ESMA confirmed on 17 April 2026 that MiCA's transitional period ended definitively on 1 July 2026, with no extensions, across all 27 member states. By May 2026, only around 17% of previously nationally-registered crypto firms had actually secured CASP authorisation under Regulation (EU) 2023/1114.
Before that date, firms operating under a pre-MiCA national registration could keep serving EU clients while their MiCA application was pending. After it, that cover is gone. Any entity providing crypto-asset services to EU clients without CASP authorisation is now in breach of EU law and must cease those services.
Reverse solicitation isn't plausible anymore. ESMA reads Article 61 narrowly: it only protects an unsolicited approach from an EU client acting entirely on their own initiative, no prompting. Any advertising, affiliate arrangement, app listing, or search marketing aimed at the EU breaks that protection, and ESMA has said this applies in a B2B context too, not just retail.
What a CASP application actually has to contain
MiCA's Level 2 technical standards spell this out precisely. Under Commission Delegated Regulation (EU) 2025/305 and its accompanying Implementing Regulation (EU) 2025/306, an application isn't a form. It's a structured dossier covering:
- A programme of operations with a forward-looking, multi-year business plan
- Governance documentation: board structure, fit-and-proper assessments, a named MLRO
- Prudential information, including minimum capital requirements that scale with the services offered
- An AML/CFT programme mapped to the applicant's actual user flows and risk profile
- Safeguarding arrangements for client assets
- Complaints-handling procedures
- A full outsourcing map
ESMA's own review of early authorisation practice found that business plans need to be assessed in a genuinely forward-looking way, factoring in expected growth and the risks that come with it, not just a static snapshot.
Why generic documentation gets rejected
The starting posture of a national competent authority (NCA) is skeptical. The burden sits entirely on the applicant to demonstrate readiness. An AML policy copied from a standard template doesn't satisfy the Level 2 technical standards, which require the programme to map directly to the applicant's specific onboarding processes and transaction patterns.
Even operators actively running an authorisation process describe target dates as soft by default, an internally expected "end of July or beginning of August" gets discussed in the same breath as "realistically, it'll be September," not because of any single failure, but because NCA review adds its own pace on top of whatever the applicant controls.
The substance test: no letter-box entities
ESMA's supervisory guidance on CASP authorisation is explicit that a CASP must have genuine operational substance inside the EU. Outsourcing too many functions outside the bloc risks a finding that the entity is a "letter-box" firm, one that exists in name within the EU while its real operations sit elsewhere.
NCAs specifically examine both the number and the importance of outsourced functions, and outsourcing to jurisdictions where the NCA can't obtain information from the outsourced party is treated as incompatible with MiCA outright. AML functions in particular can't be outsourced away from the CASP's own responsibility.
This gets more complicated for a group operating multiple regulated entities across jurisdictions. A firm pursuing CASP and VASP registration in more than one EU country at the same time has to be able to show, for each entity, which one actually holds the operational substance the NCA is testing for, rather than letting the group's overall footprint imply substance that no single entity can independently demonstrate and it only shows up once a group has more than one CASP-eligible entity to account for.
A concrete example: Cyprus's timeline
CySEC's press release, dated 23 December 2025, set 27 February 2026 as the deadline for existing national-regime CASPs to lodge a complete MiCA application, with continued operation permitted only until 1 July 2026 or a decision on the application, whichever came first.
Cyprus has been one of the more active MiCA jurisdictions through the transition, with roughly a dozen firms authorised or in the pipeline as the period closed, a small fraction of the firms that had been operating under the prior national regime.
What this means operationally right now
For a payment or OTC firm intending to serve EU clients, there are really only three positions to be in today: authorised, in an active and complete application pipeline, or executing a wind-down plan. ESMA has been explicit that unauthorised firms need wind-down plans that are operational, credible, and immediately executable.
MiCA-readiness checklist
Before submitting, or continuing, a CASP application, the documentary set below is what actually gets scrutinised first, per ESMA's own supervisory findings:
- A forward-looking, multi-year programme of operations, not a static snapshot
- Governance documentation naming a qualified MLRO and demonstrating board-level fit-and-proper standards
- Prudential/capital evidence matched to the specific services applied for
- An AML/CFT programme built around your actual onboarding flows and transaction patterns, not a generic template
- Safeguarding arrangements for client assets, documented in detail
- A complaints-handling procedure that's actually published and operational
- An outsourcing map that avoids concentrating core functions, especially AML, outside the EU
- For multi-entity groups: clarity on which specific entity holds the operational substance being tested, not an assumption that group-wide footprint is enough
- If not yet authorised: an operational, immediately executable wind-down plan
Frequently asked questions
Who does MiCA apply to?
Any entity providing crypto-asset services to clients in the EU, including payment and OTC firms, which is why CASP authorisation is now the sole gateway to operating in the bloc since the transitional period ended on 1 July 2026.
What are the requirements for MiCA CASP authorisation?
A structured application covering a forward-looking business plan, governance and fit-and-proper documentation, prudential capital requirements, an AML/CFT programme mapped to actual user flows, safeguarding arrangements, complaints procedures, and a full outsourcing map.
When did MiCA's transitional period end?
The transitional period ended definitively on 1 July 2026 across all 27 EU member states, confirmed by ESMA on 17 April 2026, with no extensions granted.
What happens if a firm doesn't get MiCA authorisation?
Providing crypto-asset services to EU clients without authorisation is now a breach of EU law, and unauthorised firms are expected to have an operational, immediately executable wind-down plan in place, not simply an application in progress.