Counterparty due diligence and onboarding

Any authorized CASP preparing to absorb customer relationships from an unauthorized firm needs to reassess its counterparty risk framework before transfers occur, not after. The risk data shows that the population of migrating customers is not homogeneous. A small subset carries disproportionate illicit and sanctions exposure. Standard KYC processes designed for retail onboarding may not be calibrated to detect that kind of concentrated tail risk quickly enough. Accounting firms advising CASPs on this transition should be reviewing their clients' enhanced due diligence triggers and transaction monitoring thresholds now. Our detailed look at building a VASP onboarding AML framework sets out what a robust process looks like under current regulatory expectations.

Audit and financial statement exposure

For audit teams, the relevant question is whether any client holds material crypto assets on a platform that has lost its MiCA authorization or is in the process of winding down. Assets held on an unauthorized firm may be subject to withdrawal restrictions, insolvency risk, or operational disruption during a rushed exit. That is a going-concern and asset recoverability question, and it needs to be on the audit planning agenda for any engagement with crypto balance sheet exposure. IFRS and EU GAAP do not provide specific guidance on the custody risk of unauthorized intermediaries, but the general impairment and disclosures framework is clear enough: if material uncertainty exists over the recoverability of an asset, it must be disclosed.

AML and sanctions screening obligations

The three-times sanctions exposure gap between unauthorized and authorized firms is the number that should sharpen attention fastest. EU AML obligations apply to obliged entities transacting with crypto service providers regardless of whether the counterparty is authorized under MiCA. If a client is still routing transactions through an unauthorized firm post-July 2026, that relationship now carries a heightened sanctions screening obligation and a potential regulatory reporting trigger. Accounting firms that double as AML-reporting entities need to assess whether their own procedures adequately cover this scenario.

For firms navigating the broader MiCA compliance picture, our earlier analysis of MiCA's impact on stablecoin accounting teams covers the asset-classification dimensions that sit alongside the licensing story.

EU VASPs After MiCA: Who Got Licensed and Who Carries the Risk

Frequently Asked Questions

What happened to firms that did not gain MiCA authorization by 1 July 2026?

From 1 July 2026, those firms cannot lawfully provide crypto asset services in the EU. They must choose between an orderly market exit, restructuring into an authorized entity, or transferring their customer relationships to a licensed CASP. AMLA expects these transitions to create material market disruption and has asked national supervisors to monitor exit planning closely.

Why did some jurisdictions have very low MiCA conversion rates?

Jurisdictions such as Lithuania and Poland had accumulated very large national registers under relatively permissive pre-MiCA regimes. Many registrants never ran observable crypto services, and those that did often did not meet MiCA's more rigorous authorization requirements. The low conversion rate reflects both the filtering effect of higher standards and the legacy of regulatory arbitrage within the EU's previous patchwork regime.

How much riskier are unauthorized firms compared to authorized ones?

According to TRM Labs data, 12% of unauthorized firms carry a High or Severe risk rating against 2% of authorized firms. Every Severe rating in the dataset belongs to an unauthorized firm. A small subset of unauthorized firms also sends between 1% and 12% of their volume directly to illicit addresses, a threshold no authorized firm crosses.

What does passporting mean for supervisory oversight after MiCA?

Passporting allows an authorized CASP to serve customers across all EU member states from a single home authorization. As a result, supervisory responsibility is concentrating in a small number of member states, particularly Germany, Ireland, Malta, Cyprus, and Luxembourg, whose regulators are now responsible for overseeing firms serving customers in countries that issued no home authorizations. AMLA has flagged this concentration as a driver of potential AML/CFT inconsistency across the bloc.

What should an accounting firm or CFO do right now?

Three immediate steps are worth taking. First, identify any client or portfolio company that holds assets on an unauthorized CASP and assess the recoverability and disclosure implications. Second, review whether any authorized CASP clients are planning to absorb customers from unauthorized firms, and if so, ensure their due diligence and transaction monitoring frameworks are calibrated for the elevated tail risk in that migrating population. Third, check whether any existing counterparty relationships involve unauthorized firms, because EU AML obligations and sanctions screening requirements apply regardless of a counterparty's MiCA status.

Source: TRM Labs

EUDEFRGeneralEnforcementAML/KYC & Licensing

Related articles

Tax Reporting
DAC7 Platform Operator Reporting: EU Implementation Status and Compliance Requirements
AML/KYC & Licensing
ESMA MiCA Register Update: 37 New CASPs Approved Post-Deadline
AML/KYC & Licensing
MiCA Transitional Period Ends: What CASPs Must Do Now
AML/KYC & Licensing
MiCA Transitional Period Expires July 1 2026: CASP Authorization Is Now Mandatory