MiCA After 1 July 2026: What Crypto Firms Without a CASP Licence Can Still Do. The Markets in Crypto-Assets Regulation has now crossed its most important operational threshold. On 1 July 2026, the final national transitional periods expired across the European Union. A firm that still provides crypto-asset services in the EU without the required authorisation can no longer treat its pending application, historic registration or non-EU status as a general permission to continue business.
That change does not mean every unlicensed crypto business must abandon Europe. It does mean that management must choose a lawful route, document it and execute it. The available routes differ sharply in cost, speed, control and regulatory risk. A serious decision therefore starts with the firm’s actual services, client base, legal entities, marketing footprint and strategic objective—not with a preferred jurisdiction or a licence brochure.
This article sets out the principal options for firms that did not obtain Crypto-Asset Service Provider authorisation before the deadline.
The deadline changed the legal position
MiCA created a harmonised framework for crypto-asset service providers across the EU. It replaced the fragmented position under which firms often relied on national virtual-asset registrations that focused primarily on anti-money-laundering obligations. CASP authorisation goes further. It tests governance, management suitability, prudential safeguards, operational resilience, conflicts, complaints, safeguarding, outsourcing and the firm’s ability to operate as a real European business.
The transitional regime gave eligible firms time to move from national rules into MiCA. That bridge has now closed. In its April 2026 statement, the European Securities and Markets Authority made the consequence explicit: firms that remain unauthorised after 1 July must cease providing crypto-asset services to EU clients. National authorities should take effective enforcement action where firms ignore that obligation.
An application in progress does not, by itself, restore a right to operate. Nor does a company solve the issue by placing an offshore entity in the contractual chain while its website, sales team or affiliates continue soliciting European clients. The analysis follows the substance of the activity.
Option 1 — Apply for a new CASP authorisation
A direct application remains the cleanest route for a group that wants to own its European regulatory platform and build a long-term EU business. It also gives the applicant control over products, technology, staff, client relationships and future passporting.
However, management must separate the right to apply from the right to trade. A new applicant normally cannot provide regulated services until the competent authority grants authorisation. The group therefore needs an interim plan for existing clients and activities.
The application must describe a business that can operate after approval, not a shell assembled to obtain a licence. Article 62 of MiCA requires extensive information on governance, shareholders, management, prudential safeguards, internal controls, AML/CFT arrangements, business continuity and ICT systems. The permanent minimum-capital requirement varies according to the services, while the prudential safeguard must equal at least the higher of the applicable minimum amount or one quarter of the previous year’s fixed overheads.
Regulators also examine substance. The applicant needs enough decision-making capacity, qualified staff and operational control in its home Member State. It may outsource functions, but it cannot outsource responsibility or reduce the regulator’s access to people, systems, data and records.
A new application suits a firm that has sufficient time, capital and management resources. It suits a group that wants to determine its own risk appetite and product roadmap. It fits less well when the commercial opportunity requires immediate market access or when the group cannot pause its existing EU activity.
Option 2 — Acquire an authorised CASP
An acquisition can shorten the path to a functioning regulated platform, but it does not turn authorisation into a transferable commodity. The buyer acquires a supervised legal entity, its governance, history, staff, systems, liabilities and regulatory relationships.
The first step is verification. Buyers should confirm the entity, home Member State, authorised services and current status in ESMA’s Interim MiCA Register. A logo, registration certificate or national VASP entry cannot substitute for that check.
The second step is regulatory due diligence. The buyer must examine the licence perimeter, capital position, client assets, complaints, AML files, outsourcing, cybersecurity, financial statements, regulator correspondence and any remediation plan. It should also test whether the target actually performs the activities described in its application. An apparently fast acquisition can become slow and expensive if the authority requires new management, fresh capital, system migration or a revised programme of operations.
The third step is change-of-control planning. The acquisition agreement should make completion conditional on the necessary regulatory clearance. The buyer should present its ownership, source of funds, business plan, governance and post-acquisition integration before it changes the target’s activity materially.
An acquisition works best when speed matters and the target already has credible substance. It works badly when the buyer selects the cheapest available licence without testing whether the entity, scope and operating model fit the proposed business.
Option 3 — Partner with an authorised CASP
A commercial partnership or white-label arrangement can provide a faster and more capital-efficient route. The authorised CASP supplies specified regulated services; the unlicensed technology or commercial partner supplies permitted functions such as software, branding, distribution support or customer experience.
The structure must reflect reality. The authorised CASP must remain responsible for the regulated service, client onboarding, safeguarding, regulatory reporting and any outsourced function for which MiCA leaves it accountable. Client agreements, disclosures and payment flows must identify the regulated provider clearly. Marketing must not create the impression that the unlicensed partner holds the licence.
Outsourcing also has limits. MiCA does not allow an authorised firm to become an empty front while an unauthorised company performs the substance of the regulated business. ESMA has emphasised autonomous operation, sufficient in-country personnel and proper control of outsourced functions. Its post-transition statement also warns that an EU CASP may not delegate custody to an unauthorised provider.
Partnerships suit firms that want to test demand, launch a defined product or enter the EU without immediately building a complete regulated organisation. They also create dependency. Management must assess termination rights, data portability, client ownership, service levels, safeguarding arrangements and the consequences if the partner changes its risk appetite.
Option 4 — Migrate clients to an authorised entity
An international group may already own an authorised CASP elsewhere in its structure, or it may appoint an external CASP to receive the affected book. In that case, it can migrate EU clients rather than abandon them.
Migration requires more than changing the name in the website footer. The receiving CASP must accept the clients under its own onboarding and AML/CFT standards. The parties must address consent, contract novation, data protection, asset transfer, open orders, complaints and client communications. They must also decide which entity remains responsible for historic conduct and records.
ESMA expects firms to execute credible client-transfer plans and to notify clients in a timely and clear manner. A rushed migration after the deadline increases conduct and operational risk. Firms should create a reconciliation record that proves where every client asset, balance and instruction moved.
Option 5 — Wind down EU activity in an orderly manner
Some firms will conclude that authorisation, acquisition or partnership does not justify the cost. An orderly exit can be the right commercial decision, but management must treat it as a regulated project.
The firm should stop new solicitation and new regulated activity, identify every affected EU client, communicate the timetable and offer a workable method to withdraw or transfer assets. ESMA specifically recognises transfers to an authorised CASP or, where appropriate, to a self-hosted wallet controlled by the client. The firm should preserve records, handle complaints and maintain enough staff and systems to complete the wind-down safely.
Closing an EU entity while continuing to target the same clients from abroad does not create a genuine exit. Websites, affiliates, events, introducers, paid advertising and language-specific campaigns can all evidence solicitation.
Reverse solicitation is not a market-access strategy
MiCA preserves a narrow situation in which an EU client initiates a service at the client’s own exclusive initiative. Firms sometimes describe this exception as a substitute for authorisation. It is not.
The exception requires a genuinely client-initiated approach. It does not allow a non-EU firm to solicit clients and then label their response “reverse solicitation”. It also does not provide a durable basis for promoting new services beyond the client’s request. ESMA has confirmed that the restriction applies to professional and institutional relationships as well as retail business.
A group may decide to serve only clients outside the EU. If so, it should align geofencing, onboarding, sales incentives, affiliate arrangements and marketing with that decision. A disclaimer alone will not repair a business model that continues to target Europe.
A practical decision framework
Management should begin with four questions.
Do we need to own the regulated relationship? If the answer is yes, a new application or an acquisition will usually provide the strongest long-term platform.
How quickly must we enter or re-enter the market? A credible acquisition or partnership may reduce the launch timetable, but only after careful due diligence and regulatory planning.
What must happen to our existing EU clients now? The firm should migrate or wind down the book immediately. It should not wait for an uncertain authorisation timetable.
Which services do we actually provide? Custody, trading-platform operation, exchange, execution, placement, advice, portfolio management and transfer services create different requirements and capital implications. The analysis must follow the product and client journey.
What FinTechLex can do
FinTechLex helps firms turn these choices into an executable structure. We can assess the service perimeter, compare jurisdictions, prepare a CASP application, identify and review acquisition targets, structure a white-label partnership, conduct regulatory and commercial due diligence, and plan a compliant client migration or wind-down.
The correct solution does not begin with “Which licence is cheapest?” It begins with a harder question: “Which regulated structure can support the business we genuinely intend to operate?”
To discuss a CASP application, an acquisition or a partnership structure, contact insight@fintechlex.com.
This article provides general information and does not constitute legal advice. The application of MiCA and national procedures depends on the facts, services and competent authority involved.
Official sources for editorial verification
- ESMA, Statement on the end of MiCA transitional periods, 17 April 2026: https://www.esma.europa.eu/sites/default/files/2026-04/ESMA75-453128700-2607_Statement_on_the_end_of_the_MiCA_transitional_periods.pdf
- ESMA, Markets in Crypto-Assets Regulation (MiCA) and Interim MiCA Register: https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica
- Regulation (EU) 2023/1114, including Articles 59, 62, 67 and 73: https://eur-lex.europa.eu/eli/reg/2023/1114/oj
- ESMA, supervisory briefing on authorisation of CASPs: https://www.esma.europa.eu/document/supervisory-briefing-authorisation-crypto-asset-service-providers-under-mica


