MiCA Transitional Period Ends: What CASPs Must Do Now
On 1 July 2026, the transitional window built into the Markets in Crypto-Assets Regulation (MiCA) closed permanently. Any crypto-asset service provider (CASP) that had been operating under a national registration while awaiting full MiCA authorization lost that legal cover the moment the deadline passed. For accounting firms, auditors, and CFOs with EU crypto exposure, this is not a background regulatory update: it redraws the map of who can legally transact in the EU and, by extension, who is a safe counterparty on the books. Understanding the specifics of MiCA compliance for crypto businesses is now a front-office task, not a compliance afterthought.
What the Transitional Provision Actually Did
MiCA came into force in stages, with the full CASP authorization framework applying from 30 December 2024. To avoid a cliff-edge for incumbent operators, the regulation allowed member states to grant a transitional period of up to 18 months, letting CASPs that were already licensed or registered under a pre-MiCA national regime keep operating while they worked through the new authorization process.
The prohibition that was only deferred
The key word in that arrangement is "deferred." MiCA Article 59 has always prohibited anyone from providing crypto-asset services in the EU without a CASP authorization. The transitional provision did not suspend that rule; it gave qualifying firms time to get compliant. That time is now gone. A CASP operating today without an authorization on ESMA's register has no lawful basis to serve EU clients, full stop.
There is a further consequence worth flagging: CASPs operating under transitional cover could not passport their services into other member states. That restriction, confirmed in ESMA's statement on transitional measures, means any cross-border activity conducted under the old cover was already limited in scope. Firms that assumed transitional status gave them EU-wide reach were mistaken.
Why the deadline was not the same everywhere
Member states had discretion over how long a transitional window to grant, up to the 18-month ceiling. Several chose shorter periods, meaning the effective cut-off varied by jurisdiction. The Netherlands, Finland, Latvia, Hungary, and Slovenia each granted six months, closing their windows on 30 June 2025. Sweden allowed nine months, with its deadline falling on 30 September 2025. France, Malta, Luxembourg, and others ran the full 18 months to the 1 July 2026 outer limit.
For any firm reviewing counterparty arrangements now, the relevant date is not always 1 July 2026. If a counterparty was registered under a Dutch or Finnish national regime and never obtained a MiCA authorization, its legal basis disappeared more than a year ago. Counterparty due diligence needs to account for that.
Who Is Actually Authorized and Where
ESMA maintains a public register of authorized CASPs, updated weekly. The register is the authoritative source: ESMA and national supervisors have been directing consumers and institutional counterparties to check it before dealing with any provider.
Concentration in a small number of jurisdictions
At the time of writing, 213 CASP entries held authorization across 23 member states. Authorization is highly concentrated: the five largest jurisdictions account for roughly 127 of those entries, close to 60% of the total. Germany leads by volume, though a significant portion of German entries are established banks and brokerages adding narrow crypto permissions to existing licenses rather than crypto-native firms. The more active cluster for crypto-focused businesses sits in Malta, the Netherlands, Cyprus, France, and Ireland.
That concentration matters for CFOs assessing their supply chain of crypto services. If your firm routes custody, trading, or settlement through CASPs, the probability is high that the relevant counterparties are based in one of those five jurisdictions. Any that are not authorized, or authorized only in a jurisdiction whose transitional window closed early, should be flagged immediately.
One note on the register figures: ESMA is explicit that authorizations reported by national competent authorities (NCAs) are not displayed immediately. The count rises from one weekly update to the next, so any snapshot figure should be dated to the day it was pulled. Do not rely on a number cited without a date.
The authorization spike at year-end 2025
Authorizations accumulated slowly through most of 2025 and then accelerated sharply. December 2025 alone saw 41 new authorizations, the single largest monthly increase, as firms raced to meet the national filing cut-offs that clustered around the year-end. The pipeline behind that spike will continue to flow through into the register over the coming weeks and months as NCAs process outstanding applications. Firms monitoring counterparty status should check the register regularly rather than treating any single pull as definitive.
Three Paths for Firms That Are Not Yet Authorized
For any CASP that has not yet secured a MiCA authorization, the options narrow sharply now that the transitional period is over. There is no fourth option that preserves EU client relationships without legal exposure.
Submit a complete Article 63 application and wait
An organization that has not yet applied, or whose application is still in process, can submit or continue under Article 63. Application quality is what drives the outcome: the thoroughness of governance documentation, the depth of AML/CFT controls, and the demonstrable substance of the applicant entity. Product type and years of prior national registration are not substitutes for that. NCAs assess what is in front of them, and incomplete or thin applications slow the process. There is no fast track created by the deadline passing.
Operate under a group entity's passport
If a parent company or affiliate already holds a CASP authorization, MiCA's passporting mechanism can extend that license to cover operations in other member states, provided the authorized entity has genuine substance and its monitoring and screening actually cover the transaction flows it absorbs. Shared branding between a group entity and an unauthorized subsidiary is not enough. Supervisors will look at where the real decision-making sits and whether the controls are actually applied to the relevant activity.
Wind down EU onboarding in an orderly way
For organizations that are not in the authorization process and do not have an authorized group entity to lean on, the only compliant path is to cease EU client onboarding and conduct a structured wind-down of existing EU relationships. The "reverse solicitation" carve-out in MiCA Article 61 is not a viable alternative for most operators. That provision permits a CASP without EU authorization to serve an EU client only when the client approached the firm entirely on their own initiative, with no prompting of any kind. Any advertising, app store listing, affiliate arrangement, influencer engagement, or search marketing directed at the EU breaks that condition. In practice, reverse solicitation covers a narrow set of circumstances and should not be treated as a business-as-usual workaround.
Ongoing Obligations for Authorized CASPs
Obtaining authorization is the start of the obligation set, not the end of it. MiCA imposes a structured framework of ongoing duties that apply from the first day of authorized operation. For accounting firms and CFOs advising or auditing authorized CASPs, understanding what those duties require operationally is essential to assessing whether a client or counterparty is genuinely compliant.
Monitoring, screening, and transaction surveillance
Authorized CASPs are required to screen wallets and transactions on an ongoing basis, maintain transaction monitoring capable of identifying suspicious patterns, conduct counterparty due diligence, and support investigations when issues arise. These are not one-time onboarding checks. They require continuous on-chain visibility and the ability to act consistently when risks are identified.
The practical implication for MiCA compliance in crypto operations is that the controls need to be embedded in daily workflows. A firm that passes the authorization assessment but then runs only periodic checks is not meeting the standard. Supervisors and auditors reviewing a CASP's compliance program will look at the frequency, coverage, and quality of monitoring outputs, not just the existence of a policy document.
Geographical scope is broader than it appears
One point that catches firms off guard: MiCA's reach is not limited to entities incorporated in the EU. A CASP headquartered outside the bloc can still fall within scope if it actively markets or provides services to EU clients. The prohibition in Article 59 applies to the activity, not just the address of the firm. Third-country operators that have been relying on transitional cover granted by an NCA face the same cliff-edge as EU-based operators, and those without any authorization path in place need to act now.
What Accounting Firms and CFOs Should Do This Week
The practical checklist for professional firms and corporate finance teams divides into three areas.
Counterparty and vendor review
Pull the current ESMA CASP register and cross-reference every crypto service provider in your transaction flows, custody arrangements, and vendor list. Note the date of the pull. Flag any counterparty that does not appear, and escalate for legal review before continuing to transact. For counterparties in jurisdictions with early transitional deadlines (the Netherlands, Finland, Latvia, Hungary, Slovenia, Sweden), check whether the authorization predates that country's cut-off or was obtained under MiCA directly.
Our earlier coverage of ESMA's fourth MiCA update and the CASP register sets out the register structure and what the authorization entries mean in practice, and is worth reviewing alongside this update.
Client assessment for advisory and audit firms
Firms advising CASPs, or auditing entities with significant crypto-asset holdings or exposures, need to reassess the regulatory standing of their clients in light of the 1 July deadline. A client that was operating under a transitional registration and has not obtained authorization is now in breach of Article 59. That changes the risk assessment for the engagement, the disclosures required in any audit report, and potentially the firm's own obligations under applicable professional standards.
Background on the supervisory context is available in ESMA's June/July 2026 newsletter on MiCA's transitional period, which covers the supervisory expectations for the post-deadline period.
Digital asset accounting software and record-keeping alignment
MiCA's reporting and record-keeping requirements for authorized CASPs create corresponding demands on the digital asset accounting software and crypto bookkeeping software that firms use to maintain and audit those records. Ledgers need to capture the full transaction chain in a format that supports both financial reporting and regulatory reporting. If existing systems were set up to meet only the pre-MiCA national regime standards, a gap analysis is overdue. The same applies to internal controls documentation: supervisors will expect evidence that the controls described in the authorization application are actually operating as described.
Frequently Asked Questions
Did all EU member states give CASPs the full 18-month transitional period?
No. Member states had discretion to grant between zero and 18 months. The Netherlands, Finland, Latvia, Hungary, and Slovenia chose six months, closing their windows on 30 June 2025. Sweden granted nine months, closing on 30 September 2025. France, Malta, Luxembourg, and several others ran to the full 18-month limit on 1 July 2026. The relevant cut-off for any given counterparty depends on the jurisdiction of their pre-MiCA registration.
Can a CASP still serve EU clients under the reverse solicitation rule?
Only in very narrow circumstances. MiCA Article 61 allows an unauthorized firm to serve an EU client if that client initiated contact entirely on their own, with no prior solicitation. Any advertising, app listing, affiliate marketing, or search promotion directed at EU users breaks that condition. Most commercial crypto operations cannot credibly rely on this carve-out for ongoing business.
How often is the ESMA CASP register updated, and is it always current?
ESMA updates the register weekly, but it is explicit that authorizations reported by national competent authorities are not reflected immediately. The count in any given week may understate the actual number of authorized CASPs. Always date your register pull and check again if the position of a specific counterparty is material to a decision.
Does MiCA apply to firms based outside the EU?
Yes, if they actively target or serve EU clients. The prohibition in Article 59 attaches to the activity of providing crypto-asset services to EU-based clients, not to the location of the service provider. Third-country firms marketing to EU users without authorization are in scope and face the same enforcement risk as EU-based operators without a license.
What should an accounting firm do if a client's CASP counterparty is not on the ESMA register?
Flag it immediately and seek legal advice before advising the client to continue transacting with that counterparty. An unlicensed CASP is operating in breach of Article 59, which creates counterparty risk, potential reputational exposure, and possibly AML/CFT implications if the relationship continues without a credible remediation plan. Document the finding and the steps taken.
Source: Elliptic
